A Chicago man has filed a proposed class-action lawsuit against Anthropic, alleging that the company’s identity-verification process for its Claude chatbot violated Illinois’ Biometric Information Privacy Act by requiring a government-issued ID and a live facial image without providing legally sufficient disclosures about the collection, retention, and destruction of biometric information. Jose Enrique Ortiz Colon alleges that he was locked out of Claude until completing the verification process through third-party identity-verification provider Persona, which allegedly scanned facial geometry and compared his live image with his driver’s-license photograph. The lawsuit contends that Anthropic failed to tell him in writing how long the biometric information would be retained and lacked a publicly available retention-and-destruction policy required under Illinois law. Anthropic has said it takes user privacy seriously and is reviewing the complaint. The case could become an important test of how stringent state biometric protections apply to AI companies increasingly using identity and age-verification systems.
Key Takeaways
- The proposed class action alleges that Claude users in Illinois were required to provide government identification and live facial images that were used to perform facial-geometry scans without all of the advance disclosures required by Illinois biometric-privacy law.
- Illinois law specifically recognizes scans of facial geometry as biometric identifiers and requires private entities collecting biometric information to provide written notice concerning its purpose and duration, obtain a written release, and maintain a publicly available policy governing retention and permanent destruction.
- The dispute reaches beyond one Claude user: as AI companies adopt increasingly intrusive identity-verification systems, the case raises a fundamental question about whether access to powerful digital services can effectively be conditioned on surrendering immutable biometric information without exceptionally clear notice and safeguards.
In-Depth
The rapid expansion of artificial intelligence is colliding with one of the most sensitive categories of personal information: biometrics. A proposed class action filed by Chicago resident Jose Enrique Ortiz Colon accuses Anthropic of crossing that line through the identity-verification process attached to its Claude chatbot.
According to the allegations, Colon was prevented from continuing to use Claude until he verified his identity. The process required him to provide a government-issued ID and a live image of his face through verification provider Persona. The lawsuit alleges that facial geometry was extracted and the live image compared with the photograph on his identification.
The central issue is not simply whether Anthropic had a legitimate reason to verify users. Companies have obvious interests in preventing fraud, enforcing age restrictions, and protecting their services. The question is whether those objectives excuse inadequate disclosure when companies collect information that users cannot replace if compromised.
Illinois law takes an unusually strict position. Its Biometric Information Privacy Act identifies facial-geometry scans as biometric identifiers and requires companies to disclose biometric collection, its specific purpose and its duration while obtaining written authorization. Entities possessing biometric information must also establish publicly available retention and destruction policies.
Colon alleges Anthropic failed to satisfy those obligations. He seeks to represent similarly situated Illinois residents and requests statutory damages and other relief. Anthropic says it takes privacy seriously and is reviewing the complaint.
The broader implications are significant. Americans increasingly must prove who they are merely to access ordinary digital services. Government identification combined with facial recognition creates a particularly sensitive package of personal information. Innovation does not eliminate a company’s obligation to respect individual privacy. If anything, the extraordinary power of artificial intelligence makes clear disclosure, genuine consent, limited retention and accountable handling of biometric information more important—not less.
Sources
- https://www.theepochtimes.com/us/claude-chatbot-user-files-class-action-lawsuit-against-anthropic-over-biometric-scans-6098901
- https://www.courthousenews.com/chatbot-user-files-class-action-against-anthropic-over-biometric-data-policy/
- https://idtechwire.com/anthropic-faces-illinois-biometric-privacy-claims-over-claude-id-checks/
- https://www.ilga.gov/legislation/ilcs/fulltext?DocName=074000140K15
- https://www.ilga.gov/legislation/ilcs/fulltext?DocName=074000140K10

