What data sharing must learn from payments, and what the law already permits.

Learn more about the reliance network.
The day I clocked how far behind data networks are compared to payments wasn't in API docs. It was when I canceled a credit card.
I had a card I couldn't find, couldn't see in Apple Pay or 1Password, didn't know the number for. But I knew it was linked to a bunch of subscriptions I didn't know how to cancel. So I did the responsible thing: called the bank, canceled the card, and got a new card. Almost a year later, doing my own accounting, I discovered I was still being charged on the newly issued card I had never given those merchants.
Somewhere in the background, the network had quietly updated my billing credentials. My "canceled" card lived on as a ghost.
I went down a rabbit hole and found out there are entire companies whose product is selling updated card numbers to payment processors.
The system is optimized so that money keeps flowing. Card updates propagate. Merchants keep billing. Everyone keeps getting paid. The only decision that didn't count was mine, the cardholder's. This is what a mature network looks like.
Back when I was an OSINT analyst I was trained to “follow the money to read the incentives”
Read the incentives and you can explain why payment networks are insanely sophisticated, why we have certain fraud networks but not others, and why data sharing gets treated like a science project.
Let's be clear about one thing first. Data sharing is not new. We've always been sharing data. Open banking does it. Consumer reporting agencies do it. The reliance framework does it. What's missing is not the sharing. It's what payments has and data doesn't: a shared, enforceable remediation and liability layer. A chargeback layer. Plus the incentive structure that makes cooperation rational even when it's inconvenient.
That's the SOLO bet. Right now we ask institutions to cooperate on data where there is no shared incentive and no shared way to fix things when they go wrong. In fact, the incentives run the other way. Payments did the opposite. It built cooperation first where money was at stake and hard-coded remediation into the system.
If we want reusable identity and portability to truly work, we should do the same, but with incentives and governance designed for both consumer agency and network accountability, not just uninterrupted billing.
Look at where the industry cooperates today and where it doesn't. We have mature payments networks and certain fraud networks. We do not have equally mature networks for BSA/AML information sharing, even though everyone claims to want them.
Why? Because we are ruthlessly selective about cooperation. We cooperate when there is obvious short-term gain from sharing, or obvious short-term loss from not sharing. Card networks talk to issuers because every transaction has dollars attached. Fraud systems that protect revenue get funded. Cooperation on deeper financial crime stays thin, because the benefit is diffuse and the liability is concentrated.
Banks themselves are the best proof. The reliance framework isn't exotic. Banks use it constantly when there's financial upside. Loan syndication runs on it: dozens of institutions relying on a lead bank's diligence, underwriting, and documentation, because everyone gets paid on the deal. Participations, correspondent relationships, agented credits. Cooperation on someone else's regulated work is a solved problem the moment there's a fee attached.
Now watch the same institutions in open banking. When the ask is "share customer data because the customer asked," the posture flips from cooperation to obstruction. Rate limits, broken connections, screen-scraping wars, litigation over Section 1033. Same banks. Same capacity to rely on one another. The only thing that changed is who benefits. When cooperation pays the bank, reliance is routine. When cooperation only serves the customer, it becomes a security concern.
Reusable identity and compliance data sits in exactly that awkward zone. The upside is enormous but distributed across the whole system: less duplication, better decisions, better AI. The downside lands immediately on whoever went first. So the rational choice for every institution is to wait for someone else to move.
The ghost card is infuriating as a consumer, but it reveals something important about the industry: in payments, the hard coordination work was already done.
Payments networks have standard rules every participant must follow, clear liability when something goes wrong, predictable remediation paths, and enforcement with actual consequences. If money goes missing, there is a playbook. If a party consistently misbehaves, they can be fined, clawed back, or pushed out. The system has teeth.
But notice where the teeth stop. If JPMorgan is banking the fraudster and Wells Fargo is banking the victim, JPM is under no obligation today to return the fraudulent funds. Payments has a playbook for disputes that threaten the network's revenue. It has no built-in duty to make the victim whole. Even the most mature network we have cooperates exactly as far as the money reaches, and no further.
Why did payments get even that far? Because when money is lost, someone loses real, immediate dollars. That concentrated pain forced the industry to agree on who is responsible, how remediation works, and how liability transfers.
The result is a deeply sophisticated governance stack built on perverse incentives. The network optimizes for continuity of billing over user agency. My subscriptions silently migrating to a card I never shared is not a bug. It's a feature in service of the incentive structure. You can dislike that structure, and I do, but you cannot ignore the machinery: shared rules, shared liability, shared remediation.
When people say reusable KYC "doesn't work yet," here's what they mean.
There is no governance for using someone else's work on the customer's behalf.
When Bank A wants to rely on diligence done by Bank B or a fintech, it isn't calling an API. It has to register them as a service provider, audit their policies and models, and absorb third-party risk as though it built the capability itself. The moment you move from raw data to someone else's regulated judgment, you're back in bespoke bilateral negotiation. Something as simple as PNC taking data via Coinbase required changing Cross River's policy and reopening contracts. That's between large, sophisticated players. Now imagine it across a hundred banks and a few hundred fintechs.
There is no remediation or liability framework. If shared data is wrong, misused, or contributes to harm, there is no network-level answer to who is responsible, who fixes it, and who pays.
The telling parallel: if JPMorgan is banking the fraudster and Wells Fargo is banking the victim, JPM is under no obligation today to return the fraudulent funds. Payments has a way to talk about fraud, but no built-in duty to make the victim whole. In data sharing we're even earlier. There's barely a common language, let alone shared obligations.
We don't need to invent this layer. The legal primitives exist. They've existed for decades. Nobody has assembled them.
The Fair Credit Reporting Act is, functionally, a chargeback layer for data, and has been since 1970. It defines who can furnish, who can consume, and for what permissible purpose. It mandates a dispute process with deadlines. It obligates furnishers to investigate and correct, and it makes corrections propagate so the same error doesn't keep resurfacing downstream. It assigns liability for inaccuracy. Remediation, liability, authorization: the pillars payments spent decades building through network rules are sitting in a federal statute the industry treats as legacy plumbing.
The reliance framework exists too. The CIP reliance rule, 31 CFR §1020.220(a)(6), is explicit statutory permission for one regulated institution to rely on another's KYC work, with liability allocated by contract and annual certification. Section 314(b) is the safe harbor for sharing financial-crime information. Banks have relied on each other's regulated work for decades, whenever the deal paid them to. Using someone else's work is codified, road-tested, and routine. It has just never been run on the customer's behalf.
That's the architecture SOLO is built on, and it's why we built a regulated specialty consumer reporting agency instead of another API company. The CRA framework is the only existing legal chassis where disputes, corrections, liability, and permissible use are already enforceable at the network level. SOLO takes the reliance machinery banks already trust and points it at the one beneficiary it has always excluded. The customer's data becomes the deal.
And we added the incentive the statutes don't supply: SOLO pays its furnishers when their work is reused. Because when money is at stake, people are held accountable for what was said. A bank that gets paid for its KYC file has a reason to keep it accurate, fresh, and defensible. A bank that furnishes for free has a reason to stop. Follow the money. It works in both directions.
Provenance makes it enforceable rather than theatrical. Governance without evidence is theater. A usable framework carries lineage, freshness, channel, and memory: who originated the data, when it was last updated, whether it came directly or via an aggregator, and how it has changed over time. Down to the attribute, the certificate, the policy version. That's what lets you say, when an outcome goes wrong: this is the path the data took, and this is who bears which share of responsibility.
Reusable financial data gets filed under "experimental," and that word is doing a lot of work. Experiments are optional. Experiments can be admired, deferred, and safely ignored.
But the label is fiction. We've always been sharing data. Open banking shares it. Consumer reporting agencies have shared it under federal law for fifty years. The reliance framework shares regulated judgment itself, and banks use it every day the economics work in their favor. Nothing about the activity is experimental. The only thing untested is doing it with the incentives pointed at the customer.
Meanwhile the pressure builds. AI models need better-governed financial data. Banks are quietly praying for a way to trust each other's work, because they know exactly how much they're spending on duplicative compliance. Regulators are being asked to oversee data flows they didn't design.
In payments, my cancellation was noise the network routed around. In a data network done right, the consumer's decision is a network event. It propagates with the same force as a card update, and everyone bound by the rules has to honor it.
The statutes are on the books. Banks already know how to rely on each other. What's been missing is a network willing to run that machinery for the customer.
That's not an experiment. That's overdue infrastructure.