US Treasury and the Working Group
The first federal endorsement of privacy technology
The regime itself mandates, pilots or funds privacy-preserving technology.
What US Treasury and the Working Group actually says
The most significant shift in this section, and the one most easily overstated. Official US government documents now treat privacy-preserving technology as part of the compliance toolkit rather than an obstacle to it. The 2025 Working Group report prioritises privacy and civil liberties, encourages privacy-preserving digital identity for customer verification, and concedes the technical and legal difficulty of enforcing obligations on privacy-enhancing protocols. Treasury's March 2026 report to Congress goes further, describing zero-knowledge credentials as a way to streamline compliance without over-collecting, and commits to issuing guidance on verifiable credentials. Read it as direction of travel and not as permission: every pro-privacy statement sits alongside an intact anti-money-laundering obligation, and the guidance has not been published.
The instruments that matter
- Working Group report, 30 July 2025
- Strengthening American Leadership in Digital Financial Technology; prioritises privacy and civil liberties, encourages privacy-preserving digital identity tools for customer verification, and acknowledges the difficulty of enforcing obligations on privacy-enhancing protocols
- Treasury request for comment, 18 August 2025
- issued under GENIUS Act section 9, asking about portable digital identity credentials designed to maximise user privacy and about the privacy risk of what is collected
- Report to Congress, March 2026
- describes credentials using zero-knowledge proofs as having the potential to streamline compliance without over-collecting information
- The adopted commitment
- Treasury will issue guidance to financial institutions on using verifiable digital credentials consistent with existing customer identification programmes; not yet issued
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- eIDAS 2 and the EU Digital Identity WalletEurope · Digital identity · Regulation (EU) 2024/1183
- ISO and IEC standardsGlobal · The standards bodies that specify privacy instead of policing it
- FinCENAmericas · Bank Secrecy Act · the deepest US constraint
- GENIUS ActAmericas · Stablecoins · censorability as a licensing precondition
- IRS broker reportingAmericas · Tax · live at the custodial perimeter, dead beyond it
- NYDFSAmericas · The most privacy-restrictive US regulator, state or federal
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.