AI fraud loophole in US company formation widens as regulator loosens rules

Related

Share

Somewhere in America right now, anyone can start a company without ever proving who they are. No ID, no interview, no verification. It sounds like a bureaucratic footnote, but it has quietly become one of the most exploitable weaknesses in the US economy — and it is exactly the kind of gap that artificial intelligence is built to exploit. This AI fraud loophole in US company formation rules is drawing fresh scrutiny as regulators abroad move in the opposite direction.

Key takeaways

  • Most US states let people form a company without verifying the identity of the owners or controllers behind it.
  • The UK and Australia already require verified identity for company directors, specifically to fight fraud schemes like “phoenixing.”
  • In August, FinCEN permanently exempted US-formed companies from reporting who owns them and said it would delete unverified ownership records already on file.
  • AI can generate huge numbers of shell companies almost instantly, but it cannot take on personal legal liability the way a human can.
  • Proposed fixes include in-person identity checks — potentially through the US Postal Service — paired with strict liability for verified individuals whose companies are used for fraud.

The US Company Formation Identity Loophole

The core problem is simple to state and hard to ignore: in most of the country, forming a business entity requires almost no proof of who is actually behind it.

Lack of Identity Verification in Most States

Companies in the US are formed under state law, and most states only ask for an organizer and a registered agent. Neither one has to be an owner of the company, and nobody checks anyone’s ID during the process. Most states do not even require a list of who actually owns the business. Banks will confirm that the people a company names as owners are real, breathing humans — but they generally take the company’s word for who is actually in charge. For decades, that arrangement worked well enough, because faking an ownership structure across dozens of shell companies took real time and effort.

Risks Posed by AI in Exploiting This Loophole

That barrier has effectively disappeared. AI systems can now handle the paperwork of company formation at scale, virtually for free, without needing sleep, a salary, or a legal identity of their own. That is precisely what makes the current AI fraud loophole US regulators have left open so dangerous — the old system assumed fraud required manual effort, and AI removes that constraint entirely.

There is a limit, though. AI can file a million shell companies in an afternoon, but it cannot make a million people personally liable for what those companies do. That gap between infinite paperwork and finite human accountability is where any real fix has to start.

International Approaches to Combat Fraud

Other countries have already closed the door that the US left open, using identity checks aimed squarely at the people running companies rather than the paperwork itself.

UK and Australia Verified Identity Requirements

The UK now requires every new company director to verify their identity, and it does so for free. Australia has gone further for longer: it has required verified director IDs since 2021, a measure introduced specifically to stop “phoenixing,” where a fraudulent company dissolves once its bills come due and simply reopens under a new name. In trucking, a similar trick known as “chameleon carrier” fraud lets operators shed safety violations by relaunching as a new company, leaving honest truckers to absorb the costs of playing by the rules. These schemes are old, but they illustrate exactly the kind of abuse that unverified company formation invites — and exactly what identity checks are designed to stop.

Recent US Regulatory Developments Widening the Loophole

Rather than tightening the rules, Washington moved the other way this year. In August, the Financial Crimes Enforcement Network, or FinCEN, permanently exempted US-formed companies from reporting who owns them, describing the ownership-disclosure requirement as a burden on small businesses. FinCEN went a step further and announced it would delete the unverified ownership records that companies had already filed. In practice, that decision widens rather than narrows the identity gap that AI-driven fraud can exploit, at the same moment other governments are moving toward stricter verification.

Proposed Measures to Close the Loophole

Closing the gap does not require new technology or an untested regulatory model — it requires applying two old, well-understood principles: verified identity and enforced liability. As economist Gary Becker argued back in 1968, deterrence comes down to the odds of getting caught multiplied by the cost of getting caught. Identity raises the odds; liability raises the cost.

In-Person Identity Verification Leveraging USPS Infrastructure

Under this proposal, at least one person controlling each company would have to verify their identity — at formation for new companies, and within a year for existing ones. A selfie and a photo of a driver’s license would not be enough, since AI can already fake both convincingly. The check would need to happen in person. The US Postal Service already runs in-person identity verification, and a single visit could produce a verified login covering every company that person ever forms or runs. The infrastructure already exists; what is missing is the requirement to use it.

Enforcing Liability on Verified Individuals

The second half of the fix is liability. If a company disappears to dodge a fraud judgment or penalty — even one handed down after the company is gone — the verified person behind it would have to pay, and would be barred from starting another company until they do. Honest businesses that simply fail would keep their normal legal protections, since ordinary debts would still stay with the company rather than the individual.

The obvious workaround is a straw owner: paying someone else to put their name on the paperwork. But that person would still have to show up in person to verify their identity, which rules out stolen or fake identities and leaves a real, findable person on record. Knowingly fronting for fraud, under this framework, would carry criminal liability rather than just an unpaid debt.

The same identity-and-liability logic extends beyond company formation. It applies to other economic chokepoints like payment systems, and it can also strengthen cybersecurity: Anthropic already runs a verification program that gives trusted cybersecurity professionals privileged access to its most capable AI models, so defenders get powerful tools before attackers do.

FAQ

Why is identity verification important in company formation?

Identity verification ensures a real human is accountable, preventing anonymous shell companies and reducing fraud risks.

How do the UK and Australia handle company director identity verification?

The UK requires new directors to verify their identity for free, and Australia has required verified director IDs since 2021 to combat fraud like phoenixing.

What role does AI play in exploiting company formation loopholes?

AI can create many shell companies quickly at scale but cannot assume human liability, enabling fraud if identity and liability are not enforced.

What solutions are proposed to close the US AI fraud loophole in company formation?

Proposals call for requiring in-person identity verification using existing infrastructure like the US Postal Service, paired with enforced liability so verified individuals are financially responsible for company misconduct.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.