Regula has found that 44% of surveyed crypto firms confirmed AI-assisted or automated activity among users undergoing identity checks.
Regula, an identity verification provider, has published its Crypto KYC Snapshot Report, based on findings from its 2026 global study ‘Identity Verification in the Age of AI Agents’. The report shows that 44% of surveyed crypto firms reported confirmed AI-assisted or automated activity among users undergoing identity verification, compared with 31% in other surveyed sectors, a gap of 13 percentage points. Such activity may include an AI assistant or agent acting on a customer’s behalf, a script interacting with a verification flow, or other automated behaviour identified through investigation or post-incident review. Regula notes that confirming the involvement of AI or automation does not in itself establish that fraud occurred or that an attack succeeded.
Document fraud and decision traceability
Asked about identity threats, crypto respondents cited counterfeit, altered, or stolen identity documents more often than deepfake or AI-generated impersonation, at 44% compared with 37%. Concern about document fraud among crypto firms was also 10 percentage points higher than the 34% recorded in other sectors. The consequences of errors appear more pronounced in crypto as well: 48% of crypto respondents associate incorrect identity verification results with financial loss, compared with 38% in other sectors. According to Regula, the findings point to the continued relevance of document authentication alongside controls for biometric impersonation and manipulation.
Crypto respondents also reported stronger decision traceability. In the survey, 62% said their organisations can fully reconstruct an identity decision, tracing all contributing systems, evidence, and decision logic, compared with 49% in other sectors. External scrutiny is common across the board, with 87% of crypto respondents saying their organisation has been asked to explain an identity-related decision to a regulator, court, or external auditor, against 81% elsewhere. In practice, an identity process may need to determine whether a document is authentic, whether the person presenting it is its rightful holder, whether biometric data came from a trusted capture source, and whether automation played a legitimate or suspicious role.
Distinguishing legitimate agents from attacks
Henry Patishman, Executive Vice President of Identity Verification Solutions at Regula, stated that the use of AI or automation during identity verification does not in itself indicate fraud, as an AI agent may be acting legitimately for a customer. However, he noted that automation can also be used to scale attacks or manipulate verification processes. According to Patishman, the challenge lies in understanding who is acting and whether the evidence supports that control, which requires selecting checks based on the risk of each interaction and preserving the evidence behind every decision. If a case is questioned later, teams should be able to see what was presented, what the checks found, which rules applied, and why the final decision was made.
The survey was conducted by Sapio Research on behalf of Regula in March 2026 among 850 fraud prevention and financial crime decision-makers. Respondents represented six sectors, namely banking, financial services, crypto, telecommunications, government, and gaming and gambling, across the US, the UK, Germany, Singapore, the UAE, Brazil, and Mexico. The snapshot compares 102 crypto respondents with 748 respondents from the other five sectors, with crypto excluded from all peer comparisons, and the question on AI-assisted or automated activity covered the 12 months preceding the survey.