Security1 distinct publisher3 min readPublished
Eight bank CISOs asked who holds the keys and who is ever allowed to look. Anthropic's answer keeps misuse-detection data in the buyer's own storage account, which also makes triaging frontier-model abuse the buyer's payroll problem.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Automated systems scan a rolling window of traffic for a narrow set of signals: attempts to develop offensive cyber or biological capability, and indications of stolen or leaked credentials [9]. Anthropic does not publish how long that window runs [9]. The retention policy bounds it regardless. Data lives 30 days [6], so correlation across sessions and accounts cannot reach back further than 30 days [1]. An operator who spaces activity across a longer interval sits outside the horizon by construction. That alert window is the part worth pricing.
Anthropic says it has seen misuse involving stolen or misappropriated enterprise credentials, and that a stolen key produces requests that look ordinary one at a time, so the pattern only appears when traffic is watched over time [10]. That credential-misuse case is what explains the design. The company separately points to agents autonomously engaging in destructive behavior, which is a different failure mode from a human abusing the tool [11].
The flag goes to the customer and stops there, with no Anthropic employee in the review loop [5]. Firms whose staff are already cleared to handle privileged legal material, non-public information and drug safety reports objected to the identity of the reviewer [13]. Those same staff are now the reviewer, and that means whoever gets the signal owns the work that follows: triage, escalation and disposition of false positives against a frontier model's traffic land on rotas that were built for endpoint and identity alerts.
On the numbers behind the launch: Anthropic says it worked with more than 100 customers on the design, spanning a quarter of the Fortune 100 and every US global systemically important bank, plus Comcast, KPMG, Mastercard, Salesforce and Visa [14]. A quarter of the Fortune 100 is 25 firms, so at most a quarter of that 100-plus design cohort were Fortune 100 buyers [2]. Help Net Security notes this is design feedback from a self-selected group of large buyers rather than a survey of the market [15]. Wells Fargo CISO Munish Kumar Sharma described the arrangement as keeping custody of the data while Anthropic operates the detection [16].
Anthropic argues that discarding each interaction immediately misses misuse that spreads across many tasks, sessions and accounts [7], and it says correlation requires storing data "for a meaningful period of time" without arguing that 30 days is the number the math demands [8]. That is a gap in the justification worth marking. The company also says it has never trained on enterprise data without explicit permission [18].
Nothing here is an exploit, and no vulnerability was disclosed. What moved is custody of a control point, in response to a procurement blocker: regulated buyers understood the detection argument and still could not deploy, because adding Anthropic as another trusted data vendor meant notifying their own customers, reworking contracts and clearing internal rules on storing sensitive material [12]. Scott DePasquale, who runs the Analysis and Resilience Center for Systemic Risk, framed the working group's question as who holds the data, who holds the keys, what automated review can and cannot see, and under what conditions a human is ever permitted to look [2]. Support is planned across Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS and Google's Agent Platform [17].
Ranked by verification strength, evidence, and original report placement.
Eight members of the Analysis and Resilience Center for Systemic Risk, a group whose roster includes the CISOs of Goldman Sachs, Morgan Stanley, Citi, Bank of America and Wells Fargo, spent months working with Anthropic on the design.
Scott DePasquale, the center's president and chief executive, said the eight defined "what it would take to run the most capable frontier models inside a systemically important bank: who holds the data, who holds the keys, what automated review can and cannot see, and under what conditions a human is ever permitted to look."
Anthropic announced the product, called Enterprise Frontier Safeguards, on Tuesday.
Activity data used for misuse detection can live in the customer's Amazon S3, Azure Blob Storage or Google Cloud Storage account, under the customer's encryption keys, access policies and audit logging.
When automated systems flag something, the signal goes to the customer and nobody at Anthropic reads it; human review by Anthropic employees is not part of the loop.
Anthropic dropped zero data retention for its most capable tier starting with Fable 5 and moved to a 30-day retention window.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
leadership
Anthropic moves misuse monitoring into cloud storage its customers control1 distinct publisher
build
Fable 5.1 binds each thinking block to the exact bytes of the prefix that produced it1 distinct publisher
leadership
Anthropic cuts Fable 5.1 prices by 25% and launches two-tier safeguard system with Mythos 5.11 distinct publisher
leadership
A Government Switched Off Two Frontier Models. Your Board Will Want The Fallback Plan.1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One trade write-up of one vendor announcement
Follow any specific here — the customer-held keys, the 30-day window, the promise that no Anthropic employee reads a flag — and it terminates at Anthropic's announcement as relayed by Help Net Security. The two outside voices, Wells Fargo's CISO and the systemic-risk center's chief executive, helped design what they are describing, so they corroborate intent rather than behavior. The design is documented in enough detail to plan against; none of it has been tested by anyone without a stake in it.
A design cohort and a calendar
What exists today is consultation plus a ship date. More than 100 customers contributed to the design, every US global systemically important bank among them, but contributing is not running: the controls are opt-in, the rollout is phased, and broad availability is aimed at later this fall. One firm attaches its name to the arrangement, and Wells Fargo's CISO describes what the split gives the bank, not what the detection has caught.
Vendor framing slightly outruns the disclosure
Anthropic argues that catching cross-account misuse requires holding data 'for a meaningful period of time,' then lands on 30 days without showing why 30; it says a rolling window is analyzed without saying how long the window is, which is exactly the figure someone spacing out activity would want. Help Net Security marks both silences and adds the one the release skips — if no Anthropic employee reads a flag, the person working the queue at 2 a.m. is on the buyer's payroll. Marked gaps are smaller gaps, which is why this sits close to aligned rather than far above it.
Everyone quoted helped build it
The unlock is commercial before it is technical. Zero data retention was the term regulated buyers could not get, its absence stalled their contracts, and these safeguards exist to un-stall them: Anthropic charges nothing and hands the storage, reads, writes and egress to the customer's cloud provider, so the hyperscalers get metered revenue and Anthropic gets the seats. The bank CISOs and the industry consortium speaking on the record are co-authors of the design, not assessors of it, and Wells Fargo's endorsement is of a specification it helped write.
Clear on the design, blind on the behavior
The mechanics are firm enough to act on: where the logs sit, who is billed, which surfaces are planned, when availability broadens. Everything about whether the arrangement performs is unresolved — one outlet, one announcement day, no look inside the detection pipeline, no examiner saying customer-held logs satisfy them, and a correlation window whose length is known only to be at most 30 days. Treat the plumbing as reliable and the assurances as pending.