Anthropic Will Keep Your Claude Logs in Your Own Cloud
Enterprise Frontier Safeguards pairs zero data retention with cross-session misuse detection by moving the logs to the customer's own S3, Azure Blob, or GCS — under the customer's keys. It's free, phased, and you have to apply.
Anthropic announced Enterprise Frontier Safeguards on September 2 — a rework of how enterprise customer data is stored, monitored, and retained. Two weeks earlier, OpenAI previewed Private Safety Processing to solve the same problem in a completely different way.
The problem: enterprises want zero data retention, safety requires seeing patterns across sessions, and those two requirements have historically been mutually exclusive.
Anthropic's answer is architectural rather than cryptographic. Instead of trying to detect misuse in data it does not keep, Anthropic keeps the data — in the customer's cloud, under the customer's keys.
How it works
Under EFS, enterprise conversation logs land in the customer's own storage: Amazon S3, Azure Blob Storage, or Google Cloud Storage, encrypted with the customer's keys and governed by the customer's access policies. Automated safety monitoring still runs against that data and still evaluates behavior across multiple sessions. What goes away is human review by Anthropic employees.
Anthropic developed it with more than 100 customers across financial services, healthcare, manufacturing, telecom, law, retail, and the public sector, and with AWS, Google Cloud, and Microsoft Azure. Rollout is phased, with broader availability targeted for later this fall. Eligible customers get zero data retention on Fable 5 and Fable 5.1 during the transition. Anthropic says it will not charge for it.
This is a direct reversal of Anthropic's previous position, and it is worth saying so plainly. Two weeks ago the competitive framing in the trade press was that OpenAI was previewing zero-retention safety while Anthropic required data logs for comparable enterprise arrangements. Anthropic has now removed that as a procurement objection without abandoning the safety capability the logging requirement existed to support.
Two solutions, two different bets
The contrast with OpenAI's approach is genuinely instructive, because both labs accepted the same constraint and refused to compromise on the same axis — and still ended up somewhere entirely different.
OpenAI's Private Safety Processing keeps the data nowhere. It derives signals from each request, retains the signals rather than the content, and evaluates accumulated signals for cross-session patterns. The privacy guarantee is mathematical: the content genuinely does not persist. The open question is whether the retained representations are abstract enough to be safe and rich enough to be useful — a tension OpenAI has committed to addressing in a technical white paper.
Anthropic's EFS keeps the data everywhere it always was, and moves the perimeter. The content persists in full. The guarantee is that it persists somewhere Anthropic does not control, cannot read without the customer's keys, and cannot be compelled to produce — because Anthropic does not have it.
The trade is clean. OpenAI asks you to trust a mechanism you cannot yet inspect. Anthropic asks you to trust a boundary you can audit yourself, and hands you an operational burden in exchange.
For a regulated buyer, the second is frequently the easier sell. A bank's security team knows how to reason about "our data, our bucket, our KMS key, our retention policy." It does not know how to reason about "non-reversible derived signals." One of those survives a compliance review with a diagram; the other needs a cryptographer.
The burden nobody should skip past
Anthropic's own framing includes a caveat that deserves more attention than it will get: enterprises do not receive zero data retention automatically. They must apply, and they are responsible for verifying the arrangement works as described.
That second clause quietly relocates a meaningful amount of assurance work onto the customer. Under a vendor-side retention policy, the vendor is accountable for the guarantee and can be audited against it. Under EFS, the customer owns the bucket — which means the customer owns the misconfiguration.
Cloud storage misconfiguration is not a hypothetical failure mode. It is the single most reliably exploited category of enterprise data exposure of the last decade. Handing an organization full custody of its AI conversation logs is a genuine privacy win only if that organization's storage hygiene is better than Anthropic's, and for a large number of companies it demonstrably is not.
There is also an interesting audit-trail consequence. If the logs live in the customer's account, the customer can delete them. That is the point — but it also means the forensic record of an incident is under the control of the party most likely to be investigated for it. Anthropic's monitoring still runs, so the safety function survives. The evidentiary function is more complicated.
Free is a strategy
Anthropic will not charge for EFS, and that is not generosity.
Enterprise AI procurement is currently decided in security reviews, not capability bake-offs. Nearly every large deal runs through a question about who can read the prompts, and until this month Anthropic's answer was worse than OpenAI's. Pricing EFS at zero removes the objection entirely rather than converting it into a line item a procurement team can argue about.
It also raises the floor for everyone else. Once two frontier labs offer zero retention with cross-session safety monitoring at no additional cost, "we retain your data for safety purposes" stops being an industry norm and starts being a competitive deficiency.
What to watch
Whether the phased rollout reaches customers who are not in the design partner cohort. A hundred co-development customers is a strong start and a small number. Fall is the stated target for broader availability.
Whether either lab publishes a detection result. Both architectures claim to catch distributed misuse that per-request classifiers miss. Neither has published a case where it did. The first published catch — from either approach — will tell you far more than the design documents.
Whether the customer-custody model produces its first breach. It will eventually, and the response to it will determine whether "your logs, your bucket" reads as a privacy feature or as liability transfer with better marketing.
Two labs have now shipped incompatible answers to the same question within a fortnight. Enterprise buyers get to pick which trade they prefer, which is a better position than they were in a month ago.
