The Identity Revolution: From Broken Checkbox to Trust Foundation
Reporting from Money20/20 USA: while the main stage sold agentic commerce, the conversation at the booths and roundtables was about an identity architecture that cannot support it.

LAS VEGAS – This was my first time at Money 20/20 and it surely was a great experience. Attending as a member of the press, I had the privilege of engaging with and interviewing numerous participants. This allowed me to gather lots of information and insights that allowed me to write this piece which intent is to try and shed some light not only on the state of the art of the IDV space but also, actually more, on its future trajectory.
This event was, I believe ironically, held inside of a casino in Las Vegas, which kind of represents the antithesis of optimization and money security (ndr). In the timeless halls of the Venetian, the official agenda at Money 20/20 was, as always, a mix of futuristic buzzwords: “Agentic Commerce,” “Banking’s Next Leap,” and the “Global Payments Race”. Giants like Stripe, Visa, and PayPal took the main stage to prophesize a world where AI agents would act as our personal financial shoppers.
But at the booths, in the private roundtables and in the expo halls, a different, more urgent conversation was taking place. The real story of this year’s conference wasn’t about the shiny, autonomous future. It was about the realization that the industry’s current architecture is fundamentally broken and cannot support it.
This is the story of how the multi-trillion-dollar identity market is collapsing under its own weight and being rebuilt from scratch.
For years, the Identity Verification (IDV) market sold “checkboxes“. In a post-conference email, a representative from the compliance startup Middesk captured the new mood perfectly: “*trust isn’t a checkbox; it’s the foundation*“.
That foundation is cracking. I spent the conference speaking with executives from global banks, cross-border payment firms, and infrastructure providers. They are all trapped in the so-called the “PII Liability”.
The PII Liability: When Data Becomes Toxic
The old model of identity is simple: to verify a customer, a company must collect and hold their Personally Identifiable Information (PII). This has created a three-way conflict between compliance, cost, and customer conversion.
Ask a payments team at a firm like PayPal, and they’ll lament the “document-heavy and high-friction” process that causes users to abandon their shopping carts. Ask a cross-border payment provider like Inter.co, which is expanding from Brazil to the US and now Argentina, and they’ll point to the staggering complexity of managing different compliance rules, and often different vendors, for each new country. Or ask a legal team, and they’ll point to their “massive PII database” as their single greatest liability.
This data, which they are legally required to collect, has become toxic. It must be segregated, encrypted, and managed to meet a huge patchwork of global regulations like GDPR and CCPA, all while painting a giant target on the company’s back for hackers.
This has given rise to “vendor sprawl”. I sat in a roundtable hosted by the data company Reltio, where the Head of Risk at Shopmonkey, voiced the industry’s single biggest complaint. “Our big problem,” she said, “is that data from different sources don’t really talk to each other”.
Companies now juggle one vendor for KYC (Know Your Customer), another for KYB (Know Your Business), and often a third for AML (Anti-Money Laundering) screening. The result is a fragmented, expensive, and dangerously incomplete picture of their customer. And as she and others noted, this model almost entirely lacks “ongoing monitoring”. It’s a one-time snapshot in a world that demands a real-time video feed.
This entire broken model is now facing two simultaneous, existential shocks: a market-wide “re-bundling” and a revolutionary “unbundling.”
From Point Solution to Trust Platform
The first shock is a massive consolidation. The era of the “point solution” is over. The market is demanding a “platform solution” that unifies identity, fraud, and compliance into a single, intelligent layer.
This was a dominant theme. I spoke with the team at Socure, a major identity platform, about their strategy. Their recent $70 million acquisition of the document verification startup Berbix wasn’t just to add a feature; it was to feed their AI-driven platform. Their entire pitch has shifted. They no longer just “verify” users; they “convert more good customers” by using AI to analyze thousands of “passive” data points like email, phone, and social media history to build a holistic risk profile.
This platform-centric model, also championed by firms like Incode, solves Shopmonkey’s problem. It breaks down the data silos. It provides the “holistic picture”. And most importantly, it enables the “continuous monitoring” that risk officers crave.
But simply building a better, bigger “honeypot” of data doesn’t solve the core “PII Liability”. For that, the market requires a far more radical solution.
When Your Wallet Becomes Your Passport
The second, and more profound, shock is the unbundling of identity from the corporation entirely.
The future of identity is not a file on PayPal’s server; it’s a “verifiable credential” that lives in a “native wallet” on your phone. This was the subtext of the entire conference.
In this new user-centric model, you verify your identity once. A secure, encrypted credential is then issued to your personal “vault”. When a new company needs to verify you, you simply grant them access to a “proof”.
This enables “selective disclosure”. The merchant doesn’t get your driver’s license, your date of birth, or your address, all toxic PII they don’t want to store. They get a simple, cryptographically-signed “yes/no” answer: “Is this person over 21?” or “Is this person’s risk score acceptable?”.
This one-two punch of “unbundling” and “re-bundling” is the solution. The platform provides the AI-driven risk intelligence, while the wallet provides the user-controlled, privacy-preserving credential.
This new architecture definitively solves the industry’s trilemma:
- Compliance: It handles data residency and retention rules automatically, a massive win for cross-border firms like Inter.co.
- Cost: It slashes the 39% of compliance expenses associated with storing and securing PII.
- Conversion: It enables “one-click KYC,” which can increase user onboarding completion by up to 70%.
This isn’t a theoretical upgrade. It’s a non-optional architectural shift, and it’s being forced on the industry by the very AI it celebrated on the main stage.
The Catalyst: Why “Agentic Commerce” Breaks Everything
The biggest headline from the show floor was “Agentic Commerce.” Stripe, in partnership with OpenAI, announced its “Agentic Commerce Protocol”. Visa and PayPal made similar announcements, detailing a future where AI agents will autonomously execute purchases on our behalf.
This multi-trillion-dollar opportunity comes with a fatal flaw: an AI agent cannot complete a liveness check. It cannot hold up its owner’s passport to a webcam.
As Stripe’s team pointed out, the central problem is trust. How does a merchant “trust and really verify the identity of the user behind the agent?”. How do they “underwrite trust” for a bot?
The legacy “checkbox” model is useless here. The only viable solution is the new architecture. The AI agent must present a verifiable credential from its owner’s native wallet. This credential is, in effect, the AI’s passport.
This is the great convergence. The Web3 firms I spoke with, like Fireblocks and Ripple, are pulled toward this decentralized, user-centric model for philosophical reasons. The incumbents, like PayPal, are pushed toward it for defensive reasons, to escape their massive “PII Liability”. And now, the AI giants like Stripe and Visa are forcing the entire industry to adopt it, because it’s the only infrastructure that can support the agentic future.
Trust the Future
The lesson from Money 20/20 is clear: we are moving from Identity Verification to Trust Verification.
- Identity Verification was a one-time event. It was fragmented, created data silos, and left companies like Shopmonkey blind to ongoing risk.
- Trust Verification is a continuous platform. It provides a holistic, real-time picture of every customer. It unifies data, it converts more “good customers,” and it provides the “foundation of trust” required for the agentic economy.
The most successful companies of the next decade won’t be the ones still selling “checkboxes.” They will be the ones building the infrastructure for trust, the digital wallets and unified platforms that will serve as the passports for both humans and their AI agents.
The future of identity isn’t about proving who you are just once. It’s about proving that you’re trustworthy, every second of every day. That’s the real story from Money 20/20 and Las Vegas

.
A version of this piece first appeared at edomusta.substack.com.
Working on something we should know about? Reach the desk at editor@fintechsdispatch.com. Event organisers and sponsors: see press & accreditation.