Get a demo — 30 minutes →
← Back to blog
Anomity robot illustrating Anthropic Enterprise Frontier Safeguards - Customer-Held Misuse Monitoring
Company

Anthropic Enterprise Frontier Safeguards - Customer-Held Misuse Monitoring

TL;DR
  • On 1 September 2026, Anthropic announced Enterprise Frontier Safeguards (EFS): misuse-monitoring activity data stays in the customer's cloud (S3 / Blob / GCS) under customer-managed keys, with Anthropic automated detection and customer-held human review.
  • EFS aims to combine ZDR-like privacy with the retention window needed to correlate misuse across sessions and accounts - without requiring Anthropic employees to review content.
  • Rollout is phased later fall 2026; interim ZDR on Fable 5 / 5.1 for eligible customers until EFS is ready.
  • Surfaces: Claude Code, Claude Enterprise, Claude Platform, Amazon Bedrock, Google Agent Platform, Microsoft Foundry - developed with 100+ enterprises and cloud partners.
  • EFS is provider-side misuse monitoring. It does not inventory agents, MCPs, or browser extensions on endpoints, and it does not enforce PreToolUse allow/deny. Anomity remains the complementary control plane for that layer. Distinct from Anomity's place in the Anthropic Cyber Verification Program.

On 1 September 2026, Anthropic announced Enterprise Frontier Safeguards (EFS) - a design meant to give regulated enterprises ZDR-like privacy while still running automated misuse detection across a meaningful retention window. Activity data can live in the customer's cloud under customer keys; flags go to the customer for human review. No Anthropic employee review is required. EFS shipped alongside Claude Fable 5.1 and Mythos 5.1, whose safeguard tiers and automatic model fallback we cover in Claude Fable 5.1 and Mythos 5.1.

What Anthropic shipped as a design

Anthropic framed a dilemma: serious misuse can span sessions and accounts, so instantaneous discard fights detection, while classic retention fights regulated-industry comfort. EFS splits the difference. Monitoring data can sit in Amazon S3, Azure Blob Storage, or Google Cloud Storage in the customer's account. Automated systems scan a rolling window for signals such as offensive cyber or biological capability development and stolen-credential patterns. Alerts route to the customer's own reviewers.

Supported surfaces named in the announcement include Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Google's Agent Platform, and Microsoft Foundry. Anthropic said the design was developed with more than 100 customers across industries and with AWS, Google Cloud, and Microsoft Azure. Interim ZDR on Fable 5 and 5.1 covers eligible customers until phased EFS availability later in fall 2026. Anthropic stated it does not charge for EFS; cloud storage costs remain the customer's.

What EFS is not

EFS is not the Anthropic Cyber Verification Program. CVP lifts dual-use cyber safeguard blocks for verified security organizations. EFS is about custody of monitoring data and who reviews misuse flags for frontier enterprise deployments. It is also not a substitute for Anthropic enterprise managed MCP connectors and IdP governance, which address a different control plane.

Most importantly for Agentic AI Security buyers: provider-side misuse monitoring does not inventory the endpoint. It will not tell you which MCP HTTP listeners, browser AI extensions, or Cursor CLI builds exist on developer machines. It will not return allow / deny / log at a Claude Code PreToolUse hook before a local tool call runs. Those gaps are why defense-in-depth still needs endpoint collectors and runtime governance - the same split we argued after Anthropic cyber-eval escapes and in Claude security scan-time versus runtime governance.

How Anomity complements customer-held provider monitoring

Anomity's three collectors - Endpoint Sensor, Browser Sensor, and cloud discovery (Google Workspace / GitHub OAuth grants) - inventory agents, MCPs, extensions, plugins, skills, secrets, hooks, CLIs, and local LLM runtimes. Runtime governance enforces allow, deny, or log before unsafe tool calls run. Decisions land in a 90-day audit trail to SIEM, Slack, email, or Jira. Metadata only; secrets redacted on-endpoint. SOC 2 Type II. Complements Network, EDR, DLP, GRC - and now, provider EFS-style monitoring.

Use EFS when you need frontier Claude with customer-held monitoring custody. Use Anomity when you need to see and govern the agents already on the fleet. To walk both layers with us, book a 30-minute demo.

Frequently asked questions

What is Enterprise Frontier Safeguards?

EFS is Anthropic's announced architecture for frontier-model misuse monitoring where activity data used for detection can live in the customer's own cloud account under customer keys, access policies, and audit logs. Automated systems flag serious misuse patterns; those flags go to the customer for human review. Anthropic human review is not required.

How is EFS different from the Cyber Verification Program?

CVP verifies cybersecurity organizations so dual-use defensive prompts are less likely to be blocked by real-time cyber safeguards on Opus/Sonnet. EFS is about where monitoring data lives and who reviews misuse flags for enterprise frontier deployments. Anomity's CVP approval is unrelated to whether a customer enables EFS.

When does EFS ship?

Anthropic stated a phased rollout starting later in fall 2026. Eligible Fable 5 and 5.1 customers receive temporary ZDR until EFS is ready. Customer-owned storage, CMEK, and fully automated review are each described as opt-in.

Does EFS replace endpoint agent governance?

No. EFS monitors provider-side activity patterns for misuse of Claude in supported enterprise surfaces. It does not discover which MCP servers, browser AI extensions, or coding agents run on laptops, and it does not return allow/deny/log at an agent tool hook before a local call runs. Those remain endpoint and runtime-governance problems.

How does Anomity complement EFS?

Anomity inventories agents, MCPs, extensions, plugins, skills, secrets, hooks, CLIs, and local LLM runtimes on the endpoint; Browser Sensor and cloud OAuth discovery cover adjacent surfaces; runtime governance enforces allow/deny/log at hooks such as Claude Code PreToolUse. That sits beside provider misuse monitoring, not inside it.

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok