Skip to content
Rush Commerce
AI & Automation3 min read

Anthropic EFS: your cloud stores the misuse logs

Anthropic Enterprise Frontier Safeguards keeps zero data retention while running misuse detection on logs held in your own S3, Azure or GCS bucket. Read the tradeoff.

Zero data retention and misuse detection have always pulled against each other: you cannot correlate suspicious activity across sessions if you delete every session. Anthropic Enterprise Frontier Safeguards, announced September 1, resolves that by moving the storage rather than removing it. The logs still exist. They just live in your cloud account instead of Anthropic's.

What actually happened

Anthropic's Enterprise Frontier Safeguards announcement describes EFS as combining zero data retention with misuse detection. The activity data used for that detection is written to cloud infrastructure the customer controls — Amazon S3, Azure Blob Storage or Google Cloud Storage — under the customer's own encryption keys, access policies and audit logging.

Automated systems then analyze a rolling window of that traffic for signals of serious misuse: attempts to develop offensive cyber or biological capabilities, and signs of stolen or leaked credentials. Flags go directly to the customer. Anthropic states that no human review by its employees is required.

The company says it developed EFS with more than 100 customers, including eight major U.S. banks and executives spanning a quarter of the Fortune 100. Anthropic charges nothing for EFS itself; the cloud providers bill for storage and data operations. Rollout is phased, starting later this fall, and eligible customers get zero data retention on Claude Fable 5 and Fable 5.1 in the meantime.

Why it matters for your business

Most small and mid-sized companies will not be in the first EFS cohort. The reason to read it anyway is that it names the shape of a tradeoff you are already making with every AI vendor, usually without looking at it.

Ask your providers the same three questions this announcement answers. Where does the data used for abuse monitoring physically sit? Who can read it — is a human at the vendor ever in the loop, or is detection fully automated with alerts routed to you? And what is the retention window, given that "zero retention" almost never means zero everywhere, it means zero on the inference path with a separate trust-and-safety pipeline running alongside. Most vendor answers to question three are vaguer than they should be.

There is also a cost line hiding in the good news. Logs in your bucket means storage and data-operation charges on your bill, and it means you now own that data for discovery, breach notification and retention policy. That is the right trade for most regulated buyers — you get keys, access control and your own audit trail — but it is a trade, not a free upgrade. If you take a deal like this, decide the lifecycle policy on that bucket before the first object lands in it, not eighteen months later when somebody asks how far back the logs go.

The broader signal: monitoring is becoming a negotiable term in AI contracts rather than a fixed condition of use. Ask for it in writing.

Key takeaways

  • Anthropic announced Enterprise Frontier Safeguards on September 1, pairing zero data retention with misuse detection
  • Activity data used for detection sits in the customer's own S3, Azure Blob or GCS account under their keys and access policies
  • Automated analysis of a rolling traffic window flags offensive cyber or bio capability attempts and leaked credentials; alerts go straight to the customer with no Anthropic human review required
  • Built with 100+ customers including eight major U.S. banks; free from Anthropic, but you pay your cloud provider for storage
  • Phased rollout starts later this fall; eligible customers get ZDR on Fable 5 and 5.1 until then
  • Ask every AI vendor the same three questions: where monitoring data sits, who can read it, and what the real retention window is

"Zero retention" is a claim you should be able to verify, not a checkbox you accept. We audit what your AI vendors actually store, where it lands, and who can read it — then design the data path so the answer is one you can defend. See how we handle AI governance, or send us the vendor terms you have not read closely.

Sources: Anthropic: Developing Enterprise Frontier Safeguards with our customers, Help Net Security.

  • #anthropic
  • #zero-data-retention
  • #ai-governance
  • #compliance
  • #vendor-risk
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.