The policy permits limited exceptions to its prohibited use categories for research purposes, but only when specifically authorized by Cohere or when the research falls within Cohere's published Responsible Disclosure Policy. Safety-related research outside that scope requires contact with safety@cohere.com.
This analysis describes what Cohere's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that research activities that would otherwise violate the Usage Policy require prior authorization from Cohere or must fall within the Responsible Disclosure Policy, creating a gating mechanism for security and safety researchers that affects the operational scope of permissible adversarial testing and red-teaming activities.
Interpretive note: The policy does not specify authorization criteria, timelines, or the process for obtaining exceptions, creating uncertainty about the practical accessibility of this mechanism for researchers.
The updated policy removes all substantive acceptable use requirements that were previously posted and enforceable. Users no longer have a referenced standard defining what conduct is prohibited on the platform. The removal of enforcement procedures means users cannot verify what conduct may trigger access restriction, suspension, or termination. The elimination of the child safety and sexually explicit content prohibitions from the posted policy creates uncertainty about whether these protections remain in effect through other terms or have been abandoned.
View change record →Under this clause, researchers seeking to conduct security or safety testing of Cohere services that would otherwise fall within prohibited categories must obtain prior authorization from Cohere or operate within the published Responsible Disclosure Policy. The clause does not specify the authorization process, timeline, or criteria.
Cross-platform context
See how other platforms handle Research Exception Requiring Prior Authorization and similar clauses.
Compare across platforms →"Cohere encourages responsible security and safety research. Limited exceptions to our Usage Policy are possible for research purposes if specifically authorized by us or permitted in accordance with our Responsible Disclosure Policy applicable to security research. For safety-related research that falls outside the scope of our Responsible Disclosure Policy or to report a model safety issue, please contact safety@cohere.com.Excerpt from Cohere's Usage Policy
1) REGULATORY LANDSCAPE: Research exceptions in acceptable use policies interact with cybersecurity legal frameworks including the Computer Fraud and Abuse Act in the US, which may create liability exposure for unauthorized security research.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that research activities that would otherwise violate the Usage Policy require prior authorization from Cohere or must fall within the Responsible Disclosure Policy, creating a gating mechanism for security and safety researchers that affects the operational scope of permissible adversarial testing and red-teaming activities.
Under this clause, researchers seeking to conduct security or safety testing of Cohere services that would otherwise fall within prohibited categories must obtain prior authorization from Cohere or operate within the published Responsible Disclosure Policy. The clause does not specify the authorization process, timeline, or criteria.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cohere.