In this webinar, Michael Johnson of Resolve shows which link building tactics to cut and which still drive rankings and AI visibility.

Reserve Your Seat
  1. SEJ
  2.  ⋅ 
  3. AI Search

Claude’s New Rules Target Fake Sources Built To Sway AI Answers

  • Anthropic's updated policy names seeding search and AI answer sources with misleading content.
  • It also covers networks of sites posing as independent and the tools behind them.
  • Automated publishing is no longer on the policy's list of high-risk uses.

Anthropic's updated usage policy names seeding search and AI answer sources with misleading content, and drops automated publishing from its high-risk list.

Claude’s New Rules Target Fake Sources Built To Sway AI Answers

Anthropic’s updated usage policy, which takes effect Nov. 12, prohibits using Claude to seed the sources that search engines and AI systems draw answers from with content that misrepresents its origin, authorship, or independence. The policy’s example is a network of sites that pose as unrelated sources and back the same claims.

Anthropic released it Oct. 8 with a post listing the changes, which also cover elections, weapons, surveillance, and sustained abuse of Claude models. The post describes a new section on deceptive activity but doesn’t mention search engines.

These rules are for everyone using Anthropic’s products, whether you’re a developer working with the API or someone using apps built on Claude. If the company suspects any violations, it might suspend or terminate access.

What The Policy Now Says

The policy’s search clause is now found in a new section called “Do Not Engage in Deceptive Campaigns or Artificial Activity.” This section outlines that the following use is not allowed:

“Manipulate the sources from which search engines or AI systems draw answers by seeding them with content that misrepresents its origin, authorship, or independence (e.g., networks of sites posing as unaffiliated sources corroborating the same claims)”

Other lines bar the use of fake personas, outlets, and reviews, and spreading content through “fake or ostensibly independent outlets, websites, or accounts” to hide their shared source. The section also prohibits creating tools meant for deceptive campaigns and selling any of these activities as a service.

The company explains that the policy already prohibited running fake-account networks and creating fake news sites. However, the guidelines were previously scattered across the parts of its rules on elections, fraud, privacy, and disinformation. The post says the new section covers any kind of deceptive activity, whether it’s political or commercial.

The earlier version, effective Sept. 15, 2025, did not reference search engines or AI responses. This graphic compares the respective versions.

Claude’s usage policy,
before and after

Five practices compared in Anthropic’s September 2025 and November 2026 policy texts.

SEPT. 15, 2025

Newly explicit in the policy text

Source manipulation that hides who’s behind it

Two practices are specifically described in the updated policy.

2025 · Not named2026 · Prohibited
Seeding search or AI answer sourcesWith content that misrepresents its origin, authorship, or independence.
Networks posing as independent sitesWhen they hide that content comes from a common source.

Editorial illustration · not an actual policy page or source list

Carried over

Still prohibited

Fake reviews
Fake personas used to misattribute content
Prohibited in both versions
High-risk use case list

Publishing no longer listed

Automatically generating content and publishing it for external consumption

2025 · Listed high-risk2026 · Not listed

This is a change to the high-risk list, not a blanket exemption from the policy.

Reading the comparison: “Not named” means the 2025 policy did not describe that practice specifically. It does not mean the practice was allowed.

“Not named” means the September 2025 text didn’t describe the practice. It doesn’t mean that version permitted it.

What Anthropic Found In September

Anthropic connects the new deceptive activity section to examples in its September threat intelligence report. For instance, it identified around 70 websites that appeared to be independent local news outlets, all linked to a France-based ad agency.

The operation involved using Claude to create articles in a consistent format, each containing three to four internal links, for automated publishing. The report mentioned that these articles were “specifically designed to boost their site’s authority rankings on search engines.”

The network published at least 8,913 articles across around 20 languages, though the company mentions that most received little engagement from actual audiences. The report doesn’t specify whether the sites improved their rankings or appeared in AI-generated answers. Anthropic has announced that it removed the Claude account and banned the organization associated with the activity.

Automated Publishing Leaves The High-Risk List

Anthropic’s previous usage policy listed “Media or professional journalistic content” as a high-risk use case, covering use of Anthropic’s products “to automatically generate content and publish it for external consumption.” The new version lists 11 high-risk areas where AI recommendations carry review and disclosure requirements, including legal, medical, and financial advice and decisions about credit, housing, and employment. Publishing isn’t among them.

For high-risk uses, the previous policy required a qualified professional to review advice, recommendations, or subjective decisions that directly impact people before they are shared. Additionally, when these outputs were delivered directly to individuals, it was necessary to inform them that AI contributed to producing the advice, decisions, or recommendations.

The company’s latest post says its requirements for high-risk recommendations haven’t changed. It also mentions that the section was rewritten to clearly specify which recommendations are included. However, the post doesn’t mention the publishing category or explain why it’s no longer listed.

The rule about not submitting “AI-assisted work without proper permission or attribution” is unchanged, and consumer chatbots still need to inform users they’re talking to AI. The new text doesn’t include a rule stopping users from presenting results as “human-generated,” but it continues to prohibit making people think they’re chatting with a human.

Why This Matters

Google’s spam policies describe “attempting to manipulate generative AI responses in Google Search” as spam. A May 15 documentation update clarified that the policies apply to generative AI responses in Search. I covered how that played out in June, when a spam update rolled out under that policy and a Cornell Tech paper showed why enforcing that at the source is difficult.

Google enforces its rules on websites, which can sometimes lead to those sites ranking lower or even disappearing from search results. Anthropic enforces its policies against Claude users, and it might limit or revoke access if needed.

Looking Ahead

Anthropic states it updates the usage policy annually and will continue to revise it as Claude’s capabilities and associated risks evolve.

By Nov. 12, verify if any content created with Claude, whether by you or an agency, is published across networks of sites presented as independent of each other. Additionally, by the same date, compare the review and disclosure procedures you’ve implemented for the old high-risk list with the new list.

Featured Image: Tetiana Yurchenko/Shutterstock. Claude wordmark: Anthropic.

Category News AI Search
SEJ STAFF Matt G. Southern Senior News Writer at Search Engine Journal

Follow on YouTube. Matt G. Southern is the Senior News Writer at Search Engine Journal, where he’s covered Google, SEO, ...