On June 17, Anthropic dropped a privacy-policy revision into inboxes and support pages with the kind of quiet-a-Friday-afternoon timing normally reserved for executive departures and SEC settlements. Starting July 8, 2026, users of Claude Free, Pro, and Max may be required to submit a government-issued photo ID and a live selfie to a third-party service called Persona before they can keep using the product. Enterprise customers are exempt, which is the first thing that tells you this isn’t really about safety.
It is, the company says, about age and identity verification. What it doesn’t say — and what the policy revision quietly confirms — is that Anthropic shipped two models, Fable 5 and Mythos 5, that it couldn’t figure out how to gate without scanning your driver’s license. The models were pulled from rotation. The ID requirement is what’s bringing them back.
That is not a safety framework. That is a recall dressed up as a feature.
The Models They Pulled, and Why Nobody’s Saying It Out Loud
Fable 5 and Mythos 5 were briefly available in Claude’s model rotation earlier this spring. Then they vanished. At the time, the explanation was vague: guardrail adjustments, routine updates. But the revised privacy policy tells the real story. Anthropic “did not have an immediate way to verify a user’s identity” and therefore “had no choice but to remove both LLMs from the model rotation.” That sentence, reported by Techzine and confirmed across multiple outlets, is doing an extraordinary amount of work.
Think about what it means. Anthropic released two frontier models to the public, discovered after deployment that there were use cases it couldn’t prevent without knowing who was on the other end of the prompt, and then yanked them. Now, instead of saying “we shipped models we couldn’t adequately safety-test for open access,” the company is presenting identity verification as a forward-looking policy improvement rather than a retroactive patch for a product that got ahead of its controls.
One engineer I spoke with — working at a competitor’s AI lab, messaging from a conference hotel bar in San Francisco — put it bluntly: “They didn’t want to say ‘we don’t know what these models will do if the wrong person asks the wrong thing,’ so they said ‘we need to know who’s asking.’ Same problem, different frame.”
Persona and the Slow Normalization of Your Face as a Login
The third-party service handling the verification is Persona, a San Francisco-based identity platform that has become the quiet infrastructure behind a growing number of “verify yourself” mandates across the internet. Persona processes photo IDs, matches them against live selfies, and retains the data according to the client’s policy. Anthropic’s policy says the data is used “solely for verification purposes,” which is what every company says until a subpoena or a breach rewrites the terms.
What’s notable here isn’t that Anthropic is using a third-party verifier — that’s standard. It’s that the company built its reputation on being the safety-conscious, thoughtfully-paced alternative to OpenAI and Google, and is now requiring biometric enrollment for casual chatbot access. Not for financial transactions. Not for healthcare data. For text generation.
The business-tier exemption is the tell. If identity verification were genuinely a safety necessity for interacting with these models, enterprise users would face the same requirement. They don’t, because enterprise customers have contracts with liability provisions, and individual users have clickwrap. The verification isn’t about what the models can do — it’s about who bears the risk when they do it.
The Quiet Truth About Frontier Model Releases
There is a pattern emerging across the industry: release, observe, restrict, rebrand. Ship a model with capabilities that generate impressive benchmarks and viral demos. Wait for the inevitable edge cases. Then add friction — rate limits, content filters, identity gates — and frame the friction as an enhancement rather than a correction.
Anthropic’s ID mandate is the most explicit version of this pattern yet, because it involves handing over a government document rather than just waiting out a cooldown timer. But the logic is the same. The models are powerful in ways the companies themselves don’t fully map before release, and the post-hoc controls keep getting passed along to users as though users were the variable that needed constraining.
By July 8, plenty of Claude users will fork over their IDs without a second thought. That’s the bargain the internet has trained everyone to accept. But the bargain deserves to be named for what it is: not a safety upgrade, but a quiet admission that the models went out the door half-governed, and the fix lands on you.
Anthropic could have said that plainly. It chose a privacy-policy update on a Tuesday instead.