SEC Peirce Backs Zero Knowledge Proofs For KYC

12 min read
3 views
Sep 25, 2026

A U.S. regulator just argued that banks and brokers keep building data haystacks for KYC. Zero-knowledge proofs could shrink that pile. The catch is simple: the rules themselves have not moved yet.

Financial market analysis from 25/09/2026. Market conditions may have changed since publication.

Ever notice how opening a brokerage account can feel like handing over your entire life in a folder? Name, address, income, tax forms, a photo of a passport, then the same ritual again at the next firm. I keep coming back to that friction because it is not just annoying. It is a design choice. And this week a departing U.S. securities commissioner said, in unusually plain language, that the design may be due for a rewrite.

Why A Privacy Pitch Landed In A Market Structure Speech

On September 23 in New York, Commissioner Hester Peirce used her penultimate week in office to argue that zero-knowledge proofs and attribute-based digital credentials could shrink the personal data that firms scoop up for KYC and AML checks. She was speaking at a digital assets conference. The remarks were her own. They were not an agency vote. They were not a new rule. Still, they matter because they put a privacy idea next to a live experiment in tokenized stocks.

That pairing is the story. One part is identity. The other is how tokenized versions of listed shares might trade through permissioned automated market makers for five years. Mix those two threads and you get a picture of a regulator who wants more on-chain activity at home, without turning every compliance file into a surveillance archive.

I’ve found that markets rarely change because a speech is elegant. They change when technology, liability, and paperwork finally line up. Peirce tried to sketch that alignment. Whether staff, Congress, and compliance lawyers follow is a different question. Let’s walk through what she actually said, what staff already studied, and what remains frozen in the current rulebook.

The Data Haystack Problem She Named Out Loud

Financial firms collect identity and transaction records because customer identification and anti-money-laundering rules tell them to. Fair enough. Crime is real. Sanctions lists exist for a reason. The trouble, in Peirce’s framing, is the pile that follows. She called those records “ever bigger data haystacks.” She also warned that repeated collection can turn financial infrastructure into a “panopticon.”

Collecting the same personal file at every institution does not automatically make the system safer. Sometimes it just makes the file easier to lose.

That line is my paraphrase of the spirit of her argument, not a statutory rewrite. She did not claim that identity checks should vanish. She asked a sharper question. Does every institution need the same raw dossier, every time, for every product?

In my experience, compliance teams answer yes because the cost of guessing wrong is brutal. A missed match on a watchlist can become a headline. A thin file can become an exam finding. So firms over-collect. Then they store. Then they defend the store. Privacy becomes a side conversation after the audit binder is thick enough.

What Attribute Credentials Would Actually Prove

Peirce’s alternative is not “trust me, bro.” It is a credential that attests to a fact. Age. Citizenship. Accredited-investor status. A clean sanctions screen. The institution would learn the attribute it needs. It would not necessarily receive the underlying passport scan, home address, or income worksheet.

A zero-knowledge proof is the cryptographic layer that makes that claim checkable. In plain English, you can prove a statement is true without showing the evidence that makes it true. Think of a bouncer who only needs to know you are old enough, not your apartment number. The club still keeps order. It just stops photocopying your wallet.

  • Prove an investor meets a status test without handing over tax returns.
  • Prove a user passed sanctions screening without exposing a full legal name to every vendor.
  • Prove jurisdiction or age on a device, then send only the proof.
  • Let a trusted verifier do heavy lifting so each broker is not reinventing the same file.

None of that is magic. Proof systems still need issuers people trust. They still need revocation when a credential goes stale. They still need a way for examiners to reconstruct what happened if a case goes sideways. That last point is where policy usually stalls.

Current Broker Rules Did Not Move With The Speech

Here is the part that gets lost in social posts. Existing customer identification programs still apply. Covered broker-dealers still need written procedures. They still collect identifying information, verify identity, keep records, and screen against designated government lists. Peirce did not issue an order that swaps a cryptographic receipt for a stored photocopy.

She did note that some broker-dealer rules already allow limited reliance on another financial institution when legal and contractual conditions are met. That is a crack in the door, not a highway. Making reliance easier, she suggested, could reduce duplicate harvesting of the same private details.

Perhaps the most interesting aspect is the honesty of the gap. Technology can already produce a proof. The rulebook still talks like the proof is a curiosity. Until examiners accept a proof as a record, firms will keep the old stack “just in case.”

Staff Already Sat Down With Privacy Identity Builders

This was not a speech written in a vacuum. Task force staff had already met with a cryptography team in July to talk through a product that checks government identity documents locally on a user’s device, then generates a proof for a requested fact. Age. Jurisdiction. Sanctions status. The underlying document stays on the device, at least in the model that was presented.

Those claims came from the presenters. They were not an agency endorsement. The memo trail matters because it shows staff asking the unglamorous questions. Can a proof satisfy customer identification? Can it satisfy screening? What about recordkeeping when a supervisor wants to replay the onboarding six months later?

The builders themselves conceded that current rules do not neatly contemplate replacing stored information with a proof. That admission is more useful than a slick demo. It tells you where the legal drafting has to happen if anyone wants this outside a lab.

Washington Had Already Floated The Same Tool

A 2025 working group report had already listed zero-knowledge proofs as one way to confirm that identity checks or screening occurred without revealing the underlying personal information. The report asked regulators to study how digital identity tools could live inside existing AML and customer-identification requirements. Peirce’s speech sits in that slipstream. It is a public push after a quieter paper trail.

I’ve sat through enough policy panels to know the pattern. First comes the white paper. Then a commissioner tests the language in public. Then industry letters arrive, half excited and half terrified of exam risk. Then nothing happens for a year unless someone writes an actual proposal.


The Five-Year Tokenized Stock Experiment Sitting Next Door

Before she turned to privacy, Peirce talked about the Innovation Exemption issued on September 17. Call it a bridge, not a cathedral. The order offers time-limited and size-limited relief so qualifying tokenized securities can trade through automated market makers while the agency thinks about permanent rules.

One slice of relief helps venues that might otherwise trip the Exchange Act definition of an exchange. Another slice helps certain liquidity providers that might otherwise look like dealers. The clock runs from September 17, 2026 through September 17, 2031. Five years. Long enough to gather data. Short enough that nobody should pretend the architecture is finished.

Eligible venues can use permissioned AMM pools for tokenized National Market System stocks. The token is supposed to carry rights that match the traditional share. A synthetic that merely tracks a price does not get the hall pass. That distinction is not academic. If the token is a wrapper with no shareholder rights, you are in a different product category, with different headaches.

Piece of the frameworkWhat it tries to doHard limit
Tier 1 tokenized stocksSmaller pilot set75 symbols and 0.25% of prior-month ADV
Tier 2 tokenized stocksWider but still capped set250 symbols and 2.5% of prior-month ADV
Venue transparencyPublic transaction informationQualifying data updates within ten minutes
DurationTemporary market experimentEnds September 17, 2031 unless replaced

Peirce said she would rather see tokenized exposure to U.S. equities develop at home than watch overseas platforms become the default venue. The chair separately called the exemption a bridge toward durable rulemaking. Those are political sentences as much as technical ones. They admit the activity is happening anyway. The fight is over where and under whose books.

Shareholder Rights Are The Line In The Sand

The framework leans hard on economic and legal equivalence. If you tokenize a listed stock, the token should not be a video-game version of the share. Voting, distributions, and the rest of the bundle matter. Issuers also get a chance to object before an unaffiliated third party puts a tokenized version of their stock onto a qualifying venue. That is a corporate-governance pressure valve. It will not please everyone. It does recognize that issuers are not props in someone else’s on-chain demo.

Why weave this into a KYC article? Because tokenized trading still needs onboarding. Permissioned pools still need to know who is in the pool. If the identity layer stays analog while the trading layer goes programmable, you get a hybrid that is expensive and leaky. Peirce’s privacy comments read like an attempt to keep those layers from fighting each other.

Industry Pushback Is Already On The Table

A major securities industry group welcomed work on tokenized securities and then immediately flagged the risks. Multiple tokenized versions of the same listed security, trading in parallel markets, could confuse investors. Prices could fragment. Liquidity could split. That is not a cranky footnote. It is the classic market-structure fear whenever a new wrapper appears beside an old one.

Peirce acknowledged the first wave of concern. She treated the exemption as one stage, not the last word. The longer job, she said, is writing rules for intermediaries and venues that handle forms of tokenized securities the old rulebook never pictured. That sentence should be taped to every pitch deck that claims “the SEC just approved everything.”

Public comments remain open on the exemption file. The agency wants views on duration, trading caps, market effects, compliance conditions, and whether any slice should become permanent. If you work in this market, that comment file is more important than any quote card.

What Zero-Knowledge Identity Would Change In Practice

Let’s get concrete. Imagine a permissioned pool that only admits investors who are not on a sanctions list and who meet a status test. Today, the operator often gathers full identity packets, stores them, and hopes the vendor stack does not spring a leak. Tomorrow, in Peirce’s preferred world, a user presents proofs. The pool learns yes or no. The raw document never crosses the wire.

  1. A trusted issuer or local check confirms the source document on the user’s device.
  2. Software builds a proof for the exact attribute the venue needs.
  3. The venue verifies the proof and logs a compliance event.
  4. Examiners later review the proof trail rather than a warehouse of scans, if the rules allow it.

Step four is the boss fight. Recordkeeping culture is conservative for a reason. When something blows up, investigators want names, timestamps, and documents they can print. A proof that “a valid check occurred” can feel thin in a courtroom unless the legal standard is rewritten to accept it.

The Panopticon Risk Is Not Just Poetry

Repeated KYC across banks, brokers, wallet apps, and trading venues creates copies. Copies get hacked. Copies get subpoenaed. Copies get combined. You do not need a spy-novel plot for that to become ugly. A breach at a vendor can expose people who never chose that vendor. They chose a broker who chose a vendor who chose another vendor.

I’ve found that people tolerate this until it happens to them. Then they ask why a sports-betting-adjacent onboarding flow needed their mother’s street from 1998. Attribute proofs will not end every abuse. They can cut the blast radius. That is a modest, adult goal.

Privacy in finance is not the same thing as anonymity. It is the difference between proving you belong and surrendering the whole attic.

Where This Still Falls Short Of A Real Safe Harbor

Peirce did not announce a rulemaking that lets proofs replace customer-identification records. She did not create a compliance exemption for ZK tooling. Transaction monitoring still exists. Suspicious activity reporting still exists. The speech is a policy preference with a technical flavor.

That is frustrating if you wanted a green light. It is also cleaner than pretending a keynote rewrites Title 17. Markets punish sloppy optimism. Better to say the door is ajar and the hallway is still full of lawyers.

What moved:
  Public language from a commissioner
  Staff meetings on privacy identity
  A separate five-year trading exemption

What did not move:
  CIP obligations
  Core AML monitoring
  Recordkeeping expectations
  Permanent market-structure rules

Tokenization Without Identity Reform Is A Half Build

On-chain settlement can be fast. On-chain identity, if it is just a PDF with extra steps, is not. The exemption tries to keep tokenized NMS names inside a supervised sandbox with volume caps and disclosure clocks. If onboarding remains a photocopy factory, the sandbox inherits the same privacy debt as the old market, plus new operational risk.

That is why I read the two halves of the speech as one argument. Bring activity onshore. Cap the experiment. Demand real share rights. And stop assuming that safety equals infinite collection. You can disagree with the mix. You cannot say it is incoherent.

Questions Firms Should Ask Before Buying The Narrative

If you run compliance, skip the hype cycle and interrogate the stack.

  • Who issues the credential, and what happens when it is revoked?
  • Can an examiner reconstruct the check without seeing raw identity data?
  • Does the proof cover the exact regulatory fact you must document?
  • Who is liable if the local document check was sloppy?
  • How do you handle customers who cannot or will not use a device-based flow?

Those questions sound dull. They are the difference between a pilot and a fine. A pretty circuit diagram will not comfort a desk that has to answer a deficiency letter.

Investors Should Watch Fragmentation More Than Slogans

If you are an investor, the privacy speech is interesting. The trading experiment may touch your wallet first. Parallel tokens of the same name can look identical in an app and behave differently in a crunch. Rights mismatches, venue outages, and thin AMM liquidity are not theoretical. Caps exist because staff knows the blast radius of a sloppy rollout.

Ask whether the token is the share or a shadow of the share. Ask where price discovery still lives. Ask who stands behind a failed pool. Those questions are older than blockchains. New rails do not retire them.

A Human Read On Why The Timing Feels Deliberate

Peirce is in her late innings as a commissioner. Late innings are when people say the quiet parts. She has spent years arguing that the agency should make room for experiments instead of governing by surprise enforcement. The exemption is that worldview in order form. The KYC comments are the same worldview aimed at data hunger.

Will the next lineup of officials keep both ideas? I would not bet the house. Personnel is policy. Comment files outlive speeches, though. A well-argued record can survive a change in tone. That is why the open file on the exemption, and any future identity workshop, matter more than a single afternoon in New York.

What “Success” Would Look Like In Five Years

Success is not a world with no identity checks. That would be reckless. Success looks more like this. A user proves the few facts a venue must know. Firms keep less sensitive bulk data. Examiners still get an audit trail they can defend. Tokenized versions of real shares trade in limited size without splitting the national market into unreadable shards. Issuers keep a voice. Investors can tell a right-bearing token from a lookalike.

If that package sounds boring, good. Market plumbing should be boring. Excitement belongs in prices, not in leaked passport scans or confused tickers.

The Bottom Line Without The Applause Track

A commissioner asked the country to collect fewer secrets while still screening for crime. She also defended a capped, temporary path for tokenized listed stocks on permissioned automated market makers. One idea is cryptographic. The other is market structure. Together they sketch a domestic alternative to offshore improvisation.

The rules on your onboarding form did not change on September 23. The conversation did. If firms treat proofs as a press release, nothing useful happens. If they treat them as a drafting project for examiners, counsel, and engineers in the same room, we might get a thinner haystack and a clearer market. That is the test. Not the quote. The file that comes after the quote.

And if you are still filling the same fourteen fields at every new platform next year, you will know which side of that test we failed.

❝
The first generation builds the business, the second generation makes it big, the third generation enjoys the fruits, the fourth generation destroys what's left.
— Andrew Carnegie
Author

Steven Soarez passionately shares his financial expertise to help everyone better understand and master investing. Contact us for collaboration opportunities or sponsored article inquiries.

Related Articles

?>