What should our AI policy actually say?
Six things: which Claude plan and account staff may use, what may and may not be typed into it, who reviews output before it reaches a client, when you disclose AI involvement, who is accountable when the output is wrong, and what happens when someone breaks the rules. Two of those are not optional in a regulated service line, because Anthropic's Usage Policy already requires that a qualified professional review AI-assisted advice before it is finalized and that you disclose AI involvement to the person receiving it. Anchor the whole document to one named plan, because Anthropic's consumer terms and commercial terms handle your data differently, and a policy written against the wrong one governs nothing you actually run. Everything below is a starting point drafted for a US service business, not legal advice, and employment policy is jurisdictional enough that a lawyer where you operate should review it before you make it binding on employees.
Before you copy any of this
This page is a draft policy, not an article about policy. The clauses below are written to be lifted into a handbook and edited in an afternoon. What follows assumes a US service business somewhere between fifty and eight hundred people, with clients or patients who did not consent to anything, a few licensed professionals whose signature carries weight, and staff who started using Claude on their own accounts before anyone asked.
It is a starting point and it is not legal advice. I am a co-founder at AuraPath AI and an Anthropic Claude Ambassador, not your lawyer. Employment policy is jurisdictional. What you may require, what you may monitor, what you may discipline someone for, and what you must disclose all change by state, by license, by union agreement, and by whatever your existing handbook already promised. Have counsel in the jurisdictions where you employ people review this before it binds anybody, and have them look specifically at the discipline clause, because that is the part most likely to be unenforceable as written.
A wrong policy is worse than none. Two ways that happens. The first is a policy that assumes a plan you do not have, so every sentence about retention and training is false for your deployment. The second is a five-page document nobody opened, which creates a paper record of a control that is not operating. Keep it short enough that people read it, specific enough that they can tell whether they just broke it, and dated so you know when it went stale.
One more note on what this page deliberately does not do. It makes no claim about what a written policy achieves legally. It does not tell you whether adopting it reduces your exposure, satisfies any regulator, or discharges a professional duty. Those are questions for your counsel, your carrier, and your licensing board, in that order.
- Adopt in this order: pick the plan, write the two data lists, name the reviewers, then write the consequence. Skipping straight to the consequence is why most templates sit unread
- Put a review date in the header. Anthropic revises its terms and support documentation frequently, and several of the plan behaviors below are documented on pages that changed this year
- Name a single owner for the document by title, not by person, so it survives turnover
- Get an acknowledgment on file, and ask counsel whether your jurisdiction expects a signature, a click, or nothing at all. Do not guess at that
Clause 1: which Claude this policy governs
Start here, because this clause decides whether the rest is true. Anthropic runs two separate legal tracks. Under the Consumer Terms of Service, which govern Claude.ai, Free, Pro, and Max, the terms state that Anthropic may use Materials to provide, maintain, and improve the Services and to develop other products and services, including training models, unless you opt out of training through your account settings. Under the Commercial Terms of Service, which govern Claude for Work and the API, the language is the opposite: Anthropic may not train models on Customer Content from Services, and Customer retains rights to its Inputs and owns its Outputs.
So a policy that says do not put client data into AI without naming the account is not a policy, it is a mood. Two people can follow that sentence identically and end up on opposite sides of a training default. Name the plan, name the organization, and say what happens on personal accounts.
It is worth reading Anthropic's own consumer guidance next to the consumer terms, because they describe the same setting from different angles. The help center article says Anthropic will use your chats and coding sessions if you choose to allow it, if conversations are flagged for safety review, or if you otherwise opt in. The Terms describe training as applying unless you opt out. Do not resolve that from either page. Open the privacy settings on the account in question and look at the toggle, then write down what you saw and the date.
The plan also decides what is even available to you. Anthropic's Team plan article lists SSO, domain capture, and just-in-time provisioning, and caps Team at 150 seats with a two-member minimum. The Enterprise article adds audit logs, SCIM, custom data retention controls, the Compliance API, customer-managed encryption keys, and US-only inference, with a twenty-seat minimum self-serve and fifty seats sales-assisted. Note that Anthropic's roles and permissions table places Manage SSO and auth under a heading marked Enterprise plan only while the Team article lists SSO as included, so verify that one in your own console rather than in a procurement deck. If you handle protected health information, the constraint is blunt: Anthropic states the HIPAA-ready configuration and its click-to-accept BAA are available on Enterprise plans only, and that Team and individual plans cannot enable HIPAA.
- Approved surface: company work is performed only in the [COMPANY] organization on the [Claude Team / Claude Enterprise] plan, signed in with your [COMPANY] email address. That organization is the only Claude environment authorized for company or client information
- Personal accounts: you may keep a personal Claude account for personal use. Company information, client information, patient information, and anything you would not post publicly may not be entered into it. This includes your own drafts of client work
- This is the same rule as your existing one about emailing a client file to a personal address. If you are unsure whether something counts, it counts
- Already been using a personal account for work: tell [ROLE] within [10] business days of this policy taking effect. No discipline for coming forward in that window. See Clause 5
- Contractors and temporary staff: no company or client information goes into any AI tool unless they are provisioned a seat in the [COMPANY] organization. A contractor's own paid account is a personal account for the purpose of this policy
- Other AI tools: this policy covers Claude because that is what we license. Any other assistant, including one embedded in a tool you already use, requires written approval from [ROLE] before company or client information touches it
- Note for anyone using a work email on a personal plan: Anthropic's Consumer Terms state that if you use an email address owned by your employer, your account may be linked to the organization's enterprise account and the organization's administrator may be able to monitor and control it, including access to Materials. Do not treat a work-email personal account as private
- Review trigger: if we change plans, this clause is rewritten before the migration, not after
Clause 2: what may go in, and what never goes in
Generic privacy language fails here. Do not sensitive information will not survive a busy Tuesday afternoon with a deadline. Write the categories in the vocabulary your staff actually uses for the documents that actually sit on their desks, and make the never list the shorter, sharper one.
There is a contractual reason to be concrete beyond good hygiene. Both of Anthropic's agreements put the permission question on you. The Commercial Terms state that Customer represents and warrants that it has all rights and permissions required to submit Inputs to the Services, and the Consumer Terms carry an equivalent representation for individuals. When somebody pastes a signed contract belonging to a third party, they are making that representation on your behalf without anyone checking whether it is true. The Commercial Terms also make Customer Content your Confidential Information, which is protective of you but says nothing about whether you had the right to hand over a client's document in the first place.
Anthropic's Usage Policy adds a floor that applies on every plan. It prohibits using the products to misuse, collect, solicit, or gain access without permission to private information such as non-public contact details, health data, biometric or neural data, or confidential or proprietary data. That is a conduct rule that applies to your staff whether or not you write anything down, and Anthropic states its Safeguards Team implements detection and monitoring to enforce the policy and that it may throttle, suspend, or terminate access for violations.
The escalation rule at the end of the list is the one most templates omit and the one that matters most. When somebody hits a task that only becomes useful with real client data in it, the correct move is not a better scrub. It is a conversation about whether you need a different surface, a BAA, or a zero-retention arrangement. Build a path for that or people will quietly decide it themselves.
- MAY GO IN: our own marketing copy, service descriptions, and public pricing. Published court opinions, statutes, regulations, and public filings. Vendor documentation we are licensed to use. Our own internal SOPs, templates, and checklists that name no client. Meeting notes you wrote yourself with client identities removed. A de-identified version of a client situation. Code and configuration from our own systems that contains no credentials and no customer records
- NEVER GOES IN: chart notes, encounter notes, lab or imaging results, or anything that puts a patient name and a clinical detail in the same document
- NEVER GOES IN: signed contracts, engagement letters, settlement agreements, or drafts of any of those, where a counterparty is named
- NEVER GOES IN: matter files, deposition transcripts, discovery productions, or anything produced under a protective order
- NEVER GOES IN: payroll registers, W-2s, I-9s, benefits enrollment, garnishment orders, or any employee compensation record
- NEVER GOES IN: bank account and routing numbers, card numbers, merchant processor details, Social Security numbers, driver license or passport numbers, or a date of birth paired with a name
- NEVER GOES IN: insurance claim files, loss runs, or adjuster notes that name the insured
- NEVER GOES IN: anything received under an NDA that names the counterparty, and anything a client marked confidential
- NEVER GOES IN: passwords, API keys, shared logins, or any credential, in any form, ever, including in a screenshot
- NEVER GOES IN: employee complaints, investigation notes, performance plans, or termination documentation
- NEVER GOES IN: resumes, applications, or candidate materials when the task is screening, ranking, or scoring. Anthropic's Usage Policy treats employment decisions as a High-Risk Use Case. See Clause 3 before you do this at all
- REDACTION RULE: de-identified means you replaced names, addresses, employers, account and file numbers, exact dates, and any detail specific enough to identify one person or one deal. Changing a name and leaving the address is not redaction. [ROLE] can show you what an acceptable version looks like
- ESCALATION RULE: if a task is only useful with real client data in it, stop and ask [ROLE]. Do not scrub harder and proceed. That request is a signal we may need a different tool or a different agreement, and it is treated as a good-faith question, never as a problem
- CONNECTORS AND INTEGRATIONS: only those on the approved list maintained by [ROLE]. Connecting a system sends data to a third party under that party's terms, not ours, and turning one on is an approval decision rather than a personal preference
- UPLOADS: the same two lists apply to files, screenshots, photographs of documents, and pasted email threads. The rule is about the content, not the format
Clause 3: who reviews output, and who is accountable when it is wrong
This is the clause that separates a real policy from a privacy notice. Anthropic's Usage Policy names High-Risk Use Cases and imposes two requirements on them. The human-in-the-loop requirement: when using the products to provide advice, recommendations, or subjective decision-making directly affecting individuals or consumers, a qualified professional in that field must review the content or decision prior to dissemination or finalization, and the policy states plainly that you or your organization are responsible for the accuracy and appropriateness of that information. The disclosure requirement is covered in Clause 4.
The categories Anthropic lists are the categories mid-market service businesses live in: legal, meaning legal interpretation, legal guidance, or decisions with legal implications; healthcare, including medical diagnosis, patient care, therapy, and mental health, with wellness advice such as sleep, stress, nutrition, and exercise expressly excluded; insurance underwriting, claims processing, and coverage decisions; finance, including investment advice, loan approvals, and creditworthiness; employment and housing, including resume screening and hiring tools; academic testing, accreditation, and admissions; and media or professional journalistic content generated and published for external consumption. If you run a clinic, a firm, an agency, or a staffing company, read that list against your actual service lines and mark which ones you are inside.
Anthropic's Commercial Terms push the same duty at you from a different direction, and this one is worth quoting to your staff verbatim. It is Customer's responsibility to evaluate whether Outputs are appropriate for Customer's use case, including where human review is appropriate, before using or sharing Outputs. The Terms then add that Customer acknowledges, and must notify its Users, that factual assertions in Outputs should not be relied upon without independently checking their accuracy, as they may be false, incomplete, misleading or not reflective of recent events. That notification duty is not aspirational. Writing this clause and circulating it is how you perform it.
Accountability has to land on a person, not a process. The failure mode in every organization I have watched roll this out is diffusion: the drafter assumed the reviewer would catch it, the reviewer assumed the drafter had checked it, and the client got a citation to a case that does not exist. Name the role that signs, and say out loud that the tool is never the accountable party.
- Nothing generated with Claude leaves this company without a named human reviewer who is competent to catch the specific kind of error that output could contain. Competent means they could have written it themselves
- For work in our high-risk lines, listed here as [LINES], the reviewer must be a qualified [licensed professional / credentialed role] and must review before the work is finalized or sent, not after
- Reviewer of record: the person who reviews is accountable for the content as if they had drafted it. Not the drafter, not the tool. Claude is not a reviewer and cannot be cited as one
- Always requires review before it leaves: anything a licensed professional signs; anything filed with a court, agency, or regulator; anything sent to a patient or client as advice, a recommendation, or a decision; anything that becomes part of a clinical, personnel, or client record; any number that appears in an invoice, a bid, or a financial statement
- Verify every specific against the primary source, not against Claude: every case, statute, or rule citation; every dosage, code, and clinical figure; every dollar amount; every deadline and filing date; every quoted contract term; every name and title. Confirming a citation means opening it
- Read the whole thing. Pasting output into a deliverable you have not read end to end is a policy violation on its own, whether or not the output was wrong
- Hiring and promotion: no screening, ranking, or scoring of candidates or employees using Claude without written approval from [ROLE]. If approved, a qualified human makes and owns every decision and no candidate is excluded on the basis of an AI-generated assessment
- Log the minimum that makes review real: what was AI-assisted, who reviewed it, and the date. One line in the matter, chart, or job record. If logging takes longer than that, nobody will do it
- If you catch an error that already went out, that is Clause 5, and the timeline there starts the moment you notice
- Whether any of this satisfies a professional standard of care, a licensing rule, or a regulator's expectation is a question for counsel and your board, not a question this policy answers
Clause 4: what clients get told, and when you do not have to
Disclosure is where most drafts go vague, usually because the drafter is not sure what is required and hedges. Anthropic's Usage Policy is not vague about its own requirement. For High-Risk Use Cases, if model outputs are presented directly to individuals or consumers, you must disclose to them that you are using AI to help produce your advice, decisions, or recommendations, and that disclosure must be provided at a minimum at the beginning of each session. Separately, and regardless of whether the use is high-risk, Anthropic requires that all consumer-facing chatbots and external-facing or interactive AI agents disclose to users that they are interacting with AI rather than a human, again at a minimum at the beginning of each chat session. If you have put a bot on your website, that applies to you today.
The Usage Policy also prohibits impersonating a human by presenting results as human-generated, or using results in a manner intended to convince a natural person that they are communicating with a natural person when they are not. Read that alongside your intake and after-hours workflows.
The other half of this clause is the part nobody drafts, which is when disclosure is not owed. If a qualified professional uses Claude to draft or research, then rewrites, verifies, and takes ownership of the work as their own, you are in a different situation from presenting model output to a client. Draw that line explicitly so staff stop improvising it. Then go read your own paper before you finalize it. Engagement letters, MSAs, NDAs, BAAs, and client security addenda frequently contain clauses about subcontractors, third-party processing, or approved subprocessors that were written before anyone at your company had heard of any of this.
Two things I am not going to tell you, and I want to be direct about why. I am not going to tell you whether a professional duty of confidentiality or candor in your jurisdiction requires you to disclose AI assistance to a client, a court, a patient, or a licensing board, because that is jurisdiction-specific and rule-specific and getting it wrong is expensive in a way this page cannot fix. I am also not going to tell you whether your existing client agreements already permit or prohibit this. Both of those go to counsel with your actual contracts in hand. What I can tell you is that silence in a contract is not the same as permission, and that finding out during a client security review is the worst possible time.
- Standing client disclosure for high-risk work, adapt and have counsel review: We use AI tools, including Claude, to help prepare and research our work. A qualified [professional] reviews everything before it reaches you and is responsible for it
- Where that goes: at the start of the engagement in writing, and at the beginning of any session in which AI-assisted output is presented directly to the client or patient
- Any chatbot, intake assistant, scheduling agent, or auto-responder that a client or the public interacts with states that it is AI at the start of the conversation. No exceptions, no personas with human first names presented as staff
- Never state or imply that AI-assisted work was produced without AI assistance if you are asked directly. If a client asks, answer plainly and route the conversation to [ROLE]
- Disclosure is generally not required for internal drafting, internal research, summarizing our own documents, or back-office work that a qualified person then rewrites and owns. When you are unsure whether you are in that category, you are not. Ask [ROLE]
- Before this policy is published: [ROLE] reviews our engagement letters, MSAs, NDAs, BAAs, and any client security addenda for subcontractor, subprocessor, or third-party processing terms, and flags every client whose paper needs a conversation or an amendment
- Client says no: some clients will prohibit AI use on their work. Those restrictions are recorded in [SYSTEM] at the client level, visible to everyone who touches the account, before the next piece of work starts
- Vendors and partners: if we send AI-assisted work to a partner who then presents it to an end client, [ROLE] confirms who carries the disclosure obligation. Do not assume it transferred
Clause 5: what happens when someone breaks it
Almost every published AI policy template stops before this section, which is precisely why almost every published AI policy template does nothing. A rule with no stated consequence is a suggestion, and staff read it as one. This is also the single most jurisdictional clause on the page, and the one you are most likely to have to change on counsel's advice, so treat the structure below as a shape rather than as language.
Design it around the incentive you actually want, which is that people tell you fast. The expensive version of an AI incident is not the paste. It is the four weeks between the paste and the moment somebody admits it, during which you could have contained it, notified whoever needed notifying, and fixed the workflow. So make self-reporting cheap and concealment expensive, and put that asymmetry in writing where people can see it.
One consequence is outside your control and worth naming, because it changes how staff weigh a shortcut. Anthropic's Usage Policy applies to anyone who can submit inputs to its products or services, including through authorized resellers or passthrough access, and Anthropic states that if it learns you have violated the policy it may throttle, suspend, or terminate access. Circumventing guardrails, jailbreaking, and prompt injection without prior authorization are named in the policy. One person's stunt can reach everybody's seats.
Now the honest caveat, again, because this clause is where it bites hardest. Whether any specific discipline described below is lawful for you depends on your state, on at-will status, on any collective bargaining agreement, on what your existing handbook already promised about progressive discipline, and on whether the conduct touches anything protected. I am not telling you that you may terminate someone for a policy breach. I am telling you that a policy with no consequence clause will not change behavior, and that the consequence clause is the one to hand your employment lawyer first.
- Self-report window: report a suspected breach to [ROLE] within 24 hours of noticing it and there is no disciplinary consequence for the breach itself. This applies even if the breach was yours, even if it was deliberate, and even if it happened before this policy existed
- Concealment is the serious offense. Failing to report, deleting a conversation to hide it, or misrepresenting what was entered is treated as [the most serious category your handbook already uses], separately from the underlying breach
- Tier one, first unintentional breach with no client or patient data exposed: same-day conversation with [ROLE], a walkthrough of the correct workflow, no file note
- Tier two, repeat breach or any breach involving client, patient, employee, or financial data: documented conversation, written follow-up, mandatory retraining, and [ROLE] decides whether access is paused during review
- Tier three, deliberate exfiltration, credential entry, concealment, use of a personal account after a prior warning, or presenting unreviewed output as reviewed: escalation to [ROLE] and [ROLE], up to and including termination, subject to our existing disciplinary process and applicable law
- Client and patient notification is never decided by the person who made the mistake. [ROLE] owns that decision, in consultation with counsel where the data warrants it. Do not contact a client to apologize before that call is made
- Who investigates: [ROLE]. Who decides consequence: [ROLE]. Who is notified in every tier-two and tier-three matter: [ROLE]. Fill these in with three different titles if you can
- Within five business days of any tier-two or tier-three matter, [ROLE] writes down what made the breach easy and what changed. If nothing changed, the same breach is scheduled to happen again
- This ladder is a draft. Before it is published, employment counsel in every state where we employ people reviews it against our handbook, any applicable collective bargaining agreement, and local law. Do not publish this clause on my word
The one page you actually hand to staff
Everything above is the document you keep. This is the version you put on the wall, and it is written for somebody who does not care about any of it and has eleven minutes before their next appointment. Short lines, no legal register, no explanation of why. The why lives upstairs.
Read it out loud at a team meeting rather than emailing it. Then send it, and send it again to every new hire in week one. If you want one sentence of context in front of it, use this one: we are not trying to catch you, we are trying to make sure a mistake stays small.
Same disclaimer, one last time, because it applies to the staff page too and not just to the long version. This is a starting point written by a practitioner, not legal advice, and a lawyer in your jurisdiction should read it before you ask anyone to sign anything.
- Use Claude for work only through your [COMPANY] login. Not your personal account. Not on your phone at home on your own login
- Never type in: patient or client names with details, signed contracts, matter files, payroll, Social Security or bank numbers, passwords, or anything a client marked confidential
- Never upload a document, screenshot, or photo of a document containing the things in the line above. Same rule, any format
- If you need real client details to make the task work, stop and ask [NAME]. That is a normal question and the answer is often yes with a different setup
- Claude is confidently wrong sometimes. Check every name, number, date, citation, and dosage against the real source before it goes anywhere
- Read the whole thing before you send it. If you did not read it, you did not review it
- Anything going to a client, a patient, a court, or an insurer gets reviewed by [ROLE OR NAME] first. Whoever reviews it owns it
- If a client asks whether we used AI, tell the truth and tell [NAME]
- Already put something in that you should not have, even months ago: tell [NAME] within 24 hours and you are fine. Hiding it is the part that gets you in trouble
- Questions go to [NAME]. There is no dumb one, and asking is always cheaper than guessing
Sources
Policies and product details change. Check the source rather than trusting this page indefinitely.
- Anthropic Usage Policy, effective September 15, 2025: High-Risk Use Case Requirements, human-in-the-loop, and session-level AI disclosure
- Anthropic Commercial Terms of Service: no training on Customer Content, customer responsibility to evaluate Outputs, and the duty to notify Users about accuracy
- Anthropic Consumer Terms of Service: training on Materials unless you opt out, and the Business Domains clause on work-email accounts
- Anthropic Privacy Center: Is my data used for model training? (commercial products, including the 5-year feedback retention)
- Anthropic Privacy Center: Is my data used for model training? (consumer products Free, Pro, and Max)
- Anthropic Privacy Center: How do I change my model improvement privacy settings?
- Anthropic Privacy Center: How long do you store my organization's data? (commercial retention, including flagged-conversation periods)
- Anthropic Privacy Center: How long do you store my data? (consumer retention, deletion, and training-pipeline periods)
- Anthropic Support: What is the Team plan? (seat caps, included identity features, pricing)
- Anthropic Support: What is the Enterprise plan? (audit logs, retention controls, Compliance API, seat minimums)
- Anthropic Support: HIPAA-ready Enterprise plans, Enterprise only and not available on Team or individual plans
- Anthropic Support: Roles and permissions on Team and Enterprise plans
- Anthropic Support: Who owns and manages the data of my team, the article to send staff
Need to send this to someone else?
I will email you this answer with every source linked, so it stands up when it lands in front of IT, legal, or finance. Plus the questions that usually come next. Unsubscribe any time.
Want to know what Claude can actually do in your business?
Four questions, about a minute, and Claude writes three automations for your specific situation with the exact prompts. No account.
Build my plan