Anyone in the United States can now establish a company without having to prove their identity. No identification documents are required, no in-person interviews are needed, and no verification is necessary. This might sound like a minor note in a bureaucratic process, but it has quietly become one of the most exploitable weaknesses in the U.S. economy, and it is precisely this loophole that artificial intelligence is best at exploiting. As overseas regulatory authorities are moving in the opposite direction, this fraud loophole in U.S. company establishment rules is being re-examined.
Key Points
- In most states in the United States, it is allowed for people to establish companies without having to verify the identity of the owners or controllers behind those companies.
- The UK and Australia have already required company directors to undergo identity verification, specifically to combat fraud tactics such as “phoenixing”.
- In August, FinCEN permanently exempted companies established in the United States from disclosing actual ownership, and stated that it would delete archived but unverified ownership records.
- AI can generate a large number of shell companies almost instantaneously, but it cannot bear personal legal responsibilities in the same way that humans can.
- The proposed fix includes face-to-face identity verification, which may be conducted through the United States Postal Service, and imposes strict responsibilities on the verified individuals; if their companies are used for fraud, they will bear the consequences.
Identity vulnerabilities in the establishment of U.S. companies
The core issue is very simple, yet it cannot be ignored: in most regions of the United States, there is almost no need to prove who the actual person in control behind a business entity is.
Lack of identity verification in most states

American companies are established in accordance with state laws, and most states require only one organizer and one registered agent. Neither of these individuals needs to be the owner of the company, and no one's identification documents are verified during the process. In fact, most states do not even require the listing of the actual owners of the business. Banks will confirm that the owners claimed by the company are indeed real persons, but they usually simply accept the company's statement regarding the person in control. For decades, this arrangement has been barely feasible, as forging ownership structures among dozens of shell companies required substantial time and effort.
AI Risks of exploiting this vulnerability
Today, this barrier has almost disappeared. The AI system can now process company establishment documents on a large scale with almost no cost, without the need for sleep, no need for a salary, and it does not possess its own legal identity. It is precisely for this reason that the AI fraud loophole left by US regulators is so dangerous – the old system assumed that fraud required human intervention, whereas the AI has eliminated this restriction.
However, there is still one limitation. AI can submit the documents of one million shell companies in one afternoon, but it cannot hold one million people personally responsible for what these companies do. A true solution must start by addressing the gap between “infinite documents” and “limited human responsibility.”
International Practices in Combating Fraud
Other countries have already closed the door left by the United States, by directly verifying the identity of the actual operators of companies, rather than just relying on paper documents.
Authentication requirements in the UK and Australia
The UK now requires identity verification for every new company director, and it's free of charge. Australia took an even earlier and more proactive step: since 2021, director identities have been required to be verified. This measure is specifically designed to prevent the practice of "_phoenixing" – where fraudulent companies dissolve after their bills are due and then re-open under a new name. In the trucking industry, there is a similar type of fraud involving "chameleon carrier", where operators get rid of their safety violation records by re-registering as new companies, leaving the costs to the honest, law-abiding truck drivers. These tactics are not new, but they illustrate the kind of abuse that can arise from unverified company formations, and also show that identity verification is intended to prevent such situations.
Recent regulatory moves in the United States have expanded these vulnerabilities.
This year, Washington has not tightened the rules; instead, it has gone in the opposite direction. In August, the Financial Crimes Enforcement Network FinCEN granted permanent exemptions to U.S. companies from disclosing beneficial ownership information, stating that such disclosure requirements imposed a burden on small businesses. FinCEN further stated that they would delete previously submitted, unverified ownership records. In fact, this decision has expanded rather than narrowed the identity gaps that can be exploited for fraud by AI, while at the same time, other governments are moving towards stricter verification measures.
Proposed measures to plug loopholes
Plugging this gap does not require new technologies or untested regulatory models – it simply requires the application of two old and clear principles: identity verification and accountability. As economist Gary Becker pointed out as early as 1968, deterrence depends on the probability of being caught multiplied by the cost of being caught. Identity verification increases the probability; accountability increases the cost.
Conduct face-to-face identity verification using the USPS infrastructure.
Under this scheme, at least one controller of each company must have their identity verified – new companies must undergo verification upon establishment, while existing companies must complete it within one year. Selfies and driver's license photos are not sufficient, as AI is already capable of forging these documents quite realistically. Verification must be conducted offline. The United States Postal Service has already been implementing face-to-face identity verification, which can generate a verified login identity in a single visit, which can then be used for all companies that person establishes or operates in the future. The infrastructure is already in place; what is lacking is the requirement to mandate its use.
Impose responsibility on verified individuals
The other half of the solution lies in responsibility. If a company disappears in order to evade a fraud conviction or fine—even if the conviction is made after the company has ceased to exist—the verified individuals behind it must make the payment, and they are not allowed to establish new companies until the payment is fully made. For honest businesses that have simply failed, their normal legal protections remain in place, as ordinary debts are still borne by the company, not by the individuals.
An obvious way to circumvent this is to find a “front man”: pay someone to have their name listed on the documents. However, this person still has to be present in person for identity verification, which rules out the possibility of using a stolen or forged identity. As a result, only a real, identifiable person will be recorded in the documents. Under this framework, knowingly acting as a front man for fraud will incur criminal liability, not just unpaid debts.
The same "identity + responsibility" logic can also be extended beyond the establishment of companies. It applies to other critical economic sectors such as payment systems and can also enhance network security: Anthropic has already implemented a verification program that allows trusted cybersecurity professionals to have priority access to its most powerful AI models, thereby giving defenders powerful tools before attackers.
Frequently Asked Questions
Why is identity verification important during the establishment of a company?
Identity verification ensures that real individuals are responsible for their actions, prevents anonymous shell companies, and reduces the risk of fraud.
How do the UK and Australia handle the verification of corporate director identities?
The UK requires new directors to verify their identities for free; since 2021, Australia has also mandated that directors' identities must be verified in order to combat fraud such as phoenixing.
What role does AI play in exploiting vulnerabilities in company setups?
AI allows for the rapid creation of a large number of shell companies on a large scale, but it cannot assume human responsibilities; if mechanisms for identity verification and accountability are not implemented, it will only encourage fraud.
What solutions are available to plug the fraud vulnerabilities in the US AI?
It is recommended to use existing infrastructure such as the United States Postal Service for face-to-face identity verification, and to cooperate with accountability measures, so that individuals who have been verified may bear financial responsibility for the company's improper actions.
This article was assisted by artificial intelligence and reviewed by an editorial team.











