Anthropic’s new inference hooks give enterprises something security teams have been asking for: a native enforcement point inside Claude Enterprise.
Onyx is integrating with Anthropic inference hooks to bring AI-native runtime security directly into Claude, allowing organizations to evaluate AI activity against their security policies before it reaches the model.
But for Onyx, the opportunity goes beyond inspecting sensitive prompts.
As Claude evolves from an AI assistant into an environment where agents can access enterprise data, call tools, write code, and take actions, enterprises need security controls that understand not only what is being said, but also which agent is acting, what it can access, and what it is trying to do.
That is the problem Onyx was built to solve.
Why Anthropic inference hooks matter
Anthropic introduced inference hooks for Claude Enterprise in early August 2026. The capability allows an external security service to inspect prompts, tool-call responses, and text extracted from uploaded files before that content reaches Claude. The external service returns an allow-or-deny verdict, which Claude then enforces in real time.
Because the enforcement point sits within Anthropic’s infrastructure, organizations can apply controls across Claude Enterprise without requiring every interaction to pass through a traditional network proxy or endpoint control.
A single integration can extend across Claude, Claude Code, Cowork, and connected tools.
For security teams, that creates an important new control point: the moment before AI activity becomes inference.
How Onyx integrates with Claude inference hooks
With the Onyx integration, organizations can connect Claude Enterprise inference hooks directly to Onyx’s runtime protection (AI Guard).
When Claude invokes the inference hook, Onyx evaluates the request against enterprise AI security policies and returns a real-time verdict before Claude processes the request. This works on any device including personal laptops and phones, with nothing to install.
Organizations can use Onyx policies to identify and stop activity such as:
- Sensitive or regulated data exposure
- Credentials, secrets, and intellectual property being sent to Claude
- Prompt injection and jailbreak attempts
- Inappropriate or unauthorized AI use
- Risky content originating from tools, connectors, or previous steps in an agent workflow
If the interaction complies with policy, Claude continues normally.
If it violates policy, Onyx can return a deny verdict, which prevents the content from reaching the model, or create an alert while allowing the request to proceed.
This gives organizations a native enforcement path into Claude while managing AI security policy through the same Onyx control plane used across the rest of their enterprise AI environment.

The prompt is only part of the risk
Inference hooks create an important checkpoint, but securing agentic AI requires looking beyond the individual prompt.
Consider a Claude Code session.
A developer may legitimately ask Claude to investigate an issue in a production repository. The prompt itself may be completely benign. Claude may also legitimately have access to the repository. The security question begins to change when the agent starts acting.
- Can it read a production secret?
- Can it modify the configuration?
- Can it execute a shell command?
- Can it send information to an external service?
- Should the same agent be allowed to perform a read operation and a write operation?
These questions cannot always be answered by examining sensitive content alone. They require understanding the agent, its identity, its permissions, the tools available to it, the session context, and the action being attempted.
Onyx was designed around exactly this runtime model.
From prompt inspection to agent-aware runtime control
Onyx AI Guard inspects AI activity inline across prompts, model responses, and agent actions. Each decision can be associated with the agent responsible for the activity rather than treated as an isolated network transaction.
Anthropic inference hooks now give Onyx another native enforcement point within that architecture. That means the same enterprise AI security strategy can extend across multiple stages of an agent interaction.
At the inference boundary, Onyx can evaluate what is about to enter Claude. At the tool-call boundary, Onyx can evaluate what an agent is about to do.
Onyx's runtime controls can block destructive operations before execution, mask sensitive information, restrict tools by policy, and apply tighter access controls as an agent operates. That distinction becomes increasingly important as AI systems move from answering questions to performing work.
One policy layer across Claude and the rest of enterprise AI
Claude is rarely the only AI environment inside a large enterprise. Security teams are increasingly responsible for a combination of:
- Claude and Claude Code
- Enterprise copilots
- Coding agents
- SaaS AI applications
- Internally developed agents
- Cloud-hosted agent frameworks
- AI gateways
- MCP servers and tools
Trying to secure each one with its own isolated policy model creates exactly the governance fragmentation enterprises are trying to avoid.
Onyx provides a Secure AI Control Plane that discovers AI assets across the enterprise and converts governance policies into controls that operate at runtime.
The Anthropic integration extends that control plane directly into Claude’s native inference path.
Security teams can therefore apply consistent AI policies while still taking advantage of the controls that Anthropic exposes natively. No separate Claude-specific security strategy. No treating Claude as an isolated security domain. Instead, Claude becomes another deeply integrated enforcement point within the broader enterprise AI security architecture.
Native enforcement is becoming the new AI security architecture
Anthropic’s inference hooks are important for another reason.
They demonstrate where AI security architecture is heading.
Historically, security teams have had to surround AI applications with external controls – network proxies, endpoint agents, gateways, or retrospective monitoring APIs. Native enforcement changes that model.
AI platforms themselves can expose security checkpoints where enterprise policy engines participate directly in runtime decisions. That enables security to move closer to the moment where AI activity actually occurs.
Onyx believes the future of enterprise AI security will require both: deep native enforcement within AI platforms, and a common control plane across the heterogeneous AI ecosystem.
Anthropic inference hooks provide the first. Onyx provides the second. Together, they give enterprises another way to adopt Claude aggressively while maintaining the controls required to move AI and agents safely into production.
Onyx support for Anthropic inference hooks is available for organizations using Onyx AI Guard and Claude Enterprise.
Request a demo to learn more.
Frequently Asked Questions
Inference hooks are a Claude Enterprise capability that lets an external security service inspect prompts, tool-call responses, and text pulled from uploaded files before Claude processes them. The service returns an allow-or-deny verdict that Claude enforces in real time. The enforcement point sits inside Anthropic's infrastructure rather than in a network proxy.
When Claude invokes the hook, Onyx AI Guard evaluates the request against the organization's AI security policies and returns a verdict before the model sees it. Compliant activity passes through normally. Policy violations can be denied outright, preventing the content from reaching Claude, or allowed through with an alert raised.
No. Because enforcement happens inside Anthropic's infrastructure, the integration covers Claude sessions on any device, including personal laptops and phones, with no agent or proxy to deploy. A single integration extends across Claude, Claude Code, Cowork, and connected tools rather than requiring per-surface configuration.
A benign prompt can still lead to a risky action. In a Claude Code session, the security question is whether the agent can read a production secret, modify configuration, execute a shell command, or send data outward. Answering that requires the agent's identity, permissions, and session context, not the prompt text.
Yes. Onyx discovers AI assets across the enterprise and enforces policy at runtime across enterprise copilots, coding agents, SaaS AI applications, internally developed agents, AI gateways, and MCP servers. Claude becomes one enforcement point inside that architecture rather than a separate security domain with its own policy model.



