Paul Shearer, a data scientist in life insurance, in his column “The Glaring AI Fraud Loophole Washington Refuses To Close” (Substack, September 26, 2026), examines the loophole through which AI gains economic power: in most US states, a company can be registered without identity verification, and on August 11, 2026, a final FinCEN rule permanently exempted American companies from reporting beneficial owners under the Corporate Transparency Act, and already submitted unverified records were decided to be deleted. The cheap fix, according to the author, is simple: one controlling person in each company must verify their identity in person.

What Happened
The factual core of the story is two US regulatory decisions. On August 11, 2026, FinCEN, the financial intelligence unit of the US Department of the Treasury, issued a final rule that permanently exempted all American companies from reporting beneficial owners as required by the Corporate Transparency Act; the text was published in the Federal Register on August 14, 2026, and FinCEN accompanied it with clarifications on the fincen.gov/boi/ifr-qa page. The same decision ordered the deletion of already submitted unverified records about owners. This looks paradoxical against the backdrop of the fact that on December 16, 2025, the Eleventh Circuit Court of Appeals confirmed the constitutionality of the Corporate Transparency Act itself. Meanwhile, in most states, registering a company can still be done without identity verification: only an “organizer” and a “registered agent” are required, owners do not need to be specified, and no one checks identifiers. Shearer’s answer is a cheap fix: to require one controlling person in each company to verify their identity in person and bear personal responsibility, similar to the IRS Trust Fund Recovery Penalty mechanism, where managers are personally liable for unpaid taxes.
Context
The Corporate Transparency Act was created so that American companies would have a federal registry of beneficial owners — a database that banks, payment systems, and law enforcement agencies relied on when checking counterparties. The court confirmed the legality of the idea itself, but the executive branch refused to implement it, and along with the unverified records, the only existing, albeit noisy, dataset on company ownership structures is being destroyed: any future analysis of the scale of the problem, academic or investigative, is deprived of a “before and after” comparison line. At the same time, the infrastructure of deception itself is becoming cheaper: North Korea is already using AI identity forgeries in interviews, and RUSI warns that AI agents will soon be able to run entire networks of shell companies with almost no human involvement. Ready-made templates for a solution exist outside the US: in the UK, verification at UK Companies House is already working in practice, in Australia, the Australia director ID system is in effect, and both precedents give legislators proven mechanics.
Why This Matters for the Industry
Anonymous company shells are a checkpoint through which AI and ordinary fraudsters cash out income, so the FinCEN decision primarily hits fintech, crypto, and payment systems, which are obligated to fight money laundering. Counterparty scoring built on beneficial owner data is degrading right now, and banks only check that the named owners exist, but not who actually controls the business. “Phoenixing” — dissolving a shell and re-registering under a new name — is again left unpunished, so any product working with American counterparties will have to build its own verification and monitoring steps instead of relying on the liquidated state registry. Remote KYC checks in the “selfie plus document” format, according to the author, are already being forged by generative models, and they should be reclassified from “control” to “weak signal”: the reliable node remains in-person verification with personal responsibility of a specific person. In parallel, a scarce resource is being created — a “verified person,” which is again becoming a product: increased demand is expected for vendors that glue state registries, Companies House API, and company connection signals into a single due diligence workflow, and in-person verification channels like USPS are turning into an operational bottleneck with cost, latency, and throughput metrics.
Why This Matters for Users
For the reader, this is a rare analysis not of “superintelligence,” but of a specific hole in bureaucracy that can be closed right now: AI can generate documents for free, but it cannot “print people” willing to answer with their own money. In practice, this means that when paying for services or partnering with American companies, it is worth independently finding out who is behind the company, and not to consider the fact of its registration a sign of reliability: an anonymous shell is now even more accessible to fraudsters collecting prepayments and customer data. To track the topic, it is useful to know at least three facts: the FinCEN rule from August 11, 2026, with clarifications on fincen.gov/boi/ifr-qa, the decision of the Eleventh Circuit Court of Appeals from December 16, 2025, and the mechanics of UK Companies House verification, where a similar verification requirement is already working in practice.
What Is Still Unknown / Limitations
The presumption that AI is already forging both selfies and documents is not an established technical fact: neither the author of the column nor the participants in the discussion provided a single reproducible measurement such as attack success rate, model type, or attack conditions. This is a plausible threat-model hypothesis, supported by anecdotal data about North Korea and RUSI warnings, not a measured result. There are almost no open standardized benchmarks for the resilience of identification procedures — selfie-with-ID, liveness, document forensics — to modern generative models: all assessments remain privileged knowledge of KYC operators. In addition, the FinCEN rule has only just come into force, and an explosion of fraud in the data is not yet visible, so its real scale can be judged later; the RUSI scenario of AI agents running networks of shell companies remains a forecast that will either be confirmed or not in the coming years.
Sources
- The Glaring AI Fraud Loophole Washington Refuses To Close — Paul Shearer's column, A Cathedral in the Wild (Substack)
- FinCEN Final Rule: Questions and Answers — exemption of American companies from BOI reporting (August 11, 2026)
- Beneficial Ownership Information Reporting Requirement Revision — Federal Register (final rule, August 14, 2026)
Author
Look at AI, editorial team
