Cohere · Cohere Usage Policy · View original document ↗

Research Exception Requiring Prior Authorization

Low severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Cohere changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Cohere Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy permits limited exceptions to its prohibited use categories for research purposes, but only when specifically authorized by Cohere or when the research falls within Cohere's published Responsible Disclosure Policy. Safety-related research outside that scope requires contact with safety@cohere.com.

This analysis describes what Cohere's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that research activities that would otherwise violate the Usage Policy require prior authorization from Cohere or must fall within the Responsible Disclosure Policy, creating a gating mechanism for security and safety researchers that affects the operational scope of permissible adversarial testing and red-teaming activities.

Interpretive note: The policy does not specify authorization criteria, timelines, or the process for obtaining exceptions, creating uncertainty about the practical accessibility of this mechanism for researchers.

Recent Activity

This document changed recently

High May 24, 2026

The updated policy removes all substantive acceptable use requirements that were previously posted and enforceable. Users no longer have a referenced standard defining what conduct is prohibited on the platform. The removal of enforcement procedures means users cannot verify what conduct may trigger access restriction, suspension, or termination. The elimination of the child safety and sexually explicit content prohibitions from the posted policy creates uncertainty about whether these protections remain in effect through other terms or have been abandoned.

View change record →

Consumer impact (what this means for users)

Under this clause, researchers seeking to conduct security or safety testing of Cohere services that would otherwise fall within prohibited categories must obtain prior authorization from Cohere or operate within the published Responsible Disclosure Policy. The clause does not specify the authorization process, timeline, or criteria.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Close Your Account
    Contact safety@cohere.com to request authorization for safety-related research that falls outside the Responsible Disclosure Policy scope, or to report a model safety issue.

Cross-platform context

See how other platforms handle Research Exception Requiring Prior Authorization and similar clauses.

Compare across platforms →

Monitoring

Cohere has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Cohere encourages responsible security and safety research. Limited exceptions to our Usage Policy are possible for research purposes if specifically authorized by us or permitted in accordance with our Responsible Disclosure Policy applicable to security research. For safety-related research that falls outside the scope of our Responsible Disclosure Policy or to report a model safety issue, please contact safety@cohere.com.

Excerpt from Cohere's Usage Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: Research exceptions in acceptable use policies interact with cybersecurity legal frameworks including the Computer Fraud and Abuse Act in the US, which may create liability exposure for unauthorized security research. The EU's NIS2 Directive and the EU AI Act's provisions on post-market monitoring and vulnerability reporting are also relevant for security researchers operating in European contexts. The policy's reference to a Responsible Disclosure Policy implies a coordinated vulnerability disclosure framework. 2) GOVERNANCE EXPOSURE: Low to Medium. The research exception is operationally narrow and requires prior authorization, which limits the volume of research activity that this provision directly governs. However, the absence of specified authorization criteria or timelines creates uncertainty for organizations conducting AI safety research or red-teaming exercises. 3) JURISDICTION FLAGS: The Computer Fraud and Abuse Act creates jurisdiction-specific exposure for US-based security researchers who conduct testing without clear authorization. EU-based researchers face different legal frameworks under national cybercrime laws. The policy's authorization mechanism provides some legal protection for researchers who obtain prior approval, but the scope of that protection depends on applicable law. 4) CONTRACT AND VENDOR IMPLICATIONS: Organizations conducting AI red-teaming, penetration testing, or safety evaluations of Cohere services as part of vendor due diligence should confirm that their testing activities fall within the Responsible Disclosure Policy or obtain explicit written authorization from Cohere before commencing. Standard commercial penetration testing agreements may not satisfy this requirement. 5) COMPLIANCE CONSIDERATIONS: AI governance teams conducting internal safety evaluations of Cohere-powered products should assess whether their testing methodology would technically violate any Usage Policy provisions and, if so, obtain prior authorization. The safety@cohere.com contact point should be used for safety-related research that does not fit within the Responsible Disclosure Policy framework.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Provision details

Document information
Document
Cohere Usage Policy
Entity
Cohere
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015307
Document ID
CA-D-00442
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
d54fb0cb544115e31c8ba69f43a76f050bb92af77f6bf7bc14f2f17bca76e972
Analysis generated
July 9, 2026 07:41 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Cohere
Document: Cohere Usage Policy
Record ID: CA-P-015307
Captured: 2026-07-09 07:41:41 UTC
SHA-256: d54fb0cb544115e3…
URL: https://conductatlas.com/platform/cohere/cohere-usage-policy/provision/CA-P-015307/research-exception-requiring-prior-authorization/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Cohere's Research Exception Requiring Prior Authorization clause do?

This provision establishes that research activities that would otherwise violate the Usage Policy require prior authorization from Cohere or must fall within the Responsible Disclosure Policy, creating a gating mechanism for security and safety researchers that affects the operational scope of permissible adversarial testing and red-teaming activities.

How does this clause affect you?

Under this clause, researchers seeking to conduct security or safety testing of Cohere services that would otherwise fall within prohibited categories must obtain prior authorization from Cohere or operate within the published Responsible Disclosure Policy. The clause does not specify the authorization process, timeline, or criteria.

Is ConductAtlas affiliated with Cohere?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cohere.