Anthropic

Claude May Ask for Your ID: Anthropic's Verification Push

Anthropic's privacy policy update, effective July 8, allows ID scans and face-geometry templates for flagged Claude users via Persona — a biometric retention concern.

Claude May Ask for Your ID: Anthropic's Verification Push — article cover
On this page6 SECTIONS
  1. What the Policy Actually Says
  2. Face Templates: How Long Kept, Who Can Demand Them
  3. Persona: The Verifier in the Middle
  4. Age Assurance and Political Pressure
  5. What It Means for Users
  6. Sources

On June 22, 2026, TechCrunch security editor Zack Whittaker reported that Anthropic has quietly updated its privacy policy: “in certain circumstances,” the company may require Claude users to upload a government-issued document to prove their age or identity. The new language was published on June 17 and takes effect July 8. When triggered, a user must upload a scanned passport or driver’s license, plus a selfie photo or video — and those images are converted into a digitized face geometry template. An AI company with tens of millions of monthly users has formally brought banking-grade identity verification into a consumer chatbot.

What the Policy Actually Says

The stated purposes are broad: account administration, enforcing the terms of service, preventing fraud, abuse, and unlawful conduct, and investigating security issues. Anthropic spokesperson Michael Aciman pointed to a post by company lead Thariq Shihipar, stressing that the policy “was updated on June 17 as an update to the appeals process” and that it is “unrelated to the Fable or Mythos rollout.” Those actually affected are a “small subset of users” whose accounts have been flagged short of a ban — accounts that in the past would typically be suspended outright now have a path: verify your identity and keep access. But Anthropic declined to say how many users that subset includes, and gave no concrete examples of what the “certain circumstances” are, saying only that users may “see a verification prompt when accessing certain capabilities” as part of routine platform integrity checks. Vague trigger conditions are precisely what makes privacy advocates uneasy.

Face Templates: How Long Kept, Who Can Demand Them

The real dispute is about data flows. Driver’s license and passport scans, selfies, and face geometry templates are all biometric data — and in some jurisdictions, like Illinois, face geometry information enjoys specific legal protection. Anthropic keeps a record of the verification result, such as whether the user met an age threshold. The verification itself is performed by San Francisco-based Persona, and the retention period for data on Persona’s side is decided by Anthropic — which would not say when the data gets deleted. The contrast is Roblox, another Persona customer, which promised in its age-check announcement that user images are deleted “immediately” after processing. The other unavoidable reality: data held by Persona remains subject to U.S. government demands for stored user information. An undefined retention period, a third-party holder, and government access — stacked together, that is the textbook risk profile for biometric data.

Persona: The Verifier in the Middle

Persona, the company doing the checks, is a startup backed by Founders Fund — and Peter Thiel also invests in Anthropic, a relationship that has already drawn criticism. Market precedent has been rocky too: Discord announced in February that it would use Persona to age-verify its global user base, then delayed the worldwide rollout within weeks amid strong user backlash. Identity verification is becoming an industry norm for consumer platforms, but nearly every deployment lands with a privacy fight attached — the difference is how transparent the vendor is about retention.

Age Assurance and Political Pressure

Claude requires users to be 18 or older, and earlier this year Anthropic introduced age-assurance checks to comply with mandates from several states and countries — the most plausible regulatory backdrop for this update. But the timing invites political readings: on June 13, the White House forced Anthropic to pull its latest cybersecurity models over alleged jailbreak concerns, and in early March the Pentagon labeled Anthropic a “supply chain risk.” Against that backdrop, any policy change that expands the collection of users’ biometric data gets examined under a microscope, no matter how often the company insists it is just part of an appeals process.

What It Means for Users

Three practical effects. First, users with flagged accounts now face a binary — verify or lose the account — and it is worth understanding where the data goes and how long it is kept before uploading an ID. Second, for enterprise buyers this is a wake-up call: consumer-grade AI services are rapidly converging on finance-grade identity verification, and vendor evaluations should now include biometric retention policies, third-party processors, and data jurisdiction. Third, biometric statutes like Illinois’s and age-assurance laws around the world will keep drawing the legal boundaries of these mechanisms. Identity verification has stopped being a product feature and become a contracting, legal, and compliance question.

Sources

AI-assisted summary compiled from the sources above, reviewed by a human before publishing.

FOUND_THIS_USEFUL?

Support more practical AI articles, tutorials, and build notes.

BUY_ME_A_COFFEE
SHAREXEMAIL