The three gates
Ask in this order
- 1 · Permitted?Does the Usage Policy allow this at all?
- 2 · Suited?Is this the kind of work Claude does well?
- 3 · Controlled?Who reviews it, and is AI use disclosed?
Gate 1 — is it permitted at all?
Anthropic publishes a Usage Policy that applies to everyone using Claude, on every plan. Its first part, the Universal Usage Standards, is a list of things nobody may do with Claude. It is broader than most people expect and worth reading once end to end, but the themes are recognisable: attacking computer systems or critical infrastructure, developing weapons, generating child sexual abuse material, creating fraudulent or deceptive content such as phishing and fake documents, impersonating a real human being, interfering with elections, and promoting self-harm or violence.
Two entries in that list catch ordinary office workers out. The policy prohibits compiling personal data about people without a proper basis, which rules out the “find me everything about this named individual” research request. And it names criminal-justice applications — parole and sentencing decisions, predictive policing, surveillance and emotion recognition — as off limits, which matters to anyone in the public sector.
Gate 2 — the high-risk middle ground
The Usage Policy has a second part, High-Risk Use Case Requirements, that covers uses affecting a person’s rights, safety, livelihood or access to essential services. The named domains are legal advice and decisions with legal consequences, healthcare and mental-health guidance, insurance underwriting and claims, financial decisions such as lending and investment advice, employment decisions including résumé screening, housing eligibility, academic testing and admissions, and automated journalistic or media content.
These are not forbidden. They carry two standing conditions. Human-in-the-loop: a qualified professional reviews the output before it is acted on. Disclosure: where the output reaches a consumer or member of the public, they are told that AI was involved — the policy asks for this at a minimum at the start of each session. A separate guideline applies the same logic to consumer-facing chatbots, which must tell people they are talking to an AI rather than a person.
Which gate did it fail?
- On the prohibited listDo not use ClaudeNo configuration makes it allowed
- High-risk domainAdd expert reviewQualified reviewer plus disclosure to the person affected
- Claude cannot know itSupply the sourceAttach the document rather than asking from memory
- Merely unfamiliarProceed and verifyNormal checking, covered in 2.4
Gate 3 — is Claude suited to it?
Permission is not fitness. Anthropic’s own help centre is blunt that Claude can hallucinate: it can produce fabricated quotations, and it can be confidently wrong about recent events because its training data has a cutoff. The guidance is to scrutinise high-stakes advice rather than rely on it, and, when Claude has searched the web, to open the cited pages and read them in their original context.
That gives a practical test for fit. Ask where the facts in the answer are going to come from. If they come from a document you attached, a connector you configured, or the text of the conversation itself, Claude is on solid ground — it is reading, summarising, restructuring, drafting. If they have to come from Claude’s memory of the world — a policy number, a price, a regulation, last quarter’s figures, whether a client is still under contract — you are asking for trouble, and the fix is almost always to supply the source rather than to prompt harder.
| Task | Where the facts come from | Verdict |
|---|---|---|
| Summarise this 40-page supplier contract | The attached document | Good fit |
| Rewrite this rejection letter in plainer English | The letter you wrote | Good fit |
| Draft interview questions for this job description | The description, plus general craft | Good fit |
| What does our refund policy say? | Claude’s memory — unless you attach it | Attach the policy |
| Which of these 200 applicants should we interview? | A high-risk employment decision | Human decides; disclose |
| Find everything about this named private individual | Compiling personal data | Not permitted |
Reshaping a high-risk request
Asks Claude to decidetext
Here are 340 CVs.
Tell me the best 12
candidates for the
seasonal supervisor
role and rank them.Asks Claude for evidencetext
Attached: the approved
scoring rubric and one
application.
For each of the five
criteria, quote the
words in the application
that bear on it. If the
application says nothing
about a criterion, write
"no evidence". Do not
score or rank.Writing it down before you need it
Judgement made case by case does not survive a busy week. Teams that use Claude well keep a short written list with three columns — green, amber, red — and put real examples in each, not abstractions. Green is work that goes ahead unsupervised: internal drafting, summarising documents you already have, reformatting, brainstorming. Amber is work that goes ahead with a named reviewer: anything customer-facing, anything quoting a figure, anything in a high-risk domain. Red is the short list of things nobody does: the Usage Policy prohibitions plus whatever your own sector adds.
A team’s use-case list, checked
- Passes: Summarise a supplier contract we holdGreen — source attached, internal use
- Passes: Draft the weekly team update from my notesGreen — no external facts asserted
- Check: Write the customer-facing outage noticeAmber — comms lead signs off before it posts
- Check: Explain a declined claim to a policyholderAmber — high-risk; adjuster decides, clauses checked
- Fails: Score job applicants and pick the shortlistReshape — human decides; disclose AI involvement
- Missing: Build a profile of a named private individualRed — compiling personal data, not permitted
Anthropic does its own work on the other side of this line: it tests policies with outside domain experts, runs classifiers that detect violations in real time, and evaluates models for bias before release. None of that removes your responsibility for the particular task in front of you — the safeguards are built for harm at population scale, not for whether this letter to this policyholder is accurate. Data sensitivity and the privacy questions that sit alongside these gates are covered in 6.2; your own employer’s rules are 6.3.
Traps the wrong answers are built from
| Tempting but wrong | Do this instead |
|---|---|
| Refusing any task that sounds sensitive | Check which gate it fails. Most high-risk tasks are permitted with a qualified reviewer and disclosure. |
| Treating a permitted task as automatically a good fit | Ask where the facts will come from; if from Claude’s memory, supply the source instead. |
| Using AI in a high-risk domain without telling the affected person | Disclose AI involvement to consumers, at minimum at the start of each session. |
| Asking Claude for the verdict in a legal, medical, lending or hiring decision | Ask for structured evidence against criteria a human set, and let the qualified person decide. |
| Keeping the rules in one person’s head | Write a green/amber/red list with real examples your team recognises. |
You should now be able to
- Sort a proposed task into prohibited, high-risk-with-conditions, or ordinary use.
- Name the two standing conditions the Usage Policy attaches to high-risk uses.
- Spot the domains — legal, health, insurance, finance, employment, housing, academic, media — that trigger those conditions.
- Reshape a request so a qualified human makes the decision and Claude does the drafting or extraction.
- Judge fitness by asking where the facts in the answer will come from.