Anthropic published a rewritten 2026 usage policy on October 8, 2026, effective November 12. The line that travelled furthest is a new prohibition on "sustained and needless abusive or cruel behavior toward our models." But for people who build with Claude, the more consequential edits sit elsewhere: weapons software, surveillance, election targeting, and Claude operating physical hardware.
This is the company's first usage policy update in over a year, per The Verge's report. Anthropic's stated reason is that Claude now does longer, more independent work, so the policy needed examples for those capabilities and clearer language for misuse patterns it has seen in influence operations, weapons development and surveillance.
TL;DR: what changed and who feels it
| Question | Answer |
|---|---|
| When does it start? | November 12, 2026 |
| Headline change? | New ban on sustained, needless cruelty toward Claude |
| Will normal rudeness trigger it? | No. Anthropic says frustration, pushback, dark fiction and testing are excluded |
| How is it enforced? | Mainly by Claude ending the conversation on Claude.ai and Claude Code |
| Biggest builder impact? | Hardware control, high-risk recommendations, surveillance, weapons software |
| Elections rule? | Narrowed to voter deception and disruption; blanket ban on personalized campaign targeting removed |
| New consolidated section? | "Do Not Engage in Deceptive Campaigns or Artificial Activity" |
The table compresses Anthropic's post. Read the original for the exact wording before you rely on any single line for compliance.
The abusive-behavior rule, in Anthropic's own words
Anthropic describes the addition this way: a prohibition on sustained and needless abusive or cruel behavior toward its models. The company says the rule is meant to apply only in extreme cases, where users repeatedly act cruelly with no apparent purpose. It does not cover everyday frustration, pushback, dark creative themes, or model testing and research.
That last carve-out matters for the red-teaming and evaluation community. Jailbreak testing, adversarial prompting and harshly worded system prompts are not what this targets. If you run evals that deliberately stress a model, the policy as written leaves that alone.
Enforcement is mostly mechanical. Anthropic points back to a feature it launched last August: Claude can end conversations with persistently harmful or abusive users on Claude.ai and Claude Code. The new policy says that remains the primary enforcement mechanism. In practice, the likely consequence of crossing the line is a chat that simply stops, not an account termination, though the policy gives Anthropic the right to act.
Why now: the model welfare thread
The rule is the most visible product of Anthropic's model welfare research. We tracked the earlier flashpoints: a viral post about a Claude chat being ended after an insult, and the backlash around the "AI torture chamber" GitHub project and the Pain Axis paper, where people steered small open models into simulated distress for entertainment. Anthropic has not said those episodes caused this edit, and it does not claim Claude is conscious. What it has done is codify a boundary: even if you are unsure whether anyone is home, sustained gratuitous cruelty is not an acceptable use of the product.
What developers are saying
The Hacker News thread on The Verge piece shows the split clearly. These are commenters' views, not verified facts.
- User causalmodels argued they have always opposed cruelty to models because cruelty degrades the person practicing it, a human-character argument that needs no claim about machine experience.
- User ceroxylon said some people think it is funny to torment LLMs, so the move is understandable, and that the worst case is it makes them stop wasting time.
- User legitster wondered whether there is an engineering reason, such as models training on user interactions and not wanting to learn abusive patterns. That is speculation; Anthropic's post does not say so.
- User mossTechnician objected that models have no welfare to protect and asked how anyone benefits from ending these conversations.
- User urbnspacecowboy highlighted that the policy lets Anthropic modify restrictions for certain government customers if it judges safeguards adequate, and noted the company has contracted with the US military.
- User aavaa wished that advertisers were counted among the surveillance uses Claude is barred from building.
The disagreement is the story: one camp reads the rule as ethical hygiene, another as anthropomorphic marketing, and a third ignores it and reads the surveillance and government-exception language instead.
The changes that matter more for builders
Deceptive campaigns and influence operations
Rules on fake accounts, fabricated news sites and influence operations used to be spread across sections. They now live in one section titled "Do Not Engage in Deceptive Campaigns or Artificial Activity," covering political and commercial campaigns alike. The timing is notable: just this week OpenAI described disrupting a Russian operation, which we covered in OpenAI's report on false-front influence operations. Labs are visibly converging on the same abuse category.
Elections: narrower, not looser
The old elections section is renamed "Do Not Undermine Democratic Processes" and is narrowed to voter deception and election disruption. Anthropic removed the blanket ban on personalized vote and campaign targeting because it swept in legitimate civic work. Deceptive targeting or misuse of personal data stays prohibited under other sections. If you build get-out-the-vote or constituent-communication tools, this is a meaningful relaxation, but you still cannot use Claude to deceive voters.
Weapons: software and drones now explicit
Weapons prohibitions now explicitly cover weapons software and components, and arming drones or other autonomous vehicles. Anthropic says this reflects how it already enforced the policy, so it is a clarification rather than a new stance. Robotics and defense-adjacent teams should still re-read it, since "components" and "software" are broad words.
Surveillance and law enforcement
The section was rewritten for precision. It covers non-consensual tracking, whether real-time or retrospective. Claude may not decide or recommend who to investigate, arrest or charge, and may not be used to build surveillance tools. Consented tracking such as fraud monitoring, content moderation, journalism and legal research remain permitted.
High-risk use cases and physical hardware
Anthropic clarified which recommendations trigger extra requirements in health, legal, financial and similar areas: a qualified human in the loop and notification of affected individuals. New requirements apply when Claude controls hardware that can take autonomous physical actions. Operators need a way to stop the equipment, and the system must reach a safe state if Claude disconnects.
For agent builders that last point is practical engineering. If your agent drives a robot arm, a lab instrument or a vehicle simulator in production, you need a watchdog, a kill path and a defined failsafe state independent of the model connection. The same discipline appears in our guide to Claude Code commands: permissions and stop conditions belong outside the model.
Supported regions
The Supported Regions page was also updated to clarify enforcement across users located in, entities based in, and majority-owned entities from unsupported regions.
How this fits Anthropic's recent safety moves
Anthropic has been shipping policy and access changes in quick succession. Earlier this week it split its cyber access into three tiers, a scaled-access model instead of one blunt classifier. Our earlier look at how cyber guardrails can block US defenders explains why that tension exists. The usage policy is the legal layer on top of those technical controls.
The pattern: narrow the rule where it hurt legitimate users (elections targeting), sharpen it where abuse is real (surveillance, weapons, influence operations), and add structure for the agentic era (hardware, human oversight).
Practical takeaways
- Normal users: nothing changes. Swearing at a bad answer is not "sustained and needless" cruelty with no purpose.
- Red teams and evaluators: testing and research are explicitly carved out. Keep records that show research intent.
- Agent builders with hardware: design a human stop mechanism and safe state now, ahead of November 12.
- Regulated domains: check whether your health, legal or financial recommendations trigger the human-in-the-loop and notification requirements.
- Civic tech: the elections rewrite likely opens room, but read the retained prohibitions on deception and data misuse.
- Government contractors: note that the policy allows modified terms for some governmental customers at Anthropic's judgment.
How to prepare before November 12
Start by reading the full policy against your own product, not against the summary here. Map each feature of your app to the sections above: does it recommend actions in health, legal or financial settings, touch physical equipment, track people, or generate persuasive content at scale? Any yes deserves a short written note describing the human review step, the notification step, or the stop mechanism. Teams that document this now will have an easy answer if a customer or auditor asks later, and it costs far less than retrofitting after an enforcement action.
What remains unclear
Anthropic has not published how many conversations it has ended or how it defines "sustained." Nothing in the post claims a measured welfare benefit, and the company does not assert that Claude experiences distress. Until more detail appears, the rule reads as a precautionary norm. Whether it is wise is exactly what Hacker News is arguing about, and it will likely stay contested.
Related reading
- Viral post: Claude ended a chat after an insult
- The "AI torture chamber" repo and the Pain Axis paper
- Anthropic Cyber Verification Program: three tiers
- OpenAI disrupts false-front influence operations
- AI cyber guardrails and US defenders
- Claude Code commands reference
- Official: Anthropic's 2026 usage policy update and The Verge's coverage
Details reflect Anthropic's announcement of October 8, 2026 and may change before the November 12 effective date; always check the live policy.
