Anthropic has published its 2026 Usage Policy update, a revision designed for models that can now perform longer and more independent work. The policy takes effect on 12 November and adds clearer examples across deceptive campaigns, elections, weapons, surveillance, high-risk decisions and autonomous physical systems.
The company says most changes clarify rules it already enforced rather than introducing entirely new prohibitions. That distinction matters for customers building agents: the policy now describes more directly how existing safety boundaries apply when Claude can plan, use tools and act across several stages of a task.
Deceptive activity gets one clear home
Restrictions that were previously distributed across elections, fraud, privacy and disinformation have been consolidated into a section covering deceptive campaigns and artificial activity. The rule applies to political and commercial conduct, including concealing who is behind a message, coordinating fake accounts and building infrastructure for influence operations.
A consolidated rule should make compliance easier to interpret. A marketing workflow, political campaign and reputation operation may use similar technical methods even when their subject matter differs. The relevant question becomes whether the system is creating false identity, artificial amplification or concealed coordination, rather than which industry label the activity carries.
Election rules focus on democratic harm
Anthropic has renamed and narrowed its elections section around conduct that undermines democratic processes. Prohibited examples include deceiving voters about candidates or voting, impersonating officials and suppressing turnout. The update removes a blanket ban on personalised vote and campaign targeting because it also captured legitimate civic work.
The company points to multilingual voter information and ballot-cure notices as examples that can serve voters without deception. Misuse of personal data and deceptive targeting remain restricted under other parts of the policy. Organisations working in this area will need to document data provenance, message purpose and review controls rather than relying on a broad category label.
Weapons software is explicitly covered
The weapons section now makes clear that prohibited development includes guidance and control software, components that make weapons operate and actions such as arming drones or autonomous vehicles. Anthropic says the wording reflects its established enforcement after observing attempts to use models for these technical layers.
This clarification closes an ambiguity that can arise when a request concerns code rather than a physical object. Agentic coding systems can connect design, simulation and implementation steps, so policy must consider the operational outcome of software rather than treating code as automatically removed from weapon development.
Surveillance boundaries become more precise
The revised policy prohibits tracking people without consent, whether in real time or by analysing previously collected data. Claude cannot decide or recommend whom law enforcement should investigate, arrest or charge, and cannot be used to build or improve tools designed for surveillance.
Permitted examples include consent-based fraud monitoring, content moderation, journalism and legal research. The boundary therefore depends on purpose, authority and effect. Customers should make those factors visible in access controls and audit records, especially where an apparently general analytical tool could be redirected towards identifying individuals.
High-risk decisions and physical action
Anthropic has rewritten its high-risk use requirements to identify more clearly which recommendations are covered. It also adds controls for models connected to hardware capable of autonomous physical action and injury. A qualified operator must be able to observe and stop the equipment, and the system must hold a safe state if Claude disconnects.
Those conditions turn familiar industrial safety ideas into explicit requirements for AI-connected hardware. A model failure, network interruption or misunderstood instruction should not leave machinery in an uncontrolled state. Designers will need reliable stop mechanisms, safe defaults and clear responsibility for the human operator.
Abuse towards models enters the policy
The announcement also says the update addresses abusive behaviour towards models. This is a developing governance area because sustained hostile interaction can be part of jailbreak attempts, harmful testing or workplace conduct that affects people reviewing outputs. The practical enforcement details will matter as customers interpret the full policy.
Enterprises should map the new text to their acceptable-use rules before the effective date. That means reviewing agent permissions, political and marketing use cases, surveillance-adjacent analytics, physical integrations and escalation procedures. Training should explain both prohibited conduct and legitimate exceptions so staff do not overcorrect by blocking valuable, low-risk work.
Clarity is only the first control
A more explicit policy helps developers predict where boundaries sit, but implementation still depends on product safeguards, monitoring and customer governance. Long-running agents can distribute a risky objective across many individually ordinary actions, making workflow-level review more important than checking a single prompt.
Anthropic’s update reflects that shift. The central challenge is no longer only what a chatbot says, but what an AI system can coordinate, decide and cause through connected tools. Customers now have a clearer policy baseline, and should use the period before 12 November to test whether their technical controls actually enforce it.