Developing Enterprise Frontier Safeguards with our customers · Anthropic, Sep 1, 2026
Anthropic replaces its data-retention mandate with a customer-held alternative
Anthropic is rolling out Enterprise Frontier Safeguards (EFS) to replace the 30-day data retention policy it attached to Fable 5 in June. "EFS works by storing data in cloud infrastructure controlled by the customer, not Anthropic," the company wrote, with automated misuse monitoring running on that data instead of a human review team at Anthropic. Flags for suspected credential theft or attempts to develop offensive cyber or biological capabilities go straight to the customer's own security team, not Anthropic's. Anthropic says it built EFS with more than 100 customers, including the CISOs of Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo through the Analysis and Resilience Center for Systemic Risk, and that it will not charge for the feature. EFS covers Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Google's Agent Platform, and Microsoft Foundry, rolling out in phases starting this fall.
Why it matters: The June retention rule was Anthropic's answer to misuse that spans multiple sessions and accounts, the kind an agent operating autonomously can commit over days rather than in one request. Regulated customers pushed back hard enough that Anthropic redesigned the enforcement mechanism around customer-held storage rather than dropping it. Anyone running Claude Code inside a bank, hospital, or law firm now has a path to frontier models without also handing Anthropic long-term custody of session logs.