Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy prohibits using OpenAI services to automate high-stakes decisions in enumerated sensitive domains, including financial activities, employment, insurance, medical, legal, law enforcement, and national security, without human review.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision imposes a human-in-the-loop requirement for a broad set of consequential decision domains, which is operationally significant for enterprise and API customers building automated decision-making systems on top of OpenAI services, though the policy does not define what constitutes adequate 'human review.'
Interpretive note: The policy does not define what constitutes adequate 'human review,' creating interpretive uncertainty about the threshold required to satisfy this provision across different use cases and jurisdictions.
This provision establishes that OpenAI services may not be used to make fully automated consequential decisions affecting individuals in domains including credit, employment, insurance, medical care, and legal proceedings without a human review step, as defined by the policy.
Cross-platform context
See how other platforms handle Human Review Requirement for High-Stakes Automated Decisions and similar clauses.
Compare across platforms →Monitoring
OpenAI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Empower people. People should be able to make decisions about their lives and their communities. So we don't allow our services to be used to manipulate or deceive people, to interfere with their exercise of human rights, to exploit people's vulnerabilities, or to interfere with their ability to get an education or access critical services, including any use for: automation of high-stakes decisions in sensitive areas without human review critical infrastructure education housing employment financial activities and credit insurance legal medical essential government services product safety components national security migration law enforcementExcerpt from OpenAI's Usage Policies
(1) REGULATORY LANDSCAPE: This provision engages the EU AI Act's requirements for human oversight of high-risk AI systems across domains including employment, credit, insurance, and law enforcement. It also engages the EU's General Data Protection Regulation provisions on automated decision-making that produces significant effects on individuals. In the US, it implicates the Equal Credit Opportunity Act, Fair Housing Act, and FTC Act in the context of automated decisions affecting credit, housing, and consumer rights. The relevant enforcement authorities include the EU AI Office, national data protection authorities, CFPB, EEOC, and FTC depending on the specific domain. (2) GOVERNANCE EXPOSURE: High. The prohibition applies across a wide range of enterprise use cases. The term 'human review' is not defined in the policy, creating interpretive uncertainty for compliance teams attempting to assess whether existing workflows satisfy the requirement. Organizations deploying AI-assisted decision tools in any of the enumerated domains should establish documented human review procedures and assess whether those procedures satisfy both this policy and applicable legal standards. (3) JURISDICTION FLAGS: EU and EEA operators face heightened exposure under the EU AI Act, which classifies many of the listed domains as high-risk AI application categories subject to mandatory conformity assessments, human oversight requirements, and registration obligations. US operators in financial services, employment, and housing face additional regulatory obligations under federal civil rights and consumer protection laws that may impose human oversight requirements independently of this policy. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should review their terms of service and vendor agreements to ensure that human review workflows are documented and that contractual responsibility for compliance with this provision is clearly allocated. The policy does not specify verification or audit mechanisms, meaning OpenAI does not disclose how it monitors compliance with this requirement in downstream applications. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should inventory all automated decision workflows that use OpenAI services and assess whether human review is documented and sufficient for each enumerated domain. For EU operations, high-risk AI system registration and conformity assessment obligations under the EU AI Act should be evaluated separately from this policy's requirements. Internal policies defining what constitutes 'human review' in each sensitive domain should be established and documented.
This provision imposes a human-in-the-loop requirement for a broad set of consequential decision domains, which is operationally significant for enterprise and API customers building automated decision-making systems on top of OpenAI services, though the policy does not define what constitutes adequate 'human review.'
This provision establishes that OpenAI services may not be used to make fully automated consequential decisions affecting individuals in domains including credit, employment, insurance, medical care, and legal proceedings without a human review step, as defined by the policy.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.