LIVE · cybersecurity feed
Live wire
CVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildHackers Are Probing PaperCut Servers, and 47% Still Have No PatchNew Malware Uses Fake CAPTCHAs to Deploy BackdoorCVE-2026-76581 · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCECVE-2026-76639 · Hack One Robot, Reach the Next: Unitree G1 Security FlawsRhysida Ransomware Group Targets Berlin Government Ahead of VoteThe Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn
cloud

Anthropic’s Enterprise Frontier Safeguards lets your Claude logs stay in your cloud

Eight members of the Analysis and Resilience Center for Systemic Risk, a group whose roster includes the CISOs of Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo, spent months working with Anthropic on a question their examiners care about more than benchmark scores. Scott DePasquale, the center’s president and chief executive, said those eight defined “what it would take to

zeroday.news ·

Anthropic has introduced a new security framework called Enterprise Frontier Safeguards, designed to address data retention and privacy concerns for enterprise customers, particularly those in regulated industries. This framework allows organizations to maintain control over their Claude AI activity logs within their own cloud environments, using their own encryption keys and access policies.

The development of Enterprise Frontier Safeguards was influenced by feedback from over 100 customers, including a quarter of the Fortune 100 and all U.S. global systemically important banks, as well as companies like Comcast, KPMG, Mastercard, Salesforce, and Visa. Notably, eight members of the Analysis and Resilience Center for Systemic Risk, which includes CISOs from major financial institutions such as Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo, collaborated with Anthropic on defining the requirements for running advanced frontier models securely within systemically important banks.

A key aspect of the new safeguards is that activity data, used for misuse detection, can reside in the customer's Amazon S3, Azure Blob Storage, or Google Cloud Storage account. This means customers control their encryption keys, access policies, and audit logging. When Anthropic's automated systems flag potential misuse, the alert is sent directly to the customer, and no Anthropic employees review the data.

This approach directly addresses a previous policy change by Anthropic. For its most capable models, starting with Fable 5, Anthropic moved away from "zero data retention" to a 30-day retention window for prompts and responses. The company stated this change was necessary for detecting sophisticated misuse patterns that spread across multiple tasks, sessions, and accounts, which could not be identified by analyzing and immediately discarding individual interactions. While Anthropic maintains it has never trained on enterprise data without explicit permission, the 30-day retention policy posed a significant hurdle for regulated enterprises due to compliance requirements regarding sensitive data storage and customer notifications.

Under Enterprise Frontier Safeguards, automated systems continuously analyze a rolling window of traffic for signals of serious misuse. This includes attempts to develop offensive cyber or biological capabilities and signs of stolen or leaked credentials. Anthropic highlights that credential theft, in particular, is difficult to detect without observing abnormal behavior over time, as individual requests from a stolen key might appear ordinary. The company also noted the risk of AI agents autonomously engaging in destructive behavior.

The customer objection was not to the review process itself, but to who performed the review. Many regulated firms have strict rules about who can access privileged legal material, non-public information, or drug safety reports, and their staff are already cleared and trained for such work. The new framework ensures that human review by Anthropic employees is not part of the loop.

Enterprise Frontier Safeguards will be supported across various Anthropic offerings, including Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google's Agent Platform, and Microsoft Foundry, with consistent controls whether customers purchase directly or through a cloud partner. Customer-owned storage, customer-managed encryption keys, and fully automated review are all opt-in features and do not affect model behavior, API pricing, or rate limits.

The rollout will occur in phases, with broad availability anticipated for later this fall. Eligible customers will receive zero data retention on Fable 5 and Fable 5.1 until the new safeguards are fully implemented for them. Anthropic will not charge for Enterprise Frontier Safeguards; customers will pay their cloud provider for storage, reads, writes, and egress, as they would for any other cloud resource.

cloudfinance
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

nation-state

An AI CAPTCHA solver talked itself out of the right answer

You have probably spent a few seconds of your life turning a picture until it lines up. Some sites, instead of asking you to tick a box, show you a circular chunk of a photo that has been spun around, and you drag it until the inside matches the ring around it. Simple enough. Annoying enough. Two researchers at Bern University of Applied Sciences wrote a script that solves one of those in 0.006 se

malware

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

23-year-old botnet down

malware

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat. The post Counterfeit installers to system

security

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity a