From November 12, Anthropic's Usage Policy requires a qualified person who can change Claude's output before it reaches anyone when Claude screens candidates, prices a loan or decides an insurance claim. It also requires a clear notice to the person affected, and it applies to internal tools as well as customer-facing ones. Anthropic published the update on October 8 and describes most of it as clarification. For operators, though, the new text is far more specific than the last version, and that leaves about five weeks to check every Claude workflow that touches a decision about a person.
The update does four things that create work. It lists which recommendations count as high-risk. It adds rules for Claude driving physical hardware. It bans recommending who to investigate, arrest or charge, along with non-consensual tracking. And it writes the ownership-based regional restriction into the Supported Regions page. The rest (a consolidated section on deceptive campaigns, a narrower elections section, explicit weapons language and a ban on sustained abuse of the model) matters less to most enterprise buyers.
Which Claude Uses Become High-Risk on November 12?
A use is high-risk when Claude produces a recommendation about a specific individual in one of eleven areas. The new Usage Policy names them: legal, medical, finance, credit, insurance, housing, employment, education and credentials, healthcare access, public benefits and services, and legal status and adjudication. Its examples are concrete: "screening, ranking, advancing, or rejecting candidates", "approving, denying, or setting the amount, rate, or limit of a loan", "determining the outcome of a claim", and "diagnosing a condition".
The scope is the part to read closely. When Anthropic last revised the policy, its August 2025 announcement said the high-risk requirements "apply specifically when models' outputs are consumer-facing." The November text has no consumer-facing qualifier in its scope sentence. Its only business carve-out covers "business operations that do not advise or decide about a specific individual." An internal recruiting tool that ranks applicants never faces a consumer, yet it decides about a specific individual, and the policy's own employment example describes exactly that.
Anthropic's announcement says the high-risk requirements are unchanged and that the section "now lists which recommendations are covered and which are not." Take the company at its word on intent. Your exposure, though, is set by the text in force on November 12, and that text lists your HR screening workflow by name.
The exclusions are just as specific. These are not covered:
- General information or education, including explaining what a law says.
- Internal drafting, research, summarization or analysis that is not the final recommendation delivered.
- Carrying out a decision a person has already made.
- Applying a fixed rule or formula where the model exercises no judgment about the individual.
Item 2 will decide most edge cases. If Claude summarizes a claim file and an adjuster decides, the summary is analysis. If Claude outputs "deny" and a clerk forwards it, Claude produced the recommendation.
What Does a Compliant Human Reviewer Look Like?
A compliant reviewer has relevant training or experience, holds any license the law requires, sees the recommendation before it reaches the affected person or gets implemented, and has authority to change it. The policy also keeps that person responsible for what is delivered or decided. That last clause rules out the usual arrangement in which a junior analyst clicks approve on a queue and accountability sits nowhere.
There is one relief valve. Where the law permits, a recommendation "wholly favorable to the individual" can skip review in four cases: paying an insurance claim, approving coverage or prior authorization for ordered care, granting healthcare eligibility, and granting or continuing a public benefit. The policy closes the obvious loophole too: "A partial approval, reduced amount, or approval with conditions is not considered 'wholly favorable.'" A claims pipeline that auto-pays clean claims and routes everything else to an adjuster fits the policy. One that auto-pays at 80% of the billed amount does not.
Disclosure is simpler. Anyone who receives advice or a decision based on a high-risk recommendation "must be clearly told that AI was used to produce it," per the policy. You do not have to name Anthropic or Claude, and no format or timing is prescribed. If you already send adverse-action letters or candidate notices, the cheapest fix is a sentence in that template.
None of this is new to regulated teams. New York City's Local Law 144 has required a bias audit within a year before using an automated hiring tool, plus candidate notice, since enforcement began on July 5, 2023. The EU AI Act's Article 26 asks deployers to give oversight to people with "the necessary competence, training and authority" and to tell people they are subject to a high-risk system, from December 2, 2027 for Annex III systems. Anthropic's clause binds earlier than Article 26 and covers every jurisdiction where you run Claude. A breach is a contract problem with your model provider, and the policy says Anthropic may warn, throttle, suspend or terminate access.
If you have already designed approval gates for agents, our human-in-the-loop buyer's guide covers the failure mode that matters here: reviewers who have authority to change an output and rubber-stamp it anyway.
What Changes When Claude Drives Hardware?
Claude connected to equipment that acts without human approval now needs a qualified person who can observe and stop it at any time, and a safe state when that person intervenes or the connection drops. The Usage Policy names six categories: moving through shared space, applying force that could injure, controlling hazardous energy or materials, acting on the human body, controlling safety systems, and running industrial processes. It adds a requirement controls engineers will recognise: operating limits must be enforced by the equipment or an independent controller, not by model output.
Under that rule, a speed limit written into a system prompt does not count. It has to live in the PLC, the robot controller or a safety relay that keeps working when the model is wrong or gone.
The announcement ties the requirements to Anthropic's Model Hardware Standard, which the company put into research preview on August 27 with AWS, Danaher, Hugging Face and Raspberry Pi among the testers. The same report notes that the EU Machinery Regulation replaces the Machinery Directive on January 20, 2027 and covers AI-based safety functions for the first time. If your lab automation or plant pilots put Claude anywhere near an actuator, the November policy is the first deadline and the machinery rules are the second.
Which Surveillance and Law-Enforcement Uses Are Now Banned?
The policy now prohibits using Claude to make or suggest decisions to "investigate, charge, arrest or detain", and to track a person without consent through location, biometrics, movements, online activity, communications or associations. The announcement says the tracking ban applies "whether real-time or through analysis of previously collected data." That second clause reaches into analytics teams that never thought of themselves as surveillance shops.
Most enterprise security and fraud work survives. The policy lists tracking people have agreed to (its examples include fraud detection and anti-money-laundering screening on a financial account), aggregated or anonymized analysis, content moderation, authorized security research, legal research and journalism as permitted, provided they are not used for a prohibited purpose. A transaction-monitoring model that flags suspicious activity for your AML team is fine. A workflow that profiles one employee's communications and movements without consent, then recommends a referral to police, is not. Insider-threat programs sit between those two and deserve a written review. So does any vendor product in your stack that runs Claude underneath.
Security teams have already had one round of this from Anthropic: our coverage of the Cyber Verification Program showed how the company trades capability for logging. The investigate-and-arrest ban comes with no such verification path.
Does the Ownership Rule Reach Your Subsidiaries?
Yes, if a person or entity in an unsupported region majority-owns or controls them. The Supported Regions page now excludes entities "incorporated or headquartered in an unsupported region" and those "majority-owned or controlled, directly or indirectly" by persons or entities there, together with their users and personnel, "regardless of whether such individuals are physically located in a supported region." The page lists supported countries only. Anything not listed, including China and Russia, is unsupported.
The rule is older than this update. Anthropic announced on September 4, 2025 that it would bar entities "more than 50% owned, directly or indirectly, by companies headquartered in unsupported regions," citing obligations to share data with intelligence services and the risk of distillation. The October 8 update moves that into the Supported Regions page, which the Usage Policy enforces. Note the wording "or controlled": a joint venture where your company holds 51% but the partner holds board control could still fall inside. That is a question for legal, with the ownership and governance documents in hand.
What to Do Before November 12
This Week:
- Pull every Claude workflow, including ones running through Bedrock, Vertex AI or a SaaS vendor, and tag each one that produces a recommendation about a named individual in the eleven high-risk areas. Start with HR, lending, claims and benefits.
- For each tagged workflow, write down who reviews the output, what they are licensed or trained for, and whether the system lets them change it before it ships. Missing any of the three is a gap.
- Ask your fraud, insider-threat and investigations leads whether any workflow suggests a person for investigation or tracks someone without consent.
This Month:
- Add an AI-use sentence to every adverse-action letter, candidate notice and claim decision template that a high-risk workflow feeds.
- Split any auto-approval rule into "wholly favorable" (may skip review where the law allows) and everything else (must route to a reviewer).
- For any Claude-to-hardware pilot, confirm that limits live in the controller and test what the equipment does when the API connection drops.
- Send the Supported Regions text to legal with a list of subsidiaries and JVs that have non-supported-region owners or board control.
Before Renewal:
- Ask Anthropic, or the cloud reseller that bills you, how it will notify you of a suspected violation and how long you get to cure before throttling or suspension. The policy names the remedies but sets no notice period.
Log every review decision. Our agent audit logging guide covers the fields that prove a human actually saw the output, which is the evidence you will need if Anthropic's Safeguards Team ever asks.
The Bottom Line
Model providers are now writing operating requirements that used to come only from regulators. When Colorado rewrote its AI Act and the EU pushed its high-risk dates into 2027, many enterprises read that as time to wait. Anthropic's version arrives first, applies everywhere you run Claude, and is enforced by the company that can switch off your API key. The upside is that a program built for this text (named reviewers with authority, notice to the person affected, limits outside the model) is most of what Local Law 144, Article 26 and the NAIC's insurer exam will ask for too.
Start with the HR screening tool. It is the workflow most likely to have no named reviewer and no notice, and it is listed by name.
Continue Reading
- Human-in-the-Loop for AI Agents: Most Approval Gates Rubber-Stamp
- Agent Audit Logging: Platform Logs Miss the Decision You Must Prove
- Anthropic Lifts Cyber Blocks for Pen Testers Who Let It Keep Logs
- AI Vendor Exit Clauses: Standard Terms Give 0 to 90 Days to Get Out
- AI Agent Accountability Act Targets the Company Running the Agent
- The Vaguer the AI Explanation, the More Novices Trusted It
