State of the Crypto Industry 2026 report with Sumsub VP North America, Danielle Labarbera

The crypto industry is entering its era of regulated maturity, shaped by new frameworks such as the CLARITY and GENIUS Acts. At the same time, fraud is evolving into AI‑driven, lifecycle‑based attacks that demand smarter defenses. In this interview, Danielle Labarbera, Sumsub VP North America, shares more insights from its State of the Crypto Industry 2026 report, covering regulation, fraud resilience, stablecoins, and the future of verification.
What is Sumsub?
Q: To start, can you tell us a bit about Sumsub and the role it plays in the crypto ecosystem today?
A: Sumsub helps crypto businesses establish and maintain trust throughout the customer lifecycle. That starts with verifying individual and business customers, but it also covers fraud prevention, AML screening, transaction monitoring, and Travel Rule compliance.
We work with more than 1,000 crypto companies, including eight of the ten largest global crypto exchanges, so we see firsthand how quickly both fraud and regulatory expectations are changing.
The important shift is that verification can no longer be treated as a gate that a customer passes through once. With 55% of crypto companies experiencing fraud last year, businesses need to understand whether a user’s identity, behavior, and transactions continue to make sense over time. Our role is to help them do that while keeping the experience as smooth as possible for legitimate customers.
2026 as a ‘regulatory maturity era’
Q: The report refers to 2026 as the ‘regulated maturity era’. The industry spent years asking for regulatory clarity. We now have developments such as the CLARITY Act and the GENIUS Act in the United States. What do these frameworks mean for businesses operating in the space?
A: These frameworks give businesses a clearer indication of the standards that will shape the US digital-asset market. The CLARITY Act addresses market structure and the division of regulatory oversight, while the GENIUS Act establishes requirements for payment stablecoins, including issuer eligibility, reserves, redemption, disclosures, AML compliance, and consumer protection.
Greater clarity can help businesses plan investments, develop products, and enter the market with greater confidence. However, it also raises the operational standard expected of them. Compliance can no longer exist solely in written policies; platforms need to demonstrate that their identity, transaction-monitoring, and reporting systems work accurately, consistently, and at scale.
That is what the report means by regulated maturity. The differentiator is shifting from simply understanding the rules to being able to execute them without creating unnecessary friction for legitimate users. The businesses best positioned to benefit will be those that embed compliance, fraud resilience, and user experience into one coherent operating model.
Q: According to the report, only 23% of crypto businesses are fully Travel Rule-compliant, while 43% don’t know whether they comply with the requirement. Is this due to low awareness, high costs, or another factor holding them back?
A: It is less about businesses not knowing that the Travel Rule exists and more about how difficult it is to operationalize consistently.
At a basic level, the Travel Rule requires crypto businesses to collect, verify, and securely transmit information about the originator and beneficiary of a virtual-asset transfer. In practice, that means determining when the rule applies, identifying the counterparty, screening both parties, securely exchanging the required information, and maintaining an auditable record of the transfer.
The difficulty is that businesses do not operate under a single universal rulebook. Thresholds, required data fields, privacy laws, and approaches to self-hosted wallets differ between jurisdictions. Platforms may also use different Travel Rule protocols that do not always interoperate smoothly.
Cost is certainly part of the issue. In our research, 52% of businesses identified costly implementation as a key challenge. But data security ranked even higher at 62%, while 50% cited regulatory fragmentation and 38% pointed to interoperability.
That helps explain why 43% are unsure of their status. A business may have implemented some of the required capabilities but still lack confidence that the process works across every jurisdiction, counterparty, and transaction type. Travel Rule compliance now goes beyond simply switching on a protocol; it requires ongoing risk management.
Crypto fraud and AI
Q: How are fraud strategies evolving in 2026?
A: One of the biggest changes we’re seeing is that fraud is becoming increasingly sophisticated.
Fraud has evolved from isolated attacks into coordinated, AI-enabled operations. Instead of relying on fake documents or stolen identities, fraudsters are combining deepfakes, synthetic identities, social engineering, account takeovers, and mule networks across multiple stages of the customer journey. The attacks are becoming more automated, more convincing, and much harder to detect because they’re designed to mimic legitimate user behavior.
That’s changing how businesses approach fraud prevention. Point-in-time checks at onboarding are no longer enough. Our research shows that organizations are increasingly investing in AI-powered fraud detection, continuous monitoring, and behavioral analytics to understand how risk evolves throughout the customer lifecycle.
The strongest strategies now connect identity, behavior, devices, and transaction intelligence into a single view of risk, allowing businesses to detect threats earlier while keeping the experience seamless for legitimate users.
Q: AI is changing almost every industry. How is it changing fraud?
A: AI has changed both sides of the fraud equation. It’s making fraud faster, cheaper, and easier to scale, allowing criminals to generate convincing fake identities, deepfakes, and synthetic documents in minutes rather than hours or days.
But it’s also changing how businesses defend themselves. AI gives compliance and fraud teams the ability to analyze far more signals than a human ever could—from identity and device data to behavioral patterns and transaction activity—to spot suspicious behavior much earlier.
The challenge is that this has become an arms race. As fraudsters adopt more sophisticated AI tools, businesses need systems that can continuously learn and adapt. The organizations that will stay ahead will need to move beyond the idea that AI is just a feature, instead using it to connect identity, behavior, and transactions into a single, real-time view of risk.
Q: Fraud has moved from being just about customer onboarding to a ‘life cycle-based’ approach. Could you give an example of this?
A: Imagine a customer passes KYC, uses a platform normally for several months, and builds a trusted account history. Traditionally, that account would be considered low risk. But today, that account could later be taken over, sold, or used as part of a mule network.
A lifecycle-based approach recognizes that risk doesn’t stop at onboarding. Businesses need to monitor what happens afterward, whether a user suddenly logs in from a new device or location, starts making unusual transactions, or begins interacting with high-risk wallets or counterparties.
No single signal necessarily indicates fraud, but when you connect identity, behavior, and transaction data, you get a much clearer picture of changing risk. That’s why the industry is moving away from one-time verification and toward continuous assessment of trust throughout the customer relationship.
Q: Stablecoins continued to gain transactional relevance over the last year. What can you tell us about the rising role of these?
We’re seeing stablecoins evolve from a trading tool into a piece of financial infrastructure.
In our research, stablecoins accounted for 36% of all crypto transactions in 2025, up from 31% the previous year. That growth is being driven by real-world use cases like cross-border payments, settlements, and treasury operations, where businesses want the speed of blockchain without the price volatility of other digital assets.
As adoption grows, so do compliance expectations. Stablecoin transactions are often cross-border and high-value, making robust KYC, KYB, transaction monitoring, and Travel Rule compliance increasingly important. Regulation like the GENIUS Act is also helping provide a clearer framework for businesses operating in this space.
Ultimately, stablecoins are no longer seen as purely speculative; they are increasingly about enabling faster, more efficient movement of money. The challenge for businesses is making sure the compliance infrastructure evolves alongside that growth.
The risk-based solution for user verification
Q: The report mentions the “three horsemen” of verification pain: false positives, speed pressure, and UX expectations—all pulling in different directions. What’s the most practical way out of that trilemma?
A: The biggest mistake businesses can make is treating every customer the same. The way out of this trilemma is a risk-based approach in which the level of verification adapts to the level of risk.
A low-risk customer shouldn’t face the same level of friction as someone triggering higher-risk signals. By combining identity, behavioral, device, and transaction data, businesses can make smarter decisions about when to introduce additional checks and when to keep the experience fast and seamless.
The other important shift is moving away from one-time optimization. Fraud patterns and customer behavior are constantly changing, so verification models need to be continuously monitored and refined. Rather than choosing between security and user experience, the goal is to deliver both by applying the right level of verification at the right time.
Q: How are crypto companies adopting non-document verification and reusable KYC in 2026? How does this change the user experience on the front end?
A: We’re seeing a clear shift away from asking users to repeatedly upload the same documents every time they join a new platform.
Instead, more businesses are adopting non-document verification, using trusted data sources alongside device, behavioral, and risk signals to verify identity. Reusable KYC builds on that by allowing verified identity credentials to be reused across participating services, reducing the need for customers to start the verification process from scratch each time.
For users, that means faster onboarding, fewer document uploads, and a much smoother experience. For businesses, it can reduce abandonment rates while maintaining strong compliance standards. This move makes trusted identities more portable and allows more intelligent identity checks.
Q: If a compliance head reads this report and wants to do one thing this quarter to close their biggest compliance gap, what should it be?
A: I’d start by taking a step back and looking at your compliance program as a whole, rather than treating KYC, fraud prevention, AML, and transaction monitoring as separate functions.
The biggest gaps often appear between those systems. A customer may pass onboarding, but if changes in their behavior, device, or transaction activity aren’t connected, important warning signs can be missed.
This quarter, I’d focus on identifying where those blind spots exist and how you can connect identity, behavioral, and transaction data into a single view of risk. That doesn’t necessarily mean adding more controls; it means making the controls you already have work together more effectively.
As regulation matures and fraud becomes more sophisticated, businesses that take a lifecycle approach to compliance will be much better placed to scale with confidence.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Brian Koome
Brian Koome has over seven years of experience in blockchain and cryptocurrency reporting, having been active in the industry since 2017. He has contributed to leading publications, including BlockToday.com. Further, he developed the Ethereum 101 course for BitDegree.org before joining Cryptopolitan as a full-time writer. Brian covers evergreen guides (EGs), deep dives, interviews, and price analysis. His focus on DeFi, blockchain innovation, and emerging crypto projects delights readers.
















