What is actually banned now

Anthropic published an updated usage policy on 8 October, effective 12 November. The company’s own framing is that most of the changes clarify existing rules rather than change how they are enforced. Two sections do more than that.

The surveillance and law enforcement section has been rewritten. It now prohibits tracking people without their consent, in real time or from data collected earlier; using Claude to decide or recommend who to investigate, arrest or charge; and building or improving surveillance tools. The permitted list is narrower than the prohibited one: tracking people have consented to, such as fraud monitoring, plus content moderation, journalism and legal research.

That is a frontier lab writing down, as a term of service, that its model may not be the thing that picks who the police go after.

The election rules got looser, not tighter

The elections section has been renamed “Do Not Undermine Democratic Processes” and narrowed to deceiving voters or disrupting elections — spreading false voting information, impersonating officials.

The blanket ban on vote and campaign targeting is gone. Anthropic says legitimate civic uses, such as multilingual voter information, are no longer barred, and that deceptive targeting and misuse of personal data remain prohibited under other sections. Chief among those is a new section, “Do Not Engage in Deceptive Campaigns or Artificial Activity”, which pulls together rules previously scattered across elections, fraud, privacy and disinformation. It covers hiding who is behind a message, using fake accounts and building influence-operation tooling — and it applies to commercial deception as much as political.

A hand dropping a folded paper into a ballot box
The blanket ban on vote and campaign targeting has been removed. Illustrative image. Edmond Dantès · pexels · Pexels License

Weapons, and machines that move

The weapons prohibitions now explicitly name weapons software and components, and arming drones or other autonomous vehicles.

The high-risk section keeps its existing human-in-the-loop and disclosure requirements, but adds something new for hardware that takes autonomous physical actions: a qualified operator must be able to stop it, and it must hold a safe state if Claude is disconnected. That second condition is the interesting one. It assumes the model will drop out mid-task and requires the machine to fail into stillness rather than into whatever it was last told.

A rule about being cruel to Claude

The policy adds a prohibition on sustained, needless abuse of the model, limited to extreme cases. Anthropic is explicit about what it does not cover: frustration, pushback, dark creative themes, and testing or research are all excluded.

It is not an empty clause. Claude can already end persistently abusive conversations on Claude.ai and in Claude Code, so the product behaviour arrived before the rule did. What is new is that the company has now written it into the document customers agree to, which turns a model behaviour into a term.

A small quadcopter drone flying against a clear sky
The weapons rules now explicitly cover arming drones and other autonomous vehicles. Illustrative image. Bert Christiaens · pexels · Pexels License

Where you are, and who owns you

The supported-regions language has been tightened in a way that will matter to corporate structures rather than individuals. It now restricts use by people physically located in unsupported regions, by entities incorporated or headquartered there, and by entities majority-owned or controlled by parties there.

That last clause reaches through ownership rather than stopping at the sign on the door.

What to watch

The date to put in the calendar is 12 November. Between now and then, the clauses worth watching are the surveillance ones: they are written broadly enough to catch a good deal of ordinary security tooling, and how Anthropic reads “building or improving surveillance tools” in practice will decide whether this is a line or a slogan.