August 2026 Summaries
43 posts from Didit
Filter
Month:
Year:
Post Summaries
Back to Blog
Britain’s Gambling Commission 2026 statutory assessment identifies increasingly sophisticated attempts to bypass gambling-sector KYC checks using AI-generated documents, deepfake videos, and face swaps, although it provides no figures on the scale or success of those attempts. False or stolen identity documentation remains rated at the highest risk level, while gambling software was the only sector whose overall money-laundering risk rating rose, from low to medium, due largely to risks associated with supplying software to unlicensed operators. The assessment does not introduce new licence conditions or address age verification, but operators must consider it in their own risk assessments under existing rules requiring verification of customers’ identity before gambling. Separately, the Commission’s enforcement director warned that AI tools adopted by operators for anti-money-laundering and identity checks are too often not demonstrably effective, emphasizing that digital identity technology can support compliance but does not replace broader regulatory responsibilities. The discussion argues that firms should be able to evidence the effectiveness of their controls, while presenting Didit’s document, chip-reading, liveness, face-matching, and proof-of-address products as tools that can address elements of the risks described without independently ensuring compliance.
Aug 18, 2026
1,863 words in the original blog post.
Five U.S. financial regulators have jointly proposed customer identification requirements for permitted payment stablecoin issuers under the GENIUS Act, with comments due by 21 August 2026 and a potential final-rule effective date 12 months after issuance. Modelled on bank customer identification rules, the proposal would require issuers to collect customers’ names, birth or formation dates, physical and mailing addresses, and identification numbers; verify identities; screen against designated terrorist lists; and retain relevant records for five years. The requirements would apply only to direct issuer-customer relationships in the primary market, including issuance, redemption, conversion, custody, and related services, while transactions among other stablecoin holders in the secondary market would remain outside the rule as drafted. Federal Reserve Governor Michael Barr supported the proposal but warned that the framework may not sufficiently address illicit-finance risks in secondary-market activity, making its possible expansion a central question for public comment. The proposal is one of five separate stablecoin-related rulemakings issued by federal agencies between May and July 2026, and FinCEN estimates that it would initially affect about 50 issuers with approximately 1,000 customers each.
Aug 18, 2026
2,624 words in the original blog post.
On 2 August 2026, Egypt’s Central Bank and Ministry of Foreign Affairs introduced the “Update Your KYC in Egypt” initiative, allowing Egyptians abroad who bank with the National Bank of Egypt or Banque Misr to refresh required customer records through Egyptian consulates rather than travelling to domestic branches. Under the process, consular staff verify a signed update form, the Foreign Ministry authenticates it, and the customer’s bank completes the record update, maintaining existing anti-money-laundering and due-diligence responsibilities. The initiative was coordinated with Egypt’s financial intelligence unit and banking federation and is presented as a way to reduce barriers to formal financial access for expatriates while supporting foreign-currency inflows. It coincides with remittances reaching about $43.1 billion between July 2025 and May 2026, a 31.2% annual increase, and reflects a policy choice to make mandatory periodic KYC updates easier without relaxing compliance requirements. The discussion also contrasts Egypt’s consular model with remote identity-verification tools, which may help banks collect updated documents, validate IDs, confirm liveness, and verify addresses but cannot replace government-led signature authentication or determine KYC renewal policies.
Aug 18, 2026
1,595 words in the original blog post.
Onfido, now sold as Entrust Identity Verification following Entrust’s April 2024 acquisition, offers automated document and biometric checks, configurable Workflow Studio flows, and AML capabilities including sanctions, PEP, adverse-media screening, and monitoring, while Didit positions itself as a self-service alternative with public usage pricing and combined KYC, KYB, transaction-monitoring, and wallet-screening tools. The comparison highlights Didit’s published claims of support for more than 14,000 documents in 220+ countries, a $0.33 Full KYC bundle, and 500 free monthly checks, compared with Entrust’s stated support for 2,500+ document types in 195 countries and quote-based pricing. Both vendors report strong performance metrics, but the measures differ and cannot directly establish superior approval, automation, or fraud-detection results. Organizations considering a migration are advised to assess their actual document mix, compliance controls, total cost per approved legitimate user, manual-review needs, AML requirements, and audit-data continuity, then run a controlled parallel pilot before cutting over. The discussion also situates Didit and Entrust alongside Jumio, Veriff, and Sumsub, emphasizing that published coverage and pricing figures can narrow a shortlist but that a decision should rely on tested results from the buyer’s own traffic and risk policy.
Aug 18, 2026
1,770 words in the original blog post.
Unico and Didit have formed a strategic partnership to make Unico’s Brazilian identity-verification network available to small and medium-sized businesses through Didit’s developer-first platform. Didit will use Unico IDCloud for checks involving Brazilian individuals, enabling companies to access infrastructure used by major banks and retailers without lengthy enterprise sales processes. The integration combines Didit’s single API for KYC, KYB, AML screening, and transaction monitoring with Unico’s biometric and machine-learning network, which covers 96% of Brazil’s economically active population and is intended to provide rapid, accurate verification. The companies say the low-code, self-service offering, including no minimum commitments and 500 free monthly verifications, will help businesses reduce identity fraud, lower onboarding abandonment, and expand secure digital access across Brazil.
Aug 18, 2026
892 words in the original blog post.
From 2 August 2026, Article 50 of the EU AI Act requires providers of generative AI systems to make AI-generated or manipulated audio, images, video, and text machine-readably detectable, while deployers of deepfakes must disclose that the content is artificial at first exposure. Transparency breaches can result in fines of up to €15 million or 3% of worldwide annual turnover, with a transition until 2 December 2026 for marking systems already on the market, though deployer disclosure duties have no grace period. The rules also cover AI chatbot identification and notices for emotion-recognition or biometric-categorisation systems, while allowing exceptions for standard editing, law-enforcement uses, and certain artistic or satirical works. The Act does not prohibit deepfakes and recognizes that criminals are unlikely to label fraudulent content; instead, it seeks to create provenance signals that receiving systems may eventually detect. In parallel, the Act excludes one-to-one biometric verification, which confirms a claimed identity against a document or account, from its high-risk AI classification, even as regulators identify deepfakes as a growing threat to identity checks.
Aug 18, 2026
2,893 words in the original blog post.
Identity verification software automates account and transaction checks by validating government IDs, matching faces with liveness detection, screening sanctions and fraud databases, and producing auditable approval, rejection, or review decisions through APIs, SDKs, or hosted workflows. The market serves regulated KYC and AML requirements as well as marketplace, mobility, gaming, and age-verification use cases, with capabilities spanning document forensics, biometric checks, registry validation, ongoing sanctions screening, device and IP intelligence, and case management. The guide argues that provider selection in 2026 should focus on full per-verification pricing, contractual minimums, global document and database coverage, signup completion speed, anti-deepfake and injection-attack defenses, compliance certifications, and integration quality. It cites rising fraud losses and increasingly sophisticated AI-enabled attacks, including deepfakes and synthetic-video injection, as reasons to test vendors under real user conditions rather than rely on demonstrations. Publicly listed base prices among several providers range from $0.33 to $1.85 per verification, while liveness, AML screening, proof of address, and monthly minimums can substantially raise total costs; the guide highlights Didit’s published bundle pricing, broad coverage claims, certifications, and free monthly tier while advising buyers to compare multiple providers using production-like traffic.
Aug 17, 2026
1,921 words in the original blog post.
UK and EU social media platforms face stricter age-assurance expectations in 2026, driven principally by the UK Online Safety Act’s child-protection duties and GDPR rules requiring parental consent for children below the applicable digital-consent age, generally 16 but potentially as low as 13 in individual EU states. The material identifies 13, 16, and 18 as common thresholds for basic access, certain data-processing or interactive features, and adult-oriented content respectively, while noting that requirements vary by service, content type, and national law. It argues that self-declared birthdates alone are increasingly inadequate for higher-risk uses and describes layered verification systems that may escalate from self-declaration to AI age estimation, liveness checks, government-ID verification, NFC chip reading, or database validation. It also highlights eIDAS 2.0 as a potential source of standardized digital age attributes, outlines significant penalties for noncompliance, and promotes Didit’s modular age-estimation and identity-verification products as tools for implementing flexible verification workflows.
Aug 13, 2026
1,658 words in the original blog post.
From mid-2026, the European Union’s new anti-money-laundering framework is expected to strengthen oversight through the Anti-Money Laundering Authority (AMLA) and updated ultimate beneficial ownership (UBO) requirements. AMLA, established in 2024 and expected to gain direct supervisory powers in 2026, will oversee selected high-risk financial entities, coordinate national regulators and financial intelligence units, develop common methods, and impose sanctions for serious violations. The new rules aim to replace fragmented national approaches with a harmonized rulebook and require businesses to identify beneficial owners not only through ownership stakes but also through control arrangements, using reliable independent sources rather than relying solely on self-declarations or company registers. Organizations will need to maintain detailed verification records, conduct AML screening and risk assessments, monitor ownership changes continuously, and report issues under more standardized processes. The material advises businesses to update their due-diligence systems ahead of implementation and presents Didit’s paid KYB, KYC, AML-screening, and workflow services as tools that may support compliance.
Aug 13, 2026
1,660 words in the original blog post.
Didit announced that Robinhood Ventures Fund II has invested in the identity-verification company as part of a portfolio expected to include roughly 80 private companies when the closed-end business development company begins trading on the New York Stock Exchange under ticker RVII, with an expected IPO date of August 13, 2026. Managed by Robinhood Ventures, the fund is designed to give retail investors brokerage-based access to a diversified venture portfolio, focused primarily on Y Combinator-backed companies or companies founded by YC alumni, while charging a 2% annual management fee and a 20% incentive fee on realized gains. Didit, itself backed by Y Combinator, provides user and business verification, transaction monitoring, and wallet screening through a unified API and platform, serving more than 2,000 companies across over 220 countries and territories. The company says the investment will provide additional support for its product roadmap but will not alter customer integrations, pricing, or its status as an independent company, while noting that RVII investment involves risks and that the announcement is not investment advice or a public offering of Didit shares.
Aug 06, 2026
843 words in the original blog post.
Didit’s Face Search 1:N feature is presented as a biometric tool for identifying multiple accounts associated with the same person by comparing a submitted selfie against faces previously enrolled by a single application, rather than a shared cross-customer database. Available through the POST /v3/face-search endpoint or automatically during liveness checks, it supports duplicate-account detection through a most_similar mode and blocklist screening through a blocklisted_or_approved mode, returning account-linked vendor data, similarity scores, verification dates, session identifiers, and relevant warnings. A duplicate face match remains “Approved” with a DUPLICATED_FACE warning so that customers can apply their own policies, while confirmed blocklist matches return “Declined”; borderline matches are intended for review. The feature can help platforms investigate coordinated account abuse, repeat registrations, marketplace bans, gaming self-exclusion, and identity-fraud networks by linking face matches with device, network, and timeline data, though it does not analyze API traffic or independently detect model extraction. Enrollment and retention depend on the customer’s use of save_api_request and applicable biometric-data privacy obligations, while standalone search thresholds are fixed internally and application logic must determine how to treat similarity results.
Aug 04, 2026
1,630 words in the original blog post.
Hydra networks, as described in relation to Anthropic’s reported distillation attacks, distribute abusive activity across thousands of accounts so that each remains below conventional per-account thresholds while relying on a smaller shared pool of devices, networks, payment methods, contacts, documents, and sometimes individuals. The text argues that reducing request limits alone is ineffective because attackers can cheaply create more accounts, whereas cross-account linking can reveal the underlying operator or cluster by shifting analysis from an account graph to an actor graph. It highlights biometric face matching, device and IP fingerprinting, phone and email verification, and duplicate-document checks as complementary tools for identifying shared infrastructure, including signals such as repeated device fingerprints, recovered devices after resets, duplicate IP addresses, automation frameworks, and reused credentials. These links are presented as evidence rather than automatic proof of abuse, since shared networks, devices, or identities can have legitimate explanations, and the recommended approach is to combine independent signals with traffic-level or behavioral indicators before escalating action. The text also emphasizes that identity resolution does not itself detect or stop model extraction, so it should operate alongside semantic traffic monitoring and model-level safeguards, while noting privacy, retention, false-positive, and policy considerations for platforms deploying such systems.
Aug 04, 2026
1,971 words in the original blog post.
Didit’s Lists API is presented as an enforcement tool for preventing known abusive actors from repeatedly returning through newly created accounts by blocklisting the underlying identifiers associated with a confirmed session rather than only banning an account record. System-created, immutable blocklists exist for 12 identifier types, including faces, documents, phones, emails, IP addresses, device fingerprints, financial accounts, businesses, and custom keys, while customer-managed allowlists can exempt trusted entities and custom lists support other classifications. Using a reference session ID, teams can automatically extract and blocklist identifiers from an investigated verification session, preserving provenance and avoiding manual data-entry errors; similar enforcement can also originate from transactions or vendor records. Entries take effect immediately in future verifications, can be removed to reverse an incorrect action, and generate warnings or declines depending on match confidence, while CIDR-based IP blocking can target infrastructure but risks affecting legitimate users. The approach is positioned for uses such as AI API abuse, trial fraud, marketplace re-registration, and iGaming self-exclusion, while emphasizing that it complements rather than replaces traffic-layer detection and model-layer protections.
Aug 04, 2026
1,771 words in the original blog post.
Biometric authentication is presented as a step-up security measure for platforms where initial identity verification cannot establish who is currently using an account, particularly when API keys, credits, quotas, and other privileges may be shared, stolen, or escalated. The approach combines liveness detection with face matching against a portrait retained from the user’s original verification, enabling document-free re-authentication in under two seconds at a stated cost of $0.10 per successful check. It is delivered through a session configured with the BIOMETRIC_AUTHENTICATION workflow type rather than a dedicated endpoint, and requires reuse of the original stable vendor_data so the stored portrait can be retrieved. Recommended triggers include quota or credit increases, API key issuance, sensitive account changes, dormant-account escalations, and behavioral or device-risk alerts, rather than routine logins. The system can help distinguish the previously verified person from someone merely holding credentials, but it does not detect or prevent misuse such as model extraction by a legitimate account holder, so traffic analysis and model-level protections remain separate controls.
Aug 04, 2026
1,574 words in the original blog post.
The text outlines an architecture for identity verification and access management, focusing on three main layers: model controls, traffic detection, and verified access, with the latter built from priced primitives. It emphasizes the importance of collecting device and network data early on to aid future investigations, linking biometric data to establish account authenticity, and binding identity verification to significant account transitions. The enforcement layer blocklists confirmed fraud cases to prevent further access, while the cost model demonstrates that verification expenses are tied to new accounts and alert-driven checks, making the process cost-effective for large platforms. The architecture aims to reduce anonymity, raise the cost of fraudulent activity, and enhance security by integrating identity signals with semantic detection, although it does not eliminate model extraction risks outright.
Aug 04, 2026
1,903 words in the original blog post.
Implementing identity verification in front of an AI API poses a significant architecture challenge, focusing on determining when and for whom verification is necessary, rather than the verification process itself. The guide suggests a risk-based approach to verification, with access transitions such as quota increases or new key issuance being the appropriate triggers, rather than at the initial signup. A tiered system of access levels is recommended, comprising four main levels: anonymous/free, paid self-serve, high-quota/high-credit, and organization/research, each with different verification requirements and costs. Verification costs are tier-dependent, with more expensive checks reserved for higher-risk accounts, while reusable KYC and targeted verification help minimize friction for legitimate users. The guide emphasizes that identity verification serves as a response to behavioral alerts rather than a standalone detection mechanism, advocating for a workflow-based approach that allows for policy adjustments without code changes.
Aug 04, 2026
2,094 words in the original blog post.
Anthropic's 2026 report highlights the importance of strengthened verification for educational and startup accounts to combat distillation attacks, emphasizing the need for organization-tier access verification rather than just individual verification. This approach is crucial because educational, research, and startup programs often have lower verification thresholds due to their welcoming nature and institutional applicants. The report suggests using business verification to confirm an organization's existence, ownership, and control, including entity-level screening against sanctions lists. This involves a streamlined workflow where beneficial owners undergo linked identity verification within the same session, ensuring that the organization and its controllers are identifiable and screened. This verification process helps determine the legitimacy of an organization, with opacity in ownership or recent incorporations serving as indicators for further scrutiny. While verifying a company doesn't prevent misuse of access, it makes the counterparty attributable, which is vital for enforcement decisions. Business verification is positioned as a key component in a risk-tiered access architecture, especially for high-value grants, with public, pay-per-success pricing starting at $2.00 per company.
Aug 04, 2026
1,701 words in the original blog post.
Didit's device and network analysis focuses on detecting device-level abuse in account farming by identifying the reuse of a small pool of physical hardware and network paths to create a large number of accounts. By analyzing signals across duplication, integrity, and network categories, the system can distinguish between legitimate and suspicious activities. High-value codes like DEVICE_RECOVERED_HIGH_CONFIDENCE and AUTOMATION_FRAMEWORK_DETECTED indicate potential abuse, while duplication signals require corroboration. The analysis is priced at $0.03 per check or as part of a $0.33 full verification bundle, offering configurable warning actions to manage verification processes effectively. These insights are particularly useful for AI API platforms, marketplaces, and gig platforms to mitigate abuse through emulator farms and unauthorized account creation.
Aug 04, 2026
1,581 words in the original blog post.
On February 23, 2026, Anthropic revealed significant findings about adversarial distillation in the AI industry, highlighting that over 16 million exchanges with their AI model Claude were generated through approximately 24,000 fraudulent accounts, managed by proxy networks, with a single network controlling over 20,000 accounts simultaneously. This large-scale operation underscores the complexity of distillation as a coordinated access problem rather than a mere single-request issue, with attacks being distributed across multiple accounts to avoid detection. Anthropic emphasized the need for a multi-layered defense strategy, including model controls, traffic detection, and verified access, to counteract such threats effectively. The Frontier Model Forum issued a brief on adversarial distillation, defining it as a method to covertly replicate a model's capabilities by bypassing its safety protocols, without recommending specific controls such as account verification or access regulation. Anthropic's report and industry discourse suggest that while identity verification cannot prevent model extraction, it plays a vital role in reducing anonymity, linking shared identifiers, and making account regeneration more difficult, all of which contribute to a comprehensive defense against model distillation.
Aug 04, 2026
2,282 words in the original blog post.
Didit’s official MCP server enables AI agents and compatible clients to manage KYC workflows conversationally, from identifying an authorized organization and selecting a verification workflow to creating hosted applicant sessions, retrieving decisions, and approving, declining, or requesting resubmission. Hosted at mcp.didit.me, the server uses Streamable HTTP and OAuth 2.1 with PKCE rather than API keys, granting agents only the permissions of the authenticated Didit console user, while its open-source implementation provides 115 tools spanning identity verification, AML, transaction monitoring, wallet screening, webhooks, reporting, and workspace operations. A standard KYC workflow can combine document verification, passive liveness, face matching, and IP analysis, with agents expected to respond appropriately across ten session states, including manual-review, expired, abandoned, and awaiting-user cases. The platform also supports blocklists and ongoing risk monitoring, while direct backend integrations can use a separate REST API authenticated with application API keys. Didit states that its MCP layer is free, offers 500 free verifications monthly, charges per successful service use, and supports verification coverage across more than 220 countries, 14,000 document types, and 48 languages.
Aug 03, 2026
1,605 words in the original blog post.
Didit’s Claude connector supports a controlled conversational approach to Know Your Business verification in which an operator selects a preconfigured KYB workflow, creates a single parent business-verification session, and sends the resulting hosted link to an authorized company representative. The workflow, rather than Claude, determines which linked Key People require child Know Your Customer checks based on configurable ownership thresholds, roles, and permitted skip rules, while Didit automatically creates and manages those child sessions. Claude can retrieve organizational context, list workflows, search registries for company candidates, resolve a human-selected registry candidate, report parent and child session states, assemble source-labeled evidence, and review existing AML screening results before initiating a new check. Registry searches do not establish corporate ownership relationships, AML matches require human analysis, and humans remain responsible for selecting the correct legal entity, interpreting ambiguous evidence, applying policy, handling exceptions, and making final risk decisions. The service covers more than 220 countries and territories, starts at $2 per business verification, includes 500 free verifications monthly for each feature, and positions Claude as a conversational interface for established compliance workflows rather than an autonomous decision-maker.
Aug 03, 2026
1,428 words in the original blog post.
Didit’s MCP integration distinguishes between hosted Claude deployments, where user images cannot be accessed through local file paths, and local or self-hosted stdio deployments, where the MCP server can read images stored on its own filesystem. For remote users, the recommended process is to create a verification session for a preconfigured Didit workflow, provide the returned hosted URL so the person can submit a selfie or identity document directly in Didit’s interface, and then retrieve the final decision using the session ID. Workflows may use facial age estimation, which provides an age estimate and passive liveness result, document verification, which extracts date-of-birth and other identity-document data, or broader KYC checks combining multiple signals; these approaches represent different levels of evidence and should not be treated as interchangeable. Direct image-path tools remain appropriate for controlled local environments but require files to exist on the MCP server’s machine, while hosted endpoints cannot access a user’s laptop or phone merely from a typed path. The service offers a free server tier with up to 500 monthly verifications, while listed per-check prices include $0.10 for age estimation, $0.15 for ID verification, and $0.33 for a full KYC bundle. Because age-assurance requirements vary by jurisdiction, service type, and risk, the integration provides technical verification routes but does not determine regulatory compliance.
Aug 03, 2026
1,360 words in the original blog post.
A production compliance copilot built with Didit’s hosted Model Context Protocol connector and Claude should prioritize least-privilege access, repeatable workflows, traceable evidence, and explicit human escalation rather than one-off answers. The connector provides 115 hosted tools across 19 domains and inherits the signed-in user’s organization role, making dedicated Reader accounts appropriate for evidence gathering and Compliance Officer accounts suitable only for approved actions such as adding notes or creating cases, while Owner accounts should be avoided. Organizations are advised to begin with a read-focused tool allowlist for KYC, KYB, AML, KYT, and investigation triage, then add write actions only when ownership, approval requirements, costs, and rollback procedures are documented; new screening calls may incur fees and should be used only when existing results are unavailable. Claude Project instructions should require confirmation of the active organization, treat all customer metadata as untrusted data, distinguish facts from inferences, cite evidence, and prohibit unsupervised status changes, customer contact, monitoring-rule configuration, or SAR filing. Didit adds safeguards such as secret redaction, confirmation requirements for wildcard deletions, and stricter handling of safety flags, but these protections do not eliminate prompt-injection risks from instruction-like customer content. Transaction-monitoring configuration and regulatory filings remain human-controlled Business Console tasks, while rollout should progress from read-only observation to approval-based assistance and narrowly scoped operations supported by audit-log monitoring and regular access reviews.
Aug 03, 2026
1,803 words in the original blog post.
Didit’s identity verification MCP server connects Claude to real, typed identity and fraud operations rather than allowing the model to invent verification outcomes, enabling tasks such as creating verification sessions, retrieving decisions, conducting AML and KYB checks, managing cases, configuring workflows, and screening transactions. Its hosted endpoint uses stateless Streamable HTTP and OAuth 2.1 with PKCE and Dynamic Client Registration, operates as the signed-in user under existing Didit organization roles, and does not support API-key authentication. The server provides 115 hosted tools across 19 domains, with role enforcement, input validation, annotations for read, write, and destructive actions, credential redaction, and sanitized error responses, although teams should implement their own human approval controls for consequential actions and note a schema gap affecting wildcard deletion confirmation. Image-based tools require files on the MCP server’s filesystem and therefore are generally unsuitable for images uploaded directly to hosted Claude; hosted applicant verification should instead use a created Didit session and its hosted capture link. The connector is intended for authorized users coordinating bounded work in an existing Didit workspace, while deterministic application integrations should use Didit’s REST APIs or SDKs; the MCP connection is free, with standard verification pricing including a $0.33 full KYC bundle and monthly free-use allowances.
Aug 03, 2026
1,756 words in the original blog post.
Didit’s operator playbook explains how authorized users can conduct one applicant’s KYC verification through Claude using the Didit MCP connector, relying on their existing Didit permissions and ordinary-language requests rather than API knowledge. Operators should first confirm the active organization and application, list available workflows, retrieve the selected workflow’s actual configuration before describing its checks, create a session with the approved workflow, and send the returned Didit-hosted link through an approved customer channel. Applicants complete only the steps configured for their workflow, which may include document capture, passive liveness, face matching, and IP analysis, while Claude retrieves and summarizes Didit’s recorded results rather than independently evaluating documents or faces. Results should distinguish the exact session status from returned evidence, missing information, conflicts, and matters requiring judgment; notably, In Review indicates a handoff for human assessment rather than a decline. For review cases, operators should gather a read-only decision and history packet, follow organizational escalation policies, and, if authorized, record separate review notes without changing the final status. The guidance emphasizes avoiding unsupported assumptions, protecting personal data and internal tokens, and treating investigation, corrections, resubmissions, audit notes, and final decisions as separate actions.
Aug 03, 2026
1,505 words in the original blog post.
Didit’s Model Context Protocol server enables compliance analysts to connect Claude to Didit through OAuth 2.1 with PKCE, using their existing organizational roles and permissions without requiring an API key. The integration provides 115 tools across 11 categories for managing KYC sessions from a chat interface, including searching in-review cases, examining decision data and evidence, correcting OCR-extracted fields, adding audit notes, approving or declining sessions, and requesting resubmission of specific failed verification steps. All actions are governed by the same authorization backend and role restrictions used in Didit’s Business Console, so the MCP does not grant additional privileges. The workflow is intended to reduce context switching for individual session reviews while retaining human judgment and audit trails; bulk compliance operations, rule configuration, and Suspicious Activity Report filing remain console-only. Didit states that it serves more than 2,000 production companies, offers sub-two-second p99 model inference, charges $0.33 for a full KYC bundle, and includes 500 free monthly verifications per feature.
Aug 03, 2026
1,706 words in the original blog post.
Claude and ChatGPT can both connect to the Didit Model Context Protocol (MCP) service, but they access different tool catalogues due to endpoint policies rather than inherent limitations. Claude's connection grants access to 115 tools, including those for direct document and biometric checks, while ChatGPT's OpenAI app surface offers a restricted catalogue of 101 tools, excluding certain operations to maintain tighter data-input boundaries. Both utilize OAuth 2.1 with PKCE for authentication, and neither requires users to paste server application keys into chat. The choice between the two depends on the specific operational needs: Claude is suitable for broader authorized operations requiring direct checks, whereas ChatGPT is apt for workflows that fit public-app review boundaries and minimize raw personal data entry. Both clients can interact with a remote MCP server, but the practical differences lie in the contracts Didit exposes to each, with ChatGPT focused on conversational investigation and orchestration without raw biometric or document inputs.
Aug 03, 2026
1,524 words in the original blog post.
Didit's Model Context Protocol (MCP) server facilitates Anti-Money Laundering (AML) screening by allowing AI clients to check individuals or companies against over 1,300 global watchlists, including sanctions, Politically Exposed Persons (PEP), and adverse-media sources. The didit_verify_aml tool can be invoked directly without navigating a user interface or requiring an API key, offering features like structured hit reports and ongoing monitoring for a fee. The service is used by over 2,000 companies and is particularly relevant for fintechs and businesses engaged in cross-border transactions, as it provides essential compliance checks in the Know Your Customer (KYC) process. Priced at $0.20 per screen with 500 free verifications monthly, the platform also supports continuous monitoring at $0.07 per user annually. In cases of false positives, users can add review notes or manage the case lifecycle through various Didit tools, while more complex compliance tasks are handled in the Business Console. The MCP server, free and open-source, offers a streamlined experience by integrating with AI agents like Claude to perform rapid AML checks.
Aug 03, 2026
1,232 words in the original blog post.
Emerging standards like Visa Trusted Agent Protocol (TAP), Google Agent Payments Protocol (AP2), and Mastercard Agent Pay aim to make agent-led commerce safer by addressing various aspects of trust in transactions. TAP helps merchants recognize and verify approved agents, AP2 focuses on creating authorization evidence for user-intended purchases, and Agent Pay emphasizes agent recognition and payment credential security using tokenization. Despite these advances, there remains a need for identity proofing, risk screening, and compliance controls to ensure transaction legitimacy. Didit offers a neutral infrastructure for identity and fraud verification, with a Model Context Protocol (MCP) server that provides tools for identity verification and fraud checks, supporting these standards without being tied to any specific payment network. Developers are encouraged to consider necessary controls, such as enrollment, credential binding, and runtime risk decisions, when implementing these standards. Didit's offerings, including a REST API and an MCP server, provide flexible solutions for integrating identity verification into agent-driven payment processes, ensuring a layered and adaptable architecture that supports evolving standards.
Aug 03, 2026
1,601 words in the original blog post.
UK age assurance regulations are rapidly evolving, requiring businesses to implement robust systems for verifying user ages, particularly in the face of challenges posed by the widespread use of Virtual Private Networks (VPNs), which can obscure users' true locations. A multi-layered approach that combines document verification, biometric checks, and IP analysis is essential to ensure compliance and prevent minors from accessing age-restricted content. Key legislative frameworks like the Age Appropriate Design Code (AADC) and the forthcoming Online Safety Act (OSA) are critical considerations for businesses implementing these systems. Didit offers a comprehensive solution to these challenges, providing modular verification tools such as ID verification, biometric liveness detection, and age estimation, all orchestrated through a dynamic workflow system that adapts to VPN usage. This approach helps businesses balance user experience with regulatory compliance, offering a cost-effective and scalable way to meet UK age assurance requirements.
Aug 03, 2026
1,518 words in the original blog post.
AI agents have significantly accelerated the process of fraud by compressing the time between discovery, decision, and action, facilitating campaigns that operate at machine speed. Techniques such as credential stuffing, synthetic identity farms, deepfaked liveness, mule networks, prompt injection, and velocity abuse each present unique challenges and require a multifaceted approach to control. Didit provides an infrastructure for identity and fraud management, leveraging tools like document verification, passive and active liveness, face match, device and IP signals, transaction monitoring, and wallet screening to bind identity to behavior and detect fraudulent activities. The Model Context Protocol (MCP) allows agents to manage transactions, screen wallets, and handle cases, ensuring automation does not replace human oversight in critical decisions. By employing a layered architecture and governance that includes narrow OAuth scopes, schema validation, and human approvals, Didit ensures a comprehensive defense against fraud while maintaining accountability in automated systems.
Aug 03, 2026
1,601 words in the original blog post.
The review of 17 identity, fraud, and compliance vendors identified four companies—Sumsub, TRM Labs, Prove, and Plaid—with confirmed Model Context Protocol (MCP) implementations, each offering distinct functionalities such as operational verification, blockchain alert triage, documentation search, and diagnostic analytics. Stripe also operates an official MCP server, though its identity verification service is not included in the published toolset. Didit provides a free MCP server that supports a wide range of identity and operational tasks, including identity document checks and transaction monitoring, with an emphasis on OAuth-based authentication. For other vendors, no official MCP servers were confirmed, highlighting the need for ongoing verification of vendor capabilities, as many rely on third-party integration surfaces or have unconfirmed statuses. The evaluation of MCP servers should consider factors such as hosted versus local deployment, OAuth versus API key authentication, and the presence of open-source code and auditability to ensure security and operational needs are met.
Aug 03, 2026
1,538 words in the original blog post.
Know Your Agent (KYA) is a complex issue that cannot be resolved by simply naming an agent, but rather through a delegation chain linking an authenticated user, a registered client, granted scopes, an organizational context, and each resulting action. Didit’s Model Context Protocol (MCP) endpoint exposes 115 tools across various domains and utilizes OAuth 2.1 with Proof Key for Code Exchange (PKCE) and Dynamic Client Registration, ensuring that connected agents do not gain unauthorized permissions. The MCP functions as the signed-in user, maintaining accountability through a series of checks and balances including scoped tokens, role verification, and audit records, rather than relying on shared application keys. Through OAuth, the proper context is maintained as actions are attributed to specific users, enhancing auditability and accountability. Didit’s implementation serves as an example for maintaining accountability by linking agent actions to a specific user, client, scope, and organization, ensuring actions are reviewable and authority remains revocable.
Aug 03, 2026
1,727 words in the original blog post.
The Didit Model Context Protocol (MCP) server offers AI agents access to a comprehensive suite of 115 tools across 19 domains for identity verification, fraud detection, and compliance checks, all available through a hosted Streamable HTTP endpoint with OAuth 2.1 authentication. This curated index serves as a navigational hub for the Didit MCP server content, guiding users to specific resources such as tools references, marketing pages, and detailed use-case guides for compliance workflows like KYC, KYB, AML screening, transaction monitoring, and crypto compliance. The platform is free with a 500-verifications-per-month tier, while additional services are priced per verification. The page emphasizes ease of integration with platforms like Claude, Cursor, VS Code, and ChatGPT, providing deep links and documentation for seamless setup. The server's public repository is available on GitHub, and the server architecture allows LLMs to function as compliance-operations agents, with the potential for high ROI in strategic use cases.
Aug 03, 2026
920 words in the original blog post.
The Didit Model Context Protocol (MCP) server is an open-source project licensed under the MIT License and can be built from a public GitHub repository to run using Docker, Node.js, or a headless stdio transport. Each operational mode of the server requires authentication as a Didit user using a Bearer access token, and there is no application API-key mode available. The HTTP entrypoint is stateless and accepts POST requests, while the stdio entrypoint is intended for a single-client, headless process. Enterprises may opt for self-hosting to keep integrations within their own network, control runtime images, and apply their own policies, while also having the flexibility to use the hosted Open Authorization (OAuth) endpoint. The repository supports deployment models without creating a separate product surface, and the guide emphasizes configuring the environment appropriately, such as setting public resource URIs and managing secrets securely. The setup supports both HTTP and stdio entrypoints, with the HTTP option being suitable for shared services accessed by multiple clients. The MCP server is designed to handle stateless operations, facilitating scaling and session management, and it integrates with Didit's upstream services for data persistence.
Aug 03, 2026
1,537 words in the original blog post.
The text outlines a detailed process for managing onboarding and compliance decisions in a crypto exchange using the Didit Model Context Protocol (MCP) server and the Claude tool. The process begins with establishing the operating context and selecting an appropriate verification workflow for each customer, which is crucial for subsequent Know Your Customer (KYC) checks. Customers complete identity verification through Didit's hosted UI, and results are reviewed manually against the exchange's policies. Anti-Money Laundering (AML) checks follow, requiring careful interpretation of results, and wallet screening assesses the risk without automatically controlling funds. The process culminates in transaction submission for monitoring, where the transaction's category-specific details dictate the schema. The Business Console handles policy authoring and rule configuration, ensuring that Claude supports operators without replacing human compliance oversight. The entire system relies on a methodical sequence of evidence gathering, policy application, and explicit actions, with clear boundaries between automated processes and operator decisions.
Aug 03, 2026
1,375 words in the original blog post.
On 23 July 2026, the UK Gambling Commission announced a £4.75 million settlement with Evolution Malta Holding Limited after finding that its games were accessible through six unlicensed websites serving Great Britain and that its anti-money-laundering risk assessment, supply-chain controls, and customer due-diligence processes were inadequate. The regulator said the weaknesses were serious enough to warrant considering a licence suspension, although the case was settled without one. The account compares Evolution’s case with 2025 enforcement actions involving Videoslots, Spreadex, and Platinum Gaming, highlighting alleged shortcomings such as reliance on ineffective algorithms, failures to escalate risk profiles, delayed checks on voucher activity, and acceptance of self-reported financial information instead of source-of-funds evidence. It argues that the recurring regulatory concern is often not the absence of controls or detection signals, but whether firms test their effectiveness, investigate warning signs, obtain evidence, and escalate cases appropriately. While identity verification, address checks, and ongoing AML screening can help provide documentary evidence, the text notes that operators remain responsible for risk judgment, monitoring, escalation, and demonstrating that their compliance systems work.
Aug 01, 2026
1,865 words in the original blog post.
Asian governments have rapidly tightened identity-verification, banking, privacy, and anti-scam rules in response to an estimated $40 billion Southeast Asian scam industry, rising fraud alerts, and increasingly sophisticated deepfake-enabled schemes. Between December 2024 and January 2026, Singapore, Vietnam, India, Thailand, Malaysia, the Philippines, Japan, South Korea, and Indonesia introduced or advanced measures ranging from liability regimes for banks, telecommunications providers, and platforms to mandatory biometric checks, data-protection obligations, and AI deepfake labeling. Singapore requires institutions that miss prescribed anti-scam controls to reimburse phishing victims, while Thailand extends potential shared liability across banks, telcos, wallets, and platforms. Vietnam has made biometric face matching against state identity records a condition for online banking and has suspended unverified accounts from online transactions, while Japan plans to eliminate photo-upload verification for remote account opening in favor of chip-based credential reading from April 2027. India’s data-protection framework will become fully binding in May 2027 with substantial penalties, and regional approaches increasingly rely on national digital identity systems, although biometric data is also treated as sensitive information under privacy laws. The discussion concludes that verification technology can support compliance with specific identity checks, but financial institutions remain responsible for operational safeguards, reimbursement duties, privacy governance, and legal compliance.
Aug 01, 2026
3,312 words in the original blog post.
The Financial Conduct Authority (FCA) conducted a survey of 242 asset management and alternatives firms during 2025/26, focusing on their financial crime controls, and published the findings on 22 July 2026. The results highlighted significant gaps in anti-money laundering (AML) practices, particularly within private-markets firms, which reported a higher presence of politically exposed persons (PEPs) and more complex ownership structures compared to non-private-markets firms. Notably, 29% of the surveyed firms lacked a formal transaction monitoring process, and 18% did not have a formal customer risk assessment method. The survey also revealed that 40% of firms outsource customer due diligence checks, but only 36% maintained full oversight of these outsourced processes. More than half of the firms reported that their money laundering reporting officers work part-time or share roles, including at larger firms managing over £10 billion. The FCA's publication did not name firms, set enforcement actions, or penalties, but served as a benchmark for good and poor practices within the industry.
Aug 01, 2026
2,056 words in the original blog post.
Article 26 of the EU anti-money laundering regulation, specifically Regulation (EU) 2024/1624, establishes a framework for updating customer information that is both periodic and event-driven, depending on the risk level of the business relationship. The regulation sets maximum intervals for updates at one year for higher-risk customers and five years for lower-risk ones, but these are ceilings rather than prescribed cycles. The periodic reviews must be supplemented by event-driven reviews triggered by changes in customer circumstances, legal obligations regarding beneficial ownership, or awareness of relevant facts. Continuous monitoring is required for transactions, while customer information is governed by these review cycles. The draft guidelines published by the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) emphasize a risk-based approach without specifying fixed frequencies beyond the established limits, and the consultation on these guidelines remains open until 3 September 2026. The regulation highlights the dynamic nature of business verification compared to more static individual identity checks, pointing out that ownership and control details can quickly become outdated, necessitating ongoing vigilance.
Aug 01, 2026
2,073 words in the original blog post.
Between March 2025 and December 2026, six of Latin America's largest economies—Mexico, Peru, Argentina, Brazil, Chile, and Colombia—overhauled their identity and data protection laws in response to rising fraud rates and advances in technology, particularly artificial intelligence. This period saw Mexico introduce a biometric national ID, the CURP, incorporating fingerprints and photographs as mandatory, while Brazil established a legal framework for data exchange with the EU, allowing personal data to move freely without additional transfer instruments. Chile is set to enforce Law 21.719 by December 2026, which introduces a dedicated data protection agency and categorizes biometric data as sensitive, requiring stricter legal bases for processing. These changes reflect a regional trend towards tighter data protection and identity verification measures, with adaptation windows for compliance becoming increasingly narrow. The ongoing regulatory developments highlight the tension between governments enforcing stringent data protection rules and simultaneously mandating biometric credentials, posing complex compliance challenges for companies operating in the region.
Aug 01, 2026
2,797 words in the original blog post.
The Federal Communications Commission (FCC) is exploring new measures to combat illegal robocalls by potentially requiring phone companies to verify customer identities before allowing calls onto the network, drawing inspiration from banking sector regulations like the Bank Secrecy Act. The proposal, released on May 1, 2026, seeks comments on implementing customer verification processes similar to those used by banks, including collecting names, addresses, government-issued IDs, and alternate phone numbers. While the FCC has proposed a $2,500 fine per illegal call, no specific rules have been adopted yet. The initiative has garnered mixed responses, with 50 state attorneys general arguing the measures are insufficient, while financial trade associations support the alignment with banking standards. The FCC is considering whether to create a safe harbor for telecom providers using third-party verification services, yet no accreditation scheme currently exists. This ongoing effort reflects a broader strategy to integrate financial regulatory models into telecommunications to enhance consumer protection against fraudulent activities.
Aug 01, 2026
4,401 words in the original blog post.
In 2026, prediction markets such as Polymarket and Kalshi faced scrutiny from various regulatory bodies, including a U.S. congressional committee and regulators in Spain and France, primarily over issues of user identity verification. The U.S. House Committee on Oversight and Government Reform highlighted concerns regarding inadequate identity controls, particularly in light of allegations that individuals with access to classified information used these platforms for insider trading. The committee requested detailed records from the platforms to assess their compliance with legal obligations, while Spain and France implemented bans due to the platforms' failure to meet local licensing and identity verification requirements. Legal battles in the U.S. centered on jurisdictional disputes over which regulatory authority has the power to enforce identity verification, rather than on the necessity of such verification itself. Other countries, including Portugal, Brazil, India, and Indonesia, also blocked these platforms, citing existing gambling laws. The broader issue remains the ability of these platforms to know and verify their users, a requirement increasingly demanded by regulators worldwide.
Aug 01, 2026
1,495 words in the original blog post.