Adapted from my Substack. This is the first installment of a series operationalizing the resilience program from AI as Normal Technology.
Epistemic status: Confident in the core thesis, less certain of its broader significance. The closing section says what would move me.
AI use: I used Claude Opus 5.5 for research, drafts, and review. I manually reviewed and redrafted every word in the final version dozens of times, retaining AI text only when I could not improve upon it.
Much of the AI risk conversation centers on questions nobody can answer yet: when superintelligence arrives, whether it will be aligned, whether a global regulatory regime can hold capabilities back. Meanwhile, some paths to power that today's AI can exploit are wide open, and the government could close them cheaply. The one we'll focus on here: in most of the US, you can form a company without anyone checking who (or what) you are.
North Korea already uses AI to fake identities, down to deepfaked job interviews, and researchers warn that AI agents could soon run whole shell networks with hardly a human in sight. The UK and Australia started verifying who runs their companies months or years ago. A few weeks ago, Washington doubled down on the loophole instead.
Companies are how AI can get a foothold in the economy. A human does business under a name they were born with and can't shed. A company is the only kind of legal person you can create on demand and throw away when it gets caught. That's what makes it a path to power that matters for AI.
AI doesn't have a birth certificate
Being smart doesn't give AI power on its own. To actually hold anything, from money and property to contracts and employees, an AI needs companies, bank accounts, and credentials that only humans provide. Even hacking only gets it in, and the hard part of a big theft has always been the cash-out, not the break-in.
For humans, paperwork is costly without AI help, while identity comes with being born. So the old system made paperwork the barrier and waved identity through on a signature. AI breaks this system because it can do paperwork at scale virtually for free, and it has no identity and nothing to lose.
But that very lack of identity is AI's biggest weakness. It can file a million shell companies, but it can't make a million people liable for them. Whether AI is a fraudster's tool or acting on its own, it has to cash out through a gate only humans should ever pass through. The fix at every gate to power comes down to two things:
Identity: Verify and record an accountable human's personal information.
Liability: Make sure that human pays if something goes wrong.
In 1968, economist Gary Becker pointed out that deterrence comes down to the chance of getting caught times the price of getting caught. Identity gives us a high chance, and liability gives us a high price. Get both right everywhere, and even very capable AI probably won't be able to quietly accumulate unaccountable power. The human accomplices it needs to recruit will recoil from getting involved, and the few who do it anyway will be shut down and prosecuted.
Right now, nobody checks who forms a company
You'd think registering a company would already require a verified human. It doesn't. Companies are formed under state law, and most states ask only for an organizer and a registered agent. Neither has to be an owner, and nobody checks ID. Most states don't even require you to list the owners. Banks check that the owners a company names are real people, but take the company's word that they're the ones in charge.
That used to be good enough, because faking an ownership structure across dozens of companies took real work. AI does that work for free.
This identity loophole doesn't just risk letting through unaccountable AI agents; it already causes plenty of damage today. It's what makes "phoenixing" work: fraudsters create a shell company, and when the bills come due, they dissolve the company and start a new one under a different name. "Chameleon carriers" in trucking do this to shed their safety violations while honest truckers have to pay for their mistakes.
Washington is unfortunately widening the identity loophole. In August, FinCEN permanently exempted every US-formed company from reporting who owns it, calling the requirement a burden on small business, and even announced it would delete the unverified records Americans had already filed.
Identity and liability close the loophole
The process of forming a company should run through our two principles of deterrence. Here's how it would work.
Identity: At least one person who controls each company must verify their identity. For new companies, that happens at formation; for existing ones, within a year. A selfie and a photo of a license won't do, because AI can fake both. It has to be in person. The US Postal Service already provides in-person identity checks, and one visit gets you a verified login that covers every company you ever run. All we need now is the requirement.
Liability: If the company vanishes to dodge fraud judgments or penalties, including ones handed down after it's gone, the verified person must pay them, and can't run another company until they do. Honest businesses that fail keep their protection, since ordinary debts stay with the company.
Nobody has to prove who's really in charge, because whoever verified pays. The obvious fraudster workaround is a straw owner: pay some human to put their name on it. But that human now has to show up in person, so stolen and fake identities stop working. Every front is a real person investigators can find. Knowingly fronting for fraud should mean prison, not just a debt the front will never pay. Any one gate can be slipped, but AI can only print paperwork for free; it can't print people.
None of this is new. On the identity side, the UK now requires every new company director to verify their identity, for free. Australia has required verified director IDs since 2021, specifically to stop phoenixing. Our version should insist on checks AI can't fake, but the principle is proven. Congress can do it nationally, since a federal appeals court upheld its power to require ownership disclosure. States can also act on their own. On the liability side, the IRS already makes the people running a company personally pay withheld payroll taxes they willfully fail to turn over.
We don't need new solutions. We need to act on the ones that already exist.
Identity and liability block other AI risks, too
The principles of identity and liability also cover other economic chokepoints, like payment rails.[1] They even help against hacking, because they play a critical role in getting powerful AI to cyber defenders first. Anthropic has given a select group of defenders privileged access to its most powerful model, and runs a verification program so legitimate security professionals can keep using its models as new safeguards arrive. The faster we can reliably verify defenders, the more secure our systems will be when attackers inevitably figure out how to use advanced AI agents maliciously. Anthropic shouldn't have to solve this alone.
A different risk arises when legitimate people and companies hand AI power willingly. There, the emphasis shifts from identity to liability. We’ll dig into that in the next installment.
How to cope with uncertain times
I don't know if or how superintelligence will work, and neither does anyone else. The right response is a saying made famous by Deng Xiaoping: "crossing the river by feeling the stones." We act on what we can see, watch what happens, and adjust. If verified identity keeps cyber defense ahead of offense and suppresses corporate and financial fraud, that's reason for optimism that the accountability principle stretches a long way. If AI finds paths to power that never touch an accountable person, or it works mostly through voluntary delegation in the legitimate economy, that's cause for concern and different controls.
Either way, this is worth doing. It stops fraud we already have, it's cheap, and it closes a loophole AI can easily exploit. That's the kind of fix we should be lining up now, instead of waiting for a crisis to scare us into knee-jerk measures that solve nothing.
When ChatGPT made a decent essay free and instant, the fix that worked was the blue book and the oral exam: colleges moving the test to something AI can't fake. The same trick will help AI-proof cyberspace and the economy.
Cryptocurrency should not be an exception to this. Anyone can hold crypto without an ID check, but spending it on anything important should require one, just as big cash payments already do. The principles of identity and liability don't work in an unregulated financial system, and that is a decisive argument against an unregulated financial system.
Adapted from my Substack. This is the first installment of a series operationalizing the resilience program from AI as Normal Technology.
Epistemic status: Confident in the core thesis, less certain of its broader significance. The closing section says what would move me.
AI use: I used Claude Opus 5.5 for research, drafts, and review. I manually reviewed and redrafted every word in the final version dozens of times, retaining AI text only when I could not improve upon it.
Much of the AI risk conversation centers on questions nobody can answer yet: when superintelligence arrives, whether it will be aligned, whether a global regulatory regime can hold capabilities back. Meanwhile, some paths to power that today's AI can exploit are wide open, and the government could close them cheaply. The one we'll focus on here: in most of the US, you can form a company without anyone checking who (or what) you are.
North Korea already uses AI to fake identities, down to deepfaked job interviews, and researchers warn that AI agents could soon run whole shell networks with hardly a human in sight. The UK and Australia started verifying who runs their companies months or years ago. A few weeks ago, Washington doubled down on the loophole instead.
Companies are how AI can get a foothold in the economy. A human does business under a name they were born with and can't shed. A company is the only kind of legal person you can create on demand and throw away when it gets caught. That's what makes it a path to power that matters for AI.
AI doesn't have a birth certificate
Being smart doesn't give AI power on its own. To actually hold anything, from money and property to contracts and employees, an AI needs companies, bank accounts, and credentials that only humans provide. Even hacking only gets it in, and the hard part of a big theft has always been the cash-out, not the break-in.
For humans, paperwork is costly without AI help, while identity comes with being born. So the old system made paperwork the barrier and waved identity through on a signature. AI breaks this system because it can do paperwork at scale virtually for free, and it has no identity and nothing to lose.
But that very lack of identity is AI's biggest weakness. It can file a million shell companies, but it can't make a million people liable for them. Whether AI is a fraudster's tool or acting on its own, it has to cash out through a gate only humans should ever pass through. The fix at every gate to power comes down to two things:
In 1968, economist Gary Becker pointed out that deterrence comes down to the chance of getting caught times the price of getting caught. Identity gives us a high chance, and liability gives us a high price. Get both right everywhere, and even very capable AI probably won't be able to quietly accumulate unaccountable power. The human accomplices it needs to recruit will recoil from getting involved, and the few who do it anyway will be shut down and prosecuted.
Right now, nobody checks who forms a company
You'd think registering a company would already require a verified human. It doesn't. Companies are formed under state law, and most states ask only for an organizer and a registered agent. Neither has to be an owner, and nobody checks ID. Most states don't even require you to list the owners. Banks check that the owners a company names are real people, but take the company's word that they're the ones in charge.
That used to be good enough, because faking an ownership structure across dozens of companies took real work. AI does that work for free.
This identity loophole doesn't just risk letting through unaccountable AI agents; it already causes plenty of damage today. It's what makes "phoenixing" work: fraudsters create a shell company, and when the bills come due, they dissolve the company and start a new one under a different name. "Chameleon carriers" in trucking do this to shed their safety violations while honest truckers have to pay for their mistakes.
Washington is unfortunately widening the identity loophole. In August, FinCEN permanently exempted every US-formed company from reporting who owns it, calling the requirement a burden on small business, and even announced it would delete the unverified records Americans had already filed.
Identity and liability close the loophole
The process of forming a company should run through our two principles of deterrence. Here's how it would work.
Nobody has to prove who's really in charge, because whoever verified pays. The obvious fraudster workaround is a straw owner: pay some human to put their name on it. But that human now has to show up in person, so stolen and fake identities stop working. Every front is a real person investigators can find. Knowingly fronting for fraud should mean prison, not just a debt the front will never pay. Any one gate can be slipped, but AI can only print paperwork for free; it can't print people.
None of this is new. On the identity side, the UK now requires every new company director to verify their identity, for free. Australia has required verified director IDs since 2021, specifically to stop phoenixing. Our version should insist on checks AI can't fake, but the principle is proven. Congress can do it nationally, since a federal appeals court upheld its power to require ownership disclosure. States can also act on their own. On the liability side, the IRS already makes the people running a company personally pay withheld payroll taxes they willfully fail to turn over.
We don't need new solutions. We need to act on the ones that already exist.
Identity and liability block other AI risks, too
The principles of identity and liability also cover other economic chokepoints, like payment rails.[1] They even help against hacking, because they play a critical role in getting powerful AI to cyber defenders first. Anthropic has given a select group of defenders privileged access to its most powerful model, and runs a verification program so legitimate security professionals can keep using its models as new safeguards arrive. The faster we can reliably verify defenders, the more secure our systems will be when attackers inevitably figure out how to use advanced AI agents maliciously. Anthropic shouldn't have to solve this alone.
A different risk arises when legitimate people and companies hand AI power willingly. There, the emphasis shifts from identity to liability. We’ll dig into that in the next installment.
How to cope with uncertain times
I don't know if or how superintelligence will work, and neither does anyone else. The right response is a saying made famous by Deng Xiaoping: "crossing the river by feeling the stones." We act on what we can see, watch what happens, and adjust. If verified identity keeps cyber defense ahead of offense and suppresses corporate and financial fraud, that's reason for optimism that the accountability principle stretches a long way. If AI finds paths to power that never touch an accountable person, or it works mostly through voluntary delegation in the legitimate economy, that's cause for concern and different controls.
Either way, this is worth doing. It stops fraud we already have, it's cheap, and it closes a loophole AI can easily exploit. That's the kind of fix we should be lining up now, instead of waiting for a crisis to scare us into knee-jerk measures that solve nothing.
When ChatGPT made a decent essay free and instant, the fix that worked was the blue book and the oral exam: colleges moving the test to something AI can't fake. The same trick will help AI-proof cyberspace and the economy.
Thanks to Abi Olvera and Arvind Narayanan for helpful pre-publication reviews, and to AI as Normal Technology for the profound reframing of AI safety that inspired this piece.
Cryptocurrency should not be an exception to this. Anyone can hold crypto without an ID check, but spending it on anything important should require one, just as big cash payments already do. The principles of identity and liability don't work in an unregulated financial system, and that is a decisive argument against an unregulated financial system.