The Real-Time Rail Paradox: Instant Payments, Real Risk

xxx

Overly cautious controls introduce friction, and friction erodes customer confidence almost as effectively as a fraud incident does. The banks managing this well won’t be the ones adding more checkpoints. They’ll be the ones making better decisions earlier, so legitimate payments keep moving while genuine risk gets caught before it settles.

From: The Real-Time Rail Paradox: Instant Payments, Real Risk.

xxx

Joseph Stiglitz’s ‘progressive AI agenda’ for the economy

Joseph Stiglitz is an American economist best known for explaining why markets don’t always work as neatly as textbook models suggest. He’s a Columbia University professor, a former World Bank chief economist, and a former chair of the U.S. president’s Council of Economic Advisers.

He shared the 2001 Nobel Memorial Prize in Economics for work on asymmetric information: situations where one party knows more than another. Think of a lender who can’t fully assess a borrower’s risk, or an insurance customer who knows more about their health than the insurer does. His work helped show how these information gaps can cause markets to produce inefficient outcomes.

Why take him seriously?
His research changed economics. It supplied rigorous reasons why competition alone doesn’t always deliver the best result.
He has substantial policy experience. He’s worked inside institutions he later criticized, especially on globalization and economic development.
He’s particularly worth reading on inequality, financial markets, and the role of government. He connects technical economics to questions about who benefits from economic policy.

xxx

Textbook economics teaches us that ever-present competition drives profits down to zero, and that it is through these lower competitive prices that society benefits from innovation. The reality is often otherwise. Google and Facebook have had sustained profits for years. Economists have explained why, without effective antitrust enforcement, that is no surprise. .

From: Joseph Stiglitz’s ‘progressive AI agenda’ for the economy.

xxx

xxx

In their fascinating paper on “The Data Economy: Market Size and Global Trade” for the Economic Statistics Centre of Excellence (part of the UK’s National Institute of Economic and Social Research), Diane Coyle and Wendy Li talk about the growing “data gap” between global Big Tech and potential competitors, disruptors and innovators. They argue (convincingly) that this data gap is a a barrier to entry that affects not only businesses but also aggregate innovation, investment and trade:

PROMOTED

Large data holdings, rich in volume and variety, thus give large online platforms a significant competitive advantage, powered by network effects and the virtuous cycle between data and the AI algorithms improving the services and increasing revenues.

This advantage means that the platforms obtain insights about adjacent sectors and can then enter them more easily.

From: Scrooge McData.

xxx

xxx

Data is the new gold and these companies have more data than anyone else, which gives them a competitive advantage. They have also figured out how to leverage this natural competitive advantage by engaging in sometimes hard-to-detect anti-competitive practices, even if doing so violates people’s privacy.

From: Joseph Stiglitz’s ‘progressive AI agenda’ for the economy.

xxx

Europe’s difficult choices on AI

xxx

AI-led growth, however, creates a tension with Europe’s bid for sovereignty, because Europe controls little of the AI value chain. The technology is set to become completely pervasive: in the economy, in health systems, in education, in energy, in defence, to name just a few areas. This is no ordinary dependency. Being cut off from AI, once the economy runs on it, would be more like being cut off from the US financial system. The effects would be catastrophic.

From: Europe’s difficult choices on AI.

xxx

POST Why is Revolut storing copies of identity documents:

xxx

British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain.
The exposed data included customers’ identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver’s licenses, according to a notification emailed to affected customers and reviewed by TechCrunch. The data may have also included verification selfies, account statements, and transaction histories, the firm said in its notification.

From: Revolut confirms customer data breach through fake government requests | TechCrunch.

xxx

I had a vague memory of something similar having happened before, and a quick trip to LLM land confirmed by suspicions. A few years ago, hackers tricked tech companies, ranging from Apple and Meta to Discord, into turning given out sensitive personal data by complying with fake emergency data requests (EDRs) seeming to come from official sources.

(These EDRs are a shortcut that tech companies built for genuine crises, such when someone has been kidnapped. Law enforcement can ask a platform for detailed data such as names and phone numbers without the warrant. Companies built these channels on trust: a request arriving from a verified law-enforcement email domain is usually honored within hours.)

Hackers soon discovered they could obtain access to real law-enforcement email accounts via the usual means (eg, phishing) and then submit EDRs concerning bogus emergencies. Since the requests came from authentic government accounts the companies complied and the compromised data was used to enable significant crimes, including SIM-swapping attacks against cryptocurrency holders, which is I am sure the sort of thing that the Revolut data will be used for.

While I was thinking about this, I got a text from my pharmacy to say that there was a message waiting for me. The text did not contain a link, which is sound security practice. So I went to the pharmacy web site and logged in to read the message waiting for me. Surely Scotland Yard could come up with some similar system? In fact, surely someone already has?

I am not an expert on law enforcement systems, but it took about two seconds’ googling to discover that such system already exist.

 

Kodex and its main competitors

Kodex Global is a platform that verifies law-enforcement and government identities before companies release user data in response to legal requests — subpoenas, warrants, court orders, and emergency disclosure requests. It maintains a vetted global network of tens of thousands of agencies and investigators, and offers case management, secure exchange, audit trails, and cost-recovery tools for the crypto, financial-services, and telecom clients that use it.[kodexglobal]

Its closest direct competitors, per industry trackers, are Casepoint, Cytrio, and Virtru — all of which touch adjacent parts of the same problem: legal-request intake, data-privacy compliance, and secure encrypted file exchange respectively, though none replicate Kodex’s specific focus on verifying law-enforcement identity itself.[cbinsights]

Beyond dedicated vendors, the biggest “competitor” in practice is that large platforms — Meta, Google, Apple — mostly built their own in-house Law Enforcement Response System (LERS) portals rather than outsourcing verification to a third party, requiring police to register an account tied to a real agency before any request is processed. So the market splits between a few specialist verification platforms like Kodex and big companies simply running their own closed, proprietary equivalent.[ministryofcyberaffairs]

 

The Real-Time Rail Paradox: Instant Payments, Real Risk

I remember talking about this with Rowan Akin-Smith at EBA Day earlier this year. Rowan is with Vyntra, one of. my advisory clients, and he’s written a good piece about this in the context of Canada’s immininet instant payments launch. Noting that overly cautious controls can introduce friction that erodes customer confidence almost as effectively as a fraud does, he goes on to say that the banks managing this well will be be the ones “making better decisions earlier, so legitimate payments keep moving while genuine risk gets caught”. Indeed.

So what is needed to make better decisions? We all know the answer to this is: it’s data, shared data.

Revolut Handed Customers’ Passports and Bitcoin Records to a Fake Government Request. Are You Affected?

xxx

Quick Read

Revolut’s compliance team released customer files to an attacker using a spoofed government email domain, exposing IDs, KYC selfies, and Bitcoin histories.

No funds were stolen and no systems were breached, but the stolen files enable highly personalized phishing attacks against identified customers.

The limited, targeted data set suggests attackers deliberately chose high-net-worth accounts; Revolut is notifying affected customers individually rather than issuing a broad disclosure.

From: Revolut Handed Customers’ Passports and Bitcoin Records to a Fake Government Request. Are You Affected?.

xxx

Mastercard predicts that over the next four years one-in-ten will use AI agents for online shopping

xxx

The report, ‘A Short History of the Future of Shopping and Payments’ comprises a survey of 13,000 parent-and-teen pairs across 13 markets – Bulgaria, Czechia, France, Germany, Israel, Italy, Netherlands, Norway, Poland, Romania, Sweden, Spain and the UK – alongside the perspectives of four world-leading futurists from the US, Europe and Asia.

The research shows a third (33%) of teens already use AI weekly to find, compare, and review products and services, compared to a fifth (21%) of their parent’s generation. And one in three (36%) say they’d happily hand over to a fully AI-run shopping assistant that chooses, and pays for, products.

From: Mastercard predicts that over the next four years one-in-ten will use AI agents for online shopping.

xxx

The Real-Time Rail Paradox: Instant Payments, Real Risk

xxx

For businesses, this isn’t an abstract infrastructure issue. Payroll, supplier payments, liquidity management, and customer refunds all increasingly depend on an institution’s ability to prevent, detect and recover from disruption in real time. Treasurers are scrutinizing how banks communicate during incidents, how quickly they recover, and how transparent they are about what went wrong. Increasingly, reliability will be measured by a less quantifiable standard: confidence.

From: The Real-Time Rail Paradox: Instant Payments, Real Risk.

xxx

The stablecoin era: The history and future of stablecoins: Ingenta Connect

There’s a good paper in the latest issue of the Journal of Payments Strategy & Systems 20(2), pp. 179-193 (Summer 2026). It’s called “The stablecoin era: The history and future of stablecoins” and it’s written by me and noted fintech commentator Simon Taylor. A “preview” presentation of the paper went down so well at Money 20/20 in Amsterdam earlier this year that I decided to head out to Simon’s upcoming Fintech Nerdcon in San Diego on November

Design a site like this with WordPress.com
Get started