SEC’s Hester Peirce Wants Zero-Knowledge Proofs to Fix KYC System

SEC's Hester Peirce Wants Zero-Knowledge Proofs to Fix KYC System


Key Takeaways

Rethinking Legacy KYC Frameworks

Outgoing Securities and Exchange Commission (SEC) Commissioner Hester Peirce has called for an overhaul of the U.S. government’s financial surveillance framework. Speaking at a Securities Industry and Financial Markets Association (SIFMA) event, Peirce advocated replacing data-heavy compliance mandates with zero-knowledge (ZK) proofs and attribute-based credentials.

Peirce challenged the foundational premises of legacy know your customer (KYC) and anti-money laundering (AML) frameworks, which mandate that institutions continuously collect personal data. She cautioned that current rules risk turning financial infrastructure into a regulatory “panopticon” driven by data maximalists who operate under the flawed assumption that collecting more data improves market integrity.

“We build ever bigger data haystacks on the theory that we will find a needle or two inside,” said Peirce, whose message has resonated with privacy advocates. “The bigger haystack, however, makes it harder to find the needles.”

Every piece of confidential business and personal data collected creates significant risks of mishandling or data breaches, imposing huge costs on compliant institutions and everyday Americans alike.

Although it has not been widely adopted by governments and regulatory agencies, ZK technology could potentially reduce unnecessary data collection while maintaining and enhancing the transparency of the underlying transaction record, according to Peirce.

The SEC commissioner’s call is backed by Remco Bloemen, head of blockchain at World Foundation, who also sees the technology working at scale.

Bloemen told Bitcoin.com News that zero-knowledge proofs could realistically replace significant parts of traditional KYC and AML rules by allowing institutions to verify pass/fail attributes without accessing underlying personal data. The key challenge, however, is translating each verification into a precise, computable circuit, including clear definitions for complex issues like aliases in sanctions screening or acceptable evidence of income and assets.

Regulatory Sandboxes Needed for Industry Adoption

While the underlying technical challenges are largely solved, broader adoption would require standardized, legally recognized definitions and reliable data sources. Production-grade age verification has already demonstrated that the model can work in practice.

“For this to be adopted widely, in my opinion, the most important missing piece is a clearly defined regulatory sandbox where institutions can experiment with this new technology in close collaboration,” Bloemen said. “Privacy-preserving KYC/AML will have to be battle-tested and case law established before broad adoption is possible.”

Bloemen argues that zero-knowledge identity systems could substantially reduce privacy and security risks by eliminating centralized databases containing sensitive KYC information, the primary target for large-scale breaches. While he considers the underlying technology mature, citing its successful use in securing billions of dollars, Bloemen acknowledges that transitioning to a new system would introduce new risks that institutions must identify and manage.

Meanwhile, Peirce, who is set to leave the SEC before the end of the year, urged the commission and market participants to move toward attribute-based verification. She encouraged allowing registered entities to rely on third-party verification to reduce operational costs and mitigate cyber vulnerabilities.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *

Pin It on Pinterest