← SurfacedDrop no. 49Tech news drama5min read

Anthropic Will Require a Government ID and a Live Face Scan to Use Claude

The story behind the drop.

Anthropic will require Claude users to submit a government ID and a live face scan starting July 8, 2026, with Persona Identities running the checks.

Published

UTC

Reading time

5 min

~210 wpm

Word count

1,117

plain English

Category

Tech news drama

tech-news-drama

// video pending

Anthropic Will Require a Government ID and a Live Face Scan to Use Claude

Starting July 8, 2026, signing in to Claude will require a government-issued photo ID and a live scan of the user's face.

The policy and the timeline

Anthropic has told users of Claude that beginning July 8, 2026, the Free, Pro, and Max tiers will all require identity verification before the chatbot continues to work as expected. The checks did not appear without warning, but they did appear without much fanfare. Anthropic quietly switched on the same verification flow around April 14, 2026, for what the company described as "a few use cases" before publishing the broader policy that takes effect this summer.

The mechanics are unremarkable in isolation. A user uploads an image of a government-issued document; accepted forms include a passport, a driver's license or state or provincial ID card, and a national identity card. The user then takes a live selfie photo or short video on a phone or webcam so the face can be matched to the face on the document. Anthropic says the process typically takes under five minutes. The company also reserves the right to block or ban accounts for repeated usage-policy violations, signing up from an unsupported location, breaking the Terms of Service, or being under 18.

Anthropic frames the change as routine platform-integrity work. "Identity verification helps us prevent abuse, enforce our usage policies, and comply with legal obligations," the company writes in its Claude support documentation. That sentence carries most of the company's stated rationale.

Who runs the verification

The work is not Anthropic's to do. The checks are handed to a third-party vendor, Persona Identities, a San Francisco identity-verification company founded in 2018 by Rick Song, a former Square engineer, and Charles Yeh, a former Dropbox engineer. Persona's core business is "Know Your Customer" verification, the same kind of document-and-face matching that banks, marketplaces, and online platforms use to catch fraud and meet age-gating rules. Discord and LinkedIn have used Persona for similar checks.

Persona has been on a steep funding climb. The company raised a $200 million Series D in May 2025 at a $2 billion valuation, and its total funding to date stands at $418 million. Its backers include Founders Fund, the venture firm co-founded by Peter Thiel, who is also an investor in Anthropic itself. The two companies are not corporate siblings, but they share a common investor at the cap-table level.

That overlap matters less than the substance of what Persona will hold. Anthropic, in its public documentation, sets out the data-handling rules. "Persona is contractually limited in how they can use your data: only to provide and support verification and to improve their ability to prevent fraud," the company writes. Anthropic also says the verification data is not used to train its AI models, and that it is not shared with third parties except in response to valid legal processes.

What the verification collects and where it lives

The data that moves through this process is sensitive by design. Among the items Persona collects are "facial geometry templates," a mathematical map of a face used to compare a live selfie to a document photo. Anthropic itself concedes in its Claude privacy policy that these templates "may be considered biometric data in some jurisdictions." That phrasing is a quiet acknowledgement that the same kind of data sits inside specific statutes in several places around the world.

The ID images and selfie material live on Persona's servers, not on Anthropic's own systems. Anthropic describes itself as the "data controller" for the verification, meaning it sets the rules for how the data is handled even though Persona physically holds it. "All data passing through and to Persona is encrypted in transit and at rest," the company writes in its support documentation, in the same paragraph that confirms the storage arrangement.

The split is meaningful. Anthropic's privacy posture, its breach-disclosure obligations, and its retention rules now extend through a contract to a separate company whose security record will become part of the Claude story whether or not Anthropic's own systems are ever touched.

The February exposure and the wider context

Persona's selection drew renewed scrutiny after a February 2026 security incident. Researchers found part of Persona's government-dashboard codebase sitting on a publicly accessible, FedRAMP-authorized endpoint. A batch of 2,456 files, totaling 53 megabytes, was reachable in a browser without any hacking or exploit required. The incident exposed code, not the IDs or selfies of end users, but it surfaced in coverage of the Anthropic announcement because it concerns the same vendor that will now sit between Claude and its users.

The broader backdrop is a 2026 shift in how online services treat the question of who is on the other side of the screen. Roughly half of U.S. states now mandate some form of online age gating before users can reach certain content or features. The White House's National Policy Framework on Artificial Intelligence treats "age assurance" as a baseline control, expecting AI platforms to determine a user's age band and apply age-appropriate safeguards. Age-verification or ID-check requirements for online services are already live or arriving in the United Kingdom, Australia, and Brazil. Colorado lawmakers have weighed shifting age verification down to the operating-system level, with enforcement potentially beginning as early as late 2026.

Privacy researchers warn that the policy direction has a cost. Collecting and transmitting ID data expands a company's attack surface, because ID images and face scans are high-value targets for identity theft, fraud, and extortion. A document scan that satisfies a one-time check is also a document scan that can sit in a database for years.

The trade at the center

The bargain that defined the chatbot era for most of its short history was small: an email, sometimes a phone number, then a conversation. Anthropic's July 8 change rewrites that bargain in concrete terms. A passport or driver's license, a selfie, and a few minutes are now the price of entry to Claude on the Free, Pro, and Max tiers. The friction is modest by design. The data is not.

What changes in practice is what a chatbot company knows about the person on the other side of the screen, and where that knowledge sits. Anthropic has the rules; Persona has the files. The question, for users and for the rest of the industry watching how this lands, is not whether the verification works as advertised. It is what the new shape of the AI account, with a face and a document attached to it, will mean once it becomes ordinary.

Sources

// Sources · primary references

02 refs