Skip to main content
Anthropic EFS: Secure customer data migration to client-controlled storage, enhancing privacy and control.

Editorial illustration for Anthropic's EFS Moves Customer Data to Client-Controlled Storage

Anthropic's EFS Puts Customer Data Under Client Control

Anthropic's EFS Moves Customer Data to Client-Controlled Storage

4 min read

Anthropic said this week it has built a way around a problem that has stalled enterprise AI contracts for months: the standoff between zero data retention and misuse detection. Banks, hospitals and government agencies typically require vendors to guarantee no prompt or transcript touches their servers. Anthropic's own security team has argued the opposite is needed to catch coordinated abuse, since spotting attacks that unfold across sessions, tasks and accounts, including ones using stolen enterprise credentials, requires holding data long enough to correlate it. A classifier that scans one interaction and deletes it can't see that pattern form.

The new architecture, called Enterprise Frontier Safeguards, tries to split the difference. Monitoring data lives in infrastructure the customer controls, not Anthropic's, while Anthropic's detection systems still run against it. Custody, encryption keys and human review stay on the customer's side of the line.

It's not live yet. Anthropic is rolling EFS out in phases, targeting broad availability this fall, with access granted by request. In the meantime, customers on Claude Fable 5 and Fable 5.1 can operate under standard zero data retention terms while they wait.

EFS stores monitoring data in cloud infrastructure the customer controls, not Anthropic’s. Detection stays with Anthropic. Custody, keys, and human review stay with the customer.

Why this matters

EFS is Anthropic betting that the ZDR-versus-monitoring standoff was a design problem, not a physics problem. Handing storage to the customer's own cloud account, under their keys and audit logs, is a real concession from a vendor that usually wants that telemetry close. For enterprise buyers in finance, healthcare, or defense, this could be the difference between a pilot that dies in procurement and one that ships.

But we'd push back gently on how much this actually decouples Anthropic from sensitive data: cross-session misuse detection still requires some correlation logic, and logic has to run somewhere, on some copy of the data, even briefly. The architecture shifts custody, not necessarily exposure. Worth watching is whether other frontier labs, OpenAI, Google, Meta, follow with their own customer-controlled storage schemes, and whether regulators treat "customer-held, vendor-processed" as materially different from "vendor-held." The next real test is a breach or subpoena involving EFS-stored data, which will tell us whether this boundary holds under pressure or was mostly a procurement talking point.

Common Questions Answered

What problem does Anthropic's EFS solve in enterprise AI contracts?

EFS resolves the standoff between zero data retention requirements and the need for misuse detection that enterprise customers like banks, hospitals, and government agencies require. Previously, vendors needed access to prompts and transcripts to detect coordinated abuse across sessions and accounts, but customers demanded guarantees that no data would touch vendor servers. EFS enables both by storing monitoring data in customer-controlled cloud infrastructure while keeping detection capabilities with Anthropic.

How does EFS distribute custody and control between Anthropic and customers?

Under EFS, monitoring data is stored in cloud infrastructure that the customer controls, not Anthropic's servers, with the customer maintaining custody of encryption keys and audit logs. Anthropic retains responsibility for the detection algorithms and analysis, while customers retain full control over data storage, keys, and human review processes. This division of responsibilities allows enterprises to maintain security compliance while still benefiting from Anthropic's misuse detection capabilities.

Why is cross-session misuse detection important for enterprise AI security?

Cross-session misuse detection is critical because coordinated attacks often unfold across multiple sessions, tasks, and accounts, including those using stolen enterprise credentials. Anthropic's security team argued that spotting these sophisticated, distributed attacks requires access to patterns that span beyond individual interactions. Without this capability, enterprises cannot adequately protect against complex abuse scenarios that traditional single-session monitoring would miss.

What is the significance of EFS for enterprise procurement and deployment?

EFS could be transformative for enterprise buyers in finance, healthcare, and defense sectors by removing a major procurement blocker that has prevented AI pilots from advancing to production. By satisfying both zero-data-retention requirements and misuse detection needs, EFS makes it possible for deals that previously stalled in compliance review to move forward to actual deployment. This represents a meaningful concession from Anthropic in terms of where telemetry is stored and controlled.

LIVE12:36AI Confidence Gap Widens as Startup Spending Details Emerge