Anthropic updates Claude’s usage policy
Anthropic will update Claude’s usage policy on September 15, 2025. The new version sets stricter limits on cyberattacks, allows more legitimate political uses, and clarifies which controls apply to consumer-facing services.

Anthropic will change Claude’s usage policy on September 15, 2025. The update specifies what is prohibited in cybersecurity, allows more legitimate political uses, and clarifies when additional controls must apply to products intended for the public.
The company presents the changes as a response to user feedback, the evolution of its products, new regulations, and its oversight priorities. The policy will continue to serve as the framework defining what Claude may and may not be used for.
Clearer limits for cybersecurity
Claude can already perform more autonomous tasks through tools such as Claude Code and Computer Use. It is also used within coding agents, systems that can execute multiple steps on their own to complete a task.
That progress increases the risk that someone could use AI to create malware, attack networks, or compromise systems at scale. Anthropic will therefore add a dedicated section prohibiting malicious activities targeting computers, networks, and infrastructure.
The policy will not block all security research. For example, vulnerability analysis will remain allowed when the system owner has given consent. The company will also publish specific examples of how these rules apply to AI agents.
More room for political content
Until now, the policy broadly prohibited lobbying and campaign content. Anthropic acknowledges that this approach could also prevent legitimate uses, such as researching public policy, preparing civic education materials, or drafting political texts.
The new version will focus on blocking deceptive or capable of disrupting democratic processes uses, as well as voter targeting and campaigning. In practice, Claude may be used to analyze a bill, but not to design political manipulation operations aimed at specific groups.
What changes for businesses and public agencies
For law enforcement, Anthropic says the change is mainly a matter of wording. The company is keeping its restrictions on surveillance, tracking, profiling, and biometric monitoring, while clarifying which administrative and analytical tools were already allowed.
It also clarifies the scope of its requirements for high-risk uses in areas such as legal, financial, and employment services. Additional requirements, including human oversight and notifying people that they are interacting with AI, will apply when the output reaches consumers directly.
This means that a company using Claude internally to support its employees will not be covered by those specific requirements in the same way as a service that uses Claude to make a decision or recommendation directly to its customers.
The changes will take effect on September 15, 2025. The key question will be how Anthropic turns these rules into concrete controls: a more detailed policy may provide greater protection for legitimate users, but it will also require precise decisions when a useful task and a risky activity look similar.