On 8 October 2026 Anthropic published the annual revision of its Usage Policy, which takes effect on 12 November. Most of the change does not invent new prohibitions: it reorders the existing ones and writes them more precisely, for a stated reason — Claude has moved on to longer tasks with less supervision, and the rules were drafted for a different kind of use. There are three substantive novelties: a dedicated section on fabricated activity campaigns, requirements for when the model drives physical equipment capable of causing harm, and a clause against sustained abuse of the model itself.
What was announced
A new section on deception. Until now, the rules against fake account networks were scattered across the elections, fraud, privacy and disinformation chapters. Anthropic has pulled them into a section of their own, under a heading that bars deceptive campaigns and artificial activity, and has extended it to any field, not just politics: commercial activity too. It covers both hiding who is behind a message and inflating its reach with invented profiles or posts, as well as building the tooling and infrastructure used to run such operations. The company justifies the change with what it says it detected over the past year: state outlets, official propaganda bureaus and private firms using Claude to sustain fake accounts and fabricated news portals, according to its September threat intelligence report.
Elections: less breadth, better aim. The elections section is renamed — it now speaks of not undermining democratic processes — and narrows to what it was really after: deceiving voters or disrupting an election. Spreading falsehoods about candidates or about how to vote, posing as a candidate or as electoral staff, or manoeuvring to keep people away from the polls. In exchange, a blanket prohibition falls away: personalised campaign targeting. Anthropic admits that rule caught legitimate civic work — an NGO translating voter information into other languages, or an administration telling a voter to cure their ballot — and notes that the behaviours which motivated the rule remain banned by other routes: deception, surveillance and privacy.
Weapons. The policy already barred developing weaponry. What is now spelled out is that the ban also reaches the software that makes a weapon work — guidance, control — and its components, as well as arming drones and other autonomous vehicles. Anthropic says it has seen concrete attempts along those lines and clarifies that this is how it was already applying the rule.
Surveillance and criminal justice. The chapter is rewritten in full to state less ambiguously what is out of bounds. Tracking a person without their consent is prohibited, whether in real time or by analysing previously gathered data. Claude cannot be used to determine or suggest who gets investigated, arrested or charged. Nor to build or improve tools designed for surveillance. In parallel, the policy spells out what remains permitted: consented tracking — fraud monitoring, for instance — content moderation, journalism and legal research.
High-risk uses. Where the system bears on someone's health, legal rights, money, livelihood or access to essential services, two existing requirements still apply: a qualified person with genuine authority to review and amend what the model proposes, and notice to the affected individual that an AI was involved. What changes is the drafting: the section now lists which kinds of recommendation are in scope and which are not, because the question kept coming up.
Hardware that moves on its own. Following the publication of its hardware standard for models, Anthropic adds conditions for when Claude is wired to equipment that performs physical actions autonomously and could injure someone. Two requirements: a qualified operator must be able to see the equipment and stop it, and the machine must be able to hold a safe state if it loses its link to the model.
Abuse of the model. Sustained, purposeless cruelty towards the models is now prohibited. Anthropic bounds the scope: it does not target the frustrated user, nor someone arguing with the model, nor dark fiction, nor testing and research. The main enforcement mechanism will remain the existing one — Claude's ability to end conversations with persistently abusive users on Claude.ai and Claude Code — rather than penalties.
Regions. The supported regions page is updated to explain how last year's rule is applied: use is barred from an unsupported region, by entities incorporated or headquartered there, and by entities controlled or majority-owned from those regions.
Context
Anthropic revises this policy once a year. The previous version introduced the restriction on companies majority-owned from unsupported regions, and kept electoral targeting under a blanket ban. The thread running through the 2026 revision is the same one running through the company's recent moves: models that work on their own for longer. A policy drafted with a chat in mind, where someone asks for a text, does not hold up the same way when the model runs a chain of actions for hours — still less when there is a robotic arm at the other end.
What it means
For anyone building on Claude, the date is what matters: 12 November. That leaves a little over a month from the announcement to check whether anything in production falls under the rewritten sections.
Three specific checks are worth doing:
- If the product decides about people — credit, hiring, diagnosis, benefits — verify that the human in the loop is not decorative. The requirement is authority to change the model's output, not merely to look at it. And that the affected person is told AI was involved.
- If the model touches hardware, you need a stop control an operator can reach and a safe state on disconnection. An agent orchestrating a machine on the assumption that the link never drops no longer complies.
- If the product does tracking, look at where consent sits. The rule draws the line at consent, not at technology: the same analysis can be permitted fraud monitoring or prohibited tracking depending on who authorised it.
There is good news for civic work too: dropping the blanket ban on electoral targeting unblocks legitimate cases that were previously caught by wording that was simply too wide.
What the announcement does not say
It gives no detail on how most of these breaches are detected, nor on what happens when one is: no scale of sanctions, no remediation windows, no appeals procedure in the text of the announcement. Nor does it clarify whether existing enterprise agreements are affected before 12 November, or whether the date applies equally across all channels.
The model-abuse clause is the haziest. "Sustained", "cruel" and "no discernible purpose" are concepts somebody has to interpret, and the announcement does not explain who or on what criteria. The company itself says it only means to reach extreme cases and that ending the conversation will remain the usual response, but that is a statement of intent, not a threshold.
As for the misuse that justifies the changes — the fake account networks, the attempts at guidance software, the systems for tracking dissidents — it all comes from Anthropic's own threat report. These are claims by an interested party: the company is at once the observer, the documenter and the rule-maker. The text also puts no numbers on how many cases there were or which countries they came from.
Finally, the announcement promises to keep adjusting the policy as capabilities and risks change, and to consult regulators, experts, civil society and users. It does not specify how that consultation is channelled, or whether future changes will carry a notice period comparable to this one's month or so.
