Anthropic moved self-hosted environments for Claude Code cloud sessions into public beta this month, available on Team and Enterprise plans. In practical terms, an organization can now run claude self-hosted-runner on its own machines or containers, and sessions started from claude.ai, the mobile or desktop apps, or the command line can execute inside that organization’s own network, with access to internal services, rather than on Anthropic’s cloud infrastructure.
Why this is a bigger deal than it sounds
Enterprise adoption of AI coding and automation tools has consistently run into the same wall: security and IT teams are uncomfortable with sensitive internal systems being reachable by, or processed through, infrastructure they do not control. Self-hosted runners are Anthropic’s answer to that specific objection, and the fact that it shipped as a real product rather than a roadmap promise is a meaningful trust signal for any organization that has been holding back on AI adoption for data governance reasons.
What it means outside of engineering teams
You do not need to be a developer for this to matter to you. If your marketing organization has been blocked from adopting AI tooling more broadly because of a security or compliance objection tied to data leaving your network, this is worth bringing to your IT and security stakeholders directly. The objection that used to be a hard stop (“we can’t have an external AI system touching our internal data”) now has a concrete technical answer for at least this part of Anthropic’s product line.
Practical steps if this is relevant to your organization
Bring this to your security team proactively, not reactively. If AI tooling adoption has stalled in your organization over data governance concerns, this is a specific, current example to raise, rather than a hypothetical future capability.
Understand it is Team and Enterprise only, and still in beta. This is not a feature available on individual Pro plans, and beta products change quickly. Do not build a critical workflow around it without confirming current availability and stability first.
Recognize the pattern, not just the feature. Anthropic shipping enterprise-grade infrastructure controls this specifically is a signal that AI vendors broadly are responding to enterprise security requirements as a real adoption blocker, not an edge case. Expect similar moves from other providers your marketing stack depends on.
The direction of travel is clear: AI tooling is becoming enterprise-ready faster than most organizations’ internal policies have caught up to evaluate it. Marketing leaders who bring concrete examples like this to their security stakeholders will move faster than those waiting for a general policy review to happen on its own schedule.
What “runs inside your own network” actually changes, mechanically
It’s worth being precise about what self-hosting changes versus what it doesn’t, because the distinction is exactly what a security review will ask about. In the standard cloud setup, a session’s execution — running commands, reading files, calling internal tools — happens on infrastructure Anthropic operates, even though the conversation is initiated by your team. With a self-hosted runner, that execution moves onto compute your organization controls; the model itself is still called over the network (there’s no version of this where the model weights run entirely on your hardware), but the actual work — reading your internal files, hitting your internal APIs, touching data that never needs to leave your network — happens on your side of the boundary. That’s the specific thing that satisfies a security team’s objection: it’s not “trust us with your data,” it’s “your data stays where it already lives, and only the reasoning request crosses the boundary.”
The conversation this actually enables with IT
The most useful thing to do with this information isn’t a broad “AI tooling is more secure now” pitch — that’s vague enough to get deprioritized. It’s a specific, scoped ask: identify the one workflow your team most wants AI assistance on that’s currently blocked by a data-residency or network-access objection, confirm it fits within Team or Enterprise plan requirements, and bring that single concrete use case to IT alongside the self-hosted runner capability as the specific technical answer to their specific objection. A scoped pilot request tied to a named capability moves through a security review meaningfully faster than a general request to “explore AI tools,” because it gives the reviewer something specific to evaluate rather than an open-ended policy question.