Blog

Compliance API Coverage Extends to Claude Cowork and Claude Code

August 2026 · 6 min read · Technical

Line illustration of a document beside a large terracotta circle containing a tick
← Back to all posts

Anthropic's Compliance API now covers Claude Cowork and Claude Code as well as the chat products. For most small businesses that is a footnote. For anyone selling into financial services, health or government in Australia, it is the difference between answering a vendor questionnaire and losing the deal at the security review.

What a compliance API is for

It gives an organisation programmatic access to its own usage and content records, so governance can be automated rather than performed by screenshot. That matters because manual evidence gathering does not survive contact with a real audit.

  • Retrieving conversation and usage records for retention or investigation

  • Feeding activity into existing monitoring and data-loss-prevention tooling

  • Demonstrating to an assessor what was accessed, by whom and when

  • Enforcing retention and deletion schedules consistently rather than by policy document

Extending that coverage to the developer and agentic products closes the gap that mattered most, because those are precisely the surfaces where the activity is high-volume, automated and hardest to reconstruct after the fact.

Why the agentic surfaces are the harder problem

A chat transcript is relatively easy to account for. An agent that ran overnight, touched four systems and produced a set of changes is a different evidentiary object, and "we think it did the right thing" is not an answer that satisfies anyone.

For APRA-regulated entities operating under CPS 234, or for any business whose client contracts include audit rights, the ability to produce a record of automated activity is not a nice-to-have. It is usually the condition on which the deployment was approved.

Where this changes an Australian sales conversation

Security questionnaires from banks, insurers and government buyers ask consistent questions: what is retained, who can access it, how do you evidence activity, what happens on termination. Being able to answer with a mechanism rather than a policy shortens that process considerably.

We have watched deployments stall for a quarter over exactly this. On a $150,000 engagement, a three-month delay at the security review is not a paperwork problem, it is a cash flow one, and the capability existed all along. What was missing was the ability to demonstrate it programmatically.

It is a capability, not compliance

Access to records does not make an organisation compliant with anything. It provides the raw material for controls that someone still has to design, implement and monitor. The obligations under the Privacy Act and any sector rules remain entirely yours.

The common failure is enabling the capability, ticking the box, and never building the process that uses it. An audit trail nobody reviews is evidence of nothing except that you bought the feature.

What to actually do with it

Route the records into whatever monitoring you already run rather than creating a new silo. The value is in the same team seeing AI activity alongside everything else, using the alerting and retention rules that already exist.

Then define a small number of things you actually want to know: unusual access patterns, activity outside business hours from unexpected accounts, anything touching your most sensitive data stores. Three good alerts beat comprehensive logging that nobody has time to read.

Retention needs a decision, not a default

Longer retention gives you better forensics and a larger liability. Under the Australian Privacy Principles you should not keep personal information longer than you need it, and an archive of AI conversations is squarely within that.

Pick a period tied to a reason: an audit cycle, a contractual obligation, an investigation window. Then enforce it automatically, because retention policies that depend on someone remembering to delete things are not policies.

Who should care, and who genuinely should not

If you are a ten-person consultancy using Claude for drafting and research, this is not your problem this year. The governance overhead would exceed the risk, and the sensible controls are the ordinary ones: who has accounts, what is connected.

It becomes relevant the moment you handle client data under contract, sell into a regulated sector, or run agents unattended against production systems. Those three triggers are worth knowing, because businesses tend to cross them without noticing.

What not to conclude

Extended coverage is not a statement that agentic tools are now safe for any purpose. The risks of unattended automation against production systems are unchanged; what has improved is your ability to see what happened, which is a prerequisite for managing those risks rather than a substitute.

Nor does any vendor capability transfer accountability. If an agent acting on your behalf mishandles client information, the obligation and the reputational damage are yours. Better records make that conversation survivable; they do not make it someone else's.

If a client security review is holding up your AI rollout, book a short call and we will look at what you can evidence today and what needs building.

Ready to move from AI pilot to production?

We help mid-market Australian businesses deploy AI automations that actually reach production and deliver measurable ROI.