NEWS

Anthropic Puts Claude Code Inside the Enterprise Firewall

A server rack inside a corporate data center, representing Claude Code sessions running on a company's own infrastructure
Claude Code sessions can now execute on machines the customer owns and audits. Source: Unsplash
TLDR

Claude Code sessions now execute on machines the customer controls

Anthropic has moved the compute layer of its coding agent inside the customer's own perimeter. With the August 7 release, a single command, claude self-hosted-runner, turns a company's own machines or containers into the environment where Claude Code sessions run. Sessions started from the web, desktop, terminal, or a scheduled routine execute next to internal services, private toolchains, and existing security controls rather than on Anthropic's infrastructure.

The distinction matters because of where data comes to rest. Repository checkouts, build artifacts, secrets, and any files a session creates or modifies stay on machines the organization provisions and governs.

"Repository checkouts, build artifacts, secrets, and any files a session creates or modifies stay on machines the organization provisions."
Anthropic, "Self-hosted environments for Claude Code"

Paired with the runner is a governance layer aimed at finance and platform teams rather than developers.

What ships with the enterprise controls
Model-level entitlementsAdmins decide which teams can call Opus, Sonnet, or Haiku
Spend capsSet at organization, group, and user level, with alerts before limits hit
Usage analyticsDashboard plus exports and an Analytics API, cost by group and by user
Cost visibilityReported next to output: artifacts created, files edited, skills and connectors used
Source: Anthropic, Claude Code enterprise release notes, August 2026.

Why on-premise execution removes the last blocker to agentic coding

For a year the enterprise objection to coding agents has been consistent, and it has had little to do with benchmarks. Regulated buyers in banking, defense, and healthcare could not send proprietary source code and live secrets to a third-party runtime, and finance teams could not sign off on a tool whose per-seat cost swung with token usage they could not see. Self-hosted execution answers the first objection by keeping the sensitive material on hardware the customer already audits. The Analytics API and spend caps answer the second by making agent cost legible and boundable before the invoice arrives.

The competitive signal is that the coding-agent contest is shifting from capability to control. When frontier models across vendors can all write and refactor production code, the deciding factor becomes who lets a buyer run it without moving data or losing budget visibility. Anthropic is betting the enterprise sale is won on governance surface, not leaderboard position.

That bet reframes what a coding agent is. Claude Code is no longer only a model that writes code. It is becoming an execution platform an enterprise can wire into its own network, permission by team, and meter to the dollar. The labs that win the next phase of enterprise AI will be the ones that treat data residency and cost control as product features, not compliance afterthoughts.

Santage is committed to independent, transparent journalism. This article is produced in accordance with Santage's Editorial Standards and aims to provide accurate and timely information. Readers are encouraged to verify information independently.