Governance, Risk, and Responsible Use — study note
Governance, Risk, and Responsible Use — study note
Domain 6 of the Claude Certified Associate – Foundations exam. Its four objectives ask you to:
- identify appropriate and inappropriate use cases;
- apply data sensitivity, regulatory and privacy considerations;
- follow organizational AI policies and governance standards;
- understand the ethical implications of AI usage.
Nothing here is legal advice. Where a question turns on the law, your organization’s own legal or compliance owners decide. Domain 2 covers what high-risk uses require (professional review and disclosure) and how to correct flawed output; Domain 5 covers writing organization instructions and sharing projects. This domain takes the governance angle on the same ground.
Which group is the use in?
| Group | Examples from the Usage Policy | What follows |
|---|---|---|
| Prohibited for everyone | Scams and phishing; fake reviews; falsified documents; misusing private information, including biometric data; impersonating real organizations; plagiarism, or submitting AI-assisted work without permission or attribution; bypassing guardrails; evading a ban | Do not do it. Anthropic may throttle, suspend or terminate access, and may block or modify outputs |
| High-risk (consumer-facing) | Legal; healthcare; insurance; finance; employment and housing; academic testing, accreditation and admissions; content generated automatically and published externally | Allowed with professional review and disclosure (Domain 2). You or your organization are responsible for accuracy |
| Additional guidelines | Consumer-facing chatbots; products serving minors; agentic use; MCP servers in the Connector Directory | Apply whether or not the use is high-risk; a chatbot must say it is AI at the start of each chat session |
| Ordinary | Drafting, summarizing, internal analysis; wellness advice is outside the healthcare category | Your organization’s usual policy |
The Usage Policy applies to anyone who can submit inputs, including through resellers or passthrough access.
Safety filters, warnings and appeals. Detection models can flag prompts, and safety filters may then block a response. Anthropic says these features are not failsafe: false positives and false negatives happen. Repeated violations can bring enhanced filters for a period, removed after a stretch with few or no violations.
| Problem | Route |
|---|---|
| A warning you believe is a mistake | Email Anthropic at the address on the safeguards page, with your details and account information |
| A suspension you believe is wrong | Log in with that account and fill out the appeal form |
| Your organization is on hold | “Request a review” on the affected organization |
Opening another account to get round a ban is itself prohibited.
Is the data appropriate to share?
| Data | Guidance |
|---|---|
| Financial identifiers, health records, passwords, confidential documents | The help center’s consumer-product article asks you to be thoughtful; at work, your organization’s policy decides. House practice: share only what the task needs, and never a password |
| An incognito chat | Not saved to history or memory, not used for training, can’t be reopened once closed; still retained for a period (default, or the organization’s setting); on Team and Enterprise, included in Owners’ data exports; profile preferences still apply; only outside projects |
| Protected health information | Needs the HIPAA-ready configuration, which is for Enterprise plans only (Team and individual plans can’t enable it). Only the Primary Owner accepts the BAA, click-to-accept in organization settings; it is a one-way decision; PHI goes only through covered features |
| Confidential professional work | Under the commercial terms, customer content is not used for training by default; admins can set an organization-wide retention period; very sensitive matters may call for zero data retention (ZDR) or an in-tenancy deployment, which changes where data resides but does not by itself switch off safety monitoring |
Governance inside an organization
| Lever | Who holds it | What to know |
|---|---|---|
| Organization instructions | At least an Owner role | Prompt-level guidance for consistent behavior; test in a new conversation; cannot disable safety guidelines or content policies |
| Capability settings | Owners (web search: Owner or Primary Owner) | Web search is enabled for the workspace, then switched on per chat by members where the chat has a web-search toggle; file creation can be disabled; owners control network access on Team and Enterprise plans, including allowing specific domains |
| Project sharing | Admins and Owners | Admins can turn off public projects or sharing; on Enterprise, Owners can turn sharing off for specific roles; when it is off, ask your admin |
What an AI policy for professional work should settle (modelled on Anthropic’s legal-work article, which is Anthropic’s view and not legal advice): commercial terms with a DPA and the no-training commitment; client-consent and engagement-letter practices; who verifies output against primary sources and how AI use is documented; and deployment decisions discussed with your own counsel, since the law is moving quickly.
Ethics
- Be open. Consumer-facing chatbots, including any external-facing or interactive AI agent, must tell users they are talking to AI, at a minimum at the beginning of each chat session. Never present AI output as human-generated. The Usage Policy lists submitting AI-assisted work without proper permission or attribution alongside plagiarism.
- Claude’s values. The constitution wants Claude to be exceptionally helpful while honest, thoughtful and caring about the world. It generally prioritizes being broadly safe, then broadly ethical, then following Anthropic’s guidelines, then genuinely helpful, weighed holistically rather than strictly. Claude only sincerely asserts what it believes true and avoids creating false impressions; a persuasive essay on request is a performative assertion, not a lie. Operators may give Claude a custom AI persona, but by default, whatever an operator instructs, it will not claim to be human when sincerely asked, and operators cannot have it deceive users with false information. A user can set up a role-play in which Claude plays a human.
- Use the right route. Report potentially inaccurate, biased or harmful output through the “report issues” thumbs-down or similar feedback, where available, or to the user-safety email. Feedback on the safety measures themselves goes to the address on Anthropic’s safety page. As house practice, a tool that runs unattended needs a named person who reviews and reports.
Sources
- Usage Policy — https://www.anthropic.com/legal/aup
- Our approach to user safety — https://support.claude.com/en/articles/8106465-our-approach-to-user-safety
- Safeguards warnings and appeals — https://support.claude.com/en/articles/8241253-safeguards-warnings-and-appeals
- Who can view my conversations? (sensitive data) — https://support.claude.com/en/articles/8325621-i-would-like-to-input-sensitive-data-into-my-chats-with-claude-who-can-view-my-conversations
- Use incognito chats — https://support.claude.com/en/articles/12260368-use-incognito-chats
- HIPAA-ready Enterprise plans — https://support.claude.com/en/articles/13296973-hipaa-ready-enterprise-plans
- Using Claude for legal work — https://support.claude.com/en/articles/15707726-using-claude-for-legal-work-privilege-confidentiality-and-how-to-think-about-configuration
- Set organization instructions — https://support.claude.com/en/articles/14546867-set-organization-instructions
- Enable and use web search — https://support.claude.com/en/articles/10684626-enable-and-use-web-search
- Create and edit files with Claude — https://support.claude.com/en/articles/12111783-create-and-edit-files-with-claude
- Manage project visibility and sharing — https://support.claude.com/en/articles/9519189-manage-project-visibility-and-sharing
- Claude is providing incorrect or misleading responses — https://support.claude.com/en/articles/8525154-claude-is-providing-incorrect-or-misleading-responses-what-s-going-on
- Claude’s constitution — https://www.anthropic.com/constitution