Jonathan Awad

Co-founder and CEO of Baselayer, an NYC AI business identity and risk platform

Overview

Jonathan Awad is co-founder and CEO of Baselayer[1][2], a platform focused on business identity and risk management with an artificial intelligence component[3]. Awad maintains a professional presence on LinkedIn[2] and X[4], where the CEO profile indicates active engagement with topics related to B2B risk, fraud prevention, and know-your-business services[3].

Career history

  1. Co-Founder, CEOMar 2023 to PresentBaselayer
  2. Angel InvestorJan 2022 to Present-
  3. GrowthJun 2021 to Jan 2023Middesk
  4. InvestorNov 2019 to Jan 2023OakNorth
  5. Growth and OperationsNov 2019 to Jun 2021OakNorth
  6. InvestorNov 2018 to Jan 2023LEX
  7. Co-Founder and Chief Investment OfficerMay 2017 to Dec 2018LEX
  8. Investment BankingJun 2018 to Nov 2019Lazard

Education

  1. BS, Economics and Political PhilosophySkidmore College
  2. AP High School Diploma at The Bronx High School of Science

Insights & ideas

The through-line

Awad's recurring argument is that the entity is never the thing worth verifying. "Businesses don't commit fraud. People commit fraud," he says. "Businesses, LLC, CC corps, they're tax rappers on people. They're liability obfuscation on people" [1]. Everything else follows from that: if an LLC is only a wrapper, then linking a person to a business is the easy half of the problem, and the hard half is establishing that the actual person is the one applying, right now, with intent. Baselayer, the platform he co-founded and runs, is built around identity, fraud and credit risk for merchants, small businesses "and increasingly the agents that represent those and the behaviors as well," working with more than 2,000 financial institutions from credit unions and community banks to merchant acquirers, issuers, lenders and marketplaces, to "very quickly on board the good businesses and then pause or decline the bad ones" [1].

The preoccupation has extended outward as the tooling on the attacker's side has improved. Where the earlier framing was about making business identity verification faster and more continuous for financial institutions [3], the current one is about volume and speed at a scale that breaks manual review, and about a coming population of non-human actors that will need to be trusted rather than blocked [1].

On the LLC explosion and synthetic businesses

Awad works from the premise that company formation is becoming as casual as opening a bank account, with the expectation that a future generation will hold three, four or five LLCs each [1]. That is fine when everyone forming them is legitimate, and the problem is what the same ease affords bad actors. The attack he describes is not a fake person, it is a real one: everyone's personally identifiable information has already been stolen, the telecom breaches saw to that, so a fraudster can "take PII real people information and then pair it with maybe an LLC that you create on their behalf, make them a business officer, make them a registered officer registered agent and very quickly spin up some sort of activity at the website, you know, different accounts, different trade lines" [1]. The individual passes KYC cleanly. The business around them is manufactured.

He is blunt about where this goes. Fraudsters start "with people with maybe less controls," testing attack patterns on smaller fintechs and net-new startups issuing cards or money, and then move upstream [1]. Combine that with automation and the result is what he calls "almost like the PPP moment that could happen every day," referring to the volume of applications that broke institutional systems, and he asks the industry to imagine that level of volume arriving daily, at which point "you can't really shift through who's real, what's real, what's a good account, what's a good application because so many of it, so much of it blurred through the lines" [1].

On intent and certainty as the real verification problem

The mechanism Awad trusts is the one that ties a live authentication event to a device. Consumers are already habituated to a one-time passcode, and the behavioural split is stark: "Good people will be totally fine to do the OTP, do that two-factor authentication, and the fraudsters won't because you immediately know it's a burner device. You know, it's a young SIM. It's not the phone number that belongs to the SIM that belongs to the device. It's just so obvious" [1]. He credits the partnership with Prove for marrying that signal to conversion, because certainty about the applicant unlocks prefill: "if you can just make sure that it is actually Austin who's applying in this moment then you can just grab the rest of Austin's data um in all one kind of unique one ID fashion" [1].

His reduction of the whole problem is a single test. "The key is is it actually Austin applying on behalf of Austin? Yes or no" [1]. Once that is settled, linking through to the business and populating its data is comparatively straightforward. The sequence he insists on is intent, then certainty, then authorisation, then everything else flows [1]. This sits alongside the case he has made for real-time business identity verification more generally, and for monitoring that continues after onboarding so institutions are alerted when something about a business changes rather than relying on a one-time check [3].

On agents as the next population to be trusted

Awad does not treat AI agents as a threat to be filtered out. He argues the opposite, that "you don't want to block agents from doing things for people or for businesses" because they can make processes faster and make lenders and banks more money, and that "the next billion or trillion people will probably be agents" on the reasoning that "they never go to sleep. They don't eat. They you don't even have to pay them" [1]. The only obstacle he sees is trust: "There's no reason why not besides trust" [1].

His proposed architecture is a registry of people and businesses, with each agent tied to a principal and required to claim that association, followed by what he calls "minting an attestation in the moment": "I attest that I give permission to this agent to do this thing with these limits for this reason in this moment," with the attestation expiring shortly after [1]. The controls live in the metadata behind the attestation, so both the supply side and the demand side can be evaluated. He describes the underlying work as claim, process, ownership, KYC and KYB done well up front, then attestations minted as agents are created and act [1]. He is candid that there is a "ton of things to do," and frames it as a problem worth solving for the coming population of non-human actors [1]. The same logic cuts the other way as a risk: an agent "issued by a fraudster to steal credentials from people and then use it and do it really fast" [1].

On sharing intelligence without sharing PII

Awad is an advocate of collective defence built specifically to avoid the legal friction that stops most information sharing. Baselayer's fraud consortium was built on the principle of no PII at all: "just get the entity names, get the entity details, put it on a mutual list" [1]. Because the underlying material is public data, it counts as intelligence rather than regulated personal information, which is precisely why it moves. His argument for participation is close to rhetorical: "when there's millions of bad entities that have been used before, if you don't check this list, what are you doing?" [1]

On what Baselayer actually does with data

The operating method is to connect people to businesses using government data, online data and proprietary databases, in service of onboarding good businesses quickly and pausing or declining the rest [1]. Awad is careful that "pause" and "decline" are "very nuanced" as outcomes, which matters given the cost of getting it wrong in either direction [1]. He is equally clear about where the difficulty actually sits: linking a person to a business is tractable, and the harder question is whether the real person is applying and performing the activity in real time [1].

Takeaways

  • Treat entities as wrappers, not actors: "Businesses don't commit fraud. People commit fraud" [1].
  • The current attack pattern is a genuine person with stolen PII installed as officer or registered agent of a freshly created LLC, with website and trade line activity spun up around it, so the individual passes KYC while the business is fabricated [1].
  • Fraudsters test attack patterns on smaller fintechs and new startups with weaker controls, then move upstream to larger institutions [1].
  • Automation threatens to produce "almost like the PPP moment that could happen every day," an application volume that makes it impossible to sort real from fake [1].
  • Device-bound authentication separates good from bad cheaply, because legitimate applicants complete an OTP and fraudsters expose burner devices and young SIMs, and the same certainty improves conversion by enabling prefill [1].
  • Do not block AI agents; tie each to a principal in a registry and mint short-lived attestations granting specific permissions with limits, reasons and expiry carried in the metadata [1].
  • A fraud consortium built on entity names and details rather than PII sidesteps most legal obstacles and still delivers usable intelligence [1].
  • Verification should not end at onboarding; continuous monitoring alerts institutions when a business changes or new risk appears [3].

Media & appearances

  • Fintech ConfidentialApple Podcasts
    Are You Suffering from Business Identity Crisis?In this episode of FinTech Confidential, Tedd Huff and Colton Pond chat with Jonathan Awad, co-founder and CEO of Baselayer. They cover some pretty interesting topics around identity verification and fraud prevention for businesses, especially small and medium-sized ones. The conversation is packed with useful insights into how financial institutions are dealing with these challenges, and how new tech is changing the game for everyone involved. The main focus of the discussion is about making business identity verification smoother and faster. Financial institutions are constantly trying to figure out how to trust the businesses they work with. Traditionally, this process has been slow, complicated, and full of risks. Nowadays, technology helps solve these problems by verifying business identities in real-time. The result is a more secure onboarding process, which cuts down on fraud and makes it easier for businesses to prove who they are. What’s really cool is that it doesn’t stop at just checking identities. Companies now have tools that can keep an eye on businesses long after they’ve been verified. Instead of just doing a one-time check, financial institutions get real-time updates if something about a business changes. So if a new risk pops up or fraud becomes more likely, they’re alerted immediately.
  • YouTube
    The LLC Explosion: AI-Manufactured Fake Businesses - YouTubeJonathan Awad, co-founder and CEO of Baselayer, discusses how AI has made it faster and easier to create fake businesses and synthetic identities. He explains that Baselayer works with over 2,000 financial institutions to help them quickly onboard legitimate businesses while pausing or declining fraudulent ones, using government data, online data, and proprietary databases to connect people to businesses. Awad emphasizes that the harder challenge is verifying whether the actual person is applying and performing the activity in real time, rather than simply linking people to businesses.
  • fintechconfidential.captivate.fm
    Are You Suffering from Business Identity Crisis? - How AI is ...In this episode of FinTech Confidential, Tedd Huff and Colton Pond chat with Jonathan Awad, co-founder and CEO of Baselayer. They cover some pretty inte...
  • Prophet Jonathan AwadYouTube
    How I became a paranormal medium.Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.

In the news

This page shows public professional information only, each fact cited. Is this you? send a correction, or ask for removal within 24 hours, no questions asked.