SEC commissioner advocates for zero-knowledge regulation, what’s next for brokerages and on-chain platforms?

CN
红线说书
49 minutes ago

In late September 2026, at the SIFMA Digital Assets Conference held in New York, U.S. SEC Commissioner Hester M. Peirce redirected the attention of the entire venue from prices and narratives back to the underlying logic of regulatory technology. According to reports from various Chinese cryptocurrency media, this commissioner, who has consistently been viewed as relatively friendly towards crypto assets, put forth a somewhat "non-traditional" argument during closed-door and public discussions aimed at brokerages, investment banks, and tokenization platforms: financial regulation should not continue to dwell on simply "collecting more data," but should try to utilize new technologies such as zero-knowledge proofs for more precise validation of key attributes that must be compliant. The examples she provided were specific enough—verifying whether a user meets age, citizenship, qualified investor status, or sanction list requirements without disclosing personal information such as names, incomes, or addresses—while acknowledging that public blockchains generate permanent, public, and auditable transaction records that law enforcement agencies can overlay with blockchain forensic tools to track illegal activities. This emphasis on data minimization while affirming on-chain traceability was understood by many attending institutions as a public reflection on the "big data surveillance regulatory model": in the future, regulation should not aim for as much underlying data as possible, but rather, within the boundaries of technological feasibility and legal allowance, collect just enough information to make compliance judgments. Although as of September 24, 2026, there was no evidence that this speech had been formally incorporated into SEC rules or guidance documents, it has nonetheless cast a shadow over the risk control systems of brokerages, compliance frameworks of tokenization platforms, and the ways on-chain users' identity and transaction data are utilized—signifying a shift in compliance games for brokerages, tokenization platforms, and on-chain users from who possesses the most data to who can provide the most trustworthy proof with the least amount of data within the framework recognized by regulators.

Rewriting Regulation from "Big Data Surveillance" to "Attribute Verification"

Before Peirce proposed "providing the most trustworthy proof with the least amount of data," the habitual path of securities and anti-money laundering regulation had been a nearly default model of big data surveillance: brokerages, trading platforms, and tokenized asset service providers collected as much detailed information as possible about customers—such as names, income levels, and addresses—during account opening and continuous due diligence for identity verification, risk categorization, and transaction monitoring. Regulatory departments and self-regulatory organizations continuously pulled these underlying data into their view through reporting rules. In this model, privacy costs and compliance costs rose in tandem—compliance teams had to maintain large and sensitive databases to respond to transparency checks and data retention requirements, while customers increasingly entrusted more personal and financial details to institutions and the regulatory systems that could potentially retrieve them each time they were asked to "provide a bit more information."

Peirce's speech in New York was a challenge to this path, as she suggested that regulation shift from "collecting more data" to "verifying more precisely," urging regulators to reconsider traditional financial monitoring methods. According to PANews reports, she pointed toward a regulatory approach based on attribute verification using zero-knowledge proofs: no longer requiring the exposure of names, incomes, or specific addresses, but only verifying several key attributes—whether the statutory age is reached, whether one has a specific citizenship, whether one meets qualified investor standards, and whether one appears on the sanction list. Under this approach, if it is included in future regulations, U.S. brokerages and on-chain trading platforms will be forced to reshape their monitoring and reporting paths: front-end processes will shift from "collecting all information" to "obtaining attributes proof acceptable to regulators," and back-end systems will transition from "storing a complete library of personal data" to "managing auditable attributes and proof chains." The value of compliance service providers will also transform from accumulating data for institutions into designing and operating regulatory-compliant attribute verification frameworks, meaning that the core competitive advantage in compliance will shift from who can access more personal information to who can meet regulatory needs with lower levels of exposure under existing legal requirements.

Envisioning Compliance with Zero-Knowledge Proofs and Public Ledger

In the regulatory scenario depicted by Peirce, the front end and back end are completely decoupled: the front end only answers "whether a certain compliance condition is met," while the back end records the movement of funds and assets on the public ledger. The role of zero-knowledge proofs is precisely to decouple these two layers—it demonstrates the truth of a proposition without disclosing underlying data, such as whether a person is over 18 years old or whether they have assets exceeding regulatory thresholds, without telling the system how old they are or how much money they have. Peirce referenced this principle, extending it to sharper scenarios in financial regulation: during account opening or issuance participation, platforms do not need to require users to provide names, incomes, or addresses but can verify whether they meet age, citizenship, qualified investor standards, or whether they are not on the sanction list through zero-knowledge proof modules; qualification is represented merely by a "pass/fail" proof, rather than a whole set of potentially misused personal information profiles.

However, she does not aim to turn the system into a "black box," but rather emphasizes its integration with public ledgers: once a transaction occurs, it still writes into the permanent, public, and auditable on-chain ledger, while law enforcement and compliance teams utilize continuously evolving on-chain forensic tools to trace illegal suspicions along the flow of funds. In other words, who the user is and where they live can remain undisclosed, but where the money departs from, which intermediary accounts it traverses, and where it ultimately arrives must be clearly logged in the on-chain timeline. The new regulatory infrastructure envisioned by Peirce uses zero-knowledge proofs as a "compliance gate" at the entry point, allowing only those who pass attribute verification to proceed, while using public ledgers and forensic tools for "post-audit" at the exit point, enabling both privacy and accountability, allowing platforms, brokerages, and on-chain projects to operate within the same verifiable and auditable paradigm.

The Boundary Game Between Data Minimization and Enforcement Needs

Peirce's proposal of "collecting less data, verifying more" directly collides with the compliance inertia built over decades within the U.S. financial system. The underlying logic of KYC, anti-money laundering, and securities compliance has consistently been to require brokerages, custodians, and on-chain platforms to maintain as complete a record of client identities and transaction histories as possible so that regulatory and enforcement agencies can access and trace this information at any time. If zero-knowledge attribute verification only leaves "pass/fail" compliance results at the entry point and no longer retains underlying information such as names, addresses, and income levels, it will touch upon the hard requirements of existing regulations regarding "record retention" and "auditability": enforcement agencies traditionally expect "visible records," yet data minimization intentionally prevents these records from being fully collected.

The real sharpness of the conflict lies in the investigation and sanction enforcement aspects. The case logic surrounding insider trading, market manipulation, and sanctions violations relies on linking on-chain addresses with real identities, account opening processes, and suitability assessment records to form a complete chain of evidence. If the entry point only conducts zero-knowledge attribute verification and the on-chain only retains a public ledger without centralizing detailed client information, future attempts at record subpoenas, asset freezes, and holding intermediary institutions accountable may hinge on whether regulators can require platforms to "restore" hidden personal information and whether the technology structure of zero-knowledge proofs is considered "qualified records," which will become a point of contention regarding authorization boundaries. More critically, this line of thought is still resting on Peirce's individual directional initiative in industry meetings; relevant speeches have yet to form formal texts on the SEC website, and there are no publicly available signals indicating that "data minimization + attribute verification" has been incorporated into compliance checklists through any rule revisions or guidance documents. Even if brokerages and on-chain platforms can technically achieve this, it can only be regarded as a forward-looking exploration rather than an existing obligation; significant boundary changes depend on whether there will be rule modifications, pilot exemptions, or explicit signals such as no-action letters in the future.

Traditional Brokerages and Tokenization Platforms' KYC Transformation at SIFMA

In the New York venue, the compliance leaders of traditional brokerages, investment banks, and tokenized asset platforms were filled to capacity as they listened to Peirce's vision of shifting regulatory logic from "collecting more data" to "precise verification," all while calculating how to revamp KYC stacks. Most institutions currently rely on centralized KYC systems and internal compliance teams for identity verification and sanction screening, central to which is capturing all underlying data including customer names, addresses, incomes, and identification proofs, and then comparing each against a checklist. Peirce's proposal to use zero-knowledge proofs to verify age, citizenship, qualified investor status, or whether one is on the sanction list, without disclosing these underlying details, presents a new technological track to existing processes for these institutions: one end remains their familiar account opening and KYC front end, while the other end might connect with third-party identity verification and zero-knowledge service providers through APIs to access identity data providers, sanction list databases, and on-chain proof generation tools, sending back the conclusion of "whether compliant with regulatory attributes" to brokerages and platforms without retaining all original data on their servers.

This also directly opens a narrative space for compliance service providers and API infrastructure companies: those who can package identity verification, fund flow monitoring, and attribute verification into pluggable compliance modules will have a greater opportunity to become the external brain for brokerages and tokenization platforms’ KYC transformations. Simultaneously, HIFI, a payment token and tokenized asset company in New York, announced that it has completed a $37 million Series A funding round, led by Left Lane Capital, with funds intended to expand tokenized capital market infrastructure and API product lines. Many view this investment in the current regulatory context as a bet on "compliance-friendly tokenized infrastructure." For institutions at the SIFMA venue, a more realistic technical path may not be to develop zero-knowledge engines themselves but to interface with infrastructures like HIFI through APIs to unify customer identity verification, attribute proof, and fund flow compliance monitoring, gradually aligning towards a regulatory stance of "collecting less data, valuing attributes," while maintaining existing compliance responsibility divisions. Those who can first achieve such embedded transformations will have a greater opportunity to seize the initiative in the next round of regulatory and capital competition in the tokenized capital market.

The Rise of Regulatory Technologists and New Tracks for Crypto Compliance

Peirce's comments at the SIFMA Digital Assets Conference were widely recounted by several Chinese media outlets around September 24. As a long-time SEC commissioner viewed as friendly toward crypto, her public advocacy for transitioning from "collecting more data" to relying on zero-knowledge proofs for attribute verification and data minimization is, in itself, a test of the existing compliance boundaries: if regulators can accept verifying age, citizenship, qualified investor status, and sanction list matching without exposing names, incomes, and addresses, then the technical stack surrounding identity verification, on-chain proof gathering, and API compliance services in the crypto industry and capital markets has the opportunity to transition from "regulated objects" to "regulatory implementation tools," and the division of responsibilities among brokerages, tokenization platforms, and compliance institutions may also be rewritten in this process. In the short term, this appears more as a collective call from regulatory technologists rather than an official route—speech texts have not yet been fully verified on the SEC's official website, nor are there any public signals indicating a transition into rules or guidance documents. The specific implementation path will still need to undergo multiple layers of selection through internal SEC negotiations, congressional legislation, and inter-agency coordination, making it likely that only in the medium to long term will it find its way into institutional frameworks via pilot projects or technical guidelines. At the same time, HIFI has announced that it completed a $37 million Series A funding round; its investment in compliance-friendly tokenized market infrastructure and API products resonates with Peirce's push for on-chain audits and identity attribute verification regulatory thinking, raising the bar for competition over "who will bear the new generation of compliance." For project parties, trading platforms, and third-party compliance institutions, what truly needs to be watched in the next few years is not only the regulatory stance on a particular chain or type of asset but three new tracks: first, identity verification technologies that can be integrated into existing KYC processes and support zero-knowledge attribute proof; second, on-chain forensic and auditing tools aimed at public ledgers; and third, compliance API services designed around the principle of data minimization. Those who can present technology solutions acceptable to the SEC and traditional financial institutions along these three main lines will have the opportunity to establish new footholds in the reconfiguration of the crypto compliance landscape.

Join our community and discuss with us, let’s become stronger together!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

Disclaimer: This article represents only the personal views of the author and does not represent the position and views of this platform. This article is for information sharing only and does not constitute any investment advice to anyone. Any disputes between users and authors are unrelated to this platform. If the articles or images on the webpage involve infringement, please provide relevant proof of rights and identity documents and send an email to support@aicoin.com. The relevant staff of this platform will conduct an investigation.