The policy prohibits using Cohere's AI to write malware, cyberweapons, or attack tools, and to plan or execute attacks against critical infrastructure such as power grids, water systems, or financial networks.
This analysis describes what Cohere's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision covers both the creation of offensive tools and their potential deployment against critical infrastructure, meaning operators in cybersecurity contexts must assess whether legitimate security research or penetration testing use cases could be construed as prohibited.
Interpretive note: The boundary between permitted security research and prohibited cyberweapon creation is not defined in the document and may require case-by-case assessment.
Operators and users cannot use Cohere's services to generate functional malicious code or to support cyberattacks, including against critical infrastructure, regardless of stated research or testing justifications unless those use cases are separately authorized.
How other platforms handle this
In assessing misuse, we consider factors such as evidence that a report was motivated by bias or hatred (e.g., based on protected characteristics such as race, sexual orientation, or gender identity) or other malicious intent.
We review account behavior and content that Members create, send, and publish in Mailchimp, including Campaigns and Websites.
We allow Content that names individuals in the highest positions in a company who have broad influence over the work environment, as long as the Content describes the individual's behavior or performance at work.
"Do not use Cohere's services to create cyberweapons or malicious code that could cause significant damage if deployed, or to conduct attacks on critical infrastructure.Excerpt from Cohere's Responsible Use Policy
REGULATORY LANDSCAPE: This provision engages the US Computer Fraud and Abuse Act (CFAA), the EU's Directive on Attacks Against Information Systems (2013/40/EU), the UK Computer Misuse Act, and critical infrastructure protection frameworks such as CISA …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision covers both the creation of offensive tools and their potential deployment against critical infrastructure, meaning operators in cybersecurity contexts must assess whether legitimate security research or penetration testing use cases could be construed as prohibited.
Operators and users cannot use Cohere's services to generate functional malicious code or to support cyberattacks, including against critical infrastructure, regardless of stated research or testing justifications unless those use cases are separately authorized.
ConductAtlas has identified this type of provision across 141 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cohere.