Blog

Claude Enterprise Inference Hooks: Inline Data-Loss Prevention for AU Compliance Teams

August 2026 · 4 min read · Technical

Line illustration of a filing cabinet beside a terracotta shield with a checkmark, representing an inline data-loss-prevention check
← Back to all posts

Anthropic has shipped inference hooks for Claude Enterprise, a beta feature that lets a compliance or security team inspect and approve or block every prompt and tool-call response before it reaches Claude, across chat, Claude Code, Claude Cowork, and connected MCP tools, Skills, and plugins.

For Australian businesses already running, or about to run, Claude at the team level, this closes a gap that used to sit on the client side only. Previously, native inline enforcement was limited to Claude Code's local client-side hooks. Now there is one enforcement layer covering every Claude Enterprise surface, without a separate integration per product.

How inference hooks actually work

When an organisation turns inference hooks on, every request routes through a signed WebSocket connection to a security server the business controls. Before Claude starts generating a response, it sends the prompt and surrounding context to that server. The server returns an allow or deny decision, and Claude only proceeds once it has an answer. The same check runs on tool-call responses too, including anything returned through MCP connectors, Skills, or plugins, before it goes back to the model.

That last detail matters more than it first appears. A DLP control that only inspects what a user types misses the half of the risk surface that runs through tool calls: a connector pulling a customer record, a plugin summarising a document, a Skill drafting from internal data. Inference hooks inspects both directions, the prompt going in and the tool-call response coming back, at the same enforcement point.

Why it matters for AU compliance and risk teams

Most mid-market and enterprise AU businesses already run a DLP stack, Netskope, Palo Alto Networks, Proofpoint, Zscaler, or an in-house equivalent, to police where sensitive data can move. Until now, extending that policy to an AI assistant meant either trusting the vendor's own controls or building bespoke integrations per surface. Inference hooks is built on an open, webhook-based protocol with a published schema, so it plugs into the DLP program a business already runs rather than asking it to stand up a parallel one.

That matters most for businesses handling data under the Privacy Act, or in APRA-regulated environments where CPS 230 operational risk obligations put real weight on demonstrable control over where data goes. Being able to point Claude Enterprise traffic at the same inspection point other SaaS tools already report to is a meaningfully easier compliance conversation than simply trusting the model vendor's own controls.

  • Shadow mode logs every decision without blocking anything, letting a team validate policy accuracy before enforcement goes live.

  • Role-based exclusions let specific teams or use cases bypass a rule while the rest of the organisation stays covered.

  • Percentage-based rollouts let a team enforce a new policy on 5% of traffic before trusting it with 100%.

  • Configurable failure-policy tolerance and timeouts decide whether a request is blocked or allowed if the security server itself is unreachable, a detail worth setting deliberately rather than accepting a default.

A worked example

A Sydney-based professional services firm running Claude Enterprise across its advisory team, with an existing Zscaler DLP policy covering email and file-sharing, could point inference hooks at the same Zscaler inspection point, run it in shadow mode for two weeks to see what it would have blocked, adjust the policy, then enforce it with role-based exclusions for the partners who need broader access. That sequence, shadow first, adjust, then enforce, is the difference between a DLP rollout that survives contact with real usage and one that blocks a partner mid-client-call in week one.

Where this fits for AU SMBs and mid-market teams

Inference hooks is currently in beta for Claude Enterprise customers. It is not a Claude Cowork or Claude Pro feature, and it is a global capability rather than an Australian-specific one, meaning no change here to where data is actually processed. For a business already on Claude Enterprise, or evaluating it alongside a DLP renewal, it is worth a conversation before that renewal locks in for another twelve months.

Worth naming plainly what inference hooks does not change too. It is a global capability, and turning it on does not move where Claude's inference itself runs, and it is not a substitute for a specific certification an auditor might ask for by name. What it does provide is a genuine, auditable control point a business can point to when a regulator or a customer's own security team asks how AI-assisted work is monitored for data leaving the organisation's boundary.

The Automata AI take

If you are scoping a Claude Enterprise rollout and want the DLP integration done properly rather than bolted on after the fact, that is a conversation we have regularly with AU businesses moving from pilot to enterprise deployment. Wiring inference hooks into an existing DLP stack, including shadow-mode validation before enforcement, typically runs A$5,000 to A$10,000 depending on how many policies and surfaces are in scope.

Book a 30-minute AI automation brainstorm and we will map inference hooks against the DLP program you already run.

Ready to move from AI pilot to production?

We help mid-market Australian businesses deploy AI automations that actually reach production and deliver measurable ROI.