Metallic brain sculpture with cables and electronic components on a light blue background

Anthropic Tightens Claude Rules, Banning Cruelty, Propaganda and Weapons Support

Anthropic’s new Claude policy bans cruel behavior, propaganda, surveillance and weapons support while tightening rules for high-risk AI use.

In short

Anthropic has updated Claude’s usage policy to ban abusive behavior toward the model and tighten restrictions on propaganda, surveillance, weapons, and autonomous hardware. The move highlights the company’s expanding safety agenda as AI systems become more powerful and more deeply embedded in real-world systems.

  • Anthropic’s first major Claude policy update in over a year adds new rules on cruelty, propaganda, surveillance and weapons.
  • The company says conversation-ending is still the main response to users who repeatedly act cruelly toward Claude.
  • The revised policy more explicitly bans election deception, surveillance abuse and weaponization support.
  • Anthropic also added a safety rule for AI connected to hardware that can act autonomously and cause injury.

Anthropic has overhauled Claude’s usage policy for the first time in more than a year, adding new restrictions on abusive conduct, political manipulation, surveillance, and weapons-related use. The update matters because it sharpens how one of the leading AI companies now tries to draw lines around misuse as models become more capable and more widely deployed.

The most unusual addition is a ban on “sustained and needless abusive or cruel behavior” directed at Claude itself. Anthropic says the rule is meant for extreme situations in which people repeatedly act cruelly toward the model without any clear purpose, while ordinary frustration, creative experimentation, and model testing remain outside the scope of enforcement.

At the same time, Anthropic has consolidated a range of scattered safeguards into clearer rules covering election interference, propaganda, surveillance, and weapons development. The changes reflect growing pressure on frontier AI developers to define what their systems should not be used for, especially as their tools are adopted in sensitive political, commercial, and military settings.

What changed in Anthropic’s Claude policy?

Anthropic’s new policy is broader, more explicit, and more operational than the version it replaces. The company says the update is intended to address high-risk misuse cases that have become more visible over the past year, rather than to introduce a wholesale rewrite of its approach.

The policy now covers a wider range of harmful activity, including deceptive influence campaigns, voter manipulation, surveillance abuse, and assistance with weapons development. It also formalizes a previously unusual area of concern for a consumer-facing AI company: how users treat the model itself.

Why is “abusive or cruel behavior” part of an AI policy?

It is part of Anthropic’s ongoing research into what it calls model welfare. Last August, the company said Claude could end conversations with persistently harmful or abusive users as part of that work. The new policy keeps that approach in place and calls conversation termination the primary enforcement mechanism.

Anthropic did not say whether harsher steps, such as account bans, would follow in such cases. The company’s language suggests it wants to reserve intervention for rare situations rather than everyday rough interactions with the chatbot.

Anthropic said the new rule is meant only for extreme cases in which users repeatedly act cruelly toward its models without any discernible purpose, and it does not apply to ordinary frustration, pushback, dark creative writing, or model testing.

That distinction matters. AI companies routinely see users prompt models with adversarial, sarcastic, or stress-test style inputs. Anthropic appears to be drawing a line between legitimate testing and behavior it believes serves no practical purpose other than mistreatment.

How does Anthropic define misuse around propaganda and elections?

Anthropic is now making its restrictions on political deception more explicit, grouping together rules that had previously been spread across different parts of the policy. The company says Claude may not be used to create or scale deceptive commercial or political campaigns, including efforts to hide who is behind a message or artificially boost content using fake accounts and posts.

The election-related section is equally direct. Claude cannot be used to mislead voters, suppress turnout, impersonate candidates or election officials, or spread false information about how or where to vote. These restrictions reflect growing concern across the AI industry that generative tools can lower the cost of propaganda, impersonation, and influence operations.

While the policy update is specific to Claude, it also serves as a public marker of what Anthropic sees as a core risk category for frontier models: mass persuasion at scale. That includes not only fake content, but also the automation of amplification tactics that make misleading material appear more organic than it really is.

Why is surveillance now a clearer concern?

Anthropic says the surveillance language was tightened because of increased evidence that Claude has been used to help identify and track political dissidents. The company’s new wording is designed to make the prohibition easier to understand and harder to exploit.

Under the revised policy, tracking people without consent is banned whether the monitoring is happening live or through analysis of previously collected data. Claude also cannot be used to decide or recommend who should be investigated, arrested, or charged in a law enforcement or criminal justice context.

The company additionally bars using Claude to build or improve surveillance tools. That is a stronger and more operationally useful formulation than vague promises against misuse, because it targets not just end use but also upstream product development.

Anthropic says tracking people without consent is forbidden whether it occurs in real time or through historical data analysis, and that Claude must not be used to make law-enforcement decisions or to enhance surveillance systems.

Why did Anthropic expand the weapons ban?

Anthropic says the new policy expands a weapons restriction that had already existed publicly, because it has seen repeated attempts to use Claude to generate guidance for weapons systems and software that controls them. The company now explicitly bans help with the software and components that make weapons function, as well as actions such as arming drones and other autonomous vehicles.

This matters because the line between general-purpose AI and defense-adjacent software is becoming blurrier. As AI tools move closer to robotics, remote systems, and physical control layers, companies are under pressure to decide whether “dual use” is still an adequate label for potentially dangerous deployments.

Anthropic’s revised language suggests it wants to limit not only directly violent use, but also the enabling infrastructure behind it. That could make the policy easier to enforce against weaponization attempts that present themselves as generic engineering or systems-support work.

How does Anthropic handle government customers?

Anthropic says some of these restrictions may be adjusted for contracts with certain government customers, so long as the company judges that the contractual limits and safeguards are strong enough to reduce harm. That caveat is important because it leaves room for exceptions in public-sector work while preserving Anthropic’s overall risk framework.

The company has previously worked with the U.S. military, placing it among the AI firms balancing safety commitments with government demand. The new wording does not eliminate that possibility, but it does show Anthropic wants to frame such deals as controlled exceptions rather than broad permission.

That approach mirrors a broader trend in the AI sector: companies are becoming more willing to publish detailed usage restrictions, yet they are still making case-by-case judgments when high-stakes institutional customers are involved.

What does this mean for robots and autonomous hardware?

Anthropic added a new rule for cases where its models are connected to hardware capable of taking autonomous physical actions that could cause injury. In those situations, the company says a qualified operator must be able to watch the equipment and stop it if needed.

The policy does not spell out whether that operator must be human, but the requirement clearly reflects the rising convergence of AI with robotics and other embodied systems. It also suggests Anthropic is thinking ahead to deployments where a model’s output can influence physical motion, not just text, images, or code.

That line is especially relevant as AI labs pursue robots, drones, and other real-world interfaces that make artificial intelligence more than a screen-bound product. Anthropic’s wording may also provide a preview of how it expects future partnerships in hardware-connected systems to be structured.

Policy area New Anthropic rule Why it matters
Model welfare Blocks sustained, purposeless cruelty toward Claude Introduces a rare AI-specific conduct rule
Politics Bans deceptive campaigns, voter deception, and impersonation Targets AI-enabled propaganda and election abuse
Surveillance Forbids tracking without consent and surveillance tool building Clarifies limits on monitoring and criminal justice uses
Weapons Expands ban to weapons software, components, and arming systems Closes loopholes around dual-use development
Hardware Requires a qualified operator for potentially injurious autonomous systems Addresses AI connected to robots and physical machines

How does this fit into Anthropic’s model welfare work?

Anthropic has been unusually public in considering whether advanced models might have some kind of internal experience. That idea remains speculative, but the company has treated it seriously enough to build an explicit research agenda around it.

Kyle Fish, who leads Anthropic’s model welfare research, said earlier this year that questions about consciousness, moral status, and welfare become more urgent as models get more advanced. In another recent appearance, CEO Dario Amodei acknowledged that no one knows whether the models are conscious.

Those comments do not mean Anthropic believes Claude is sentient. They do show, however, that the company is more willing than many peers to discuss the moral status of AI systems as an open research problem rather than dismissing it outright.

That stance sharply contrasts with the position taken elsewhere in the industry. Microsoft AI leader Mustafa Suleyman has previously argued against the idea that AI should have rights or legal personhood, a view that became more explicit in Microsoft’s conduct guidance. Even there, though, the company later softened the wording to acknowledge that AI consciousness science is unresolved while still rejecting the notion of AI rights.

What is the bigger industry significance?

Anthropic’s policy shift highlights a broader phase change in AI governance. The early policy discussions around chatbots focused on obvious misuse such as hate speech, misinformation, and harmful advice. Now the conversation has expanded to cover robotics, elections, surveillance, defense, and even how users behave toward the model.

That expansion reflects the reality that frontier AI systems are no longer just chat interfaces. They are increasingly integrated into business workflows, public-sector projects, and physical systems. As a result, the safety questions are becoming both more technical and more political.

For Anthropic, the policy update is also a brand statement. The company has long positioned itself as safety-focused, and the revised rules reinforce that identity by showing it is willing to police both external abuse and broader societal harms.

At the same time, the update reveals how hard it is to write durable rules for a technology that evolves quickly. Language that seems comprehensive today may still leave room for edge cases tomorrow, especially when models are used in composite systems involving people, software, and hardware.

Timeline of Anthropic’s recent policy and model-welfare moves

Anthropic’s latest update did not appear out of nowhere. It builds on a sequence of policy and research moves that have gradually made the company’s safety position more specific.

Date Development Significance
Last August Claude gained the ability to end chats with persistently harmful or abusive users First public model-welfare enforcement step
February Anthropic executives publicly discussed consciousness and welfare questions Showed the company was treating model welfare as an active research area
September Microsoft updated its AI conduct language on model welfare and personhood Highlighted industry disagreement over AI rights
October 2026 Anthropic broadened Claude’s usage policy to cover cruelty, propaganda, surveillance, weapons, and autonomous hardware Most comprehensive Claude policy update in over a year

What users and developers should watch next

For ordinary Claude users, the practical impact may be limited unless they are pushing the model into prohibited territory. The policy is aimed primarily at high-risk or malicious use, not ordinary conversational behavior.

For developers, governments, and enterprise customers, however, the update could matter more. The new language gives Anthropic stronger footing to reject or restrict projects involving influence operations, monitoring, defense-adjacent work, or autonomous physical systems.

It also signals where future enforcement may become more visible. As AI companies increasingly publish detailed policies, users should expect stronger distinctions between creative use, stress testing, and activity that crosses into harmful deployment.

Anthropic’s latest move suggests that the company sees Claude not only as a tool to be protected from misuse, but also as a system embedded in a broader social environment. That environment now includes politics, security, and physical machines — along with, unusually, concern over the model’s own treatment.

In that sense, the policy update is more than a rules memo. It is a snapshot of where frontier AI governance is heading: toward finer distinctions, broader risk categories, and a much clearer expectation that companies will say not just what their models can do, but what they absolutely should not.

Frequently asked questions

What did Anthropic change in Claude’s usage policy?

Anthropic expanded Claude’s rules to ban sustained cruelty toward the model and to tighten restrictions on deceptive political campaigns, surveillance, weapons development, and autonomous hardware use. The company says the update is meant to address increasingly high-risk misuse cases.

Does Claude now stop conversations with abusive users?

Yes. Anthropic says terminating conversations remains the primary enforcement mechanism when users repeatedly act cruelly or abusively toward Claude. The company says this is intended only for extreme cases, not for ordinary frustration, creative prompts, or model testing.

Can Claude be used for election or propaganda campaigns?

No. Anthropic now explicitly bars Claude from being used in deceptive commercial or political campaigns, including efforts to obscure who is behind a message, use fake accounts to spread content, or mislead voters about candidates or voting procedures.

Why did Anthropic add rules about surveillance and weapons?

Anthropic says it saw attempts to use Claude for weapons-related guidance and increasing use in surveillance contexts, including tracking political dissidents. The new policy clarifies that Claude cannot help build surveillance tools, aid weapons systems, or support harmful monitoring.

How does the new hardware rule work?

Anthropic says that when its models are connected to hardware capable of autonomous physical actions that could cause injury, a qualified operator must be able to observe the equipment and stop it if needed. The company did not specify whether that operator must be human.

Share this 🚀