What you will be able to do
- Recognise tasks Claude handles well, and why these are low-risk places to delegate
- Tell apart a task where Claude may inform a human decision from one where it must not be the decision-maker
- Identify uses the Usage Policy prohibits outright, including when an agent rather than a person performs them
- Apply a Diligence-style check before deciding whether to hand a task to Claude at all
Key concept
Inform, don't decide — Claude is a good fit where its output is a draft, a summary or a suggestion that a person can check and correct before it matters. Where the output lands on people as a decision about them, or the purpose itself is deceptive or harmful, the use becomes inappropriate. That is either because a qualified human must review first, or because no amount of review makes it acceptable.
1.Where Claude fits well: work you can check
Anthropic's own list of what Claude is for is ordinary knowledge work. Claude can draft anything from a text message to a novel, teach a new topic, summarise long material, pair-program, act as a brainstorming or debate partner, translate, and interpret images such as charts. All of these share one trait: a person reads the output before it has any effect. A weak summary gets reread and a buggy function fails its tests. A clumsy draft email gets edited. If Claude gets something wrong, the error surfaces and costs little.
The same help article is candid about limits, and those limits are part of judging fit. It says Claude is strongest in English and translates other languages with uneven quality. So translating an internal memo for gist is a comfortable use. Sending a machine translation of a contract to a counterparty without review is a different decision, even though it is the same capability.
At organisational scale, Anthropic's customer-support guide lists signals that a process suits Claude. These include high volumes of similar questions, the need to pull information together from large knowledge bases, round-the-clock availability, sudden spikes in demand, and the need for a consistent brand tone. The guide presents these as reasons to automate portions of support. Humans stay in the loop for the harder cases.
| Signal | What Claude contributes | What it frees humans for |
|---|---|---|
| High volume of similar questions | Handles them efficiently | More complex issues |
| Information spread across vast knowledge bases | Quickly retrieves, processes and combines it | Avoids time spent researching or consulting multiple sources |
| Need for round-the-clock coverage | Support without fatigue | Avoids costly continuous staffing |
| Sudden increases in query volume | Absorbs the spike | No need to hire and train extra staff |
| Consistent brand tone | Can be instructed to represent your tone and values | Less variation in communication styles |
2.When the output becomes a decision about someone
The picture changes when Claude's output stops being a draft and becomes the decision. Anthropic's guidance for teams building on the API names this category directly: for sensitive information and decision making, a qualified professional should review the content before it reaches consumers. The word qualified matters. A reviewer has to be able to judge whether the output is right, not just confirm that it exists.
The legal-summarisation guide shows the same principle in a specific domain. Summarising contracts is a strong use of Claude. But the guide tells builders to understand that errors in summaries could create legal liability, and to add notices that the summaries are AI-generated and should be reviewed by legal professionals. The task is appropriate. Treating its output as final legal advice is not.
Sampling reviews some decisions after they have already landed on people. Everyone outside the sample gets a decision that no qualified person looked at before it took effect. Anthropic's guidance puts professional review before dissemination, not in an audit afterwards. The fix is to have Claude prepare the case, for example by summarising, flagging or drafting a recommendation, while a qualified person makes each decision.
| Use | Informs a human | Decides on its own |
|---|---|---|
| Legal documents | Structured summary a lawyer reviews | Summary sent to a client as the answer |
| Sensitive decisions about people | Draft assessment a qualified professional checks first | Output released to the affected person unreviewed |
| Customer support | Answers routine questions and escalates complex issues | Resolves every case with no human path |
Anthropic also describes safety as a shared responsibility. Its features are not failsafe, and the organisation deploying Claude is the second line of defence. This is why the human checkpoint belongs to the deployer's design. A team cannot assume the model will refuse to make a decision it should not make.
Anthropic's Usage Policy formalises this. When it was restructured, it broke out specific high-risk use cases that carry additional requirements because they pose an elevated risk of harm. The details of those requirements belong to the governance lessons. For identifying use cases, the takeaway is that some domains are not banned but come with conditions. The usual condition is qualified human review before anyone is affected.
A cybersecurity vendor asks Claude to reverse-engineer a competitor's software and write exploit code for a previously undisclosed vulnerability, intending to sell the exploit on a private marketplace. Is this an appropriate use of Claude?
Correct answer: B — No, because the Usage Policy bans creating exploits and malware meant for unauthorized offensive use
- A. Incorrect. Security research is not blanket-permitted; the Usage Policy specifically prohibits developing exploits and malware for unauthorized offensive use, regardless of the requester's field.
- B. Correct. Anthropic's Usage Policy prohibits using Claude to create malware, exploits, or other tools designed to exploit vulnerabilities without authorization, which is exactly what this scenario describes.
- C. Incorrect. Labeling content as AI-generated does not make a prohibited use case permissible; disclosure is not a substitute for complying with the underlying restriction.
- D. Incorrect. The core problem is the unauthorized creation of offensive exploit code, not a copyright dispute over the resale of the finished exploit.
3.Uses that no review makes acceptable
Some requests are not a question of oversight at all, because the purpose itself is the problem. A fabricated refund confirmation is deceptive whether or not a human approves it. Anthropic's article on agents and the Usage Policy lists concrete examples. It states that every agentic use must still follow the Usage Policy, so moving a task from a chat window into an automated agent changes nothing.
| Theme | Examples the article lists |
|---|---|
| Surveillance and profiling | Tracking individuals’ activities without notification or consent; profiling people by protected attributes; facial recognition or biometric identification |
| Deception and fraud | Websites mimicking legitimate pages; content that leads to phishing, social engineering or fraud; impersonating people without consent |
| Platform abuse | Spamming government services or crisis helplines; coordinated harassment; manipulating polls or traffic metrics; click farming; influence operations; bulk abuse reporting |
| System and financial compromise | Installing malware without authorization; privilege escalation; unauthorized or fraudulent financial transactions; using stored credentials to access another person's account |
The list is explicitly non-exhaustive, so treat it as a set of patterns rather than a checklist. The common thread is harm to people who did not agree to it. That includes deceiving them, watching them, manipulating what they see, or taking actions in their name or with their resources. Marketing copy built on invented clinical results falls into this category, and so do support replies that invent facts to stall a customer.
Even the one formal route to modified restrictions leaves the core prohibitions in place. Anthropic may tailor use restrictions for carefully selected government entities. One example is allowing foreign intelligence analysis under applicable law, and only for models at ASL-2. Even then, prohibitions on disinformation, weapons, censorship, domestic surveillance and malicious cyber operations still apply. Eligibility also depends on safeguards against misuse and on independent, democratic oversight. So even the exception is decided by how well harm is controlled.
A parenting-app startup wants to build a chatbot for teenagers using Claude, marketed as a virtual "friend" that engages in romantic and sexual role-play with users who state they are 15 years old. Is this an appropriate use of Claude?
Correct answer: B — No, because the Usage Policy bans sexual role-play with minors regardless of consent or fictional framing
- A. Incorrect. Parental consent does not override the Usage Policy's prohibition on sexual content involving minors; this category of harm is not waivable through consent forms.
- B. Correct. The Usage Policy prohibits sexual content involving minors outright, and framing the interaction as fictional role-play or obtaining consent does not exempt it from this rule.
- C. Incorrect. Fictional framing does not exempt content from the Usage Policy's prohibition on sexualized interactions with users identified as minors.
- D. Incorrect. Adding age verification does not resolve the issue, since the underlying content itself is prohibited regardless of how age is confirmed.
4.Disclosure and bounded autonomy make a use appropriate
Between drafting help and prohibited uses sits a wide middle ground. There, how Claude is deployed decides whether a use is appropriate. Two controls come up repeatedly in Anthropic's guidance.
The first is disclosure. For external-facing products, Anthropic recommends telling users they are interacting with an AI system. The Usage Policy update made this a requirement for organisations whose own users interact with Claude through their tools. A support bot that says it is AI is ordinary. The same bot posing as a named human agent is edging towards impersonation.
The second is limiting what an agent can do without a person. The prohibited list includes actions against critical infrastructure and system exploitation. The practical counterpart is scoping. Give Claude low-impact, reversible actions to take on its own, and require explicit human approval before anything touches systems or people where a mistake would be costly or hard to undo.
Bounded autonomy along the line of recoverability. Mistakes in staging and low-priority tickets are cheap and visible, so Claude acts alone there. Production changes can do serious damage, so a human approves before execution. This is the inform-don't-decide idea applied to actions instead of text.
5.Deciding whether to delegate at all
The previous sections sort use cases after someone has proposed them. Anthropic's AI Fluency material goes one step earlier and asks whether AI should be used at all. The Delegation-Diligence loop starts with Problem Awareness, which means being clear on the problem before reaching for a tool. Next comes Platform Awareness, because you cannot sensibly delegate to a tool you do not understand. Only then does Task Delegation happen. Creation, Transparency and Deployment Diligence follow to make sure the delegation is responsible.
The course is blunt about the default. You start with no AI, and the analysis has to earn the decision to opt in. It also names the pitfalls. Reaching for AI when you do not know what you want is the immediate one. Convergence and skill atrophy are the long-term ones. So a use can be inappropriate without breaking any rule. It may simply be the wrong tool for a problem you have not defined, or a task you need to keep the skill to do yourself.
| Stage | Question to ask before using Claude |
|---|---|
| Problem Awareness | What problem am I actually solving? |
| Platform Awareness | Do I understand the tool well enough to hand it this? |
| Task Delegation | Which part of the work goes to the tool, and which stays with me? |
| Creation, Transparency and Deployment Diligence | Have I checked the result against my standards, and am I open about how it was made? |
A university biosecurity lab asks Claude to help draft detailed synthesis instructions for a novel pathogen with pandemic potential, describing the request as an internal red-team exercise. Is this an appropriate use of Claude?
Correct answer: C — No, because the Usage Policy bans assisting biological weapons development regardless of affiliation or intent
- A. Incorrect. Institutional accreditation does not exempt a request from the Usage Policy's ban on assisting with the development of biological, chemical, or nuclear weapons.
- B. Incorrect. Framing a request as a red-team exercise does not create an exemption; the prohibition applies to the substance of the request, not its stated purpose.
- C. Correct. The Usage Policy prohibits helping design or synthesize biological, chemical, radiological, or nuclear weapons, and this restriction applies regardless of who is asking or why.
- D. Incorrect. No sales exception can authorize weapons-development content; this category is a universal prohibition, not a negotiable licensing term.
Sources8
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.Letting Claude make decisions about people is acceptable as long as staff spot-check a sample of the results afterwards.Why is that wrong?
Anthropic's guidance puts review by a qualified professional before content reaches the people affected. An after-the-fact sample leaves most decisions unreviewed when they take effect.
2.When an agent performs a task automatically, it falls outside the rules that govern what a person types into a chat.Why is that wrong?
Anthropic states that every agentic use still has to follow the Usage Policy. Automating a prohibited task leaves it prohibited.
Covered in Uses that no review makes acceptable
3.A government contract with tailored restrictions can unlock any use, including surveillance or disinformation.Why is that wrong?
Tailored government restrictions are narrow, such as foreign intelligence analysis under applicable law. The core prohibitions stay in force.
Covered in Uses that no review makes acceptable
4.If Claude is capable of a task, using it is the sensible default.Why is that wrong?
The Diligence approach starts with no AI. The analysis of the problem decides whether and how to opt in, and capability alone does not justify delegation.
Covered in Deciding whether to delegate at all
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.https://support.claude.com/en/articles/7996845-what-are-some-things-i-can-use-claude-forOfficial docs
“Claude is great at generating concise summaries of long articles, news stories, documents, conversations, or even books!”
↩︎ Where Claude fits well: work you can check“Claude knows more than a dozen languages and can translate between them to varying degrees of success.”
↩︎ Where Claude fits well: work you can check - 2.
“Claude excels at handling a large number of similar questions efficiently, freeing up human agents for more complex issues.”
↩︎ Where Claude fits well: work you can check - 3.
“For sensitive information and decision making, have a qualified professional review content prior to dissemination to consumers.”
↩︎ When the output becomes a decision about someone“Our features are not failsafe, and committed partners are a second line of defense.”
↩︎ When the output becomes a decision about someone“For external-facing products, disclose to your users that they are interacting with an AI system.”
↩︎ Disclosure and bounded autonomy make a use appropriate“For sensitive information and decision making, have a qualified professional review content prior to dissemination to consumers.”
↩︎ Key concept“For sensitive information and decision making, have a qualified professional review content prior to dissemination to consumers.”
↩︎ Exam trap 1 - 4.
“Understand the legal implications of errors in the summaries, which could lead to legal liability for your organization or clients.”
↩︎ When the output becomes a decision about someone“clarifying that the summaries are generated by AI and should be reviewed by legal professionals”
↩︎ When the output becomes a decision about someone - 5.
“that have additional requirements due to posing an elevated risk of harm.”
↩︎ When the output becomes a decision about someone“help their own users understand they are interacting with an AI system”
↩︎ Disclosure and bounded autonomy make a use appropriate - 6.https://support.claude.com/en/articles/12005017-using-agents-according-to-our-usage-policyOfficial docs
“All uses of agents and agentic features must continue to adhere to Anthropic’s Usage Policy.”
↩︎ Uses that no review makes acceptable“Generate content that leads to phishing, social engineering, or fraud”
↩︎ Uses that no review makes acceptable“Access or modify another person's account using their stored credentials without authorization”
↩︎ Uses that no review makes acceptable“Execute commands that attempt privilege escalation or system exploitation”
↩︎ Disclosure and bounded autonomy make a use appropriate“All uses of agents and agentic features must continue to adhere to Anthropic’s Usage Policy.”
↩︎ Exam trap 2 - 7.
“including those prohibiting use for disinformation campaigns, the design or use of weapons, censorship, domestic surveillance, and malicious cyber operations, remain”
↩︎ Uses that no review makes acceptable“The safeguards in place to prevent misuse and mitigate risks of mistakes.”
↩︎ Uses that no review makes acceptable“including those prohibiting use for disinformation campaigns, the design or use of weapons, censorship, domestic surveillance, and malicious cyber operations, remain”
↩︎ Exam trap 3 - 8.https://academy.claude.com/courses/ai-fluency-for-creative-work/delegation-and-diligenceOfficial docs
“Problem Awareness comes first: be clear on the problem you are actually solving before reaching for a tool.”
↩︎ Deciding whether to delegate at all“The starting position is no AI; the analysis determines whether and how you opt in.”
↩︎ Deciding whether to delegate at all“Convergence and skill atrophy are the long-term pitfalls; reaching for AI when you do not know what you want is the immediate one.”
↩︎ Deciding whether to delegate at all“The starting position is no AI; the analysis determines whether and how you opt in.”
↩︎ Exam trap 4