Anthropic announced Enterprise Frontier Safeguards on September 1, 2026, a design that keeps activity data in cloud storage the customer controls while Anthropic’s automated systems still look for misuse. The company built the product with more than 100 customers in finance, healthcare, manufacturing, telecom, law, retail, and the public sector, plus Amazon Web Services, Google Cloud, and Microsoft Azure. EFS will roll out in phases starting later this fall. Until it is ready, eligible customers get zero data retention on Claude Fable 5 and Fable 5.1.
The same day, AWS said Claude Fable 5.1 is generally available on Amazon Bedrock and Claude Platform on AWS. Anthropic has marked Fable 5.1 a Covered Model, which adds data-retention, safety-review, and access rules wherever the model is offered. AWS said EFS is how eligible customers can use those models and still keep the data in an environment they control.
Why retention became a sales problem
Anthropic says Mythos-class models such as Fable 5.1 raise the odds of both human misuse and autonomous misbehavior. The company reports attempted abuse that ranges from fraud to multi-session cyberattacks, including cases that use stolen enterprise credentials. Detecting that pattern, it argues, needs a window of stored traffic. Single-turn classifiers that discard the prompt immediately cannot correlate work across sessions and accounts.
That is why Anthropic added 30-day retention starting with Fable 5. The company says it has never trained on enterprise data without permission and will not start now. Regulated buyers still balked. Adding another vendor that holds logs means contract updates, customer notifications, and a new audit surface. EFS is the compromise: monitoring still runs, but the bytes sit in the customer’s Amazon S3, Azure Blob Storage, or Google Cloud Storage account, under the customer’s keys, access policies, and audit trail.
When the detectors fire, the signal goes to the customer. Anthropic says no Anthropic employee has to read the flagged traffic. Automated systems watch a rolling window for offensive cyber or biological work and for signs of leaked credentials. Customer teams already cleared for privileged legal files or non-public information handle the human review.
EFS is planned for Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google’s Agent Platform, and Microsoft Foundry. Design partners named in the post include the Analysis and Resilience Center for Systemic Risk, whose bank members include Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo, plus Comcast, KPMG, Mastercard, Salesforce, and Visa.
“Enterprise Frontier Safeguards gives us exactly what we asked for: our logs stay in a Wells-managed environment under Wells-managed keys. We keep custody of our data while Anthropic operates the detection.” Wells Fargo, in Anthropic’s announcement
Decoded Take
Frontier labs have been selling intelligence and then asking enterprises to accept a retention policy that compliance teams cannot sign. EFS is Anthropic admitting that argument lost. The interesting split is who holds the keys versus who writes the detectors. If the models only work when Anthropic can see a 30-day window, and the window now lives in the bank’s bucket, the product becomes a sensor the customer can turn off. Watch whether EFS ships on Bedrock and Azure this fall as a checkbox, whether Covered Model rules still force a retention story on mid-market buyers, and whether banks treat customer-held logs as good enough for their regulators. A detector that never sees the traffic is a brochure. A detector that fires into a Wells-managed queue is a control.