Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement permits use of user Inputs and Outputs for AI model training by default, with an opt-out available in account settings, but specifies two conditions under which training use continues regardless of opt-out status: when conversations are flagged for safety review, and when users have explicitly submitted content as feedback.
This analysis describes what Anthropic's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a conditional opt-out structure in which the training data opt-out right is subject to two categorical exceptions that may encompass a meaningful subset of user conversations. Compliance teams should evaluate whether this carve-out structure satisfies the opt-out right requirements under CCPA and the purpose limitation and legal basis requirements under GDPR and UK GDPR.
Interpretive note: The scope of what qualifies as safety-flagged content is not defined in the policy, creating ambiguity about how broadly the carve-out may apply in practice.
Under this clause, users can limit use of their conversations for model training through account settings, but the agreement retains authorization to use safety-flagged or explicitly reported conversations for training purposes regardless of that setting. The specific scope of what qualifies as safety-flagged content is not defined with precision in the policy.
How other platforms handle this
Microsoft also emphasizes the importance of validating AI models responsibly to enhance fairness and alignment with reality.
training AI/ML models with performance metrics to optimize network reliability; providing dedicated customer support; and, refining our Service suite through usage insights.
This is still Your Content, and you are responsible for it and its accuracy, as well as your use of it on our Services and any and all decisions made, actions taken, and failures to take action based on Your Content.
Monitoring
Anthropic has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We may use your Inputs and Outputs to train and improve Anthropic AI models, unless you opt out through your account settings. Even if you opt-out, we will use Inputs and Outputs for model improvement when: (i) your conversations are flagged for safety review to improve our ability to detect harmful content, enforce our policies, or advance AI safety research, or (ii) you've explicitly reported the materials to us (for example via our feedback mechanisms).Excerpt from Anthropic's Privacy Policy (Superseded Capture)
REGULATORY LANDSCAPE: This provision implicates CCPA's opt-out of sale and sharing rights, GDPR and UK GDPR purpose limitation and legal basis requirements (Articles 5 and 6), and the FTC Act's prohibition on unfair or deceptive practices. The carve-out for safety-flagged content invokes a legitimate interest basis that EU and UK data protection authorities may scrutinize for proportionality. The FTC is the primary US enforcement authority. GOVERNANCE EXPOSURE: High. The safety-review carve-out creates potential tension with CCPA opt-out rights if safety flagging is applied broadly, and with GDPR purpose limitation if training use of flagged data is not clearly disclosed as a compatible purpose. The scope of what constitutes safety-flagged content is not defined in the policy, creating interpretive uncertainty about how broadly this exception may apply. JURISDICTION FLAGS: California (CCPA opt-out of sharing), EU and UK (GDPR purpose limitation and legitimate interest balancing), Brazil (LGPD consent and legitimate interest grounds). The policy's separate legal bases table lists Scientific Research and Legitimate Interests for model training, which may face challenge in jurisdictions requiring explicit consent for AI training. CONTRACT AND VENDOR IMPLICATIONS: Enterprise and B2B customers using separate agreements are excluded from this policy, but organizations whose employees use consumer accounts should assess whether training data flows from consumer accounts affect confidentiality or data protection obligations. Procurement teams integrating Claude via API under consumer terms should verify which agreement governs their data. COMPLIANCE CONSIDERATIONS: Legal teams should assess whether the safety-review carve-out is sufficiently specific to satisfy transparency requirements under GDPR and CCPA. A consent mechanism audit should evaluate whether the opt-out is clearly presented at or before first use. Data mapping should document the distinction between opted-out user data used under the carve-out versus standard training data flows.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
How Meta, TikTok, and Supabase restructured governance language across documents, jurisdictions, and consent frameworks through incremental document updates.
How 10 AI platforms describe the use of user data for model training, improvement, and development, based on archived governance provisions.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes a conditional opt-out structure in which the training data opt-out right is subject to two categorical exceptions that may encompass a meaningful subset of user conversations. Compliance teams should evaluate whether this carve-out structure satisfies the opt-out right requirements under CCPA and the purpose limitation and legal basis requirements under GDPR and UK GDPR.
Under this clause, users can limit use of their conversations for model training through account settings, but the agreement retains authorization to use safety-flagged or explicitly reported conversations for training purposes regardless of that setting. The specific scope of what qualifies as safety-flagged content is not defined with precision in the policy.
ConductAtlas has identified this type of provision across 222 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Anthropic.