Anthropic moves misuse monitoring into the customer's own cloud bucket
Enterprise Frontier Safeguards pairs zero data retention with automated misuse detection, and stores the monitoring data in the customer's S3, Azure or GCS under their keys. OpenAI answered the same problem differently in August.
No Anthropic employee reads the safety logs. Your team does, and that is the part nobody has staffed yet.
Anthropic announced Enterprise Frontier Safeguards on September 1, 2026. It pairs zero data retention with automated misuse detection. The monitoring data does not stay with Anthropic. It goes to the customer's own Amazon S3, Azure Blob Storage or Google Cloud Storage, encrypted under keys the customer controls. No Anthropic employee reviews it, and flags go to the customer's own teams.
Anthropic says it built EFS with more than 100 customers in financial services, healthcare, law, the public sector and other regulated fields. It costs nothing from Anthropic; the customer pays its cloud provider for storage. It rolls out in phases through fall 2026 across Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Google's Agent Platform and Microsoft Foundry. It replaces the 30-day retention requirement that has applied to Fable 5 and Mythos 5 since June. Until the rollout finishes, the Claude docs still list 30-day retention for Fable 5.1 and Mythos 5.1 unless Anthropic authorizes zero retention.
Two answers to one problem
Both labs face the same conflict. Zero retention means the lab keeps nothing, but catching misuse of a capable model means someone has to look at patterns over time. OpenAI's answer in August, Private Safety Processing, keeps the analysis on OpenAI's side and automates it so staff never see the content. Anthropic's answer moves the data out of its hands: the logs live in the customer's bucket, under the customer's keys.
Sanchit Vir Gogia of Greyhound Research named the catch in CSO Online's coverage: "Custody should not be confused with visibility." Holding the data does not mean anyone reads the alerts, and EFS moves that triage work onto the customer.
Why a build studio cares
For clients we audit, EFS changes a checklist item. The old question about a Claude-backed feature was how long Anthropic keeps the prompts. The new questions are: which bucket holds the monitoring data, who holds the keys, what retention policy that bucket has, and who is on call when a flag fires. A log of flagged prompts is sensitive data in its own right, and it now sits in the client's cloud under the client's residency rules. If nobody owns those alerts, the safeguard exists on paper only.
Next step: read Anthropic's announcement and the CSO Online analysis. If your team has switched on zero retention and nobody has checked where the safety logs go, write to us at hello@gattyworks.com.