Anthropic's Claude Now Requires Government ID and a Selfie — Users Are Furious
Anthropic quietly rolled out identity verification for Claude subscriptions, asking for passports and live selfies via third-party vendor Persona. ChatGPT and Gemini require neither. Here's why this decision is a mess, who's actually affected, and what Persona's track record means for your data.
On April 14th, 2026, Anthropic updated a help center page. No blog post. No announcement email. No press release. Just a quietly modified support document saying some Claude users would need to submit a government-issued photo ID and a live selfie before accessing certain features or completing their subscription.
The AI community found out about it through screenshots on X.
Within hours, the tweet everyone was quoting read: "Claude now requires government ID verification (via Persona) before subscription. ChatGPT doesn't. Gemini doesn't. Anthropic just handed their competitors a gift." That's the version that got shared thousands of times. And the person was not wrong.
Let's talk about what actually happened, why Anthropic did it, why the execution looks terrible, and what the third-party they chose means for your data.
What Anthropic Is Actually Asking For
Anthropic's updated help page specifies the following to verify your identity:
- A physical, undamaged government-issued ID: passport, driver's license, or national identity card
- Photocopies, mobile IDs, and student credentials are rejected
- A live selfie may be required on top of the document scan
- The process runs through a third-party provider called Persona Identities
Anthropic stated: "We are rolling out identity verification for a few use cases, and you might see a verification prompt when accessing certain capabilities, as part of our routine platform integrity checks, or other safety and compliance measures."
The phrase "a few use cases" is doing a lot of work in that sentence. The company declined to specify what those use cases are, declined to list trigger conditions, and declined to respond to press inquiries about the rollout's scope at the time of publication.
So you could be a paying subscriber, logging in on a Tuesday afternoon to write code, and suddenly face a passport requirement. No prior warning. No explanation beyond the boilerplate. That is what "routine platform integrity checks" means in practice.
The Timing Matters
Anthropic spent the first two months of 2026 benefiting from OpenAI's controversy. When OpenAI signed a deal to deploy AI on Pentagon classified networks, a significant number of users migrated to Claude specifically because Anthropic had passed on that contract. Free signups reportedly surged 60% in January and February alone.
Those users chose Claude because Anthropic positioned itself as the privacy-conscious alternative.
Those same users now need to hand over a passport to continue using the product they chose specifically to avoid surveillance. That is not a framing problem. That is the actual situation.
Meanwhile, Anthropic is in talks that would value the company at $800 billion and recently signed a multi-year cloud infrastructure deal with CoreWeave. The company is expanding aggressively. Identity verification fits that pattern, whether users like the connection or not.
Who Persona Identities Is, and Why It's a Problem
Anthropic did not build its own verification system. They contracted Persona Identities, the same Know Your Customer infrastructure used across financial services and, until recently, Discord.
Discord chose Persona for age verification earlier this year. Discord dropped them in under a month after a security researcher found nearly 2,500 of Persona's front-end files sitting on a U.S. government-authorized endpoint. That exposed code revealed Persona conducts 269 distinct verification checks, including screening users against politically sensitive watchlists and adverse media categories covering terrorism and espionage. Persona CEO Rick Song said it was not a major vulnerability. Discord disagreed and walked away.
Anthropic chose this vendor after that incident became public.
Persona's list of subprocessors includes AWS, Confluent, Google, Stripe, Twilio, and OpenAI. Yes, OpenAI. Your identity documents submitted to verify your Claude account may flow through systems operated by Anthropic's direct competitor as part of normal fraud detection operations.
Anthropic's official response: "Persona is contractually limited in how they can use your data: only to provide and support verification and to improve their ability to prevent fraud."
Contractual limits are only as strong as enforcement, and enforcement requires knowing a violation occurred.
The Data Handling Claims
Anthropic made several specific claims about how your verification data gets handled:
- Your ID and selfie go to Persona's servers, not Anthropic's own systems
- Anthropic acts as "the data controller," setting the rules
- The data is encrypted in transit and at rest
- It will not be used to train AI models
- It will not be shared with third parties for marketing purposes
That last part about model training matters. Anthropic has been careful on this front since its earliest commercial policies. The encryption and controller claims are standard practice for any serious KYC vendor.
The part worth watching: Anthropic "failed to state" what the retention period for your identity documents actually is, according to The Register's reporting. The company acknowledged it sets its own retention period, then stopped short of disclosing what that period is.
For reference, an October 2025 breach at Discord exposed roughly 70,000 government IDs that users had submitted for age verification. That was a different vendor, but the principle holds: third-party custody of government documents has a track record of being compromised. No vendor is immune. The question is what happens when Persona gets breached.
Why Anthropic Might Actually Need This
The cynical read is easy: Anthropic is treating AI access like a financial product, verifying identity the same way banks and crypto exchanges do. One X post put it bluntly: "mandatory kyc just to use an ai model. anthropic is officially treating compute like a financial asset."
That framing is emotionally satisfying, but there are legitimate reasons for this that deserve acknowledgment.
Anthropic's most capable research model, Claude Mythos Preview, autonomously discovered zero-day vulnerabilities in every major operating system and web browser during testing, including vulnerabilities decades old. Mythos Preview can write browser exploits and escalate kernel privileges. Anthropic restricted it to 40 organizations through a controlled program and did not release it publicly.
The versions of Claude available to regular subscribers are not Mythos Preview. But the trajectory is clear. If future Claude variants can produce working exploits for critical infrastructure, the question of who is behind the keyboard stops being philosophical and becomes a liability question. Identity verification builds a paper trail before those capabilities reach consumer tiers.
You can disagree with the decision. You can think the privacy tradeoff is wrong. But the capability argument is real, and dismissing it means not engaging with what these models are becoming.
Also worth noting: Anthropic appears to be responding to non-U.S. users accessing Claude through intermediaries in unsupported regions. A live selfie matched against a government ID is difficult to circumvent. For Chinese users accessing Claude via proxies, or anyone in an unsupported region, verification functions as a ban. That is probably the most immediate and concrete enforcement goal.
The No-CVE Angle No One Is Talking About
This is not the first time a company has tried to link identity verification to AI access. OpenAI introduced a similar verification mechanism for API users in April 2025 -- though they kept standard ChatGPT accounts free of that requirement. Anthropic is the first major AI company to push verification requirements to consumer subscription users directly.
If you write or work on applications using the Anthropic API, this policy currently does not affect direct API access. Developer access runs through a separate path. The verification prompts appear in the consumer product, not in API-level tooling.
What Competitors Are Doing Instead
ChatGPT accepts users 13 and older with no document verification. Gemini operates under the same 13-plus standard. Neither requires a passport to use the consumer product.
That gap is significant for Anthropic's market position. The users who switched to Claude over OpenAI's Pentagon deal were privacy-motivated. Those users now face a harder choice: stay with a platform that asks for government documents, or move back to the companies they left specifically because of surveillance concerns.
Crypto commentator Ryan Sean Adams summarized it on X: "Not even a regulatory requirement – Anthropic just doing it because they want to." That framing has stuck because it is accurate. No government mandated this. Anthropic chose it.
If You Hit the Verification Prompt
Per Anthropic's documentation:
- Submit the form for manual review if the automated check fails
- File an appeal if you disagree with the verification result
- A refund is available for any billing period disrupted by verification issues (at least one user confirmed receiving one)
For accounts in unsupported regions, manual review is the only path forward, and there is no guarantee of a positive outcome.
The Bigger Picture
Crypto got regulated. Social media got regulated. AI is next, and companies know it. Anthropic building a voluntary identity layer before regulators demand one is either responsible corporate behavior or a preemptive capture of the compliance narrative, depending on your perspective.
The White House published a national AI legislative framework in March 2026. David Sacks outlined six focus areas. The direction of travel is toward more verification, not less. Anthropic may be getting ahead of that curve.
The problem is execution. Choosing a vendor that Discord publicly dropped over privacy concerns, declining to disclose retention periods, and rolling out with zero advance communication to users -- that is not responsible corporate behavior. That is a company moving fast and hoping the fine print holds.
If you are a paying Claude subscriber, read the Persona subprocessor list. Know where your documents actually go. And decide for yourself whether the product is worth what it is now asking for.