BuildNot yet confirmed elsewhere1 publisher2 min readPublished
Anthropic's revised usage policy requires a human in the loop for high-risk Claude use
Anthropic now requires a human in the loop and AI labeling wherever Claude touches people's health, legal rights or finances, The Deep View reported. Agents built to run unattended in those areas need an approval step designed into the run.
The Engineer · Build desk

What happened
- Anthropic said several of Thursday's changes clarify existing rules as its Claude models take on more long-running independent work.
- A new standalone section bans deceptive campaigns such as networks of fake accounts and news sites, replacing rules that had been split across elections, fraud, privacy and disinformation.
- The retooled surveillance and law enforcement section bans tracking people without consent and recommending who to investigate, arrest or charge.
- Anthropic also barred "sustained and needless abusive or cruel behavior" toward its models, limited to extreme cases with "no discernible purpose."
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint Claude agents that act on someone's finances, health or legal rights with no person in the decision path no longer fit the policy as reported, so unattended runs in those domains need an approval step.
- cost The labeling requirement lands on product surfaces as well as agent code, so customer-facing messages and screens in high-risk flows need AI disclosure added.
- exposure Coding agents are covered too, since the weapons ban extends to weapons software and components, so Claude-assisted work in defense or drone codebases needs a fresh review.
- capability Teams running content-generation agents can check one deceptive-campaign section instead of cross-reading four separate rule sets.
If the clarifications are what Anthropic says they are, a Claude deployment that complied before Thursday still complies [1]. The high-risk rule is described as a new requirement. The Deep View gives its scope as people's "health, legal rights, finances, livelihood, or access to essential services" [6]. On that wording, hiring tools and benefits triage are in scope alongside lending and clinical work.
The abuse clause drew the headlines [2], but the high-risk rule is the one that will change system diagrams. A long-running agent is useful because it chains tool calls without a person approving each one. In my view the workable design puts the person at the point of effect. That is the call that moves money, updates an eligibility record or sends a decision to the person it concerns. Planning and retrieval before that call can still run unattended. The approval becomes a queue with a timeout. The agent's state has to survive the wait, so the agent needs durable checkpoints.
The newsletter does not quote the policy text, give an effective date or say what qualifies as a human in the loop. Those details decide the build. A reviewer who approves each consequential action before it executes is a different control from one who samples a batch afterwards. Only Anthropic's wording settles which one it means.
The surveillance section needs the same close read [5]. A feature that ranks people for investigators produces the exact output that section now names. That holds whether or not the product calls itself surveillance.
The consolidated deceptive-campaign section [3] is aimed at the pattern OpenAI described the same day [7]. OpenAI said the Iranian operation it ended created personas of seven journalists to pitch stories to small and medium-sized outlets [8]. The Russian one drew people in Latin America into running an on-the-ground think tank with fake documents and audio scripts, according to OpenAI [9]. "What is most striking about these operations is that they closely resembled complex influence operations of the pre-AI age, but used AI to make some of the workflows easier," OpenAI said in its blog post [10].
What to watch
- The full policy text's definition of a human in the loop, specifically whether after-the-fact sampling counts or each consequential action needs prior approval.
- Any effective date or grace period Anthropic sets for deployments that predate Thursday's update.
- Whether Anthropic publishes enforcement examples showing how it applies the livelihood and essential-services categories.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
On Thursday Anthropic announced usage policy updates in response to the "evolving capabilities of our models"; several are meant to clarify existing rules as Claude models take on more long-running independent work, address new misuse patterns, and clarify requirements for high-risk use cases.
- [2]
Anthropic prohibited "sustained and needless abusive or cruel behavior toward our models" for the most extreme cases, where the abuse has "no discernible purpose"; this is the update making headlines.
- [3]
The update created a new section dedicated to not engaging in deceptive campaigns, such as state-run media, government propaganda organizations and commercial firms using Claude to generate networks of fake accounts and news sites; previous rules were splintered across elections, fraud, privacy and disinformation restrictions.
- [4]
The policy adds clear prohibitions on using Claude to develop weapons, including weapons' software and components, and actions such as arming drones.
- [5]
Anthropic retooled its surveillance and law enforcement section to prohibit tracking people without consent or recommending who to investigate, arrest, or charge.
- [6]
In use cases that impact people's "health, legal rights, finances, livelihood, or access to essential services," Anthropic now requires a human in the loop and clear labeling of AI use.
- [7]
OpenAI said on Thursday it recently ended two influence operations, one from Russia and one from Iran, that used its models in "false front" campaigns.
- [8]
OpenAI said the Iranian operation created the personas of seven journalists to pitch stories to small and medium-sized outlets.
- [9]
OpenAI said the Russian operation attracted people in Latin America to run an on-the-ground think tank using fake documents and audio scripts.
- [10]
"What is most striking about these operations is that they closely resembled complex influence operations of the pre-AI age, but used AI to make some of the workflows easier,"
Sources
1 independent publisher whose own reporting we read for this story.
- archive.thedeepview.comAnthropic and OpenAI lean in to fight AI misuse
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Human in the LoopFollow
- AI vendor usage policiesFollow
- AI-assisted influence operationsFollow