Anthropic today launched Enterprise Frontier Safeguards, a system that allows companies to store activity logs from Claude in their own cloud accounts—Amazon S3, Azure Blob Storage, or Google Cloud Storage—under encryption keys they control. The AI company co-developed the feature with more than 100 customers, including Goldman Sachs, Morgan Stanley, Citigroup, Bank of America, and Wells Fargo, before releasing it publicly on September 1, 2026. Anthropic describes the product as "a solution that combines the privacy of zero data retention with state-of-the-art safeguards for detecting misuse."

Under the new system, customer activity data used for monitoring resides in the customer's own cloud infrastructure under their encryption keys, access policies, and audit logging. Anthropic's automated systems scan a rolling window of traffic for signs of serious misuse—including attempts to build offensive cyber or biological capabilities and indicators of stolen or leaked credentials. When a flag is triggered, those alerts route directly to the customer, and their internal teams handle the response with no human review by Anthropic staff required. The company charges nothing for Enterprise Frontier Safeguards itself; cloud providers bill customers separately for storage, reads, writes, and data egress. Rollout begins later this fall across Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google's Agent Platform, and Microsoft Foundry, with eligible customers receiving zero data retention on Claude Fable 5 and 5.1 in the meantime.

"Enterprise Frontier Safeguards gives us exactly what we asked for: our logs stay in a Wells-managed environment under Wells-managed keys," said Munish Kumar Sharma, Chief Information Security Officer at Wells Fargo. Scott DePasquale, President and CEO of ARC—whose members include Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo—added that "eight of our members worked with Anthropic to define what it would take to run the most capable frontier models inside a systemically important bank." The report notes that Anthropic was unusually candid about what forced the change: "The enterprises we worked with generally understood the safety and security value of data retention, but many—especially in regulated industries—found it difficult to use models with data retention."

The move addresses a procurement obstacle that had blocked highly regulated firms from adopting Claude: compliance teams couldn't add Anthropic as a trusted vendor under existing contracts without customer notification and renegotiation. By storing logs in infrastructure the customer owns, the split lets banks maintain custody of their data while Anthropic operates the detection logic remotely. OpenAI launched a parallel product called Private Safety Processing the prior month, making customer-controlled retention a competitive baseline across frontier labs. The day before Anthropic's announcement, the Pentagon added ChatGPT Mil and Grok to GenAI.mil but skipped Claude, underscoring the strategic cost of not meeting data residency requirements in regulated sectors.

Enterprise Frontier Safeguards sits within a broader Claude 5.1 platform update that includes 75% cheaper cache reads and reduced cybersecurity false positives, treating data custody as one component of a wider enterprise release. For banks and other systemically important institutions, the feature resolves a tension between deploying the most capable frontier models and satisfying internal risk frameworks that prohibit sending sensitive activity logs to third-party vendors. The phased rollout later this fall will determine whether customer-owned storage becomes table stakes for AI vendors competing in finance, defense, and other heavily regulated verticals. Compliance architecture is no longer a back-office afterthought—it's now the gatekeeper that decides which AI models get through the door. The question isn't whether frontier labs will converge on customer-controlled retention, but how quickly laggards will lose access to the most lucrative enterprise contracts.