Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
OpenAI's Usage Policies, updated October 29, 2025, define what users and developers may and may not do when using OpenAI products and services. The terms explicitly prohibit a range of activities including real-time remote biometric identification in public spaces, automation of high-stakes decisions in financial, medical, legal, and law enforcement contexts without human review, creation of facial recognition databases without data subject consent, and any use involving child sexual abuse material. The policy also states that violating or circumventing its rules and safeguards may result in loss of access to OpenAI systems or other unspecified penalties, and that users may appeal enforcement decisions.
This document establishes OpenAI's Usage Policies, effective October 29, 2025, governing permissible and prohibited uses of OpenAI products and services across all user categories. The agreement states that users must not use OpenAI services for enumerated prohibited activities including threats, harassment, weapons development, biometric identification in public spaces, CSAM, academic dishonesty, and automation of high-stakes decisions in sensitive areas without human review; the terms also reserve OpenAI's right to withhold access where it reasonably believes such action necessary to protect its service, users, or third parties. The policy's prohibition on automation of high-stakes decisions across domains including financial activities, law enforcement, medical services, and national security without human review, and its explicit prohibition on real-time remote biometric identification in public spaces, reflect alignment with regulatory postures adopted under the EU AI Act and related frameworks, though the terms do not specify how 'human review' is defined or what threshold satisfies that requirement. The policy engages regulatory frameworks including the EU AI Act, GDPR, COPPA, and FTC Act, given its provisions on biometric data, minor protections, privacy aggregation prohibitions, and consumer-facing deception restrictions; applicability of specific regulatory obligations depends on jurisdiction, user category, and the nature of the downstream application built on OpenAI services. Compliance teams operating in the EU or California should evaluate how these use restrictions interact with operator-level obligations under the EU AI Act's prohibited practices provisions and CCPA data minimization principles.
The agreement establishes a set of prohibited use categories that apply to all users of OpenAI services, including restrictions on using the services for harassment, biometric profiling, manipulation, academic dishonesty, and automation of decisions in sensitive domains such as employment, credit, and healthcare without human review. Under these terms, users who violate or circumvent the stated policies may lose access to OpenAI systems or face other penalties as determined by OpenAI. The document states that users may appeal enforcement decisions if they believe a policy enforcement action was made in error.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
5 important changes detected
6 versions captured · Last updated: July 2026
OpenAI updated its Usage Policies page on June 29, 2026 to display language selection options for multiple languages before the policy content. The actual policy text remained unchanged, stating 'We …
View change record →OpenAI's Usage Policies document was updated on June 25, 2026, with one sentence modified. The change involved the removal of language listing available interface languages from the header of the …
View change record →OpenAI's Usage Policies document underwent a technical language update on May 23, 2026. The change involved modifications to the language selector options and their display names across the policy header. …
View change record →OpenAI has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle Human Review Requirement for High-Stakes Automated Decisions and similar clauses.
Compare across platforms →OpenAI expanded its data sharing terms to include third-party marketing partners. The updated policy authorizes the use of personal data fo…
872 provisions across 8 AI platforms. The terms your AI provider sets become the terms your product operates under.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
The bill does not regulate most AI startups directly. But it changes the companies they depend on. Here is what the first federal AI law wo…
H.R. 8094 would make the FTC the referee for AI model disclosure. It also names system cards as a way to comply, which turns a voluntary in…
Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.