DevNews

Enterprise Frontier Safeguards: 30 days, in your own cloud

On this page
  1. What actually changed
  2. The part that isn’t shipping
  3. The wording worth reading twice
  4. Who shaped it
  5. What we’d do this week
  6. Sources

Somebody on your compliance team killed the Fable 5 pilot back in June, and the reason fit on one line: thirty days of your prompts parked on a vendor's servers. Anthropic has moved. On 1 September it announced Enterprise Frontier Safeguards, and the short version is that retention doesn't go away, it changes address. The traffic used for misuse detection lands in a bucket you own, encrypted with keys you hold, and the flags go to your security team rather than Anthropic's. We think that's a better shape than the June policy. It is also not something you can switch on this morning. The rollout is phased and starts later this fall, and the one concrete thing on offer today is an interim zero data retention grant on Fable 5 and 5.1, for customers Anthropic calls eligible without saying who that is.

The short answer

Anthropic announced Enterprise Frontier Safeguards on 1 September 2026. The monitoring data that Fable-class models generate stops living on Anthropic infrastructure and starts living in your cloud account, under your encryption keys, with detection flags routed to your own security people. Nothing ships today. What you get in the meantime is an interim zero data retention grant on Fable 5 and 5.1, if you qualify.

$0what Anthropic charges for EFS
100+customers it was designed with
Fallwhen the phased rollout starts
Answer card stating that Anthropic announced Enterprise Frontier Safeguards on 1 September 2026, that activity data used for misuse monitoring moves into cloud storage the customer controls under the customer own encryption keys, that Anthropic charges nothing for the feature while the cloud provider bills storage and egress, and that the phased rollout starts later in autumn 2026 with interim zero data retention on Fable 5 and Fable 5.1 for eligible customers.
The one-card version. Custody moves. The monitoring does not stop. PNG

What actually changed

Back in June, Anthropic attached 30-day retention to Fable 5 and everything Mythos-class after it. The stated reason was never training. It was that a serious abuse pattern often spreads across many sessions and many accounts, so scoring each call on its own and binning the data immediately does not catch it. Correlation needs history. Fair enough as engineering.

It also made the model unusable for a whole tier of buyers. Anthropic says as much in plain language: enterprises broadly understood the security argument, and many in regulated industries still could not adopt a model that came with vendor-held retention.

EFS is the compromise. Three pieces, each opt-in:

  • Customer-owned storage. Activity data used for monitoring goes to your Amazon S3, Azure Blob Storage or Google Cloud Storage account.
  • Customer-managed encryption keys. Your keys, your access policies, your audit trail.
  • Fully automated review. Anthropic’s classifiers run over a rolling window of traffic looking for attempts to build offensive cyber or biological capability, and for signs of stolen or leaked credentials. Hits go straight to you.

That last one is the piece that reads best. The argument Anthropic reports hearing from regulated customers is that a human confirming a flag is genuinely useful, but the human doing it has to be one of theirs, because privileged legal material and non-public information each come with rules about who is cleared to look. Hard to argue with.

The part that isn’t shipping

Nothing here is live. The announcement is a design, a partner list and a request form.

Anthropic says the rollout happens in phases starting later this fall, with broad availability the goal for the same season. Until then, eligible customers get zero data retention on Fable 5 and Fable 5.1. That word eligible carries a lot of weight and appears nowhere with a definition, which is the same gap we flagged when Fable 5.1 shipped the day before with its retention clause intact.

Diagram comparing the June 2026 arrangement, where prompts and outputs from covered Claude models are retained for thirty days on Anthropic infrastructure under Anthropic keys with Anthropic reviewers seeing flagged content, against Enterprise Frontier Safeguards, where the same activity data is written to the customer own Amazon S3 or Azure Blob Storage or Google Cloud Storage bucket under customer managed encryption keys while Anthropic automated classifiers still analyse a rolling window of that traffic and deliver flags to the customer security team rather than to an Anthropic reviewer.
The detectors did not move. The bucket did. PNG

The wording worth reading twice

Two sentences in the announcement deserve a slow read.

The first: flags go to the customer and no human review by Anthropic employees is required. Required is not the same as impossible, and fully automated review is listed as opt-in rather than as the default. So an organisation that takes customer-owned storage but skips the automated-review option sits in a different position from one that takes all three. Worth pinning down in the contract rather than inferring from a blog post.

The second: the rolling window has no length attached to it. Anthropic’s June policy said 30 days. The EFS page says a rolling window of traffic and stops there. Reporting on the change says the 30 days survives and only the location moves, which is the sensible reading, but the official page never states it. If you’re the person who has to write a retention period into a data processing addendum, that number is not public yet.

Who shaped it

This is the unusual part, honestly. Anthropic names the room. More than a hundred customers across finance, healthcare, manufacturing, telecom, law, retail and the public sector, plus its cloud partners at Amazon Web Services, Google Cloud and Microsoft Azure.

More pointedly, it worked with the Analysis and Resilience Center for Systemic Risk, whose membership includes the CISOs of the largest US banks. Goldman Sachs, Morgan Stanley, Citi, Bank of America and Wells Fargo all get named. So do Comcast, KPMG, Mastercard, Salesforce and Visa. The ARC’s chief executive describes eight members defining what it would take to run a frontier model inside a systemically important bank, down to who holds the keys and under what conditions a person is ever permitted to look.

You can read that as marketing. We read it as a signal about who the buyer actually is now. Frontier model access is being architected around bank compliance departments, not around developers.

Checklist separating what the Enterprise Frontier Safeguards announcement of 1 September 2026 confirms from what it leaves open, confirming customer owned storage in Amazon S3 or Azure Blob Storage or Google Cloud Storage under customer managed encryption keys, automated detection flags routed to the customer with no Anthropic human review required, no charge from Anthropic and no change to model behaviour or API pricing or rate limits, and equivalent controls across the three major clouds, against the open questions of a phased rollout with no date beyond later this fall, a rolling window whose length is never stated, an eligibility bar for interim zero data retention that is never defined, cloud provider billing for storage and reads and writes and egress, and access granted through a request form rather than a console setting.
Read the right-hand column before you put a date in the migration plan. PNG

What we’d do this week

Not much, and that’s the point. There is no console setting to go find.

If you already hold a zero data retention agreement and it blocked you from the newest models, ask your account team two things: whether you qualify for the interim ZDR on Fable 5 and 5.1, and what the retention window is under EFS. If you’re budgeting, add a line for the storage. It’s your bucket now, so it’s your bill, egress included every time something reads those logs.

And if you were watching the other side of this trade, OpenAI previewed Private Safety Processing on 19 August with a similar goal and a different architecture. Two vendors, two answers, both still previews. The procurement question is genuinely live now, which it wasn’t in June when one side simply said no.

Sources

Anthropic, Developing Enterprise Frontier Safeguards with our customers, 1 September 2026. CNBC, Anthropic changes data retention policy after pushback from customers. The Decoder, Anthropic changes data retention policy after enterprise pushback.

Frequently asked questions

What is Enterprise Frontier Safeguards?

It is the system Anthropic announced on 1 September 2026 to replace vendor-held retention on its most capable models. Activity data used for misuse monitoring gets written to cloud storage the customer owns, such as Amazon S3, Azure Blob Storage or Google Cloud Storage, under the customer's own encryption keys, access policies and audit logging. Anthropic's automated detectors still run over a rolling window of that traffic, but the flags are delivered to the customer instead of to an Anthropic reviewer.

Does Enterprise Frontier Safeguards remove the 30-day retention?

No, and read that carefully. It moves custody. Anthropic's announcement describes automated analysis of a rolling window of traffic and never puts a number on that window, while press coverage of the change reports that the 30-day period stays as it was. So the honest answer today is that the data still has to sit somewhere for a meaningful period, and what changes is whose account it sits in. If the exact window matters to your policy, that number is not in the public announcement.

What does Enterprise Frontier Safeguards cost?

Anthropic charges nothing for it. Your cloud provider does. If you elect to keep the activity data in your own account, that provider bills you for the storage plus reads, writes and egress, the way it bills any other resource. Anthropic also states that none of the controls change model behaviour, API pricing or rate limits. So the new line item is a storage bill for logs you did not previously have to hold.

Which products will support it?

Anthropic lists Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google's Agent Platform and Microsoft Foundry, with equivalent controls whether you buy from Anthropic directly or through Amazon Web Services, Google Cloud or Microsoft Azure. Support for third-party offerings serving eligible customers is described as in progress, which is not the same as shipping.

Can I use Claude Fable 5.1 with zero data retention right now?

Only if Anthropic says you are eligible. The announcement says eligible customers receive ZDR on Fable 5 and Fable 5.1 until EFS is ready, and neither the announcement nor the model documentation defines eligible. Access to EFS itself runs through a request form, not a console toggle. If your procurement depends on it, the useful move is to ask your account team for the eligibility criteria in writing.