The cryptocurrency industry is entering an era of regulated maturity, shaped by new frameworks like the CLARITY Act and the $GENIUS Act. At the same time, fraud is evolving into AI-powered attacks based on the cryptocurrency lifecycle, demanding more effective protection. In this interview, Danielle LaBarbera, Sumsub's Vice President for North America, shares additional insights from the "State of the Crypto Industry 2026" report, covering regulation, fraud resilience, stablecoins, and the future of verification.
What is Sumsub?
Q: To start, could you tell us a bit about Sumsub and the role it plays in today's crypto ecosystem?
A: Sumsub helps crypto businesses build and maintain trust throughout the customer lifecycle. This starts with verifying individual and corporate clients and includes fraud prevention, AML screening, transaction monitoring, and Travel Rule compliance.
We partner with over 1,000 crypto companies, including eight of the ten largest global crypto exchanges, so we see firsthand how quickly both fraud prevention requirements and regulatory expectations are changing.
An important shift is that verification can no longer be seen as a one-time checkpoint a customer passes. Given that 55% of crypto companies encountered fraud last year, businesses need to understand whether a user's identity, behavior, and transactions remain relevant over time. Our role is to help them with that while ensuring the smoothest possible experience for legitimate customers.
2026 as the "Era of Regulatory Maturity"
Q: The report calls 2026 the "era of regulated maturity." The industry has sought regulatory clarity for years. Now we see developments like the CLARITY Act and the Genius ($GENIUS) Act in the United States. What do these frameworks mean for companies operating in this space?
A: These frameworks give businesses a clearer picture of the standards that will shape the U.S. digital asset market. The CLARITY Act governs the market structure and the allocation of regulatory oversight, while the $GENIUS Act sets requirements for payment stablecoins, including issuer rights to issue, reserves, redemption, disclosure, AML compliance, and consumer protection.
Clearer interpretation can help companies plan investments, develop products, and enter markets with more confidence. However, it also raises the operational standards expected of them. Compliance can no longer be limited to just written policies; platforms must demonstrate that their identity, transaction monitoring, and reporting systems work accurately, consistently, and at scale.
That's what the report implies by regulated maturity. The key is moving from simply understanding the rules to being able to execute on them without creating unnecessary friction for legitimate users. The greatest advantage will go to those companies that integrate compliance, fraud resilience, and user experience into a single, cohesive operating model.
Q: According to the report, only 23% of crypto companies are fully compliant with the Crypto Travel Rule, and 43% are unsure if they are compliant. Is this due to low awareness, high costs, or another factor holding them back?
A: It's not so much that companies are unaware of the Travel Rule's existence, but rather how difficult it is to ensure its consistent application in practice.
At a basic level, the Travel Rule requires crypto businesses to collect, verify, and securely transmit information about the sender and recipient of a virtual asset transfer. In practice, this means identifying when the rule applies, identifying the counterparty, verifying both parties, securely exchanging the necessary information, and maintaining an auditable record of the transfer.
The complexity lies in the fact that businesses aren't operating under a single, universal set of rules. Thresholds, mandatory data fields, privacy laws, and approaches to self-custodied wallets vary by jurisdiction. Platforms may also use different Travel Rule protocols that don't always interoperate seamlessly.
Cost is certainly part of the challenge. In our research, 52% of companies cited costly implementation as a key issue. But data security ranked even higher at 62%, while 50% pointed to regulatory fragmentation, and 38% cited interoperability problems.
This helps explain why 43% are unsure of their status. A company may have implemented some necessary capabilities but still be uncertain whether the process works across all jurisdictions, with every counterparty, and for all transaction types. Travel Rule compliance now goes beyond simply turning on a protocol; it requires ongoing risk management.
Crypto Fraud and Artificial Intelligence
Q: How will fraud-fighting strategies evolve in 2026?
A: One of the most significant changes we're seeing is that fraud is becoming increasingly sophisticated.
Fraud has evolved from isolated attacks to coordinated operations using artificial intelligence. Instead of relying on fake documents or stolen identities, fraudsters combine deepfakes, synthetic identities, social engineering, account takeovers, and networks of mules at different stages of the customer journey. Attacks are becoming more automated, convincing, and much harder to detect because they're designed to mimic the behavior of legitimate users.
This changes how companies approach fraud prevention. Checks at the onboarding stage are no longer enough. Our research shows organizations are increasingly investing in AI-powered fraud detection, continuous monitoring, and behavioral analytics to understand how risk evolves throughout the customer lifecycle.
The strongest strategies now integrate identity, behavioral, device, and transaction data into a unified risk view, allowing companies to detect threats earlier while maintaining convenience for legitimate users.
Q: AI is changing practically every industry. How is it impacting fraud?
A: AI has changed both sides of the fraud equation. It makes fraud faster, cheaper, and easier to scale, enabling criminals to create convincing fake identities, deepfakes, and synthetic documents in minutes instead of hours or days.
But it's also changing how businesses defend themselves. AI gives compliance and fraud teams the ability to analyze far more signals than a human ever could—from identity and device data to behavioral patterns and transaction activity—to identify suspicious behavior much earlier.
The challenge is that this has turned into an arms race. As fraudsters adopt increasingly sophisticated AI tools, businesses need systems capable of continuous learning and adaptation. Organizations that want to stay ahead need to move beyond viewing AI as just a feature and instead use it to unify identity, behavioral, and transaction data into a single, actionable view of risk.
Q: Fraud has shifted from a purely onboarding-focused approach to a "lifecycle"-based approach. Could you give an example?
A: Imagine a customer completes KYC, uses a platform normally for a few months, and builds a history of trusted activity. Traditionally, that account would have been considered low-risk. But today, that account could later be taken over, sold, or used as part of a mule network.
A lifecycle-based approach recognizes that risk isn't confined to the sign-up stage. Companies need to monitor what happens afterward: for example, if a user suddenly logs in from a new device or location, starts making unusual transactions, or interacts with high-risk wallets or counterparties.
No single signal necessarily indicates fraud, but when you combine identity, behavioral, and transaction data, you get a much clearer picture of changing risk. That's why the industry is moving away from one-time verification and toward continuous trust assessment throughout the customer journey.
Q: Over the past year, stablecoins have continued to gain traction for transactions. What can you tell us about the growing role of stablecoins?We are seeing stablecoins evolve from a trading instrument into a piece of financial infrastructure.
According to our research, in 2025, stablecoins accounted for 36% of all cryptocurrency transactions, up from 31% the previous year. This growth is driven by real use cases like cross-border payments, settlements, and treasury operations, where businesses want blockchain speed without the price volatility of other digital assets.
As adoption grows, so do compliance requirements. Stablecoin transactions are often cross-border and high-value, making robust KYC, KYB, transaction monitoring, and Travel Rule compliance increasingly critical. Regulation like the $GENIUS Act also helps provide a clearer framework for businesses in this space.
Ultimately, stablecoins are no longer viewed as purely speculative instruments; they are increasingly being used to enable faster, more efficient movement of money. The challenge for businesses is to ensure compliance infrastructure evolves alongside this growth.
Risk-Based User Verification Solution
Q: The report mentions the "three horsemen" of verification challenges: false positives, speed pressure, and user experience expectations—all pulling in different directions. What is the most practical way out of this trilemma?
A: The biggest mistake companies can make is to treat every customer the same. The way out of this trilemma is a risk-based approach where the level of verification adapts to the level of risk.
A low-risk customer shouldn't face the same hurdles as a customer who triggers higher-risk signals. By combining data on identity, behavior, device, and transactions, companies can make more informed decisions about when to introduce additional checks and when to keep the process fast and seamless.
Another key shift is moving away from one-time optimization. Fraud patterns and customer behavior constantly change, so verification models need continuous monitoring and refinement. Rather than choosing between security and user experience, the goal is to deliver both by applying the right level of verification at the right time.
Q: How are crypto companies implementing documentless verification and reusable KYC in 2026? How will this affect the front-end user experience?
A: We're seeing a clear shift away from requiring users to upload the same documents over and over every time they sign up for a new platform.
Instead, more companies are implementing documentless verification by using reliable data sources alongside device, behavioral, and risk signals to confirm identity. Reusable KYC or identity wallets allow users to reuse verified identity data across participating services, reducing the need for customers to start the verification process from scratch each time.
For users, this means faster sign-ups, fewer document uploads, and a much smoother front-end experience. For companies, it can reduce abandonment rates while maintaining strong compliance standards. This move makes trusted identities more portable and enables smarter identity decisions.
Q: If a head of compliance reads this report and wants to take one action this quarter to address the most significant compliance gap, what should that be?
A: I would start by looking at your compliance program holistically, rather than viewing KYC, fraud prevention, AML, and transaction monitoring as separate functions.
The biggest gaps often exist between these systems. A customer might pass onboarding successfully, but if changes in their behavior, device, or transaction activity aren't connected, important red flags can be missed.
This quarter, I would focus on identifying these "blind spots" and how you can unify identity, behavioral, and transaction data into a single risk view. This doesn't necessarily mean adding new controls; it's about making the controls you already have work together more effectively.
As regulation evolves and fraud schemes become more complex, companies that take an integrated, lifecycle-wide approach to compliance will be much better positioned to scale with confidence.
end-content







