Read the usage policy before you build on an AI vendor
How to check, in an hour, whether a vendor's rules and your legal duties allow the work you are about to sell, and what to do when they don't.
on this page · 0 / 0 checked
You picked your assistant on how well it writes. Nobody picks one on the usage policy, which is the document that actually decides whether you are allowed to do the work you just quoted for. It is free, it is dated, and it carries the only rules in this market that produce a hard no: not a worse answer, not a slower answer, but an account that stops working and a client deliverable you cannot ship.
The people who find this out late are not doing anything exotic. They are screening job applicants, drafting letters that read as legal advice, summarising medical notes for a clinic, building a tool that identifies faces in a customer’s CCTV, or automating a decision about someone’s tenancy. Each of those is addressed by name in at least one major vendor’s published rules. This guide is a procedure for checking, before you build, whether the vendor and the law allow the thing, and what to do when only one of them does. It is written for a one-person business or a small team without a legal department. If you have procurement and counsel, they already do this, and they do it better. Nothing here is legal advice.
The document that decides your eligibility is free and dated
Each of the three big assistants publishes a usage policy that applies to anyone who can submit inputs to its products, including through resellers and passthrough access, and it sits separately from the terms of service and from any law [1]. Anthropic’s Usage Policy is effective 15 September 2025 [1]. OpenAI’s Usage policies are effective 29 October 2025 [2]. Google’s Generative AI Prohibited Use Policy carries a last-modified date of 17 December 2024 [3]. Three vendors, three documents, three dates, and no reason to assume they say the same thing.
Read the version for the product you pay for, on the vendor’s own domain, and read it once end to end rather than searching for your keyword. Set aside half an hour for each. What you are looking for is not the obvious material about weapons and abuse, which will not describe your business. You are looking for the two or three clauses that quietly govern ordinary commercial work, because those are the ones that decide whether your use case is eligible at all.
Then save the date and the clause. When a client asks whether you are allowed to run their data through an assistant, the useful answer is a quoted line with a version date attached, not your recollection of a policy page you read in the spring. Vendors revise these documents and keep the superseded text online, which is why Anthropic’s policy page carries both an effective date and a link to the previous version [1]. A claim about what a policy said is only as good as the date on it.
The clauses that catch ordinary small-business work
Three patterns come up repeatedly, and none of them look like misuse when you are the one doing them.
The first is advice in a licensed field. Anthropic requires, for high-risk uses, that “a qualified professional in that field must review the content or decision prior to dissemination or finalization”, and that where outputs go directly to individuals “you must disclose to them that you are using AI to help produce your advice, decisions, or recommendations” [1]. OpenAI prohibits the “provision of tailored advice that requires a license, such as legal or medical advice, without appropriate involvement by a licensed professional” [2]. If you sell contract templates, HR guidance, tax summaries or health content, the vendor is not asking you to stop. It is telling you that a licensed human has to be in the loop and that the client has to be told a model was involved.
The second is decisions about people. OpenAI prohibits high-stakes automated decisions without human review in areas including credit, employment, housing, insurance, legal and medical [2]. Google prohibits anything that “makes automated decisions that have a material detrimental impact on individual rights without human supervision in high-risk domains”, and names employment, healthcare, finance, legal, housing, insurance and social welfare as the examples [3]. A CV screener that ranks applicants and drops the bottom half without anyone reading them is inside that description. The same screener that produces a shortlist a human then reviews is not.
The third is anything that identifies or infers things about a person. OpenAI’s rules cover facial recognition databases built without consent, “real-time remote biometric identification in public spaces”, “inference regarding an individual’s emotions in the workplace and educational settings, except when necessary for medical or safety reasons”, and evaluating or classifying people based on their social behaviour [2]. Anthropic prohibits use to “Target or track a person’s physical location, emotional state, or communication without their consent” [1]. Small integrators walk into this through a client’s security-camera project or a sales tool that scores prospects on their social posts.
If your use case sits in one of those three, you are not blocked. You are conditionally allowed, and the conditions are a named human reviewer, a disclosure line and consent. Write those into the proposal and the price, because they are work.
Your legal duties sit on top of the vendor’s rules
Vendor policy and law are separate stacks, and complying with one tells you nothing about the other. If you serve customers in the European Union, the AI Act’s transparency rules came into effect in August 2026 [7]. In practice, humans “should be made aware that they are interacting with a machine so they can take an informed decision”, providers of generative AI have to ensure that AI-generated content is identifiable, and certain content, including deep fakes and text published to inform the public, has to be clearly and visibly labelled [7]. That is not a vendor preference you can negotiate away by moving to a different model.
The heavier obligations arrive later. Prohibited practices and AI literacy obligations applied from 2 February 2025, governance rules and obligations for general-purpose AI models from 2 August 2025, and rules for high-risk systems in sensitive areas from 2 December 2027, with systems embedded in regulated products from 2 August 2028 [7]. If you are building something that touches hiring, credit, education or essential services, that last date is your planning horizon, not a distant abstraction.
The operational version of this for a small shop is short. A chatbot on a client’s site needs a line that says it is a bot. Content published to inform the public needs to be marked when it is machine-generated. The first of those is also what Anthropic’s policy asks for wherever model outputs are presented directly to individuals, at a minimum at the start of each session [1]. Writing the line once satisfies two masters, which is the only free lunch in this guide.
The same brand has different rules on different tiers
The most common reasoning error is treating a vendor as one thing. The rules that matter most to a client, the ones about training and retention, usually differ between the free tier, the consumer app, the business plan and the API, under the same logo.
Google’s Gemini API Additional Terms of Service, effective 23 March 2026, are explicit. On the unpaid tier, Google “uses the content you submit to the Services and any generated responses to provide, improve, and develop Google products and services”, human reviewers “may read, annotate, and process your API input and output”, and the terms tell you plainly: “Do not submit sensitive, confidential, or personal information to the Unpaid Services” [4]. On paid services, “Google doesn’t use your prompts … or responses to improve our products”, and prompts and responses are logged for a limited period to detect abuse and meet legal obligations [4].
OpenAI draws the same line by product. It states that by default it does not use data from ChatGPT Enterprise, Business, Edu, ChatGPT for Healthcare, ChatGPT for Teachers or the API platform, inputs or outputs, for training or improving its models, with explicit opt-in available; it lets qualifying organisations configure retention, including a zero data retention option on the API platform; and it lists regions where eligible customers can store sensitive content at rest, including the United States, Europe, the United Kingdom, Japan, Canada, South Korea, Singapore, Australia, India and the UAE [5].
So the honest answer to “is it safe to put client data in” is a sentence with a tier in it. The same prompt typed into a free key and into a paid business account gets different treatment from the same company. When you write this into a client contract, name the tier, name the product, and keep the link.
Large buyers negotiate the terms, and you get the published ones
Big customers do not read these policies the way you do. They ask for changes. Anthropic’s Usage Policy says so directly: the company “may enter into contracts with certain governmental customers that tailor use restrictions to that customer’s public mission and legal authorities” where, in its judgment, the contractual restrictions and safeguards adequately mitigate the harms the policy addresses [1]. Read that clause as the general case. Terms are a negotiation for buyers with leverage and a published document for everyone else.
The public example is worth reading for its shape rather than its subject. On 31 August 2026 the US Department of War launched OpenAI’s ChatGPT Mil on GenAI.mil, accredited for controlled unclassified information at Impact Level 5 and “built for scale to support more than 3 million Department personnel”, aimed at “document-heavy unclassified work across the Department, including planning, policy, logistics, and administration” [6]. That release describes the result as a “multi-model ecosystem for the warfighter” and names no vendor other than OpenAI [6]. Anthropic, for its part, said it had held two narrow exceptions on government work, fully autonomous weapons and mass domestic surveillance, and that on 4 March 2026 it received a letter designating it “a supply chain risk to America’s national security”, an action it called not legally sound and said it would challenge in court [8]. Nothing in that sequence turned on which model wrote a better memo.
The lesson for a business your size is not about defence procurement. It is that the rules governing your access are set by a negotiation you are not in, between the vendor and its largest customers and regulators, and they can move without you. That is a reason to know exactly which clause your work depends on, so you notice when it changes.
A second source you have actually tested
The cheap insurance against all of this is a second vendor you have run your real work through at least once. Not an account you opened. A job you completed.
Three things make switching survivable, and all three are habits rather than purchases. Keep your prompts in files you own, in a repository or a folder, rather than saved inside one vendor’s interface. Keep the inputs, the client documents and data, in your own storage, so that changing model means changing an endpoint rather than re-collecting material. And write your own acceptance test for each recurring job, meaning three or four real inputs and the output you would accept, so that trying another model is an afternoon of comparison and not a leap of faith.
Then price the switch, because “we could move” is only true if you know what moving costs. Count the workflows that would need re-testing, estimate the minutes each takes to re-run and check, and multiply by what your hour is worth. For most solo operators the number is small enough to be embarrassing next to the risk it covers, and that is the point of computing it.
jobs × minutes ÷ 60 × hourly rate. Add the second vendor's monthly seat separately. Computed in the page; nothing is sent anywhere.
What still goes wrong
Policies change, and the ones quoted here carry dates for that reason: 15 September 2025 for Anthropic [1], 29 October 2025 for OpenAI [2], 17 December 2024 for Google’s prohibited-use rules [3] and 23 March 2026 for the Gemini API terms [4]. A guide is a snapshot. Before you commit a client to anything, open the source and check that the clause still reads the way it reads here.
Reading the policy also cannot tell you how it will be enforced against you. The published rules describe categories, not the line the vendor’s systems actually draw on a given day. OpenAI states that breaking or circumventing its rules and safeguards may mean you lose access to its systems or face other penalties, and that you can appeal if you think a mistake was made [2]. That is the honest shape of it: a decision arrives first, and you argue afterwards, on someone else’s timetable. Which is why the second source matters more than any argument you would eventually win.
The last limit is the one this guide inherits from its subject. Nothing here tells you whether a use is wise, only whether it is permitted. A hiring screen with a human reviewer bolted on satisfies three vendors’ policies and can still be a bad system that quietly ranks people on something you would not defend out loud. Eligibility is the floor. If the only reason you are keeping a person in the loop is that a policy document made you, you have built the thing the policy was written about.
- 01Anthropic — Usage Policyanthropic.com
- 02OpenAI — Usage policiesopenai.com
- 03Google — Generative AI Prohibited Use Policypolicies.google.com
- 04Google — Gemini API Additional Terms of Serviceai.google.dev
- 05OpenAI — Enterprise privacy and business dataopenai.com
- 06U.S. Department of War — Department of War Launches OpenAI's ChatGPT Mil on GenAI.milwar.gov
- 07European Commission — AI Act regulatory frameworkdigital-strategy.ec.europa.eu
- 08Anthropic — Where things stand with the Department of Waranthropic.com