claudecoworkexpert.com
Back to news
August 5, 2026

Anthropic launches inference hooks: inline data loss prevention for Claude Enterprise, including Cowork

Anthropic released inference hooks in beta for Claude Enterprise on August 5. Every prompt and tool result can now be routed through your organization's own security server for an allow-or-deny verdict before it ever reaches the model, across chat, Claude Code, and Claude Cowork. It plugs into existing DLP infrastructure from Zscaler, Palo Alto Networks, Netskope, and Proofpoint. For compliance teams this is the first org-level inline control that actually covers Cowork sessions.

Anthropic launched inference hooks on August 5, 2026, in beta for Claude Enterprise. The idea is simple and, for compliance teams, long-awaited: before a prompt reaches the Claude model, Anthropic first sends the conversation to an AI security server that your organization (or its security vendor) operates over HTTPS. That server returns an allow or deny verdict. A denied request never reaches the model at all.

The checkpoint moves to the server side. Traditional DLP for AI tools relies on browser plugins or network proxies on every device. Inference hooks run on Anthropic's side, after a request leaves the client and before inference starts. One organization-level configuration covers every governed surface, chat, Claude Code, and Claude Cowork included, with nothing to install on user devices.

Tool calls are inspected too. The same check runs when Claude calls a tool through MCP connectors, skills, or plugins: the tool's response is checked before it reaches the model. That matters for Cowork specifically, where a single session can touch mail, drives, CRM systems, and internal databases through connectors.

Built to plug into existing security stacks. The protocol is webhook-based with a published schema, designed to work with DLP infrastructure from Netskope, Palo Alto Networks, Proofpoint, and Zscaler, or a custom-built server. Rollout controls are pragmatic: a shadow mode (always allow, but log) lets teams monitor before enforcing, and role-based exclusions plus percentage-based rollouts support a gradual introduction.

The honest limitations. Verdicts are binary: a server can allow or deny a prompt, but cannot rewrite or redact it. And at launch the only hook event fires on the prompt before inference; response-side enforcement, checking what the model returns, is planned as a later event. It is also Enterprise-only for now.

Why this matters for Cowork organizations. Until now, the standing compliance caveat around Cowork was that its activity is hard to govern centrally. Inference hooks are the first inline, organization-wide control that includes Cowork sessions, a meaningful step for regulated industries evaluating agentic AI.

Also this week in brief: Anthropic extended the 50% weekly usage boost for Claude Code through August 19 (Pro, Max, Team, and seat-based Enterprise), and the introductory API pricing for Sonnet 5 ($2/$10 per million tokens) ends August 31; standard pricing of $3/$15 applies from September 1.

Key takeaways

  • Inference hooks launched August 5, 2026, in beta for Claude Enterprise
  • Every prompt gets an allow/deny verdict from your own AI security server before it reaches the model
  • Covers chat, Claude Code, AND Claude Cowork with one org-level configuration; nothing installed on devices
  • Tool-call responses (MCP, skills, plugins) are checked too, before Claude sees them
  • Integrates with Zscaler, Palo Alto Networks, Netskope, Proofpoint, or a custom server; shadow mode for monitoring first
  • Limits: binary verdicts only (no redaction), prompt-side only at launch, Enterprise-only
  • Also: Claude Code 50% usage boost extended to August 19; Sonnet 5 intro pricing ends August 31

What should you do?

  1. 1Enterprise admins: start in shadow mode to see what would be flagged before enforcing anything
  2. 2Check whether your existing DLP vendor (Zscaler, Palo Alto, Netskope, Proofpoint) already supports the hook schema
  3. 3Revisit internal policies that banned Cowork for sensitive data; inline enforcement may change the assessment
  4. 4Claude Code users: make use of the 50% higher weekly limits while they last (through August 19)
  5. 5API users on Sonnet 5: budget for standard pricing ($3/$15) from September 1

This site is an initiative of erikvanderveen.nl