Home / Companies / Didit / Blog / September 2026

September 2026 Summaries

12 posts from Didit

Filter
Month: Year:
Post Summaries Back to Blog
Didit describes its AI red-teaming program as a continuous staging-environment process in which AI agents with source-code access attempt to defeat identity-verification workflows using forged documents, artificial camera feeds, and automated user journeys. The company stresses that agent-reported bypasses are not treated as confirmed vulnerabilities until engineers reproduce and investigate the underlying evidence, implement fixes where needed, rerun tests, and assess effects on legitimate users. These exercises also provide examples of automation behavior, such as timing, retries, sequences, and device context, that can inform bot detection without treating any single unusual signal as proof of fraud. Didit argues that the same behavioral analysis can reveal usability obstacles including unclear instructions, permission problems, poor lighting, and damaged documents, supporting a balance between stronger fraud controls and accessible verification. Emphasizing the sensitivity of identity data and the possibility that any provider can be breached, the company calls on industry technical and security leaders to assign ownership, resources, and ongoing attention to security across verification flows, data systems, access controls, and incident response.
Sep 10, 2026 1,606 words in the original blog post.
As large language models increasingly use tools, credentials, and transaction capabilities, AI security concerns are shifting from harmful outputs toward accountability for autonomous actions, with OWASP identifying excessive agency as a major risk area. The text argues that effective controls such as least-privilege access, approval workflows, and audit logs depend on linking an agent’s authority to a verified human or business principal, while deepfakes and biometric injection attacks are making basic identity checks less reliable. It notes that regulators, including UK financial authorities, are beginning to promote “know your agent” approaches, and that EU AI Act transparency obligations have applied since August 2026 alongside existing AML, privacy, financial-resilience, and crypto rules. Emerging IETF proposals seek to standardize delegated agent authorization, but all rely on a trustworthy root identity that authorization protocols alone cannot establish. The proposed architecture combines robust onboarding verification, agent credentials bound to verified principals, continuous sanctions and risk monitoring, risk-based reauthentication, and comprehensive logs. The text presents Didit as a provider of API-based KYC, liveness, fraud monitoring, AML screening, transaction monitoring, and business-verification services intended to support this identity and accountability framework.
Sep 09, 2026 1,994 words in the original blog post.
The Financial Action Task Force revised Recommendation 16, its cross-border payment-transparency standard often called the Travel Rule in virtual-asset contexts, in June 2025 to reflect the broader role of fintechs and digital payment systems. Once implemented nationally, the changes will require peer-to-peer cross-border payments above USD/EUR 1,000 to include the sender’s or relevant party’s name, address, and date of birth, while defining the payment chain as beginning with the institution that receives a customer instruction. The revisions also call for technologies that reduce fraud and payment errors, including recipient banking-information verification, while retaining an exemption from full requirements for card payments used to purchase goods or services. FATF expects countries to be ready by the end of 2030, and an October 2025 assessment annex explains how compliance will be reviewed in mutual evaluations. Draft implementation guidance was consulted on from June to August 2026, focusing on misdirected payments, financial inclusion, digital wallets and mobile money, and data-protection issues. The changes do not directly bind firms until adopted by individual jurisdictions, but they may require payment providers to ensure onboarding records contain accurate, structured, transmissible identity and address information.
Sep 08, 2026 2,224 words in the original blog post.
FinCEN proposed on 1 September 2026 to designate the five UAE branches of Egypt’s state-owned Banque Misr as institutions of primary money laundering concern and bar U.S. financial institutions from maintaining correspondent or payable-through accounts for them under the fifth special measure of Section 311 of the USA PATRIOT Act. The proposal cites approximately $1.8 billion in transactions involving 103 potential Iranian shadow-banking front companies from January 2024 through June 2026, arguing that companies registered in jurisdictions such as the UAE and Hong Kong can obscure beneficial ownership and help sanctioned Iranian actors access the dollar system. If finalized, the rule would also require U.S. institutions to take reasonable steps to avoid processing relevant transactions through foreign correspondent accounts and to apply special due diligence across those accounts. FinCEN describes the direct screening burden of adding Banque Misr UAE to existing systems as limited, while the broader due-diligence obligation presents a more open-ended challenge because suspected front companies may be unidentified or not yet sanctioned. The proposal is not effective, accepts comments through 1 October 2026, and may be modified, withdrawn, or finalized; the source also uses the proposal to discuss the limits of sanctions screening, the importance of ongoing monitoring and beneficial-ownership verification, and related compliance services.
Sep 08, 2026 2,617 words in the original blog post.
The FCA’s Wealth Management Survey Report 2026, published on 18 August and based on self-reported information from around 400 firms serving more than 5.5 million retail clients and managing nearly £1 trillion, found that all respondents now refresh Know Your Client checks, compared with 8% that reported no refreshes in 2023/24. However, the report identified significant weaknesses in the information and screening controls that support effective ongoing monitoring: 26% of firms do not collect expected transaction frequency, 13% do not record expected investment amounts, about 10% do not verify source of wealth, around 6% do not check for politically exposed persons, and around 7% do not conduct sanctions screening, while some also omit adverse-media checks or timely higher-risk-client reviews. The FCA said these gaps can hinder detection of suspicious activity, identification of high-risk clients, and compliance with legal duties, noting that PEP and source-of-wealth checks are required in relevant circumstances and sanctions breaches can constitute criminal offences. Because the figures come from a non-random, self-reported survey, they should be read as a minimum indication of control gaps rather than definitive sector-wide rates, though a separate July 2026 FCA review of asset managers reported broadly similar issues.
Sep 08, 2026 2,619 words in the original blog post.
AUSTRAC suspended Cryptolink Pty Ltd’s registration for three months from 9 August 2026, requiring its 96 crypto ATMs to close after the company allegedly failed to submit mandatory threshold transaction reports and respond to an information request, despite completing an earlier enforceable undertaking addressing separate compliance shortcomings. The action occurred amid intensified Australian oversight of virtual asset providers, with AUSTRAC recording 16 registration actions by 13 August 2026, more than the combined total for 2021–2025, following the creation of a Cryptocurrency Taskforce and sector-wide ATM conditions including A$5,000 cash limits, enhanced due diligence, scam warnings, and stronger transaction monitoring. The account emphasizes that meeting remediation requirements does not remove ongoing reporting duties, particularly as new, more detailed reporting forms take effect through a transition ending in 2029, and notes that compliance technology can support identity verification and monitoring but cannot fulfill a reporting entity’s legal obligations.
Sep 08, 2026 1,359 words in the original blog post.
A September 1, 2026 report by The Block found that credit-card purchases of the WIF memecoin through Robinhood Wallet and Fomo, processed by Crossmint, were coded as digital media rather than cryptocurrency, allowing users to avoid separate identity checks, earn ordinary card rewards, and bypass the quasi-cash treatment commonly applied to crypto purchases. Visa’s April 2026 rules require cryptocurrency transactions to use quasi-cash merchant codes 6012 or 6051 and a special crypto indicator, but its guidance also permits ordinary coding for fiat purchases of NFTs, leaving no explicit classification for memecoins. Crossmint has cited an SEC staff statement describing memecoins as collectible-like and not securities, although that statement does not address payment-network coding, anti-money-laundering obligations, or customer identification. Chase said it believed the digital-media categorization was incorrect and opened a case with Visa, while Visa and Mastercard made only general compliance statements and the New York Attorney General said it was reviewing the matter. No regulator, card network, or other authority had publicly resolved whether memecoins should be treated as cryptocurrency or digital goods for card-processing purposes, highlighting how a merchant code can determine rewards, fees, issuer visibility, and identity-verification practices.
Sep 08, 2026 3,132 words in the original blog post.
California’s Digital Age Assurance Act, enacted in October 2025 and effective 1 January 2027, will require operating-system providers with account-setup features to collect a device user’s age or birth date from an adult account holder and provide apps or covered app stores with a real-time age-bracket signal rather than a date of birth. The minimum brackets are under 13, 13–15, 16–17, and 18 or older, and the law characterizes this information as nonpersonally identifiable data. AB 1856, which passed the California Legislature in August 2026 but had not yet received the Governor’s approval at the time described, would broaden the law’s applicability beyond devices identified as primarily used by children, clarify signal recipients, and prohibit requesting an age signal unless required by the Act or another law. The approach differs from service-by-service age verification systems, such as the United Kingdom’s model, by allowing a device to reuse one age assertion across applications, potentially reducing repeated disclosures and verification costs. However, the device signal is based on information entered during setup and does not independently confirm the current user’s identity or age, so services facing higher-assurance legal obligations may still need separate age or identity verification.
Sep 08, 2026 2,317 words in the original blog post.
Dunamu, operator of South Korea’s Upbit exchange, announced on 26 August 2026 that it had become the country’s first digital asset exchange designated by the Ministry of the Interior and Safety as an administrative information sharing institution following a May inspection. Under the Electronic Government Act, the designation makes Dunamu eligible to apply for access to specific government-held records for purposes such as KYC, potentially replacing customer-uploaded documents with direct, consent-based verification from official sources. However, designation alone does not grant unrestricted data access: each request must specify its purpose and scope, may require approval from the data-holding agency and the Personal Information Protection Commission, and requires the customer’s prior consent for personal data. Dunamu says it is still preparing the service and has not disclosed when it will launch or which records it will use. Direct government-record checks may reduce document friction and improve record accuracy, but they do not confirm that the person using an account is the person named in the records, leaving face matching, liveness checks, and anti-money-laundering obligations with the exchange.
Sep 08, 2026 2,427 words in the original blog post.
The UK National Crime Agency’s Flash Alert 0808-NECC, issued on 31 August 2026 with the National Economic Crime Centre, OFSI and other partners, describes A7 as a Russian-backed cross-border settlement network allegedly designed to help sanctioned clients move value through foreign shell companies, local bank accounts, promissory notes and layered correspondent-banking arrangements that obscure Russian origins. Established in 2024 and backed by Promsvyazbank and VEB.RF, A7 claims to have settled more than USD 86 billion in its first year, though the NCA notes this is the network’s own unverified figure. The alert says A7 creates or controls overseas “sub-agents,” including by furnishing websites, corporate email addresses and VPN access intended to make staff and companies appear locally based, while transactions may be supported by false invoices and routed through intermediary jurisdictions. It identifies seven indicators, including unusual transaction volumes or invoices, limited ownership information, high-risk jurisdictions, thin or generic online presences, and VPN activity inconsistent with a customer’s profile, emphasizing that four indicators focus on customer identity and onboarding data rather than payments. The NCA cautions that a Flash Alert is intelligence about a potential typology rather than proof of illicit conduct or a sanctions list, so firms should assess all circumstances, submit suspicious activity reports where appropriate, and report confirmed sanctions breaches or frozen assets to OFSI.
Sep 08, 2026 3,018 words in the original blog post.
Australia’s second tranche of AML/CTF reforms commenced on 1 July 2026, extending reporting-entity obligations to legal, conveyancing, accounting, real estate, property development, trust and company service, and precious-metals sectors, with AUSTRAC enrolment required within 28 days of beginning a designated service. The operational focus is customer due diligence, including collecting and independently verifying identity, establishing beneficial ownership for companies and trusts, screening customers and associated individuals for sanctions, politically exposed person status and adverse media, maintaining records, and conducting ongoing re-screening as lists change. The text highlights the complexity of verifying trust and company structures, where multiple directors, trustees, settlors, and beneficial owners may need to be linked to a single case. It presents Didit as a technology provider that combines document verification, liveness detection, facial matching, IP analysis, AML screening, ongoing monitoring, and business registry checks through an API or SDK, with stated pricing, free monthly verification allowances, Australian document support, webhook integrations, and configurable data retention.
Sep 07, 2026 1,445 words in the original blog post.
Didit’s Document AI is designed to automate extraction and verification of nonstandard documents that often delay onboarding, such as bank statements, payslips, tax certificates, corporate records, and source-of-wealth letters. Organizations can configure up to three document types per workflow, define required fields and extraction instructions, and receive typed outputs such as standardized dates and numeric values from a vision-language model that reads documents by meaning rather than fixed layout. The service performs PDF and image metadata forensics to identify potential tampering, compares extracted names with verified identity or business registry data, and supports custom rules that can approve, review, or decline cases for unreadable files, missing fields, mismatches, unsupported formats, or exhausted retries. It is available through Didit’s hosted workflows and SDK or as a standalone server-to-server API, supports PDFs and images in multiple languages, costs $0.20 per document after an allowance of 500 free monthly documents, and is positioned for lending, cryptocurrency onboarding, business verification, and regulated professional services.
Sep 07, 2026 1,093 words in the original blog post.