What is Claude's identity verification?
In June 2026, Anthropic confirmed that it has begun asking some users of Claude, its AI assistant, to verify their identity before they can keep using certain parts of the service. In practice that means proving you are a real, specific person by uploading a government-issued photo ID and taking a live selfie, rather than just signing in with an email address. An updated section of Anthropic's privacy policy that formally covers this takes effect on 8 July 2026.
It is important to be precise about the scope, because early headlines made it sound universal. Anthropic says verification applies to a small subset of Claude's tens of millions of monthly users. You are not going to be asked to scan your passport every time you open Claude to draft an email. But the direction of travel matters for any business that is leaning on AI, so it is worth understanding exactly what is happening and why.
Why Anthropic is doing this now
Anthropic positions identity verification as part of its broader AI safety work. Better verification deters fraud and abuse, makes the models harder to attack at scale, and helps the company meet emerging rules that demand stronger accountability for who is using powerful AI. The thread running through all of it is the same: as AI becomes more capable, knowing there is a real, accountable person behind high-risk activity becomes more valuable.
8 Jul 2026
the date Anthropic's updated privacy policy section covering identity verification takes effect.
Under 5 min
the time Anthropic says a verification check typically takes, using a photo ID and a live selfie.
Zero
use of your identity data to train Claude's models, according to Anthropic's stated commitment.
Analysts at Forrester read the move as a milestone rather than a one-off. In their words, requiring verification for certain use cases shows that Anthropic believes generative AI and AI agents have become providers of high-risk, high-value transactions. That is the same logic that has long required identity checks in banking, payments and travel. Forrester also expects the major providers, including Google, Microsoft and OpenAI, to follow with verification of their own, which would make identity checks a normal feature of advanced AI rather than an outlier.
What you are asked for, and how it works
If you are one of the users prompted to verify, the process is short and follows a familiar pattern. Here is the path from prompt to result.
-
1
You are prompted to verify
The request appears when you access certain capabilities, during a routine platform integrity check, or when an account is flagged for activity that may breach the usage policy.
-
2
Upload a government photo ID
A valid, physical, government-issued document such as a passport, driver licence, state or provincial ID, or national identity card. It needs to be clear, undamaged and show your photo.
-
3
Take a live selfie
You take a selfie with your phone or webcam so it can be matched against the photo on your ID. The whole check typically takes under five minutes.
-
4
Persona runs the check
A third party, Persona, performs the match. Your ID and selfie are collected and held by Persona, not on Anthropic's systems, and the data is encrypted in transit and at rest.
-
5
The result is returned
Anthropic receives the verification result, for example a confirmation that you passed, and you regain access. Anthropic says it does not use your identity data to train its models or share it with others.
Who actually has to verify?
This is the question most business owners care about, so it is worth being concrete. Verification is not a blanket requirement. It is targeted at higher-risk activity and flagged accounts, and it can also be offered as an appeal, a way for a flagged user to stay on the platform instead of being cut off. The table below sketches who is more and less likely to see a prompt.
| Factor | More likely to be asked | Unlikely to be asked |
|---|---|---|
| Typical trigger | Accessing certain higher-risk or agentic capabilities, or being flagged for activity that looks fraudulent or abusive | Everyday chat, drafting, research and coding within the usage policy |
| Account behaviour | Sign-ups from unsupported locations, suspected automation or abuse, repeated policy violations | A single, consistently used business or personal account |
| Volume and automation | High-volume, automated or agent-driven usage that platform integrity checks single out | Normal interactive use by a person or small team |
| Status | A flagged account using verification as an appeal to avoid a ban | An account in good standing with no integrity flags |
In short, if you run a single business account and use Claude for ordinary work within its usage policy, you are unlikely to be prompted. The teams most likely to encounter verification are those running automated or agent-driven AI workflows at volume, where platform integrity checks are most active.
The privacy questions worth asking
Handing a government ID and a selfie to an AI company understandably makes people pause, and it is healthy to ask hard questions before you comply with any verification request, from any vendor. Here is a fair reading of what Anthropic has committed to, and what remains open.
On the reassuring side, Anthropic says it chose Persona as its verification partner for the strength of its technology, privacy controls and security safeguards. Your ID and selfie are held by Persona, not Anthropic. Persona is told it may only use the data to provide and support verification and to improve fraud prevention. Everything passing to Persona is encrypted in transit and at rest, and Anthropic is explicit that it does not use identity data to train Claude or sell it on.
On the open side, the clearest unanswered question reporters raised is retention: Anthropic decides how long Persona keeps the documents, and it has not spelled out a firm deletion timeline. Some other companies that use Persona delete images almost immediately after processing, so it is reasonable to want the same clarity here. It is also worth knowing, for context, that Persona is backed by Founders Fund, an investor that also backs Anthropic, which is the kind of detail a privacy-conscious business may want to factor into its own risk view. None of this is a reason to panic, but it is a reason to read the terms and keep a record before you verify.
What it means for Australian businesses
For most Australian businesses, this changes very little in day to day terms, because ordinary usage is unlikely to trigger a prompt. The real value is in treating it as a prompt to get your AI governance in order, the same way you would for any tool that touches sensitive data.
The key local point is this: the data involved in verification, a government identifier combined with face geometry from a selfie, is sensitive information under the Privacy Act 1988, which the Office of the Australian Information Commissioner regulates. Sensitive information carries higher obligations than ordinary personal information. So if a staff member is ever asked to verify on a work account, that is a decision to make deliberately, not a box to click past. Think about whose identity is being shared, with which provider, and what your own privacy policy says about it.
The broader strategic read is that accountability is becoming part of how serious AI is used, alongside the security basics every business should already have in place. If you are building AI into customer-facing or revenue-critical work, treat identity and data handling with the same care you would give your cyber security and your AI visibility. Getting ahead of it now is far cheaper than scrambling later.
A simple readiness checklist
You do not need a heavy policy for this. A short, written approach that your team understands is enough. Work through these six points.
- 1.Know who would be verified. Identify which staff or accounts run higher-risk or automated AI tasks, since those are the most likely to be prompted.
- 2.Decide who approves it. Make verifying on a work account a deliberate decision signed off by a named person, not something any team member does on the spot.
- 3.Read the terms before you verify. Check what is collected, who holds it, how it is used, and how long it is kept. Save a copy for your records.
- 4.Keep client data out of at-risk accounts. Do not run unusual, high-volume or experimental activity from the same account that handles sensitive customer information.
- 5.Note it in your privacy records. If staff identity data is shared with a verification provider, reflect that in your privacy documentation under the Privacy Act 1988.
- 6.Expect it to spread. Assume other AI providers will add verification too, and write your approach once so it covers any vendor.
Handled this way, Claude's identity verification is not a threat to your business. It is an early sign of AI growing up, and a useful prompt to make sure the way you use it is as accountable as the rest of your operation.
Key takeaways
- Anthropic is rolling out end-user identity verification for Claude. An updated privacy policy section covering it takes effect on 8 July 2026, and it currently affects only a small subset of Claude's tens of millions of monthly users.
- You may be asked to verify when you access certain capabilities, during routine platform integrity checks, or when activity on an account looks potentially fraudulent or abusive. It is also offered as an appeal so a flagged user can stay on the platform instead of being banned.
- Verification means uploading a valid government photo ID and taking a live selfie. It usually takes under five minutes and is run by a third party, Persona, which holds the ID and selfie rather than Anthropic. Anthropic says it does not use this data to train its models or sell it on.
- Forrester reads the move as a signal that generative AI and AI agents are now treated as high-risk, high-value transactions, and expects Google, Microsoft and OpenAI to follow with verification of their own.
- For Australian businesses, the data involved (a government identifier plus face geometry) is sensitive information under the Privacy Act 1988. The practical response is to understand who in your team would be verified, document the data flow, and keep client information out of any account at risk of being flagged.