Dashboard

Anthropic Enterprise Frontier Safeguards, Explained

Anthropic announced Enterprise Frontier Safeguards on 1 September 2026, a configuration that lets enterprise customers keep a zero data retention agreement while still getting automated misuse detection.

Cecilia Iona
Cecilia Iona
Senior Editor, AI & Product
2 September 20261 min read

Anthropic announced Enterprise Frontier Safeguards on 1 September 2026, a configuration that lets enterprise customers keep a zero data retention agreement while still getting automated misuse detection. The short version: the safety monitoring moves to the customer's own cloud infrastructure, and no Anthropic human ever reads the flagged traffic. If you have ever been told you must choose between "we keep nothing" and "we can spot an attacker", this is a vendor trying to sell you both.

What Anthropic actually announced

The company describes Enterprise Frontier Safeguards as combining zero data retention with state-of-the-art safeguards for detecting misuse. Three details matter more than the framing.

  • Data sits on the customer's cloud, not Anthropic's. The named cloud partners are Amazon Web Services, Google Cloud and Microsoft Azure.

  • Detection is automated only. Anthropic states there is no Anthropic human review required, and when the automated systems flag a pattern the signal goes to the customer's own team to evaluate.

  • Anthropic charges nothing for the feature itself. Customers pay their cloud provider standard storage costs.

Anthropic says it built the feature with more than 100 customers across financial services, healthcare, manufacturing, telecom, law, retail and the public sector, and it names participants including Goldman Sachs, Morgan Stanley, Citi, Bank of America, Wells Fargo, Comcast, KPMG, Mastercard, Salesforce, Visa, Stripe, Snowflake, Cognition and Factory.

The tension it is trying to resolve

Misuse detection has an awkward requirement. To notice that someone is systematically probing for stolen credentials or building an attack over many sessions, a system has to compare traffic across sessions and accounts over a rolling window. That means retaining something. Zero data retention means retaining nothing.

Enterprises in regulated industries have been stuck on exactly that contradiction. The usual outcome is that the security team wins, ZDR gets signed, and the vendor's abuse detection is switched off for that account. Anthropic's answer is to keep the rolling window but put it somewhere the customer already controls, and to route the alerts back to the customer rather than into a vendor review queue.

Whether that satisfies a given regulator is a separate question from whether it satisfies a given security team, and the announcement does not claim otherwise.

Why this matters if you are building on top of AI

Most readers here are not Goldman Sachs. The reason to care is that enterprise procurement terms tend to become the default terms for everyone else about a year later, and this one changes what you can reasonably ask for.

The practical shift is that "zero retention" stops being a single switch and becomes a question with a second half: where does the detection data live, and who reads it. That is a better question, and it is one you can now ask smaller vendors too. If you sell software with an AI feature inside it, expect your own customers to start asking it of you. Our guide on getting an AI product through a client security review covers what those conversations look like from the vendor side.

It also gives a cleaner mental model for the thing most people get wrong about API privacy, which is assuming that "we do not train on your data" and "we do not store your data" are the same statement. They are not, and the gap between them is exactly where retention windows live. If that distinction is new, start with what happens to your prompts after you send them, then read our explainer on what zero data retention actually means.

The part worth reading sceptically

Two caveats sit inside the announcement itself.

First, availability. Anthropic says the rollout happens in phases later this autumn, with eligible customers getting ZDR on Fable 5 and 5.1 in the meantime. Announced is not shipped, and the gap here is measured in months.

Second, the burden moves rather than disappearing. If alerts land with your team instead of the vendor's, your team now owns triage for a class of signal it has never seen before. That is a real operational cost, and a small company should count it before treating this pattern as free. If you have no process for that yet, an AI incident response plan is the prerequisite, not the follow-up.

FAQ

Is Enterprise Frontier Safeguards available now?

No. Anthropic says it rolls out in phases later this autumn. Eligible customers receive zero data retention on Fable 5 and 5.1 until it launches.

Does it cost extra?

Anthropic charges no fee for the feature. Customers pay their own cloud provider's standard storage costs for holding the detection data.

Does anyone at Anthropic read the flagged content?

Per the announcement, no. Detection is automated, and the resulting signals go to the customer, whose own team decides what to do with them.

Does this apply to individual or small-team plans?

Not currently. It is an enterprise configuration built with large regulated customers and delivered through AWS, Google Cloud and Azure. For smaller teams, the relevant lever is still your vendor's standard retention policy and your own chat log retention window.

How did this land?

About the author

Cecilia Iona
Cecilia Iona

Senior Editor, AI & Product

Cecilia leads the Swarmz editorial desk. She has spent a decade turning complex AI and product topics into writing people actually finish, and she owns the blog's quality bar.

Share

Get the next post in your inbox

One email a month. Product updates, engineering posts, and the best of Built with Swarmz.

I agree to receive emails about AI building tips and Swarmz product news. Unsubscribe any time.