Anthropic announced Enterprise Frontier Safeguards on 1 September, alongside the Fable 5.1 launch. Activity data moves into the customer's own Amazon S3, Azure Blob Storage or Google Cloud Storage, under customer-managed encryption keys, access policies and audit logging, across Claude Code, Claude Enterprise, Claude Platform, Amazon Bedrock, Google Agent Platform and Microsoft Foundry.
Who actually designed it
The company says it was built with over 100 customers, described as including a quarter of the Fortune 100 and all US global systemically important banks. The advisory work ran through the Analysis and Resilience Center for Systemic Risk, whose members include the CISOs of Goldman Sachs, Morgan Stanley, Citi, Bank of America and Wells Fargo; Comcast, KPMG, Mastercard, Salesforce and Visa are named among other participants. Wells Fargo's CISO is quoted saying “our logs stay in a Wells-managed environment under Wells-managed keys.”
What the common framing gets wrong
Read as a launch, this is a security product. Read as a sequence, it is a walk-back. Anthropic had removed zero data retention for its most capable tier starting with Fable 5 and imposed a 30-day retention window so it could run cross-session, cross-account misuse detection. Enterprises objected. CNBC's own headline on the same announcement calls it a data-retention policy change made after customer pushback.
Two details that get lost
First, it is not shipped. The rollout is phased and broad availability is only “targeted for later this fall”; until a customer's phase arrives, the interim concession is plain zero data retention on Fable 5 and 5.1, not the product. Second, “free” is doing work. Anthropic bills nothing for the safeguards, but the customer now pays for the storage, the reads and writes, and the egress of their own detection logs. The cost moved; it did not vanish.
A custody split, not a deletion
The architecture is worth stating precisely, because “your data stays with you” implies more than it delivers. Anthropic still runs misuse detection over the same data. It simply no longer holds it. What changed is custody and key control, not whether the vendor inspects your traffic.
