Updated 1 hour ago
Anthropic sets November 12 rules for Claude in 11 high-risk decision areas

AI Policy

Anthropic sets November 12 rules for Claude in 11 high-risk decision areas

Claude deployments affecting health, legal rights, finances, jobs and essential services face clearer human‑review and disclosure requirements. Physical‑action systems also need operator control and independent safety limits.

The effective date creates a deployment checklist

Anthropic's [2026 Usage Policy update](https://www.anthropic.com/news/2026‑usage‑policy‑update), published October 8, says the revised rules take effect November 12. The practical change for builders is a clearer test for workflows that can affect a person's health, legal rights, finances, livelihood or access to essential services. Anthropic says its underlying human‑review and disclosure principles have not changed, but customers repeatedly asked which use cases they cover. The current [Usage Policy](https://www.anthropic.com/legal/aup) now names 11 high‑risk recommendation areas: legal, medical, finance, credit, insurance, housing, employment, education and credentials, healthcare access, public benefits and services, and legal status and adjudication. A workflow that produces an individualized recommendation in one of those areas needs a qualified person who can meaningfully review and change the recommendation before it is delivered or used for a decision. The affected person must also be told that AI contributed. This is Anthropic's provider policy, not a statement that compliance with it satisfies local law. Anthropic expressly says the requirements do not replace legal obligations and may not make its products suitable for every use case. Teams therefore need two separate checks: whether Anthropic permits the deployment, and whether the deployment complies with the laws and professional rules that apply to it.

High‑risk depends on the output's role, not the industry's label

The policy draws a useful line between producing the consequential recommendation and assisting around it. General education, internal research, drafting and summarization are listed as exclusions when they are not the ultimate recommendation delivered to an individual. Explaining advice that a qualified professional already gave, applying a fixed rule without model judgment, and carrying out a decision a person already made can also fall outside the high‑risk recommendation requirements. That means a health, finance or legal product cannot classify the whole workflow from its marketing category alone. The relevant question is what the model output does at the final handoff. A model that summarizes a clinician‑approved plan is different from one that interprets symptoms and recommends treatment. A system that explains investing is different from one that tells a named user how to allocate specific assets. Teams should document that handoff explicitly: the model's input, the output a person sees, who may change it, and whether any downstream system acts on it. If the answer changes across features or customer configurations, the policy classification can change with it.

Human review has to be qualified and able to change the result

A passive approval screen is not enough under the wording Anthropic uses. The reviewer must have the training or experience to evaluate the output, hold a licence where the underlying work legally requires one, and have authority to change what is delivered or decided. The qualified person remains responsible for the result. For implementation, that suggests four fields an audit trail should preserve without recording unnecessary sensitive data: which output was reviewed, who held the reviewing role, whether the reviewer changed it, and which version was ultimately delivered. The system should prevent delivery when the required review is missing rather than treating review as an optional note. Anthropic lists a narrow exception for decisions that are wholly favorable to the individual, including paying an insurance claim or granting certain healthcare coverage or public benefits, where law permits. Partial approvals, reduced amounts and approvals with conditions do not count as wholly favorable. Disclosure and other legal obligations may still apply.

Physical‑action agents need controls outside model output

The clearest new operational section covers hardware that can act without human approval and could injure someone. The policy names movement through shared space, force‑capable machinery, hazardous energy or materials, actions on the human body, safety systems and industrial processes. For these systems, a qualified operator must be able to observe the equipment and stop it. The equipment must stop or hold a safe state if the operator intervenes or the connection to Anthropic's service is lost. Limits on speed, force, temperature, pressure, voltage, dose, operating area and similar safety bounds must be enforced by the equipment or a controller independent of model output. That independence requirement is the key engineering consequence. A Claude instruction that says “stay below this limit” is not the same as a controller that makes exceeding the limit technically unavailable. Network loss and model failure should move the system to a safe state, not leave the last command running indefinitely.

Agents, disclosures and regional access remain separate gates

The revised policy also says consumer‑facing chatbots and agents must disclose at the beginning of a session or in the interface that users are interacting with AI. Agent builders remain responsible for actions taken through tools, browsers and connected systems. Those obligations sit alongside the universal prohibitions, rather than replacing them. Anthropic also [clarified its Supported Regions Policy](https://www.anthropic.com/supported‑countries). Access is restricted for people physically located in unsupported regions, entities incorporated or headquartered there, and entities majority‑owned or controlled by people or entities in unsupported regions. A supported employee location therefore does not by itself resolve the organization‑level test. A pre‑November 12 review should inventory each deployed workflow, identify the final recommendation or physical action, record the applicable reviewer and disclosure, test safe‑state behavior, and check the deploying entity's regional eligibility. The policy does not provide a certification that a system is safe or lawful. It provides a set of provider‑enforced conditions that teams can turn into specific release gates before the effective date. *Figure: Four operational gates in Anthropic's November 12 policy. Sources: [Anthropic's October 8 announcement](https://www.anthropic.com/news/2026‑usage‑policy‑update), [Usage Policy](https://www.anthropic.com/legal/aup), and [Supported Regions Policy](https://www.anthropic.com/supported‑countries). Figure by OpenTools Team; no third‑party expressive material used.*

Share this article

PostShare

Related News