Letter No. 147 July 2026 Mental Models · Digital Trust · The $1Q Thesis

🔐 The Trust Economy

For twenty years, businesses competed for attention, and generative AI just made attention infinite and nearly free. The next twenty years they compete for trust — and trust is the one input AI cannot manufacture at scale. This letter is about who gets paid as verification becomes the scarce resource.

This publication has spent 146 letters mapping sectors — space, water, memory chips, nitrogen. This letter is different: it is a mental model, not an industry, and this publication's own view is that after this many letters, new frameworks age better than new sectors. This is the first of that kind.

Attention Became Infinite. Trust Did Not.

For two decades, the entire architecture of digital business — advertising, search, social platforms, media — was built on competing for a genuinely scarce resource: human attention. Generative AI has quietly ended that scarcity. Experts now estimate AI-generated content could make up as much as 90% of online content in 2026, and detected deepfake cases surged from roughly 500,000 in 2023 to about 8 million in 2025 — a 900% increase in three years. When content, ads, and even personalised outreach can be generated infinitely and essentially for free, attention stops being the bottleneck. Verifying that any of it is real becomes the bottleneck instead.

The evidence this shift is already operational, not theoretical: Gartner's September 2025 survey of 302 cybersecurity leaders found 62% of organisations had already faced at least one deepfake attack in the prior twelve months. The same research house's February 2024 prediction — that by 2026, 30% of enterprises would consider face-biometric identity verification unreliable in isolation — is now, in Gartner's own words, "a present-tense reality." Consumers lost $27.2 billion to identity fraud in 2024 alone, up 19% year-on-year, and one single deepfake video-call incident cost the engineering firm Arup $25.6 million in 2024 through fifteen fraudulent wire transfers authorised by an employee who believed he was speaking to his own CFO.

The Market Nobody Has Priced Yet

The global identity verification market is valued at $13.75 billion in 2025, projected to reach $50.58 billion by 2034 — a 15.6% compound growth rate that most portfolios have zero deliberate exposure to. Regulators are moving faster than in most other AI-adjacent categories precisely because the harms are concrete and immediate: the EU AI Act now requires machine-readable labelling of AI-generated content, the US Take It Down Act (2025) forces platform removal of non-consensual synthetic imagery within 48 hours, and 29 US states now carry specific deepfake statutes as of April 2026. Regulation, in this case, is not a headwind to the trust industry — it is the industry's addressable market expanding by statute.

This is a structural, not cyclical, repricing of what businesses need to buy. Cybersecurity spend used to be about keeping bad actors out. Increasingly, it is about proving — cryptographically, biometrically, procedurally — that the person, document, or voice on the other end of a transaction is who or what it claims to be. Identity is the new perimeter, and perimeter security has always commanded a premium over generic IT spend.

An enterprise that can no longer trust a face on a video call or a voice on a phone line has one option left: build verification into every workflow that used to run on trust. That verification layer is the business this letter is pricing.

Where the Money Actually Flows

Four categories capture this shift in practice. Ratings and certification — the business of a trusted third party stamping a claim as verified — has existed for a century in credit ratings and is now expanding into AI model provenance, ESG claims, and content authenticity. Internet-scale authentication infrastructure sits underneath an enormous share of daily verification events, from bot mitigation to domain-name integrity. Identity verification specifically — document checks, biometric liveness, deepfake detection — is the fastest-growing sub-segment, expected to keep compounding at double-digit rates through the 2030s. Premium human expertise — the accountant, the doctor, the editor whose judgement carries a name and a reputation — becomes relatively more valuable precisely because AI-generated alternatives are abundant and unverified.

Two Companies That Already Monetise This

Moody's Corporation (NYSE: MCO) is, at its core, a century-old trust business: it gets paid to tell capital markets which claims about creditworthiness can be relied upon, a service that becomes more valuable, not less, as the volume of unverified financial claims in the world increases. Cloudflare (NYSE: NET) sits at the internet's authentication layer — bot management, verified-access, and Turnstile (its CAPTCHA replacement) are all, functionally, trust-verification products sold as infrastructure, billed on the same usage-based model that made the company's core CDN business durable. Neither company markets itself as an "AI trust play" today. Both already monetise the exact function this letter argues becomes structurally more valuable as synthetic content scales.

The Verdict

The framework, stated plainly: when a resource that was scarce (attention) becomes abundant, and a resource that was assumed (trust) becomes scarce, the businesses that get paid shift from those who capture attention to those who verify claims. This is not a sector call — it cuts across credit ratings, cybersecurity, identity verification, content authentication, and premium professional services simultaneously, which is exactly why it is worth naming as its own thesis rather than folding into "cybersecurity" or "AI infrastructure" coverage elsewhere in this archive. The risk: verification technology itself is an arms race, and today's detection method is tomorrow's defeated benchmark — iProov's own testing found human accuracy at identifying deepfakes sits near 0.1%, and commercial detection tools fare only modestly better in production. The businesses that win this framework will be the ones that treat trust as a continuously re-earned service, not a badge issued once and never re-checked.

Pawan Bhatia

Founder, NextGen Economics · Bangalore, India · July 2026
Sources: DeepStrike / Truthscan (Deepfake Statistics 2026) · Gartner (CISO deepfake surveys, Sep 2025 & Feb 2024 prediction) · Javelin Strategy & Research (2024 Identity Fraud Study) · Financial Times (Arup deepfake fraud case, May 2024) · Fortune Business Insights & Business Research Company (Identity Verification Market sizing, 2025-2034) · iProov Threat Intelligence Report · EU AI Act, US Take It Down Act (2025) statutory text.
Not investment advice. This letter proposes a cross-sector investment framework; it does not constitute a recommendation regarding any security. Company examples are illustrative of a category, not endorsements.