Share:
The Business Is Verified. Trulioo Still Wants to Know Who Is Behind It
TL;DR: A company can verify a person or business and still be left with an important question about what connects them. We spoke with Trulioo’s Chad Gerhardstein about what building UBO Discovery revealed, and why the same problem could become harder as AI agents begin acting on people’s behalf.

A company can be legitimate on paper and still leave a basic question unanswered: who ultimately owns it?

A registry may show another company as the shareholder. That company may sit beneath a holding company in another country. Follow the chain far enough, and it can end at a trust or another structure where no natural person is clearly visible.

The records themselves may be accurate. The difficulty is connecting them well enough to identify who actually sits at the end.

Trulioo built its UBO Discovery Agent around that gap.

But the work exposed a broader risk problem. Trulioo Chief Risk and Strategy Officer Chad Gerhardstein told SaaStake that some of the most valuable signals can hide “in the seams” between onboarding and verification.

Those seams matter beyond business ownership. As AI agents begin acting on people’s behalf, companies may know who the customer is and still need to establish whether the action being taken falls within the authority that person gave the agent.

A Registry Can Be Correct and Still Leave the Most Important Question Unanswered

The ownership gap Trulioo is trying to close begins with the records themselves.

Business registries can reveal part of an ownership structure, but the trail may be fragmented across jurisdictions or stop before identifying the person who ultimately controls the company. Following it can mean connecting separate filings, different entity formats, and records held in multiple countries.

Gerhardstein told SaaStake that even in markets with well-established registries, the hardest structures to uncover are layered ones that eventually lead to trusts or other entities where no natural person is clearly visible in the available records.

Building UBO Discovery over the past year also showed Trulioo where automated discovery runs into friction.

“The constraint isn’t AI’s reasoning capability. It’s the availability of structured, high-accuracy data to reason against,” Gerhardstein said.

Getting an AI system to follow a complicated ownership structure is only part of the challenge. It needs reliable evidence at each step. If the underlying records cannot establish a connection, better reasoning cannot supply the missing evidence.

Trulioo Started Reconstructing the Ownership Structure Across Sources

Instead of treating a registry result as the end of the search, Trulioo’s UBO Discovery Agent looks across additional sources to reconstruct the ownership structure.

Trulioo says the system can draw from corporate filings, disclosures, legal and public records, and verified third-party databases to establish relationships between entities. Each finding is tied back to its source. When the available evidence still cannot establish part of the structure, the system reports the gap rather than filling it with an assumption.

That changes what reaches the compliance analyst. Instead of manually assembling an unresolved ownership structure from separate sources, the analyst can review the relationships the system has established, check the evidence behind them, and concentrate on what remains unclear.

Trulioo reported a 40% improvement in UBO coverage for one large social media platform operating across APAC. In individual markets, it reported a 69% uplift in the Philippines and 24% in Singapore.

But reconstructing ownership also pointed Trulioo toward a problem that extends beyond UBO discovery.

The Risk Can Sit Between Two Successful Checks

That observation broadens where risk can become visible.

Gerhardstein said Trulioo began as an identity company focused on confirming the information requested during verification. But as the company expanded across markets and cross-border use cases, it found that verifying the individual pieces did not always reveal what was happening between them.

Quote by CHad

A marketplace, for example, may have already verified the identity of a customer. It may also have verified the business involved in the transaction. Both checks can be accurate. What they do not necessarily establish is the authority connecting that verified person to everything that happens next. 

That distinction becomes more important as another layer enters the transaction.

An AI agent could make a purchase on behalf of a customer whose identity has already been established. The marketplace may know who the customer is and recognize the agent making the request, yet still face another question: was that agent authorized to take this particular action?

At that point, identity verification alone is no longer enough. The marketplace also needs a way to connect the action back to the authority the customer originally gave.

Who Gets to Prove What an AI Agent Is Allowed to Do?

Gerhardstein sees that as one of the open questions the industry still has to solve.

For an AI agent to transact on someone’s behalf, he said, its actions need to remain verifiably connected to the person who authorized them. There also needs to be a way to reconcile what the person approved with what the agent actually did, particularly when questions of fraud or liability arise.

The unresolved part, he said, is not whether that connection can technically be created. It is which system will become authoritative.

A consumer might use an independent AI agent that works across different merchants. A bank could provide an agent tied to a customer’s card. Or a marketplace could operate its own agent within its platform. Each model places trust in a different part of the transaction.

Gerhardstein expects the protocols behind agent authorization to take shape as those models develop and some become more widely adopted.

Until then, recognizing the people and systems involved is only part of the problem. Companies also need a reliable way to establish who authorized an agent, what it was permitted to do, and whether the action it ultimately took stayed within those limits.

As AI Takes on More Work, People Have to Decide Where Trust Stops

That also changes what people are responsible for.

After moderating “Who’s Actually On the Other Side?” at Marketplace Risk, Gerhardstein said what stayed with him was the need to define how people and AI agents will work together as the technology takes on more responsibility.

Trulioo’s own work shows where some of those boundaries begin to appear. A system can assemble ownership evidence, but someone still has to investigate what the records cannot establish. An AI agent may be authorized to transact, but people still have to determine what it is allowed to do, where those limits sit, and what happens when an action falls outside them.

Gerhardstein argues that companies will need to invest not only in the technology, but also in training people to work alongside it as new threats emerge.

The identity industry has spent years getting better at establishing who is on the other side. The harder question now is what connects that identity to the business, system, or agent acting around it. As more layers sit between a person and an action, proving that relationship may become just as important as proving the identity itself.