Back to Blog
strategy

Anthropic's Usage Policy changes on 12 November: what UK firms deploying Claude must check

By Dee KhabraPublished Last reviewed

What changed

On 8 October 2026 Anthropic published a new version of its Usage Policy, the rulebook that governs every use of Claude. It takes effect on 12 November 2026. The policy applies to anyone who submits inputs to Anthropic's products: people using the apps, businesses using the API, customers reaching Claude through a cloud provider or reseller, and the end users of products built on Claude. Anthropic says most of the changes clarify existing rules.

The change with the widest reach is to the High-risk Use Case Requirements. Anthropic has always required two controls where Claude is used in ways that affect someone's health, legal rights, finances or livelihood: a qualified human in the loop, and disclosure to the person affected. It says those requirements have not changed. What is new is that the policy now lists what is covered. There are eleven High-risk Areas: legal, medical, finance, credit, insurance, housing, employment, education and credentials, healthcare access, public benefits and services, and legal status and adjudication. Each is defined by example. Finance includes advising an individual on their own taxes or preparing a tax return for them to sign or file. Employment includes screening and ranking candidates, setting shifts or pay and evaluating a worker's performance.

Where a recommendation falls in one of those areas, a qualified person must meaningfully review it, with authority to change it, before it is delivered or acted on, and the individual must be clearly told that AI was used. There is no need to name Anthropic or Claude. The policy also lists exclusions: general information, internal drafting, research and summarisation that is not the recommendation delivered, applying a fixed rule, and business operations that do not concern a specific individual. A narrow set of wholly favourable decisions, such as paying an insurance claim, may proceed without human review where the law allows.

The update also adds requirements for Claude connected to hardware that acts autonomously, consolidates the rules on deception into a new section covering fake accounts, fake reviews and undisclosed sponsorship, states the surveillance and law enforcement prohibitions more precisely, prohibits sustained and needless abuse of the models, and clarifies that the Supported Regions Policy bars entities majority-owned or controlled from unsupported regions.

Why it matters for UK business

The Usage Policy is a contract term, not law, but it is enforced: Anthropic says it may warn, throttle, suspend or terminate access where it suspects a breach. It also follows the model. A firm that reaches Claude through Amazon Bedrock, or through a third-party product that happens to run on Claude, is inside it.

The eleven areas read like the client list of a UK professional services practice. A law firm drafting a document for a client to sign, an accountant preparing a self-assessment return, an adviser making a personalised investment recommendation, a broker pricing a policy, a lender setting a credit limit, an HR team ranking applicants, a clinic triaging patients and a letting agent assessing a tenancy application are all named, in substance, on the list. The areas are framed around advice to, or decisions about, an individual. The policy does not say in terms whether advice to a corporate client is caught, and we would not read that silence as an exemption.

The useful comparison is with UK data protection law. Articles 22A to 22D of the UK GDPR bite on significant decisions taken solely by automated means, which is why many firms have concluded that a human sign-off takes them out of scope. Anthropic's policy works differently in two ways. It applies to recommendations, so it is engaged even when a human makes the final call. And it asks more of that human: they must be qualified in the field, hold a licence where the law requires one, and carry out a meaningful review rather than an approval click. Then it adds the disclosure, which the UK rules on solely automated decisions do not require of a human-reviewed process. A firm can be comfortably outside Article 22A and still owe its client a clear statement that AI was used. Our Data (Use and Access) Act briefing covers the statutory side.

The exclusions are what make the policy workable. Using Claude to summarise HMRC guidance, research case law, draft an internal note or analyse a set of accounts is not a High-risk AI Recommendation. Using it to prepare the return, the letter of advice or the shortlist that goes to the individual is. The line is whether Claude's output is, in substance, the recommendation delivered.

Three other points will catch specific firms. Any consumer-facing chatbot or agent must tell users they are dealing with AI, at the start of each session or in the interface. Marketing teams and agencies should read the new deception section closely: fake reviews, sockpuppet accounts and networks of sites seeded to manipulate what search engines or AI systems cite are now prohibited in one place. And manufacturers connecting Claude to machinery must have a qualified operator who can observe and stop it, a safe state if the connection drops, and limits enforced independently of the model.

What to do, and what not to do

Do:

  • Before 12 November, list every Claude use case and mark each one against the eleven areas: recommendation about an individual, or excluded support work.
  • For each one in scope, name the qualified reviewer, make sure the review can change the outcome, and keep evidence that it happened.
  • Add a clear AI disclosure where the advice or decision reaches the individual. In our reading that means the engagement letter, the advice itself or the decision notice, not a line in a privacy policy.
  • If you build a product on Claude, carry the requirements into your own customer terms and onboarding, and check the chatbot disclosure.
  • Review any review-generation, persona or content-seeding workflow against the deception section.
  • Record the outcome in your AI policy and DPIA with the date.

Do not:

  • Treat the policy as new law, or as optional. It is a condition of using the tool.
  • Count an unqualified approver as a human in the loop.
  • Use Claude to make or suggest decisions in law enforcement or criminal justice processes. That is prohibited outright, not a high-risk use case.

Where The AI Consultancy fits

Mapping use cases to the policy and building the review and disclosure steps into the workflow is part of our Claude implementation service. The professional-duty background is in our briefing on the UKJT statement on AI liability, and the employment-law position is in our guide to AI in HR and recruitment.

Verified on 10 October 2026 against Anthropic's "2026 Usage Policy update" (8 October 2026) and the Usage Policy text published that day, effective 12 November 2026. Where this briefing says where a disclosure should sit, or how the policy relates to UK law, that is The AI Consultancy's reading, not Anthropic's. This briefing is general information, not legal advice; read the policy itself and confirm your position with a qualified adviser.

Frequently asked questions

We already have a human review every AI-assisted decision. Does that satisfy Anthropic's Usage Policy?
It satisfies half of it, provided the reviewer is qualified and the review is real. The policy asks for a qualified person, meaning someone with the training or experience to evaluate the output in that field and a licence where the law requires one, who meaningfully reviews the recommendation and has authority to change it. It separately requires that the individual who receives the advice or is the subject of the decision is clearly told AI was used. A human sign-off is often enough to take a decision outside the UK GDPR rules on solely automated decisions, but it does nothing for the disclosure requirement, which is contractual and applies whether or not a human was involved.
Is Anthropic's Usage Policy legally binding on a UK business?
It binds as a contract term, not as law. Using Claude, whether directly, through a cloud provider or inside another vendor's product, is conditional on complying with it, and Anthropic says it may warn, throttle, limit, suspend or terminate access where it suspects a breach. The policy also says it does not replace local legal requirements and that users should follow local law where that adds to or conflicts with it. For a UK firm that means UK GDPR, sector regulation and professional conduct rules still apply in full, and the Usage Policy sits on top as a condition of the tool.

Get new briefings by email

The AI Consultancy newsletter delivers briefings and analysis for UK businesses. We use your address only to send it, and you can unsubscribe at any time.

By subscribing you consent to receive The AI Consultancy newsletter by email. You can unsubscribe at any time. See our privacy policy.

Related Articles

strategy

What is a Fractional Chief AI Officer? A UK Guide for 2026

strategy

Fractional CAIO Cost in the UK 2026: Day Rates, Monthly Retainers, Real Examples

strategy

Fractional CAIO vs AI Consultant: Which Does Your UK Business Need?