Anthropic launches Enterprise Frontier Safeguards to enable ZDR and abuse detection

Anthropic announced this week Enterprise Frontier Safeguards (EFS), an architecture that aims to provide regulatory teams the ZDR (zero data retention) guarantee they require while providing security teams with the abuse-detection capability that until now has depended on retaining information on the provider’s servers. The design moves monitoring data storage to a cloud environment under the customer’s control, keeps the detection engines at Anthropic, and leaves encryption keys, access controls and human review in the organization’s hands.
Anthropic’s stated reason for never retaining organizational data has never been model training; the company says it has never trained on corporate data without explicit permission, only on detection quality. Starting with Fable 5, a 30-day retention policy was introduced, based on the argument that the most sophisticated attacks Anthropic has identified—including cases of stolen corporate credentials—are spread across many tasks, sessions and accounts. Running an automatic classifier on each interaction and discarding the result immediately cannot capture such patterns; correlation requires a time window.
The architecture was built with input from more than a hundred customers in financial services, health care, manufacturing, telecommunications, legal, retail and the public sector, together with AWS, Google Cloud and Microsoft Azure. Contributors also included the Center for Systemic Risk Analysis and Resilience, whose members comprise the CISO of Goldman Sachs, Morgan Stanley, Citi, Bank of America and Wells Fargo, as well as teams at Comcast, KPMG, Mastercard, Salesforce and Visa. According to Anthropic, the design discussions covered roughly a quarter of the Fortune 100 and every systemically important U.S. bank.
Three core design choices emerged from that process. First, storage shifts to the client: activity data used for monitoring can reside in the organization’s cloud account under its own encryption keys, access policies and audit logs; customers indicated that onboarding an additional trusted data supplier would trigger customer notifications and contract updates, which the architecture avoids. Second, human review moves to the client: when monitoring identifies a pattern worthy of attention, the signal is sent directly to the organization; Anthropic maintains that automated review handles the scanning, but a human still adds value by confirming genuine abuse, clearing false positives, and, in regulated environments, must be authorized to handle privileged legal material, non-public information or drug-safety reports. Third, detection remains with Anthropic: automated systems analyze a rolling window of traffic to spot attempts to develop cyber or offensive-biological capabilities and signs of stolen or forged credentials.
EFS is not yet available for deployment. The rollout is planned in phases with broad availability targeted for the coming autumn, and access will be granted on a request basis. In the meantime, customers can run Claude Fable 5 and Fable 5.1 under ZDR. EFS is one of three organizational eases released alongside Fable 5.1 and Mythos 5.1: the other two are pricing and accuracy. Fable 5.1 cut cache reads by 75% to $0.25 per million tokens, roughly a 25% price drop for typical workloads and up to 45% for agent-heavy loads. Cyber-defense mechanisms now generate about 60% fewer interventions per Claude Code session compared with Fable 5.