anthropic.com web signal

Anthropic's EFS Lets Banks Keep Claude Logs in Their Own Clouds

5 sources tracking this story

TL;DR

  • Anthropic co-developed EFS with more than 100 customers including Goldman Sachs, Morgan Stanley, Citi, BofA, and Wells Fargo before launch.
  • Activity logs route to customer-owned AWS S3, Azure Blob, or GCS under customer encryption keys; Anthropic operates detection logic with no human review of the content.
  • OpenAI launched a parallel Private Safety Processing product the prior month, per The Register, making customer-controlled retention a competitive baseline across frontier labs.

Anthropic today unveiled Enterprise Frontier Safeguards, calling it "a solution that combines the privacy of zero data retention (ZDR) with state-of-the-art safeguards for detecting misuse."

The mechanic: customer activity data used for monitoring "can be stored in the customer's own cloud account (such as Amazon S3, Azure Blob Storage, or Google Cloud Storage)," under keys the customer controls. Anthropic's "automated systems analyze a rolling window of traffic for signals of serious misuse, including attempts to develop offensive cyber or biological capabilities and signs of stolen or leaked credentials." When something trips, "those flags go directly to the customer and their people take it from there – no human review by Anthropic employees is required."

The post is unusually candid about what forced the change: "The enterprises we worked with generally understood the safety and security value of data retention, but many–especially in regulated industries–found it difficult to use models with data retention." Yesterday the Pentagon added ChatGPT Mil and Grok to GenAI.mil and skipped Claude.

The featured customers are banks. "Enterprise Frontier Safeguards gives us exactly what we asked for: our logs stay in a Wells-managed environment under Wells-managed keys," says Munish Kumar Sharma, Chief Information Security Officer at Wells Fargo. Scott DePasquale, President and CEO of ARC, whose members include Goldman Sachs, Morgan Stanley, Citi, Bank of America and Wells Fargo, adds: "Eight of our members worked with Anthropic to define what it would take to run the most capable frontier models inside a systemically important bank."

Rollout is phased, "starting later this fall," across "Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google's Agent Platform, and Microsoft Foundry." Anthropic charges nothing for EFS itself; cloud providers bill for storage, reads, writes and egress. Eligible customers get zero data retention on Claude Fable 5 and 5.1 in the interim.

What others are reporting

Coverage cluster as of 24h after publish

  1. The Register Read →

    Skeptical take: EFS shifts the safety monitoring burden to customers and surfaces OpenAI Private Safety Processing as a prior parallel launch, framing this as competitive catch-up.

    EFS works by storing data in cloud infrastructure controlled by the customer, not Anthropic
  2. Help Net Security Read →

    Explains the procurement blocker: compliance teams could not add Anthropic as a trusted vendor under existing contracts without customer notification and renegotiation.

    Our logs stay in a Wells-managed environment under Wells-managed keys. That split is what lets our teams put frontier models to work safely.
  3. Unite.AI Read →

    Names co-designing institutions including Wells Fargo, Goldman Sachs, and ARCS member banks, showing demand was driven by systemically important firms.

    We keep custody of our data while Anthropic operates the detection.
  4. MarkTechPost Read →

    Places EFS within Claude 5.1 platform updates including 75% cheaper cache reads and reduced cybersecurity false positives, treating data custody as one component of a broader enterprise release.

    Activity data used for monitoring can live in the customer's own cloud account, under their encryption keys, access policies, and audit logging.

Shared on Bluesky by 2 AI experts