Hester Peirce, a commissioner at the US Securities and Exchange Commission, has called for a change in how financial institutions handle Know Your Customer (KYC) and anti-money laundering (AML) requirements. Speaking at SIFMA’s Digital Assets Conference on September 23, Peirce said regulators should move away from collecting as much personal information as possible. Instead, they should verify specific facts when technology allows it.
Peirce described the current system as a growing “haystack” of names, addresses, identification numbers, and transaction records that institutions collect in the hope that law enforcement can find a small number of criminals inside it. She questioned whether the cost and privacy risks of collecting this information are justified by the results.
Her alternative is attribute-based verification. A user could prove they are over a certain age or are not on a sanctions list without handing over their name and address. Peirce pointed to zero-knowledge proofs as a way to establish that a requirement has been met without revealing the underlying information.

KYC could become proof, not paperwork
That proposal puts some of crypto’s privacy technology directly against the traditional KYC model. A cryptographic credential could let it verify only what it actually needs to know, instead of an exchange storing personal details.
Privacy does not necessarily mean anonymity. A zero-knowledge system could prove that someone passed a required check while withholding the information used to establish that fact. Peirce also suggested allowing regulated institutions to rely on verification already completed by another trusted entity. This reduces the number of databases holding the same personal information.
RELATED: Zero-Knowledge Everything: Trust, Privacy, and Verification in the Digital Age
That idea is close to an option crypto developers are proposing. A Web3 builder argued that combining proof of identity, proof of the code an agent is running, and proof of how it pays could create a new type of economic actor that does not need a passport.
KYC works because behind every account there is a person who can be taken to court, whereas an agent can offer stronger guarantees than a document, namely cryptographic proof of who it is (registries like ERC-8004), of what code it is running (sealed TEE environments) and of how…
— PostAurum (@PostAurum) September 24, 2026
The concept is still experimental, but it exposes the opportunity Peirce is describing. If software agents, wallets, and users can prove specific attributes directly, financial compliance could become better instead of requiring every institution to collect the same full identity file.
Also Read: Do KYC Databases Make Crypto Holders Targets of Wrench Attacks?
Could privacy technology give regulators the proof they need?
The biggest challenge to Peirce’s argument is that regulators want information because they need to investigate financial crime. Peirce herself argues that blockchain transparency and forensic tools could allow authorities to investigate illicit activity while reducing unnecessary personal data collection.
Crypto users are also worried about what happens after authorities collect their identity data. Freddie New, co-founder of BitcoinpolicyUK, pointed to the UK’s Cryptoasset Reporting Framework in a recent tweet. Service providers began collecting customer information from January 2026 and must report relevant data to HMRC, with the first reports covering 2026 activity due in 2027. The UK rules also provide for information exchange with participating foreign tax authorities.
In a world where all crypto exchanges in the UK will soon be sharing ALL your private information with the tax authorities (name, address, buys and sells, amounts held), and where that information will be shared with other tax authorities across the world… this is terrifying to… https://t.co/9V5tLvWFlP
— Freddie New (@freddienew) September 24, 2026
That concern is not simply theoretical. Research from Gart documented 305 crypto-related cases involving kidnapping, ransom or physical attacks across 57 countries between 2014 and February 2026. However, that research does not establish that regulatory data collection caused those attacks.
Peirce’s proposal therefore tests whether privacy technology can give regulators the proof they need without giving them every detail they could collect. DeFi Planet has previously examined this direction in its analysis of zero-knowledge technology.
The difficult part will be turning that principle into systems regulators can trust. If cryptographic credentials can prove compliance reliably, KYC may become more about verifying the facts that actually matter.
Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads, and CoinMarketCap Community for seamless access to high-quality industry insights
Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.

























































































