ANTM
PolicyAnalysis

Anthropic's 2026 Usage Policy: What Changes on November 12 and What Builders Should Check

Anthropic says most of the 2026 update clarifies existing rules. A reading of the policy text shows which parts a team building on Claude should actually check before the new version takes effect.

Editorial desk

Published 8 min read

A row of thin teal vertical lines, tall and uneven on the left and uniform on the right, passing through a glowing teal square frame with a few small coral dots inside, on a near-black background
Illustration generated with AI (FLUX.1 [schnell] (Black Forest Labs) via Cloudflare Workers AI, Apache 2.0). Prompt and direction by ANTM.

Anthropic published a new version of its Usage Policy on October 8, 2026, and it takes effect on November 12.[1] If you build a product or an agent on Claude, this document is part of your contract with the model provider, so the Anthropic Usage Policy 2026 is worth reading before the effective date rather than after a block or a suspension. This article separates what Anthropic says is new from what it says is only clarified, then turns the high-risk and agent sections into a checklist. It is a reading of the published text, not legal advice; where your use case is borderline, the policy page and your own counsel decide, not this summary.

What Anthropic says changed

The announcement opens by saying that "most of the updates in the latest version are intended to clarify existing rules," and ties the update to Claude taking on longer, more independent work.[1] It lists seven changes. The table below restates them using the announcement's own framing of new versus clarified.

AreaWhat the announcement saysNew or clarified
Deceptive activityRules scattered across elections, fraud, privacy and disinformation sections are consolidated into "Do Not Engage in Deceptive Campaigns or Artificial Activity", covering political or commercial activity.[1]Consolidation; the announcement says the activity was already prohibited
ElectionsSection renamed "Do Not Undermine Democratic Processes" and narrowed to deceiving voters or disrupting elections. The blanket ban on personalised vote and campaign targeting is removed.[1]Narrowed, with one prohibition removed
WeaponsProhibitions now state that they cover software and components that make weapons work, and actions such as arming drones.[1]Clarified; Anthropic says it reflects how the previous policy was enforced
Surveillance and law enforcementRewritten to be more precise: no tracking people without consent, no deciding or recommending who to investigate, arrest or charge, no building or improving surveillance tools.[1]Clarified; Anthropic says enforcement in practice is unchanged
High-risk use casesRewritten to list which recommendations are covered and which are not; adds controls for autonomous physical actions.[1]Requirements unchanged for advice and decisions; physical-action controls are added
Abuse of modelsNew prohibition on "sustained and needless abusive or cruel behavior toward our models".[1]New
Supported regionsThe regions page was updated to clarify enforcement of existing restrictions.[1]Clarified

The part most teams should read twice: high-risk use cases

The policy requires that when Claude is used to give a "High-risk AI Recommendation" or to control equipment capable of "High-risk Physical Actions", three controls apply.[2]

  1. Qualified human in the loop. A qualified person must meaningfully review the recommendation, with authority to change it, before it is delivered as advice or used to implement a decision. The policy defines a qualified person as someone with the training or experience to evaluate the output in that field, holding a licence where the law requires one.[2]
  2. Disclosure. The individual who receives the advice, or is the subject of the decision, must be clearly told that AI was used. You do not have to name Anthropic, Claude or the model.[2]
  3. Physical actions. A qualified individual must be able to observe the equipment and stop it at any time, the equipment must stop or hold a safe state when that person intervenes or when the connection to Anthropic's services is lost, and operating limits such as speed, force, temperature or dose must be enforced by the equipment or a controller independent of model output.[2]

The policy names eleven high-risk areas for recommendations: legal, medical (including mental health), finance, credit, insurance, housing, employment, education and credentials, healthcare access, public benefits and services, and legal status and adjudication.[2] Within each, the text is specific. For example, finance covers a personalised recommendation to buy, sell, hold or allocate among specific investment products, and advice to an individual on their own taxes; employment covers screening, ranking, advancing or rejecting candidates.[2]

The exclusions matter just as much, because they define what ordinary products can still do without a reviewer in the loop. The policy lists general or educational content (explaining what a law says or how a treatment works without applying it to the individual), wellness content, helping a person understand advice that a qualified person already gave, internal drafting or analysis that is not the final recommendation delivered, applying a fixed rule or formula where the model exercises no judgement about the individual, and business operations that do not advise or decide about a specific individual.[2] There is also a carve-out for wholly favourable decisions: where the law permits, review is not required before acting on a recommendation that is entirely in the individual's favour, such as paying an insurance claim. A partial approval, reduced amount or approval with conditions does not count as wholly favourable.[2]

Our reading: where the line falls

This section is our interpretation of the published text, not Anthropic's guidance.

  • A tool that summarises a candidate's CV for a recruiter, and leaves the shortlist to the recruiter, looks like internal analysis. A tool that ranks candidates and passes the ranking to a hiring system looks like it falls under the employment area, because ranking and screening are named explicitly.
  • A chatbot that explains how a mortgage works sits on the educational side. The same chatbot telling a named user which loan to take sits on the credit and finance side.
  • The test in the text is whether the output is applied to an individual's circumstances and used to advise or decide, not whether the subject is health, money or law.

If your product sits near that line, the safe pattern is a design where the model drafts and a qualified person decides, with a visible AI-use notice for the affected individual. That is also the pattern that matches the requirements as written.

What the update means for agents

Two parts of the policy bear directly on agent builders. First, agentic use cases "must comply with the Usage Policy", and users are responsible for ensuring that the agents they build or deploy, including actions taken through tools, browsers or connected systems, comply.[2] You cannot treat an agent's tool calls as outside the policy because a model chose them. Second, the new physical-action controls apply when model outputs are acted upon by hardware without human approval and the hardware can move through shared space, apply injurious force, control hazardous energy or materials, act on the human body, control safety systems or run industrial processes.[2] The policy also excludes cases where a qualified person reviews generated plans, code or commands before they run, and monitoring that does not control equipment.[2]

For background on how those tool actions are structured and secured, see how AI agents work, and how to secure them and what Model Context Protocol is.

Consumer-facing chatbots and agents have a separate duty: they must disclose that users are interacting with AI rather than a human, at minimum at the start of each chat session or in the product interface.[2]

Other changes that can affect a commercial product

Deceptive campaigns. The new section is not limited to politics. It lists, among others, fake personas, accounts and outlets used to mislead people about origin or about how widely a view is held (it gives sockpuppets, astroturfing, fake reviews and bots that claim to be human as examples), concealing the sponsorship of content meant to influence opinion, and building tools designed to enable such campaigns.[2] One item is notable for anyone working in search or content marketing: it lists manipulating the sources from which search engines or AI systems draw answers by seeding them with content that misrepresents its origin, authorship or independence.[2] Marketing automation that generates fake reviews or posts under invented identities is squarely in scope.

Surveillance. The list of prohibitions includes tracking a person without consent through location, biometrics, communications or online activity, in real time or by analysing previously collected data. The same section says it does not prohibit tracking individuals have agreed to, such as fraud detection or anti-money-laundering screening on a financial account, aggregated or anonymised analysis, content moderation, authorised security research, legal research by law enforcement agencies or courts, or journalism, provided these are not used for the prohibited purposes.[2]

Platform abuse. The policy continues to prohibit using outputs to train another AI model, including model distillation, without prior authorisation from Anthropic, and reselling or proxying access through unauthorised means.[2] These lines are not flagged as new in the announcement, but they affect teams that fine-tune smaller models on outputs.

Supported regions. The Supported Regions Policy applies to use by persons physically located in an unsupported region, by entities incorporated or headquartered there, and by entities majority-owned or controlled, directly or indirectly, by persons or entities in unsupported regions, including their users and personnel regardless of where those individuals are located.[3] If you resell access or have investors or parent companies abroad, check this page rather than assuming location alone decides eligibility.

Abuse of the models. The new prohibition targets "sustained and needless abusive or cruel behavior toward our models." Anthropic says it is meant for extreme cases with no discernible purpose, and not for frustration, pushback, dark creative themes or model testing and research. It adds that Claude's ability to end such conversations remains the primary enforcement mechanism.[1] For most teams this has no practical effect, but red-teaming programmes should make sure their work is plainly testing, which the announcement says is not covered.

A pre-November-12 checklist

  1. Classify each feature. For every feature that produces advice or a decision about a person, decide whether it falls in one of the eleven high-risk areas or an exclusion, and write the reasoning down.
  2. Name the qualified reviewer. For covered features, identify who reviews, what qualification or licence they hold, and what authority they have to change the output.
  3. Add the notice. Make sure the affected individual is told AI was used, and that consumer-facing chat starts with an AI disclosure.
  4. Audit agent actions. List every tool, browser and connected system your agents can act through, and confirm none moves into physical action, surveillance or deceptive activity.
  5. Check physical safety limits. If hardware is involved, confirm that stop capability and safe-state behaviour on lost connection exist, and that limits are enforced outside the model.
  6. Review ownership and access. Check your corporate structure and customers against the Supported Regions page.
  7. Re-read in November. The policy takes effect on November 12; reread the live text then, because the page you see today is the version announced on October 8.

What remains uncertain

The announcement states the intent of each change, but how Anthropic applies the policy in individual cases is not described in either page, and we have not seen enforcement data. We also did not compare the old and new texts line by line; the differences described above are those Anthropic itself identifies. Some terms, such as "meaningfully review" and "qualified person", are defined in general terms and will be interpreted case by case. For questions about hallucinated or incorrect output in high-risk settings, which is the reason such review requirements exist, see why AI models hallucinate and what reduces it.

Frequently asked questions

When does the 2026 Anthropic Usage Policy take effect?
Anthropic's announcement, dated October 8, 2026, says the updated policy takes effect on November 12.[1]
Did the high-risk use case requirements change?
Anthropic says the requirements themselves have not changed, but the section was rewritten to list which kinds of recommendations are covered and which are not.[1]
Does the policy apply to agents I build on Claude?
Yes. The policy states that users are responsible for ensuring that agents they build or deploy, including actions taken through tools, browsers or connected systems, comply with it.[2]
Is using Claude to explain how a law or medical treatment works a high-risk use?
The policy lists general information or educational content, without applying it to an individual's circumstances, among the exclusions from the high-risk requirements.[2]

The ANTM newsletter

The signal, not the noise.

Sourced AI coverage in your inbox. Double opt-in, unsubscribe in one click.

Referenced sources

  1. 1.
    2026 Usage Policy update(opens in a new tab)

    AnthropicPrimary sourcePublished Oct 8, 2026Accessed Oct 3, 2026

  2. 2.
    Usage Policy (effective November 12, 2026)(opens in a new tab)

    AnthropicPrimary sourcePublished Oct 8, 2026Accessed Oct 3, 2026

  3. 3.
    Supported Regions Policy (Supported countries and regions)(opens in a new tab)

    AnthropicPrimary sourcePublished Oct 9, 2026Accessed Oct 3, 2026

ANTM Editorial

Editorial desk

The editorial desk at AI's Next Top Model. Every article is sourced to primary documents and approved by an editor before publication. See the editorial policy for how we work.

Concentric teal orbital rings with a dashed coral line running from a small circle to a central ellipse, marked with coral ticks
Agents

How AI Agents Work, and How to Secure Them

An agent is a model that directs its own tool use. That flexibility is useful and risky. Here is how agents differ from workflows, when to use one, and the controls that matter.

Explainer4 min read