Starting Wednesday, anyone who wants to use Anthropic's two most capable models has to prove, with a government ID and a photo of their own face, that they are who they say they are.
As of July 8, 2026, an updated Anthropic privacy policy took effect requiring identity verification for users of Fable 5 and Mythos 5, the company's frontier tier. The check runs through Persona, a San Francisco identity-verification startup, and asks each account holder to submit a government-issued document — a passport, driver's license, or national ID — plus a live biometric selfie. It is a one-time process per account. Anthropic's more widely used models, Claude Opus 4.8 and Sonnet 5, remain available under standard subscription terms with no ID check.
The policy is the quiet, structural sequel to a loud disruption. On June 12, three days after Fable 5 and Mythos 5 launched, the U.S. government issued an export-control directive suspending all access to both models "by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees," according to Anthropic's own statement at the time. The company pulled the models globally. The Commerce Department withdrew the directive on June 30, and Anthropic redeployed on July 1. The ID requirement is the machinery that lets Anthropic satisfy Washington's underlying concern — keeping frontier capability away from restricted nationalities — without repeating a blanket worldwide shutdown.
How the verification works
Under the arrangement, Persona collects and stores the sensitive material. Anthropic says it retains only a user's verification status, not the underlying ID documents or the biometric selfie, which sit with Persona under that company's own data-retention policies. In effect, Anthropic learns whether an account passed the check and, critically, the nationality attached to it — the data point that makes nationality-based access control possible.
That design maps directly onto the export-control problem. "The Persona verification is the mechanism that allows Anthropic to comply with future export control directives without pulling models globally," the daily AI briefing Unrot noted in its July 8 roundup. "If the government directs Anthropic to restrict access by foreign nationals in the future, verified US citizen status becomes the criterion rather than a blanket global ban." Anthropic has not published a full country-by-country access matrix; the AI newsletter Build Fast with AI reported that verification is "most likely to affect users whose account indicators — time zone, payment method, IP address patterns — suggest a location that might trigger the original export control concern," while for most U.S. subscribers it is "a one-time check that does not affect ongoing usage."
Persona is not a fringe vendor. Founded in 2018 by former Dropbox and Square engineers, it raised a $200 million Series D in May 2025 at a $2 billion valuation, led by Founders Fund and Ribbit Capital, and says it processed more than 300 million verifications in 2024. (Founders Fund is Peter Thiel's venture firm, a detail some coverage has emphasized; it was the round's lead investor, though the company counts a broad roster of backers including Coatue, Index Ventures, and First Round.)
Why It Matters
This is the moment access to a frontier AI model started to look less like signing up for software and more like clearing a border. The tradeoff is stark. On one side, export-control compliance and a genuinely narrower blast radius than a global takedown — verified users keep working while restricted access gets gated. On the other, a new pool of highly sensitive data: government IDs and facial biometrics, held by a third party, tied to identities that a foreign adversary or a data breach would very much like to have.
Anthropic's structural answer — keep the documents at Persona, retain only status — is a meaningful privacy hedge, but it does not eliminate the concern. Biometric data is not a password; a face cannot be reset. And the transparency around exactly what Persona shares back, and for how long anything is stored, remains thin. Even sympathetic observers flagged the gap. Whether users "trust Anthropic and Persona with biometric ID data is a separate and legitimate question that Anthropic has not addressed with adequate transparency about the data-sharing relationship," Unrot wrote.
The larger stakes are precedent. Age-gating and identity-gating have arrived piecemeal across the internet for years, but this extends the logic to the frontier of AI capability itself: the most powerful models become the ones you must show ID to touch. If that becomes the norm as governments lean harder on export controls — and with a White House frontier-model framework expected around an August 1 deadline — anonymous access to top-tier AI may quietly become a thing of the past.
What to watch
Three signals. First, whether Anthropic publishes a clearer country-by-country access policy and a fuller account of Persona's data handling, or leaves the compliance posture opaque. Second, whether OpenAI and Google adopt similar ID-verification gates as their own gated frontier models — GPT-5.6 and Gemini 3.5 Pro — move toward broad release under the coming federal framework. Third, whether privacy regulators, particularly in the EU, treat mandatory biometric verification for AI access as proportionate — or as a step too far.
“The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States.”— Anthropic, Company statement, June 12, 2026