Anthropic's weapons ban now names the software too

Anthropic's rulebook for Claude now has a line you would not expect in a terms-of-service document: you may not be persistently and needlessly cruel to the model. The ban sits in an updated Usage Policy, published by Anthropic, which takes effect on November 12 and also tightens the wording on weapons, surveillance, elections and fake-account networks.
At a glance
- Anthropic rewrote its Usage Policy for Claude: rules on fake accounts and fabricated news sites now sit in one section, the elections section is narrower, and the weapons and surveillance bans are spelled out.
- Most changes clarify existing rules. Anthropic says the weapons and surveillance wording matches how it already enforced the old policy, and the high-risk requirements for health and finance are unchanged.
- The abuse rule covers only repeated, purposeless cruelty, and its main enforcement remains Claude's existing ability to end conversations with persistently abusive users on Claude.ai and Claude Code.
If you have not been following, Anthropic updates its Usage Policy every year in response to new model capabilities and customer feedback. Since the last refresh, Claude has taken on longer, more independent work. The company says it also saw new patterns of misuse in influence operations, weapons development and surveillance, documented in its latest threat intelligence report. The Verge reports this is Anthropic's first usage policy change in over a year.
Claude could already end abusive chats, and the new rule covers only purposeless cruelty
The rule drawing the most attention bans sustained and needless abusive or cruel behavior toward Claude. Anthropic limits it to extreme cases of repeated cruelty with no discernible purpose. Frustration, pushback, dark creative themes, and model testing and research are outside it.
Around August 15, 2025, Anthropic let Claude models end rare conversations with persistently abusive users, now on Claude.ai and Claude Code, and called it an ongoing experiment. According to Anthropic's announcement, Claude Opus 4 and 4.1 got the ability mainly as exploratory work on potential AI welfare. The Hacker News report adds that Anthropic has sought out prominent religious scholars, in some cases seeking to convince them that Claude could be conscious or have a soul.
Anthropic's description makes ending a chat a last resort: Claude does it only after several redirection attempts fail or the user asks, and never when someone may be at imminent risk of harming themselves or others. The ended chat accepts no new messages, but other conversations are unaffected, a new chat can start immediately, and earlier messages can be edited into new branches. Think of a waiter who stops serving one table, not a bouncer who clears the room.
Fake-account networks and fabricated news sites now fall under one rule
Anthropic says it has seen state media outlets, government propaganda offices and commercial firms use Claude to run networks of fake accounts and fabricated news sites. The old policy already banned this, but the rules were scattered across the elections, fraud, privacy and disinformation sections. They now sit in one section, Do Not Engage in Deceptive Campaigns or Artificial Activity, which covers political and commercial deception alike.
That includes hiding who is behind a message, amplifying content through fake accounts or posts, and building tools and infrastructure for influence operations. The elections section, renamed Do Not Undermine Democratic Processes, now targets deceiving voters or disrupting elections: false information about candidates or how to vote, impersonating candidates or election officials, and suppressing turnout.
Anthropic also dropped its blanket ban on personalized vote and campaign targeting, saying it blocked legitimate civic work such as nonprofits writing voter information in other languages or election officials sending ballot cure notices. Targeting that relies on deception or misuses voters' personal data stays banned under the deceptive campaigns, surveillance and privacy sections.
The weapons ban now names guidance and control software
Anthropic says people have tried to use its models to build guidance and control software for weapons. The rewritten section states that the ban covers the software and components that make weapons work, along with actions like arming drones and other autonomous vehicles.
Surveillance got the same treatment. Anthropic's September threat intelligence report described AI being used to build systems that identify and track political dissidents. Tracking people without consent is now banned, in real time or through previously collected data. Claude cannot decide or recommend who to investigate, arrest or charge, and cannot be used to build or improve surveillance tools.
The section also lists what stays allowed: tracking people have agreed to, such as fraud monitoring, plus content moderation, journalism and legal research. For both weapons and surveillance, Anthropic says the new wording matches how it already enforced the previous policy.
Claude-driven hardware must hold a safe state, and high-risk and regional rules are spelled out
Uses that can affect someone's health, legal rights, finances, livelihood or access to essential services still need a qualified human in the loop, meaning someone with the authority to review and change Claude's recommendations. The affected person must be told that AI was used. Those requirements are unchanged, but the section now lists which kinds of recommendations are covered and which are not.
Following its Model Hardware Standard, Anthropic adds rules for hardware that takes autonomous physical actions and could cause injury. A qualified operator must be able to observe the equipment and stop it if needed, and the equipment must hold a safe state if Claude is disconnected.
Last year Anthropic restricted access for companies majority-owned by entities headquartered in unsupported regions. Its Supported Regions page now spells out enforcement: Claude is off-limits to people physically located in those regions, to entities incorporated or headquartered there, and to entities majority-owned or controlled by persons or entities in them.
Anthropic names ending conversations as the primary enforcement mechanism for the abuse rule, and by its own description an ended chat still leaves the user free to start a new one or branch an earlier message. In our view, that makes the abuse rule read more as a stated position than a hard limit.
The November 12 cutoff for Claude users
From November 12 the new wording governs how Claude may be used, including the operator and safe-state requirements for teams connecting Claude to equipment that acts on its own. Anthropic says it will keep updating the policy as Claude's capabilities and risks change, seeking input from across the company, policymakers, subject matter experts, civil society and users. No date for the next revision has been given.
Related stories
- Amodei asks rivals to let evaluators inside training
- Claude access cut over bioweapons concerns
- UK testing agency skipped over Anthropic's new model
- Older Claude models fold on an explicit-content jailbreak
- Claude's text watermark: statistical, not hidden characters
- How Claude's watermark hides in random word picks
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
