Anthropic's new ToS quietly opens the door to ID verification

4 min read 1 source clear_take
├── "This marks the end of the 'LLMs are infrastructure, not consumer media' regulatory argument"
│  └── top10.dev editorial (top10.dev) → read below

The editorial argues that the AI industry spent 2024-2025 positioning LLMs as infrastructure akin to AWS to avoid consumer media regulation, and that Anthropic's quiet privacy policy update is the first concrete admission that this framing has lost. The trigger isn't one law but a stack — UK Online Safety Act, California AB 1043/SB 976, Utah SB 142, Texas HB 18, and EU AI Act Article 28 — that collectively force frontier-model vendors into the same identity-verification regime as adult content s

├── "The lack of transparency around scope and triggers is the real problem"
│  ├── top10.dev editorial (top10.dev) → read below

The editorial highlights that Anthropic shipped this change with no blog post, no changelog entry, and no email to API customers — just a silent diff in the legal page. Critical questions remain unanswered: which jurisdictions trigger verification, whether Claude.ai, the API, and Claude Code are all affected, and whether enterprise customers can opt out on behalf of end users. The terms simply reserve the right without committing to scope.

│  └── @arunc (Hacker News, 158 pts) → view

By surfacing the privacy policy diff on Hacker News with no accompanying explanation from Anthropic, the submitter implicitly frames this as a story about a quiet, undisclosed expansion of data collection rights. The 158-point score and 115-comment thread reflect a community treating the silent rollout itself as newsworthy.

└── "This is the predictable downstream effect of the UK Online Safety Act vendor pattern reaching the model layer"
  └── top10.dev editorial (top10.dev) → read below

The editorial explicitly traces the verification mechanism — Yoti, Persona, Veriff, Stripe Identity — back to the vendor stack the UK Online Safety Act imposed on adult content sites in July 2025. The argument is that this was never going to stay confined to porn sites; the same compliance infrastructure was always going to migrate up to any service producing text or images accessible to minors, and frontier-model providers are next in line.

What happened

Anthropic quietly updated its privacy policy to include provisions for age and identity verification, a category of data collection that did not previously exist in its terms. The change surfaced on Hacker News at score 158 with no accompanying blog post, no changelog entry, and no email to API customers — just a diff in the legal page at anthropic.com/legal/privacy.

The new language permits Anthropic to collect, process, or require third parties to collect government-issued ID, biometric face scans, or other identity signals to confirm a user is of legal age or is who they claim to be. This is the same vendor pattern — Yoti, Persona, Veriff, Stripe Identity — that the UK Online Safety Act forced onto adult content sites in July 2025, now arriving at the frontier-model layer.

Anthropic has not said which jurisdictions trigger the requirement, which products are affected (Claude.ai consumer? API? Claude Code?), or whether enterprise customers can opt out on behalf of their end users. The HN thread is full of developers asking exactly those questions and getting no answers. The terms simply reserve the right.

Why it matters

The AI industry spent 2024 and most of 2025 arguing that LLMs are infrastructure — closer to AWS than to TikTok — and therefore shouldn't be regulated like consumer media. That argument just lost, and Anthropic's legal team is the first to write the loss into a privacy policy. The trigger isn't one law. It's the stack: the UK Online Safety Act's expanding scope, California's AB 1043 and SB 976, Utah's SB 142, Texas's HB 18, and the EU AI Act's Article 28 transparency obligations for general-purpose models with "systemic risk." Several of these explicitly name generative AI services that produce text or images accessible to minors.

The vendor economics are worth naming. Yoti charges roughly $0.10–$0.30 per verification at volume. Persona is similar. Stripe Identity is $1.50 per check. At Anthropic's scale — Claude.ai alone reportedly crossed 30M weekly actives in Q1 2026 — even a one-time verification per user is a $3M–$45M line item, paid to a handful of KYC vendors that didn't exist as a category five years ago. This is the same dynamic Cory Doctorow flagged about the Online Safety Act: the regulation creates a compliance toll, and the toll booth operators are the real winners.

There's also a competitive read. OpenAI added age estimation to ChatGPT in late 2025 but stopped short of hard ID checks. Google's Gemini relies on Google account age signals, which are notoriously soft. By writing identity verification into its terms now, Anthropic is either getting ahead of enforcement or signaling to regulators that it will be the cooperative frontier lab — useful positioning when the next round of EU AI Act implementing acts lands in late 2026.

The community reaction on HN split predictably. One camp reads this as Anthropic capitulating to surveillance creep. The other reads it as table stakes for operating in regulated markets, and notes that nothing in the new terms *requires* verification — it only *permits* it. Both readings are correct. The policy gives Anthropic the legal cover to do this; whether and how they exercise it is the next shoe.

What this means for your stack

If you build on the Claude API, three things change immediately.

First, your data-flow diagrams are now wrong. If Anthropic verifies your end users, a face scan or driver's license image transits Anthropic's infrastructure (or a sub-processor's) on behalf of *your* product. Your DPA needs to reflect that. Your privacy policy probably needs to disclose it. If you're under HIPAA, FERPA, or GLBA, you need to figure out whether Anthropic's KYC sub-processor is on your BAA — and the answer is almost certainly no, because the sub-processor list hasn't been published yet.

Second, enterprise procurement just got a new question. Any RFP touching Claude after this week should include: "Under what conditions will Anthropic require identity verification of our end users, and can we contractually disable that requirement?" If the answer is "we'll let you know," that's a procurement blocker for regulated industries. Expect Bedrock and Vertex AI customers to ask their AWS and GCP account teams the same question, because the Claude models served there inherit the terms by reference.

Third, if you're shipping a consumer product on Claude — a tutor, a companion app, a creative tool — you now have a forced choice between adding age-gating to your own onboarding (and absorbing the verification cost and churn) or waiting for Anthropic to do it for you on terms you don't control. The first option is more expensive. The second option is worse for your conversion funnel and your brand.

Looking ahead

The interesting tell will be the first time Anthropic actually invokes this clause — probably in a UK or California rollout, probably tied to a specific Claude feature like image generation or extended conversation memory. When that happens, the precedent it sets won't be "AI labs verify age" — it'll be "AI labs are the KYC chokepoint for the application layer built on top of them," and every other frontier lab will follow within a quarter. The terms are the leading indicator. The implementation is the lagging one, and it's coming.

Hacker News 158 pts 115 comments

Anthropic updates their terms to verify age or identity

→ read on Hacker News
SimianSci · Hacker News

More signal that the open-weight models should be our destiny as an industry. These proprietary models are being used to usher in more surveillance and gatekeeping across the industry.

Aurornis · Hacker News

This is an updated terms of service, but they've had ID verification for certain accounts and situations for months.Here is the Wayback Machine archive from April of their identity verification help page: https://web.archive.org/web/20260415064244/https://supp

throwaw12 · Hacker News

Couple years ago the West was complaining about surveillance and scoring system of citizens in China (or was making fun of it)Seems like US wants to get ahead on this and be #1Also Sam Altman will love this idea, because he already tried it with Worldcoin

nubinetwork · Hacker News

Considering that you need a credit card to pay for the tokens, why does anthropic need to verify your age or identity? Yes, I suppose some kid could steal my credit card, but I've got bigger problems if that happens...

krumhausen · Hacker News

Hmm. giving my personal data away to an American company controlled by us gov that infringes people’s IP and is now using an ID verify by Peter Thiel.

// share this

// get daily digest

Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.