Anthropic's 2026 usage policy update: what changes on 12 November
Anthropic's annual policy refresh consolidates deception rules, adds physical-action controls for agentic Claude, and bans sustained model abuse.
Anthropic published its annual usage policy update on 8 October 2026. The new rules take effect on 12 November 2026, giving developers and operators roughly five weeks to check their products against the revised text. Most of the changes sharpen existing rules rather than invent new ones, but several are substantive enough to affect what you can ship.
A single home for anti-deception rules
The most visible structural change is a new section called “Do Not Engage in Deceptive Campaigns or Artificial Activity.” Anthropic’s previous policy already prohibited influence operations, fake accounts, and fabricated content, but those rules were spread across sections covering elections, fraud, privacy, and disinformation. Consolidating them makes the intent clearer and the scope broader: the prohibition now covers deceptive activity of any kind, political or commercial, including building the infrastructure, such as fake-account networks and automated posting tools, that makes those campaigns run.
Anthropic’s own threat intelligence work drove this change. Its September 2026 threat intelligence report documented operations in which Claude was used to rewrite fabricated news stories and distribute them across approximately 70 invented news websites, amplified by 70 linked X/Twitter accounts and more than 250 inauthentic commenting accounts. The policy already caught that behaviour. The new section makes it harder to miss.
The elections section has been renamed “Do Not Undermine Democratic Processes” and is now focused specifically on voter deception: spreading false information about candidates or voting procedures, impersonating candidates or officials, and suppressing turnout. One notable relaxation is that Anthropic has dropped its blanket ban on personalised vote and campaign targeting. The old wording was broad enough to catch legitimate civic work, such as translating voter information or notifying people that a postal ballot needed correcting. Deceptive targeting and misuse of voters’ personal data remain prohibited under other sections.
New controls when Claude takes physical action
Claude is increasingly used in agentic settings, including robotics and hardware control. The updated policy adds explicit requirements for deployments where Claude takes autonomous physical actions that could cause injury.
A qualified operator must be able to observe the equipment and stop it if needed. The equipment itself must be able to hold a safe state if Claude is disconnected. These requirements do not apply where a qualified person reviews commands before they are executed, so purely advisory or pre-approved workflows are not affected.
The weapons section has also been tightened. Anthropic’s policy has always prohibited using Claude to develop weapons, but people have attempted to use models to build guidance and control software for weapons systems. The updated text makes clear that the prohibition covers the software and components that make weapons function, including arming drones and other autonomous vehicles.
What this means for you: If you are building on the Claude API and your product connects to any hardware that acts in the physical world, check whether a qualified operator can observe and halt that hardware, and whether it fails safely if the Claude connection drops. Robotics and automation builders have until 12 November 2026 to verify this.
High-risk decisions need a human reviewer and a disclosure
When Claude is used in ways that affect someone’s health, legal rights, finances, livelihood, or access to essential services, the policy now requires two things: a qualified human with authority to review and override Claude’s output, and a clear notice to the person affected that AI was used. This applies to internal tools as well as customer-facing products.
Anthropic has named specific categories as high-risk from 12 November: candidate screening, loan pricing, and insurance claim decisions are among them. If your product touches any of these areas, you need both a human review step and a disclosure mechanism in place before the deadline.
Surveillance rules sharpened
The revised policy clarifies that monitoring individuals without their knowledge or consent is prohibited regardless of whether it happens in real time or draws on historically collected data. Claude may not play a role in determining or advising on who should be investigated, arrested, or prosecuted. The intent is to close workarounds where historical data collection was used to sidestep live-monitoring restrictions.
You cannot persistently abuse Claude
A new rule prohibits sustained and needless abusive or cruel behaviour toward Anthropic’s models. Anthropic is careful to scope this narrowly: it applies only in extreme cases where users “repeatedly act cruelly toward our models, with no discernible purpose.” It excludes user frustration, pushback, dark creative themes, and model testing and research.
The enforcement mechanism already exists. Since August 2026, Claude models have been able to end conversations with persistently abusive users on Claude.ai and Claude Code. The updated policy now makes that behaviour an explicit rule with consequences ranging from conversation termination to account suspension or permanent bans.
This is worth noting not because it will affect most users but because of where it sits in the document. Anthropic is treating hostile treatment of a model as a policy matter in the same document that covers weapons and election interference. That is a deliberate signal about how the company thinks about Claude’s status.
Supported regions now covers ownership, not just location
The Supported Regions Policy has been extended to cover companies majority-owned or controlled from unsupported regions, not just users physically located there. If your organisation has complex ownership structures, it is worth checking whether this affects your access.
The practical checklist
If you are building on the Claude API, the five areas most likely to require action before 12 November 2026 are:
- Agentic hardware deployments. Ensure a qualified operator can observe and halt any Claude-connected equipment, and that the equipment holds a safe state on disconnection.
- High-risk consumer decisions. Add a qualified human reviewer and an AI-use disclosure for any product touching health, finance, legal rights, livelihood, or essential services, including candidate screening, loan pricing, and claims decisions.
- Influence and content tools. Review any product that generates or distributes content at scale against the new consolidated deception section.
- Election or civic tools. The personalised targeting relaxation is genuine, but the remaining prohibitions on voter deception, impersonation, and data misuse are sharper than before.
- Ownership structures. If your organisation has majority ownership or control from a region not on Anthropic’s supported list, confirm your access position.
The full updated policy is at anthropic.com/aup. Anthropic’s September 2026 threat intelligence report, which documents the misuse patterns that informed several of these changes, is at anthropic.com/threat-intelligence-report-september-2026.