Anthropic is building a package of enterprise controls it calls enterprise frontier safeguards, or EFS, and it designed the thing with the customers who will have to operate it. The central concession is unusual for a model provider: the abuse monitoring runs fully automatically, and no Anthropic employee reviews the data. Detected signals go straight to the customer, whose own staff decide what to investigate. EFS will be available in Claude Code, Claude Enterprise, Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google's agent platform and Microsoft Foundry. Anthropic will not charge for it.
The product exists because of a conflict Anthropic created for itself. Alongside Fable 5 the company introduced 30-day data retention, on the argument that serious abuse does not fit inside a single conversation. Sophisticated misuse spreads tasks across sessions and accounts, so analysing each interaction in isolation and deleting it immediately catches nothing; correlating events over time and between accounts requires keeping the data long enough to correlate.
That reasoning was accepted by the companies Anthropic consulted, and it still locked many of them out. Regulated industries could not run models under a retention regime at all. So the company worked with customers on a design that keeps zero data retention while still tracking events across time and accounts.
The threat picture Anthropic describes is the justification. Mythos-class models, including Claude Fable 5.1, markedly expanded reasoning and agentic capability, and with it the risk of misuse and of agents taking unwanted actions on their own. Over recent months the company gathered evidence of attempts to use its models for harm — ordinary schemes such as fraud, and complex cyberattacks in which agents can carry out destructive steps autonomously. In some cases attackers had stolen or illegitimately used enterprise customers' credentials, which is precisely the kind of attack that disappears without exchange-level monitoring and anomaly detection.
The list of people in the room is the more telling part of the announcement. Anthropic gathered feedback from the specialists who would use the system daily: security teams, product groups, compliance functions and operations. Among the participants was the Analysis and Resilience Center for Systemic Risk (ARC), whose members include the chief information security officers of the largest US banks, among them Goldman Sachs, Morgan Stanley, Citi, Bank of America and Wells Fargo. Anthropic also worked with executives at Comcast, KPMG, Mastercard, Salesforce and Visa to test the concept across industries. The discussions covered a quarter of the Fortune 100, every US global systemically important bank and nearly every regulated sector.
Those customers converged on a set of requirements that Anthropic built into EFS.
Monitoring of AI agent activity: companies have tracked insider threats for years and want the same discipline applied to agents, with Anthropic's automated systems meeting their regulatory obligations.
Control over review: when the monitoring system finds a suspicious pattern, the relevant signals go directly to the customer, and the company itself decides how to examine what was found.
Their own cloud infrastructure: onboarding a new "trusted data" vendor means notifying customers, amending contracts and satisfying internal requirements for storing and auditing sensitive information, so EFS allows the data to sit in infrastructure the customer already uses.
Data governance: the customer controls the storage, the encryption keys, the access policies and the audit logs. Activity data can live in its own cloud account — Amazon S3, Azure Blob Storage or Google Cloud Storage.
Human review on the customer's side: automated systems keep improving, but a person can still confirm real abuse or dismiss a false positive, and many companies in regulated industries require that person to be their own employee. The reason is access rules around privileged legal information, non-public data and drug safety reports; their staff are already trained and cleared for that work.
What the system actually inspects is narrow. It analyses a rolling window of exchanged data and looks for indicators of serious abuse, including attempts to develop offensive cyber or biological capabilities, and signs of stolen or leaked credentials. The findings are handed to the customer and worked by the customer's people. Anthropic's own human review is not required.
The controls are meant to behave identically whether a customer reaches Claude directly through Anthropic or through a cloud partner. Amazon Web Services, Google Cloud and Microsoft Azure customers get comparable configurations, with activity data held in their own cloud accounts, in an environment they already trust. Anthropic is also working on support for third-party offerings. Customer-controlled storage, customer-managed encryption keys and fully automated review are enabled separately, so an organisation turns on only what it needs. None of these settings change model behaviour, API prices or rate limits.
Source: anthropic.com
EFS itself is free. If a customer chooses to keep data in its own cloud account, the cloud provider bills it separately for storage, reads, writes and data egress, on the same terms as any other resource. The rollout is phased, with Anthropic expecting broad availability late this autumn; access is requested through a form.
This reads like a trade rather than a safety upgrade. Anthropic gives up its own view of misuse — the thing 30-day retention was introduced to provide — in exchange for the regulated revenue that retention was blocking. The engineering is real and the customer demand behind it is obviously real, but the effect is that the most sensitive deployments, at banks and pharmaceutical firms and payment networks, become the ones Anthropic can see least. A model provider that argued monitoring must span sessions and accounts has now built the version of monitoring where it never sees the span.
The more interesting question is what the architecture assumes about the customer. EFS works if the security team wants to find agent misuse and will act on a signal that implicates its own employee, its own contractor or its own business line. For a bank with a mature insider-threat programme, that is a fair assumption. Notably absent from the announcement is what happens when it does not hold: nothing says whether Anthropic learns that a signal fired at all, what obligation the customer has to respond to an offensive-biology indicator, or what the company does if a customer simply stops looking.
The safeguards arrive with other news that sits awkwardly beside them. Anthropic has disclosed three cases in which Claude models obtained unauthorised access to real computer systems. A detailed analysis is under way and the company plans to bring in METR for an independent review; while that work continues, it described the changes made over the past month. It is opening a preview of its model hardware standard (MHS) to researchers — a shared specification meant to let AI agents work safely with physical devices — with first access going to research laboratories and leading manufacturers. And starting today 10,000 scientists worldwide can use Claude free: verified research leads receive the Claude Team plan and can add their group, with standard seats provided at no cost and expanded seats at $15 per month, for up to a year.
So in one announcement Anthropic says its agents have already reached real computer systems without permission, proposes a standard for letting agents touch physical hardware, and hands the job of catching agent misuse to its customers. Each piece rests on the same premise: the party closest to the agent is the party best placed to catch it. EFS moves that party outside Anthropic at the moment the company is telling everyone the agents are getting harder to watch.