01 / AUTONOMY
AI policies are changing because agents are doing longer, more independent work.
Anthropic's October 8 Usage Policy update says Claude now takes on longer and more independent tasks, and adds clearer examples for how existing rules apply to those capabilities. The practical signal for small businesses is broader than one provider: a tool that drafts a paragraph creates a different level of exposure than an agent that works across systems, makes recommendations, or carries a task through several steps. The control should match what the workflow can affect.
02 / CONSEQUENCE
High-impact decisions need stronger review than ordinary administrative work.
The updated policy requires qualified human review when AI use can affect health, legal rights, finances, livelihood, or access to essential services, and requires disclosure to the affected person. It also adds requirements for AI connected to equipment that can take autonomous physical action. Even when a small business is outside those exact examples, the operating principle is useful: the greater the consequence and reversibility of a decision, the more explicit the authority, review, and stop conditions should be.
03 / ACCESS
Capability can be granted in levels instead of being simply on or off.
Anthropic's October 6 expansion of its Cyber Verification Program uses three access tiers based on the work being performed, the applicant's qualifications, and the controls in place. That structure offers a practical model for ordinary operations. An employee or agent can start with read-only research, progress to preparing a change for approval, and receive direct action authority only after the workflow proves reliable. Tiered authority creates room to gain value without treating every task as equally safe.
THE CJC VIEW
Implementation beats experimentation.
Small businesses do not need one blanket AI policy for every task. They need a short classification that helps people recognize when a convenient automation has crossed into consequential work.
The most useful dividing lines are simple: what can the agent see, what can it change, who could be affected, and how difficult is the action to reverse? Those answers should determine the approval step—not the novelty of the tool or the confidence of its output.
PRACTICAL NEXT STEP
Classify one AI workflow into three operating tiers
- Choose one AI-assisted workflow that the business expects to use more often during the next month.
- Define Tier 1 as read-only or drafting work that cannot change a system, contact a customer, commit money, or affect a person's rights or livelihood.
- Define Tier 2 as preparation work that may update a draft or proposed record but requires a named person to review and approve the final action.
- Define Tier 3 as direct action in a business system, and list the evidence, access limit, exception handling, and rollback method required before granting that authority.
- Run five examples at the lowest useful tier, record mistakes and interventions, and expand authority only when the results meet a written quality standard.
More capable agents do not require a choice between full automation and no automation. Tiered authority gives a small business a disciplined middle path: start with visibility, add approval, and grant action only when the process has earned it.
Sources and further reading
- 2026 Usage Policy update — Anthropic
- Expanding the Cyber Verification Program — Anthropic
- Advancing computer use with Ironclad — OpenAI