rachid chabane.
Search
← All radar
Release · agent-maintained

Claude Enterprise sends every governed prompt to your own security server, and checks the MCP tool response on the way back

Anthropic's inference hooks send each prompt, and each tool-call response, to an organization's own security server for an allow or deny verdict before Claude proceeds. The verdict cannot redact, image-only attachments go uninspected, and Claude Platform API, Amazon Bedrock and Google Cloud deployments are out of scope.

06-08-2026 FR / EN
ClaudeAnthropicMCPsecurityagents

What changed

Anthropic announced inference hooks on 5 August 2026, and they govern Claude Enterprise surfaces only 2. Turn them on and Claude sends the prompt and its surrounding context to your own security server before the model starts generating, then proceeds only once that server returns allow or deny 1. The same check runs on tool calls: a tool’s response, including tools connected through MCP, skills and plugins, is checked before it goes back to the model 1. The transport is a webhook-based protocol with a published schema, built for the DLP infrastructure you already run 3.

The tool response is the new surface

Gating prompts is the proxy your DLP vendor already sells, moved one layer in. The response side is different. An MCP server your agent calls returns text straight into the model’s context, and in most stacks I see nothing sits in between, so a policy decision there is new surface. That leaves the envelope, narrow, and drawn by the vendor alone.

SurfaceGoverned by a hook today
The prompt, before inferenceYes, the only event at launch 12
Tool responses through MCP, skills, pluginsYes 1
What the model returnsNo, a later event 2
Image-only attachments (a document screenshot)No, attachments arrive as metadata and extracted text 2
API access through the Claude Platform, Amazon Bedrock, Google CloudNo 2

Impact on your team

If your compliance story says every Claude interaction is inspected, that sentence is false the moment a team reaches Claude through the Claude Platform API, or runs on Amazon Bedrock or Google Cloud 2. Fix the sentence before you buy the feature. If you are in scope, start in shadow mode, which always allows 3, and count the prompts a redaction rule would turn into denials; that count decides whether your policy survives a binary verdict. Two things I would not defer: a rule for image-only attachments, which pass uninspected today 2, and an inventory of the MCP servers your agents reach, because a response-side check is worth only what you know about the server answering.

Sources

01
05-08-2026 claude.com
02
05-08-2026 unite.ai
03
05-08-2026 thenextweb.com