What you will be able to do
- Explain why a written AI policy beats 'use common sense', and name the three questions a usable policy answers
- Decide when to disclose AI assistance and when to route work through a human reviewer
- Apply the pre-approval questions a security team asks before an AI tool is connected to a data source
- Say what record should exist of connectors, roles and actions, and why its absence hurts an incident review
- Choose the right action when a capability you want to use is not mentioned in the policy at all
Key concept
Organizational AI policy — A written, task-level set of commitments about where AI may and may not be used, what gets disclosed to whom, and when the rules get revisited. It is not a single yes-or-no stance on AI; it is a set of decisions made per mode of work and per task.
1.Why 'use common sense' is not a policy
A manager who tells his team to use good judgement with Claude and write nothing down has not set a policy; he has distributed the decision. Everyone then draws their own line, nobody can be shown to have crossed it, and the organization learns what its rules were only after something goes wrong. The AI Fluency material treats policy-writing as a deliverable in its own right: draft something that keeps humans in the loop and that ties AI use back to what the organization is actually for.
What makes a policy usable is that it is decided at the level of mode and task rather than as one global stance. 'We allow AI' and 'we ban AI' are both unusable, because neither tells an analyst whether she may draft a client email, summarize an internal report, or score a job applicant. The same course names the three questions a policy has to answer, and adds the part most policies forget — the trigger that makes you reopen it.
What you disclose, and to whom — disclosure is set by audience, not once for everything. And when you will revisit the policy: the material warns that a policy without revision triggers goes stale silently, which is exactly what happens when a new capability ships and nobody reopens the document.
2.Disclosure and keeping a human in the loop
Anthropic's own guidance to organizations building on Claude sets two habits that internal policies tend to mirror. First, tell people when they are dealing with an AI: for external-facing products, disclose to users that they are interacting with an AI system, and for organizations serving minors that disclosure is mandatory rather than advisory. Second, where the content matters, put a qualified person in front of it before it goes out.
Internal disclosure — 'this memo was drafted with Claude' — is a different obligation, and it comes from your own policy rather than from Anthropic. If the policy says AI assistance is disclosed on internal documents, heavy editing does not dissolve that: the policy sets what you disclose and to whom, and a draft you reworked is still a draft Claude produced. The right move is to add the disclosure note and send it, not to argue that your edits made the output original.
Human review is the other half. The AI Fluency framing is to design a repeatable AI-assisted workflow with appropriate human review built into it, rather than reviewing whatever happens to feel risky on the day. That is the same instinct behind having a qualified professional check content before it reaches consumers.
A company systematically queries Claude through the API to collect large volumes of model outputs, then uses that data to train a rival large language model that it plans to sell. This activity is:
Correct answer: C — Prohibited under the Usage Policy's restrictions on using Claude's outputs to develop competing models.
- A. Incorrect. Ownership of individual outputs does not exempt systematic scraping used to train a competing model from Usage Policy restrictions.
- B. Incorrect. Omitting attribution does not make the underlying prohibited activity, training a competitor on scraped outputs, acceptable.
- C. Correct. The Usage Policy prohibits model scraping and using Claude's outputs to develop competing models.
- D. Incorrect. The prohibition applies to the scraping and competing-model training itself, not only to republishing Anthropic's original training data.
3.Approval before you connect Claude to something
The moment that most often needs an approval step is connecting Claude to a data source — a mailbox, a document store, an internal system. Anthropic's Deputy CISO describes a review process built around four questions, and they are worth knowing because they are the questions your own security team will ask you.
| Question | What it establishes |
|---|---|
| What untrusted content does it ingest? | Whether an outsider can plant instructions in what Claude reads. If the answer is nothing, the agent-specific risk is near zero |
| What actions can it take, and on whose behalf? | Read-only versus read/write, and which identity the action happens under |
| What is the blast radius if it is misaligned? | Whether a bad outcome touches one file or the whole org |
| What observability do I have? | Whether agent actions can be told apart from user actions, and whether they land in your SIEM |
Two principles follow. Least agency: grant the narrowest capability that still completes the task, rather than the broadest one that definitely will. And staged rollout — the stated default posture is admin-paced: enable a small group, watch the telemetry, expand. For a knowledge worker this cashes out as a simple rule: the approval happens before the connector is linked, not after the first useful result.
A journalist uses Claude to help draft portions of an article that will be published under the news outlet's byline. Under Anthropic's Usage Policy guidance for high-risk journalistic content, what is required?
Correct answer: B — The outlet must apply appropriate human editorial review and disclosure practices regarding AI involvement before publication.
- A. Incorrect. Journalistic content generated for publication is treated as a high-risk use case, not an exempt category.
- B. Correct. Journalistic content requires human editorial review and appropriate disclosure of AI involvement before publication.
- C. Incorrect. The policy requires editorial review and disclosure, not a blanket ban on any AI-assisted text appearing in the article.
- D. Incorrect. Anthropic does not require a per-article signed release; the obligation is editorial review and disclosure by the outlet.
4.Who is accountable, and what record exists
When an employee uses Claude from a chat interface or a personal agent harness on their laptop, the person at the keyboard is accountable for the outcome — the same accountability that attaches to anything else done with their credentials. The tool does not absorb responsibility. Trouble starts in the middle of the spectrum, where an agent carries someone's delegated identity into systems that person is not watching; ambiguous accountability is how incidents become unexplainable.
That is the real cost of a department that has a policy but keeps no record of which connectors individual staff have linked. Nothing is necessarily wrong until an incident review begins — and then there is no way to establish what Claude could reach, on whose behalf, or whether a given action was a person or an agent. Contrast Anthropic's own incident-response agent, where every action landed in the SIEM so anything unexpected would surface in minutes, not weeks.
Scope. You cannot bound what data was reachable or attribute actions to a person versus an agent, so the investigation cannot say what did and did not happen — the reviewers are left reconstructing the blast radius from memory.
Some records exist at the platform level too. Retention is configurable, and Claude for Work administrators are the ones who set an organization-wide retention period — not individual members. And every human read of retained data is logged to a tamper-proof entry that customers with Access Transparency can retrieve. Know that these controls exist and who holds them; the exam cares about the boundary, not the API.
A user requests deletion of their personal data from conversation logs. Which action best satisfies this request in accordance with data privacy regulations?
Correct answer: B — Delete all conversation logs containing the user’s personal data and confirm removal promptly.
- A. Incorrect. Anonymizing data may reduce identifiability but does not fully comply with deletion requests under regulations like GDPR, which typically require complete removal of personal data unless a legitimate reason exists to retain it in anonymized form. Keeping the logs for analysis directly conflicts with the expectation that personal data be deleted.
- B. Correct. Deleting all conversation logs containing the user's personal data and confirming removal promptly directly honors the deletion request and aligns with data privacy regulations such as GDPR's right to erasure. This approach represents the most appropriate operational handling of the request.
- C. Incorrect. Disabling the API key prevents future data collection but does not remove existing conversation logs or personal data. This action addresses access control, not data deletion, and therefore fails to satisfy the user's request.
- D. Incorrect. Exporting logs to a secure archive before deleting active records preserves the data rather than eliminating it, which conflicts with the deletion request unless there is a legal basis for retention. This approach does not fully comply unless the archived data is also deleted or anonymized.
5.The controls your admins run, and how they reach you
Governance is not only a document. On Claude Enterprise, access itself is the first gate: before worrying about token-level limits, the guidance is to make sure the right people have access to the right surfaces, and to roll out higher-intensity surfaces in waves rather than to everyone on day one. If a colleague cannot see a surface you can, that is usually policy working, not a bug to route around.
| Control | What it governs |
|---|---|
| Custom role with the Analytics (Can view) admin permission | Lets a designated group owner review their team's usage without making them an Owner or Admin |
| Organization instructions | Standing guidance injected into every Claude conversation across the organization |
| Role Models tab (model access, effort cap, default model) | Which models a role may use and what it starts with by default |
Organization instructions are the interesting one for policy compliance, because the guidance shows up in-product at the moment of use rather than in documentation users have to go find. A policy that only lives in a wiki competes with the user's deadline; the same rule injected into the conversation does not. One mechanical detail worth holding: admin permissions only apply to members whose role is set to Custom.
Sources7
6.When the policy does not mention it at all
The hardest everyday case is a capability your policy simply does not address. Silence is not permission, and it is not prohibition either — it is a gap, and the person who found it is the person best placed to report it. Ask before you use it, and say what you want to use it for so the answer can be written down for everyone else.
Two things make this the right default. Anthropic's usage policy does not go quiet just because your internal document does: all uses of agents and agentic features must continue to adhere to it, whatever your org has or has not written. And quietly proceeding is precisely the failure mode security leaders describe — saying no produces shadow adoption, which has zero telemetry and generally no off switch, and the unapproved version has exactly the same properties. The blog opens by observing that somewhere in your organization, an employee has already connected an agent to something without telling you.
The goal is not zero risk. As the guide puts it, our jobs are to make agentic risk legible and bounded — which is only possible if the new use case is visible. Raising the gap is what makes your use the governed kind.
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.If the AI policy does not mention a capability, it is fine to use it — nothing forbids it.Why is that wrong?
Silence is a gap to raise before use, not permission. Proceeding unasked is shadow adoption, and Anthropic's usage policy binds the use regardless of what the internal document says.
Covered in When the policy does not mention it at all
2.Editing an AI draft heavily makes it your own work, so a disclosure requirement no longer applies.Why is that wrong?
Disclosure is a commitment your policy sets per audience, not a test of how much you rewrote. If the policy requires disclosing AI assistance on internal documents, add the note and send it.
Covered in Disclosure and keeping a human in the loop
3.If an agent running under my account does something wrong, responsibility sits with the tool or the vendor.Why is that wrong?
When a person drives Claude from a chat interface or personal agent harness, that person is accountable for the outcome, exactly as with anything else done with their credentials.
Covered in Who is accountable, and what record exists
4.An inventory of who has connected what is administrative overhead; the policy document is the real control.Why is that wrong?
Without that record an incident review cannot scope the blast radius or separate agent actions from user actions. Observability is one of the four questions asked before approval.
Covered in Who is accountable, and what record exists
5.Once the AI policy is written and circulated, governance for that year is done.Why is that wrong?
A policy with no named triggers for revisiting it decays quietly as capabilities change; the revision trigger is part of the policy, not an optional extra.
Covered in Why 'use common sense' is not a policy
6.Any member can be given permission to review their team's usage reports.Why is that wrong?
Admin permissions only take effect for members whose role is set to Custom, so a group owner needs a custom role granting Analytics (Can view) — not a note asking them to help out.
Covered in The controls your admins run, and how they reach you
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“Draft an organizational AI policy that keeps humans in the loop and aligns AI use with your mission and values”
↩︎ Why 'use common sense' is not a policy“Combine all four competencies to design a repeatable AI-assisted workflow with appropriate human review”
↩︎ Disclosure and keeping a human in the loop“Combine all four competencies to design a repeatable AI-assisted workflow with appropriate human review”
↩︎ Approval before you connect Claude to something - 2.https://academy.claude.com/courses/ai-fluency-for-creative-work/putting-it-all-togetherOfficial docs
“There is no single position on AI usage; it is decided at the level of mode and task.”
↩︎ Why 'use common sense' is not a policy“A policy without revision triggers goes stale silently.”
↩︎ Why 'use common sense' is not a policy“There is no single position on AI usage; it is decided at the level of mode and task.”
↩︎ Key concept“Three questions anchor the policy: where AI fits and does not, what you disclose and to whom, and when you will revisit.”
↩︎ Exam trap 2“A policy without revision triggers goes stale silently.”
↩︎ Exam trap 5 - 3.
“For external-facing products, disclose to your users that they are interacting with an AI system.”
↩︎ Disclosure and keeping a human in the loop“For sensitive information and decision making, have a qualified professional review content prior to dissemination to consumers.”
↩︎ Disclosure and keeping a human in the loop - 4.
“Organizations must disclose to their users that they are interacting with an AI system rather than a human.”
↩︎ Disclosure and keeping a human in the loop - 5.https://claude.com/blog/ciso-guide-to-agentic-aiSecondary source
“grant the narrowest capability that still completes the task”
↩︎ Approval before you connect Claude to something“Our default posture at Anthropic is admin-paced rollout: enable a small group, watch the telemetry, and then expand access.”
↩︎ Approval before you connect Claude to something“Ambiguous accountability is how incidents become unexplainable.”
↩︎ Who is accountable, and what record exists“every action landed in our SIEM, so anything unexpected would surface in minutes, not weeks”
↩︎ Who is accountable, and what record exists“produces shadow adoption, which has zero telemetry and generally no off switch”
↩︎ When the policy does not mention it at all“somewhere in your organization, an employee has already connected an agent to something without telling you”
↩︎ When the policy does not mention it at all“our jobs are to make agentic risk legible and bounded”
↩︎ When the policy does not mention it at all“the person at the keyboard is accountable for the outcome”
↩︎ Exam trap 3“What observability do I have? Can you tell agent actions from user actions? Does it land in your SIEM?”
↩︎ Exam trap 4 - 6.
“Retention is configurable. Claude for Work administrators can set an organization-wide retention period.”
↩︎ Who is accountable, and what record exists“Every human read is logged to a tamper-proof entry that customers with Access Transparency can retrieve.”
↩︎ Who is accountable, and what record exists - 7.
“Before worrying about token-level limits, make sure the right people have access to the right surfaces.”
↩︎ The controls your admins run, and how they reach you“Roll out higher-intensity surfaces in waves, starting with the teams most likely to use them productively.”
↩︎ The controls your admins run, and how they reach you“the guidance shows up in-product at the moment of use rather than in documentation users have to go find”
↩︎ The controls your admins run, and how they reach you“Admin permissions only apply to members whose role is set to Custom”
↩︎ Exam trap 6 - 8.https://support.claude.com/en/articles/12005017-using-agents-according-to-our-usage-policyOfficial docs
“All uses of agents and agentic features must continue to adhere to”
↩︎ When the policy does not mention it at all“All uses of agents and agentic features must continue to adhere to”
↩︎ Exam trap 1