Verification Without Surveillance
September 2026 · Alex Galle-From
Personal analysis. Not the position of my employer or any client.
In December 2025 I published a short essay arguing that the cost of producing a convincing false identity or document was falling toward zero while the cost of checking one was rising, and that the usual institutional response to that condition is more record-keeping. I called the crossing point the authentication cliff. This note restates the argument in plainer terms and connects it to the statute I drafted in response, because the statute depends on the premise and the statute is the more useful thing to examine.
The premise
Institutional checks on identity and documents rest on an economic assumption: a good forgery costs more to make than to catch. Signature cards, notarization, call-back procedures for wire instructions, the habit of asking for a second form of identification, all assume the fraudster's cost is high relative to the checker's.
Both sides of that ratio are moving. Generative tools produce plausible identification images, voices, letters, and account statements at close to no cost per item. On the checking side, telling a generated document from a real one now takes specialist tooling and time, and the volume of transactions allows neither. In trust administration this arrives as ordinary work: a beneficiary's identity, a signed direction letter, a statement offered as proof of funds. Each now has to be treated as possibly fabricated, and the procedures for confirming them were built for a different cost structure.
Courts meet the same problem through the rules of evidence. Federal Rule of Evidence 901 asks the proponent to show that an item is what it claims to be. When any recording can be challenged as generated, a court that cannot resolve the question has two options: admit material it cannot authenticate, or exclude material it cannot disprove. Either option shifts the cost onto the party least able to bear it.
The default response
When an institution cannot verify a claim at the point of the transaction, it asks for more records. Identity documents are collected and kept. Presentations are logged. Retention periods lengthen. Reporting duties are added. Nobody designs this as surveillance; each requirement answers a specific fraud, and retention is the cheapest control to administer. Over time the result is a permanent record of who presented what, where, and when, held by parties who did not need it to complete the transaction. Anti-money-laundering and foreign-account reporting regimes already work this way, and age-verification statutes are the newest instance: the goal is legitimate, and the design question in each of them is what record the check leaves behind.
I do not think the people building these regimes want the record. I think the record is what you get when verification is expensive and liability for a bad verification is diffuse. Nobody in the chain answers for a false confirmation, so everybody keeps evidence.
The alternative
The alternative is to let a relying party confirm the one fact it needs, from a party that answers for the confirmation, and to make sure the confirmation leaves no record beyond that.
The technical pieces exist. The W3C Verifiable Credentials data model lets a holder present a single attribute from a signed credential without disclosing the rest; zero-knowledge proof systems are one way to implement that property. What has been missing is the legal structure around the credential: who may issue one, what capital stands behind it, who pays when a verified claim is false, and what the issuer and the relying party are forbidden to keep.
The Minnesota Digital Trust & Consumer Protection Act, a model statute now at version 1.6, is my draft of that structure. Its verification provisions do four things.
- Credentials must be signed by a licensed issuer, verifiable by the relying party without contacting the issuer, and structured to the W3C Verifiable Credentials Data Model v2.0 or an equivalent open standard (§ 325M.01, subd. 3).
- Issuers must not collect or retain which relying parties a subject presents to, except as strictly necessary for revocation, security, fraud prevention, compliance with federal law, or a lawful court order or other compulsory process (§ 325M.01, subd. 9). The rules implementing this must provide for compelled disclosure under court order without enabling routine tracking (§ 325M.06, subd. 1(d)).
- Relying parties may retain the record of a presentation for thirty days, with exceptions for statute, litigation hold, and federal supervisory requirements (§ 325M.02, subd. 2).
- The fraud registry stores keyed-hash tokens rather than government identifiers, and is not a consumer report (§ 325M.02, subd. 4).
Accountability comes from the liability side. An issuer that falsely verifies a factual claim pays the relying party from a bond, on strict liability, and an industry-funded guaranty association stands behind the bond (§ 325M.02, subd. 1; § 325M.05). The verification event is regulated by who answers for it, not by what it records.
What this does and does not claim
The Act does not claim to detect generated content. It does not require any particular cryptographic primitive; it mandates the property, an issuer that cannot see where its credentials are presented, and leaves the mechanism to rulemaking. It does not abolish the records federal law already requires; the safe harbors in § 325M.02, subd. 2 preserve them. What it does is set the default the other way: no record unless a specific rule requires one, with a named party liable if the confirmation was wrong.
Whether that default holds depends on things a statute cannot settle: whether issuers can be bonded at a price that lets anyone but incumbents enter, and whether relying parties will accept a yes-or-no answer in place of a copy of the document. The actuarial guidance and administrative rules on this site are my attempt at the first question. The second is an empirical question about institutions, and I do not have the answer yet.
The full statute text, actuarial guidance, and administrative rules are at /legislation.