DEV Community

Breach Protocol
Breach Protocol

Posted on Originally published at groundtruth.day

Claude's over-18 rule is not new. Here is what its age check actually asks for.

Claude being available only to adults is not new. Anthropic's consumer terms have required users to be at least 18 since at least May 2024, and the support article that went viral on Hacker News on 11 September 2026 is dated 18 May 2026. What does exist, and what the more than 500 comments were really about, is enforcement: Anthropic disables accounts its systems flag as possibly belonging to a minor, and restores them only if the user passes an age check run by the verification company Yoti.

Key facts

  • 18+ has been in Claude's consumer terms since at least May 2024: "You must be at least 18 years old to use the Services."
  • Verification is triggered only after an account is flagged. Users choose a selfie for facial age estimation, a photo of a government ID, or the Yoti Digital ID app.
  • Anthropic says Yoti deletes the images "as soon as your age is checked" and that Anthropic receives only a pass or fail result.
  • Primary source: Anthropic's age assurance article.

What actually happens

The support article is short. "Claude, our consumer product, is only available to people over 18 years. You'll need to confirm you're 18 or over while setting up an account. When we detect signals that you may be under 18, we'll ask you to verify your age before you can continue using Claude." Elsewhere it says: "We have safety systems in place to detect if people under 18 may be using Claude and we'll disable accounts based on indicators of minor activity."

What those indicators are is only partly public. In a December 2025 post on protecting the wellbeing of users, Anthropic said classifiers flag conversations in which a user says they are under 18, and that it was "developing a new classifier to detect other, more subtle conversational signs that a user might be underage." On mobile, a separate minimum-age article notes that "in certain US states, new laws require app stores to verify users' ages and share that information with app developers."

A bar has always had an over-18 sign on the door; what changed is that the bartender now asks some customers for ID when something makes them look young. The sign is old. The carding is what people are noticing.

What it asks you to hand over

If you are flagged, you choose one of three routes through Yoti: a selfie that estimates your age from your face, a photo of a government ID, or an over-18 credential from Yoti's own digital ID app. "Your selfie, document images, and any personal data are deleted by Yoti as soon as your age is checked. Anthropic never sees your ID or image; we receive only a pass/fail result and do not process or store any personal data from the verification," the article says.

Two details deserve attention. Anthropic's privacy policy, in its current version, includes a "Verification Data" category that covers ID images and "facial geometry templates." That clause is broader than the Yoti promise, because Anthropic runs a separate identity verification process with the vendor Persona for other purposes. That is also distinct from the government-ID checks for Fable 5 we covered in July, which relate to export controls.

And the article is silent on some things users most want to know: when enforcement began, whether it applies beyond the consumer app to Claude Code, the API or business plans, and what happens to an account that fails the check.

Why it matters

The real risk is false positives. In April the Indian outlet Medianama reported adult users locked out after being flagged, quoting the suspension email: "Our team found signals that your account was used by a child. This breaks our rules, so we paused your access to Claude." For those users, the choice is between handing a face scan or an ID to a third party and losing access, including their chat history.

Age assurance is becoming standard across consumer AI as lawmakers push for protections for young users, and every approach trades privacy against accuracy. Guessing age from conversation is less intrusive than demanding ID from everyone, but it will sometimes guess wrong. The honest caveat is that Anthropic has not published how accurate its classifiers are or how many accounts they have disabled, so users cannot judge how likely they are to be flagged. The Hacker News thread collects first-hand reports, which remain unverified.


Originally published on Ground Truth, where every claim is checked against the primary source.

Top comments (0)