New Claude rules: what to check in automations before November 12

An updated Claude Usage Policy takes effect on November 12, 2026. Bot and automation owners should review what recommendations the system gives people, who reviews them, and what actions AI can take on its own.

Key clarification: Anthropic is not requiring human oversight in sensitive scenarios for the first time. These requirements existed before. The new version describes their boundaries in more detail and adds safeguards for dangerous autonomous equipment actions. Update published October 8, 2026.

What has actually changed

Comparing the new policy with the version in effect since September 15, 2025 helps distinguish new requirements from clarifications.

Area What changed
Human oversight Existed before. Recommendations requiring review and the reviewer's authority are now defined more precisely.
AI disclosure Existed before. Rules for recipients of recommendations and people subject to decisions have been clarified.
Surveillance and law enforcement decisions Anthropic has described the prohibitions in more detail while retaining its previous approach to enforcement.
Dangerous physical actions Requirements for operator monitoring, stopping, and placing equipment in a safe state have been added.
Deceptive campaigns Previously scattered prohibitions have been consolidated into a separate section.

In the previous version, automated generation and external publication of professional journalistic content were separately listed as high-risk scenarios. The new list has no separate item for this. Prohibitions on misinformation and deception remain.

Basis for comparison: previous version of the Usage Policy and version taking effect on November 12, 2026.

Which processes to review first

Start with automations whose output affects a specific person. The new version lists legal and medical advice, personalized investment and tax advice, lending, insurance, housing, employment, education, access to healthcare and public services, and decisions on legal status.

Practical check: find the point in your processes where Claude's text becomes a recommendation to a client or a system action.

  • Does the HR bot collect information from résumés or already rank candidates?
  • Does the legal assistant search for documents or draft a ready-to-file application?
  • Does the medical bot schedule appointments or interpret symptoms?
  • Does the financial assistant explain terms or recommend a specific investment?
  • Does the rental service accept applications or independently decide whom to reject?

For the audit, record for each process: input data, Claude's output, the recipient of the output, and actions available to the system. The label “internal assistant” alone says nothing about the consequences of its work.

When a human needs to be in the loop

For a high-risk recommendation, a qualified specialist must meaningfully review the result before it is provided to a person or a decision is implemented. The reviewer needs expertise in the relevant field, the right to modify the result, and a license if required by applicable law.

To make such a review work technically, we recommend the following process:

  1. Claude prepares a draft. The result receives the status “Pending review”.
  2. The specialist sees the context. They have access to the source data, documents used, and proposed response.
  3. The specialist makes a decision. Approves, corrects, rejects, or requests additional information.
  4. The system implements the approved version. Sends the response or performs the permitted action.

The “Approve” button is useless if the employee sees only the final score without an explanation and source materials. The review must provide enough information to identify an error.

Important setting: a lack of response from the reviewer must not automatically count as approval. If the specialist is unavailable, the request remains in the queue or is assigned to another authorized employee.

Where to tell users about AI use

External chatbots and agents must disclose that the user is interacting with AI: at the start of each session or in the product interface. For high-risk recommendations, also notify the person receiving the advice or affected by the decision. It is not necessary to mention Anthropic, Claude, or the model name.

A practical option for a regular customer bot:

You are interacting with an AI assistant. It helps find information and forward requests to an employee. You can contact a person if needed.

For a process with mandatory specialist review, you can use different wording:

AI is used to prepare the response. Before a personalized recommendation is sent, it is reviewed by a specialist.

Use the second wording only after implementing an actual review. If the response has already been sent automatically, promising human oversight misleads the user.

Check all entry points: the website, Telegram, application form, support widget, and reopening the conversation. The notification must be visible where people use the product.

Which autonomous actions to limit

First, make a list of the tools available to the agent: sending messages, updating the CRM, initiating payments, working with files, controlling equipment. Then separately identify actions that require confirmation.

For software integrations, we recommend:

  • separate draft preparation from sending it to the customer;
  • give the agent separate credentials with minimal permissions;
  • check authorization for actions in the application, not only in the prompt;
  • tie approval to a specific version of the response;
  • provide for stopping the process and handing it over to a person.

We discuss access architecture in more detail in the article on AI agent security and restricting permissions in email and CRM.

For equipment capable of causing injury under autonomous control, the new policy requires oversight by a qualified operator, the ability to stop it, and a safe state if communication with Claude is lost. Safe operating limits must be enforced by the equipment or controller independently of the model's output.

Practical takeaway for developers: the model's command must not be able to disable emergency protection. Such integrations should be reviewed together with a specialist in the relevant equipment.

What cannot be fixed with a confirmation button

A prohibited scenario does not become permissible after adding a human. Anthropic separately prohibits decisions and recommendations in law enforcement and criminal proceedings, such as on investigation or arrest, as well as certain forms of non-consensual surveillance.

Therefore, start the audit with the system's purpose. If the scenario itself is prohibited, improving the approval interface does not solve the problem.

Example: how to improve HR automation

Training example. A company receives resumes through a form. Claude assesses candidates, records a score in the CRM, and automatically sends rejections to people below a set threshold.

For this process, we suggest the following improvement:

  1. Keep the original resume and job requirements.
  2. Use Claude to prepare a structured review indicating missing information.
  3. Send the assessment and response draft to an authorized HR specialist.
  4. Allow sending only after confirmation of the specific text.
  5. Record who reviewed the result and what changes they made.
  6. Provide notice to the candidate about the use of AI.

For an MVP, one vacancy and a limited application queue are enough. Before enabling bulk sending, test the process with incomplete resumes, conflicting information, and incorrect assessments.

For n8n or Python: maintain the statuses “Draft,” “Pending review,” “Approved,” “Rejected,” and “Completed.” Before taking action, check the status, the reviewer's authority, and that the approved result version matches. After editing a draft, request new approval.

Checklist by November 12, 2026

The following items are recommendations for a technical audit. The logging and statuses below are suggested as a way to organize controls; Anthropic does not establish a universal log format for all integrations.

  • Inventory. All processes involving Claude have been identified, including background tasks and connected tools.
  • Purpose. For each process, it has been determined whether it provides a personalized recommendation or affects a decision about a person.
  • Prohibitions. It has been checked whether the use case itself is permitted.
  • Reviewer. A specialist with the necessary knowledge and authority has been assigned.
  • Execution block. Critical action is impossible before review.
  • Transparency. AI notice is placed at the relevant interaction points.
  • Access rights. The agent has received only the necessary permissions.
  • Log. The result, version, reviewer, their decision, and the action performed are retained.
  • Failure. Behavior in the event of an API failure, timeout, empty response, and absence of a specialist has been checked.
  • Stop. The responsible employee can suspend the process.
  • Testing. Tests with incorrect data, repeated requests, and attempts to bypass approval have been completed.

In the log, use request IDs and the necessary details. Do not copy the entire volume of personal documents there without a justified need.

What businesses in Bulgaria and the EU should consider

The Usage Policy sets out the terms for using Anthropic products. It does not replace legislation: the new version explicitly retains the obligation to comply with applicable legal requirements.

For businesses, it is useful to conduct two checks: compliance with the model provider's rules and compliance with requirements applicable to the specific process. The basic organization of such work is covered in the checklist for preparing an AI project for EU requirements.

The audit result should be specific: a list of processes, required changes, responsible employees, and tested failure scenarios. The phrase "do not make important decisions" in a prompt does not replace restrictions in the system itself.

If Claude is already connected to customer bots, CRM, or internal processes, discuss automation auditing with CenterAI: we will review the agent's actions, approval of results, and behavior during failures.

Sources and verification

Review date: October 9, 2026. The new version of the policy and the previous version of September 15, 2025 were compared.

Leave a Reply

Your email address will not be published. Required fields are marked *