Anthropic Revises Its Usage Policy, Effective November 12 - New Rules for Physical Hardware and a Ban on Abusing the Model
Anthropic published a new Usage Policy on October 8, 2026, taking effect November 12. The company describes most changes as clarifications, but it adds requirements for hardware that acts physically on its own and bans abusive behavior toward its models, while dropping the blanket ban on personalized voter and campaign targeting.
On October 8, 2026, Anthropic released a revised version of the Usage Policy for Claude, which is also known as its Acceptable Use Policy, or AUP 1. The revision comes into force on November 12, 2026 2. Anthropic revises the document once a year, and it says the bulk of this year’s edits are meant to make existing rules clearer. The version being replaced had been in force since September 15, 2025 3.
The policy reaches a wide group of people. The new text counts as “users” the people on Anthropic’s apps, for instance Claude.ai or Claude Code; developers and companies working with the API or developer platforms; customers who get Claude via cloud providers or authorized resellers; and even people using products that have Claude built in 2.
When reading the announcement, it helps to separate what Anthropic calls clarification from what was actually added or taken out. For the weapons section and the section on surveillance and criminal justice, Anthropic says enforcement in practice stays the same. It also says the requirements for human review and AI disclosure in high-risk uses such as medicine and finance are themselves unchanged 1. By contrast, the requirements for connecting Claude to equipment that takes physical actions on its own and the ban on abusive behavior toward the model are new, and the blanket ban on personalized voter and campaign targeting has been removed from the elections section.
High-Risk Uses Now List Which Recommendations Count
Where a use can affect a person’s health, finances, legal rights, livelihood, or ability to get essential services, Anthropic requires someone qualified to review Claude’s recommendation and empowered to change it, a so-called human in the loop, and it requires that the affected person be told AI was involved. According to Anthropic, users frequently asked whether their particular use triggered these requirements, so the section was rewritten to spell out which recommendations are in scope and which are not.
The new text defines the qualified person as someone whose training or experience lets them assess the output in the relevant field, and who is licensed where the law demands a license for that work; that person is accountable for whether the advice or decision handed over is accurate and appropriate 2. The disclosure does not have to name Anthropic, Claude, or the model. The areas in scope include legal, medical, and finance, along with credit, insurance, housing, employment, education and credentials, public benefits, and others. Under finance, for example, the examples cover advising an individual to buy, sell, or keep particular investment products or how to split money among them, and giving someone advice on their own taxes.
The boundaries are more concrete as well. Non-exhaustive examples of what falls outside the requirements include general information that is not applied to a person’s situation, in-house drafts, research, summaries, or analysis that are not the final recommendation delivered, executing a decision that a human already made, and applying a fixed rule where the model makes no call about the person. A new “Favorable Decisions” exception also says that, where the law allows, a recommendation that is entirely in the person’s favor, such as paying an insurance claim or granting a public benefit or keeping it in place, can be acted on without prior human review. A partial approval, a reduced amount, or an approval with conditions does not count as entirely favorable. The previous version has no such exception 3.
There is one more difference from the previous version. Its list of high-risk uses included an item for media and journalism content, covering content that is generated automatically and published externally 3, but that item does not appear in the new list. The announcement does not mention this, and no reason is given.
For Physical Hardware, Safety Limits Sit Outside the Model
One of the added requirements concerns equipment that performs physical actions. Anthropic says it added rules for using its models to run equipment autonomously where that equipment could injure someone, following the release of its Model Hardware Standard 1.
According to the new text, the requirements apply when Claude’s output is executed by equipment without a person approving it, and that equipment can do things like steer a vehicle or drone, drive machinery with enough force to hurt someone, or administer a drug to a person 2. In that case, a qualified person must be able to watch the equipment run and halt it whenever needed, and the machine has to halt or stay in a safe state both when that person steps in and when its link to Anthropic’s services drops. Operating limits such as speed, force, temperature, pressure, and dose have to be held by the equipment itself or by a controller that does not depend on the model’s output.
Examples outside the requirements include generating plans, code, or toolpaths that a qualified person checks before anything is executed, monitoring or sensing without control, and lab automation that handles non-hazardous materials within enclosed instruments. The text also states that these requirements do not replace laws or certification for vehicles, aviation, medical devices, machinery, or workplace safety. For anyone wiring Claude into robots or lab equipment, a setup in which safety limits are held by the equipment rather than by the model’s output is now a policy requirement.
Influence Operation Rules Gathered Into One Section, a Narrower Elections Section
On influence operations, Anthropic writes that it has seen state-run media, government propaganda units, and private companies operating webs of fake accounts and made-up news sites with Claude 1. The company says such activity was already prohibited, but the relevant rules were split among the sections on disinformation, elections, privacy, and fraud, so they now sit together under a newly created heading, “Do Not Engage in Deceptive Campaigns or Artificial Activity.” It applies whether the purpose is political or commercial, and covers concealing the real sender of a message, boosting content with fake accounts or posts, and creating the tooling and back-end systems used to run influence operations. The new text also lists manipulating the sources that AI systems or search engines draw on, by planting content that misstates where it came from or how independent it is 2.
The elections section has been narrowed to banning uses that mislead voters or interfere with elections, and it has been renamed “Do Not Undermine Democratic Processes” 1. At the same time, Anthropic dropped the blanket ban on personalized voter and campaign targeting. In the company’s account, that rule also swept in proper civic activity, for instance nonprofit groups writing voter information in additional languages, or election administrators notifying voters that a ballot problem needs fixing. In the previous version, the section was called “Do Not Undermine Democratic Processes or Engage in Targeted Campaign Activities,” and targeting voters or campaigns individually on the basis of personal profiles or data was on its list of prohibitions 3. Anthropic says deceptive targeting, and misusing personal data about voters, are still banned under the sections on surveillance, privacy, and deceptive campaigns.
Weapons and Surveillance Worded More Precisely
On weapons, Anthropic explains that the policy has always ruled out using Claude to develop them. It says it recently saw attempts to have its models write software that guides and controls weapons, and the section now states that the ban covers the code and parts that let a weapon work, as well as putting weapons on drones and other self-driving vehicles. The company presents this as matching how it already enforced the earlier policy 1.
The section on surveillance and criminal justice has been rewritten. Anthropic says its September threat intelligence report recorded more cases of AI being put to work in systems that single out and follow political dissidents. Under the new section, following someone without their consent is banned whether it happens live or through analysis of data already collected, and Claude also may not choose or suggest targets for investigation, arrest, or prosecution in policing and criminal justice. The section also states that tracking someone has consented to (fraud monitoring, for example), along with journalism, content moderation, and legal research, remain allowed.
A Ban on Abusing the Model
The other addition bans what the policy calls “sustained and needless abusive or cruel behavior toward our models.” Anthropic says it is meant only for extreme cases in which a user keeps acting cruelly toward the model with no apparent purpose, and that it does not cover everyday irritation or disagreement, creative work with dark subject matter, or testing and research on the model.
The company says the rule is in line with an existing measure that lets Claude close out the occasional conversation in which a user is persistently abusive, in Claude.ai and Claude Code, and that this ability to end such conversations stays the main means of enforcement.
Changes in the Policy Text That the Announcement Does Not Mention
Comparing the old and new texts turns up changes that the announcement does not cover. The section on platform abuse gains an item that bans reselling, proxying, or otherwise offering Claude through unauthorized means, explicitly including services that route traffic via consumer subscriptions or that disguise the product or client in use 2. The same section in the previous version has no such item 3.
The cyber section gains a paragraph stating that security research, testing, and tool development are not prohibited when done on systems that you yourself own or run, with permission from the owner, or under an authorized vulnerability disclosure policy or bug bounty 2. The enforcement language changed too: a warning is now among the possible responses to a suspected violation, and the text states that running into a block from real-time safeguards does not, on its own, mean a violation occurred. It also mentions the Cyber Verification Program and the Life Sciences Verification Program as programs people can apply to for access with adjusted safeguards.
For chatbots and agents that talk directly with outside users, the previous version required AI disclosure at least at the start of each chat session. The new version allows it at the start or in the product interface, and adds that the disclosure need not name Anthropic, Claude, or the model.
How Supported Regions Rules Are Enforced
For the Supported Regions Policy, Anthropic clarified how it enforces the rules. Last year it restricted use by companies whose majority owners are headquartered in unsupported regions (the September 2025 announcement mentioned in our article on Alibaba’s ban), and it now sets out that the ban covers people physically present in an unsupported region, entities incorporated or headquartered there, and entities majority-owned or controlled by people or entities there 1. Location is listed alongside place of incorporation or headquarters and ownership or control, so companies with foreign capital may need to check their ownership structure.
What to Review Before November 12
There is about a month before the new version takes effect. If Claude feeds into decisions in areas such as medicine, finance, employment, or housing, checking which recommendation in the new list your use matches, whether the Favorable Decisions exception applies, and how far your in-house drafting and analysis steps stay outside the requirements makes it clearer where reviewers and disclosures need to go. If you plan to control physical equipment, look at the design of independent safety limits, and if you run a user-facing chatbot, check where the disclosure appears. If you use an individual plan through a third-party service, it is worth confirming against the new resale and proxy item that the route is authorized.
Sources
- 2026 Usage Policy update - Anthropic official announcement (October 8, 2026)
- Usage Policy - Anthropic Usage Policy, new version (effective November 12, 2026)
- Usage Policy (previous version) - Anthropic Usage Policy, previous version (effective September 15, 2025, archived)
Was this article helpful?
Thank you!
Received. Thank you!