Skip to content
OTFotf
All posts

Anthropic’s November 12 Usage Policy update: checklist for AI app builders

D
DaveAuthor
6 min read
Anthropic’s November 12 Usage Policy update: checklist for AI app builders

Anthropic’s updated Usage Policy takes effect on November 12, 2026. For teams building an app that sends user requests to Claude, the useful step is not to rewrite every prompt. Inventory where Claude makes recommendations that could affect people or is connected to hardware that can take physical actions, then review those flows against the policy update.

Anthropic says much of the update clarifies existing requirements. It calls out clarified high-risk use requirements in areas such as health and finance, and adds controls for cases where Claude is used to take autonomous physical actions. It also describes more explicit policy language around deceptive activity, elections, weapons, surveillance, law enforcement, and abusive conduct toward models. This checklist helps product and engineering teams identify which flows need review before the effective date. It is an implementation aid, not legal advice.

Start with a use-case inventory

Search your codebase and product configuration for every Claude integration: API calls, user-facing assistants, background agents, tools, browser automation, and connected devices. Record what information enters each flow, what the model can return, which actions can follow, and who reviews the result.

A useful inventory row can be simple:

SurfaceModel outputCan it affect a person or device?Human reviewNext check
Support assistantGeneral explanationNo individual decisionSupport escalationConfirm it does not cross into personal advice
Benefits featureEligibility recommendationYes, public benefitQualified reviewerApply high-risk recommendation controls
Building controllerEquipment commandYes, physical actionOperator observes and can stopValidate independent limits and safe state

Classify the behavior rather than the industry label. Anthropic describes the update as clarifying how existing rules apply to Claude’s longer, more independent work. The announcement does not say that every health or finance feature is prohibited; it says requirements for high-risk use cases are clarified. Review the actual flow against the policy instead of inferring a ban from the sector name.

Check whether an output is a high-risk recommendation

Anthropic’s announcement specifically calls out high-risk use cases in areas such as health and finance. Start by locating flows where Claude’s output could influence a user’s health or financial choices. This is a triage prompt, not a complete list of policy categories: consult the Usage Policy itself for the actual covered requirements.

For each flow, record what the model is asked to do, what information it sees, and whether someone might rely on its output. The product team should not treat a general information feature and a personalized recommendation as the same workflow. This inventory is a practical review aid; use the complete policy text to determine which exact requirements apply to a specific feature.

The update describes a qualified human-in-the-loop requirement for high-risk advice and decisions: a qualified person must be able to review and, if necessary, change Claude’s recommendations. It also says the affected individual must be told AI was used. Keep both steps visible in the product flow. Do not treat a model-generated answer as ready for delivery just because it passed a formatting check.

Translate those requirements into product behavior. Put review before the output reaches the person or triggers a decision. Give reviewers enough context to assess the recommendation, a clear way to change it, and an escalation path when they cannot verify it. Record which flow is under review and where the disclosure appears so the team can repeat the check when the feature changes.

Dex and Luna review a Claude recommendation, edit or reject it, and disclose AI use before it reaches the user

Same component. Web and mobile. One codebase.

The free, open-source SDK gives you components that work the same on web and mobile — one codebase. github.com/otf-kit/sdk

Get the free SDK

Map physical actions separately

A model connected to hardware can create a different class of risk from software that only drafts a suggestion. Anthropic’s update adds requirements for use of its models with hardware that takes autonomous physical actions and might be capable of causing injury.

If your product has such a connection, map the whole command path: model output, tool or service call, controller, device, and the person who can intervene. The update says a qualified operator must be able to observe the equipment and stop it if needed. It also says the equipment must be able to hold a safe state if Claude is disconnected.

Test the stated controls as system behavior, not prompt wording. Simulate loss of service and operator stop actions. Confirm that the operator can observe the equipment and intervene, and that the connected equipment reaches the safe state your implementation defines when Claude disconnects. Keep evidence with the integration’s review notes.

Byte and Nova check an AI-connected machine's permission gate, operator stop, and safe state when service disconnects

Review agent tools and user-facing disclosure

If your app uses Claude through tools or an agent, inventory those paths as part of your review. Record which actions are available and whether they can reach hardware or influence a high-risk recommendation. This is an engineering method for locating affected flows, not a new Anthropic policy requirement.

Do not infer from a successful test response that a use is permitted. The announcement describes clarified rules for deceptive activity, elections, weapons, surveillance, law enforcement, and abusive behavior toward models. If an integration touches one of those areas, open the corresponding section in the full policy and review the exact text before changing the feature.

Make the review repeatable

Put the checklist into the release process for Claude-powered features:

  1. List every model call, agent, tool, and device path that can affect an external user or system.
  2. Mark flows that make recommendations about a specific person in one of the policy’s high-risk areas.
  3. Confirm a qualified reviewer can change covered recommendations before delivery or use, and that users receive the required disclosure.
  4. For physical-action flows, test operator observation and stop controls, safe state on service loss, and independent operating limits.
  5. Confirm consumer-facing chatbot disclosure and check what each agent tool can actually change.
  6. Save the policy version, review owner, test evidence, and unresolved questions with the feature’s release record.

Keep one owner for each reviewed integration and a date for its next review. If the feature changes its model, tools, or connected equipment, rerun the relevant checks instead of carrying forward an approval that described a previous design. That gives the team a concrete record of what was examined before the effective date.

The practical goal is to find the Claude integrations whose behavior needs a product change before November 12, rather than treating every model call as the same risk. Revisit the inventory when you add tools, change what an agent can do, or connect a model to a new data source or device. For a broader review of production safeguards around AI features, see the AI app security checklist.

Sources

ai-toolsagentsannouncement
OTF SDK + Kits

Buy once, own the code. Ship with the agent you already use.

  • Free, open-source SDK — same component, web and mobile
  • Paid kits include AI configs + 40+ tested prompts — your agent reads the whole project
  • $99/kit or $149 for everything. No subscription, no sandbox limit.
Need more than components?

Full-stack kits.
Pay once, own the code.

Auth, database, and payments already connected — so you ship product, not setup. Or take the delivered kits in the Bundle.

Everything Bundle — $149See full pricing

Get the free AI configs pack

Pre-tuned AI configs for Cursor, Claude, and Lovable — drop them in and your AI tool instantly understands your project.

No spam. Unsubscribe any time.

Prefer the free SDK? Star it on GitHub →