Enterprise Frontier Safeguards (EFS), announced by Anthropic on September 1, 2026, pairs zero data retention (ZDR) with automated misuse detection by storing the monitoring data in cloud infrastructure the customer controls — Amazon S3, Azure Blob Storage, or Google Cloud Storage — under the customer's own encryption keys, access policies, and audit logging. Anthropic says flags go to the customer's own cleared team, with no Anthropic human review required. For a bank, RIA, insurer, or law firm, that settles the two questions that stalled most Claude pilots, and raises a third: if the vendor keeps nothing, your firm is the only party holding the record. Books-and-records and supervision rules do not care that the model forgot. The compliance project moves from the vendor questionnaire to your own archiving and supervision stack.
Five of the largest US banks just helped Anthropic build a Claude deployment where the vendor keeps nothing. Zero data retention on their side does not mean zero retention obligation on yours.
The first sentence is the news: on September 1, 2026, Anthropic announced Enterprise Frontier Safeguards, and the two objections that killed most regulated-firm AI pilots now have vendor-side answers. The second is what your compliance committee will need explained, because nothing in it changes what your firm owes its regulators.
Anthropic describes EFS as combining the privacy of zero data retention with state-of-the-art safeguards for detecting misuse. The mechanism is the news: instead of Anthropic holding activity data in order to analyze it, the data lives in cloud infrastructure the customer controls.
| Element | What Anthropic states |
|---|---|
| Announced | September 1, 2026 |
| Where monitoring data lives | The customer's own cloud account (Amazon S3, Azure Blob Storage, Google Cloud Storage), under the customer's encryption keys, access policies, and audit logging |
| What the monitoring looks for | Automated systems analyze a rolling window of traffic for signals of serious misuse, including attempts to develop offensive cyber or biological capabilities and signs of stolen or leaked credentials |
| Who reviews a flag | The customer. Anthropic states EFS has automated safety monitoring, with no Anthropic human review required |
| Where it is supported | Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google's Agent Platform, and Microsoft Foundry |
| What is opt-in | Customer-owned storage, Customer-Managed Encryption Keys, and fully automated review are each opt-in; Anthropic says none change model behavior, API pricing, or rate limits |
| Price | Anthropic says it does not charge for EFS; a customer's cloud provider bills storage, reads, writes, and egress as it would any other resource |
| Timing | Phased rollout, with the goal of broad availability later this fall; eligible customers get ZDR on Fable 5 and Fable 5.1 in the meantime |
Anthropic also explains why retention existed. It says it introduced 30-day retention with Fable 5 because the most sophisticated misuse spans many tasks across multiple sessions and accounts, and cannot be caught if each interaction is analyzed and then instantly discarded. Effective detection requires correlating data across time and accounts. Anthropic is explicit that this was never about training: it says it has never trained on enterprise data without permission and never will. Regulated customers understood the logic and still could not live with retention.
Anthropic says it built EFS with more than 100 customers across financial services, healthcare, manufacturing, telecom, law, retail, and the public sector. It names the Analysis and Resilience Center for Systemic Risk (ARC), whose members include the chief information security officers of the largest US banks — Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo — along with leaders at Comcast, KPMG, Mastercard, Salesforce, and Visa, and says the conversations spanned a quarter of the Fortune 100 and every US global systemically important bank. These are Anthropic's stated collaborators, not independently verified deployments.
Anyone who has sat through a vendor review for an AI tool at a regulated firm knows the two questions that end the meeting.
Where do the prompts go? Every prompt is potentially material non-public information, privileged material, client personal data, or an unredacted account number. When the answer was "to the vendor, retained for thirty days," most firms stopped there. Anthropic's answer now: the monitoring data sits in your cloud account, encrypted with your keys, governed by your access policies, written to your audit log. Anthropic says this responded to a specific complaint: adding a trusted data vendor means customer notifications, contract updates, and new internal storage and audit requirements.
Who at the vendor can read them? Harder, because a reviewer at a model provider is a person outside your control looking at material your own rules may restrict to cleared staff. Anthropic says regulated customers told it the reviewer has to be one of their own, since many operate under rules governing who may see privileged legal material, non-public information, or drug-safety reports. EFS answers with automated safety monitoring and no Anthropic human review required.
Together, those are the unlock. Your cloud, your keys, your audit log, no human review at the vendor is a sentence a CISO can take to a risk committee.
Here is the mirror image, which the announcement does not address because it is not Anthropic's job to.
If the vendor retains nothing, your firm becomes the only party holding the record. That is a feature for confidentiality and a liability for recordkeeping. Books-and-records and supervision rules attach to the firm and to the communication, not to the tool that produced it. An advisor who drafts a client email in Claude has produced a client communication. A relationship manager who asks a model to rewrite a recommendation has created content that will be judged later against what the firm was required to capture, supervise, and retain.
None of that changes because the model provider deleted its copy. If anything it sharpens: under EFS, if it is not in your archive, it does not exist. The vendor forgetting is not the firm being excused.
There is a subtler version. EFS creates a new artifact: automated misuse flags delivered to your team. A flag that arrives, is reviewed, and is cleared is a supervisory event. If nobody has decided who receives it, how fast it must be triaged, and where the disposition is written down, the firm has a stream of discoverable security signals with no supervisory record attached — worse than not having the signals at all.
For two years, the AI compliance project at most regulated firms has been vendor due diligence: questionnaires, data-processing terms, subprocessor lists, retention schedules, and an argument about training. For Claude, that is largely finished. Anthropic answered it in architecture rather than policy language. What replaces it is an internal build.
| Question | Who owned it before | Who owns it under EFS |
|---|---|---|
| Where activity data is stored | The model provider, described in a contract | Your cloud team, in an account you provision and govern |
| Who holds the encryption keys | The model provider | Your key-management function, with your rotation and access policy |
| Who sees a misuse flag first | The provider's trust and safety staff | Your cleared security or compliance reviewers |
| How a flag becomes a supervisory record | Not defined; the flag rarely reached you | Your workflow, your case system, your retention schedule |
| Whether AI-drafted client communications are captured | Ambiguous; sometimes assumed to sit with the vendor | Unambiguously your archiving and supervision stack |
| How long any of it is kept | The provider's retention setting | Your records schedule, applied to your own storage |
Read that table as a staffing question, not a technology one. Every row on the right names a function that must exist, have an owner, and produce evidence. Most firms already have those functions for email, chat, and phone. Few have connected them to a model that drafts text in a browser tab. The gap between archiving email and archiving the AI-assisted work that becomes email is where the next examination finding lives.
An assumption is buried in EFS: that you can provision and govern your own cloud storage, manage your own encryption keys, and staff a review workflow for flags. A global bank has all three. A mid-market RIA, community bank, regional insurer, or specialty lender often has none, and a bespoke cloud footprint is not a trade most will make for an AI tool.
Those firms reach the same posture through a platform they already run and already govern. That is what the "within the Salesforce Trust Boundary" framing of the Claudeforce partnership between Salesforce and Anthropic was really about: the controls, data residency, audit trail, and retention schedule belong to the platform, and the firm inherits them instead of building them. We covered the mechanics in our breakdown of what the trust boundary means for regulated firms.
This is not enterprise-good, mid-market-compromise. It is a question of where your controls already live. If your client data, communications, case management, and audit trail already sit in Salesforce Financial Services Cloud, putting the model inside that boundary means one control environment instead of two and one place a regulator has to look. Both paths end in the same place: the record is yours, held where your controls are.
Vantage Point is an official Claude partner and a Claude Partner Network Member, and we implement Salesforce and HubSpot for firms that have to answer to somebody. The model question and the records question are the same question, and they get answered in your CRM, your archive, and your supervision workflow rather than in a vendor contract. We help teams map which AI-assisted communications are records, design the compliance and security controls that capture and supervise them, and build the Salesforce data foundation that keeps it inside one boundary a regulator can inspect. Senior consultants only — no junior handoffs; the experts you meet are the experts who deliver.
Vantage Point designs the Salesforce data foundation, archiving, and supervision workflows that let regulated firms adopt frontier AI without opening a new books-and-records gap. Talk to an AI compliance architect.
No. Zero data retention describes what the model provider keeps, not what your firm must keep. Books-and-records and supervision obligations attach to the firm and to the communication, so a client email drafted with Claude is still a client communication you have to capture, supervise, and retain. A vendor that retains nothing makes your own archive the single source of truth.
EFS is a Claude deployment option Anthropic announced on September 1, 2026 that combines zero data retention with automated misuse detection. Anthropic says the monitoring data is stored in cloud infrastructure the customer controls, such as Amazon S3 or Azure Blob Storage, under the customer's own encryption keys, access policies, and audit logging.
Anthropic states that it does not charge for EFS, and that customer-owned storage, Customer-Managed Encryption Keys, and fully automated review are each opt-in and change neither model behavior, API pricing, nor rate limits. If you store data in your own cloud account, your cloud provider bills storage, reads, writes, and egress like any other resource.
Anthropic says EFS rolls out in phases, with the goal of broad availability later this fall, and that eligible customers receive zero data retention on Claude Fable 5 and Fable 5.1 until EFS is ready for them. Treat the fall timing as a stated goal, not a committed date.
Your team does. Anthropic states that EFS uses automated safety monitoring with no Anthropic human review required, and that flags go directly to the customer so their own people can take it from there. Your firm needs a named function to receive flags and a documented way to disposition them.
To use EFS as Anthropic describes it, yes: it assumes you can provision and govern cloud storage, manage encryption keys, and staff a review workflow. Firms that will never run a bespoke cloud footprint can reach a comparable posture inside a platform whose controls they already inherit — the point of running Claude within the Salesforce trust boundary.
Vantage Point is a boutique CRM consulting firm helping businesses transform with Salesforce, HubSpot, and AI — 150+ clients, 400+ engagements, and a 4.71/5 average engagement rating. More at vantagepoint.io.