Demo Request
Take a personalized product tour with a member of our team to see how we can help make your existing security teams and tools more effective within minutes.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Home
Blog

Inference Hooks Are Live. Now Reco Stands Between Rogue Prompts and Claude.

Tal Shapira
Updated
August 7, 2026
August 7, 2026
3 min read
Ready to Close the SaaS Security Gap?
Chat with us

Security for enterprise AI tends to move in two stages: first you learn what’s actually happening, then you stop the part that shouldn’t. Reco took the first stage with Claude Enterprise in June, bringing the same identity governance, posture management, and agent security we apply to Okta, Salesforce, and M365 to every Claude surface (see our announcement). As one of Anthropic’s Compliance API partners, we give security teams a full record of what happens inside Claude: which conversations touched sensitive data, which apps and identities were involved, and when.

Yesterday, Anthropic moved the second stage forward for the entire ecosystem. Their new inference hooks give every Claude Enterprise organization a real enforcement point: a prompt can now be routed to a security server, evaluated, and allowed or denied before Claude ever sees it. 

What inference hooks change

Until now, most controls around Claude sat either at the network layer (e.g., an AI gateway that only sees what routes through it) or on the endpoint (e.g., watching what a browser or agent does locally). Inference hooks add a third option that lives on Anthropic’s side: every governed prompt sent to Claude Chat, Claude Cowork, or Claude Code is handed to your configured security server first. That server gets the transcript including the prompt, prior tool calls and their results, and any text pulled from attachments, and has a few seconds to return a verdict. Allow, and the request proceeds like normal. Deny, and the user sees why, and it never reaches the model.

Because the check happens inside Anthropic’s own infrastructure rather than on a network path or a managed device, coverage isn’t conditional on how someone is connecting. The same policy applies whether a request comes from Claude on the web, the desktop app, Claude Code running locally, or a CLI session on an unmanaged laptop.

Reco is now the security server behind the hook

Reco already inspects AI activity across the agents and app surfaces our customers use — including full-stack protection for Claude’s Console, Managed Agents, and Claude Enterprise, and runtime inspection through Reco Browser Guard. Inference hooks give us a new place to apply that same policy engine: instead of watching a prompt after the fact, we now get to decide, in real time, whether it should reach Claude at all.

We turned this on against our own workspace first. Below is one of the actual blocks from that testing:

A prompt containing a card number, blocked by a Reco policy before Claude Code could act on it.
Figure 1: A prompt containing a card number, blocked by a Reco policy before Claude Code could act on it.

The same checkpoint holds regardless of which Claude surface someone is using. In our testing, the identical policy caught a flagged prompt inside a Claude Code CLI session running against our own repository:

The same policy enforced inside a CLI session — no separate agent, no separate configuration.
The same policy enforced inside a CLI session — no separate agent, no separate configuration.

Why this matters more than routing traffic through a gateway

An AI gateway can only govern what it sees, and it only sees what’s routed through it. That leaves notable gaps like a Claude Code session on someone’s laptop, a CLI call, or a Cowork task doesn’t always take the network path a gateway expects. Closing that gap usually means deploying more infrastructure per surface. Inference hooks flip that. Because the checkpoint lives on Anthropic’s side of the connection, one configuration governs every governed request across Claude Chat, Cowork, and Claude Code at once, without rerouting traffic or separate agents per device or app. You get the guarantee that everything is inspected, not just everything that happened to pass through a particular pipe.

That’s the meaningful shift for security teams already using an AI gateway alongside Reco. Inference hooks aren’t a replacement for endpoint and browser-level controls, but rather the piece that removes the “what if it doesn’t route through the gateway” question.

What this means for Claude Enterprise customers using Reco

If you’re already running Reco alongside Claude Enterprise, this is additive: your existing policies — DLP rules, identity and app risk context, AI activity monitoring — now have a point of enforcement sitting in front of inference itself. If you’re evaluating Claude Enterprise and want inline enforcement from day one, this is the fastest path to it.

For the full picture of how Reco secures Claude end to end see the Reco for Claude integration guide.

Have questions about this integration? Contact your Reco account team, or reach out through reco.ai.

No items found.

Tal Shapira

ABOUT THE AUTHOR

Tal is the Cofounder & CTO of Reco. Tal has a Ph.D. from the school of Electrical Engineering at Tel Aviv University, where his research focused on deep learning, computer networks, and cybersecurity. Tal is a graduate of the Talpiot Excellence Program, and a former head of a cybersecurity R&D group within the Israeli Prime Minister's Office. In addition to serving as the CTO, Tal is a member of the AI Controls Security Working Group with the Cloud Security Alliance.

Technical Review by:
Gal Nakash
Technical Review by:
Tal Shapira

Tal is the Cofounder & CTO of Reco. Tal has a Ph.D. from the school of Electrical Engineering at Tel Aviv University, where his research focused on deep learning, computer networks, and cybersecurity. Tal is a graduate of the Talpiot Excellence Program, and a former head of a cybersecurity R&D group within the Israeli Prime Minister's Office. In addition to serving as the CTO, Tal is a member of the AI Controls Security Working Group with the Cloud Security Alliance.

Table of Contents
Let’s Talk About Your Non-Human Users
Chat with us
Get the Latest SaaS Security Insights
Subscribe to receive updates on the latest cyber security attacks and trends in SaaS Security.

Your agents are already running. Do you know what they're doing?

Request a demo