AI Agent Cloud Governance: Anthropic’s Privacy Beta

AI agent cloud governance graphic illustrating customer-governed cloud data buckets alongside a transparent policy check, ethical guardrails, and resource audit status screen.

What Anthropic actually announced

On September 1, Anthropic put out a post titled “Developing Enterprise Frontier Safeguards with our customers.” Long name. Real idea underneath it, though. The company is rebuilding how it handles enterprise data for Claude, and for the first time, customers get to keep monitoring data in their own cloud account instead of Anthropic’s.

They’re calling it Enterprise Frontier Safeguards, or EFS if you want the acronym everyone’s already using. And it’s a genuinely different approach to AI agent cloud governance than what existed a month ago. Worth understanding, even if, and I’ll get to this, you shouldn’t be rushing to sign up yet.

AI agent cloud governance has mostly meant one thing for the past year or two: figuring out how to stop an AI agent from doing something it shouldn’t inside your own environment. Anthropic’s announcement flips part of that question around. It’s asking where the AI vendor’s own monitoring data lives, and who controls it. That’s a newer, less discussed piece of the same puzzle.

The three controls, and what they promise

Three pieces, each one opt-in on its own. That matters because it means a firm doesn’t have to take the whole package to get some of the benefit.

  • First, customer-owned storage. Activity data used for misuse monitoring can live in your own Amazon S3, Azure Blob Storage, or Google Cloud Storage account, not Anthropic’s.
  • Second, customer-managed encryption keys, so you hold the keys, not the vendor.
  • Third, fully automated review, meaning flags from Anthropic’s monitoring systems route straight to your own security team. No Anthropic employee looks at your data unless something requires it by law.

 

That third piece is the one I think most law firms will care about first. Under the old setup, Anthropic could review flagged content itself. Under EFS, that job stays inside your firm, with people who are already cleared to see privileged material.

Coverage spans Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, and Microsoft Foundry, among others. Whichever cloud you’re already on, the controls are supposed to work the same way. None of the three, per Anthropic, change model behavior, pricing, or rate limits. You’re not paying more for privacy, at least not to Anthropic. Your cloud provider still bills you normally for storage and egress.

Why this matters more for law firms than most industries

Every industry cares about data control. Law firms have a sharper version of the problem, because the data in question is often privileged, and privilege doesn’t tolerate ambiguity about who touched what.

Anthropic’s own announcement quotes a Chief Legal Officer from a professional services firm saying this reflects “an unwavering commitment to client confidentiality.” That’s the pitch. And it’s a real one. If your firm’s Claude usage today involves any confidential client work, the question of who can see the underlying monitoring data, and where it physically sits, isn’t a minor technical detail. It’s the kind of thing that shows up in an outside counsel guideline or a malpractice inquiry.

 

We’ve written before about what a defensible AI agent governance program needs to include for a firm handling privileged work, and data location and access control sit right at the center of that. EFS is Anthropic trying to answer part of that question at the vendor level, which is new, and honestly overdue.

AI agent cloud governance beyond just Anthropic

It’s worth zooming out for a second, because Anthropic isn’t operating in a vacuum here. Microsoft, Google, and a handful of smaller vendors have all been circling the same problem this year: agentic AI tools that touch sensitive data, running on infrastructure the customer doesn’t fully control. AI agent cloud governance, as a category, is becoming a real procurement question, not just a security team’s side project.

What makes EFS notable is that it’s the first attempt from a frontier model lab, specifically, to put customer-controlled storage and customer-led review at the center of the offer, rather than bolting it on as an enterprise add-on years later. Whether that becomes the industry norm or stays an Anthropic-specific feature is genuinely an open question right now.

The word nobody's saying loud enough: BETA

Here’s where I want to slow down, because most of the coverage this week skipped past it. This is not a shipped feature. It’s not something you can turn on in your Claude console tomorrow morning.

Anthropic’s own page says EFS “will be rolling out to customers in phases, with the goal of making it broadly available later this fall.” Access right now runs through a request form, not a settings toggle. There’s no published configuration guide. No API reference for the customer-storage piece. No walkthrough for setting up the S3 bucket policies or the key management on your end. None of that exists publicly yet, because the program hasn’t opened widely.

I’d call this a beta in every sense that matters, even though Anthropic doesn’t use that word in the announcement itself. A hundred-plus companies helped shape it, real banks, real law firms, real security teams. That’s a legitimate design process. It’s also, by definition, not the same as a mature, documented, generally available product. The Register’s own coverage put it plainly: customers will still need to verify the zero-retention promise held on their end, which is a very reasonable thing to say about a program still finding its footing.

What's still missing from the picture

A few things I’d flag directly, so nobody on your team assumes more maturity than exists right now.

 

  • There’s no public technical spec for how the customer-cloud storage integration actually works under the hood. IAM role structure, what exactly gets written to your bucket and how often, whether there’s a retention window even inside your own storage. Unknown, as of this writing.
  • There’s no pricing detail beyond “your cloud provider bills you normally.” Fine as far as it goes, but firms evaluating cost against the old Zero Data Retention arrangement don’t have enough to build a real comparison yet.
  • And there’s no word on audit or compliance certifications specific to EFS itself. SOC 2, ISO 42001 alignment, anything like that. Anthropic’s broader trust center exists, but nothing EFS-specific has been published.

 

None of this means the idea is bad. It means the idea is early. Those are different things, and worth keeping separate when someone on your leadership team asks, “should we sign up.”

Old ZDR versus the new model, briefly

Anthropic already had a Zero Data Retention option before this announcement, available to qualified accounts on a case-by-case basis, mostly for the API and Claude Code. That program still exists, and eligible customers get ZDR on Fable 5 and Fable 5.1 automatically while they wait for EFS to become available to them.

The difference is scope. ZDR was narrower, and it didn’t give customers control over where monitoring data lived, because under ZDR there generally wasn’t ongoing monitoring data to control. EFS trades pure zero retention for retained-but-customer-controlled data, paired with automated misuse detection your own team reviews. Different tradeoffs, aimed at firms that want both privacy and the security value of pattern detection across sessions.

 

If your firm currently has a DLP strategy built around consumer AI tools, this is worth reading alongside our piece on why local DLP won’t protect agents like Claude and Copilot on its own. Vendor-side controls like EFS and firm-side DLP aren’t substitutes for each other. You need both.

What to do while you wait

I don’t think firms should wait passively for EFS to arrive, though. There’s real work to do in the meantime, and most of it doesn’t depend on Anthropic finishing the rollout.

Start by mapping exactly which Claude products your firm uses today, and under what data terms. Not what you think the terms are. What they say, in writing, right now.

Then decide who at your firm will own the EFS relationship if it becomes available, security, compliance, or IT, because that ownership question tends to get skipped until the day access actually opens up.

Build the habit of asking any AI vendor, not just Anthropic, the same three questions: where does our data physically live, who can access the monitoring layer, and what happens if that changes without much notice. That habit is worth more long term than any single vendor’s feature. We laid out a broader version of this thinking in our post on AI risk mitigation for law firms, and the questions there apply just as well to a beta program as they do to a mature one.

 

If you’re the one who ends up fielding the “should we request access” question internally, a short list is more useful than a long one. Ask what happens to your data during the months between requesting access and actually getting it. Ask whether your cloud team has the bandwidth to own bucket policies and key rotation once EFS does arrive, because someone will need to. And ask your vendor management process to flag EFS for a second look once Anthropic publishes real technical documentation, rather than treating today’s announcement as the final word on AI agent cloud governance for Claude.

Where to start

Anthropic deserves some credit here. Building this with more than a hundred customers, including some of the most heavily regulated banks in the country, is a real signal they’re trying to solve the right problem. But “trying to solve it” and “having solved it” are different sentences, and I think firms should hold both truths at once rather than picking one.

Read the full Anthropic announcement directly rather than relying on secondhand summaries, this one included. And if you want the skeptic’s take before you request access, The Register’s coverage is worth five minutes, it’s the most direct piece written so far about the gap between the promise and the proof.

Not sure your firm’s current AI setup would survive a client’s confidentiality questions today?

Cocha Technology’s Zero Trust Assessment gives you a clear picture of where your data actually lives, who can reach it, and what a defensible AI vendor posture looks like before you commit to any new program, beta or otherwise. Reach out to get started.

Recent Posts

Have Any Question?

Call or email Cocha.  We can help with your cybersecurity needs!

About the Author:

Picture of Steve Combs

Steve Combs

Co-Founder & Managing Director, Cocha Technology

Steven is a fractional CIO/CISO with 30+ years of enterprise IT and security leadership. He has built AI governance frameworks for organizations with 1,700+ users, led enterprise Microsoft Copilot deployments, and conducted security assessments across law firms, energy companies, financial institutions, and PE-backed manufacturers.