The question "is this business real, and should I believe what it's telling me" isn't new. It's about as old as American commerce. What's changed is that you can now spin up a company, a website, and a merchant account before lunch, and there's no correspondent in town to write you up.
My guest has spent his career on the modern version of that problem. John Canfield built risk and verification systems at eBay, at WePay (acquired by JPMorgan Chase) and at Google, where he led the Ads verification and transparency initiative. He's now co-founder and CEO of BlueArc, which uses AI to verify business customers.
Some themes:
1. How verification became paperwork The Bank Secrecy Act, then post-9/11 customer identification rules, hard-coded KYC as document collection — optimized for what an examiner could inspect, not what would catch a bad actor. When did "compliant" and "works" come apart?
2. Identity versus credibility He led Google Ads verification in 2020 and now argues that approach won't stop scams: identity answers who's speaking, credibility answers whether to believe them. Platforms spent a decade saying claim-level review couldn't scale, so why now?
3. Flipping the economics — who actually pays If the goal is no added friction for legitimate businesses, and if platforms can charge for deeper review, what then?
4. FTC v. Genesis Tech (filed June 2026, N.D. Cal.): we talked about this case, where the FTC alleges a network of 15 corporations and 8 individuals ran deceptive subscription apps through a shifting web of Cyprus and Delaware shell companies, continually registering new entities and merchant accounts to outrun fraud monitoring — with linked PayPal accounts processing close to $700M in the twelve months ending September 2025. Per the FTC’s standard, a practice is deceptive if it's likely to mislead a consumer acting reasonably in the circumstances and is material to their decision — no intent and no actual victims required, and net impression governs, so an ad that is literally true in every sentence can still be unlawful.
Chapter Timestamps:
00:00 Introduction
1:21 Jon Canfield’s trust-and-safety background and BlueArc’s mission
3:34 Why business verification differs from verifying individuals
5:36 The missing business graph behind platform risk decisions
7:20 Legal entities are not enough: domains as a business identity layer
11:32 Balancing low-friction verification with domain control and vouching
16:36 Verification does not equal credible advertising claims
19:08 Risk-based claim credibility, transparency, and the limits of black-box enforcement
23:24 AI-enabled advertiser engagement and remediation
27:00 Proportional friction: local flower ads versus high-risk miracle claims
30:56 Scam economics and why advertisers may need to fund deep validation
34:16 Shared third-party validation and BlueArc’s next priorities
39:19 FTC material misrepresentation as a scalable policy framework
42:38 Know Your Agent: AI shopping agents, authorization, and scam resilience
46:02 Review-site integrity and adversarial manipulation
Resources & Links:
Rob Leathern (https://www.linkedin.com/in/leathern/)
John Canfield (https://www.linkedin.com/in/johncanfieldbayarea/)
BlueArc (https://bluearc.ai/)