A hand holding a government-issued ID card under the camera of a smartphone running an identity-verification interface, the kind of check Anthropic uses through the vendor Persona for a small subset of flagged Claude accounts
Photo via Unsplash

TL;DR: A claim went around that on July 8, 2026 every consumer Claude user would have to scan a government ID or be permanently locked out with no way to appeal. That is not what is happening. Anthropic's identity check, run through the vendor Persona, has been live since roughly April 14, 2026. It hits a small subset of accounts that get flagged for suspicious or policy-violating activity, not the whole user base.[1] It is an appeal path: a flagged or suspended user can verify to make their case and get access back. July 8 is just the date a privacy-policy update formalizing the practice takes effect.[1] The thing actually worth your attention is who does the checking. Persona's government-facing dashboard code leaked from a public endpoint in February 2026.[2]

What the Scary Version Got Wrong

The viral framing had three load-bearing claims, and all three were off.

Claim one: every consumer Claude user has to verify. No. Anthropic's own support page says a small subset of users might see a verification prompt. The trigger is account-level: something flagged the account, usually suspicious activity or a suspected policy violation, and verification is how Anthropic confirms there is a real person behind it.[1] If your account is in normal standing, you are not being marched toward an ID scanner on a deadline.

Claim two: fail once and you are permanently locked out, no retry, no appeal. That gets the purpose of the flow backwards. The verification step is itself the appeal. If an account gets restricted or suspended, verifying identity is the documented way to contest it and regain access.[1] Calling it a no-appeal lockout describes the opposite of the mechanism.

Claim three: July 8 is a countdown to a new mandatory rollout. Also no. The verification capability has been running since about April 14, 2026. July 8 is the effective date of a privacy-policy update that writes the existing practice into the consumer-accounts policy.[1] A policy formalizing something that already exists is not a starting gun.

What Is Actually Happening

Strip out the panic and here is the real shape of it. Anthropic uses Persona, an identity-verification company, to run a check that pairs a government ID with a selfie. The selfie is matched against the ID to confirm the same person is on both. That check is reserved for accounts that have been flagged, and it functions as remediation: pass it, and a flagged or suspended account can come back.[1]

On the data: Anthropic says Persona deletes verification data in line with its stated retention limits and applicable law. There is no public, exact retention duration, which is a fair thing to push on, but it is not the same as "kept forever for everyone."[1] The honest summary is narrow on purpose. A targeted, appealable identity check on flagged accounts is a normal trust-and-safety tool. Plenty of platforms do a version of it. The interesting questions are about the vendor and the data, not about an imaginary universal deadline.

The Real Worry Is Persona

Here is where skepticism is earned. In February 2026, security researchers found a Persona government dashboard codebase sitting on a publicly reachable FedRAMP-authorized endpoint: about 53 megabytes across 2,456 files, no exploit required. The exposed code documented 269 distinct verification checks, going well past simple ID and age confirmation, and included the ability to file Suspicious Activity Reports straight to FinCEN at the US Treasury and to Canada's FINTRAC.[2]

That is the part that should make you sit up. Not because Anthropic is secretly building a lockout, but because the company you would be handing your face and your ID to has a documented exposure and ships tooling wired into government financial-intelligence reporting. Anthropic says it has contractually barred Persona from using verification data for advertising, marketing, or model training. Useful, but a marketing-and-training restriction does not touch the watchlist-screening and government-reporting machinery that the leaked dashboard showed Persona is built to run.[2] If you are weighing whether to verify, the vendor's track record is the variable that matters.

The Biometric-Law Angle, Honestly Framed

A selfie used for face matching can count as biometric data depending on where you live, and that pulls in real law. In Illinois, the Biometric Information Privacy Act (740 ILCS 14) treats a scan of face geometry as a covered identifier. It requires written notice and consent before collection, a published retention schedule, and it gives an individual a private right of action without proof of separate harm, with damages set per violation.[3] That is why the missing public retention duration is a fair thing to keep asking about.

In the European Union, GDPR Article 9 puts biometric data in a special category with extra processing conditions. None of this is unique to Anthropic, and none of it means a verification flow is automatically illegal. It means that if you are in the flagged subset and you do get asked to verify, these are the rules that govern how that data has to be handled, and they give you something to point at if it is handled badly. The accurate read is not "a litigation bomb is about to go off for everyone." It is "if you are one of the people actually asked to verify, you have rights, and the vendor has obligations."[3]

What to Actually Do

The useful version of this story is short.

If you were not flagged, do nothing. There is no universal July 8 deadline coming for your account. The prompt is targeted, not blanket.[1]

If you do get a prompt, understand why. It generally means the account got flagged or restricted. Verifying is the path to appeal and regain access, and you can contact Anthropic support if something looks wrong.[1]

If the vendor gives you pause, that is reasonable. Given the February exposure and Persona's government-reporting tooling, it is fair to decide you would rather not hand over a selfie and an ID, and to weigh whether you need that particular account.[2]

Know your jurisdiction. If you are in Illinois, BIPA sets out what notice and consent you are owed before any face-geometry scan, and what a retention schedule should look like. If you are in the EU, GDPR Article 9 applies. Save the policy text and the date if you are ever actually asked to verify.[3]

Bottom Line

The countdown was fake. The check is real, narrow, appealable, and already months old. The legitimate concern is not Anthropic herding everyone into an ID scanner. It is that the identity work is outsourced to a vendor whose government dashboard leaked, and that the retention details are thinner than they should be. Aim the skepticism there, not at a deadline that does not exist.

Sources

  1. Anthropic Support: Identity verification on Claude (states the prompt reaches a small subset of users, ties verification to flagged or restricted accounts, describes it as an appeal path to regain access, and notes the related privacy-policy update). https://support.claude.com/en/articles/14328960-identity-verification-on-claude
  2. Cybernews: Persona leak exposes global surveillance capabilities (the February 2026 exposure of Persona's government dashboard code on a public FedRAMP-authorized endpoint, roughly 53 MB across 2,456 files, 269 verification checks, and Suspicious Activity Report filing to FinCEN and FINTRAC). https://cybernews.com/privacy/persona-leak-exposes-global-surveillance-capabilities/
  3. Illinois General Assembly: Biometric Information Privacy Act (BIPA), 740 ILCS 14 (covers scans of face geometry as a biometric identifier, requires written notice, consent, and a retention schedule, and grants a private right of action without proof of separate harm). https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=3004