Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
OpenRouter's Acceptable Use Policy sets out the rules for using its AI model routing platform, covering what types of content and applications are permitted or prohibited across all models accessible through the service. The policy states that users and operators building applications on OpenRouter are prohibited from using the platform to generate content involving child sexual abuse material, weapons of mass destruction, unlawful surveillance, or systematic deception, and that operators are responsible for ensuring their end users comply with these restrictions. The policy also incorporates by reference the terms of individual upstream AI model providers, meaning that users may be subject to additional restrictions depending on which model they access through the platform.
This document is OpenRouter's Acceptable Use Policy, which governs permissible and prohibited uses of the OpenRouter platform, an API-based service that routes requests to third-party AI model providers. The terms establish categories of prohibited content and conduct, including prohibitions on generating content that facilitates illegal activity, produces CSAM, enables weapons development, or engages in systematic deception, and the agreement states that users are responsible for ensuring their applications comply with both OpenRouter's policy and the upstream model providers' terms of use. The policy is operationally notable in that it applies not only to direct API users but also to downstream applications built on the platform, creating a layered compliance obligation where operators bear responsibility for their end users' conduct. The document engages general consumer protection frameworks, AI governance considerations, and content moderation obligations that may interact with the EU AI Act, GDPR for EU-based users, and sector-specific regulations depending on the use case. Compliance teams deploying OpenRouter in regulated industries should evaluate whether the upstream model provider terms create additional constraints that are incorporated by reference into the user's obligations under this policy.
The agreement establishes that all users and operators accessing AI models through OpenRouter are bound by the platform's prohibited use categories as well as the terms of individual upstream model providers, which may vary by model. Under these terms, operators who build applications on the OpenRouter API bear compliance responsibility for their end users' conduct on the platform. You can review the terms of specific upstream model providers by accessing the individual model pages within the OpenRouter platform.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
OpenRouter has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.