06-reference/research

anthropic aup agentic use operative clauses

2026-09-13·research-brief·source: deep-research·by Ray Data Co (deep-research synthesis)
anthropic-tosusage-policyagentic-useray-substratecompliance

Anthropic's operative agentic-use clauses, read verbatim at the source, mapped to what Ray actually does

The question

"Verbatim read of anthropic.com/legal/aup + the agentic-use Help Center article (support.anthropic.com/en/articles/12005017) to capture the actual prohibited-agentic-activity examples (news posts lack the operative clauses)." This closes the gap flagged in [[2026-07-04-anthropic-max-plan-tos-productized-agentic-use]], which reasoned from news posts and never read the canonical pages.

What we already know (from the vault)

What the web says (primary sources, read verbatim 2026-09-13)

All four pages below were fetched raw with curl (a browser User-Agent string was needed) and the text was extracted locally. Quotes are exact.

Version dates (answers "has anything changed since 2026-07-04?"):

The Help Center agentic examples: the full list, verbatim. The article opens: "All uses of agents and agentic features must continue to adhere to Anthropic's Usage Policy. The following are intended to be non-exhaustive illustrations..."

Operative clauses in the Usage Policy that bear on agentic operation (verbatim, https://www.anthropic.com/legal/aup):

Consumer Terms operative clauses (verbatim, https://www.anthropic.com/legal/consumer-terms, Section 2 and Section 3):

Convergences and contradictions

Synthesis for RDCO

The verbatim read confirms the parent brief's bottom line but moves the risk to different clauses. The Help Center agentic examples are almost entirely about harm to third parties, and Ray does none of it. The clauses that actually touch RDCO sit in the Consumer Terms (automation, securities, account sharing) and in the Usage Policy's disclosure and High-Risk sections. Two facts raise the stakes. First, the Consumer Terms let Anthropic end a Subscription "at any time for any other reason," so compliance lowers the risk but never removes it. Second, the June 15 credit that the parent treated as Anthropic formally backing subscription automation was paused. Ray's cron/claude -p pattern therefore runs on tolerance plus the Claude Code product surface, not on a written permission.

Mapping each RDCO activity against the operative text:

RDCO activity Operative clause Verdict
Always-on stock Claude Code, cron and claude -p on Max OAuth Consumer Terms: automation allowed only via API key "or where we otherwise explicitly permit it" Grey (textual), clear in practice. No explicit grant was found; Anthropic's own docs acknowledge and meter this usage. Token extraction and harness spoofing remain the real ban vectors.
iMessages to the founder; vault ingestion; deep-research; cron reports None Clear
Founder's 1Password-held credentials used by Ray Help Center: "another person's account ... without authorization"; Consumer Terms: no making the Account "available to anyone else" Clear while the founder is the only human. It flips on the first teammate.
Email: Ray drafts, founder taps send, Ray executes send Usage Policy: impersonation, "convince a natural person that they are communicating with a natural person" Grey-low. The founder authors the decision and sends under his own name. It stays clear only while the human gate is real, not a rubber stamp.
X/LinkedIn/Sanity Check: founder approves, Ray posts Usage Policy High-Risk "Media ... automatically generate content and publish it for external consumption" (human-in-the-loop plus AI disclosure); "Plagiarize or submit AI-assisted work without ... attribution"; Help Center "artificial engagement" and "coordinated inauthentic behavior" Grey. The approval gate meets the human-in-the-loop requirement. Scaled-abuse examples do not apply (one account, the founder's own). Open: whether High-Risk applies to an individual's own publishing, and whether the posts need an AI-use disclosure.
Discord replies to non-founders (reply plus tag founder) Usage Policy: "any external-facing or interactive AI agent, must disclose ... at the beginning of each chat session" Grey. Ray talking to outsiders is an external-facing interactive AI agent. Compliant only if the Discord identity or first reply clearly says it is AI; not verified here.
Paper trades (Alpaca sandbox) Help Center: "unauthorized, illegal, or fraudulent financial transactions (such as brokerage or investment advisory activities)"; Consumer Terms: "rely upon the Services ... to buy or sell securities" Clear today (no real securities traded). At risk the moment it becomes live execution on the Max subscription: the Consumer Terms securities clause has no "unauthorized" qualifier.
Published investing content / IC-memo lead magnets Consumer Terms: "provide ... advice about securities"; Usage Policy High-Risk Finance: "investment advice" At risk. If framed as advice to readers, both clauses apply: qualified-professional review plus AI disclosure. Keep it framed as analysis, not advice; the disclosure footer from [[2026-06-16-position-disclosure-ic-memo-lead-magnets]] is the right control.
Contact stubs from Gmail/Calendar; family-history research Help Center: "Collect, compile, or analyze personal information to create profiles based on ... personal circumstances" Grey-low. These are business-contact and genealogy records, not attribute profiling. The "living-person data stays local" rule is the right guardrail.
curl with a browser User-Agent string to get past blocks (cms.gov, and this brief's own fetches) Usage Policy: "circumvent the guardrails or terms of other platforms or services" Grey-low. It is a small bypass of a site's own guardrail. Fine for occasional public-document reads, but it should not become a standing crawler.
Scribble Works via AI Gateway BYOK (API) Commercial Terms govern; the Usage Policy still applies to "anyone who can submit inputs"; minors guideline (UNVERIFIED); external-agent AI disclosure Grey pending the minors article. The "parents on site, kids on paper" design likely keeps minors from directly interacting with the model. Any interactive AI surface still needs the AI disclosure.
Security audits of RDCO's own systems Usage Policy: "without authorization of the system owner" Clear. RDCO owns the systems.

What changes: (1) The parent brief's statement about the June 15 credit should be treated as superseded. Ray's automation draws from normal subscription limits, and there is no dedicated credit. (2) The two practical controls to confirm are an AI-disclosure line on outsider-facing Discord replies, and no live trade execution routed through the Max subscription. If live trading ever happens, it runs on an API key under Commercial Terms or with no Claude in the execution path. (3) The only real "flip to API" pressure comes from outsider-facing surfaces and securities, not from Ray's internal automation.

Why this is in the vault

It is the primary-source text behind [[2026-05-05-personal-license-boundary]] and the paper-trade-to-live decision in the investing pipeline. It also informs the Discord non-founder reply behavior and the approve-then-Ray-posts content workflow. Each gets a clause-level verdict here instead of an inferred one.

Open follow-ups

Related

Sources