NSFW roleplay and the four rulebooks: what the policies actually say, checked July 2026
Whether an LLM will write adult roleplay is governed by three different layers people keep conflating: the app's filter, the provider's usage policy, and the model's trained refusals. We read the current policy documents from OpenAI, Anthropic, Google, and xAI — with dates — and map where each lab draws its lines, what enforcement looks like on an API account, and what BYOK does and does not change.

“Which LLM allows NSFW roleplay” gets asked daily, and the top answers are two-year-old Reddit threads citing policies that no longer exist. So we did the boring thing: on July 18, 2026, we read the current usage policy of each major lab, wrote down what the text actually says, and dated every claim. No workarounds in this piece, no “this one lets you do anything” — just the rulebooks, and the three-layer mechanism that decides what happens when you hit send.
Three layers, three different owners
When a spicy scene gets refused — or an account gets suspended — one of three separate systems did it, and they belong to different parties. The app layer: whatever platform sits between you and the model can filter, rewrite, or block. The policy layer: the usage policy attached to your provider account; it is a contract, enforced by detection systems and account consequences, whether or not the model refused anything. The model layer: the refusals trained into the weights, which can be stricter than the written policy and do not update on the same schedule.
Most confusion online comes from reading evidence about one layer as if it described another. A model writing something is not the policy permitting it. A filter knob is not a waiver. And an app with no filter is not an app with no rules upstream. Hold the layers apart and every provider below becomes legible.
One more distinction before the table, because it invalidates half the anecdotes you will read: consumer products and API accounts are different surfaces of the same lab. What ChatGPT will or will not write says little about what OpenAI’s usage policies permit on a developer account; what a Grok consumer mode allowed last month says nothing about what binds an xAI API key today. Product features ship and vanish. The policy documents below are the layer that suspends accounts, so they are what we read.
What the four rulebooks say, side by side
| Provider | Document, as checked 2026-07-18 | Explicit fiction between adults | Universal hard lines in the text |
|---|---|---|---|
| OpenAI | Usage Policies, effective 2025-10-29 | No blanket ban in the policy text; consumer “adult mode” shelved indefinitely (March 2026), model refusals still apply | Non-consensual intimate content, sexual violence, minors incl. “underaged sexual or violent roleplay”, circumventing safeguards |
| Anthropic | Usage Policy (AUP) | Categorically prohibited: “sexual intercourse or sex acts”, “sexual fetishes or fantasies”, “erotic chats” | Minors incl. fictional settings and roleplay (reported to authorities), sexual violence, bypassing guardrails |
| Generative AI Prohibited Use Policy, last modified 2024-12-17 | Prohibited when “created for the purpose of pornography or sexual gratification”; narrow exceptions clause | CSAE, non-consensual intimate imagery, circumventing safety filters | |
| xAI | Acceptable Use Policy, effective 2026-06-26 | No categorical ban on fictional adult text in the AUP — and no positive allowlist either | Sexualizing children, pornographic depictions of real persons’ likenesses, nudifying real people |
| Local models | None — no provider, no account | No policy layer exists; local law and the app’s own rules are what remain | — |
Dates matter more here than anywhere else we write. Between October 2025 and March 2026, OpenAI announced, delayed, and then shelved its verified-adults erotica plan — three different “current states” inside six months. Treat this table as a snapshot with a timestamp, not scripture.
OpenAI: the permissive text that never became a permissive product
The current usage policies (effective October 29, 2025) prohibit sexual violence, non-consensual intimate content, and everything involving minors — the list includes “underaged sexual or violent roleplay” by name. What the text conspicuously lacks is a blanket ban on adult consensual fiction. That gap was deliberate: in October 2025 Sam Altman announced erotica for age-verified adults under a “treat adult users like adults” principle. It never shipped. The Verge, citing the Financial Times, reported in March 2026 that the plan was shelved indefinitely after internal pushback. So the practical state, as of our check: a policy text that does not forbid adult fiction, sitting under models that still largely decline to write it. Layers, again — the policy layer thawed, the model layer did not.
Anthropic: the clearest written no
No ambiguity to interpret. Anthropic’s Usage Policy has a section titled “Do Not Generate Sexually Explicit Content”, and it enumerates: depicting or requesting sex acts, content related to sexual fetishes or fantasies, and — verbatim — “erotic chats”. The policy applies to “anyone who can submit inputs”, explicitly including access through resellers and passthrough setups, so reaching Claude through a middleman changes nothing. Two more clauses worth knowing: the child safety section covers fictional settings and roleplay in so many words, with detected cases reported to authorities; and enforcement is not just account-level — Anthropic states it may block or modify model outputs in-flight when inputs violate policy.
Google: a filter knob is not a permission slip
Google’s Generative AI Prohibited Use Policy (last modified December 17, 2024) bars sexually explicit content, defined by purpose: “content created for the purpose of pornography or sexual gratification”, with a closing clause allowing exceptions for educational, documentary, scientific, or artistic considerations. What trips people up is the Gemini API itself, which exposes adjustable safety settings — the sexually-explicit category can be dialed down by a developer. Read the fine print instead: the API terms say applications with less restrictive settings may be subject to Google’s review and approval, and the abuse-monitoring docs describe automated scanning with prompts and outputs retained for 55 days for enforcement. The knob controls the model layer. The policy layer stays where it is.
xAI: rules about real people, silence about fiction
The xAI Acceptable Use Policy (effective June 26, 2026) reads differently from the other three: its sexual-content prohibitions are anchored to real humans — undressing or nudifying real persons, “depicting likenesses of persons in a pornographic manner” — and to children, full stop. Fictional adult text is neither banned nor green-lit; the AUP publishes no positive allowlist, and it asks users to respect the service’s guardrails, whatever they are configured to be on a given product surface. We would put it this way: xAI has the least restrictive written text of the four, and treating a policy’s silence as a service guarantee is how people get surprised. Grok’s consumer-side modes have changed several times in 2026 alone; the document above is what actually binds an API account.
Local models: the question dissolves
Run a model on your own hardware and the policy layer simply does not exist — no usage policy, no account to suspend, no traffic leaving the device. What remains is local law and the rules of whatever app hosts the model. The trade is capability: local models that fit on consumer hardware sit well below the frontier models on the craft of long fiction. That trade-off, not policy, is why most roleplayers still end up at a provider’s API.
What enforcement actually looks like on an API account
Every lab describes roughly the same machinery: automated classifiers over API traffic, human review for flagged patterns, and an escalation ladder — warnings, throttling, suspension, termination. Anthropic names a Safeguards Team and reserves in-flight output blocking; Google pairs automated scanning with manual review of flagged projects; OpenAI states that breaking or circumventing rules “may mean you lose access to our systems” and offers an appeal path. One structural point deserves emphasis, because it answers the question people are usually really asking: bypassing safeguards is treated as a violation in its own right across the board — OpenAI lists “circumventing our safeguards”, Anthropic prohibits jailbreaking without authorization, Google bars “circumvention of abuse protections or safety filters”, and xAI makes respecting its guardrails a baseline condition of use. The workaround is not a gray area. It is the violation.
Where BYOK actually puts the boundary
Query three from the search box: does BYOK mean the app polices your chats? In Foreverse, no. Your key stays on your device, requests go straight to the provider, and we are not in that loop — that is the definition of BYOK, and it cuts both ways. Importing a card does not filter its text; we add no platform layer on top of your BYOK traffic; what your characters can say is decided by the provider behind your key, which is exactly why the app lets you choose from a directory of 62 providers and read each one’s terms yourself.
Two honest boundaries on our side of the deal. First, the app surface has its own content policy — sexual content involving minors is a hard line reported onward, and community sharing carries adult-content filtering in browsing. Second, none of this page is legal advice or a promise about enforcement odds; it is a dated reading of four documents that have already changed once this year. If a decision matters to you, open the policy itself — the four links above go to the primary sources, not to summaries of summaries. That habit, more than any provider choice, is what keeps an account safe.
FAQ
Which LLM providers actually allow NSFW roleplay?
As of July 18, 2026, the written policies diverge sharply: Anthropic categorically prohibits sexually explicit content including erotic chats; Google's Prohibited Use Policy bars content created for pornography or sexual gratification, with narrow exception categories; OpenAI's current usage policies ban non-consensual and minor-involving content but carry no blanket ban on adult fiction — while its consumer 'adult mode' remains shelved; xAI's policy centers on real people and minors rather than fiction. Every lab bans sexual content involving minors, real-person sexual depictions, and non-consensual material, no exceptions.
Will OpenAI ban my API key for adult content?
OpenAI's usage policies state that breaking or circumventing its rules and safeguards 'may mean you lose access to our systems', with an appeal path. The hard lines in the current text are non-consensual sexual content, anything involving minors (including 'underaged sexual or violent roleplay'), and circumventing safeguards — that last one matters, because jailbreak-style workarounds are themselves a violation at every major lab. We can describe the mechanism; nobody outside the lab can promise you odds.
Does BYOK mean the app polices my chats?
No. With BYOK, requests go from your device straight to the provider you chose — Foreverse is not in that loop, adds no filter on top of it, and importing a card does not filter its text. What governs the output is the provider's policy and the model's own refusals. The app's content policy applies to the app surface itself, such as community sharing, where hard lines like content sexualizing minors are enforced.
Gemini lets me turn the sexually-explicit safety filter off. Doesn't that mean it's allowed?
No — that is the most common misreading of the whole topic. The Gemini API exposes an adjustable safety-filter knob, but Google's Prohibited Use Policy still applies to everything you generate, the API terms say less-restrictive configurations may be subject to Google's review, and abuse monitoring retains prompts and outputs for 55 days for enforcement. A filter setting is a developer control, not a policy waiver.
Questions or ideas? Join our Discord →