Anthropic hands data control back to enterprise customers — what Enterprise Frontier Safeguards means for regulated software builds
Anthropic announced Enterprise Frontier Safeguards on 1 September 2026, replacing its data retention policy after pushback from regulated-industry customers by storing AI misuse-monitoring data in the customer's own cloud infrastructure instead of Anthropic's, rolling out free across Claude Code, Claude Enterprise, Bedrock and Microsoft Foundry from this autumn.
6 September 2026
Anthropic announced Enterprise Frontier Safeguards (EFS) on 1 September 2026, developed with more than 100 customers across financial services, healthcare, manufacturing, telecom, law, retail and the public sector — including security leaders from Goldman Sachs, Morgan Stanley, Citi, Bank of America and Wells Fargo. The change replaces a data retention policy that had drawn real pushback from business customers, particularly in regulated industries where “a vendor holds monitoring data on our activity” is a much harder sell than it is for a consumer chatbot.
The mechanism is straightforward: EFS keeps Anthropic’s misuse-detection running, but the activity data that detection relies on now lives in cloud infrastructure the customer controls, not Anthropic’s. Custody, encryption keys and human review sit with the customer; automated detection stays with Anthropic. It works whether a business accesses Claude directly or through a cloud provider, and it’s rolling out free, in phases, across Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock and Microsoft Foundry starting this autumn.
Why this is a commissioning question, not just a compliance one
For any organisation in healthcare, finance or another regulated sector, “where does the AI vendor’s monitoring data actually sit” has been a genuine blocker to adopting AI-assisted development tools at all, not just a checkbox on a procurement form. A security or compliance team that can’t answer that question confidently tends to default to blocking the tool outright, which in practice means the engineering team either works without AI assistance or uses it informally, off the record — neither of which is a good outcome. EFS is Anthropic responding directly to that blocker rather than asking regulated customers to accept it as the cost of using frontier AI tooling.
So what
If your organisation has held back from AI-assisted development because of data control concerns, this is a concrete reason to revisit that position once EFS rolls out to whatever platform you’re using — the practical objection it was built to answer is likely to be your organisation’s own. For NHS and other healthcare software work specifically, where data governance is non-negotiable and often the single biggest factor in tool selection, this kind of customer-controlled monitoring model is what makes it realistic to build AI-assisted workflows into a compliant delivery process rather than working around one. See our healthcare software development work or get in touch to talk through what a compliant AI-assisted build looks like for a regulated project.