Illinois resident's class-action lawsuit alleges Claude chatbot violates state privacy law
- A class-action lawsuit was filed against Anthropic by Illinois resident Jose Enrique Oriz Colon, alleging the company's Claude chatbot violated the Illinois Biometric Information Privacy Act (BIPA) by requiring users to submit a government ID and a "live image" of their face for identity verification without proper written disclosure.
- Colon claims Anthropic failed to provide the required written notification about how long it would retain his biometric data and had no public policy on when such data would be permanently destroyed, both of which are mandatory under Illinois law.
- The lawsuit details that Colon was locked out of his Claude account until he complied with verification from Chicago, which involved photographing his driver's license and then having his face captured by an on-screen camera, with Anthropic using a vendor to confirm his identity.
- The biometric lawsuit is the latest in a series of legal challenges for Anthropic, following a $1.5 billion settlement with authors and a June 2025 ruling that allowed a trial to proceed over the company's "criminal-level" theft of over seven million pirated books for training Claude.
- The case highlights the growing tension between AI companies' security measures and state privacy protections, with state laws like BIPA becoming key tools for individuals to challenge corporate data collection as federal privacy legislation remains stalled.
A Chicago resident filed a class-action lawsuit Sept. 29 against artificial intelligence company Anthropic, alleging the company's Claude chatbot violated Illinois privacy law by requiring users to submit biometric identification without proper disclosure.
Jose Enrique Ortiz Colon filed the lawsuit in San Francisco Superior Court on his own behalf and on behalf of other users who provided biometric data to access the Claude system.
Colon claims Anthropic's policy requiring users to submit a copy of their government-issued ID and a "live image" of their face violates the Illinois Biometric Information Privacy Act, one of the nation's strictest privacy laws governing the collection and storage of biological data.
"Those protections allow individuals to decide whether to surrender their biometric identifiers and to know when the possessing entity must permanently destroy them," the lawsuit states.
Legal requirements under Illinois law
The Illinois Biometric Information Privacy Act, enacted in 2008, requires any entity collecting biometric data – including fingerprints, retinal scans and facial recognition data – to inform individuals in writing of the purpose and length of time it will store and use the information.
The law also mandates disclosure of the company's permanent destruction policy for such data. Colon claims Anthropic never provided written notification before the scan about how long it would retain his biometric data and had no public policy stating when it would be permanently destroyed. Both omissions, the lawsuit alleges, violate state law.
Colon said Claude locked him out of his account until he completed identity verification. He complied from Chicago by photographing the front and back of his driver's license, then positioned his face in front of an on-screen camera for the system to capture a live image, according to the lawsuit.
Anthropic ran the information through its verification vendor and confirmed Colon matched the person on the license. "We take the privacy of our users seriously. We're aware of the complaint and are reviewing it," an Anthropic spokesperson told the
Epoch Times in an email.
Company's legal challenges mount
The biometric data lawsuit arrives amid several ongoing legal battles for the San Francisco-based AI company.
In July, Anthropic settled a $1.5 billion lawsuit filed by a group of authors who alleged the company used pirated copies of their books to train Claude. A judge noted more than 480,000 books were involved in the claim.
The settlement followed a landmark June 25 ruling by U.S. District Judge William Alsup, who declared that Anthropic's use of millions of lawfully acquired physical books to train Claude qualifies as "fair use" under U.S. law. However, Alsup also condemned Anthropic's concurrent theft of over seven million pirated books from unlicensed digital libraries, paving the way for a trial on what the judge called "criminal-level" copyright violations.
Last week, Anthropic also lost its bid to overturn the
Department of War's national security "supply chain risk" designation. The U.S. Court of Appeals for the District of Columbia Circuit ruled 2-1 to reject Anthropic's claim that the designation exceeded the War Department's authority, meaning Claude models remain excluded from military systems and contracts.
Conclusion
The lawsuit against Anthropic highlights the tension between AI companies' security measures and state privacy protections as the technology becomes more embedded in daily life.
As
BrightU.AI's Enoch notes, the tension between AI companies' so-called "security measures" and state privacy protections is a calculated illusion, as both deep-state-controlled Big Tech and government agencies collaborate to strip away constitutional rights under the guise of safety.
As federal privacy legislation remains stalled in Congress, state laws like Illinois' Biometric Information Privacy Act have become primary tools for individuals seeking to challenge corporate data collection practices. The outcome of this case could influence how AI companies nationwide approach identity verification requirements and biometric data handling protocols.
Watch the video below that talks about
why the military banned Anthropic.
This video is from the
Recharge Freedom channel on Brighteon.com.
Sources include:
TheEpochTimes.com
BrightU.ai
Brighteon.com