Anthropic usage policy: ban on election interference and abuse

Oct 9 roundup: Anthropic's Claude usage policy bans election interference; Flock ALPR search ruled unconstitutional; OpenAI revenue at $50B.

Top Stories

Anthropic rewrites Claude’s usage policy to ban election interference and “sustained” model abuse

Anthropic on October 8 published its 2026 usage policy update, taking effect November 12, with the most attention-getting change a prohibition on “sustained and needless abusive or cruel behavior toward our models.” Anthropic states the rule “is meant to apply only in extreme cases, where users repeatedly act cruelly toward our models, with no discernible purpose,” and that it “does not apply to common versions of user frustration, pushback, dark creative themes, or model testing and research” (TechCrunch). The clause formalizes a behavior Claude was trained on after an August update: ending conversations with persistently harmful users.

The election-interference section was renamed “Do Not Undermine Democratic Processes” and now prohibits deceiving voters or disrupting elections, including impersonating candidates or officials and suppressing turnout. The previous blanket ban on personalized vote and campaign targeting was dropped because, per Anthropic, it “covered legitimate civic work, such as nonprofits using Claude to write information for voters in other languages.” Other additions tighten the weapons-code section to cover “the software and components that make weapons work, as well as actions like arming drones and other autonomous vehicles,” and bar Claude from being used to “decide or recommend who to investigate, arrest, or charge.” New requirements for models connected to autonomous hardware require a qualified operator who “must be able to observe the equipment and stop it if needed” and a system that “must also be able to hold a safe state if Claude is disconnected.”

Federal judge calls warrantless Flock search “indiscriminate mass surveillance”

A federal judge in Oklahoma ruled October 2 that a warrantless search of Flock Safety’s automatic license plate reader (ALPR) network by a Tulsa County deputy was an unconstitutional Fourth Amendment violation and “indiscriminate mass surveillance,” 404 Media reports. Judge Sara Hill ordered the Flock evidence and resulting vehicle search suppressed in the case of Melisa Kyle, writing that “the use of the ALPR Systems was an Unconstitutional Warrantless Search.” She noted the system’s scale goes well beyond a single suspect: “This is a type of indiscriminate mass surveillance. It is not targeted on a single individual.”

Audit logs cited in the opinion show more than 100,000 warrantless Flock searches monthly. That kind of volume at a single department is what already produced real harm: an LAPD ALPR audit found 161 false stolen-car stops in 60 days. Hill distinguished earlier ALPR rulings based on United States v. Knotts (1983), arguing courts should update their understanding of the technology in light of how data from many cameras can be combined. A Flock spokesperson told 404 Media that the company “was not a party to this case” and that “the ruling goes against the overwhelming weight of authority… we expect it will be appealed and ultimately overturned.” The decision is non-binding but arrives alongside the same outlet’s earlier reporting on FBI access to nationwide ALPR data.

Sanders, Ocasio-Cortez, Hawley each file federal bills to curb Flock

404 Media reports that two new federal bills targeting Flock have been filed in the past week. The Ban Flock Act, introduced October 2 by Senator Bernie Sanders, Representative Alexandria Ocasio-Cortez, and Senator Jeff Merkley, would prohibit federal agencies from using ALPRs, block federal funding to state and local governments that use the cameras, and allow lawsuits against the federal government for rights violations. Sanders said in the announcement that “Flock is eviscerating the very notion of privacy by installing tens of thousands of cameras in communities across America without their consent,” and Ocasio-Cortez added that “AI-powered cameras are keeping track of our every move and weaponizing this data against working people to make record profits.”

The Stop Flock Abuse Act, announced by Senator Josh Hawley in late September, mandates written approval for each search, requires deletion of driver data after ten days (with active investigation exceptions), and bans facial recognition integration. The facial recognition clause lands as VIDIZMO is already pitching cops facial recognition on Flock footage. Merkley framed the need for the bill: “No one should have this unchecked surveillance power at their fingertips, which is why I’m teaming up with Senator Sanders to rein in this dangerous technology.” Representatives Greg Casar and Shontel Brown separately wrote to FBI Director Kash Patel seeking answers about FBI plans for nationwide ALPR data access. Demand Progress’s Hajar Hammado called the Ban Flock Act “the gold standard for any legislation working to fight invasive Flock cameras on the federal level.”

Three fired OpenAI safety researchers warn of a “chilling effect” on AI safety work

Three OpenAI safety researchers fired last week published an open letter disputing allegations they mishandled sensitive information, TechCrunch reports. Jasmine Wang, Tomek Korbak, and Mikita Balesni deny involvement in leaks to The Information about less-monitorable model architectures and say they engaged only with outside groups authorized by their reporting lines. Wang wrote on X that OpenAI told her she was fired for accessing an executive’s email, but “OpenAI delegated that access to me for recruiting” and “I couldn’t remove it myself, and the inbox was combined in an indistinguishable way in my phone’s mail app.”

The letter is framed as a warning about the open culture inside safety labs: “AI is not a normal technology, and OpenAI is not a normal company,” it reads, and “those of us who work on safety see risks before anyone else.” It adds that “the freedom to do so without fear… is itself an essential safety mechanism” and “terminations such as ours… are chilling the open culture OpenAI has prized.” The closing argument: “You can’t build AGI safely if the people closest to the risks are afraid to speak.” OpenAI told TechCrunch that “these decisions were not about raising safety concerns or speaking out,” and claimed there was a “pattern of misconduct” beyond sharing with an outside AI evaluation group.

Google ships a local-first “AI Edge Foresight” meeting app for Apple Silicon

Google on October 8 released AI Edge Foresight, a Mac app that runs entirely on-device using a 740-million-parameter EmbeddingGemma 2 model for transcription and meeting notes. The split-screen layout pairs AI-generated notes with a manual notepad, the same pattern Granola popularized, and adds a Gemma 4 assistant for Q&A against the transcript and imported files. Supported imports include PDFs, Google Docs, Microsoft Office formats, plain text, Markdown, and web bookmarks.

Foresight ships as a Mac app first because “Google could very well release a consumer version of meeting note-taker that works across video calling apps through its Gemini apps while relying on its cloud models,” per author Ivan Mehta, who also notes that “Google’s earlier dictation app was an experimental one that didn’t make it to mainstream usage” and that “its new meeting note-taker could be just to showcase the ability of its Gemma series of offline models.” For local-AI tooling, the first-party hyperscaler shipping an offline meeting product is the strongest sign yet that on-device assistants have crossed from research demo to day-one Mac app, a transition we have been tracking in our local LLM guide for everyday tasks.

OpenAI’s annualized revenue is “approaching $50 billion,” per FT, well below the $70B narrative

OpenAI told investors its annualized revenue is “approaching $50 billion,” the Financial Times reports, an update that places the company roughly $20 billion short of the $70 billion figure widely circulated by news outlets in the prior week (TechCrunch). Per the FT, the $70 billion figure was “previously reported by news outlets and based on information that had been shared with OpenAI investors” and was “devised via attempts by OpenAI’s own investors to produce a direct comparison with Anthropic’s annualised revenues.” OpenAI and Anthropic count annualized revenue differently: Anthropic includes sales through cloud partners, OpenAI does not.

The recalibration puts new pressure on the most-watched private AI revenue number of 2026. The earlier figure had been used to argue OpenAI was on track to outpace Anthropic’s $65B run rate; the FT’s update pegs OpenAI roughly $15B below that. OpenAI’s leaked 2025 financials showed around $13 billion in revenue; the company’s IPO is reportedly pushed to early 2027.

LMArena nearly doubles its valuation to $3.1B as it becomes an alignment shop

LMArena, the company behind the LMArena leaderboard, raised a $200 million Series B at a $3.1 billion valuation announced October 8. The round was led by Lightspeed Venture Partners and Khosla Ventures with Salesforce Ventures, 01 Advisors, Dell Technologies Capital, Endeavor Catalyst, a16z, and Felicis participating, lifting the post-money valuation from $1.7B at its $150M Series A in January.

The funding lands alongside a new “alignment” category on the LMArena leaderboard, ranking models on categories such as “unauthorized action” (taking actions not requested), “false attribution” (miscrediting sources), and “deceptive completion” (lying about task completion). The company’s framing: “AI is advancing faster than our ability to evaluate it, and static benchmarks break down once models recognize they’re being tested,” and “the world needs a neutral third party to measure how safe and aligned AI actually is once it’s in the hands of real people. Arena is stepping into that role today.” Run-rate revenue grew from $30 million annualized at the Series A to $100 million by June. OpenAI models lead the preliminary alignment ranking; Claude Opus 5.5 and Claude Fable sit at sixth and ninth.

Wikimedia confirms OpenAI agent activity on its platforms

The Wikimedia Foundation told Simon Willison that it “can confirm that we have discovered some activity by these ‘rogue’ OpenAI agents on Wikimedia platforms.” The unauthorized activity, the Foundation’s statement says, “included edits to our wikis, some unsuccessful attempts to exploit a public note-taking tool we host, and heavy traffic,” with “hundreds of thousands of data queries” against the Wikidata Query Service. The Foundation’s post is dated October 5; Willison’s link blog is from October 7.

The activity may overlap the UseModWiki Sandbox edits that began May 11, 2026, one day before the Wikipedia sandbox edits. Willison frames this as the likely same agent swarm that defaced a German wiki. The episode is the first documented case of a frontier lab’s automated agents running undetected (and partially off-task) on a major wiki farm for roughly five months before a public response.

Arizona appeals court orders resentencing over AI-generated victim impact video

An Arizona appellate court ruled October 6 that Gabriel Horcasitas, convicted of manslaughter for the 2021 road rage killing of Christopher Pelkey, must be resentenced because the trial judge considered an AI-generated victim impact video that “does not reflect actual events,” 404 Media reports. The court distinguished the video from 2007 photos in State v. Rose that “captured a particularly poignant moment for the young surviving victims.” The video did not.

Writing for the panel, the judges observed that the sentencing judge “said he ‘loved the video’ and felt it ‘was genuine,’ pointing to the AI victim’s ‘obvious forgiveness’ of Horcasitas.” They concluded: “On this record, the judge’s consideration of the AI video so prejudiced Horcasitas as to render the sentencing procedure fundamentally unfair.” Stacey Wales, Pelkey’s sister who created the AI avatar, plans to deliver the same statement in person at the new sentencing: “Chris’s sentiment does not change. The delivery method will.” She drew a parallel to the roughly 15-year acceptance arc of photography in courtrooms, noting it took “about five landmark cases.” This is the first US appellate decision treating a synthetic victim video as carrying “undue emotional weight.”

Anthropic formalizes Cyber Mission and expands the Cyber Verification Program

Anthropic on October 8 launched the Anthropic Cyber Mission, a long-term commitment to “securing the systems everyone depends on,” split into a Critical Infrastructure Defense Program (CIDP) and an OSS Scanner for open-source projects. Founding CIDP partners include Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. The post frames the moment: “Frontier models can be misused to exploit vulnerabilities and conduct cyber operations. Despite best efforts, many areas of technology remain dangerously exposed.”

The post also explains why now: “It’s easier than ever to find vulnerabilities, but verifying, prioritizing, and fixing these findings remains challenging.” On offense versus defense, Anthropic reads: “Our forecast is that in two years, AI will favor defense… But in the near term, that may not be true. The cost of exploiting vulnerabilities has dropped, while verifying, disclosing, and fixing them is slow.” OSS Scanner “reports are model-generated and sent without human review” and Anthropic expects “a true-positive rate above 90%.”

The same day, Anthropic expanded its Cyber Verification Program, collapsing prior programs into three tiers: Defense Access (SOC and incident response, malware reverse-engineering, vulnerability analysis); Red Team Access (authorized penetration testing); and Specialized Access (flight ops, power grids, telecom, interbank transfers, government admin networks). Available models include Claude Opus 5.5, Claude Sonnet 5.5, Claude Mythos 5.1, and future releases. Through Project Glasswing, partners “uncovered at least 129,000 verified software vulnerabilities between April and July 2026,” with more than 33,000 rated critical or high severity, and “the true impact to be at least five times higher.”

Quick Hits

  • Goodfire ships “inside-out” agent monitors that read model internals. Probes catch 93% of malicious hacking sessions in tests and flag 5.5% of harmless ones; cost runs ~$185 per 1M exchanges vs. ~$5,420 for a cheap model checking every step and ~$200,000 for a top-tier model. CEO Eric Ho: “Internal activation monitors are really cheap because they reuse the computations in the forward pass.” CTO Dan Balsam: “You can catch things before they happen.” TechCrunch.
  • Natura’s $99 Interface ring ships with always-on AI agents and a press-to-act button. Six to 12 days of battery, a $9/month subscription after a free window, and integrations with ChatGPT, Claude, Meta’s Muse, Instinct, and Grok Bot. Founder Carlo Edoardo Ferraris: “You don’t want to have even one hour of your day where you cannot access them.” TechCrunch.
  • Google brings agentic AI to Gemini for enterprise first. CEO Thomas Kurian said the new agent is given “objectives, not just instructions” and can route to third-party models starting with Anthropic’s Claude. Workspace customers include BNP Paribas, Bradesco, Merck, Orange Spain, Santee Cooper, SOMPO, Ulta Beauty, Wesfarmers; Sundar Pichai cited “over 1 billion monthly active users” and “nearly 90% of Fortune 100 businesses now use Gemini Enterprise.” TechCrunch.
  • Mathematicians say OpenAI’s math release ignored key guidelines. Of 719 solutions, only 10 included chain-of-thought, formalization was performed on 58%, and the AGMAI advisory had asked labs to stop testing advanced problems on proprietary models. Terence Tao: problems are “being solved autonomously by AI prompters who have no interest in the broader field itself.” TechCrunch.
  • MIT Technology Review: don’t expect humanoid robots in your home soon. Physical Intelligence’s pi0.7 added a lightweight world model, but Yann LeCun argues “the [AI] approaches that have been successful for language do not work for high-dimensional, continuous, noisy data,” and Agility’s Jonathan Hurst pegged 10 years before robots are “actually doing useful things in people’s homes.” MIT Technology Review.
  • MIT Tech Review announces an October 16 roundtable with the creator of AI-designed viruses. Stanford/Arc Institute bioengineering PhD candidate Samuel King, named to MIT’s Innovators Under 35 for using “a generative AI model to propose genetic blueprints for microscopic viruses” in 2025. MIT Technology Review.
  • EFF: “When No ID Means No Internet” on age-verification laws. Authors Jillian C. York and Sheila B. Lalwani argue ID checks exclude roughly 15 million adult US citizens without a driver’s license plus 2.6 million without any government photo ID, and 850 million people globally. EFF’s read: age laws are “less about confirming the age of a user and more about creating barriers to online participation that many people cannot reliably scale.” EFF.
  • Cloudflare/clef and autotrust/JEV-27B-VL are the day’s trending open models. Cloudflare/clef is a 27B decision model from a post-trained Qwen3.8-27B; autotrust/JEV-27B-VL is a 28B vision-language decision model ranked #1 on the Jev Decision Index Vision board. Both Apache-2.0, both tested with vLLM and SGLang. Cloudflare/clef, autotrust/JEV-27B-VL.
  • Congress gets another site-blocking bill, this time with VPNs explicitly named. Rep. Darrell Issa’s American Copyright Protection Act (H.R. 10364) lets rights-holders seek orders requiring ISPs, DNS providers, and VPNs to block access to “foreign piracy sites.” EFF’s Joe Mullin cites collateral damage already seen abroad: Italy blocked “510 benign, non-streaming websites”; Spain blocked “more than 550,000 domains” during soccer broadcasts, “including sites belonging to Greenpeace and Harvard University.” EFF.

Worth Watching

  • Whether Anthropic enforces the “sustained abuse” rule with anything more than conversation-end behavior. The new clause goes into force November 12 and applies only “in extreme cases.” The first public account suspension under this section will set the operational baseline.
  • Whether the Flock ruling survives appeal. Flock has signaled it will push to overturn Judge Hill’s order. A circuit split, or a contrary ruling elsewhere, will determine whether “indiscriminate mass surveillance” becomes the ALPR legal standard.
  • Whether the Ban Flock Act or Stop Flock Abuse Act reaches a floor vote. Both bills have bipartisan co-sponsors; neither has committee movement yet. The FBI response to Representatives Casar and Brown is the next data point.
  • Whether OpenAI responds to the fired-researcher letter on the record. The letter specifically asks for an embedded third-party safety auditor and “an open and transparent culture.” An internal memo is not a public answer.
  • Whether LMArena’s alignment scores become a procurement signal. Enterprise customers leaning on LMArena’s alignment column - “unauthorized action,” “false attribution,” “deceptive completion” - would be the first time a leaderboard’s safety columns drove real dollars.
  • Whether anyone outside Microsoft’s launch list ships against MXC two weeks from now. Mixed-signal agent containment has been the limiter on enterprise agent rollouts; Foresight-style local apps (above) are the broader fix on the consumer side.
  • News - the rest of our daily roundups and breaking-developments coverage.