You are working with an AI system, and it runs code by itself. The Agent reads your prompts, chat history, notebook contents and connected data, generates code, and then executes that code in a cloud Sandbox without asking you to approve each action.
You authorise the Agent to act for you
When you use the Agent, you authorise it to create, edit and delete cells and files, install software, run terminal commands, make network requests from the Sandbox, and use your Connected Accounts within the permissions you granted. Actions the Agent takes at your direction are treated as your actions under these Terms, including under the Acceptable Use section. You are responsible for what you ask it to do and for what it does in your project as a result.
Controls you have
You can stop a run in progress, steer it while it is running, and use plan mode, which has the Agent propose a plan for you to review before it creates, edits, deletes or runs notebook cells. Plan mode does not stop the Agent from reading your project or from searching and fetching material while it plans. Outside plan mode, the Agent does not ask you to approve most of what it does. A few actions do pause for approval, including sending a project file to our document parsing provider, and any tool on a connected MCP server, which requires your approval per tool before the Agent may call it. We describe these controls as they are: they let you interrupt and direct the Agent, and they do not guarantee that it will never take an action you did not want.
Output can be wrong
Output is generated by statistical models. It can be inaccurate, incomplete, out of date, biased, or entirely fabricated, including citations, statistics, dataset descriptions, API signatures and code that looks correct and is not. Treat Output as a draft to verify, not as a source of truth. You are responsible for reviewing and testing anything you rely on or ship.
Not professional advice, and not for high risk use
The Services are general purpose research tooling. They do not provide medical, clinical, diagnostic, legal, financial, or safety engineering advice. Do not use them as a medical device or for clinical decision making, and do not use them in circumstances where an error could lead to death, personal injury, or severe environmental or property damage. We have not designed, validated or documented the Services for those uses. If you deploy the Services into a regulated or safety critical setting, you do so as the party responsible for that system.
Prompt injection
The Agent reads content from your files, datasets, connected systems, MCP servers and the public internet. That content can contain instructions designed to manipulate the Agent into acting against your interests, for example exfiltrating data or running unwanted commands. We design against this and we cannot prevent it. Do not give the Agent access to credentials, repositories or systems whose misuse you could not tolerate.
Destructive and costly actions
The Agent can overwrite and delete files, environments and repository contents, and some of that is irreversible. Keep your own backups of anything you cannot lose. The Agent can also start work that costs money, including GPU compute, metered model usage, and charges on your own Connected Accounts and BYOK provider accounts. Those charges are yours. Pay as you go is off by default and capped, as described in section 6, and you can stop a run at any time. Note that stopping a run does not shut down your Sandbox: Sandbox compute is metered on the Sandbox’s running time and continues until it is paused or reclaimed, so close a GPU Sandbox you are finished with rather than only stopping the run.
Marking
The Agent identifies itself as an AI system in chat, and its messages are shown as the Agent’s rather than yours. We record whether a notebook cell was written by you or by the Agent. Where we display or export an indication that content was AI generated, do not remove, alter or falsify it, and do not present Output as human authored where that would mislead someone.