← all news

Anthropic's enterprise safeguards watch for misuse without reading your data

AI · · · source (anthropic.com)

Anthropic introduced Enterprise Frontier Safeguards, aimed at a real tension for regulated companies: they want frontier models watched for dangerous misuse, but they cannot hand their prompts and outputs to a vendor for human review. The design answers that by keeping the data on the customer's side. Activity logs land in the customer's own cloud storage, an S3, Azure Blob, or Google Cloud Storage bucket they control, under their own encryption keys and access policies. Anthropic staff do not read flagged content.

The monitoring runs as automated analysis over rolling windows of traffic, looking for a narrow set of serious signals: attempts to build offensive cyber or biological capabilities, and indicators of stolen credentials. When something matches, the pattern is routed to the customer's own security team for human review rather than to Anthropic. The controls are meant to work the same way across Claude Code, Claude Enterprise, the Claude platform, and third-party hosts including Amazon Bedrock, Google's agent platform, and Microsoft Foundry. Anthropic says it built the system with more than 100 enterprise customers across finance, healthcare, law, and the public sector, and that it charges nothing for the safeguards themselves, though customers pay their cloud provider for the storage. The phased rollout began this fall.

Why it matters

If you run Claude in a regulated environment, this is the difference between a policy promise and an architecture you can audit. Your security team, not Anthropic, sees the flags and holds the keys, which is the specific thing compliance reviewers ask about. Check whether the misuse categories and your cloud provider match your setup before you rely on it.

AnthropicSecurityEnterprise