A quiet change in U.S. banking guidance could become important infrastructure for agentic finance. On 8 September, FinCEN and staff from the Federal Reserve, FDIC, NCUA and OCC published new FAQs explaining how verifiable digital credentials can be used under Customer Identification Program rules.

The guidance covers government-issued credentials such as mobile driver’s licences and also allows electronic credentials to be used as non-documentary verification methods where a bank’s CIP supports them. Responsibility does not disappear: the financial institution still has to establish a reasonable belief that it knows the customer’s true identity and, where a third party issues the credential, satisfy itself about the authentication assurance involved.

Proof has moved quickly into that opening. Its new reusable Verifiable Digital Credential is issued after identity proofing through a Kantara-certified IAL2 service and chains to Proof’s WebTrust-audited certificate authority. It is designed to let a person reuse cryptographic evidence of identity without repeatedly distributing copies of passports or licences.

Separately, Proof is positioning its x401 protocol around agent authority: a service can request evidence of who is behind an agent and what that person authorised. That is Proof’s product and protocol direction, not a requirement or endorsement contained in the FinCEN guidance.

The distinction could become fundamental in financial services. A bank may increasingly need to verify three things independently: the human, the software agent and the mandate joining them.


Conquered Your Data? - Now Combat Your AI
Souvik Choudhury, an AI and Data Governance Specialist at Fractal Analytics with a background spanning Infosys, HSBC and several startups, joins Stewart Tinson to unpack why data governance and AI governance can’t be treated as sequential problems, and why so many organisations discover the gap between them the hard way. Souvik argues that traditional data governance remains the foundation everything else is built on, and that AI agents amplify existing weaknesses rather than replacing the need for accountability, contextualisation and lineage. He walks through a real project example where an organisation believed it had solved data governance by using agents to generate column definitions, only to discover the definitions were pulled from generic internet knowledge rather than the organisation’s own policies, leaving a false sense of confidence behind a genuinely ungoverned dataset. The conversation covers where accountability actually sits when an autonomous agent makes a bad decision, why third-party models don’t dilute an organisation’s own responsibility for outcomes, and why Souvik pushes back on the idea that governance is an innovation-killing bureaucracy rather than the structural work that makes innovation possible in the first place. He also sets out a practical, staged approach to evaluating AI governance tooling rather than jumping straight to an enterprise platform, and offers a way to actually measure AI governance maturity using a weighted scoring model across multiple pillars. The discussion closes on an unexpected angle: the sustainability cost of AI infrastructure, and why Souvik believes environmental impact deserves a seat alongside profitability and productivity in any serious cost-benefit conversation about agentic AI.
Share this post
The link has been copied!