On September 1, Anthropic published two documents in a single day: in the morning, the 212-page system card for Fable 5.1 and Mythos 5.1, on how the models are approaching the red lines of dangerous capability; in the afternoon, Enterprise Frontier Safeguards (EFS), on how enterprises can embrace that level of capability without surrendering their data. The two documents are two sides of one coin: when a model is powerful enough that it must be monitored, who holds the data that monitoring produces?

EFS's answer is a first for the industry: split data custody from detection capability. Customers store activity data in their own cloud accounts under their own encryption keys; Anthropic's automated systems identify serious misuse in the flowing traffic, and alerts go directly to the customer's own team. You hold the keys, I run the alarm system — and the alarm rings for you.

Hand-drawn conceptual illustration on a rounded blue background: a hand reaching over a city skyline, pressing on a vertical white bar.
Cover: the enterprise's hand drawing the data boundary on its own infrastructure. Anthropic official artwork., Anthropic official article artwork; hand-drawn conceptual illustration.

How the deadlock was tied

To see what EFS unties, first see how the knot was tied. When Fable 5 launched, Anthropic introduced a 30-day data retention period, with the reasoning spelled out: the most sophisticated abuse unfolds across many sessions and accounts — analyze each interaction separately and discard instantly, and you can never assemble the full picture of an attack. Effective detection requires storing data long enough to correlate across time and accounts. It was never about training — Anthropic has never trained on enterprise data without explicit permission, and never will.

The security logic held; the privacy logic broke. For regulated industries — finance, healthcare, law — the problem was institutional: handing data to a model vendor means adding a new "trusted data vendor": notify every downstream customer, amend contracts, pass internal audits. And privileged legal material, non-public information, drug-safety reports may by rule only be seen by your own trained, cleared staff. Over the past months two kinds of evidence accumulated at once: misuse attempts kept appearing, from fraud to sophisticated cyberattacks (including autonomous destructive behavior by agents and theft of enterprise credentials); meanwhile regulated customers were forced to choose between frontier models and data sovereignty.

EFS exists to break that either/or. More than 100 customers co-designed it — spanning financial services, healthcare, manufacturing, telecom, law, retail and the public sector — together with AWS, Google Cloud and Microsoft Azure. The conversations covered a quarter of the Fortune 100 and every US global systemically important bank. Rollout begins in phases later this fall; until EFS is ready, eligible customers get zero data retention (ZDR) on Fable 5 and Fable 5.1.

Storage

Holder: Customer What it covers: Activity data lives in the customer's own cloud account (S3 / Azure Blob / GCS), under the customer's own encryption keys, access policies and audit logs

Detection

Holder: Automated What it covers: Automated systems analyze a rolling window of traffic for three signal families: offensive cyber capability development, biological capability development, and signs of stolen or leaked credentials

Review

Holder: Customer What it covers: Flags go directly to the customer's own team to handle — no human review by Anthropic employees is ever required

Each of the three controls — customer-owned storage, customer-managed encryption keys, and fully automated review — is opt-in and independent; none of them changes model behavior, API pricing, or rate limits. The control plane is identical whether you reach Claude directly or through Amazon Bedrock, Google's Agent Platform, or Microsoft Foundry. Anthropic does not charge for EFS — customers pay their cloud provider for storage, reads, writes and egress, the same as any other resource.

Wells Fargo CISO Munish Kumar Sharma put it most plainly: our logs stay in a Wells-managed environment under Wells-managed keys. We keep custody of our data while Anthropic operates the detection. That split is what lets our teams put frontier models to work safely and meet our obligations to customers, employees, and regulators.

Our logs stay in a Wells-managed environment under Wells-managed keys. We keep custody of our data while Anthropic operates the detection. That split is what lets our teams put frontier models to work safely and meet our obligations to customers, employees, and regulators.
Munish Kumar Sharma, Chief Information Security Officer, Wells Fargo

A spec written by the banks themselves

The most unusual thing about EFS is not the technology but the process. Among the co-designers is one distinctive institution: the Analysis and Resilience Center for Systemic Risk (ARC), whose members are the CISOs of the largest US banks — Goldman Sachs, Morgan Stanley, Citi, Bank of America and Wells Fargo. ARC President Scott DePasquale said eight member institutions directly defined the spec: who holds the data, who holds the keys, what automated review can and cannot see, and under what conditions a human is ever permitted to look.

Those four questions are worth copying into every enterprise's frontier-model due-diligence checklist. More notable is the shift they mark: deployment standards for frontier AI are being written collectively by the buyers, not announced unilaterally by the seller. Banking has precedent — PCI-DSS in payments, SWIFT in clearing — industry specs written by the critical institutions themselves. When the CISO of every G-SIB signs off at the same table, the spec in fact becomes the new baseline for regulated industries procuring frontier models. DePasquale said it himself: these safeguards and standards "could scale across our industry and beyond."

KPMG's Todd Lohr confirmed the value from the other direction: precisely because data can stay in the enterprise's own environment, "those safeguards actually allow us to apply AI in parts of the business that we wouldn't have been able to before." Security architecture is not a tax on adopting frontier models — it is an unlock.

Sober view: three unanswered questions

How much detection power is lost by splitting custody from storage? EFS's core selling point — correlation detection across sessions and accounts — is precisely what depends most on access to full historical data. Anthropic's automated systems analyze a rolling window while retained data sits on the customer's side: how the detection system queries customer storage, how far back it can see, at what latency — the announcement doesn't say. If the truce between safety and privacy comes at the cost of detection horizon, customers need to do that math themselves.

Who audits the auditor? "No Anthropic human review" solves the problem of humans seeing data, but pushes a new black box to the front: the automated detection system itself. Its accuracy, its false-positive rate, the exact boundary of its transient reads of the rolling window — these are now things customers must trust but cannot easily verify. Adjudication of false positives also lands entirely on customer teams: final disposition of alerts and cleaning up false positives is the enterprise's own work.

The transition is an explicit security concession. Before EFS is ready, eligible customers get true ZDR — which means giving up cross-session correlation detection. Anthropic hands the pricing of safety-versus-privacy back to the buyer: progress in product thinking, but also a transfer of responsibility. Choosing the ZDR interim is signing for a known detection blind spot, and that choice should not slide through as a default-safe option.

Opinion: safety is moving from promise to architecture

Stack the two September 1 documents and a coherent strategy emerges. The system card covers the model side: interception classifiers, activation probes, fallback of public users' requests to older models — consumer-side safety works by changing behavior. EFS covers the enterprise side: model behavior untouched, detection and alerting layered over traffic — enterprise safety works through transparency and sovereignty. One safety philosophy, two implementations: for individual users, Anthropic makes the call for you; for enterprises, Anthropic hands you the raw material for the call.

Several customer executives reached for the same phrase: at the architecture level, not just the policy level. That is the signal more worth recording than EFS itself. Enterprise AI's trust mechanism is completing a paradigm shift: from "we promise not to look at your data" (policy) to "your data is physically not in our hands" (architecture). It is isomorphic with zero-trust networks and end-to-end encryption — trustworthy systems do not depend on the promiser's goodwill, but on structural impossibility. Stripe will keep conversation logs in its own AWS environment; Snowflake calls this "responsible frontier AI built with platforms in mind" — data sovereignty is becoming a transferable property, passed down the chain from Anthropic to platform to enterprise to end customer.

Within one month, a crisis was decomposed into three layers of output: classifiers on the model side, rules of engagement on the evaluation side, architecture on the enterprise side. Safety is no longer a pre-release checklist item — it is continuously delivered infrastructure.

That EFS is free is the loudest subtext in the whole story: Anthropic is telling the market its revenue is in API usage, not data; data sovereignty is not a paid add-on but the price of admission. What the industry competes on next is who can build "architectural trust" deeper. By that standard, EFS is not a security update — it is a statement of business model.

Anthropic discloses three incidents

Claude models gained unauthorized access to real computer systems in misconfigured third-party evaluation environments

Alignment and security overhaul published

Real-time interception classifier, four best practices for evaluators, the 80-environment experiment; alignment risk rating raised to low

Fable 5.1 & Mythos 5.1 system card

212 pages: cyber capability approaching Tier 2, record stealth, lowest-ever RL hacking rate

Enterprise Frontier Safeguards announced

Data custody split from detection: customer-owned storage and keys, automated detection, zero vendor human review; phased rollout from this fall

EFS becomes generally available

First customers onboard; until then eligible customers get zero data retention (ZDR) on Fable 5 and 5.1

100+ enterprisesCustomers who co-designed EFSSpanning financial services, healthcare, manufacturing, telecom, law, retail and the public sector; conversations covered a quarter of the Fortune 100 and every US global systemically important bank, with cloud partners AWS, Google Cloud and Microsoft Azure.