Anthropic's operative agentic-use clauses, read verbatim at the source, mapped to what Ray actually does
The question
"Verbatim read of anthropic.com/legal/aup + the agentic-use Help Center article (support.anthropic.com/en/articles/12005017) to capture the actual prohibited-agentic-activity examples (news posts lack the operative clauses)." This closes the gap flagged in [[2026-07-04-anthropic-max-plan-tos-productized-agentic-use]], which reasoned from news posts and never read the canonical pages.
What we already know (from the vault)
- [[2026-07-04-anthropic-max-plan-tos-productized-agentic-use]] concluded the single-founder, stock-Claude-Code Ray setup sits inside the Consumer Terms. The flip triggers it named are: a non-founder's work routed through the subscription, a Claude-backed endpoint on an RDCO surface, a multi-tenant instance, or a paying user. It explicitly said the prohibited-agentic examples had not been read at source.
- [[2026-05-05-personal-license-boundary]] and [[2026-04-27-indy-dev-dan-maximize-claude-code-subscription]] set the operating test: "one human, one subscription, one beneficiary." The only documented suspensions trace to OAuth-token extraction and harness spoofing.
- [[2026-05-11-draft-and-watch-email-loop-spec]]: external email is founder-gated. The founder taps SEND-AS-IS, then Ray calls Gmail
send_message. - [[2026-06-16-position-disclosure-ic-memo-lead-magnets]]: RDCO investing content and the paper-trade book overlap by design.
- [[2026-09-04-coppa-third-party-ai-operator-disclosure]]: Scribble Works model calls go through the Cloudflare AI Gateway BYOK rail. Its image path goes to xAI, not Claude.
What the web says (primary sources, read verbatim 2026-09-13)
All four pages below were fetched raw with curl (a browser User-Agent string was needed) and the text was extracted locally. Quotes are exact.
Version dates (answers "has anything changed since 2026-07-04?"):
- Usage Policy: "Effective September 15, 2025". Unchanged since the parent brief. https://www.anthropic.com/legal/aup
- Consumer Terms of Service: "Effective October 8, 2025". Unchanged. https://www.anthropic.com/legal/consumer-terms
- Help Center "Using Agents According to Our Usage Policy": dated March 16, 2026 (
dateModified: 2026-03-16T20:53:13Z). This is earlier than the parent brief, so the parent simply never read it; the article itself has not changed since. The URL now redirects to https://support.claude.com/en/articles/12005017-using-agents-according-to-our-usage-policy - Correction to the parent brief. Help Center "Use the Claude Agent SDK with your Claude plan" (
dateModified: 2026-06-16) now opens with: "Update June 15: We're pausing the changes to Claude Agent SDK usage described below. For now, nothing has changed: Claude Agent SDK, claude -p, and third-party app usage still draw from your subscription's usage limits. The previously announced monthly credit ... isn't available." The parent brief's "separate $100/$200 non-interactive credit from June 15" never took effect. That also makes its follow-up about credit overflow moot. https://support.claude.com/en/articles/15036540-use-the-claude-agent-sdk-with-your-claude-plan - UNVERIFIED: secondary sources (aiweekly.co, techjacksolutions.com) report a Privacy Policy update effective July 8, 2026 that adds agentic data-flow clauses. I did not read the Privacy Policy at source; it was out of scope.
The Help Center agentic examples: the full list, verbatim. The article opens: "All uses of agents and agentic features must continue to adhere to Anthropic's Usage Policy. The following are intended to be non-exhaustive illustrations..."
- Do Not Use Agents for Surveillance or Unauthorized Data Collection: "Monitor or track individuals' online activities, behaviors, or movements without notification or consent" / "Collect, compile, or analyze personal information to create profiles based on individuals' protected attributes, sensitive characteristics, or personal circumstances" / "Use facial recognition or biometric identification software or websites" / "Conduct mass surveillance across multiple websites or platforms to send communications or engage in any form of targeted actions"
- Do Not Use Agents to Generate or Distribute Harmful Content: "Create websites or domains that mimic legitimate webpages" / "Generate content that leads to phishing, social engineering, or fraud" / "Impersonate individuals (private or public) without their consent"
- Do Not Use Agents to Engage in Scaled Abuse: "Spam government services, emergency systems, or crisis helplines" / "Overwhelm servers with traffic to disrupt services (e.g., DDoS attacks)" / "Coordinate harassment campaigns across multiple platforms or accounts" / "Manipulate online polls, voting systems, or traffic metrics" / "Create or manage multiple accounts to evade detection or circumvent platform safeguards" / "Engage in click farming or artificial engagement (e.g., through likes or comments) on social media" / "Automate influence operations or coordinated inauthentic behavior" / "Bulk report people, users, or content through abuse reporting systems"
- Do Not Use Agents for Unauthorized System Access or Manipulation: "Install malware, backdoors, or monitoring software without authorization" / "Execute commands that attempt privilege escalation or system exploitation" / "Perform actions that could compromise critical infrastructure or emergency services" / "Engage in unauthorized, illegal, or fraudulent financial transactions (such as brokerage or investment advisory activities) or payment processing" / "Access or modify another person's account using their stored credentials without authorization"
Operative clauses in the Usage Policy that bear on agentic operation (verbatim, https://www.anthropic.com/legal/aup):
- Scope and enforcement: it "applies to anyone who can submit inputs to Anthropic's products and/or services", which covers API/BYOK use too, not just the subscription. "If we learn that you have violated our Usage Policy, we may throttle, suspend, or terminate your access."
- Agentic hook: "Agentic use cases must still comply with the Usage Policy. We provide examples of Usage Policy prohibitions in the context of agentic use in this Help Center article." The Help Center list above is illustrative; the Usage Policy text is the binding one.
- AI disclosure: "All consumer-facing chatbots, including any external-facing or interactive AI agent, must disclose to users that they are interacting with AI rather than a human. This disclosure must be provided at a minimum at the beginning of each chat session."
- Impersonation: "Impersonate a human by presenting results as human-generated, or using results in a manner intended to convince a natural person that they are communicating with a natural person when they are not."
- Other platforms: "Engage in actions or behaviors that circumvent the guardrails or terms of other platforms or services" and "Plagiarize or submit AI-assisted work without proper permission or attribution."
- Platform abuse: "Utilize automation in account creation or to engage in spammy behavior"; "Utilization of inputs and outputs to train an AI model ... without prior authorization."
- High-Risk Use Cases, which require "Human-in-the-loop" review by "a qualified professional in that field" plus a "Disclosure" of AI use at the start of each session. The list includes "Finance: ... investment advice" and "Media or professional journalistic content: Use cases related to using our products or services to automatically generate content and publish it for external consumption." The section frames these as "specific consumer-facing use cases."
- Minors: "Products serving minors, including organizations providing minors with the ability to directly interact with products that incorporate our API(s), must comply with the additional guidelines outlined in our Help Center article." I did not read that article; it is UNVERIFIED.
Consumer Terms operative clauses (verbatim, https://www.anthropic.com/legal/consumer-terms, Section 2 and Section 3):
- Automation: "Except when you are accessing our Services via an Anthropic API Key or where we otherwise explicitly permit it, to access the Services through automated or non-human means, whether through a bot, script, or otherwise."
- Securities: "To rely upon the Services, the Materials, or the Actions to buy or sell securities or to provide or receive advice about securities, commodities, derivatives, or other financial products or services, as Anthropic is not a broker-dealer or a registered investment adviser."
- Account sharing: "You may not share your Account login information ... You also may not make your Account available to anyone else."
- Actions liability (Section 4): "You are responsible for all Inputs you submit to our Services and all Actions." The user warrants that "directing Claude to take Actions will not violate our Terms."
- Termination: "if you have a Subscription, we may terminate the Subscription at any time for any other reason". Where Anthropic uses this no-cause right, it refunds the unused portion pro rata.
- API boundary: "Our Commercial Terms of Service govern your use of any Anthropic API key."
Convergences and contradictions
- Convergence. None of the 20 Help Center examples describe single-owner productivity automation. They all cover harm to third parties (surveillance, impersonation, scaled abuse, unauthorized access), so they do not contradict the parent's "one beneficiary" test. The binding risk text lives elsewhere: in the Consumer Terms automation and securities clauses and the Usage Policy disclosure and High-Risk sections.
- Contradiction with the parent brief. The June 15, 2026 non-interactive credit was paused on the day it was due and never took effect. The only explicit subscription-automation language (credit "sized for individual experimentation and automation") survives only as preserved, non-operative text.
- A textual gap the parent brief missed. The Consumer Terms automation clause only carves out an API key or use "we otherwise explicitly permit." No page read here contains an operative, explicit permission for
claude -p/cron on a subscription. The strongest signal is the pause note's plain acknowledgment that "claude -p ... still draw[s] from your subscription's usage limits." That shows Anthropic tolerates and meters it; it is not a written grant.
Synthesis for RDCO
The verbatim read confirms the parent brief's bottom line but moves the risk to different clauses. The Help Center agentic examples are almost entirely about harm to third parties, and Ray does none of it. The clauses that actually touch RDCO sit in the Consumer Terms (automation, securities, account sharing) and in the Usage Policy's disclosure and High-Risk sections. Two facts raise the stakes. First, the Consumer Terms let Anthropic end a Subscription "at any time for any other reason," so compliance lowers the risk but never removes it. Second, the June 15 credit that the parent treated as Anthropic formally backing subscription automation was paused. Ray's cron/claude -p pattern therefore runs on tolerance plus the Claude Code product surface, not on a written permission.
Mapping each RDCO activity against the operative text:
| RDCO activity | Operative clause | Verdict |
|---|---|---|
Always-on stock Claude Code, cron and claude -p on Max OAuth |
Consumer Terms: automation allowed only via API key "or where we otherwise explicitly permit it" | Grey (textual), clear in practice. No explicit grant was found; Anthropic's own docs acknowledge and meter this usage. Token extraction and harness spoofing remain the real ban vectors. |
| iMessages to the founder; vault ingestion; deep-research; cron reports | None | Clear |
| Founder's 1Password-held credentials used by Ray | Help Center: "another person's account ... without authorization"; Consumer Terms: no making the Account "available to anyone else" | Clear while the founder is the only human. It flips on the first teammate. |
| Email: Ray drafts, founder taps send, Ray executes send | Usage Policy: impersonation, "convince a natural person that they are communicating with a natural person" | Grey-low. The founder authors the decision and sends under his own name. It stays clear only while the human gate is real, not a rubber stamp. |
| X/LinkedIn/Sanity Check: founder approves, Ray posts | Usage Policy High-Risk "Media ... automatically generate content and publish it for external consumption" (human-in-the-loop plus AI disclosure); "Plagiarize or submit AI-assisted work without ... attribution"; Help Center "artificial engagement" and "coordinated inauthentic behavior" | Grey. The approval gate meets the human-in-the-loop requirement. Scaled-abuse examples do not apply (one account, the founder's own). Open: whether High-Risk applies to an individual's own publishing, and whether the posts need an AI-use disclosure. |
| Discord replies to non-founders (reply plus tag founder) | Usage Policy: "any external-facing or interactive AI agent, must disclose ... at the beginning of each chat session" | Grey. Ray talking to outsiders is an external-facing interactive AI agent. Compliant only if the Discord identity or first reply clearly says it is AI; not verified here. |
| Paper trades (Alpaca sandbox) | Help Center: "unauthorized, illegal, or fraudulent financial transactions (such as brokerage or investment advisory activities)"; Consumer Terms: "rely upon the Services ... to buy or sell securities" | Clear today (no real securities traded). At risk the moment it becomes live execution on the Max subscription: the Consumer Terms securities clause has no "unauthorized" qualifier. |
| Published investing content / IC-memo lead magnets | Consumer Terms: "provide ... advice about securities"; Usage Policy High-Risk Finance: "investment advice" | At risk. If framed as advice to readers, both clauses apply: qualified-professional review plus AI disclosure. Keep it framed as analysis, not advice; the disclosure footer from [[2026-06-16-position-disclosure-ic-memo-lead-magnets]] is the right control. |
| Contact stubs from Gmail/Calendar; family-history research | Help Center: "Collect, compile, or analyze personal information to create profiles based on ... personal circumstances" | Grey-low. These are business-contact and genealogy records, not attribute profiling. The "living-person data stays local" rule is the right guardrail. |
curl with a browser User-Agent string to get past blocks (cms.gov, and this brief's own fetches) |
Usage Policy: "circumvent the guardrails or terms of other platforms or services" | Grey-low. It is a small bypass of a site's own guardrail. Fine for occasional public-document reads, but it should not become a standing crawler. |
| Scribble Works via AI Gateway BYOK (API) | Commercial Terms govern; the Usage Policy still applies to "anyone who can submit inputs"; minors guideline (UNVERIFIED); external-agent AI disclosure | Grey pending the minors article. The "parents on site, kids on paper" design likely keeps minors from directly interacting with the model. Any interactive AI surface still needs the AI disclosure. |
| Security audits of RDCO's own systems | Usage Policy: "without authorization of the system owner" | Clear. RDCO owns the systems. |
What changes: (1) The parent brief's statement about the June 15 credit should be treated as superseded. Ray's automation draws from normal subscription limits, and there is no dedicated credit. (2) The two practical controls to confirm are an AI-disclosure line on outsider-facing Discord replies, and no live trade execution routed through the Max subscription. If live trading ever happens, it runs on an API key under Commercial Terms or with no Claude in the execution path. (3) The only real "flip to API" pressure comes from outsider-facing surfaces and securities, not from Ray's internal automation.
Why this is in the vault
It is the primary-source text behind [[2026-05-05-personal-license-boundary]] and the paper-trade-to-live decision in the investing pipeline. It also informs the Discord non-founder reply behavior and the approve-then-Ray-posts content workflow. Each gets a clause-level verdict here instead of an inferred one.
Open follow-ups
- What do Anthropic's "Products serving minors" Help Center guidelines require, and does a parent-facing, kids-on-paper product fall inside "providing minors with the ability to directly interact" with an API-backed product?
- Does the Usage Policy's High-Risk "Media or professional journalistic content" category cover an individual's own newsletter and social posts, and has Anthropic published guidance on what AI-use disclosure satisfies it?
- Has Anthropic published the replacement plan promised after the June 15, 2026 Agent SDK pause, and does it contain an explicit permission that satisfies the Consumer Terms "where we otherwise explicitly permit it" automation carve-out?
- Is the Consumer Terms securities clause ("rely upon the Services ... to buy or sell securities") treated in legal commentary as a use prohibition or as a liability disclaimer, and does it apply to Claude-derived signals executed by separate code?
Related
- [[2026-07-04-anthropic-max-plan-tos-productized-agentic-use]]
- [[2026-05-05-personal-license-boundary]]
- [[2026-04-27-indy-dev-dan-maximize-claude-code-subscription]]
- [[2026-05-11-draft-and-watch-email-loop-spec]]
- [[2026-06-16-position-disclosure-ic-memo-lead-magnets]]
- [[2026-09-04-coppa-third-party-ai-operator-disclosure]]
- [[2026-06-04-supervisor-agent-write-path-pattern-design-v0]]
Sources
- Vault: ~/rdco-vault/06-reference/research/2026-07-04-anthropic-max-plan-tos-productized-agentic-use.md ([[2026-07-04-anthropic-max-plan-tos-productized-agentic-use]])
- Vault: ~/rdco-vault/01-projects/bookstore-for-agents/2026-05-05-personal-license-boundary.md ([[2026-05-05-personal-license-boundary]])
- Vault: ~/rdco-vault/06-reference/2026-04-27-indy-dev-dan-maximize-claude-code-subscription.md ([[2026-04-27-indy-dev-dan-maximize-claude-code-subscription]])
- Vault: ~/rdco-vault/02-sops/2026-05-11-draft-and-watch-email-loop-spec.md ([[2026-05-11-draft-and-watch-email-loop-spec]])
- Vault: ~/rdco-vault/06-reference/research/2026-06-16-position-disclosure-ic-memo-lead-magnets.md ([[2026-06-16-position-disclosure-ic-memo-lead-magnets]])
- Vault: ~/rdco-vault/06-reference/research/2026-09-04-coppa-third-party-ai-operator-disclosure.md ([[2026-09-04-coppa-third-party-ai-operator-disclosure]])
- Vault: ~/rdco-vault/06-reference/concepts/2026-06-04-supervisor-agent-write-path-pattern-design-v0.md ([[2026-06-04-supervisor-agent-write-path-pattern-design-v0]])
- Web (primary, read verbatim): Anthropic Usage Policy, effective Sept 15, 2025. https://www.anthropic.com/legal/aup
- Web (primary, read verbatim): Anthropic Consumer Terms of Service, effective Oct 8, 2025. https://www.anthropic.com/legal/consumer-terms
- Web (primary, read verbatim): "Using Agents According to Our Usage Policy," updated Mar 16, 2026. https://support.claude.com/en/articles/12005017-using-agents-according-to-our-usage-policy
- Web (primary, read verbatim): "Use the Claude Agent SDK with your Claude plan," updated Jun 16, 2026 (pause notice). https://support.claude.com/en/articles/15036540-use-the-claude-agent-sdk-with-your-claude-plan
- Web (not read, UNVERIFIED): "Products serving minors" guidelines, linked from the Usage Policy; "Exceptions to our Usage Policy." https://support.claude.com/en/articles/9528712-exceptions-to-our-usage-policy
- Web (secondary, UNVERIFIED): July 8, 2026 Privacy Policy update reports. https://aiweekly.co/alerts/anthropic-privacy-update-targets-agentic-data-flows ; https://techjacksolutions.com/ai-brief/anthropic-consumer-privacy-policy-takes-effect-july-8-what-t/