The privacy of AI users is becoming a growing concern. And Anthropic just crossed a line its competitors haven’t dared to cross yet: the possibility of requiring identity verification to access Claude. Here’s what this update actually contains and what it means in practice.
Anthropic and Identity Verification: What the Official Policy Says
On June 8, 2026, Anthropic published a revised version of its privacy policy, with an effective date set for July 8, 2026. The text is available directly on Anthropic’s official website.
The key change appears in the “Verification Data” section. Here’s the substance of it: in certain circumstances, Anthropic may ask a user to verify their age or identity. If the user agrees, the data collected can include:
- An image of an official identity document (passport, national ID card) along with the information it contains (ID number, date of birth)
- A photo or video of the user’s face
- Facial geometry templates, explicitly described as “biometric data” in certain jurisdictions
- The result of the verification (for example, whether the user’s age exceeds a defined threshold)
The wording is clear and precise in the original text. This isn’t a rumor or an interpretation: it’s written in black and white in the active privacy policy.
A Selective Measure, but With Vague Criteria
Anthropic does not require this verification from all its users. The policy refers to “certain circumstances” without specifying what those are. That’s where the main grey area lies.
It’s unclear what criteria trigger a request. It’s also unclear which third-party provider will handle these verifications, or how the collected data will be stored or deleted after use.
The official justification Anthropic offers comes down to two arguments: keeping its services “safe and secure” and complying with evolving regulations. That’s a predictable response, but it doesn’t fully address legitimate questions about whether the measure is proportionate.
Biometric Data and GDPR: The Real Issue
Collecting facial geometry is not a trivial matter. In Europe, this type of data falls under the category of sensitive data as defined by the GDPR. Processing it is subject to strict conditions, including the requirement of an explicit legal basis and compliance with the data minimization principle.
Anthropic is an American company with servers based in the United States. The privacy policy does address the question of data transfers outside the European Economic Area, and mentions adequacy mechanisms and standard contractual clauses. But the question of whether biometric verification is actually compliant with the GDPR remains open.
For European users, this deserves close attention. If you use Claude in a professional or sensitive context, you’ll want to monitor whether this verification applies to your account and under what circumstances.
An Unprecedented Stance Compared to OpenAI and Google
As of now, neither OpenAI with ChatGPT nor Google with Gemini require identity or age verification for standard consumer access. Anthropic stands out clearly from its two main competitors on this point.
This decision can be read two ways. Either Anthropic is getting ahead of regulatory requirements on the horizon, particularly under the European AI Act or US legislation on protecting minors online. Or the company is deliberately positioning itself at a higher level of control, consistent with its longstanding focus on safety and responsible research.
Either way, the signal is strong: the “open access for everyone” era for consumer AI may be coming to an end.
Key Takeaways
- Anthropic has officially incorporated the possibility of age or identity verification into its privacy policy, effective July 8, 2026.
- The data potentially collected includes biometric information (facial geometry), which puts this measure in a sensitive category under the GDPR.
- Verification is selective: not all users are affected, but the targeting criteria are not public.
- Neither OpenAI nor Google currently impose an equivalent measure for their consumer-facing products.
- Questions about European compliance and how data will be handled by a third-party provider remain without a complete official answer.
This development is worth watching closely, especially if you use Claude in a professional context or manage environments where data protection is critical. If the topic interests you, feel free to discuss it in the comments or follow the blog for future analysis.
Sources
- Anthropic’s official privacy policy (published June 8, 2026, effective July 8, 2026)
