Anthropic Usage Policy Changes on 12 November: The Deployer Checklist for Teams Building on Claude
Anthropic published its 2026 Usage Policy update on 8 October and it takes effect on 12 November. The headline changes cover deceptive campaigns, surveillance, weapons software, physical hardware and ownership based region rules, and the high risk requirements for human review and AI disclosure now say more clearly what they cover. If you build on Claude, this is a supplier term change with five weeks of runway.
On 8 October 2026 Anthropic published an update to its Usage Policy, the acceptable use terms that sit behind Claude.ai, the Claude API and products built on Claude, and the new text takes effect on 12 November 2026. Usage policy changes rarely get the attention of a model launch, but for a company that ships a product on Claude they matter more, because the policy is part of the contract. If your product does something the policy now prohibits, or does something in a high risk category without the safeguards the policy requires, you are out of terms with a supplier your product depends on. That gives founders, developers and compliance teams roughly five weeks to read the change, map it to what they actually ship, and record the outcome.
Most of the update reorganises and sharpens rules rather than inventing new ones. A new section on deceptive campaigns and artificial activity pulls together rules on fake accounts, fabricated news sites and influence operations, and it applies to commercial manipulation as well as political work, including building the tooling for such campaigns. The elections section is renamed to focus on voter deception and election disruption, and the blanket ban on personalised campaign targeting is removed, although targeting that relies on deception or misuse of personal data stays prohibited through other sections. The weapons section now names weapons software, guidance and control systems and arming drones or other autonomous vehicles, which Anthropic describes as codifying how it already enforced the rule.
The surveillance section is the one most likely to touch ordinary business products. It now prohibits tracking people without consent, whether in real time or from previously collected data, building or improving surveillance tools, and using Claude to decide or recommend who should be investigated, arrested or charged. Anthropic says consent based tracking such as fraud monitoring, content moderation, journalism and legal research remains permitted. If you run a fraud, trust and safety, workforce analytics or investigations product, do not assume you are fine because the word surveillance does not appear in your marketing. Write down what data the feature uses, whether the people concerned consented or have a lawful basis that maps to consent, and whether Claude output ever ranks individuals for enforcement action. That record is the evidence you will want if a customer or Anthropic asks.
The high risk use case requirements are where deployer obligations live, and the update says the substance is unchanged while clarifying which recommendations they cover. High risk means products that affect health, legal rights, finances, livelihood or access to essential services. In those products a qualified person with authority to review and change the Claude recommendation must be in the loop, and the affected individual must be told that AI was used. Credit decisions, insurance and health eligibility, hiring screens, tenancy checks and legal triage all sit squarely here. If you sell into those markets, check two things in the product itself rather than the policy deck: that a named role can actually override the output before it reaches the person, and that the disclosure is shown to the individual, not buried in terms of service.
The update also adds controls for Claude connected to hardware that can take autonomous physical actions capable of causing injury. A qualified operator must be able to observe the equipment and stop it, and the equipment must hold a safe state if Claude is disconnected. That second requirement is an engineering requirement, not a policy one, and it is easy to miss in robotics, warehouse, building management or lab automation pilots that started as a quick agent demo. Test it the plain way: cut the model connection mid task and watch what the hardware does. Keep the test record, because it is the same evidence an ISO 42001 auditor would expect for an AI system impact assessment and the same evidence a customer will ask for in a security questionnaire.
Two quieter changes deserve a line in your supplier file. The Supported Regions enforcement now reaches entities majority owned or controlled by persons or entities in unsupported regions, not only people physically located there or companies incorporated there. If your cap table, parent company or a reseller in your chain has that exposure, have counsel look at it before 12 November rather than after an account review. The update also prohibits sustained and needless abuse of the models, which Anthropic scopes narrowly to extreme, repeated cases with no discernible purpose, and it excludes testing and pushback, so red team and evaluation work on your own product is not caught by it.
Here is how to turn this into compliance evidence instead of a reading exercise. In ISO 27001 terms the Usage Policy is a supplier agreement term, so log the change under your supplier relationship and change management controls, with the review date and owner. In ISO 42001 terms it is an external issue and a third party requirement for every AI system that uses Claude, so update the AI system inventory and, where a high risk category applies, the impact assessment. For SOC 2, it belongs in vendor management and in the description of complementary controls you rely on. If you run your programme in Vanta, Drata or Secureframe, attach the policy version and your mapping note to the Anthropic vendor record and set a reminder for 12 November so the evidence shows the review happened before the effective date, not after.
There is also an EU AI Act overlap worth noting. The Article 50 transparency obligations have applied since 2 August 2026, and the Anthropic disclosure requirement for high risk uses lines up with the spirit of them even though it is a contract term rather than a legal one. Doing the disclosure once, properly, in the product screen where the decision is shown, satisfies both and is far cheaper than two separate pieces of copy. Our AI governance and ISO 42001 guides cover how to structure the inventory and impact assessment so a single record serves the supplier review, the certification audit and the regulator.
A practical plan before 12 November. List every product feature that calls Claude, mark any that touch tracking, enforcement, physical hardware or a high risk category, and confirm human review and AI disclosure in the shipped product for each high risk feature. Run the disconnect test on anything that moves. Check ownership and reseller exposure for the region rule. Then record the review against the Anthropic supplier entry in your compliance platform. If you build on more than one model provider, repeat the exercise for each, because usage policies diverge and your product is held to whichever one the request actually reaches.
Editorial note: AES Tech reviews are independent. Some outbound links are affiliate links and are marked sponsored; they never change our rankings. See our disclosure.
Get the next post by email
One short email when something worth knowing ships. No spam, unsubscribe anytime.
Comments
Moderation policyLoading comments...
Add a comment
Corrections and first-hand experience are the most useful things you can leave. Comments are screened automatically and reviewed by a human; see the moderation policy.