Claude EFS Keeps Logs in Customer Clouds—Anthropic Still Runs Detection

Anthropic’s September 1 announcement introduced Enterprise Frontier Safeguards, or EFS, for organizations using Claude. The opt-in architecture stores monitoring activity in customer-controlled cloud infrastructure while Anthropic’s automated systems detect serious misuse patterns and send flags to the customer for human review.
EFS is not yet broadly available: deployment is due to begin in phases later in fall 2026, and organizations can currently request access. Axios described the new system on September 2 as a way for Anthropic to monitor enterprise use without having to store the customer data itself, addressing a central privacy objection to provider-held logs.
Monitoring records remain inside the customer’s cloud boundary

EFS changes where retained monitoring activity sits; it does not eliminate the history required for detection. Customers can place that activity in their own Amazon S3, Azure Blob Storage or Google Cloud Storage account, governed by their encryption keys, access policies and audit logging.
The underlying safety problem is that sophisticated abuse may extend across multiple tasks, sessions or accounts. A system that analyzes each interaction separately and immediately discards it can miss those patterns, so EFS maintains a rolling window that automated safeguards can correlate over time.
The duration and configuration options for that rolling window have not been made public. The privacy proposition is therefore based on customer custody and access control, rather than on an absence of retained monitoring records.
Anthropic detects patterns; the customer conducts human review

The architecture separates automated detection from human investigation. Anthropic operates safeguards that analyze the rolling traffic window for signals such as attempts to develop offensive cyber or biological capabilities and indications of stolen or leaked credentials. A pattern requiring attention generates a flag delivered directly to the customer.
Authorized customer personnel then assess whether the flag represents genuine misuse or a false positive and choose any response under their own security and governance procedures. Anthropic employees are not required to perform that human review, an important distinction for organizations whose legal, security or regulated information may be viewed only by specifically cleared staff.
The responsibility split is:
- Store monitoring activity: the customer’s selected cloud account when customer-owned storage is enabled.
- Control encryption and access: the customer through its keys, policies and audit controls.
- Run automated misuse detection: Anthropic’s safeguards.
- Receive the resulting flag: the customer’s designated team.
- Perform human review: authorized customer personnel; Anthropic employee review is not required.
- Choose the operational response: the customer under its own incident procedures.
Customer-owned storage, Customer-Managed Encryption Keys and fully automated review are separate opt-in controls. Enabling them is not intended to alter Claude’s model behavior, API pricing or rate limits, allowing an organization to select the controls that match its technical and regulatory requirements.
EFS resembles zero data retention but still involves provider processing

EFS is designed to deliver privacy protections comparable to zero data retention while preserving cross-session misuse detection. Retained activity can stay in infrastructure controlled by the enterprise, and the enterprise determines which people may inspect it. Anthropic nevertheless remains in the processing path because its automated systems analyze activity and generate the misuse signal.
That distinction matters for contractual and regulatory assessments. Customer-held keys and customer-led investigation reduce the need for provider employees to inspect underlying activity, but they do not mean that no Anthropic-operated system processes the monitoring window.
The public architecture does not fully specify the technical permissions required by the detector, the complete contents delivered with a flag or the available retention settings. Enterprises will need those details to determine whether EFS satisfies their own definitions of data access, residency and processor responsibility.
The safeguards are free, but cloud use remains billable
There is no separate Anthropic charge for EFS. However, ITmedia’s September 2 account notes that customers choosing their own cloud storage remain responsible for provider charges covering storage, reads, writes and data egress; it also describes the monitoring records and subsequent human review as remaining on the customer side.
The controls are planned for Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google’s Agent Platform and Microsoft Foundry. Equivalent controls are intended across Amazon Web Services, Google Cloud and Microsoft Azure, while support for eligible third-party offerings remains under development.
Eligible customers can use Fable 5 and Fable 5.1 with zero data retention until EFS is ready, but that temporary arrangement is not EFS availability. As of September 2, the firm commitments are an access-request process and a phased rollout targeted to begin later in fall 2026; exact launch dates, eligibility criteria, rollout cohorts and retention options remain unspecified.
Also read:
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.