A sharper line on influence campaigns
The new section, “Do not engage in deceptive campaigns and artificial activity,” covers political and commercial deception. It bars hiding who is behind a message, spreading material through fake accounts or publications, and building tools or infrastructure for influence campaigns.
The revision follows Anthropic’s reports over the past month about state media, government propaganda agencies and commercial companies using Claude to create networks of fake accounts and false news sites. Those activities were already prohibited, but the rules were scattered across sections on elections, fraud, privacy and disinformation.
Election rules now focus on deception and disruption: Claude cannot be used to mislead voters or undermine elections. The examples include spreading false information about candidates or voting, impersonating candidates or election officials, and trying to stop people from voting.
Anthropic has also removed its general ban on personalized targeting of voters and political campaigns. The restriction had covered lawful civic work, such as nonprofits preparing voter information in other languages and election officials notifying people that they need to correct their ballots. Deceptive targeting and improper use of voters’ personal data remain covered by the rules on deceptive campaigns, surveillance and privacy.
From weapons to physical systems
Anthropic says it has recently seen attempts to get models to provide instructions and software for controlling weapons. The revised rules make explicit that the weapons ban covers necessary software and components, as well as arming drones and other autonomous vehicles. The company says these changes reflect how it applied the previous rules.
A separate clarification covers models connected to devices that can take physical actions and cause injury. A qualified operator must be able to monitor the equipment and stop it when needed; if Claude disconnects, the equipment must enter a safe state.
That safeguard sits alongside existing requirements for high-risk uses. When Anthropic products could affect someone’s health, legal rights, finances, livelihood or access to important services, a qualified professional must supervise the system and be able to review or change Claude’s recommendations. People affected by a decision must also be told that AI was used. Anthropic says those requirements have not changed, but it has rewritten the section to specify which kinds of recommendations fall under them.
Surveillance, and the boundaries of enforcement
Anthropic has rewritten its rules on surveillance and criminal justice after describing in a September threat report how AI is increasingly used to build systems that identify and track political dissidents. Claude cannot be used to track people without consent, whether in real time or through previously collected data. It also cannot recommend or decide whom law enforcement should investigate, arrest or charge, or help create or improve surveillance tools.
The revised section also names permitted uses, including surveillance people have consented to, fraud monitoring, content moderation, journalism and legal research.
Another new rule addresses repeated, purposeless cruelty or abuse directed at models. Anthropic says it is meant for extreme cases, not ordinary frustration, disagreement, dark creative work, testing or research. Claude can already end rare conversations with persistently abusive users on Claude.ai and Claude Code; that remains the main way the company intends to apply the rule.
Anthropic has also clarified where Claude is available. It cannot be used by people physically in unsupported regions, organizations registered or located there, or organizations primarily owned or controlled by people or entities from those regions. The company had restricted access for companies majority-owned by organizations in unsupported regions last year.
The test is in the exceptions
I think the most consequential change is not another prohibition but the removal of the blanket ban on personalized political targeting. Anthropic is drawing a narrower boundary between civic outreach it considers legitimate and targeting that relies on deception or improper use of personal data. That distinction is more workable than a broad ban, but it leaves the hard question in the details: how the company decides which side a particular use falls on.
The same tension runs through the rest of the update. Anthropic says some rules describe existing practice more clearly, while the physical-equipment requirements add concrete conditions for systems that can cause harm. The document can define those conditions; the unresolved test is whether they remain enforceable when Claude is part of a larger system, rather than the only component making decisions or taking action.
Daily AI news
Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.
Only what matters — every day
Follow on X