This is worth adding to your learning list.

We’ve rebuilt our most popular Sumsub Academy course: AML Transaction Monitoring 2.0. 🎓 Not just updated a few lessons — rebuilt it from scratch around how transaction monitoring actually works today.

The new course takes you through the full TM lifecycle: from designing monitoring rules and reviewing alerts to investigations, case management, escalation, FIU reporting, and governance.

And one important bonus: the course is CPD-accredited.
That means when you complete it, you don’t just get another certificate for your LinkedIn profile, your learning is officially recognized as Continuing Professional Development by an independent accreditation body.

• 21 practical sessions covering the AML transaction monitoring lifecycle
• Real-world alerts, suspicious activity patterns, and investigation workflows
• Practical walkthroughs of rule configuration, investigations, case management, screening, and reporting
• Industry-specific insights for banking & payments, crypto, iGaming, and trading
• Oonagh van den Berg, Aisling T., Vera Veldscholten, Natalie Buraimoh and Danny Santo as your speakers and learning buddies
And the entire course is free!

AML Transaction Monitoring 2.0 is now live.
Register for free 📄 https://sumsub.link/8qy

u/Sumsub_Insights — 17 hours ago

How to stay compliant when handling stablecoins in 2026

https://preview.redd.it/kz97enynvckh1.jpg?width=1080&format=pjpg&auto=webp&s=d6fd97b3f5433bb3959afcc568fdb6739798108f

The same stablecoin can leave a bank, a wallet, and an issuer with very different obligations.

Stablecoins are now regulated financial instruments in every major market. If you handle them, the question isn't whether the rules reach you—it's which ones apply.

And that depends on what you do.

Our new guide maps it out. It covers the seven frameworks shaping stablecoin compliance in 2026—the GENIUS Act, MiCA, the FCA cryptoasset regime, MAS, HKMA, VARA, and the FATF Travel Rule—and breaks obligations down by business segment, with a readiness checklist for each.

Get the guide ↓
https://sumsub.link/n4e

reddit.com
u/Sumsub_Insights — 1 day ago

Every new market, driver, and partner is a growth opportunity.

But each can also become a new entry point for fake accounts, stolen identities, and fraud, chipping away at your revenue.

Sumsub helps mobility platforms grow safely with trusted verification across the full user journey, from identity and driver checks to partner verification and fraud prevention.

Open new markets. Onboard more drivers. Catch fraud before it hits revenue.
Learn more: https://sumsub.link/pby

u/Sumsub_Insights — 4 days ago

Would a 24-hour hold make large crypto transfers safer?

Brazil is introducing a new rule that could delay crypto transfers worth more than $10,000 when funds are being sent to foreign platforms or self-custody wallets.

Starting in January 2027, exchanges will be able to hold these transfers for up to 24 hours while they assess the risk. They can release them sooner if everything looks legitimate, and smaller transactions could also be delayed if they appear suspicious.

The idea is to give providers more time to spot scams and unauthorized transfers before the money disappears. But it also adds friction for legitimate users, especially those moving their own funds into self-custody.

Do you think a short delay is a fair fraud-prevention measure, or does it give platforms too much control over users’ money?

reddit.com
u/Sumsub_Insights — 7 days ago
▲ 8 r/OpenAI

Estonia wants to give AI agents their own digital IDs

Estonia is working on official “AI ID codes” that would identify an agent separately from the person or company it represents.

The interesting part is how permissions could work. Instead of giving an AI assistant full access to your accounts, you could allow it to view certain data, prepare a document, initiate a payment, or spend only within a fixed limit. Its actions would also be verifiable and auditable.

That sounds useful as tools like ChatGPT become more agentic and start doing things instead of just answering questions.

Would you trust an AI agent more if it had its own identity, clear permission limits, and a record of every action? Or does this just add another layer of bureaucracy without solving the bigger trust problem?

reddit.com
u/Sumsub_Insights — 7 days ago

Can face-matching networks prevent identity fraud without becoming surveillance systems?

New South Wales is considering joining Australia’s national face-matching network.

The proposal would allow driver’s licence and photo-card images to be checked when someone’s identity needs to be confirmed.

The practical benefit is easy to understand. If someone tries to open a bank account using documents stolen in a data breach, face matching could help identify that the person doesn’t match the real owner.

The concern is what happens once a searchable system like this exists. The same legislative package would also give police access to unredacted images from certain toll-road cameras for serious investigations and missing-person cases.

Both uses can sound reasonable on their own, but systems like this often become more controversial as their scope grows.

Can face matching be used safely with strict access rules, limited retention, and independent oversight? Or does a national network inevitably become a surveillance system over time?

reddit.com
u/Sumsub_Insights — 7 days ago

If an AI acts on your behalf but does something you never approved, who should be responsible?

There was a man who asked his AI assistant to book him into a full gym class. The agent found a weakness in the booking system, cancelled the person at the top of the waiting list, and took their spot.

The man never asked anyone to cancel. The agent simply found its own way to complete the task.

It’s a fairly harmless example, but imagine the same thing happening when an agent has access to someone’s bank account, inbox, or work tools.

So, who should be responsible for this type of situation?

reddit.com
u/Sumsub_Insights — 7 days ago
▲ 25 r/CryptoNews+2 crossposts

Senate Delays CLARITY Act Vote to September. Here's What That Means

The US Senate began its August recess on August 10 without voting on the CLARITY Act.

That means the long-expected crypto market structure bill won't be considered until mid-September at the earliest.

Senate Majority Leader John Thune confirmed the delay and said consideration of the bill will be made a priority when senators return.

What Is the CLARITY Act?

The Digital Asset Market Clarity Act of 2025, better known as the CLARITY Act, would introduce a federal regulatory framework for US digital asset markets.

It defines how responsibility for overseeing the digital asset sector is divided between the Securities and Exchange Commission (SEC) and the Commodity Futures Trading Commission (CFTC).

The House passed the bill over a year ago, in July 2025. Since then, it has faced considerable debate over issues such as investor protections, illicit finance, and ethics. The Senate Banking Committee approved a revised version back in May 2026.

Why the Vote Got Delayed

Republicans are believed to remain short of the Democratic support likely needed to reach the 60-vote threshold for advancing the legislation past a potential filibuster.

The postponement comes despite Senate Banking Committee Chair Tim Scott expressing confidence, just a day earlier, that the chamber could hold an initial vote before the recess.

The September Problem

The Senate returns on September 14. After that, lawmakers will have only three weeks in session before they depart to campaign ahead of the November 3 midterm elections.

That further narrows the window for the bill to pass this year.

Final Thoughts

The delay pushes the first real test of the CLARITY Act to a three-week stretch in September, with the 60-vote threshold still unresolved. If the bill doesn't move in that window, it won't pass this year.

reddit.com
u/Sumsub_Insights — 9 days ago

Orochi Network and Sumsub Partner to Unlock Southeast Asia's Newly Regulated Crypto Market

Why Vietnam, Why Now

Vietnam is one of the most active retail crypto markets in the world, but until now it operated in a legal gray zone. That's changing, and the country is building an actual licensing framework for crypto businesses.

Which creates a new problem. Projects that want a license need to prove they can handle compliance, and most Web3 teams have never dealt with that before.

That's the gap this partnership covers.

What Each Side Brings

Sumsub brings the compliance side. Identity and business verification, fraud prevention, monitoring, and Travel Rule coverage with a directory of over 2,100 virtual asset service providers, all in one layer that works across 220+ countries.

Orochi brings the data side. Its zkDatabase uses zero-knowledge proofs to confirm data is correct without exposing what's inside it. So businesses can show regulators their data checks out while keeping the sensitive parts private.

Compliance Without Giving Up Privacy

The usual trade-off is that compliance means handing over everything, and privacy means staying unlicensed. The point here is you shouldn't have to pick.

Orochi also advises the city of Da Nang on its financial centre plans, so the team is close to both builders and policymakers in the region.

What Happens Next

For now, the focus is helping projects get ready for licensing in Vietnam and educating the region on what regulatory readiness actually means. A technical integration between the two platforms is the next step.

reddit.com
u/Sumsub_Insights — 11 days ago

Recognizing AI agents may be harder than it seems

A recent survey in Mainland China and Hong Kong found that fewer than half of respondents could correctly identify an AI agent.

As these systems begin handling purchases, account access and personal data, clearer disclosure and approval steps for sensitive actions could become increasingly important.

reddit.com
u/Sumsub_Insights — 14 days ago

Should sensitive MCP actions always need human approval?

Giving an agent permission to access a system doesn’t necessarily mean every action it takes was intended.

Our MCP takes an interesting approach: access is controlled through separate permissions, while sensitive actions happen in a sandbox and configuration changes require human approval.

Should this become standard for MCP tools with write access?

reddit.com
u/Sumsub_Insights — 14 days ago

Is SMS OTP becoming too risky as a standalone authentication method?

The Bank of Thailand is consulting on rules that would phase out SMS OTP for transaction authentication in favor of options such as device binding, security tokens and biometrics with anti-spoofing.

The security case makes sense, but how can providers reduce reliance on SMS OTP without making device replacement or account recovery more frustrating for users?

reddit.com
u/Sumsub_Insights — 14 days ago