For the past few years, the onboarding experience for leading large language models has followed a predictable pattern of frictionless entry. A user provides an email address, verifies a phone number, and is immediately granted access to a frontier model capable of writing code or analyzing complex legal documents. This era of loose anonymity allowed developers and enthusiasts to iterate quickly, often bypassing regional restrictions or managing multiple accounts to test different prompts. However, that window of unrestricted access is closing. Users are now encountering a sudden, jarring friction point: a prompt demanding a government-issued photo ID and a real-time selfie before they can proceed.
The Mechanics of Identity Verification
Anthropic has officially integrated a rigorous identity verification layer into the Claude ecosystem, specifically targeting users who access certain high-stakes features or those flagged during platform integrity checks. This is not an internal tool developed by Anthropic, but rather a deployment of technology from Persona Identities, a third-party verification specialist. The process is designed to be swift but uncompromising, typically concluding in under five minutes, provided the user has the correct documentation on hand.
To pass the check, users must provide a physical, government-issued photo ID, such as a driver's license or a state-issued identification card. The system then requires a live selfie captured via smartphone or webcam to ensure the person holding the ID is the actual user. The criteria for acceptance are strict. Anthropic and Persona explicitly reject digital scans, screenshots, photos of photos, or mobile-based digital IDs. Furthermore, non-government identification—including student IDs, employee badges, library cards, and bank cards—is entirely ineligible for verification.
When a verification attempt fails, the system allows for retries, often suggesting improvements in lighting or the use of an alternative government ID. If all automated attempts fail, the user is directed to a manual review request form to resolve the dispute. This rigid pipeline ensures that the identity of the user is tied to a verifiable legal entity, removing the possibility of using synthetic identities or easily obtainable digital copies to gain access to the model.
From Anonymity to Accountability
This shift represents a fundamental pivot in how AI labs view their relationship with the end user. For a long time, the industry focused on model alignment and safety filters—trying to stop the AI from saying the wrong thing. Anthropic is now shifting the focus toward user accountability—ensuring they know exactly who is saying the thing to the AI. This is a move toward AI governance and compliance rather than a technical upgrade to the model's intelligence.
By implementing this system, Anthropic is effectively weaponizing its Usage Policy. When access is tied to a government ID, the cost of a policy violation increases significantly. In the previous regime of email-based accounts, a banned user could simply create a new account in seconds. With identity verification, a ban becomes a permanent exclusion tied to a legal identity, making it nearly impossible to circumvent restrictions through burner accounts. This is particularly critical for Anthropic's efforts to manage access in unsupported regions, where account creation via VPNs has been a common workaround.
From a data privacy perspective, Anthropic has structured this as a controller-processor relationship. Anthropic acts as the data controller, setting the rules for who gets access, while Persona acts as the data processor, handling the actual sensitive imagery. The government IDs and selfies are stored within Persona's secure systems, not on Anthropic's own servers. Anthropic only accesses these records through the Persona platform when necessary, such as during an appeal or a legal inquiry. Crucially, the company has stated that this identity data is used exclusively for verification and legal compliance and is never fed into the training sets for Claude.
For the professional AI practitioner, this introduces a new layer of operational risk. The transition from a low-friction email login to a high-friction legal verification means that account stability is no longer guaranteed. If a corporate account used for a critical production workflow is suddenly flagged for identity verification, the inability to provide a government ID for the account owner could lead to an immediate service outage. The era of managing a fleet of proxy accounts for different testing environments is effectively over, as the system now recognizes the human behind the screen rather than the email address in the field.
This move signals the end of the experimental phase of AI deployment and the beginning of the regulated era, where access to frontier intelligence is treated less like a public utility and more like a licensed professional tool.




