Developing Enterprise Frontier Safeguards with our customers

Developing Enterprise Frontier Safeguards with our customers

与客户共同开发企业前沿安全防护机制

Sep 1, 2026 2026年9月1日

Today we’re announcing Enterprise Frontier Safeguards (EFS), a solution that combines the privacy of zero data retention (ZDR) with state-of-the-art safeguards for detecting misuse. EFS works by storing data in cloud infrastructure controlled by the customer, not Anthropic. EFS will be rolling out to customers in phases, starting later this fall. To make the transition smooth, eligible customers will receive ZDR on Fable 5 and Fable 5.1 until EFS is ready. 今天,我们宣布推出“企业前沿安全防护”(Enterprise Frontier Safeguards,简称 EFS)。该解决方案将“零数据留存”(ZDR)的隐私性与检测滥用的尖端防护机制相结合。EFS 的工作原理是将数据存储在由客户而非 Anthropic 控制的云基础设施中。EFS 将从今年秋季晚些时候开始分阶段向客户推出。为了确保平稳过渡,符合条件的客户在 EFS 就绪之前,可在 Fable 5 和 Fable 5.1 上继续使用 ZDR。

We developed EFS in close collaboration with more than 100 customers in industries like financial services, healthcare, manufacturing, telecom, law, retail, and the public sector, and with our cloud partners at Amazon Web Services, Google Cloud, and Microsoft Azure. 我们与金融服务、医疗保健、制造、电信、法律、零售和公共部门等行业的 100 多家客户,以及我们的云合作伙伴亚马逊云科技(AWS)、Google Cloud 和 Microsoft Azure 进行了密切合作,共同开发了 EFS。

EFS will be supported on Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google’s Agent Platform, and Microsoft Foundry. EFS 将在 Claude Code、Claude Enterprise、Claude Platform、Amazon Bedrock、AWS 上的 Claude Platform、Google Agent Platform 以及 Microsoft Foundry 上获得支持。

Solving the dilemma of frontier security

解决前沿安全困境

Mythos-class models, like Claude Fable 5.1, represent a major increase in intelligence and agentic capabilities. However, with that increase comes the potential for both misuse and autonomous misbehavior. 像 Claude Fable 5.1 这样的 Mythos 级模型,代表了智能和代理能力的重大提升。然而,这种提升也带来了滥用和自主违规行为的潜在风险。

Over the last few months, we’ve seen substantial evidence of attempted misuse of AI models. These range from typical forms of abuse, such as fraud, to sophisticated cyberattacks, which can include agents autonomously engaging in destructive behavior. Some of these instances involve theft or misappropriation of enterprise customers’ credentials, which are difficult to detect without the ability to monitor traffic and detect abnormal behavior. 在过去几个月中,我们看到了大量试图滥用 AI 模型的证据。这些滥用行为从欺诈等典型形式,到复杂的网络攻击(包括代理自主进行破坏性行为)不等。其中一些案例涉及企业客户凭证的窃取或挪用,如果没有监控流量和检测异常行为的能力,这些行为很难被发现。

Furthermore, because the most sophisticated misuse can involve many tasks spread across multiple sessions and accounts, it is not sufficient to run automated analysis on each interaction separately and then instantaneously discard the data. Effective detection requires storing data for a meaningful period of time so that it can be correlated across time and accounts. 此外,由于最复杂的滥用行为可能涉及跨多个会话和账户的多个任务,仅对每次交互进行单独的自动化分析并立即丢弃数据是远远不够的。有效的检测需要将数据存储一段有意义的时间,以便能够跨时间和账户进行关联分析。

For this reason, we introduced 30-day data retention starting with Fable 5. This policy was not motivated by a desire to train on enterprise data: Anthropic has never trained on enterprise data without explicit permission, and never will. 因此,我们从 Fable 5 开始引入了 30 天的数据留存政策。该政策并非出于利用企业数据进行训练的目的:Anthropic 从未在未经明确许可的情况下使用企业数据进行训练,未来也绝不会这样做。

The enterprises we worked with generally understood the safety and security value of data retention, but many–especially in regulated industries–found it difficult to use models with data retention. We therefore sat down with customers to design a solution that could provide the best of both worlds: the privacy of ZDR and the safety allowed by monitoring across time and accounts. 与我们合作的企业普遍理解数据留存对安全保障的价值,但许多企业(尤其是在受监管行业)发现很难使用带有数据留存的模型。因此,我们与客户共同设计了一种能够兼顾两者的解决方案:既拥有 ZDR 的隐私性,又能通过跨时间和账户的监控实现安全性。

Designed with our customers

与客户共同设计

We built Enterprise Frontier Safeguards with feedback from the experts who will use it every day: security, product, compliance, and delivery teams. One of the groups we worked with was the Analysis and Resilience Center for Systemic Risk (ARC), whose members include the chief information security officers of the largest US banks, including Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo. We also worked with leaders at companies such as Comcast, KPMG, Mastercard, Salesforce, and Visa, to make sure the design held up across industries. Our conversations spanned a quarter of the Fortune 100, every US global systemically important bank, and virtually every regulated industry. 我们在构建 EFS 时参考了每天使用该系统的专家(包括安全、产品、合规和交付团队)的反馈。我们合作的团体之一是系统性风险分析与韧性中心(ARC),其成员包括高盛、摩根士丹利、花旗、美国银行和富国银行等美国大型银行的首席信息安全官。我们还与康卡斯特(Comcast)、毕马威(KPMG)、万事达卡(Mastercard)、Salesforce 和 Visa 等公司的领导者合作,以确保该设计适用于各行各业。我们的对话涵盖了四分之一的财富 100 强企业、美国所有全球系统重要性银行,以及几乎每一个受监管的行业。

Here is what we heard from this wide range of customers, and what we built into EFS to address these common concerns: 以下是我们从这些广泛的客户群体中听到的反馈,以及我们为解决这些共同关切而在 EFS 中构建的功能:

On monitoring 关于监控 Enterprises have long applied monitoring for insider risk, and now want help upleveling monitoring for agents. Their concerns were about Anthropic’s automated monitoring systems meeting their regulatory standards. 企业长期以来一直应用监控来防范内部风险,现在希望在提升代理监控方面获得帮助。他们担心 Anthropic 的自动化监控系统是否符合其监管标准。

With EFS, customers control how data gets reviewed. When monitoring detects a pattern that needs attention, those signals are sent directly to customers so they can review what the automated systems detected. 通过 EFS,客户可以控制数据的审查方式。当监控检测到需要关注的模式时,这些信号会直接发送给客户,以便他们审查自动化系统检测到的内容。

On data storage 关于数据存储 It’s a lot of work for enterprises to add another “trusted data vendor” for a number of reasons. They need to notify all of their customers who these vendors are and update contracts. They also have internal requirements for safely storing and auditing data, given its high level of sensitivity. Because of these concerns, we architected EFS so that customers have the ability to store data on their existing cloud infrastructure. 由于多种原因,企业增加一个新的“受信任数据供应商”需要大量工作。他们需要通知所有客户这些供应商是谁并更新合同。鉴于数据的敏感性,他们对数据的安全存储和审计也有内部要求。考虑到这些顾虑,我们对 EFS 进行了架构设计,使客户能够将数据存储在他们现有的云基础设施上。

In EFS, customers can control their data storage and management. Customers want the ability to have their data live in infrastructure they control, under their own encryption keys, access policies, and audit logging. Activity data used for monitoring can be stored in the customer’s own cloud account (such as Amazon S3, Azure Blob Storage, or Google Cloud Storage). 在 EFS 中,客户可以控制自己的数据存储和管理。客户希望数据能够存储在他们控制的基础设施中,并使用他们自己的加密密钥、访问策略和审计日志。用于监控的活动数据可以存储在客户自己的云账户中(例如 Amazon S3、Azure Blob Storage 或 Google Cloud Storage)。

On automated and human review 关于自动化与人工审查 Even as automated review is becoming more effective, a person looking at a flag still adds value by confirming real misuse and clearing false positives. But what we heard from many customers, especially those in regulated industries, is that the person doing that review needs to be one of their own. Many operate under rules that tightly govern who may see certain information—privileged legal material, non-public information, drug-safety reports. Their teams are already trained and cleared for that work. 尽管自动化审查正变得越来越有效,但人工查看标记仍然具有价值,可以确认真实的滥用行为并清除误报。但我们从许多客户(尤其是受监管行业)那里了解到,进行审查的人员必须是他们自己的员工。许多企业在严格的规则下运营,规定了谁可以查看特定信息——例如特权法律材料、非公开信息、药物安全报告等。他们的团队已经接受过相关培训并获得了处理这些工作的授权。

EFS has automated safety monitoring, no Anthropic human review required. Customers want protection against cyberattacks, and appreciate that these can be difficult to detect if they unfold across many sessions and accounts. With EFS, automated systems analyze a rolling window of traffic for signals of serious misuse, including attempts to develop offensive cyber or biological capabilities and signs of stolen or leaked credentials. Those flags go directly to the customer and their people take it from there – no human review by Anthropic employees is required. EFS 具备自动化安全监控功能,无需 Anthropic 进行人工审查。客户希望获得针对网络攻击的保护,并意识到如果攻击跨越多个会话和账户,将很难被发现。通过 EFS,自动化系统会分析滚动流量窗口,以寻找严重滥用的信号,包括试图开发攻击性网络或生物能力的行为,以及凭证被盗或泄露的迹象。这些标记会直接发送给客户,由他们的人员进行后续处理——无需 Anthropic 员工进行任何人工审查。