Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy permits limited exceptions to its prohibited use categories for research purposes, but only when specifically authorized by Cohere or when the research falls within Cohere's published Responsible Disclosure Policy. Safety-related research outside that scope requires contact with safety@cohere.com.
This analysis describes what Cohere's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that research activities that would otherwise violate the Usage Policy require prior authorization from Cohere or must fall within the Responsible Disclosure Policy, creating a gating mechanism for security and safety researchers that affects the operational scope of permissible adversarial testing and red-teaming activities.
Interpretive note: The policy does not specify authorization criteria, timelines, or the process for obtaining exceptions, creating uncertainty about the practical accessibility of this mechanism for researchers.
The updated policy removes all substantive acceptable use requirements that were previously posted and enforceable. Users no longer have a referenced standard defining what conduct is prohibited on the platform. The removal of enforcement procedures means users cannot verify what conduct may trigger access restriction, suspension, or termination. The elimination of the child safety and sexually explicit content prohibitions from the posted policy creates uncertainty about whether these protections remain in effect through other terms or have been abandoned.
View change record →Under this clause, researchers seeking to conduct security or safety testing of Cohere services that would otherwise fall within prohibited categories must obtain prior authorization from Cohere or operate within the published Responsible Disclosure Policy. The clause does not specify the authorization process, timeline, or criteria.
Cross-platform context
See how other platforms handle Research Exception Requiring Prior Authorization and similar clauses.
Compare across platforms →Monitoring
Cohere has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Cohere encourages responsible security and safety research. Limited exceptions to our Usage Policy are possible for research purposes if specifically authorized by us or permitted in accordance with our Responsible Disclosure Policy applicable to security research. For safety-related research that falls outside the scope of our Responsible Disclosure Policy or to report a model safety issue, please contact safety@cohere.com.Excerpt from Cohere's Usage Policy
1) REGULATORY LANDSCAPE: Research exceptions in acceptable use policies interact with cybersecurity legal frameworks including the Computer Fraud and Abuse Act in the US, which may create liability exposure for unauthorized security research. The EU's NIS2 Directive and the EU AI Act's provisions on post-market monitoring and vulnerability reporting are also relevant for security researchers operating in European contexts. The policy's reference to a Responsible Disclosure Policy implies a coordinated vulnerability disclosure framework. 2) GOVERNANCE EXPOSURE: Low to Medium. The research exception is operationally narrow and requires prior authorization, which limits the volume of research activity that this provision directly governs. However, the absence of specified authorization criteria or timelines creates uncertainty for organizations conducting AI safety research or red-teaming exercises. 3) JURISDICTION FLAGS: The Computer Fraud and Abuse Act creates jurisdiction-specific exposure for US-based security researchers who conduct testing without clear authorization. EU-based researchers face different legal frameworks under national cybercrime laws. The policy's authorization mechanism provides some legal protection for researchers who obtain prior approval, but the scope of that protection depends on applicable law. 4) CONTRACT AND VENDOR IMPLICATIONS: Organizations conducting AI red-teaming, penetration testing, or safety evaluations of Cohere services as part of vendor due diligence should confirm that their testing activities fall within the Responsible Disclosure Policy or obtain explicit written authorization from Cohere before commencing. Standard commercial penetration testing agreements may not satisfy this requirement. 5) COMPLIANCE CONSIDERATIONS: AI governance teams conducting internal safety evaluations of Cohere-powered products should assess whether their testing methodology would technically violate any Usage Policy provisions and, if so, obtain prior authorization. The safety@cohere.com contact point should be used for safety-related research that does not fit within the Responsible Disclosure Policy framework.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that research activities that would otherwise violate the Usage Policy require prior authorization from Cohere or must fall within the Responsible Disclosure Policy, creating a gating mechanism for security and safety researchers that affects the operational scope of permissible adversarial testing and red-teaming activities.
Under this clause, researchers seeking to conduct security or safety testing of Cohere services that would otherwise fall within prohibited categories must obtain prior authorization from Cohere or operate within the published Responsible Disclosure Policy. The clause does not specify the authorization process, timeline, or criteria.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cohere.