P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Anthropic's new Usage Policy is 79% longer and takes effect 35 days after it was posted

Anthropic's post of 8 October says most updates to its Usage Policy clarify existing rules. A diff of the two texts finds 1,951 more words, a rewritten high-risk section, and no audit, notice or opt-out stated in the pages read.

By Parminder Kumar Sharma · · 32 min read

A compliance desk at dusk with a thin and a thick printed policy document, a printed checklist with empty boxes, a blank approval card, an open laptop showing a blank document viewer and a small red emergency-stop button. No people. Overlaid text reads Usage Policy: 79% longer, effective 12 November, plus 79%, our word count 4,424 against 2,473.

35 days and 1,951 more words

Anthropic published a new version of its Usage Policy on 8 October 2026, effective 12 November. That is 35 days from publication to effect (derived: 23 days left in October plus 12 in November). The new text runs to 4,424 words against 2,473 in the version in force since 15 September 2025: 1,951 words more, or 78.9 per cent (derived, from our own count and diff, saved with the sources). In the Universal Usage Standards one section is added, none is removed and five are renamed in wording. Anthropic's announcement says: "Most of the updates in the latest version are intended to clarify existing rules."

That fact does not settle whether the change is clarification. A longer text can add examples without adding rules, and a short deletion can remove a rule. The word count also says nothing about enforcement: how Anthropic detects, judges or acts on any line of the policy is in neither document. What follows compares the two texts section by section, sets each change against what the post says about it, and lists what neither document states. It makes no claim about what Anthropic does in practice.

Anthropic wrote both the policy and the post that summarises it, and sells the product the policy governs, so the post is its own account of its own text. The second half is for UK organisations that build on Claude: where the new high-risk and disclosure requirements meet UK data protection and sector guidance, what the ownership test means for a company with overseas shareholders, and the register to keep before 12 November.

What changed, against what the post says

The post describes eight changes. The table sets each beside the policy text as compared line by line. The middle column paraphrases the post. The right column is what the two versions show.

Anthropic's eight described changes, set against the old and new policy texts. Sources: the post of 8 October 2026, the version effective 15 September 2025 and the version effective 12 November 2026, compared by script.

AreaWhat the post saysWhat the two texts show
Deceptive activityA new section consolidates rules that were scattered across elections, fraud, privacy and disinformation, and covers deceptive activity of any kind, political or commercial.A new section, Do Not Engage in Deceptive Campaigns or Artificial Activity, with six bullets. Old bullets on artificial political movements, fake reviews and posing as human are folded in. One bullet has no old counterpart: seeding "the sources from which search engines or AI systems draw answers" with content that misrepresents its origin.
ElectionsRenamed Do Not Undermine Democratic Processes. The blanket prohibition on personalized vote and campaign targeting is removed because it covered legitimate civic work. Deceptive targeting and misuse of personal data stay prohibited elsewhere.Renamed, and the targeting bullet is gone: no sentence in the new text mentions targeting voters or campaigns. The old bullet on lobbying with fabricated information also has no counterpart; the general bullet on false information in political and electoral contexts is unchanged. This is a removed prohibition, which the post says in so many words.
WeaponsProhibitions now cover guidance and control software and arming drones and other autonomous vehicles. The changes reflect how Anthropic enforced the previous policy.None of the four old bullets survives intact; six new ones stand in their place. New words include "test", "operate", "deploy", "plan the deployment", "retrofitted hardware", "targeting, fire control, or engagement" and "drones, vehicles, or any unmanned or autonomous platforms". The weapons bullets do not use the post's word "guidance".
Surveillance and criminal justiceRewritten to be more precise: no tracking without consent, no deciding or recommending who to investigate, arrest or charge, no building or improving surveillance tools, with permitted uses listed. It "does not reflect a change in what we enforce in practice".The text goes further than the summary. It bars making or suggesting decisions to "investigate, charge, arrest or detain, prosecute, sentence, or grant or revoke early or conditional release"; the old bullet named parole and sentencing. The tools bullet covers tools "designed for the surveillance uses prohibited in this section", narrower than the post's "tools designed for surveillance". The permitted-uses paragraph is new.
High-risk use casesThe human-in-the-loop and disclosure requirements "haven't changed". The section was rewritten to list which recommendations are covered and which are not.Rewritten from 354 to 1,447 words, 4.1 times and 56 per cent of all the words added (derived). Seven categories become eleven areas, one old category is gone, and exclusions and a favourable-decisions exemption are new. The wording of both requirements differs. See the next section.
HardwareNew requirements where Claude is connected to hardware taking autonomous physical actions: a qualified operator able to observe and stop it, and a safe state if Claude is disconnected.Six hardware categories trigger the requirement and four exclusions apply. The text adds a third part the post does not mention: operating limits such as speed, force, temperature or dose must be "enforced by the equipment or a controller independent of model output".
Abuse toward modelsA new prohibition on sustained and needless abusive or cruel behaviour toward the models, for extreme cases. Claude ending conversations "will remain the primary enforcement mechanism".The last bullet of the renamed section Do Not Engage in Cruel, Abusive, or Psychologically Harmful Conduct. The post says the ability to end conversations is on Claude.ai and Claude Code. The [page it links](https://www.anthropic.com/research/end-subset-conversations), of 15 August 2025, describes it for Claude Opus 4 and 4.1 in consumer chat interfaces and names neither Claude Code nor the API.
Supported RegionsEnforcement clarified: use by people physically in an unsupported region, by entities incorporated or headquartered there, and by entities majority-owned or controlled by persons or entities there is prohibited.The page matches the post. Before, one sentence reserved the right to refuse entities whose "majority direct or indirect ownership is attributable" to unlisted nations, "to the extent permitted by law". The list of 185 countries is unchanged. See the Supported Regions section.

Across the Universal Usage Standards, 35 of the 82 old bullets survive word for word (42.7 per cent) and 23 more are reworded; 24 have no close match in the new text, and 30 of the 88 new bullets have no close match in the old (derived by script, matching at a text similarity of 0.55 or above, so a heavily rewritten bullet counts as one removed and one added). So 58 of 82 old bullets, 70.7 per cent, survive intact or reworded. That is consistent with "most". The 24 are where the questions are: all four weapons bullets, four of eight election bullets, five of thirteen fraud bullets and two of seven surveillance bullets.

Anthropic's own September report supports part of the "no change in enforcement" claim, on Anthropic's account and unchecked by anyone else. The report covers activity disrupted between December 2025 and August 2026, under the 2025 policy, and says of its surveillance cases that "in every case" the actors violated the Usage Policy, and of its weapons cases that they misused Claude in violation of it. It names actors and individuals; this briefing prints none. It also says its safeguards blocked many requests in a weapons case "but not all". The text comparison can show that the new wording is more explicit. It cannot show what was enforced before.

The text also contains changes the post does not mention. The table lists those that a UK organisation building on Claude is most likely to meet.

Changes in the new text that the post of 8 October does not mention. Source: the two policy versions compared line by line.

WhereNew textOld text
Enforcement trigger"If we suspect that you may have violated our Usage Policy", Anthropic may "warn" as well as throttle, limit, suspend or terminate. Encountering a real-time block "does not by itself indicate a violation"."If we learn that you have violated our Usage Policy", then throttle, suspend or terminate.
Computer and network systemsHeading now ends "Without Authorization". A new paragraph says the section does not prohibit security research, testing or tool development on systems you own or operate, with the owner's authorisation, or in an authorised bug bounty or disclosure policy. It points to the Cyber Verification Program. Three bullets gain an authorisation qualifier: persistent access tools, automated tools at scale, and bypassing security controls.No such paragraph. Only three bullets carried an authorisation qualifier: discovering vulnerabilities, gaining access and interception tools.
Platform abuse"or create multiple accounts" is added to an existing bullet. New bullets cover stolen or unauthorised payment methods and "Resell, proxy, or otherwise provide access to Claude through unauthorized means". The training bullet covers "outputs" only.No bullet on payment or resale. The training bullet read "inputs and outputs".
Harmful conduct and biasNon-consensual intimate imagery is named. "caste, or disability" join the protected attributes, and "any other identifying trait" is dropped.Neither named.
DisinformationThe impersonation bullet adds that it "does not prohibit clearly disclosed parody, satire, or fiction".No such carve-out.
Chatbots and agentsDisclosure may be given "in the product interface" as well as at session start. Users are responsible for what their agents do "through tools, browsers, or connected systems".Disclosure at "the beginning of each chat session". Agent use "must still comply".
Scope sentenceApplies to "customers accessing Claude through cloud providers and authorized resellers", individuals using Claude.ai and Claude Code, and "the end users of products or services integrating Claude".Applied to anyone who can submit inputs, "including via any authorized resellers or passthrough access".

The high-risk section, old against new

The post says the requirements "haven't changed" and that the rewrite answers a question customers kept asking: whether a given use case has them. Both can be true of intent. The words differ in ways the post does not list. The table puts the two versions side by side, with the covering words quoted briefly.

The high-risk section in the version effective 15 September 2025 and the version effective 12 November 2026. Quotes are from the policy pages read on 9 October 2026.

ItemEffective 15 September 2025Effective 12 November 2026
Who is coveredIntroduced as applying to "specific consumer-facing use cases". Human review applies to advice or decisions "directly affecting individuals or consumers".Applies to "anyone who uses our products to make a High-risk AI Recommendation or control equipment capable of High-risk Physical Actions". The words "consumer-facing" are gone from the section.
Human reviewA "qualified professional in that field must review the content or decision prior to dissemination or finalization".A qualified person "must meaningfully review" the recommendation, "with the authority to change or modify it", before it is delivered to someone who might rely on it or used to implement a decision.
Who is qualifiedNot defined.Someone with "the training or experience to evaluate the output in that field", who "holds a license where applicable law requires one". The person "remains responsible".
DisclosureIf outputs are "presented directly to individuals or consumers", disclose AI use, "at a minimum at the beginning of each session".An individual who receives advice "or who is the subject of a decision" must be "clearly told that AI was used". No timing is given. Users "do not need to identify Anthropic, Claude, or the model used".
What is coveredSeven categories, each phrased as "use cases related to": legal, healthcare, insurance, finance, employment and housing, academic testing and admissions, and media.Eleven High-risk Areas, each defined by the action taken: legal, medical, finance, credit, insurance, housing, employment, education and credentials, healthcare access, public benefits and services, legal status and adjudication.
Media and journalism"Media or professional journalistic content": use cases that "automatically generate content and publish it for external consumption".No such area. The post does not mention its removal.
What is not coveredWellness advice is excluded from healthcare.Six exclusions, including general information "without applying it to the individual's circumstances", internal drafting or summarisation, and "applying a fixed rule, formula, or algorithm where the model exercises no judgment about the individual".
Favourable decisionsNothing.Where permitted by law, no human review is needed for a recommendation "wholly favorable to the individual": paying an insurance claim, approving care a clinician ordered, granting eligibility for a healthcare service, granting or continuing a public benefit. A "partial approval, reduced amount, or approval with conditions" is not wholly favourable.
Physical actionsNothing.Six hardware categories, four exclusions and a requirement with three parts. See the next section.

What the covering words do. The old test was whether a use case was "related to" a domain. The new test is whether the product provides a recommendation of a named kind. In employment that is "screening, ranking, advancing, or rejecting candidates", in public benefits "determining eligibility for, or the amount of, government benefits", in credit "approving, denying, or setting the amount, rate, or limit of a loan". A tool that helps a human draft sits outside. A tool that ranks candidates sits inside. A tool that applies a fixed rule sits outside this policy's human-review test, which is not the same as sitting outside UK law, as the UK section shows.

What the rewrite widens and narrows. Public benefits and services and legal status and adjudication, including immigration, asylum and citizenship, have no category in the old list. On the words, the old "related to" wording caught a legal research tool; the new exclusion for internal research and drafting probably does not (our inference). The old section described itself as consumer-facing; the new one does not, and its disclosure duty reaches "the subject of a decision", such as a job applicant who never saw the output (our reading of the words; Anthropic does not say so).

What is gone. On the words, a publisher that used Claude to generate content and publish it automatically was inside the old requirements. It is not inside the new list, and the post is silent on why. The consumer-facing chatbot disclosure and the deception rules still apply. Whether any publisher was ever treated as inside the old category is not stated.

"Human in the loop" is a label, not a control. The text gives the label three properties: the person is qualified, reviews "meaningfully", and can change the recommendation before it reaches anyone. It names no way to evidence any of the three, asks for no record of a review, and says nothing about the volume a reviewer can meaningfully handle. A rubber stamp satisfies the label and fails the sentence.

Hardware: three parts to the requirement, one not in the post

The post names two parts of the hardware requirement: a qualified operator who can observe and stop the equipment, and a safe state if Claude is disconnected. The policy has three. The text says the equipment "must stop or hold a safe state when that individual intervenes or when connection to our services is lost", and the operator can "stop it at any time". The third part is the one the post leaves out: operating limits for speed, force, reach, temperature, pressure, voltage, energy output, dose or operating area must be "enforced by the equipment or a controller independent of model output". A limit that lives in a prompt, or in the model's own judgement, does not meet that sentence.

The requirements apply where outputs "are acted upon by hardware without human approval" and the hardware or linked equipment can do one of six things: move through shared space, apply force that could cause injury, control hazardous energy or materials, act on the human body, control safety systems, or run industrial processes. Four exclusions apply, among them "Generating plans, code, toolpaths, waypoints, or commands that a qualified person reviews before they are executed on equipment". A coding agent that writes control code for a person to review is outside. The same agent wired to run it is inside, if the equipment falls in one of the six categories.

The Model Hardware Standard that the post links is a different thing. Anthropic's page of 27 August 2026 describes a shared specification for agents operating lab and manufacturing devices, opened as a research preview to a first group. It says its drivers record "what safety limits will be enforced", a partner says it "enforces device-level safety limits", and Anthropic says it is developing a "physical safety roadmap". It does not mention a qualified operator or a safe state on disconnection, and does not say that its limits meet the policy's test of being independent of model output. The policy text does not mention the standard. So the requirement applies to any use of Claude to control such equipment, whether or not the standard is involved (our reading).

The NCSC's blog of 20 August 2026 separates "Human-in-the-loop: humans approve actions before they happen" from "Human-on-the-loop: humans monitor actions and can intervene if needed". The policy asks for the first for advice and decisions, and for the second plus hard limits for physical action. For higher-risk cases the NCSC recommends "human oversight alongside technically enforced controls", and says to keep the ability to "pull the plug". That is the closest UK source read to the policy's independent limits. The HSE and machinery law were not read here; the policy itself says its requirements do not replace "vehicle, aviation, medical device, machinery, or workplace safety law or certification".

What the documents do not establish

The table sets what is stated, with its source, against what is not. The gaps are the ones that decide how much weight a customer can put on any of the new wording. The policy does define "qualified", which the post does not; what it does not say is how anyone checks.

What the documents read state and do not state, for the questions a customer would ask. Sources: the policy, the post, the Supported Regions page and the Commercial Terms, read on 9 October 2026.

QuestionStatedNot stated
What does "qualified" mean?The policy: "the training or experience to evaluate the output in that field", licensed "where applicable law requires one".Any standard, credential list or evidence test. Who decides whether a given person meets it.
Who checks the human in the loop?The qualified person "remains responsible". Anthropic's Safeguards Team "implements detection and monitoring". The Commercial Terms (D.2) require a customer to answer "reasonable requests for information" to verify "identity and use".How detection could see a review that happens outside Claude. Whether Anthropic audits, asks for evidence or relies on attestation. What it asks for in practice.
What must "told that AI was used" look like?"Clearly told". No need to name Anthropic, Claude or the model. For chatbots: at session start or "in the product interface".Wording, timing for decisions, medium, language, or whether a line in terms and conditions counts.
How is majority ownership or control measured?"Majority-owned or controlled, directly or indirectly, by persons or entities in unsupported regions". Anthropic's post of 4 September 2025 said "more than 50% owned".A threshold on the page. What "controlled" means. Look-through rules, treatment of funds or dispersed holders, evidence required, or how often it is checked.
Do customers get notice or an opt-out before 12 November?Commercial Terms M.3: updates to "these Terms" take effect 30 days after posting "or Customer otherwise receives Notice". Either side may end the agreement for convenience with Notice (I.2.a).Any individual notice of this change. An opt-out. A grace period. That M.3 governs the policy, which the Terms incorporate by reference. The policy's own update sentence promises no notice.
Which text governs from 8 October to 12 November?The new page: "Effective November 12, 2026". The old page: "replaced by a newer version". The post: "takes effect on November 12".A sentence saying the 2025 text governs until then. That is the natural reading, not a stated rule.
How does it apply through a cloud provider?The policy applies to customers "accessing Claude through cloud providers and authorized resellers". The Supported Regions page covers models "offered through cloud platforms and authorized resellers".Which contract carries the policy on Bedrock, Vertex AI or Foundry, from what date, who enforces it and who notifies. See the Supported Regions section.
Is there a change log?Each policy page links "Previous Version". The chain reaches four earlier versions.A change log, redline or summary beyond the post. A notification list.
What enforces the new abuse prohibition for API products?Claude ending conversations "will remain the primary enforcement mechanism", on Claude.ai and Claude Code.Whether that ability applies to API traffic. The page it links describes consumer interfaces.
How is any of this enforced?Anthropic "may warn you or throttle, limit, suspend, or terminate". The Terms (I.3.a) allow suspension if Anthropic "reasonably believes or determines" a violation.Thresholds, evidence standards, appeals, or timing. Anthropic has not published how well its detection works: see [our earlier briefing](https://www.pk-sharma.com/briefing/the-number-not-published) on its agent oversight metrics.

The Commercial Terms page read is headed "Effective June 17, 2025", so it shows no change to the contract text in step with the policy. The contracting party for a customer resident in the EEA, Switzerland or UK is "Anthropic Ireland, Limited" under the Terms, which matters for who sends a notice and to whom.

Supported Regions: the ownership test as written, and the cloud routes

The Supported Regions page now says that any country or region not listed is unsupported, and that this includes three things: use by persons "while physically located in an unsupported region, including users and personnel of otherwise supported entities"; use by entities "incorporated or headquartered" in one and their users or personnel, "regardless of whether such individuals are physically located in a supported region"; and use by entities "majority-owned or controlled, directly or indirectly, by persons or entities in unsupported regions". The United Kingdom is on the list of 185 countries. The post's description matches the page.

Against an Internet Archive capture of 2 October 2026, the list is the same set of 185 (the old page had two identical lists, one for the API and one for Claude.ai, and the new has one; derived by comparing them). The prose changed. Before, a single sentence reserved the right not to serve entities "whose majority direct or indirect ownership is attributable" to unlisted nations "to the extent permitted by law". Now there are three limbs, the words "or controlled" and "persons" are added, personnel are covered wherever located, and the qualifier "to the extent permitted by law" is gone. Anthropic's post of 4 September 2025 put the test as entities "more than 50% owned, directly or indirectly" by companies headquartered in unsupported regions, and named China as an example. The page itself prints no percentage.

This briefing makes no claim about any named company. It does not say who is or is not caught, and nothing here is advice on any shareholder. The point is structural. A UK company is in a listed country, so it is not itself an unsupported entity. The third limb turns on who owns or controls it, and the page gives no threshold, no definition of control and no method. Three consequences follow from the words alone.

First, a company with overseas shareholders cannot read its own position off the page. It can only record what it knows. UK companies already have to identify individuals who hold more than 25 per cent of shares or voting rights, who can appoint or remove a majority of the board, or who exercise significant influence or control, under the people with significant control summary guidance (published 19 November 2025). That register names people at a 25 per cent threshold. Anthropic's page speaks of persons or entities and of majority or control, so the register is a starting point for the question and not Anthropic's test, and no one should read it as a safe harbour.

Second, the first limb is about where a person sits, not who employs them: it covers "users and personnel of otherwise supported entities". On its words, a UK company's own staff or contractors using Claude while physically in an unsupported region are within it. Travel, remote contractors and offshore development teams belong in the register. Third, the page says nothing on how a customer would be asked to show its position, so the written question to the supplier is part of the work.

Through a cloud provider, the pages read say only this.

What the policy and the platform pages say about reaching Claude through a cloud provider. Pages read on 9 October 2026; nothing is inferred beyond the words.

RouteWhat the pages sayNot stated
Policy and Supported Regions pageBoth say they apply to customers using Claude through cloud providers and authorized resellers.The contract that carries them, the date, who enforces, who notifies.
Amazon BedrockAnthropic's [docs](https://platform.claude.com/docs/en/build-with-claude/claude-in-amazon-bedrock) say data handling "is governed by Amazon Bedrock". AWS's [Service Terms](https://aws.amazon.com/service-terms/) call third-party models "Third-Party Content" and say "you agree to the applicable terms here"; for certain models, abuse detection stores inputs and outputs for up to 30 days to detect violations of AWS's or third-party model providers' "terms of service or use policies".Whether Anthropic's Usage Policy is among "the applicable terms" for Bedrock customers, and from what date.
Claude Platform on AWSAnthropic's [docs](https://platform.claude.com/docs/en/build-with-claude/claude-platform-on-aws) say setup "accepts Anthropic's Commercial Terms of Service and Usage Policy". AWS's Service Terms 50.16.1 say use "is subject to" them.Any difference in notice from a direct customer.
Google Cloud (Vertex AI)Anthropic's [docs](https://platform.claude.com/docs/en/build-with-claude/claude-on-vertex-ai) say data handling "is governed by Google Cloud". Google's [page](https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/partner-models/claude) says availability is subject to "Separate Offerings" terms "and separate terms found in the relevant model card".The model card terms, which were not read.
Microsoft FoundryAnthropic's [docs](https://platform.claude.com/docs/en/build-with-claude/claude-in-microsoft-foundry) say Anthropic is "an independent processor for Microsoft" and customers are "subject to Anthropic's data use terms". Microsoft's [page](https://learn.microsoft.com/en-us/azure/foundry/foundry-models/how-to/use-foundry-models-claude) says Anthropic's Supported Regions Policy "may apply" to availability.Whether the Usage Policy binds Foundry customers directly, and the date.

So the pages read state that the policy applies on the cloud routes and say nothing about how. For a customer whose contract is with the cloud provider, the Anthropic Commercial Terms clause on 30 days is not shown to apply to them. The date, the notice and the enforcer are three written questions for the account team.

The 35-day clock, and what a customer can do on it

The diagram draws the clock from the pages read. Solid boxes are stated. Dashed boxes are what a customer would want to know and the pages do not say. The two dates are the only fixed points.

A tall timeline of ten boxes. Stated: the previous Usage Policy effective 15 September 2025; a 7 October capture still showing it; the post and new text on 8 October, day 0; the new policy effective 12 November, day 35. Derived: 7 November, 30 days after posting. Not stated, dashed: notice to each customer, opt-out or grace period, which text governs until 12 November, dates on cloud routes, and how enforcement works.
Drawn from the Anthropic post and policy pages, the Commercial Terms (effective 17 June 2025) and an Internet Archive capture, read on 9 October 2026.

The Commercial Terms say Anthropic may update them "at any time", effective 30 days after posting or notice, with changes not retroactive. Posting on 8 October and an effective date of 12 November is 5 days beyond that period (derived: 30 days after 8 October is 7 November). Whether that clause governs the policy is not stated: the Terms list the Usage Policy among the documents "incorporated by reference", but the update clause speaks of "these Terms". What a customer can do within the Terms is end the agreement for convenience with Notice. That is an exit, not an opt-out of one provision, and the pages read offer nothing between the two.

UK: where the policy meets UK law and guidance

The policy is a supplier's contractual condition. UK law applies to the organisation using Claude whatever the policy says, and the policy says so itself: the high-risk requirements "do not replace local legal requirements" and users "should always default to following local laws". No page read says that a vendor's usage policy changes a UK controller's duties. The table sets each requirement beside the UK source read for it, and says where they overlap and where they do not.

Where Anthropic's requirements meet UK law and guidance. Sources read on 9 October 2026: legislation.gov.uk, ICO, FCA, NCSC, DSIT.

Policy requirementUK source readWhat they share and do not share
Qualified human reviews a recommendation, with authority to change itUK GDPR Articles 22A to 22D, as substituted by [section 80](https://www.legislation.gov.uk/ukpga/2025/18/section/80) of the Data (Use and Access) Act 2025. ICO [draft guidance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/automated-decision-making/what-does-the-uk-gdpr-say-about-adm/), updated 31 March 2026 for the Act.Both want review with authority to change. The Act defines a decision as solely automated if there is "no meaningful human involvement". The ICO says involvement must be "active and not just a token gesture", by a person "suitably trained and qualified to understand the system's logic, outputs, limitations, and risks", applied "every time", with ad hoc spot-checking, in its words, not "sufficient", and a record kept of how the human was involved. The policy's qualification is about the field, not the system, and it asks for no record. Passing one test does not pass the other.
Individual told that AI was usedArticle 22C(2): information about decisions, the chance to make representations, to obtain human intervention and to contest. ICO [safeguards page](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/automated-decision-making/what-are-the-adm-safeguards/).The policy asks for notice that AI was used. Article 22C asks for information about the decision itself and routes to a person and to challenge, for solely automated significant decisions. A banner saying AI was used satisfies at most part of the first of the four, and says nothing of the other three.
Fixed rules and wholly favourable decisions skip the policy's human reviewArticle 22A: a "significant decision" has "a legal effect" or "a similarly significant effect". The law-enforcement counterpart in the same section says "adverse"; Article 22A does not. ICO examples of automated decisions include automatic benefit entitlement.An exemption in the vendor's policy is not an exemption in UK law. A favourable decision can still be significant, and a fixed algorithm making it is the paradigm of a solely automated one. The ICO lists "provision" as well as denial of insurance or benefits among significant effects.
Special category data in a decisionArticle 22B: a significant decision based wholly or partly on special category data may not be solely automated unless explicit consent, or contract or legal authority with an Article 9(2)(g) condition.The policy is silent. Medical and healthcare-access uses will often involve health data; Article 9 itself was not read for this briefing, so check which categories apply.
Finance and credit areasFCA [AI approach page](https://www.fca.org.uk/firms/innovation/ai-approach), last updated 2 October 2026: "We do not plan to introduce extra regulations for AI." It points to the [Consumer Duty](https://www.fca.org.uk/firms/consumer-duty) and the Senior Managers and Certification Regime.The FCA page defines no "qualified person" and says nothing of vendor policies. The policy defers to licensing "where applicable law requires one", so who is qualified is a question of that law, not of the policy.
Employment area[Equality Act 2010 section 19](https://www.legislation.gov.uk/ukpga/2010/15/section/19) on indirect discrimination.The section turns on a "provision, criterion or practice" and puts the burden on the person applying it to show it is a proportionate means of a legitimate aim. It does not mention AI. On its words, neither a vendor rule nor a human reviewer changes that test.
Physical actionsNCSC blog, 20 August 2026.The NCSC separates in-the-loop from on-the-loop oversight and recommends technically enforced controls and emergency shutdown for higher-risk agents. See the hardware section.
Evidence a review happenedDSIT [Introduction to AI assurance](https://www.gov.uk/government/publications/introduction-to-ai-assurance/introduction-to-ai-assurance), published 12 February 2024.Lists risk assessment, impact assessment, bias audit, compliance audit, conformity assessment and formal verification as assurance mechanisms. A reviewer's sign-off sits alongside these, not in place of them. The ICO's own [AI and data protection guidance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/) is "under review" because of the Act and was last updated on 15 March 2023.

For security teams. The new computer-systems paragraph is the one change in the policy that helps a defender: security research, testing and tool development on systems you own or operate, with the owner's authorisation or in an authorised bug bounty, are stated as not prohibited, "provided the activity complies with applicable law". The adjusted-safeguards route is the Cyber Verification Program, which Anthropic expanded on 6 October into three tiers, Defense Access, Red Team Access and Specialized Access, and which requires data retention for enrolled organisations. Our earlier briefing covers the tiers, applying from the UK, the retention requirement, and why authorisation under the Computer Misuse Act belongs to the organisation and not to the tier. A real-time block, the policy says, "does not by itself" indicate a violation.

The register to keep: model, policy version and a date

A UK organisation that builds on Claude needs one record that answers two questions on 12 November: which workflows are affected, and what each one relied on. The register below is the artefact. It costs a row per workflow and makes the 12 November review a checking exercise rather than an investigation.

A register of Claude workflows. Fields to record, and why each one is in it.

FieldRecordWhy
Workflow and ownerName, purpose and a named accountable role.The NCSC advises "making named individuals or group responsible" where unintended activity would matter.
Route and contract holderDirect to Anthropic (Anthropic Ireland, Limited for UK customers under the Terms), Claude Platform on AWS, Bedrock, Vertex AI or Foundry, and who signed.The pages read differ by route and the notice clause is Anthropic's.
Model and versionExact model name and the date it was approved for this workflow.A model change is a change to the thing that was reviewed.
Policy version relied on"Effective 15 September 2025" now, "Effective 12 November 2026" after, with a dated saved copy.Only a dated copy shows what was relied on if the live page changes.
High-risk statusThe area or physical category, or the exclusion that applies, with the covering words quoted.The test is by action, so the record must be by action.
Human reviewThe named person or role, what qualifies them, where in the flow they review, and a record of each review.The ICO asks for a record of how the human was involved.
DisclosureThe wording shown, where and when. For solely automated significant decisions, the Article 22C route.The policy says "clearly told". The Act asks for more.
Location and ownershipWhere staff and contractors use the tool from, and the ownership and control chain.The first and third limbs of the Supported Regions wording.
Next review12 November 2026, then every model or policy change.The effective date is a fixed point; a new model is not announced on a schedule.

If a use case now sits in the high-risk list, there are three honest options. Stop it. Redesign it so that it falls inside an exclusion that is true of it, for example by making the model produce internal drafts that a named person turns into the recommendation, and record why the exclusion applies. Or put the controls in place before 12 November: a qualified reviewer with authority to change the output, a record of each review, the disclosure wording, and for any decision about a person without meaningful human involvement, the Article 22C safeguards. Whichever is chosen, write down who decided, on what date, against which version of the policy. If the recommendation is wholly favourable and the plan is to skip review, take the data protection advice first: the policy exemption does not carry over to UK law.

What to do, in order

Take this with you

Defender and governance actions before 12 November

  • List every workflow that sends data to Claude, by route, and who holds the contract for each: Anthropic directly, Claude Platform on AWS, or Amazon Bedrock, Google Cloud or Microsoft Foundry.
  • Save dated copies today of the 15 September 2025 policy, the 12 November 2026 policy, the Commercial Terms and the Supported Regions page. Anthropic links earlier versions but publishes no change log, and a live page can change.
  • Open the register and fill one row per workflow, including the policy version each relied on.
  • Test each workflow against the eleven High-risk Areas and six physical categories using the covering words. Record in, out because of a quoted exclusion, or unclear.
  • For every in or unclear, name the qualified person and what qualifies them, put the review before delivery or implementation, and keep a record of each review.
  • Write the disclosure wording and decide where it appears. If any decision about a person is made without meaningful human involvement, check UK GDPR Articles 22A to 22D and the Article 22C safeguards first.
  • Do not rely on the fixed-rule or wholly favourable exemptions without a written data protection assessment. UK law does not contain them.
  • For hardware, confirm a person can observe and stop the equipment, that it stops or holds a safe state when the connection to Claude is lost, and that operating limits are enforced outside the model output. Test the disconnect.
  • Map ownership and control to the ultimate owners and list where staff and contractors use Claude from. Ask the supplier in writing how the test is applied. Assume nothing about any shareholder.
  • Ask in writing, through Anthropic or the cloud provider as the contract requires: whether customers get notice, any grace period, which text governs until 12 November, the same date on the cloud route, and what evidence of review they would ask for. File the replies with their dates.
  • Security teams: read the three Cyber Verification Program tiers and apply if the work needs adjusted safeguards.
  • Diarise 12 November 2026. Re-run the register, confirm the policy version, re-approve each high-risk workflow, and repeat on every model or policy change.
  • If a use case now sits in the high-risk list: stop it, redesign it into an exclusion that is true of it, or put the controls in place before 12 November. Record who decided and why.

The question that exposes the gap

A policy that says "human in the loop" has told a customer what to call a control, not how to prove one. Anthropic's texts define the person, the review and the disclosure, and name no one who checks any of them. On 12 November, which named person in your organisation could show which version of the Usage Policy each Claude workflow was approved against, and who reviews what it recommends before anyone relies on it?

Key facts

Sources

  1. PrimaryThe post of 8 October 2026, "2026 Usage Policy update", read in full in a browser page of its own: the eight described changes, the effective date of 12 November, the statements that most updates clarify existing rules and that the surveillance update does not reflect a change in what Anthropic enforces in practice.Anthropicaccessed 2026-10-09
  2. PrimaryThe Usage Policy as live on 9 October 2026, headed "Effective November 12, 2026", read in full including the High-risk Use Case Requirements and Additional Use Case Guidelines tabs: the new text used for the diff and every quotation.Anthropicaccessed 2026-10-09
  3. PrimaryAnthropic's own archive page for the previous Usage Policy, headed "Effective September 15, 2025" and "replaced by a newer version", with a "Previous Version" chain to three earlier versions. The old text used for the diff.Anthropicaccessed 2026-10-09
  4. PrimaryCapture of the live Usage Policy page at 22:21:03 UTC on 7 October 2026, the last before the post: it still shows the September 2025 text, identical to Anthropic's archive page. Used to date the previous version as in force until the post.Internet Archiveaccessed 2026-10-09
  5. PrimarySupported Regions Policy page as live on 9 October 2026: the three-limb wording on physical location, incorporation or headquarters, and majority ownership or control; the list of 185 countries; the statement that it covers cloud platforms and authorized resellers.Anthropicaccessed 2026-10-09
  6. PrimaryCapture of the Supported Regions page at 16:58:36 UTC on 2 October 2026: the earlier one-sentence ownership wording and two lists of 185 countries, compared with the live page.Internet Archiveaccessed 2026-10-09
  7. PrimaryCommercial Terms of Service, "Effective June 17, 2025": D.2 policies incorporated by reference and information requests, D.3 outputs, I.2.a termination for convenience, I.3 suspension, M.2 electronic notices, M.3 amendment after 30 days, M.9 integration, and the Anthropic Ireland, Limited contracting party for EEA, Swiss and UK customers.Anthropicaccessed 2026-10-09
  8. PrimaryPost of 4 September 2025 on restricting sales to unsupported regions: the "more than 50% owned, directly or indirectly" test and the reasons given.Anthropicaccessed 2026-10-09
  9. PrimaryThreat intelligence report, "Detecting and countering misuse of AI: September 2026", read for the influence operations, surveillance and conventional weapons sections at the level of its own summaries: activity disrupted December 2025 to August 2026, statements that actors violated the Usage Policy. Actors and individuals it names are not reproduced.Anthropicaccessed 2026-10-09
  10. PrimaryPost of 27 August 2026 previewing the Model Hardware Standard: a research preview for a first group, partner case studies, a physical safety roadmap in development. No mention of the policy's qualified operator, safe state or independent limits.Anthropicaccessed 2026-10-09
  11. PrimaryPost of 15 August 2025 on Claude Opus 4 and 4.1 ending a rare subset of conversations in consumer chat interfaces: the page the 8 October post links for ending abusive conversations.Anthropicaccessed 2026-10-09
  12. PrimaryPost of 6 October 2026, "Expanding the Cyber Verification Program": three access tiers (Defense Access, Red Team Access, Specialized Access) and the data retention requirement.Anthropicaccessed 2026-10-09
  13. PrimaryClaude in Amazon Bedrock documentation: AWS-managed infrastructure and "Data handling for this offering is governed by Amazon Bedrock".Anthropicaccessed 2026-10-09
  14. PrimaryClaude Platform on AWS documentation: Anthropic-operated, and setup "accepts Anthropic's Commercial Terms of Service and Usage Policy".Anthropicaccessed 2026-10-09
  15. PrimaryClaude on Vertex AI documentation: "Data handling for this offering is governed by Google Cloud".Anthropicaccessed 2026-10-09
  16. PrimaryClaude in Microsoft Foundry documentation: hosting options, Anthropic as independent processor for Microsoft, customers "subject to Anthropic's data use terms".Anthropicaccessed 2026-10-09
  17. PrimaryAWS Service Terms, section 50: 50.12.1 third-party models as Third-Party Content, 50.12.2 abuse detection storage of up to 30 days, 50.16.1 Claude Platform on AWS subject to Anthropic's Commercial Terms, Data Processing Addendum and Usage Policy.Amazon Web Servicesaccessed 2026-10-09
  18. PrimaryMicrosoft Foundry guide to Claude models: Anthropic's Supported Regions Policy "may apply" to availability.Microsoft Learnaccessed 2026-10-09
  19. PrimaryGoogle Cloud page on Anthropic Claude models: availability subject to "Separate Offerings" terms and separate terms in the relevant model card (the model card was not read).Google Cloudaccessed 2026-10-09
  20. PrimaryData (Use and Access) Act 2025 section 80, substituting Articles 22A to 22D into the UK GDPR: solely automated decisions, significant decisions, restrictions, safeguards; and sections 50A to 50C for law enforcement processing.legislation.gov.ukaccessed 2026-10-09
  21. PrimaryICO draft guidance on automated decision-making including profiling, updated 31 March 2026 for the Data (Use and Access) Act and under consultation: scope and contents.Information Commissioner's Officeaccessed 2026-10-09
  22. PrimaryICO draft guidance chapter on what the UK GDPR says about ADM: the criteria for meaningful human involvement, timing, record keeping, and the list of areas where a decision may be significant.Information Commissioner's Officeaccessed 2026-10-09
  23. PrimaryICO draft guidance chapter on the ADM safeguards in Article 22C: information about decisions, representations, human intervention, contest.Information Commissioner's Officeaccessed 2026-10-09
  24. PrimaryGuidance on AI and data protection, last updated 15 March 2023 and marked as under review because of the Data (Use and Access) Act.Information Commissioner's Officeaccessed 2026-10-09
  25. PrimaryFCA approach to AI, first published 8 September 2025, last updated 2 October 2026: no extra AI regulation planned, existing frameworks including the Consumer Duty and the Senior Managers and Certification Regime.Financial Conduct Authorityaccessed 2026-10-09
  26. PrimaryFCA Consumer Duty page: the Duty requires firms to put customers' needs first.Financial Conduct Authorityaccessed 2026-10-09
  27. PrimaryIntroduction to AI assurance, published 12 February 2024: assurance mechanisms including risk assessment, impact assessment, bias audit, compliance audit, conformity assessment and formal verification.Department for Science, Innovation and Technologyaccessed 2026-10-09
  28. PrimaryBlog of 20 August 2026, "Managing the cyber risk of agentic AI": human-in-the-loop, on-the-loop and out-of-the-loop, named responsibility, technically enforced controls, emergency shutdown.National Cyber Security Centreaccessed 2026-10-09
  29. PrimaryEquality Act 2010 section 19, indirect discrimination: provision, criterion or practice and the proportionality test.legislation.gov.ukaccessed 2026-10-09
  30. PrimaryPeople with significant control summary guidance for companies, published 19 November 2025: the conditions of more than 25% of shares or voting rights, the right to appoint or remove a majority of the board, and significant influence or control.Department for Business and Trade and Companies Houseaccessed 2026-10-09
  31. Reported byEarlier briefing on the Cyber Verification Program: tiers, UK eligibility, retention and authorisation.pk-sharma.comaccessed 2026-10-09
  32. Reported byEarlier briefing on Anthropic's agent oversight metrics and the catch rate it does not publish.pk-sharma.comaccessed 2026-10-09

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.