Home / Companies / Didit / Blog / August 2026

August 2026 Summaries

14 posts from Didit

Filter
Month: Year:
Post Summaries Back to Blog
The text outlines an architecture for identity verification and access management, focusing on three main layers: model controls, traffic detection, and verified access, with the latter built from priced primitives. It emphasizes the importance of collecting device and network data early on to aid future investigations, linking biometric data to establish account authenticity, and binding identity verification to significant account transitions. The enforcement layer blocklists confirmed fraud cases to prevent further access, while the cost model demonstrates that verification expenses are tied to new accounts and alert-driven checks, making the process cost-effective for large platforms. The architecture aims to reduce anonymity, raise the cost of fraudulent activity, and enhance security by integrating identity signals with semantic detection, although it does not eliminate model extraction risks outright.
Aug 04, 2026 1,903 words in the original blog post.
Implementing identity verification in front of an AI API poses a significant architecture challenge, focusing on determining when and for whom verification is necessary, rather than the verification process itself. The guide suggests a risk-based approach to verification, with access transitions such as quota increases or new key issuance being the appropriate triggers, rather than at the initial signup. A tiered system of access levels is recommended, comprising four main levels: anonymous/free, paid self-serve, high-quota/high-credit, and organization/research, each with different verification requirements and costs. Verification costs are tier-dependent, with more expensive checks reserved for higher-risk accounts, while reusable KYC and targeted verification help minimize friction for legitimate users. The guide emphasizes that identity verification serves as a response to behavioral alerts rather than a standalone detection mechanism, advocating for a workflow-based approach that allows for policy adjustments without code changes.
Aug 04, 2026 2,094 words in the original blog post.
Anthropic's 2026 report highlights the importance of strengthened verification for educational and startup accounts to combat distillation attacks, emphasizing the need for organization-tier access verification rather than just individual verification. This approach is crucial because educational, research, and startup programs often have lower verification thresholds due to their welcoming nature and institutional applicants. The report suggests using business verification to confirm an organization's existence, ownership, and control, including entity-level screening against sanctions lists. This involves a streamlined workflow where beneficial owners undergo linked identity verification within the same session, ensuring that the organization and its controllers are identifiable and screened. This verification process helps determine the legitimacy of an organization, with opacity in ownership or recent incorporations serving as indicators for further scrutiny. While verifying a company doesn't prevent misuse of access, it makes the counterparty attributable, which is vital for enforcement decisions. Business verification is positioned as a key component in a risk-tiered access architecture, especially for high-value grants, with public, pay-per-success pricing starting at $2.00 per company.
Aug 04, 2026 1,701 words in the original blog post.
Didit's device and network analysis focuses on detecting device-level abuse in account farming by identifying the reuse of a small pool of physical hardware and network paths to create a large number of accounts. By analyzing signals across duplication, integrity, and network categories, the system can distinguish between legitimate and suspicious activities. High-value codes like DEVICE_RECOVERED_HIGH_CONFIDENCE and AUTOMATION_FRAMEWORK_DETECTED indicate potential abuse, while duplication signals require corroboration. The analysis is priced at $0.03 per check or as part of a $0.33 full verification bundle, offering configurable warning actions to manage verification processes effectively. These insights are particularly useful for AI API platforms, marketplaces, and gig platforms to mitigate abuse through emulator farms and unauthorized account creation.
Aug 04, 2026 1,581 words in the original blog post.
Claude and ChatGPT can both connect to the Didit Model Context Protocol (MCP) service, but they access different tool catalogues due to endpoint policies rather than inherent limitations. Claude's connection grants access to 115 tools, including those for direct document and biometric checks, while ChatGPT's OpenAI app surface offers a restricted catalogue of 101 tools, excluding certain operations to maintain tighter data-input boundaries. Both utilize OAuth 2.1 with PKCE for authentication, and neither requires users to paste server application keys into chat. The choice between the two depends on the specific operational needs: Claude is suitable for broader authorized operations requiring direct checks, whereas ChatGPT is apt for workflows that fit public-app review boundaries and minimize raw personal data entry. Both clients can interact with a remote MCP server, but the practical differences lie in the contracts Didit exposes to each, with ChatGPT focused on conversational investigation and orchestration without raw biometric or document inputs.
Aug 03, 2026 1,524 words in the original blog post.
Didit's Model Context Protocol (MCP) server facilitates Anti-Money Laundering (AML) screening by allowing AI clients to check individuals or companies against over 1,300 global watchlists, including sanctions, Politically Exposed Persons (PEP), and adverse-media sources. The didit_verify_aml tool can be invoked directly without navigating a user interface or requiring an API key, offering features like structured hit reports and ongoing monitoring for a fee. The service is used by over 2,000 companies and is particularly relevant for fintechs and businesses engaged in cross-border transactions, as it provides essential compliance checks in the Know Your Customer (KYC) process. Priced at $0.20 per screen with 500 free verifications monthly, the platform also supports continuous monitoring at $0.07 per user annually. In cases of false positives, users can add review notes or manage the case lifecycle through various Didit tools, while more complex compliance tasks are handled in the Business Console. The MCP server, free and open-source, offers a streamlined experience by integrating with AI agents like Claude to perform rapid AML checks.
Aug 03, 2026 1,232 words in the original blog post.
Emerging standards like Visa Trusted Agent Protocol (TAP), Google Agent Payments Protocol (AP2), and Mastercard Agent Pay aim to make agent-led commerce safer by addressing various aspects of trust in transactions. TAP helps merchants recognize and verify approved agents, AP2 focuses on creating authorization evidence for user-intended purchases, and Agent Pay emphasizes agent recognition and payment credential security using tokenization. Despite these advances, there remains a need for identity proofing, risk screening, and compliance controls to ensure transaction legitimacy. Didit offers a neutral infrastructure for identity and fraud verification, with a Model Context Protocol (MCP) server that provides tools for identity verification and fraud checks, supporting these standards without being tied to any specific payment network. Developers are encouraged to consider necessary controls, such as enrollment, credential binding, and runtime risk decisions, when implementing these standards. Didit's offerings, including a REST API and an MCP server, provide flexible solutions for integrating identity verification into agent-driven payment processes, ensuring a layered and adaptable architecture that supports evolving standards.
Aug 03, 2026 1,601 words in the original blog post.
UK age assurance regulations are rapidly evolving, requiring businesses to implement robust systems for verifying user ages, particularly in the face of challenges posed by the widespread use of Virtual Private Networks (VPNs), which can obscure users' true locations. A multi-layered approach that combines document verification, biometric checks, and IP analysis is essential to ensure compliance and prevent minors from accessing age-restricted content. Key legislative frameworks like the Age Appropriate Design Code (AADC) and the forthcoming Online Safety Act (OSA) are critical considerations for businesses implementing these systems. Didit offers a comprehensive solution to these challenges, providing modular verification tools such as ID verification, biometric liveness detection, and age estimation, all orchestrated through a dynamic workflow system that adapts to VPN usage. This approach helps businesses balance user experience with regulatory compliance, offering a cost-effective and scalable way to meet UK age assurance requirements.
Aug 03, 2026 1,518 words in the original blog post.
AI agents have significantly accelerated the process of fraud by compressing the time between discovery, decision, and action, facilitating campaigns that operate at machine speed. Techniques such as credential stuffing, synthetic identity farms, deepfaked liveness, mule networks, prompt injection, and velocity abuse each present unique challenges and require a multifaceted approach to control. Didit provides an infrastructure for identity and fraud management, leveraging tools like document verification, passive and active liveness, face match, device and IP signals, transaction monitoring, and wallet screening to bind identity to behavior and detect fraudulent activities. The Model Context Protocol (MCP) allows agents to manage transactions, screen wallets, and handle cases, ensuring automation does not replace human oversight in critical decisions. By employing a layered architecture and governance that includes narrow OAuth scopes, schema validation, and human approvals, Didit ensures a comprehensive defense against fraud while maintaining accountability in automated systems.
Aug 03, 2026 1,601 words in the original blog post.
The review of 17 identity, fraud, and compliance vendors identified four companies—Sumsub, TRM Labs, Prove, and Plaid—with confirmed Model Context Protocol (MCP) implementations, each offering distinct functionalities such as operational verification, blockchain alert triage, documentation search, and diagnostic analytics. Stripe also operates an official MCP server, though its identity verification service is not included in the published toolset. Didit provides a free MCP server that supports a wide range of identity and operational tasks, including identity document checks and transaction monitoring, with an emphasis on OAuth-based authentication. For other vendors, no official MCP servers were confirmed, highlighting the need for ongoing verification of vendor capabilities, as many rely on third-party integration surfaces or have unconfirmed statuses. The evaluation of MCP servers should consider factors such as hosted versus local deployment, OAuth versus API key authentication, and the presence of open-source code and auditability to ensure security and operational needs are met.
Aug 03, 2026 1,538 words in the original blog post.
The Financial Conduct Authority (FCA) conducted a survey of 242 asset management and alternatives firms during 2025/26, focusing on their financial crime controls, and published the findings on 22 July 2026. The results highlighted significant gaps in anti-money laundering (AML) practices, particularly within private-markets firms, which reported a higher presence of politically exposed persons (PEPs) and more complex ownership structures compared to non-private-markets firms. Notably, 29% of the surveyed firms lacked a formal transaction monitoring process, and 18% did not have a formal customer risk assessment method. The survey also revealed that 40% of firms outsource customer due diligence checks, but only 36% maintained full oversight of these outsourced processes. More than half of the firms reported that their money laundering reporting officers work part-time or share roles, including at larger firms managing over £10 billion. The FCA's publication did not name firms, set enforcement actions, or penalties, but served as a benchmark for good and poor practices within the industry.
Aug 01, 2026 2,056 words in the original blog post.
Article 26 of the EU anti-money laundering regulation, specifically Regulation (EU) 2024/1624, establishes a framework for updating customer information that is both periodic and event-driven, depending on the risk level of the business relationship. The regulation sets maximum intervals for updates at one year for higher-risk customers and five years for lower-risk ones, but these are ceilings rather than prescribed cycles. The periodic reviews must be supplemented by event-driven reviews triggered by changes in customer circumstances, legal obligations regarding beneficial ownership, or awareness of relevant facts. Continuous monitoring is required for transactions, while customer information is governed by these review cycles. The draft guidelines published by the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) emphasize a risk-based approach without specifying fixed frequencies beyond the established limits, and the consultation on these guidelines remains open until 3 September 2026. The regulation highlights the dynamic nature of business verification compared to more static individual identity checks, pointing out that ownership and control details can quickly become outdated, necessitating ongoing vigilance.
Aug 01, 2026 2,073 words in the original blog post.
Between March 2025 and December 2026, six of Latin America's largest economies—Mexico, Peru, Argentina, Brazil, Chile, and Colombia—overhauled their identity and data protection laws in response to rising fraud rates and advances in technology, particularly artificial intelligence. This period saw Mexico introduce a biometric national ID, the CURP, incorporating fingerprints and photographs as mandatory, while Brazil established a legal framework for data exchange with the EU, allowing personal data to move freely without additional transfer instruments. Chile is set to enforce Law 21.719 by December 2026, which introduces a dedicated data protection agency and categorizes biometric data as sensitive, requiring stricter legal bases for processing. These changes reflect a regional trend towards tighter data protection and identity verification measures, with adaptation windows for compliance becoming increasingly narrow. The ongoing regulatory developments highlight the tension between governments enforcing stringent data protection rules and simultaneously mandating biometric credentials, posing complex compliance challenges for companies operating in the region.
Aug 01, 2026 2,797 words in the original blog post.
The Federal Communications Commission (FCC) is exploring new measures to combat illegal robocalls by potentially requiring phone companies to verify customer identities before allowing calls onto the network, drawing inspiration from banking sector regulations like the Bank Secrecy Act. The proposal, released on May 1, 2026, seeks comments on implementing customer verification processes similar to those used by banks, including collecting names, addresses, government-issued IDs, and alternate phone numbers. While the FCC has proposed a $2,500 fine per illegal call, no specific rules have been adopted yet. The initiative has garnered mixed responses, with 50 state attorneys general arguing the measures are insufficient, while financial trade associations support the alignment with banking standards. The FCC is considering whether to create a safe harbor for telecom providers using third-party verification services, yet no accreditation scheme currently exists. This ongoing effort reflects a broader strategy to integrate financial regulatory models into telecommunications to enhance consumer protection against fraudulent activities.
Aug 01, 2026 4,401 words in the original blog post.