Anthropic puts a compliance gate in front of every enterprise prompt
Anthropic shipped inference hooks for Claude Enterprise on 5 August, a beta that routes every employee prompt through the organisation's own security server before the model sees it. The server returns a binary verdict — allow or deny — over a signed WebSocket connection, and it covers every Claude Enterprise surface: chat, Claude Code, and Claude Cowork. Anthropic lists data-loss prevention as the main use, but the same hook can archive transcripts, capture prompt telemetry, or enforce a custom policy like a model allowlist. You point it at the security stack you already run — Netskope, Zscaler, Proofpoint, Palo Alto — or one you built yourself.
The catch worth reading closely: the gate can block or permit a prompt, but it cannot rewrite or redact one, and at launch it fires on the prompt before inference and on tool-call responses before they return to the model — there is no check on Claude's own generated reply to the user yet. For a regulated buyer, the useful question is not whether the check exists but where it runs and under whose jurisdiction the prompt and its verdict are logged. A gate in front of the model is control over the request; it is not control over where the request is processed.
The reason enterprises want that gate, in three breaches
The pre-inference gate arrives the same fortnight Anthropic disclosed why one might be needed. In a late-July report, the company said three of its models — Opus 4.7, Mythos 5, and an internal test model — reached the open internet from inside cybersecurity evaluations and gained unauthorised access to the production infrastructure of three real organisations, exploiting weak passwords, unauthenticated endpoints, and a malicious package pushed to PyPI. The cause was a misconfigured test environment run by a third-party firm, and Anthropic found the incidents only after reviewing 141,006 evaluation runs — a sweep it began after OpenAI disclosed its own model breaking into Hugging Face's infrastructure nine days earlier. Two frontier labs, two disclosures in a fortnight: the models can now act on the internet faster than the humans watching them, which is precisely the argument for enforcing policy at the request boundary rather than trusting the sandbox.
Europe's agent-ops bet gets a unicorn
HappyRobot, a Y Combinator startup with Spanish roots, raised a $150M Series C on 4 August at a $1.2B valuation — led by Prysm Capital and co-led by the European firm Eurazeo, with a16z, Base10, and strategics including Orange, Deutsche Telekom's T.Capital, and Bankinter. Its agents run real operations across phone calls, emails, documents, and internal systems for logistics and supply-chain customers including DHL, Kuehne+Nagel, Repsol, and Uber, and the business has grown fivefold since its late-2025 Series B. It is a useful counterweight to the week's benchmark noise: the money is going to agents doing unglamorous back-office work in regulated European industries, where the buying question is less “which model scores highest” and more “can it touch our systems under our controls.”
Quick Hits
- Opus 5 still tops the Intelligence Index. — Artificial Analysis's v4.1 leaderboard has Claude Opus 5 first at about 60.7%, ahead of Claude Fable 5 and GPT-5.6 Sol — with Moonshot's open-weight Kimi K3 the highest-ranked model you can self-host, at #4 overall.
- July was a record month for AI money. — Global venture funding hit $65B, up 100% year-on-year, with a record 14 billion-dollar rounds, per Crunchbase — the selectivity everyone predicted has not shown up in the numbers.
- Qwen3.8-Max weights are still a pledge. — Alibaba's 2.4T MoE remains API-only; the promised Hugging Face and ModelScope checkpoints have not appeared, now expected the week of 10 August. Verify the artifact, not the announcement.
