The post has been translated automatically. Original language: Russian
The author of the initial study and adaptation for publication by the Astana Hub resident: Svetlana Romanenko, EMY (Ethical Metadata Yield) LLP, Taking into account the research: "Legal regulation of the international financial architecture in the context of digital transformation. The experience of the European Union and the Republic of Poland"
In the first article, EMY was presented as a trusted data architecture concept. In this article, the same approach is considered in a narrower context — digital assets, tokenization, and verifiability of data origin.
Why regulation is not enough
Digital assets, tokens, blockchain, artificial intelligence, and cross-border digital services have already become part of the modern economy. Until recently, many of these tools were perceived as an experimental area of the technology market. Now they are gradually moving into a regulated environment.
The European Union is building a legal framework for crypto assets, artificial intelligence, data access, digital services, personal data, and digital markets. Kazakhstan is also moving in this direction: the Law of the Republic of Kazakhstan "On Digital Assets in the Republic of Kazakhstan" establishes the legal basis for the issuance and turnover of digital assets.
But regulation alone does not answer the main question: is it possible to trust the data on the basis of which a digital asset is created, transmitted or used?
The experience of the European Union and the Republic of Poland, considered in the initial study, shows that even with financial supervision and the development of European regulatory approaches, there remains a practical gap between the legal status of a market participant and the user's ability to verify the actual provision of a digital asset, the authority of the platform, the movement of funds and the responsibility of the issuer.
It is this gap that is the focus of the EMY concept.
Where the risk arises
In a typical digital environment, the user often sees only the interface: personal account, balance, token, transaction status, or digital document. But behind this interface, it is not always clear who created the record, on what basis it appeared, whether the token is associated with a real object, who is responsible, and whether the revision history can be restored. A typical risk arises when a digital token is claimed to be linked to a real asset, but the user cannot independently verify the existence of such an asset, the issuer's authority, the movement of reserves, and the legal nature of the instrument. The problem is not that tokenization as a technology is bad. The problem is that there is often no verifiable link between a digital asset, its issuer, user rights, movement of funds, and the responsibility of the platform.
Blockchain partially solves this problem. It can lock the record and make it difficult to change it covertly. But the blockchain does not guarantee the integrity of the initial data entry. If false information was originally entered into the system, the very immutability of the record does not make it true. Therefore, for the digital economy, not only the issue of record storage is important, but also the issue of its origin.
What does EMY offer
The EMY concept suggests considering tokenization as a way to establish a trusted relationship between data, an object, a subject, a legal basis, and a history of actions. In this model, an EMY token is a digital container for verified communication. His task is not to trade on the stock exchange and not to change the value, but to show why a particular digital record can be trusted.
Technically, the EMY token is closer to a cryptographically authenticated set of metadata that exists inside a secure digital circuit. Logically, it is closer to the Verifiable Credentials model than to a crypto asset traded on the market. The EMY code acts as a unique identifier that links a digital object or event with its metadata and subsequent history of actions.
Ethical metadata is understood not just as a technical description of a record, but as a record of its legal and managerial context: the basis for creation, purpose of use, amount of access, responsible person, history of changes and digital footprint.
If we are talking about a digital asset, it is important to see not only the token itself, but also which object is behind it, who created it, on what basis, what documents confirm its status, who made the changes and what digital footprint remained after each operation.
What might this look like in practice?
Let's imagine a corporate supply chain. The same object goes through a purchase request, contract, invoice, warehouse record, act of completed work or delivery, payment and accounting. In normal practice, these data can be stored in different systems, and in case of a dispute, you have to manually restore where the discrepancy occurred.
In the EMY model, each significant object or event can be assigned an EMY code. The EMY token captures the link between the object, the document, the responsible person, the basis of the operation and the digital footprint. Then the verification goes not only for a single document, but for the entire history of its origin and modification. For example, if the delivery does not match the contract or the warehouse record differs from the act, the system should allow you to see not only the final value, but also the entire chain: who initiated the application, on what basis the contract was concluded, which object was delivered, who confirmed acceptance, when the payment was made and what changes were made during the process.
This approach is important for procurement, financial control, asset management, subsurface use, internal audit, and compliance. It does not cancel the existing accounting systems, but helps to restore the semantic and legal connection between the data in different contours.
How does EMY differ from banking ecosystems and existing standards
Kazakhstani banks are already developing digital ecosystems, superapplications, payment solutions, Open Banking, partner platforms and their own registers of customer data. This is a strong infrastructure, but it usually operates within its own circuit: payments, invoices, customer data, products, and partner services. EMY is considering another site, the junction between different systems. Its purpose in the concept is to help restore the data chain when one process passes through a bank, a state registry, an ERP, a contract system, a warehouse, an insurance company, an auditor or a regulator.
In such a situation, it is important not only to make a payment or save a document, but to restore the entire chain: where the data came from, who changed it, on what basis, and what digital footprint remained.
At such junctures, the main risk arises: it is unclear which system is the source of truth, who changed the record, on what basis it was done, and how to prove the history of the digital object. In this sense, EMY can be considered as an add-on trust layer, a layer of trusted data connectivity that can complement banking, corporate, and government ecosystems.
Trusted data infrastructures already exist in international practice, including EBSI and Verifiable Credentials solutions. Such approaches are primarily focused on verifying digital attributes, documents, and identity.
EMY uses a similar logic of verifiability, but focuses on a broader link: subject — object — event — legal basis — digital footprint. For corporate, government, and quasi-government processes, this is fundamental: an object, contract, asset, shipment, budget request, or accounting operation are no less important than the entity itself. Therefore, EMY develops the application logic of verifiability for the tasks of audit, compliance, asset management, procurement, financial control and verification of the origin of data.
Connection with digital assets and artificial intelligence
Modern regulation of digital assets is built around transparency, verifiability, identification of participants, disclosure of information and responsibility of the issuer. EMY transfers these principles from the token's market circulation level to the data architecture level.
This is especially important in the context of the development of artificial intelligence. AI systems depend on the quality of the data. If the data is substituted, incomplete, collected without a clear legal basis, or does not have a verifiable source, the result of such a system becomes risky.
The EMY concept can be useful as a data origin layer for AI contours. In this approach, it is important not only what result the model produced, but also what data this result is based on.
Project stage
At the current stage, EMY is being considered as a concept and patent architecture for trusted tokenization. The project is at the stage of architectural study and preparation for the creation of a PoC/MVP.
The basic elements of the future implementation should be the EMY code, the EMY token, the ethical metadata layer, and the digital footprint capture module. This positioning is important: EMY does not present the concept as a finished product, but shows the direction of technological implementation.
class="paragraph"> For Astana Hub, this topic is at the intersection of Data Governance, Trust Technologies, LegalTech, RegTech, Web3, AI compliance, digital identity and verifiable data. This is the concept of a future software architecture where tokenization is used not for speculative turnover, but to create a trusted connection between data, object, subject and legal basis.Instead of output
The law may establish a duty to disclose information, but technology should help verify whether information has been disclosed.
The right may require user identification, but the technology must record what action the user performed and in what context.
The law may consolidate the responsibility of the issuer, but technology should help restore the digital chain between the issuer, the asset, the user and the operation.
The digital economy is gradually moving away from trust in the interface and requires verifiable data. The blockchain is able to fix the record. But trust arises only when it is clear who created the data, where it came from, on what basis it is used, what rights are associated with it, and how its history has changed.
The EMY concept is aimed precisely at this task: to make a digital record not just electronic, but verifiable — with a clear origin, legal basis, connection to the object and a recoverable history of actions.
The following sources were taken into account when preparing the material:
1. The Law of the Republic of Kazakhstan "On Digital Assets in the Republic of Kazakhstan" dated February 6, 2023 No. 193-VII SAM.
https://adilet.zan.kz/rus/docs/Z2300000193
2. The Law of the Republic of Kazakhstan "On Artificial Intelligence" dated November 17, 2025 No. 230-VIII SAM.
https://adilet.zan.kz/rus/docs/Z2500000230
3. Digital Code of the Republic of Kazakhstan dated January 9, 2026 No. 255-VIII SAM.
https://adilet.zan.kz/rus/docs/K2600000255
4. Regulation (EU) 2023/1114 — Markets in Crypto-Assets Regulation, MiCA.
https://eur-lex.europa.eu/eli/reg/2023/1114/oj/eng
5. Regulation (EU) 2024/1689 — EU Artificial Intelligence Act.
https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
6. Regulation (EU) 2016/679 — General Data Protection Regulation, GDPR.
https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
7. W3C Verifiable Credentials Data Model v2.0.
https://www.w3.org/TR/vc-data-model-2.0/
8. EBSI Verifiable Credentials Framework.
https://hub.ebsi.eu/vc-framework
Автор исходного исследования и адаптации для публикации резидента Astana Hub: Романенко Светлана Владимировна ТОО «EMY (Ethical Metadata Yield)» С учетом исследования: «Правовое регулирование международной финансовой архитектуры в условиях цифровой трансформации. Опыт Европейского союза и Республики Польши»
В первой статье EMY была представлена как концепция архитектуры доверенных данных. В этом материале тот же подход рассматривается в более узком контексте — цифровые активы, токенизация и проверяемость происхождения данных.
Почему регулирования недостаточно
Цифровые активы, токены, блокчейн, искусственный интеллект и трансграничные цифровые сервисы уже стали частью современной экономики. Еще недавно многие из этих инструментов воспринимались как экспериментальная зона технологического рынка. Сейчас они постепенно переходят в регулируемую среду.
Европейский союз выстраивает правовую рамку для криптоактивов, искусственного интеллекта, доступа к данным, цифровых услуг, персональных данных и цифровых рынков. Казахстан также движется в этом направлении: Закон Республики Казахстан «О цифровых активах в Республике Казахстан» закрепляет правовые основы выпуска и оборота цифровых активов.
Но регулирование само по себе не отвечает на главный вопрос: можно ли доверять данным, на основании которых создается, передается или используется цифровой актив?
Опыт Европейского союза и Республики Польши, рассмотренный в исходном исследовании, показывает, что даже при наличии финансового надзора и развитии европейских подходов к регулированию сохраняется практический разрыв между правовым статусом участника рынка и возможностью пользователя проверить реальное обеспечение цифрового актива, полномочия платформы, движение средств и ответственность эмитента.
Именно этот разрыв находится в фокусе концепции EMY.
Где возникает риск
В обычной цифровой среде пользователь часто видит только интерфейс: личный кабинет, баланс, токен, статус операции или цифровой документ. Но за этим интерфейсом не всегда понятно, кто создал запись, на каком основании она появилась, связан ли токен с реальным объектом, кто несет ответственность и можно ли восстановить историю изменений. Типичный риск возникает, когда цифровой токен заявляется как связанный с реальным активом, но пользователь не может самостоятельно проверить наличие такого актива, полномочия эмитента, движение резервов и правовую природу инструмента. Проблема не в том, что токенизация как технология плоха. Проблема в том, что часто отсутствует проверяемая связь между цифровым активом, его эмитентом, правами пользователя, движением средств и ответственностью платформы.
Блокчейн частично решает эту задачу. Он может зафиксировать запись и затруднить ее скрытое изменение. Но блокчейн не гарантирует честность первичного ввода данных. Если в систему изначально внесена недостоверная информация, сама неизменность записи не делает ее правдивой. Поэтому для цифровой экономики важен не только вопрос хранения записи, но и вопрос ее происхождения.
Что предлагает EMY
Концепция EMY предлагает рассматривать токенизацию как способ фиксации доверенной связи между данными, объектом, субъектом, правовым основанием и историей действий. В этой модели EMY-токен — это цифровой контейнер проверяемой связи. Его задача — не торговаться на бирже и не менять стоимость, а показывать, почему конкретной цифровой записи можно доверять.
Технически EMY-токен ближе к криптографически заверяемому набору метаданных, который существует внутри защищенного цифрового контура. По своей логике он ближе к модели Verifiable Credentials, чем к криптоактиву, обращающемуся на рынке. EMY-код выполняет роль уникального идентификатора, который связывает цифровой объект или событие с его метаданными и последующей историей действий.
Под этичными метаданными понимается не просто техническое описание записи, а фиксация ее правового и управленческого контекста: основания создания, цели использования, объема доступа, ответственного лица, истории изменений и цифрового следа.
Если речь идет о цифровом активе, важно видеть не только сам токен, но и то, какой объект за ним стоит, кто его создал, на каком основании, какие документы подтверждают его статус, кто вносил изменения и какой цифровой след остался после каждой операции.
Как это может выглядеть на практике
Представим корпоративную цепочку поставки. Один и тот же объект проходит через заявку на закуп, договор, накладную, складскую запись, акт выполненных работ или поставки, платеж и бухгалтерский учет. В обычной практике эти данные могут храниться в разных системах, а при споре приходится вручную восстанавливать, где возникло расхождение.
В модели EMY каждому значимому объекту или событию может присваиваться EMY-код. EMY-токен фиксирует связку между объектом, документом, ответственным лицом, основанием операции и цифровым следом. Тогда проверка идет не только по отдельному документу, а по всей истории его возникновения и изменения. Например, если поставка не совпадает с договором или складская запись расходится с актом, система должна позволять увидеть не только итоговое значение, но и всю цепочку: кто инициировал заявку, на каком основании заключен договор, какой объект поставлен, кто подтвердил приемку, когда была произведена оплата и какие изменения вносились по ходу процесса.
Такой подход важен для закупок, финансового контроля, управления активами, недропользования, внутреннего аудита и комплаенса. Он не отменяет существующие учетные системы, а помогает восстановить смысловую и правовую связь между данными в разных контурах.
Чем EMY отличается от банковских экосистем и существующих стандартов
Казахстанские банки уже развивают цифровые экосистемы, суперприложения, платежные решения, Open Banking, партнерские платформы и собственные реестры клиентских данных. Это сильная инфраструктура, но она обычно работает внутри своего контура: платежи, счета, клиентские данные, продукты и партнерские сервисы. EMY рассматривает другой участок — стык между разными системами. Его задача в концепции — помочь восстановить цепочку данных, когда один процесс проходит через банк, государственный реестр, ERP, договорную систему, склад, страховую компанию, аудитора или регулятора.
В такой ситуации важно не только провести платеж или сохранить документ, а восстановить всю цепочку: откуда появились данные, кто их изменил, на каком основании и какой цифровой след остался.
На таких стыках возникает главный риск: непонятно, какая система является источником истины, кто изменил запись, на каком основании это сделано и как доказать историю цифрового объекта. В этом смысле EMY можно рассматривать как надстроечный trust-layer — слой доверенной связности данных, который может дополнять банковские, корпоративные и государственные экосистемы.
В международной практике уже существуют инфраструктуры доверенных данных, включая EBSI и решения на базе Verifiable Credentials. Такие подходы в первую очередь ориентированы на проверку цифровых атрибутов, документов и идентичности.
EMY использует близкую логику проверяемости, но делает акцент на более широкой связке: субъект — объект — событие — правовое основание — цифровой след. Для корпоративных, государственных и квазигосударственных процессов это принципиально: объект, договор, актив, партия товара, бюджетная заявка или учетная операция имеют не меньшее значение, чем сам субъект. Поэтому EMY развивает прикладную логику проверяемости для задач аудита, комплаенса, управления активами, закупок, финансового контроля и проверки происхождения данных.
Связь с цифровыми активами и искусственным интеллектом
Современное регулирование цифровых активов строится вокруг прозрачности, проверяемости, идентификации участников, раскрытия информации и ответственности эмитента. EMY переносит эти принципы с уровня рыночного обращения токена на уровень архитектуры данных.
Это особенно важно в условиях развития искусственного интеллекта. AI-системы зависят от качества данных. Если данные подменены, неполны, собраны без понятного правового основания или не имеют проверяемого источника, результат работы такой системы становится рискованным.
Концепция EMY может быть полезна как слой происхождения данных для AI-контуров. В таком подходе важно не только то, какой результат выдала модель, но и то, на каких данных этот результат построен.
Стадия проекта
На текущем этапе EMY рассматривается как концепция и патентная архитектура доверенной токенизации. Проект находится на стадии архитектурной проработки и подготовки к созданию PoC/MVP.
Базовыми элементами будущей реализации должны стать EMY-код, EMY-токен, слой этичных метаданных и модуль фиксации цифрового следа. Такое позиционирование важно: EMY не выдает концепцию за готовый продукт, но показывает направление технологической реализации.
Для Astana Hub эта тема находится на стыке Data Governance, Trust Technologies, LegalTech, RegTech, Web3, AI compliance, цифровой идентичности и проверяемых данных. Это концепция будущей программной архитектуры, где токенизация используется не для спекулятивного оборота, а для создания доверенной связи между данными, объектом, субъектом и правовым основанием.
Вместо вывода
Право может установить обязанность раскрытия информации, но технология должна помочь проверить, была ли информация раскрыта.
Право может требовать идентификации пользователя, но технология должна зафиксировать, какое действие совершил пользователь и в каком контексте.
Право может закрепить ответственность эмитента, но технология должна помочь восстановить цифровую цепочку между эмитентом, активом, пользователем и операцией.
Цифровая экономика постепенно уходит от доверия к интерфейсу и требует проверяемых данных. Блокчейн способен зафиксировать запись. Но доверие возникает только тогда, когда понятно, кто создал данные, откуда они получены, на каком основании используются, какие права с ними связаны и как менялась их история.
Концепция EMY направлена именно на эту задачу: сделать цифровую запись не просто электронной, а проверяемой — с понятным происхождением, правовым основанием, связью с объектом и восстановимой историей действий.
При подготовке материала учитывались следующие источники:
1. Закон Республики Казахстан «О цифровых активах в Республике Казахстан» от 6 февраля 2023 года № 193-VII ЗРК.
https://adilet.zan.kz/rus/docs/Z2300000193
2. Закон Республики Казахстан «Об искусственном интеллекте» от 17 ноября 2025 года № 230-VIII ЗРК.
https://adilet.zan.kz/rus/docs/Z2500000230
3. Цифровой кодекс Республики Казахстан от 9 января 2026 года № 255-VIII ЗРК.
https://adilet.zan.kz/rus/docs/K2600000255
4. Regulation (EU) 2023/1114 — Markets in Crypto-Assets Regulation, MiCA.
https://eur-lex.europa.eu/eli/reg/2023/1114/oj/eng
5. Regulation (EU) 2024/1689 — EU Artificial Intelligence Act.
https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
6. Regulation (EU) 2016/679 — General Data Protection Regulation, GDPR.
https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
7. W3C Verifiable Credentials Data Model v2.0.
https://www.w3.org/TR/vc-data-model-2.0/
8. EBSI Verifiable Credentials Framework.
https://hub.ebsi.eu/vc-framework