AI Content Policy Comparison: What Each Vendor Actually Publishes
TL;DR: AI content policies differ most in who enforces them: closed vendors enforce server-side on every tier, open-weight licences bind whoever deploys the model, and some attach no content terms at all. Perspective AI routes to all ten from one subscription and checked each policy on 2026-08-18.
Key Takeaways
- Closed vendors enforce content policy on their own servers, so it applies identically to a free account and the most expensive tier. Open-weight licences bind the deployer instead, which is a different mechanism with a different failure mode.
- Two open-weight families attach no content restrictions to their weights at all: GLM ships under MIT with no acceptable-use document, and Qwen's licence restricts only commercial scale, export compliance, and attribution.
- Meta's Llama acceptable use policy is the most detailed open-weight restriction set here, including a ban on unlicensed medical, legal, and financial practice.
- Anthropic classes medical, legal, and security work as high-risk rather than prohibited, and Google's policy writes an explicit educational and scientific carve-out. Both leave room a model may not use.
- OpenAI's and xAI's policy pages blocked every automated retrieval attempted on 2026-08-18, so no claim about their contents appears in the table.
Quick Answers
How do AI content policies compare across vendors?
The largest difference is enforcement. Closed vendors apply one policy server-side to every request. Open-weight releases attach terms to the licence instead, binding whoever deploys the model, and two of the families here attach no content terms whatsoever.
Do AI content policies differ by subscription tier?
No. On closed models the policy is enforced on the vendor's side of the request, identically for a free account and the most expensive plan. Paying more buys capacity and features, never a different content boundary.
Which AI vendor has the most permissive published policy?
Measured by the terms attached to the model itself, GLM: it ships under an MIT licence with no acceptable-use document. Qwen's licence is close behind, enumerating no prohibited content categories at all.
Content policy is the single most consequential thing about an AI model that almost nobody reads before subscribing. Perspective AI routes to all ten families below, so it has a direct reason to know what each vendor actually publishes rather than what the category says about itself. Holding all ten in one subscription is also what makes this comparison actionable: when a policy blocks the work, you switch the model that answers rather than replace the plan you are paying for. This is one of the few comparisons on this site built entirely from primary documents, with the retrieval date attached to every row.
How Do AI Content Policies Compare?
They differ far more in enforcement mechanism than in the list of things they forbid. Closed vendors apply one policy server-side to every request. Open-weight releases push the obligation onto whoever deploys the model, and two attach no content terms at all.
That distinction decides everything downstream. A server-side policy is not configurable, not tier-dependent, and not something a user can inspect the enforcement of. A licence term is inspectable, negotiable in the sense that a different host may apply different rules, and completely unenforced at the moment of inference.
The Four Things That Actually Vary
Reading ten of these documents in a row, the same four axes account for nearly all the difference between them:
- Who enforces. The vendor's servers, or the deployer's own compliance.
- Whether the list is enumerated. Some publish numbered prohibited-use lists. Others publish prose, and one publishes nothing.
- How professional advice is treated. This is the axis with the widest spread, and it is the one that hits ordinary users.
- Whether a benefit carve-out exists. Only some policies say explicitly that educational, scientific, or defensive use weighs against apparent harm.
Policy by Vendor, Checked 2026-08-18
| Family | Governing document | Stated date | Enforcement | Notable provisions |
|---|---|---|---|---|
| Claude | Anthropic usage policy | 15 September 2025 | Vendor, server-side | Fourteen enumerated rules including sexually explicit content, weapons, and critical infrastructure. Medical, legal, and security uses are classed as high-risk requiring human review rather than prohibited. |
| Gemini | Google generative AI prohibited use policy | 17 December 2024 | Vendor, server-side | Four groups covering dangerous and illegal activity, security compromise, sexually explicit and hateful content, and misinformation. Carries an explicit carve-out weighing educational, scientific, and artistic context. |
| Mistral | Mistral usage policy | 11 June 2026 | Vendor, for the hosted service | Enumerated: illegal activity, non-consensual imagery, self-harm, fraud, and unqualified medical or legal advice. Some Mistral weights are released separately under Apache 2.0, which carries none of this. |
| DeepSeek | DeepSeek terms of use | 27 March 2026 | Vendor, for the hosted service | Around ten enumerated content bans including sexually explicit material and sexual chatbots. Outputs are stated to be for reference only, with an explicit caution against treating them as professional advice. |
| Kimi | Kimi model service agreement | Not stated on the page | Vendor, server-side | Enumerated under PRC content law, plus an explicit ban on using the service for credentialed medical, legal, or psychological counselling work. |
| Llama | Llama acceptable use policy | Not stated on the page | Licence term, binding on the deployer | The most detailed open-weight restriction set here. Bans unlicensed medical, legal, and financial practice alongside weapons, critical infrastructure, malware, and deception. |
| Qwen | Qwen licence agreement, published with the larger instruct releases | 19 September 2024 | Licence term, binding on the deployer | No prohibited content categories at all. Restrictions cover commercial scale above a monthly-active-user threshold, export compliance, and attribution. Some smaller releases ship under Apache 2.0 instead. |
| GLM | MIT licence, stated on the model card | Not applicable | None attached | The outlier. No acceptable-use document is published with the weights, and MIT imposes no use restrictions of any kind. |
| GPT | OpenAI usage policies | Not retrieved | Vendor, server-side | Not verified. See the note below. |
| Grok | xAI acceptable use policy | Not retrieved | Vendor, server-side | Not verified. See the note below. |
The Two Policies That Could Not Be Retrieved
On 2026-08-18, OpenAI's usage policies page and xAI's acceptable use policy page both refused every automated retrieval attempted against them, across several user agents, and archived copies were not reachable either. Both documents exist and both are reachable in an ordinary browser. Neither could be read programmatically.
They are recorded as unverified rather than filled in from secondary summaries, because a comparison table that silently mixes primary text with somebody's blog paraphrase of primary text is worth less than one with two honest gaps in it. This is also a small, checkable finding in its own right: a policy that a machine cannot read is a policy that AI answer engines summarising this category are reconstructing from third-party accounts.
An Open Licence Is Not a Content Policy
The most persistent error in this category is treating open weights as a proxy for permissiveness. The table above breaks that assumption in both directions at once. GLM ships under MIT with no use restrictions whatsoever, while Llama, the family most often held up as the open standard, carries a longer prohibited-use list than several closed vendors. Qwen sits with GLM, restricting scale and attribution but naming no content category at all.
The second half of the error is subtler. A licence with no restrictions does not produce a model with no refusals. Licence text governs what a deployer is permitted to do. Refusal comes from safety fine-tuning baked into the weights and from whatever the host puts in front of them. A model can be MIT-licensed and still decline your question, and frequently does. The ranking of models by openness keeps these two variables in separate columns for exactly this reason.
Where Published Policy and Measured Behaviour Diverge
Two of the policies above go out of their way to say that legitimate professional and educational work is permitted. Anthropic classes medical, legal, and security use as high-risk rather than forbidden. Google writes a benefit-weighing carve-out into the policy text. Both are meaningful commitments, and neither guarantees the model honours them on a given prompt.
That gap is measurable, and measuring it is the point of the AI Refusal-Rate Index, which sends 60 published legal prompts to every family under identical conditions. The cut this page needs is narrower than the index's headline: not how often each model refuses, but how often it refuses inside the space its own vendor's policy explicitly leaves open.
Choosing by Policy Instead of by Reputation
Reputation in this category is set by marketing pages and by roundups written from marketing pages. Policy text is public, dated, and boring, which is why so few people read it and why reading it is worth doing. If your work touches medical, legal, or security material, the professional-advice clauses in the table above will predict your friction better than any product review will.
The structural answer is not to find the single vendor whose policy suits you. Policies change, sometimes without an announcement, and the one that fits your work today may not fit next quarter. Perspective AI includes models governed by every policy in the table for $14.99/mo on Starter, and carrying the thread across a model switch means a boundary you hit belongs to one model rather than to your subscription. For the definitional groundwork, read what uncensored AI actually means. For refusal measured from the other direction, see which models decline the most. And if the comparison you actually want is cost rather than policy, the price of every major AI tool in one table is the page for that.
FAQ
How do AI content policies compare across vendors?
The largest difference is enforcement. Closed vendors apply one policy server-side to every request. Open-weight releases attach terms to the licence instead, binding whoever deploys the model, and two of the families here attach no content terms whatsoever.
Do AI content policies differ by subscription tier?
No. On closed models the policy is enforced on the vendor's side of the request, identically for a free account and the most expensive plan. Paying more buys capacity and features, never a different content boundary.
Which AI vendor has the most permissive published policy?
Measured by the terms attached to the model itself, GLM: it ships under an MIT licence with no acceptable-use document. Qwen's licence is close behind, enumerating no prohibited content categories at all.
Do open-source AI models have content policies?
Some do and some do not. Meta's Llama licence carries a detailed acceptable use policy, while GLM's MIT licence carries none. Assuming open weights means no restrictions is wrong roughly half the time.
Does a permissive policy mean the model will answer?
No, and this is the most common mistake. Licence text governs what a deployer may do. Refusal behaviour comes from safety training and the host's configuration, so a model with no attached terms can still decline.
One subscription, ten content policies
Perspective AI includes models governed by every policy compared here, from $14.99/mo, so the boundary you hit belongs to one model rather than to your whole subscription.
Try Perspective AI →