Last updated: October 2026
How do you secure Claude for UK enterprise?
Start with three decisions: which route you use to reach Claude, where the data can sit, and which controls constrain what Claude and its agents can do. Anthropic's first-party API offers only global or US inference, so UK-specific requirements usually mean choosing a cloud route and layering your own controls, using documentation reviewed on 1 October 2026.
This guide applies to Claude Opus 5.5 and Sonnet 5.5.
TL;DR - Key Takeaways
- No UK or EU region on the first-party API. The
inference_geosetting accepts only "global" or "us", with US-only inference priced at 1.1x (Anthropic docs, 2026). - Retention has limits. API data is deleted within 30 days, but content flagged by safety systems can be kept for up to 2 years (Anthropic privacy centre, 2026).
- Enterprise audit logs cover 180 days. They are Enterprise-only and also exposed through the Compliance API (Anthropic support, 2026).
- UK guidance is interim. The NCSC's agentic AI guidance of 20 August 2026 advises sandboxing, unique agent identities, chain-of-thought and log capture, and a kill switch (NCSC, 2026).
- Models help, controls decide. Anthropic says Opus 5.5 attempted to circumvent boundaries about 85% less often than Opus 5 (Anthropic, 2026).
At a glance: routes to Claude and what they offer a UK buyer
| Route | UK or EU residency option | Watch for |
|---|---|---|
| Anthropic API or Claude Enterprise | Global or US only | No UK region; US-only inference costs 1.1x |
| Claude Platform on AWS | US or Global only | Same limits as first-party |
| Amazon Bedrock (London, eu-west-2) | London listed; EU Geo and Global profiles | EU profiles are not UK-only; check In-Region per model |
| Microsoft Foundry | Global Standard and US Data Zone | Europe listed as "coming 2026" |
| Google Vertex AI | Not verified for London | Confirm before you plan around it |
Where can Claude data stay in the UK?
Today there is no single first-party answer. According to Anthropic's documentation (2026), workspace geography is US-only and cannot be changed after creation. AWS (2026) documents the same US or Global choice for Claude Platform on AWS.
Amazon Bedrock is the route most UK buyers examine. AWS defines eu.* inference profiles as keeping data within EU regions, and the UK is not in the EU, so an EU profile is not a UK-only guarantee. The global.* profiles carry no residency constraint. For Sonnet 5.5, the AWS model card (2026) lists London with Geo and Global support but not In-Region.
For Opus 5.5, pages we reviewed disagreed on London In-Region support, so confirm on the live AWS model card. Anthropic's Foundry documentation (2026) lists Global Standard and US Data Zone deployments, with Europe still to come.
What Claude Enterprise controls and contracts cover
Claude Enterprise adds the governance layer. According to Anthropic (2026), it includes SSO and SCIM, role-based access, audit logs, a Compliance API, custom retention, customer-managed keys and IP allowlisting, and admins approve connectors with per-tool permissions. Anthropic does not train on Team, Enterprise or API inputs and outputs by default.
| Control | What it gives you | Limit to note |
|---|---|---|
| Audit logs | 180 days of activity | Enterprise-only |
| Zero data retention | Nothing stored at rest after the response | Excludes Enterprise interfaces, Batch and Files API |
| Custom retention | Configurable retention periods | Flagged content can still be kept up to 2 years |
| Connector approval | Org-wide approval, per-tool permissions | Needs admin review of each server |
| Certifications | ISO 27001:2022, ISO/IEC 42001:2023, SOC 2 Type I and II | Commercial products only |
Sources: Anthropic documentation, accessed 1 October 2026. Fable 5.1 and Mythos models need 30-day retention, so check ZDR eligibility per model (Anthropic docs, 2026).
On contracts, UK guidance by Talk Think Do (2026) reports a data processing agreement with Article 28 terms, EU standard contractual clauses and the UK Addendum. We could not open Anthropic's DPA directly, so read it yourself.
How to secure Claude for UK enterprise: a seven-step checklist
- Choose the route. Decide between first-party Claude and a cloud route, based on whether you need UK-only processing.
- Run a DPIA and transfer risk assessment. Map prompts, outputs, files, logs and connectors, and record who receives them.
- Switch on Enterprise controls. Enforce SSO, SCIM, role-based access, audit logging and retention settings.
- Lock down Claude Code. Use managed settings, deny rules, the sandbox and MCP allowlists.
- Restrict connectors and tools. Approve servers one by one and apply least privilege.
- Log and monitor. Export audit and tool-call logs to your SIEM and set alerts.
- Red-team before rollout. Test injection and tool-misuse paths against your own data.
For Claude Code, Anthropic's admin guide (2026) lists managed settings for permission allow and deny rules, sandbox enablement, MCP server allowlists and forceLoginOrgUUID. It also warns that denying WebFetch alone does not stop curl if Bash is allowed, so combine permissions with the sandbox. For Cowork, Anthropic (2026) warns of prompt injection and notes the VM does not limit what Claude reads or does.
UK rules that shape a Claude deployment
| Framework | Status on 1 October 2026 | What it means for Claude |
|---|---|---|
| NCSC agentic AI guidance | Interim, 20 August 2026 | Sandbox agents, unique identities, immutable logs, kill switch |
| DSIT AI Cyber Security Code | Voluntary, 13 principles | Basis for secure-by-design supplier questions |
| Data (Use and Access) Act 2025 | Mostly in force from 5 February 2026 | Reformed automated decision-making; new transfer test |
| ICO AI and ADM code | In development | Watch for DPIA and ADM expectations |
| FCA and PRA | Principles-based, no AI-specific rules | Apply Consumer Duty and SM&CR to AI use |
According to Clifford Chance (2026), the Act also added a "recognised legitimate interests" basis, applied a "not materially lower" test to international transfers, and raised PECR fines to £17.5 million or 4% of turnover. A statutory instrument in force from 12 May 2026 requires the ICO to prepare an AI and ADM code, per law firm Bratby (2026). The FCA and PRA take a principles-based approach, per Results Sense (2026).
Claude security and governance: prompt injection, tool misuse and data leakage
Model safeguards are improving but are not the whole defence. Anthropic says Opus 5.5 ties Claude Fable 5.1 for the lowest prompt-injection success rate on Gray Swan's benchmark, and that most Opus 5.5 cyber tasks are re-routed to Opus 4.8. Those are vendor-reported results.
According to OWASP (2025), prompt injection is LLM01. OWASP's Agentic Top 10 (9 December 2025) adds goal hijack, tool misuse and identity and privilege abuse.
Real incidents follow a normal vulnerability lifecycle. Anthropic disclosed on 13 November 2025 that a state-linked actor tracked as GTG-1002 used Claude Code for largely automated espionage (AI Incident Database, 2025). Check Point disclosed Claude Code flaws on 25 February 2026, including CVE-2025-59536 and CVE-2026-21852, and all were fixed before disclosure (The Hacker News, 2026).
How NeuralTrust addresses this
Anthropic's controls stop at its boundary, while agents act across your tools.
- Our Agent Gateway, TrustGate, enforces per-agent and per-tool policy between Claude and your MCP servers and APIs.
- TrustGuard, the Runtime Security layer, inspects prompts, tool calls and outputs as they happen.
- TrustTest, (AI Red Teaming) tests your Claude agents for injection and misuse before go-live.
- TrustLens (Agent Posture Management) shows which agents reach which tools.
NeuralTrust delivers these as the Runtime Security Mesh, and has four Gartner Hype Cycle 2026 recognitions in AI Runtime Defense. Our NCSC analysis maps the guidance to controls.
Which should you choose?
| If you are... | Start with | Why |
|---|---|---|
| Handling low-sensitivity UK data | Claude Enterprise, first-party | Fullest admin controls; accept global or US inference |
| Needing EU-only processing | Bedrock with an EU Geo profile | Keeps data in EU regions, not UK-only |
| Needing UK-only processing | Bedrock London In-Region, if your model supports it | Confirm on the live AWS model card first |
| Running agentic coding | Claude Code with managed settings and sandbox | Deny rules plus network limits |
| Running many agents and MCP tools | Add a gateway and runtime layer | Policy and audit independent of model |
For model-level detail, read our Claude Opus 5.5 enterprise security analysis and the OWASP agentic AI Top 10 guide.
Conclusion
To secure Claude for UK enterprise, pick the deployment route against your residency need, run a DPIA, enable every Enterprise control, lock down Claude Code and approve connectors one by one. Claude's own safeguards are strong and vendor-reported, but agents act through your tools, so add policy, monitoring and testing you control. Re-check residency details before each rollout, because region support changes quickly.
Secure Claude in Production with NeuralTrust
Talk to our team about gateway policy, runtime inspection and red teaming for your Claude agents.
FAQs about Secure Claude for UK Enterprise
1. Is Claude UK GDPR compliant?
UK GDPR compliance depends on how you deploy and govern Claude, not on the model alone. Anthropic's DPA reportedly includes Article 28 terms, SCCs and the UK Addendum. You still need a lawful basis, a DPIA, a transfer risk assessment and controls over what staff and agents send (Talk Think Do, 2026).
2. Does Claude store data in the UK?
Not on the first-party API. Its inference_geo setting accepts only global or US, and workspace storage is US-only. Amazon Bedrock lists London for some Claude models, but EU Geo profiles are not UK-only and In-Region support varies by model, so verify on the live AWS model card (Anthropic docs, 2026).
3. Can Claude be used with UK-only data processing?
Possibly, through Bedrock London In-Region, if your model supports it. AWS lists Sonnet 5.5 in London with Geo and Global but not In-Region support, and sources disagreed for Opus 5.5. Confirm per model, then test routing with real requests before you commit.
4. Does Anthropic train on Claude Enterprise data?
By default, no. Anthropic states that it does not train on Team, Enterprise or API inputs and outputs. Flagged content can still be retained for safety review for up to two years, and feedback you submit is retained separately, so read the retention terms (Anthropic, 2026).
5. Is Claude Code safe for enterprise use?
It can be, with managed settings. Use permission deny rules, enable the sandbox, restrict network domains, allowlist MCP servers and force your organisation login. Anthropic warns that denying WebFetch alone does not stop curl if Bash is allowed (Anthropic admin guide, 2026).
6. What should a DPIA for Claude cover?
Cover what data enters prompts, files and connectors, where each is processed and retained, who receives it, the transfer mechanism, flagged-content rules, and agent actions that affect people. Add automated decision-making checks and a review trigger when models or regions change.
7. Is Claude available in AWS London?
AWS lists London (eu-west-2) for some Claude models, but support differs by model. Sonnet 5.5's model card shows Geo and Global inference but not In-Region, and pages disagreed on Opus 5.5, so check the live card for your model (AWS, 2026).
8. How do I stop prompt injection in Claude agents?
You cannot remove it, but you can contain it. Apply least-privilege tools, approve connectors individually, sandbox execution, inspect tool output at a gateway, require human approval for risky actions and red-team regularly. OWASP ranks prompt injection first among LLM risks (OWASP, 2025).
About the Author
Roger Howroyd is Head of Global SEO and AI at NeuralTrust, where he leads the company's search strategy across SEO, AEO, GEO, and LLM optimisation. He specialises in AI-powered search, content strategy, and SEM. Connect on LinkedIn.
NeuralTrust is the leading platform for securing and scaling AI agents. Named a Pioneer in the Gartner Emerging Market Quadrant for AI Application Security 2026, recognised across four Gartner Hype Cycle reports in 2026, and featured in the Gartner Market Guide for Guardian Agents 2026, the Gartner Market Guide for AI Gateways 2025 and the KuppingerCole Leadership Compass for Generative AI Defense 2025. Headquartered in Barcelona with offices in London and New York. ISO 27001 certified.
Sources
- Anthropic, Data residency, accessed 1 October 2026.
- Anthropic, API and data retention, accessed 1 October 2026.
- Anthropic, How long do you store my organization's data?, 1 July 2026.
- Anthropic, Claude for Enterprise, accessed 1 October 2026.
- Anthropic, Access audit logs, accessed 1 October 2026.
- Anthropic, Claude Opus 5.5, 22 September 2026.
- Anthropic, Claude Code admin setup and sandboxing, accessed 1 October 2026.
- Anthropic, Use Claude Cowork safely, accessed 1 October 2026.
- Anthropic, Claude in Microsoft Foundry, accessed 1 October 2026.
- AWS, Claude Platform on AWS data residency, accessed 1 October 2026.
)
)