Work with us
AI tools / General-purpose AI assistants / Claude.ai

How to govern Claude.ai

Anthropic's assistant for drafting, analysis and long documents, and what to watch as its capabilities grow.

Anthropic · Reviewed monthly, and when Anthropic announces a capability change · Last reviewed 3 Sep 2026

No governance change Reviewed the recent release notes against Claude.ai's use patterns. No change to what it can do without approval, the data it is expected to touch, or who reviews its output. Full changelog ↓

How Claude.ai is used

We see six common ways businesses use Claude.ai, and we govern each one on its own terms. If your team uses it differently, that is fine: you describe the use in your own words and Certrak works out the governance from what it actually does.

General productivity assistance

Consequence to people: Low

Drafting, summarising, brainstorming, internal Q&A - day-to-day help with internal work

Internal informationEvery output reviewedInternal use only
  • Review rhythm: Annual review
  • Governance is mostly about: Safe everyday use; Checking what it produces; What it may be given

Document analysis and review

Consequence to people: Low

Reviewing contracts, reports, or technical documents

Internal informationEvery output reviewedInternal use only
  • Review rhythm: Annual review
  • Governance is mostly about: Safe everyday use; Checking what it produces; What it may be given

Marketing content creation

Consequence to people: Low

Drafting marketing copy, social posts, ads, blog content

Internal informationEvery output reviewedCustomers, no decisions about them
  • Review rhythm: Twice-yearly review
  • Governance is mostly about: Safe everyday use; Checking what it produces; A person stays accountable

Customer communications drafting

Consequence to people: Medium

Drafting customer emails, support replies, or other outbound communications - reviewed before sending

Personal informationEvery output reviewedCustomers, no decisions about them
  • Review rhythm: Quarterly review
  • Governance is mostly about: Safe everyday use; Checking what it produces; What it may be given

Code generation and review

Consequence to people: Low

Writing or reviewing code, with a developer in the loop

Internal informationEvery output reviewedInternal use only
  • Review rhythm: Annual review
  • Governance is mostly about: Safe everyday use; What it may be given; Checking what it produces

Internal data analysis and insights

Consequence to people: Low

Analysing business data, surfacing insights, building dashboards

Internal informationEvery output reviewedInternal use only
  • Review rhythm: Annual review
  • Governance is mostly about: Safe everyday use; Checking what it produces; What it may be given

Governing Claude.ai in practice

  1. Name one person who owns Claude.ai in your business. Governance starts with a name.
  2. Write down what Claude.ai is used for. Certrak recognises 6 common uses: General productivity assistance, Document analysis and review, Marketing content creation, Customer communications drafting, Code generation and review and Internal data analysis and insights. Yours may differ; write down yours.
  3. Decide what Claude.ai may and may not be given. Personal information is in scope for some uses; write the boundary down before it is needed.
  4. Agree that a person reviews every output before it is used, and name who.
  5. Look at this again every quarter, and sooner on any of these: industry incidents, vendor model updates and data classification changes.

What changed, and how Certrak responded

We record every check here, including the ones that changed nothing. A check that found no governance change proves we looked.

  1. No governance change Scheduled review

    Claude release notes

    Anthropic shipped it 28 Aug 2026.

    Reviewed the recent release notes against Claude.ai's use patterns. No change to what it can do without approval, the data it is expected to touch, or who reviews its output.

    Vendor release note →