Skip to main content
Back to Blog
20 May 2026, byZebrabyte GDPR & conformitate

The Watchers: How Biometric Identity Verification Has Become a Global Financial Surveillance and Automated Classification Infrastructure

The Watchers: How Biometric Identity Verification Has Become a Global Financial Surveillance and Automated Classification Infrastructure

ZebraByteResearch Division – Cybersecurity, AML & Data Protection Identity Verification and Biometric Screening Architecture described in “The Watchers” Technical, Legal and...

Identity verification and biometric screening architecture described in “The Watchers”

Technical, legal and geopolitical analysis of Romania and the European Union

ZebraByte Research Division – Cybersecurity, AML & Data Protection

Introduction and Delimitation

In February 2026, a comprehensive technical document entitled “The Watchers” was published describing the existence of an infrastructure associated with Persona and used in connection with OpenAI.

Perosna The Watchers

The authors claim that they have identified dedicated endpoints for screening against sanctions lists, facial biometric comparison modules with politically exposed persons (PEPs), SAR generation and transmission functions to the Financial Crimes Enforcement Network and STR to FINTRAC, as well as the existence of a government deployment with FedRAMP status.

In this report, we treat the information in the document as real on a technical level and we analyze the systemic implications. The aim is not to defend any entity, but to assess the impact on fundamental rights, on the data protection regime and on the Romanian ecosystem.

Described architecture – a global identity classification infrastructure

The infrastructure would include a separate “watchlistdb” service hosted in Google Cloud, separate from the company’s main infrastructure. This separation is significant because in practice, AML screening systems that operate sensitive lists (OFAC, EU, UN, internal lists) are isolated to meet security and segmentation requirements.

Furthermore, the document describes the existence of publicly exposed JavaScript source map files containing complete TypeScript code, including data models and listings for 269 separate checks.

Perosna The Watchers

If these sourcemaps were publicly accessible, this represents a major DevSecOps configuration weakness, but also a rare source of transparency on internal mechanisms.

Din analiza structurii, sistemul ar realiza:

  • capture government ID (including NFC in some cases),

  • Selfies with Liveness Detection

  • extragere de embedding biometric,

  • comparison with PEP bases, including on the face level,

  • screening of global sanctions,

  • screening adverse media,

  • screening crypto prin integrare Chainalysis,

  • re-screening automat la interval configurabil,

  • Maintain biometric data for up to three years.

This is not just an identity verification. Identity risk assessment infrastructure with integration into financial intelligence flows.

Face PEP Screening – Implications

Traditionally, PEP screening is performed nominally, by comparing name and date of birth with lists of politically exposed persons, according to the recommendations of the Financial Action Task Force (FATF).

If the system described compares the user’s selfie with public images from databases such as Wikidata or other PEP sources

Perosna The Watchers

Then we have an extension of the concept of PEP screening into a much more intrusive area.

In the European Union, biometric data used for unique identification falls under Article 9GDPR.Their processing is only permitted under strict conditions. In Romania, the ANSPDCP has previously sanctioned the use of biometrics without proportionate justification.

Furthermore, Directive (EU) 2015/849 on the prevention of money laundering (AMLD4), as amended by AMLD5 and AMLD6, requires PEP screening, but does not explicitly authorise biometric facial matching.

Therefore, if a Romanian citizen were classified as “similar PEP” on the basis of a biometric score, this would raise questions regarding:

  • the proportionality of the measure,

  • the right to explanation (Article 15 ZBTKEEP),

  • the right to appeal against automated decisions (Article 22 ZBTKEEP).

SAR and STR – financial integration

The document describes the existence of modules for the direct transmission of SAR to the Financial Crimes Enforcement Network and STR to FINTRAC

Perosna The Watchers

.

FinCEN is the U.S. Treasury’s financial intelligence agency responsible for collecting and analyzing suspicious activity reports.

In Romania, the equivalent is ONPCSB, according to Law 129/2019. Automatic data transmission to a foreign authority would require:

  • temei legal explicit,

  • international transfer agreement,

  • compliance with theGDPRmechanisms concerning transfers to third countries.

Following the invalidation of the Privacy Shield by the Court of Justice in the case Schrems II (C-311/18), the transfer of data to the United States is subject to further assessment and adequate safeguards.

Recurrent re-screening and passive monitoring

Existence of a “recurring-enabled” parameter in screening configurations

Perosna The Watchers

It suggests the possibility of periodic automatic re-evaluation.

This involves continuous monitoring, not just punctual verification.

In Romania, such practice should be explicitly stated in the privacy policy and justified by the AML legal obligation.

Integration of AI throughAPIOpenAI

The document mentions the existence of an “AskAI” module that uses theAPIOpenAI

Perosna The Watchers

.

Integrating an AI model into a system that processes biometric and SAR data raises additional problems:

  • What data is transmitted to the model?

  • Are they anonymous?

  • Are there journalism and auditing?

Under the future AI Act (EU Artificial Intelligence Regulation), AI systems used in financial risk assessment or biometric classification can fall into the “high-risk AI systems” category.

Retention for three years

The document indicates maximum three-year retention for face lists

Perosna The Watchers

.

GDPRimposes the principle of limitation of storage (Article 5 (1) e).

In Romania, any extended retention of biometric data would require DPIA and clear legal justification.

Geopolitical and regional impact

The mention of Ukraine’s blocking in the context of access to services raises questions about alignment with OFAC lists, although Ukraine is not fully sanctioned

Perosna The Watchers

.

For Romania, a EU member state and Ukraine’s immediate neighbor, the application of additional geopolitical filters could affect residents, refugees or people with dual citizenship.

The General Conclusion

If the described infrastructure is operational according to the document

Perosna The Watchers

We have a system that:

  • collecting facial biometrics,

  • performs PEP matching including facial,

  • Maintain biometric data.

  • performs automatic re-screening

  • integrate financial reporting mechanisms,

  • use AI in the analysis flow.

For Romania, the implementation or integration of such a system would require:

  • audit tehnic independent,

  • DPIA detaliat,

  • mecanism de contestare,

  • The full transparency,

  • International data transfer analysis.

Without these measures, legal, constitutional and reputational risks would be substantial.

Share this post
Etichete
Archived

Scris de Zebrabyte

ZebraByteeditorial material on digital security, infrastructure, privacy and compliance, kept in the company's technical archive.

ReceiveZebraByteanalytics and guidelines on cyber security, privacy and compliance.
ZebraByte

Framework-uri gestionate Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Don’t see the framework you are looking for?
Reach out – it may already be supported in the program.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert