Anthropic updated its privacy policy on June 8, and the change takes effect July 8. It introduces a new category of data called "Verification Data" and says the company may, under certain circumstances, ask users to prove who they are. That means scanning a physical government ID, taking a selfie, and submitting what the policy calls a "facial geometry template," which is a numerical map of your face. In some countries and several U.S. states, that last item legally counts as biometric data.
The policy applies to Claude Free, Pro, and Max plans. Business customers on Team, Enterprise, or API plans are not in scope. Anthropic's official position is that checks will hit only a small subset of users whose accounts have been flagged for possible policy violations but not outright banned. It is framed as a path to appeal, not a routine gate.
The problem is the language in the policy itself is broader than that framing. It states checks may occur as part of "routine platform integrity checks," which is a wider net than just flagged accounts. The triggers are unpublished. The data retention period has not been disclosed. And if you refuse, the consequences are not explained.
The verification is handled by a company called Persona, not by Anthropic directly. Anthropic does not store the raw ID images on its own servers, but it can access the verification records held by Persona whenever it needs to. Persona is backed by Founders Fund, the investment firm co-founded by Peter Thiel, who also holds a stake in Anthropic through that same fund. Discord tried using Persona for age checks and reversed course after users pushed back over that investor connection and after a security incident showed roughly 2,500 Persona files exposed on a government-accessible server.
The deeper reason this is happening has little to do with fraud prevention. In June, the U.S. government issued an export control order forcing Anthropic to take its two most capable models offline entirely, because it had no way to verify whether users were in restricted countries. The entire platform went dark for those models globally, not just in sanctioned regions. That exposed a gap every major AI company has: their access systems were built for convenience, not for identity filtering at scale. Identity checks are how Anthropic starts closing that gap.
This is also where things get relevant for anyone using AI tools for business tasks. Claude has been moving beyond simple chat toward what the industry calls "agentic" use: AI that books appointments, drafts and sends emails, manages documents, and executes multi-step tasks on your behalf. When software acts in the real world under your name, knowing who authorized those actions stops being optional. Identity checks on that kind of tool carry more weight than identity checks on a search engine.
For now, most Claude users will never see a verification prompt. But the infrastructure is being put in place, the policy language is written broadly, and the pressure from governments to know who is using AI is only increasing. Other AI providers will follow, whether they want to or not. OpenAI introduced mandatory identity checks for some API access in late 2025. ChatGPT and Gemini do not yet require it for standard consumer accounts, but that distinction may not hold for long.
If you use Claude personally and not through a business account, there is no action needed today. If you are ever prompted, only physical original documents are accepted. Know that the data sits with Persona, not Anthropic, and that Anthropic has not published how long it is kept.