Anthropic's Age Assurance Policy Shifts Minor-Access Compliance Onto Deployers
What happened
Anthropic published Age assurance on Claude, a formal support policy restricting Claude's availability to minors across its platform. The policy formalizes what had previously been an informal restriction, creating a documented compliance baseline that enterprise operators and API customers are expected to uphold. The development arrives against a backdrop of intensifying regulatory scrutiny of AI platforms accessible to children, including enforcement patterns in the EU under the EU Digital Services Act, AI and Algorithmic Accountability Provisions and the precedent set by Italy's Garante, which fined a Character.AI operator EUR 158,000 for failing to implement adequate age controls on a consumer AI platform. For organizations that have embedded Claude in consumer or education-facing products, this policy now constitutes a vendor requirement that must be reflected in their own access management and user verification workflows.
Why it matters
- ·Platform-level age restrictions do not automatically protect operators from regulatory liability. Under COPPA, the EU Digital Services Act, and analogous child-protection regimes, deployers who make AI services accessible to minors bear independent legal exposure regardless of the underlying model provider's policies.
- ·Anthropic's published policy functions as a contractual and usage-policy baseline. Enterprise customers who have not implemented age-verification or access controls at the application layer may now be in breach of Anthropic's terms, which creates vendor-relationship risk on top of regulatory risk. The Italy Garante enforcement precedent confirms regulators are willing to pursue operators, not just platform developers.
- ·The policy narrows the defense that operators could previously claim -- that minor access was the model provider's responsibility to prevent. Organizations offering Claude-powered products to general or mixed audiences now need to document how they verify user age, which may require significant changes to onboarding flows, identity checks, and intake risk assessments.
Governance controls affected
What to do now
- ☐Audit all Claude-powered products and API integrations to identify any surfaces accessible to general or mixed-age audiences, including consumer apps, educational tools, and B2B2C platforms.
- ☐Confirm whether existing onboarding or identity-verification workflows include an age-gating or age-assurance step that satisfies both Anthropic's policy and applicable regulations such as COPPA or the EU Digital Services Act.
- ☐Update vendor policy monitoring processes to track Anthropic's usage policies as a governed contractual dependency, so future changes to age or access restrictions trigger a re-assessment.
- ☐Document your organization's age-assurance approach in your AI system intake and risk assessment records to establish an audit-ready compliance trail.
- ☐Escalate any consumer-facing Claude deployments in education or youth-adjacent contexts to your legal and compliance team for a jurisdiction-specific review against applicable child safety regulations.
What to watch next
Regulators in the EU and US are actively developing more prescriptive age-verification requirements for online platforms, and AI services are increasingly within scope. The EU Digital Services Act, AI and Algorithmic Accountability Provisions already impose systemic risk assessment obligations on very-large online platforms, and enforcement is expanding. Compliance teams should monitor whether Anthropic issues additional operator guidance that specifies technical age-assurance standards, and whether the FTC or EU AI Office signals that AI chatbot providers will be treated as subject to platform-level child-protection duties independently of their deployers.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
