Blog

Claude Enterprise Frontier Safeguards: Data Retention

September 2026 · 7 min read · AI Strategy

Line drawing of a locked box held inside a customer boundary, with an exit path blocked
← Back to all posts

On 1 September 2026, Anthropic announced Enterprise Frontier Safeguards, or EFS: an approach that pairs zero data retention with misuse detection by storing data in cloud infrastructure the customer controls rather than Anthropic's. It rolls out to customers in phases later in 2026, and eligible customers keep zero data retention on Fable 5 and Fable 5.1 in the meantime.

If you run an Australian business under APRA supervision, in health, in legal services or in government, this is the announcement that resolves the tension you have been arguing about internally for most of the year: monitoring that catches misuse usually requires keeping data, and keeping data is the thing your risk committee will not sign.

How does Claude Enterprise data retention work under EFS?

Under Enterprise Frontier Safeguards, data sits in cloud infrastructure controlled by the customer rather than by Anthropic, which is what allows zero data retention and misuse detection to coexist. Monitoring still runs, but customers control how detected activity gets reviewed. When the automated systems flag a pattern that needs attention, the signal goes directly to the customer to assess, rather than to a vendor-side review process the customer cannot see into.

That last detail is the one procurement teams should focus on, because it is what addresses the standing objection that a vendor's own automated monitoring does not meet the organisation's regulatory obligations. Putting the review in the customer's hands changes who is accountable for the judgement call.

Why retention existed in the first place

It helps to understand what the 30-day retention introduced with Fable 5 was actually for. Sophisticated misuse of agentic models spans many tasks across multiple sessions and accounts, so detecting it requires correlating activity over a meaningful window of time. A single request looks fine; the pattern across a fortnight does not. Anthropic has been explicit that retention was never about training on enterprise data, and that it has never trained on enterprise data without explicit permission.

The problem was that a perfectly reasonable security rationale collided with a perfectly reasonable compliance position. Many regulated enterprises simply could not use models with data retention, whatever the reason for it. EFS is the attempt to stop making customers choose.

  • More capable agentic models raise the ceiling on both misuse and autonomous misbehaviour, including fraud, sophisticated cyberattacks and credential theft that is hard to spot without watching traffic for abnormal behaviour.

  • Detecting that kind of activity requires correlation across time and accounts, which requires storing something.

  • Zero data retention removes the storage, and with it the correlation.

  • EFS moves the storage to infrastructure the customer controls, keeping the correlation without handing the data to the vendor.

Who it was built with, and where it runs

EFS was developed with more than 100 customers across financial services, healthcare, manufacturing, telecom, law, retail and the public sector, together with cloud partners AWS, Google Cloud and Microsoft Azure. The feedback came from security, product, compliance and delivery teams, including the Analysis and Resilience Center for Systemic Risk, whose membership includes the chief information security officers of Goldman Sachs, Morgan Stanley, Citi, Bank of America and Wells Fargo, plus Comcast, KPMG, Mastercard, Salesforce and Visa. Anthropic says the conversations spanned a quarter of the Fortune 100 and every US global systemically important bank.

Support is planned across Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google's Agent Platform and Microsoft Foundry. For Australian buyers that surface list matters more than the customer list, because it determines whether the control applies to the deployment you already have rather than one you would have to migrate to.

What to confirm before you treat EFS as a compliance answer

Questions to resolve with your account team before relying on Enterprise Frontier Safeguards
QuestionWhy it matters for an Australian business
Which phase of the rollout are we in?It ships in phases later in 2026, so your start date is not automatic
Which surface is our workload on?Coverage is per surface, and your deployment may not be in the first group
Where is the customer-controlled infrastructure?Data residency questions under the Privacy Act depend on the region, not the vendor
Who reviews a flagged signal internally?Signals go to the customer, so someone has to own triage and response
What happens before EFS reaches us?Eligible customers keep zero data retention on Fable 5 and Fable 5.1 in the interim

What this does not solve

EFS changes where data lives and who reviews alerts. It does not write your AI use policy, decide which records can be put in front of a model, or satisfy an APRA expectation about operational resilience on its own. A control the vendor ships still has to be configured, evidenced and tested inside your own environment before an auditor will accept it as a control you actually operate.

Nor does it remove the internal work of deciding who responds when a signal arrives. Moving review to the customer is the right answer for accountability, and it creates a job somebody has to hold. On client engagements we generally see $20,000 to $40,000 of work in the first year to stand up that capability properly, covering policy, the triage runbook, evidence collection and staff training. That is the number to plan against, and it is the part most businesses forget when they read a security announcement as a finished solution.

If you are still working through the basics of vendor data handling, our note on what zero data retention really means for Australian businesses is the place to start, and CPS 230 and Claude agents for Australian banks covers the supervised end of the market.

The takeaway for regulated Australian teams

Take the announcement to your next risk committee with three things: which surfaces you run on, which rollout phase you are in, and who owns a flagged signal on the day it arrives. That turns an interesting vendor update into a decision your organisation can actually make. Everything else can wait until the phased rollout reaches you.

We do this work with Australian teams in regulated industries. See our consulting services, walk through the security review to signed order form path for Claude Enterprise, or read the original announcement on developing Enterprise Frontier Safeguards.

FAQ

Frequently asked questions

What is Claude Enterprise Frontier Safeguards?

Enterprise Frontier Safeguards is an approach announced in September 2026 that combines zero data retention with misuse detection by keeping data in cloud infrastructure the customer controls rather than Anthropic's own infrastructure.

Does Anthropic train on enterprise data?

Anthropic states it has never trained on enterprise data without explicit permission and never will. The 30-day retention introduced with Fable 5 existed to correlate activity for misuse detection, not for model training.

When will Enterprise Frontier Safeguards be available?

It rolls out to customers in phases beginning later in 2026. Until it reaches them, eligible customers receive zero data retention on Fable 5 and Fable 5.1 so there is no gap in coverage.

Which products will support Enterprise Frontier Safeguards?

Planned support covers Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google's Agent Platform and Microsoft Foundry, so coverage depends on which surface your workload runs on.

Who reviews activity that monitoring flags?

Customers control how data gets reviewed. When automated monitoring detects a pattern needing attention, the signal goes directly to the customer, which means an internal team has to own triage and response.

Why did Claude introduce data retention at all?

Sophisticated misuse can span many tasks across multiple sessions and accounts, so effective detection requires storing data long enough to correlate patterns across time and accounts rather than judging single requests.

Ready to move from AI pilot to production?

We help mid-market Australian businesses deploy AI automations that actually reach production and deliver measurable ROI.