⚡ Quick Summary
Published under an AAAI copyright notice and circulated as arXiv preprint 2409.09041v1, this paper identifies the acceptable use policies (AUPs) of 30 foundation model developers and analyses the use restrictions they contain. It defines an AUP as a legally binding developer policy, embedded in terms of service or a model licence, that prohibits specified content and domains of use, and it treats AUPs as a lens on how foundation models are regulated. The paper compiles the policies, codes them inductively, and publishes a 30×127 matrix of developers and prohibited use categories. Mis/disinformation and harassment/abuse appear in 26 policies each; privacy, discrimination and child harm/child sexual abuse material in 21 each; political content in 9, medical advice in 8, weapons and surveillance in 7. Developers alone decide what is acceptable and rarely disclose how they enforce their policies. The paper concludes that AUPs are an early form of self-regulation that shapes which firms and industries can use foundation models and fragments the AI supply chain.
🧩 What’s Covered
The paper moves from definitions and legal context, through methodology and findings, to enforcement problems and discussion.
- Background and definitions: Defines an AUP for foundation models and distinguishes it from model cards, model behaviour policies and third-party contracts.
- Norms and law: The EU AI Act's Annexes IXa and IXb, China's July 2023 Interim Measures and February 2024 Basic Safety Requirements (31 safety risks), and the US Voluntary AI Commitments.
- Methodology: A four-step search protocol and inductive qualitative content analysis producing 127 prohibited use categories and a 30×127 matrix published on GitHub.
- The 30 policies: Table 1 records policy title and section, model specificity, document type, flagship model and output modality, headquarters and weight openness; 12 of the 30 release flagship model weights.
- Prohibited content: Figure 1 rankings and per-developer counts, from Anthropic's 69 prohibitions to TII's 6, with averages of 20 for closed and 24.5 for open developers; examples include Chinese developers' national security clauses and Eleven Labs' ban on password trafficking.
- End-use restrictions: Six developers ban model scraping, 16 ban building a competing service, five restrict automated posting, and others bar weapons manufacture, surveillance and legal, financial or medical advice.
- Correlations and non-adopters: Figure 2's matching-coefficient comparison of policies, the example of Amazon Web Services reconciling providers whose correlation falls below 0.6, and Table 2's seven developers without AUPs.
- Enforcement and discussion: Barriers for open developers, deployer challenges, jailbreaks and fine-tuning away safety measures, liability shifting to users, researcher access, beneficial-use case studies, transparency gaps and areas for future work.
💡 Why it matters?
AUPs are the binding layer that determines which uses of a foundation model are permitted, and they bind where non-enforceable model cards do not. The analysis shows how fragmented those rules are: a cloud provider distributing several developers' models faces policies correlating below 0.6, and users of several models must internalise different restriction sets. The paper maps silences — political content, medical advice, weapons — and shows how strict policies can block beneficial uses such as robotics research or drug harm reduction. It also connects AUPs to disclosure duties under the EU AI Act's Annexes IXa and IXb and to Chinese and US instruments.
❓ What’s Missing
The paper states that enforcement is largely opaque and does not measure whether AUPs change user behaviour; it reports that only 8 of 14 developers disclose appeals processes and 7 disclose justification for enforcement, and that Google disclosed no enforcement actions under its Generative AI Prohibited Use Policy. Coding covers 30 developers drawn from one developer list and reflects policies as of 18 April 2024, so later changes such as Meta's July 2024 Llama 3.1 licence update fall outside the sample. Costs to deployers, quantified market effects and evidence that AUPs reduce harm are absent; the paper identifies enforcement data collection as an area for future work.
👥 Best For
Compliance and policy teams mapping what foundation model providers permit and prohibit; legal and procurement staff reading licences and terms of service before adopting a model; cloud and platform deployers who must reconcile several developers' AUPs; and researchers or analysts studying self-regulation, content governance and the foundation model supply chain.
📄 Source Details
Acceptable Use Policies for Foundation Models by Kevin Klyman (Stanford University, Center for Research on Foundation Models; Harvard University, Belfer Center for Science and International Affairs). The page 1 notice reads "Copyright © 2024, Association for the Advancement of Artificial Intelligence (www.aaai.org). All rights reserved."; the document is stamped arXiv:2409.09041v1 [cs.CY], 29 August 2024, and Table 1 is marked "Last updated April 18, 2024". 22 pages in English, with references numbered to [184]. No URL for the document itself is printed.