Anthropic's 2026 usage policy for agent builders: the hardware stop button made it into the announcement, the subscription proxy clause did not
The hardware rules can be checked with a pulled cable. Unauthorized proxying through consumer subscriptions, responsibility for what an agent does with its tools, and a lower enforcement bar cannot be checked from outside, and they came in without comment.
Anthropic published a new Usage Policy on October 8. It takes effect on November 12 and replaces the version from September 2025. The TechCrunch headline led with one new line, the ban on abusing the model. Set the new text beside the archived one, line by line, and the parts that bind people who build agents are elsewhere. Several are not in Anthropic's summary post at all.
My read is that the policy now holds two kinds of clause. One kind you can check by pulling a cable. The other kind you cannot check at all, and from November it is enforced on suspicion.
What does Anthropic's usage policy now require when Claude controls hardware?
A person who can watch the equipment and stop it, a safe state when that person steps in or the connection drops, and limits the model cannot talk its way past. The text is new, and more concrete than a usage policy usually gets:
For High-risk Physical Actions, there must be a qualified individual who is
able to observe the equipment’s operation and stop it at any time, and the
equipment must stop or hold a safe state when that individual intervenes or
when connection to our services is lost. Any operating limits to keep the
equipment within safe bounds, such as speed, force, reach, temperature,
pressure, voltage, energy output, dose, or operating area, must be enforced
by the equipment or a controller independent of model output.It applies when hardware acts on Claude's output "without human approval" and can injure someone: vehicles and robots in shared space, presses and arms, hazardous energy, devices that act on the body, safety systems, industrial processes. Household devices are out only when they stay inside the manufacturer's built-in safety limits and the worst outcome is "discomfort or inconvenience." Monitoring without control is out too, and so is anything a qualified person reviews before it runs on the equipment. The summary post ties the section to the Model Hardware Standard, in research preview since August 27.
The last sentence of the clause is the one I would frame. I argued in A prompt is not an invariant that a load-bearing rule has to sit where the model's decision does not enter. Here that is a term of use, for the one class of agent where the cost of a miss is a crushed hand. Nothing in the policy asks the same of an agent that only moves data.
Which Anthropic usage policy clauses for agent builders are missing from the announcement?
The proxy clause first, because it is the one I would have expected the summary to mention. It is new in the section on platform abuse:
Resell, proxy, or otherwise provide access to Claude through unauthorized
means, including services that route requests through consumer subscriptions
or misrepresent the product or client being usedIn May I wrote that running a third-party harness on a Claude subscription was against terms and practically tolerated. What counts as authorized is not in the policy. Anthropic's own help article says today that third-party apps work with subscription limits. My read is that the clause aims at services that hand other people access through a subscription login. "Misrepresent the product or client being used" is the phrase to read twice if your tool presents itself as something it is not, and the line next to it now names "circumvention of the account sign-up or log-in process" as a bypass.
The agentic clause used to say that agentic use "must still comply" and pointed to a help article. It now assigns the actions:
Users are responsible for ensuring that agents they build or deploy,
including actions those agents take through tools, browsers, or connected
systems, comply with this Usage Policy.And the enforcement paragraph moved from "If we learn that you have violated" to "If we suspect that you may have violated," with "warn" and "limit" added to throttle, suspend and terminate.
What did Anthropic's usage policy change for high-risk decisions about people?
The two principles stayed, a qualified human reviewer and disclosure, and the text under them was rewritten. The summary post says the requirements "haven't changed." The wording did. Disclosure used to apply when model output was shown directly to a person. It now reaches anyone who "is the subject of a decision" based on the recommendation. Disclosure follows the decision now, not the screen, so an agent that scores applicants in a back office owes it to people who never see a word the model wrote.
The list of covered areas grew more specific, down to "setting or changing shifts, hours, or pay." One category left it: media, which in 2025 covered using Claude to "automatically generate content and publish it for external consumption."
Does Anthropic's usage policy ban on seeding AI answers reach SEO work?
Only where the content lies about who is behind it. The new section on deceptive campaigns includes this:
Manipulate the sources from which search engines or AI systems draw answers
by seeding them with content that misrepresents its origin, authorship, or
independence (e.g., networks of sites posing as unaffiliated sources
corroborating the same claims)Read with the media category's exit, this is one move seen twice. The policy stopped treating automated publishing as the risk and made hidden origin the offense. On my reading the test is origin, authorship and independence, not optimization. Publishing as yourself, with nothing hidden about who wrote it, who paid for it or who it is tied to, is outside the clause. Measuring whether an assistant cites you is outside it too. A ring of sites that pose as unrelated is inside, and so is building the tooling for one.
How is Anthropic's usage policy ban on cruelty to Claude enforced for API builders?
By Claude ending the conversation, and that is the summary post speaking. The policy itself says nothing about how. The post says the ability to end conversations will "remain the primary enforcement mechanism," and names it for Claude.ai and Claude Code. If that is the whole mechanism, a product on the API is not on that path, and what applies to it is the general paragraph that now starts at suspicion. That is my inference. Neither document says it.
What should an agent builder check in Anthropic's usage policy before November 12?
Start with what you can test. Cut the connection on a hardware rig and see what the equipment does. Look at whether your chatbot or agent says it is an AI at the start of a session or in the interface; the new text accepts either. Check whether anything you ship reaches Claude through someone's subscription login on behalf of other people. Phrases like "meaningfully review" and "designed to facilitate" cannot be tested from the outside. They are judgment calls, and the stated threshold for Anthropic to act on one is now suspicion.