Anthropic to Implement ID Verification for Claude Access, Partnering With Controversial Persona
Key Takeaways
- ▸Anthropic is rolling out identity verification for Claude features without advance notice, with verification prompts potentially appearing when accessing any capability
- ▸Persona Identities, the chosen verification vendor, has a history of privacy controversy from its failed Discord partnership and concerns over its extensive subprocessor network
- ▸The implementation raises data privacy concerns given the complex chain of third-party providers handling sensitive identity documents and selfies, despite Anthropic's assurances about data handling and contractual limitations
Summary
Anthropic has quietly rolled out identity verification requirements for certain Claude features, using Persona Identities as its verification vendor. The move is being implemented on a case-by-case basis as part of what Anthropic describes as "routine platform integrity checks" and "safety and compliance measures." The company states that identity data will not be used to train its models and will only collect the minimum information necessary, with data sharing limited to Persona and Anthropic except where legally required.
The choice of Persona as the verification partner has drawn significant backlash from users and privacy advocates. Persona previously faced controversy when Discord selected it for age verification before ultimately scrapping those plans. The criticism intensified after reports showed Persona works with numerous subprocessors including AWS, Google, OpenAI, and Stripe, creating a complex data chain that increases the risk of personal information exposure. While Anthropic claims contractual limitations prevent Persona from misusing data, the company notably failed to specify its data retention period, leaving key privacy questions unanswered.
Editorial Opinion
While identity verification can serve legitimate safety purposes, Anthropic's choice of Persona and the opaque rollout process will likely undermine user trust rather than enhance platform security. The failure to disclose data retention periods and the acknowledgment of a complex subprocessor chain contradicts the company's stated commitment to minimal data collection, suggesting that privacy protections may not match the rhetoric. Companies implementing identity verification systems should prioritize transparency about timelines, data handling, and retention policies from the outset.



