Anthropic is changing how it handles enterprise customer data, letting businesses store AI safety-monitoring logs in their own cloud accounts instead of Anthropic’s. The announcement, made September 1, 2026, effectively answers the core complaint enterprises have raised about Anthropic’s data retention policy since it launched three months earlier.
The new system, called Enterprise Frontier Safeguards (EFS), lets customers keep activity data used for misuse detection inside their own Amazon S3, Azure Blob Storage, or Google Cloud Storage accounts, under encryption keys they control. When Anthropic’s automated monitoring flags a potential problem, the alert goes straight to the customer’s own security team — Anthropic says no human reviewer on its side needs to see the underlying data.
Table of Contents
What Changed, and Why
Anthropic introduced 30-day data retention for safety monitoring in June 2026, alongside the launch of Claude Fable 5 and Mythos 5, so it could detect misuse patterns spread across multiple sessions rather than single conversations. Anthropic frames EFS as the product of ongoing customer conversations, not an admission the policy failed — but CNBC and PYMNTS both independently describe it as a response to sustained pushback from enterprise customers, particularly in regulated industries like banking and healthcare where the retention requirement clashed with compliance rules.
The underlying monitoring rationale hasn’t changed: Anthropic says sophisticated misuse rarely shows up in one interaction and requires correlating behavior over time. What EFS changes is who holds the data that correlation runs on.
How Enterprise Frontier Safeguards Works
EFS has three moving parts. Storage: activity data flows into the customer’s own cloud account rather than Anthropic’s infrastructure, with the customer controlling encryption keys, access policies, and audit logs. Monitoring: Anthropic’s automated systems still scan a rolling window of activity for patterns like fraud, stolen credentials, or attempts to develop offensive cyber or biological capabilities. Review: flagged alerts go to the customer’s own security or compliance staff, not an Anthropic employee — something Anthropic says matters most to organizations bound by rules about who can see certain categories of information, such as privileged legal material.
One thing Anthropic hasn’t explained: exactly how its detection systems analyze data that never enters Anthropic’s own infrastructure. Whether that involves a detection service running inside the customer’s cloud tenancy, an abstracted signal sent back to Anthropic, or something else isn’t disclosed, and no independent technical breakdown has surfaced.
EFS is free to use — customers pay their cloud provider’s standard storage and transfer costs — and it isn’t available yet. Anthropic says it will roll out in phases, targeting broad availability “later this fall,” with eligible customers using standard zero data retention on Fable 5 and Fable 5.1 in the meantime.
A Paired Model Release
Anthropic used the same day to release Claude Fable 5.1 and Mythos 5.1, which it describes as the same underlying model differentiated by access: Fable 5.1 is generally available, while Mythos 5.1 is restricted to vetted organizations in cybersecurity and life sciences. “Mythos-class” is Anthropic’s own term for this capability tier. Trade press has also reported, via Anthropic, a roughly 60% drop in benign requests incorrectly flagged by Fable 5.1’s safety classifiers compared to Fable 5 — a company-reported figure that hasn’t been independently verified.
Built With Enterprise Customers
Anthropic says it developed EFS with more than 100 customers across financial services, healthcare, manufacturing, telecom, law, retail, and the public sector, alongside AWS, Google Cloud, and Microsoft Azure. Much of that input came through the Analysis and Resilience Center for Systemic Risk (ARC), whose members include CISOs from Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo; ARC’s leadership says eight member institutions helped define requirements around data custody and review conditions.
Executives tied to Goldman Sachs, Wells Fargo, Snowflake, Stripe, Rogo, and Cognition are quoted describing the same requirement: keeping sensitive data in infrastructure they control while still accessing Anthropic’s most capable models. These are design-partner endorsements, not confirmed production deployments — EFS isn’t broadly available yet.
EFS vs. OpenAI’s Approach
Anthropic isn’t alone in solving this. Roughly two weeks before EFS, OpenAI previewed Private Safety Processing, paired with a broader zero-data-retention commitment. OpenAI’s system aims to detect abuse across related interactions while limiting what reaches OpenAI itself to an abstracted signal about an issue’s type and severity, regardless of where the underlying content sits.
| Anthropic EFS | OpenAI Private Safety Processing | |
|---|---|---|
| Where data lives | Customer’s own cloud account | Customer infrastructure, or OpenAI storage under customer-held keys |
| Who reviews flags | Customer’s own team | Not fully detailed; OpenAI gets an abstracted signal only |
| Cost | None beyond standard cloud fees | Not detailed publicly |
| Availability | Phased rollout, later fall 2026 | Preview announced; white paper and rollout planned for September |
Neither system has been independently tested for real-world effectiveness.
Timeline: June 2026 — 30-day retention introduced with Fable 5/Mythos 5 → July 30, 2026 — Anthropic discloses unauthorized-access incidents during safeguard-free evaluations → mid-to-late August 2026 — OpenAI previews Private Safety Processing → Sept 1, 2026 — EFS announced alongside Fable 5.1/Mythos 5.1 → later fall 2026 — EFS phased rollout targeted.
What’s Still Unclear
There’s no independent security audit of EFS’s key management or access controls, no public detail on exact eligibility criteria, and — as one independent analysis notes — no published technical explanation of how the underlying detection mechanism works. None of this means EFS doesn’t function as described, only that the claims currently rest on Anthropic’s own account.
The Bottom Line
For organizations that held off on Anthropic’s most capable models over data-residency concerns, EFS is a structural change, not just messaging — it targets the objection that mattered most to regulated industries. But nothing changes immediately: broad availability is months out, and independent verification of how the system performs is still to come. Both major AI labs are now betting that enterprise adoption depends on giving customers structural control over their own data. Whether that bet pays off depends on details both companies are still filling in.
Frequently Asked Questions
What is Anthropic’s Enterprise Frontier Safeguards (EFS)? A security architecture, announced September 1, 2026, letting enterprise customers store AI safety-monitoring data in their own cloud accounts under their own encryption keys, with flags reviewed by the customer’s own team rather than Anthropic’s.
Why did Anthropic change its data retention policy? Anthropic introduced 30-day retention in June 2026 to catch misuse spread across sessions. CNBC and PYMNTS report EFS as a response to enterprise customers, especially in regulated industries, who found that policy difficult to work with.
Is Enterprise Frontier Safeguards available now? No. Anthropic says it will roll out in phases, targeting broad availability later this fall of 2026.
Does EFS cost extra to use? No — Anthropic doesn’t charge separately; customers pay standard cloud provider rates for storage and transfer.
How is EFS different from OpenAI’s approach? OpenAI’s Private Safety Processing limits what reaches OpenAI to an abstracted signal about an issue’s type and severity. Anthropic’s EFS keeps the underlying activity data in the customer’s own cloud account by default. Neither has been independently evaluated.
What is the difference between Claude Fable 5.1 and Mythos 5.1? Anthropic describes them as the same underlying model: Fable 5.1 is generally available, while Mythos 5.1 is restricted to vetted cybersecurity and life-sciences organizations.
Does Anthropic still review flagged data under EFS? No — Anthropic says automated systems handle detection and route flags directly to the customer’s own team, with no Anthropic employee review required.

