All field notes

Enterprise Frontier Safeguards

Anthropic Separates Safety Detection From Telemetry Custody

Enterprise Frontier Safeguards proposes a cross-cloud division of responsibility: Anthropic supplies automated safety detection while customers retain telemetry, keys, logs and human review.

MP
Max PerfiljevFounder & CEO, AES · Architect of Autonomous Organizations
Read in Russian

Anthropic announced Enterprise Frontier Safeguards (EFS) on September 1, 2026. The planned capability is designed for enterprises using covered frontier models that want both strong privacy properties and monitoring that can correlate activity across sessions and accounts. Its architectural significance is more specific than “zero retention” or “better safety”: EFS separates automated detection from custody of the data being inspected, and from the human judgment applied to a resulting signal.

Under the announced model, customers can keep activity data in their own cloud accounts, governed by customer-managed encryption keys, access policies and audit logging. Anthropic’s automated systems analyze a rolling traffic window for serious misuse signals, which Anthropic says can include offensive cyber or biological activity and potentially stolen or leaked credentials. Detected signals go to the customer for review. Anthropic says EFS does not require review by its employees.

That division is the material change. A specialist control provider can perform detection over organizational activity without becoming the custodian of the underlying telemetry or the final adjudicator of what a detection means. AWS has separately confirmed the intended operating model for its environment: prompts and outputs would remain in the customer’s AWS account under customer-controlled keys, policies and logging, while automated safety review operates without required human review by Anthropic.

What changed—and what did not

EFS introduces a proposed cross-cloud operating pattern for particular frontier-model deployments. Anthropic says it will support Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google’s Agent Platform and Microsoft Foundry. It also says the design was developed with more than 100 enterprise customers and with AWS, Google Cloud and Microsoft Azure.

It is not broadly available. Anthropic plans a phased rollout beginning later in fall 2026, with broader availability targeted later that season. Nor is EFS a declaration that monitoring disappears. Its monitoring depends on a rolling window of activity. The relevant question is where that evidence resides, who controls access to it, and who is permitted to interpret a signal as a consequential organizational finding.

The announced controls are also not one indivisible default. Customer-owned storage, customer-managed encryption keys and fully automated review are described as separate opt-in controls. Enterprises will need to establish which configuration is actually active for each deployment, rather than infer the strongest custody posture from the product name.

Finally, EFS is not a complete governance runtime, and the announcement does not establish detection efficacy or guarantee prevention of misuse, credential compromise or autonomous misbehavior. It describes a detection-and-review mechanism. The organization still needs policy, authority boundaries, escalation routes, evidence handling and decisions about what follows a reviewed signal.

Four roles that should not collapse into one

Autonomous organizations need to distinguish at least four roles that are often bundled together in AI deployments: observability, evidence custody, automated detection and human adjudication. EFS makes that separation unusually visible.

  • Observability produces the activity record required to understand what occurred across sessions, accounts and systems.
  • Evidence custody determines where that record lives, which encryption keys protect it, which access rules apply, and which audit trail can establish its handling.
  • Automated detection evaluates activity for defined patterns or signals at machine speed.
  • Human adjudication decides whether a signal is meaningful in context and what, if anything, the organization should do next.

Combining these roles in one external service can be operationally convenient, but it concentrates power. The party that observes may hold the record; the party that holds the record may set practical access conditions; and the party that detects may acquire de facto influence over the response. That may be acceptable in a bounded service arrangement. It is a poor default for an organization that must preserve its own accountability across clouds, teams and model providers.

EFS does not remove Anthropic from the control path: Anthropic supplies the automated detection capability. But its stated model narrows the provider’s role relative to a design in which the provider stores all telemetry and sends it to its own human reviewers. This is an important distinction. A detection engine can be specialized and external while the evidentiary record, the access boundary and the final organizational judgment remain internal.

The operating consequence: safety signals need a governed handoff

For an autonomous organization, a flag is not yet a decision. It is an event entering a governance process. The organization must be able to establish what was detected, over which activity window, under which applicable policy, and which authorized person or process reviewed it. It must then determine whether the appropriate outcome is to close the signal, gather additional evidence, restrict a capability, suspend a workflow, or escalate to a defined incident process.

That requires more than customer-controlled storage. Customer custody gives the organization a basis for retaining and auditing the evidence. It does not by itself define the semantic contract of the alert, the authority to inspect sensitive content, the retention period, or the action authority attached to a confirmed finding. These must be explicit organizational controls.

The clean architecture is therefore not “the model provider governs the organization” and not “the customer operates without specialist safeguards.” It is a governed handoff. The specialized detector emits a bounded signal. The organization receives that signal into its own evidence and decision environment. Its policies determine who may access the relevant record, who may assess it, what independent corroboration is needed, and which operational powers can be exercised as a result.

Detection should be portable across clouds. Custody and adjudication should remain accountable to the organization that bears the consequences.

Questions to settle before adopting the pattern

Enterprises considering EFS should treat its opt-in controls as an architecture review, not as a privacy checkbox. The first task is to map the actual evidence route: where activity is written, what the rolling window contains, which identities can read it, which keys and policies apply, and what logs prove access and review. This is especially important when the same organization uses multiple supported surfaces and clouds.

  1. Choose the custody configuration deliberately. Confirm whether customer-owned storage and customer-managed keys are enabled for the relevant deployment, and document any exceptions.
  2. Define the alert contract. Specify what information a detected signal delivers to the customer, how it is correlated to organizational identities and work, and how the signal is retained and audited.
  3. Separate review authority from response authority. A reviewer may validate a signal without automatically holding authority to suspend an agent, revoke access or initiate an external notification.
  4. Set an escalation path before the first flag. Serious-signal review cannot depend on an improvised inbox or an unnamed on-call person.
  5. Preserve provider accountability without surrendering organizational accountability. Record detector versions, configurations and relevant system outputs alongside the organization’s review and response decisions.

The deeper lesson is that privacy and safety monitoring are not mutually exclusive only when telemetry has a defensible custody model. A rolling monitoring window can support automated detection without requiring the organization to outsource the record of its own activity or the judgment over its own response.

Anthropic’s announcement is still a rollout plan, not evidence that this model has become standard practice or that it solves enterprise governance. But it identifies a direction worth demanding from safety infrastructure: controls should be able to inspect a governed runtime while the organization retains control of its evidence, its access boundaries and its consequential decisions.

BUILD WITH AES

Turn architecture into an operating company.

AES connects strategy, tasks, organizational memory, knowledge, agents, people and approvals in one execution environment.