Thursday Aug 6

Anthropic Lets Security Teams Screen Claude

6AUG
ALLOW OR DENYSECURITYCLAUDE

Every prompt your employees send Claude can now pass through your company's own security server first. It answers allow or deny before Claude ever sees the text. Data leaks get caught in real time.

The feature is called inference hooks, in beta for Claude Enterprise. It is inline data loss prevention, the software that stops sensitive data leaving the building. One org-level config covers chat, Claude Code, and Cowork.

The webhook protocol is open, with a published schema. Point it at the same server Netskope, Palo Alto, Proofpoint, or Zscaler already report to. Zscaler shipped an integration on day one.

Data governance is the top blocker for enterprise AI rollouts. This moves security teams from blocking AI to inspecting AI traffic like email and web. Shadow mode and staged rollouts ease the switch.

full brief & sources

⚡ Why this matters

  • Data governance is the number one blocker for enterprise AI adoption, and this attacks it directly.
  • The compliance stack becomes a first-class part of the AI platform, not a bolt-on proxy.
  • An open webhook schema means existing DLP vendors plug in without waiting for partnerships.

🔍 What happened

  • On August 5 Anthropic launched inference hooks in beta for Claude Enterprise.
  • Every employee prompt and tool-call response routes through the organization's own security server for an allow-or-deny verdict before it reaches Claude.
  • Coverage spans chat, Claude Code, and Claude Cowork with one org-level configuration.
  • The webhook protocol is open with a published schema, compatible with Netskope, Palo Alto Networks, Proofpoint, Zscaler, or in-house servers.
  • Rollout helpers include shadow mode, role-based exclusions, percentage rollouts, and a configurable failure policy with timeouts.
  • Zscaler already shipped an integration.

💬 Smart takes

  • Anthropic: point the hooks at the same server your existing security tools already report to. One verdict path for everything.
  • Zscaler: shipped a day-one integration, pitching it as scaling AI adoption while addressing the risks.
  • Skeptic: an inline verdict on every prompt adds a network hop to every message. Latency and server outages will test that failure policy fast.

🧭 Where this goes

  1. LikelyOpenAI and Google ship equivalent inline hooks for their enterprise tiers within two quarters.
  2. Likelythe major DLP vendors all list Claude inference hooks as a supported channel by year end.
  3. Possiblethe published schema becomes a de facto standard for AI traffic inspection across vendors.
  4. Possibleregulators in finance and healthcare start treating inline AI inspection as a compliance baseline.
  5. Wild Carda public incident where hooks caught a breach becomes the reference story that unlocks banks and pharma.

🥄 The Spoon Take

Enterprises never trusted AI because it bypassed the security stack email and web traffic go through. Anthropic just wired Claude into that stack instead of around it. The security team stops being the department that says no and becomes the department that inspects. That flip is what unlocks adoption.

🤔 Pushback

A synchronous check on every prompt is a latency tax and a single point of failure, and beta configs rarely survive contact with production traffic.