On June 15, Anthropic updated its privacy policy with a quiet, 47-word addition. Starting July 8, users of Claude Free, Pro, and Max “may be asked to verify your age or identity.” The company will collect government-issued ID scans and facial selfies, processed by a third party called Persona. The documents needed to unlock certain model capabilities — specifically, access to the now-pulled Fable 5 and Mythos 5 models — will sit on servers run by a firm that Discord quietly dropped in February after researchers found 53 megabytes of its front-end code sitting exposed on a public Google Cloud server connected to a federal compliance program.
The reaction online was swift and predictable. The Hacker News thread hit 614 points by Monday morning. The r/ClaudeAI subreddit settled on a one-word verdict: “absolutely not.” Persona’s backing by Peter Thiel’s Founders Fund became the headline villain. The narrative writes itself: AI company forces users to hand biometric data to a Thiel-backed surveillance outfit with a recent breach history. What could possibly go wrong?
And yet that narrative — however satisfying — misses something structural. The scandal isn’t that Anthropic chose a controversial partner. It’s that its choice was almost certainly not a choice at all.
The Compliance Pipeline You’ve Never Heard Of
When a U.S. AI company needs to verify hundreds of thousands of global users against an export-control order — the specific mechanism that forced Fable 5 and Mythos 5 offline — it cannot build the solution in-house on a two-week timeline. It buys from a vendor. The market for identity verification that can handle government-ID document parsing, biometric liveness checks, and cross-jurisdictional compliance at scale has exactly three credible players: Persona, Stripe Identity, and Jumio.
Stripe Identity, launched in 2021, works well if you already live inside Stripe’s payments ecosystem. Anthropic, which bills through its own infrastructure, does not. Jumio, the oldest of the three, built its reputation verifying gambling and crypto customers — a legacy that AI safety policymakers in Washington view about as warmly as an open bar at an NTSB hearing. That leaves Persona, which by 2026 had become the default answer for any platform that woke up one morning and discovered it suddenly needed to know who its users were.
A compliance officer who has navigated these waters at two major platforms described it this way in a Slack DM: “You don’t pick Persona because you like Persona. You pick Persona because the other two vendors failed the security review, ghosted you, or quoted a 14-month integration timeline. It’s the last taxi at the stand.”
The Export Order That Changed the Calculus
The identity-verification requirement did not emerge from some spontaneous corporate appetite for biometric surveillance. It emerged — directly, explicitly — from a U.S. government export-control order covering frontier AI models. More than 60 cybersecurity and technical experts signed a letter protesting the order, according to The Register. Anthropic responded not by lobbying harder (though it did that too) but by building a technical compliance mechanism that would let it turn the models back on.
This is the part the privacy outrage elides. Anthropic was not choosing between “collect IDs” and “don’t collect IDs.” It was choosing between collecting IDs through a vendor — and thereby restoring access to models users were already asking for — or keeping those models dark indefinitely while hoping the export order gets unwound. For a company burning an estimated $2.7 billion a year on compute and talent, indefinite darkness is not a strategy.
The irony is that the same users furious about ID verification are, in many cases, the same users who spent the previous month furious that Fable 5 was gone. You cannot have both. The architecture of export controls on AI — still a new and evolving body of regulation — creates exactly this bind: re-enable the model by verifying users, or keep the model offline on principle. One of those options ships a product.
The Real Fight Isn’t Persona
Persona’s breach history is a legitimate concern, and anyone who shrugs at 53 megabytes of exposed FedRAMP-connected server code should not be running identity infrastructure. But fixating on Persona-as-villain avoids a harder question: why is the identity-verification market for AI compliance a three-horse race, with two of the horses limping?
The answer is that verifying identity online at scale — with document parsing that works across 190 countries, in real time, with acceptable false-positive rates, while satisfying the data-residency requirements of jurisdictions from Brussels to New Delhi — is genuinely difficult. It is not a software problem you solve with a few engineers and a Jira board. It is a regulatory-and-software problem that requires years of accumulated certifications, audits, and government relationships. Few firms bother. Fewer still survive.
The Persona backlash is, in this light, not a story about one company making a bad vendor choice. It is a story about a regulatory regime that created an urgent requirement for identity infrastructure, combined with a market that has allowed that infrastructure to consolidate around a single, imperfect answer. Blame Anthropic if you want. But the structural forces that made Persona inevitable will outlast this news cycle — and they will apply to every other frontier model provider soon enough.
A contractor who worked on integration for one of Persona’s competitors put it more bluntly in a courthouse hallway after a deposition: “Everyone hates Persona until they need to verify a million users by Tuesday.” That is not a defense of Persona. It’s an observation about the compliance architecture we’ve built — and the bills that are now coming due.
Sources
- Anthropic may require identity verification for Claude use
- Anthropic reserves right to check ID for Claude subs - The Register
- Anthropic to Require Identity Verification for Certain Capabilities …
- Anthropic to widen data collection for Claude users from July 8
- Discord distances from Peter Thiel–backed verification software after code found on U.S. gov site | Fortune