AI agents · OpenClaw · self-hosting · automation

Quick Answer

Anthropic EFS vs OpenAI Private Safety Processing 2026

Published:

The Short Answer

By September 2026 both frontier labs concede the same point: serious misuse — stolen credentials, agents that keep acting after being told to stop, attacks spread across accounts — is invisible one request at a time. Each now offers a way to correlate across sessions without its own staff reading your data. The designs differ in where the data sits, who holds the keys, and what the vendor gets back.

Anthropic EFSOpenAI Private Safety Processing
AnnouncedSeptember 1, 2026Previewed August 19, 2026
Where content livesCustomer’s own S3 / Azure Blob / GCSCustomer infrastructure (ZDR), or OpenAI storage encrypted with customer keys
Who holds keysCustomer (CMEK, opt-in)Customer; OpenAI holds no copy
Who sees a flagCustomer’s security team only; no Anthropic human reviewOpenAI receives a narrow signal of activity type; can trigger enforcement; no content access
Cloud partnersBedrock, Google Agent Platform, Microsoft Foundry — equivalent controlsNot specified in the preview
CostFree; cloud storage/egress billed by providerNot announced
StatusPhased rollout, broad availability targeted fall 2026Early-customer testing; rollout + white paper promised for September
Bridge for ZDR buyersZDR on Fable 5 / 5.1 until EFS arrivesZDR already available on frontier models incl. GPT-6 Astra

If you must sign today and your regulator cares who reads the logs, EFS is the more concrete offer. If ZDR on the frontier tier is the hard requirement, OpenAI already has it — and is building detection around it rather than replacing it.

The Problem They Both Solve

Anthropic introduced 30-day retention with Claude Fable 5 in July 2026, explicitly for cross-session detection. OpenAI took the opposite line in August, keeping ZDR on GPT-6 Astra and framing retained-data requirements as something “some recent frontier-model deployments” impose. Regulated buyers were stuck: Anthropic’s most capable model came with a vendor holding their prompts; OpenAI’s came with single-interaction safety checks that miss slow, distributed abuse.

Both August–September announcements are attempts to escape that trade-off.

Where the Data Lives

EFS is unambiguous: activity data used for monitoring goes to a bucket in the customer’s own cloud account, governed by the customer’s encryption keys, access policies and audit logging. Anthropic never holds it. That was a direct ask from the Analysis and Resilience Center for Systemic Risk, whose members include the CISOs of Goldman Sachs, Morgan Stanley, Citi, Bank of America and Wells Fargo.

Private Safety Processing has two modes. For ZDR deployments, content stays on infrastructure the customer controls. OpenAI is also developing an option where content sits on OpenAI storage encrypted with keys the customer controls — OpenAI personnel have no copy. Functionally similar, but the second mode means OpenAI operates the storage, which some data-residency policies treat differently from a customer-owned bucket.

Who Reviews a Flag

This is the sharpest difference.

EFS: automated systems analyse a rolling window for offensive cyber/bio development and stolen-credential signals, and “those flags go directly to the customer and their people take it from there — no human review by Anthropic employees is required.” The alert queue is yours to staff. That is a feature for firms whose staff are already cleared to see privileged material, and a cost for firms that are not.

Private Safety Processing: when a risk is identified, OpenAI receives a narrowly defined signal indicating the type of activity, which “can be used to determine whether enforcement is necessary.” Personnel do not see content even when flagged; customers can choose to share information to appeal or support an investigation. OpenAI keeps the enforcement decision; Anthropic hands it to you.

What Is Still Unsettled

  • Window length. Neither vendor has published how long the rolling correlation window runs — which matters if you are reasoning about what an attacker could hide by spacing activity out.
  • PSP specifics. OpenAI’s preview promises a technical white paper and rollout in September 2026; until it lands, the guarantees above are preview language, not terms.
  • Third-party resellers. Anthropic says it is “working to support third-party offerings”; the cloud-partner promise covers AWS, Google Cloud and Azure only.

How to Choose

  1. Start from your contract, not the blog post. Confirm which workloads qualify and whether the guarantee is contractual.
  2. Decide who you want staffing the alert queue. If the answer is “us,” EFS. If you would rather the vendor own enforcement, PSP.
  3. Check the cloud path. Buying through Bedrock, Google Cloud or Foundry? EFS explicitly ships equivalent controls there; regional endpoints still carry roughly a 10% token premium.
  4. Use the bridge. Anthropic customers waiting on EFS get ZDR on Fable 5.1; OpenAI customers have ZDR on Astra today.

Sources