Enterprise Frontier Safeguards: the fix for "we need zero retention, but we also need misuse detection"
In brief
Claude Fable 5 shipped with a 30-day data retention requirement so Anthropic could detect misuse spanning multiple sessions. That locked out every customer whose compliance position depends on zero data retention. On September 1, 2026 Anthropic announced Enterprise Frontier Safeguards, which moves the monitoring data into the customer’s own cloud account under their own keys and sends detections to the customer’s security team instead of Anthropic’s. Here is how it works and what to do about it now.
Contents
Anthropic announced Enterprise Frontier Safeguards (EFS) on September 1, 2026, the same day as Claude Fable 5.1. It resolves a conflict that had been blocking a specific and well-funded set of customers for two months.
The deadlock
Two requirements, both legitimate, that pointed in opposite directions.
Requirement one: zero data retention. A bank, a hospital system, or a defence contractor often cannot let a vendor store its prompts and completions at all. Not for 30 days, not for 24 hours. Zero data retention (ZDR) is frequently the entire basis on which the vendor got approved. It is not a preference; it is the contract.
Requirement two: cross-session misuse detection. The serious misuse patterns Anthropic worries about on its most capable models do not appear inside one conversation. Someone building an offensive cyber capability, or working toward a biological one, spreads the work across many sessions over days. Catching that requires looking at a rolling window of traffic. Looking at a rolling window requires the traffic to exist somewhere.
Claude Fable 5 came down on the second side. It shipped with a mandatory 30-day retention requirement and was not available under ZDR. Fable 5.1 and Mythos 5.1 carry the same requirement.
The result was that the customers with the strongest need for frontier capability — and the biggest budgets — were the ones structurally excluded from the frontier model.
How EFS splits the problem
EFS separates the three things that were previously bundled into "retention."
1. Storage sits with the customer. Activity data used for monitoring lives in the customer's own cloud account — AWS, Google Cloud, or Azure — under the customer's own encryption keys. It never lands on Anthropic's servers. The ZDR promise, as the customer's compliance team understands it, holds.
2. Detection stays with Anthropic. Anthropic's automated systems analyse that rolling window, looking for a deliberately narrow set of things: attempts to build offensive cyber or biological capability, and signs of stolen or leaked credentials. The detection logic is Anthropic's, because that is the part with the threat intelligence behind it. What it is not is general content review.
3. Review sits with the customer. When monitoring flags a pattern worth attention, the signal goes directly to the customer. Human review happens at the enterprise, by the enterprise's own security team. No Anthropic personnel read the flagged content.
Read as an architecture, this is a fairly standard split: the customer holds the data plane, the vendor supplies the detection plane, and escalation routes to the customer's SOC. What is new is a frontier model vendor agreeing to give up the read.
Who this was designed with
Anthropic says design conversations covered more than 100 enterprise customers across financial services, healthcare, and manufacturing, plus major cloud providers and security organisations — including roughly a quarter of the Fortune 100 and every US global systemically important bank.
That list is the point. EFS is not a general privacy feature. It is a specific unlock for regulated buyers who had already said no.
Timing, and what it means for you now
EFS rolls out in phases, with the stated goal of broad availability later in autumn 2026. Access today is request-based.
Which leaves you in one of three positions.
If you are on ZDR and blocked from Fable: until EFS reaches you, eligible customers can use Fable 5 and Fable 5.1 under ZDR policies as an interim arrangement — but that is by arrangement, not by default. The action is a conversation with your account team, this quarter, not next.
If you are on standard retention and never noticed: nothing changes for you, and EFS is not something you need. Do not spend a cycle on it.
If you are mid-procurement on Claude for a regulated function: EFS changes the answer you can give your risk committee, and it is worth putting in the business case now rather than after the phase you land in. See Building a business case for Claude.
What EFS does not do
Worth being precise, because the announcement is easy to over-read.
- It is not a general content firewall. The detection scope is offensive cyber capability, biological capability, and credential compromise. It will not catch an employee pasting a customer list into a prompt. For that you want inference hooks and a real usage policy.
- It does not remove the model's own retention requirement. Fable 5.1 still carries 30-day retention as a model property. EFS changes where the data lives and who reviews it, not whether monitoring happens.
- It is not available yet in general. Phased, request-based, autumn 2026 target. Do not put it in a plan that ships next month.
- It does not reduce your obligations. You now hold the monitoring data in your own account under your own keys. That is the point, and it is also a new thing in your environment to secure, key-rotate, and retain or delete on a schedule you own.
That last one is easy to miss in the relief of getting to yes. The data did not disappear; it moved onto your side of the line. Budget the storage, name the owner, and write the retention rule before the first byte lands.
Try this today — the 30-minute compliance readout
If you are the person who will be asked about this, produce a one-page readout before someone asks. Four lines:
Our current retention posture with Anthropic, stated exactly: ZDR, standard 30-day, or a negotiated term. Get this from the contract, not from memory — this is the line people get wrong.
Which models we are consequently blocked from. As of today that is Fable 5, Fable 5.1, and Mythos 5.1 for ZDR customers. Name the workloads that would use them if unblocked.
The ask. One sentence to your account team: whether you are eligible for the interim ZDR arrangement on Fable now, and which EFS rollout phase you are in.
The cloud account decision. EFS puts monitoring data in your AWS, Google Cloud, or Azure account under your keys. Decide now which account, which region, whose keys, and what the retention rule is. If your answer is "we would have to find out," that is the finding, and it is the thing that will delay you by a month later.
Then put a date on it. EFS lands in phases through autumn 2026, and the customers who get the early phases will be the ones who asked.
Related: Claude Fable 5.1 · Claude Fable 5 · Claude inference hooks · Claude admin: security and privacy · The Compliance API · What to share with Claude