Anthropic published its 2026 Usage Policy update on 8 October 2026, and the new text takes effect on 12 November 2026. The policy is Anthropic's terms of use rather than a law, and it applies to every company that builds on Claude and to the end users of products that integrate it. Most of the changes clarify existing rules for Claude doing longer, more independent work. Two parts change what an agent operator has to build: the rewritten high-risk requirements and new controls for models connected to physical hardware.
Who The Policy Covers
The Usage Policy applies to anyone who submits inputs to Anthropic's products: people using Claude.ai and Claude Code, developers and businesses on the API, customers reaching Claude through cloud providers and authorized resellers, and the end users of products that integrate Claude. The page is marked effective 12 November 2026.
For agents, the policy says users are responsible for making sure that agents they build or deploy comply, "including actions those agents take through tools, browsers, or connected systems." Consumer-facing chatbots and agents that talk directly to external users must disclose that the user is talking to AI, at least at the start of each session or in the product interface. If Anthropic suspects a violation, it may warn, throttle, limit, suspend or terminate access.
What Anthropic Says Changed
Anthropic's announcement lists these changes:
- Deceptive campaigns: rules that were spread across the elections, fraud, privacy and disinformation sections now sit in one section, Do Not Engage in Deceptive Campaigns or Artificial Activity. It covers political and commercial activity: hiding who is behind a message, amplifying content through fake accounts or posts, and building the tools and infrastructure for influence operations.
- Elections: the section is renamed Do Not Undermine Democratic Processes and focuses on deceiving voters or disrupting elections. The blanket ban on personalized vote and campaign targeting is gone, because it caught civic work such as translated voter information and ballot cure notices.
- Weapons: the prohibition now names the software and components that make weapons work, and arming drones and other autonomous vehicles. Anthropic says this reflects how it already enforced the old policy.
- Surveillance and law enforcement: tracking people without consent is prohibited whether it happens live or through analysis of data already collected. Claude cannot decide or recommend who to investigate, arrest or charge, or be used to build or improve surveillance tools. Tracking people have agreed to, such as fraud monitoring, plus content moderation, journalism and legal research remain permitted.
- Abuse of the models: a new prohibition on sustained and needless abusive or cruel behavior toward Claude, which Anthropic says applies only in extreme cases.
- Supported regions: the policy bars use by people physically located in an unsupported region, by entities incorporated or headquartered in one, and by entities majority-owned or controlled from one.
High-Risk Recommendations
The requirements here have not changed, according to Anthropic. The section was rewritten to answer more directly which uses they cover. When a product makes a High-risk AI Recommendation, the policy requires two controls:
- A qualified person reviews the recommendation, with authority to change it, before it is delivered as advice or used to implement a decision. The policy defines qualified as having the training or experience to evaluate the output in that field, plus a licence where the law requires one. That person stays responsible for what is delivered or decided.
- The individual who gets the advice, or who is the subject of the decision, is clearly told that AI was used. The disclosure does not have to name Anthropic, Claude or the model.
The policy lists eleven High-risk Areas: legal, medical, finance, credit, insurance, housing, employment, education and credentials, healthcare access, public benefits and services, and legal status and adjudication. Each area comes with examples, such as screening or rejecting job candidates, setting a credit limit, or determining the outcome of an insurance claim.
The policy also lists exclusions. Among them: internal drafting, research or analysis that is not the final recommendation delivered; carrying out a decision a person has already made; applying a fixed rule or formula where the model exercises no judgment about the individual; and business operations that do not advise or decide about a specific person. Where the law permits, a decision wholly favorable to the individual, such as paying an insurance claim, can go ahead without the human review step. A partial approval does not count as wholly favorable.
Models Connected To Hardware
Following its Model Hardware Standard, Anthropic added requirements for High-risk Physical Actions. They apply when hardware acts on Claude's output without human approval and the equipment can move through shared space, apply force that could cause injury, control hazardous energy or materials, act on the human body, control safety systems, or run industrial processes where a fault could injure someone.
- A qualified individual must be able to observe the equipment and stop it at any time.
- The equipment must stop or hold a safe state when that person intervenes or when the connection to Anthropic's services is lost.
- Operating limits such as speed, force, reach, temperature, pressure or dose must be enforced by the equipment or by a controller independent of model output.
Excluded: plans, code, toolpaths or commands that a qualified person reviews before they run on equipment; monitoring or reporting without control; consumer devices operating within the manufacturer's built-in safety limits; and lab automation handling non-hazardous materials inside enclosed instruments.
What Operators Should Change Before 12 November
- List every output your Claude-based agents deliver to or about a specific person, and mark the ones that fall in the eleven High-risk Areas.
- For those, put a qualified reviewer with authority to change the output before it is delivered or acted on, and tell the affected person that AI was used.
- Check that every external-facing agent discloses that it is AI at the start of each session or in the interface.
- If an agent drives hardware without human approval, add a stop that a qualified person can use at any time, a safe state on disconnect, and limits enforced outside the model.
- Record who was in the loop for each high-risk output, so you can show the review happened.
What This Does Not Settle
- The Usage Policy is a contract term for Anthropic's products. The policy itself says the high-risk requirements do not replace local law, and that for physical devices they do not replace vehicle, aviation, medical device, machinery or workplace safety law or certification.
- Companies building on other model providers are bound by those providers' terms, not this one.
- This note relies on Anthropic's own summary of what changed. It does not compare the new policy line by line with the previous version.
Related: The deployer assurance checklist covers human review and disclosure duties from the regulator side. See also our notes on Anthropic's verified cyber access tiers and Project Fetch and physical autonomy.