Skip to content
KStart free
AI InfrastructureDefenseQuantumAll studies →

T Stamp Inc IDAI US Equity

Information Technology · CIK 1718939 · FY ends Dec 31
$3.20
-0.15 (-4.48%)
USD · as of 2026-08-28 · marketstack

T Stamp Inc (Nasdaq: IDAI), an SEC filer in Services-Prepackaged Software, closed at $3.20, -4.5%, on 2026-08-28, with a market cap of $19M as of 2026-08-27, a return on equity of -141.7%, a net margin of -265.2% and 3-year sales growth of -16.5%. Institutional ownership, earnings history and filed financials are on the tabs below.

IDAI · 10-K · period ended 2025-12-31

← all IDAI documents
filed 2026-03-31 · EDGAR original ↗

Our rendering of the filing — original pagination and typography are not reproduced, and tables are reduced to their short label cells (the figures live on FA). Nothing is summarized: every line below is the filing's own text.

blocks 1591 of 1,468336k characters rendered

idai-20251231

Table of Contents

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION

Washington, D.C. 20549

FORM 10-K

x Annual Report pursuant to Section 13 or 15(d) of the Securities Exchange Act of 1934

For the fiscal year endedDecember 31, 2025

oTRANSITION REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE

ACT OF 1934

For the transition period from ______________ to _____________

Commission file number: 001-41252

T Stamp Inc. (D/B/A Trust Stamp)

(Exact name of registrant as specified in its charter)

3017 Bolling Way NE, Floor 2, Atlanta, Georgia30305

(Address of registrant’s principal executive offices) (Zip code)

Registrant’s telephone number, including area code (404) 806-9906

Securities registered under Section 12(b) of the Act:

Title of each class TradingSymbol(s) Name of each exchange on which registered

Class A Common Stock, $0.01 par value per share IDAI The NASDAQ Stock Market LLC

Securities registered pursuant to Section 12(g) of the Act: None.

Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes oNox

Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes oNox

Indicate by check mark whether the issuer (1) has filed reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yesx No o

Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yesx No o

Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.

Large accelerated filer o Accelerated filer o

Non-accelerated filer x Smaller reporting company x

Emerging growth company x

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. o

Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 USC. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. o

If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. o

Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). o

Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Exchange Act). Yes o No x

As of June 30, 2025, the aggregate market value held by non-affiliates of the registrant, computed by reference to the price at which the registrant’s Class A Common Stock was last sold on the NASDAQ Stock Exchange on such date was $5,164,124(2,017,236 at a closing price per share of $2.56 on June 30, 2025). As of March 30, 2026, there were 5,285,008 shares of Class A Common Stock, par value $0.01 per share, of the registrant outstanding.

Table of Contents

Documents Incorporated by Reference

None

Auditor Name: Auditor Location: Auditor Firm ID:

CBIZ CPAs P.C. Marlton, New Jersey 199

Table of Contents

T STAMP INC.

TABLE OF CONTENTS

Page

PART I 4

Item 1 Business 4

Item 1A Risk Factors 24

Item 1B. Unresolved Staff Comments 30

Item 1C Cybersecurity 30

Item 2 Properties 31

Item 3 Legal Proceedings 31

Item 4 Mine Safety Disclosures 32

Item 6 Reserved 48

Item 7A Quantitative and Qualitative Disclosures About Market Price 49

Item 8 Financial Statements and Supplementary Data F-1

Report of Independent Registered Public Accounting Firm F-2

Consolidated Balance Sheets as of December 31, 2025 and 2024 F-4

Item 9A Controls and Procedures 43

Item 9B Other Information 44

Item 9C Disclosure Regarding Foreign Jurisdictions that Prevent Inspections 44

PART III 45

Item 10 Directors, Executive Officers, and Corporate Governance 45

Item 11 Executive Compensation 51

Item 13 Certain Relationships and Related Transactions 55

Item 14 Principal Accounting Fees and Services 56

Item 15 Exhibits, Financial Statement Schedules 57

Signatures 62

2

Table of Contents

Statement Regarding Forward-Looking Statements

This Form 10-K contains “forward-looking statements” within the meaning of Section 27A of the Securities Act of 1933, as amended (the “Securities Act”) and Section 21E of the Securities and Exchange Act of 1934, as amended (the “Exchange Act”), that involve risks and uncertainties, as well as assumptions that, if they never materialize or prove incorrect, could cause our results to differ materially and adversely from those expressed or implied by such forward-looking statements. Forward-looking statements may include, but are not limited to, statements relating to our outlook or expectations for earnings, revenues, expenses, asset quality or other future financial or business performance, strategies, expectations or business prospects, or the impact of legal, regulatory or supervisory matters on our business, results of operations, or financial condition. Specifically, forward-looking statements may include statements relating to our future business prospects, revenue, income, and financial condition.

Forward-looking statements can be identified by the use of words such as “estimate,” “plan,” “project,” “forecast,” “intend,” “expect,” “anticipate,” “believe,” “seek,” “target,” or similar expressions. Forward-looking statements reflect our judgment based on currently available information and involve a number of risks and uncertainties that could cause actual results to differ materially from those described in the forward-looking statements.

In addition to those factors discussed under Item 1A—“Risk Factors,” important factors could cause actual results to differ materially from our expectations. These factors include, but are not limited to:

•adverse economic conditions;

•general decreases in demand for our products and services;

•changes in timing of introducing new products into the market;

•intense competition (including entry of new competitors), including among competitors with substantially greater resources than us;

•inadequate capital;

•unexpected costs;

•revenues and net income lower than anticipated;

•litigation;

•becoming delisted from Nasdaq;

•the possible fluctuation and volatility of operating results and financial conditions;

•the impact of legal, regulatory, or supervisory matters on our business, results of operations, or financial condition;

•inability to carry out our marketing and sales plans; and

•the loss of key employees and executives.

All forward-looking statements included in this Form 10-K speak only as of the date of this Form 10-K and you are cautioned not to place undue reliance on any such forward-looking statements. Except as required by law, we undertake no obligation to publicly update or release any revisions to these forward-looking statements to reflect any events or circumstances that arise after the date of this Form 10-K or to reflect the occurrence of unanticipated events. The above list is not intended to be exhaustive and there may be other factors that could preclude us from realizing the predictions made in the forward-looking statements. We operate in a continually changing business environment and new factors emerge from time to time. We cannot predict such factors or assess the impact, if any, of such factors on our financial position or results of operations.

In this Annual Report on Form 10-K, unless the context indicates otherwise, the terms “Trust Stamp”, the “Company”, “we”, “us”, and “our” refer to T Stamp Inc., a Delaware corporation.

3

Table of Contents

PART I.

Item 1. Our Business

Overview

Trust Stamp was incorporated under the laws of the State of Delaware on April 11, 2016 as “T Stamp Inc.” T Stamp Inc. and its subsidiaries (“Trust Stamp”, “we”, or the “Company”) develop and market identity authentication software for enterprise and government partners and peer-to-peer markets.

Trust Stamp primarily develops proprietary artificial intelligence-powered solutions, researching and leveraging machine learning artificial intelligence, including computer vision, cryptography, and data mining, to process and protect data and deliver insightful outputs that identify and defend against fraud, protect sensitive user information, facilitate automated processes, and extend the reach of digital services through global accessibility. We utilize the power and agility of technologies such as GPU processing, edge computing, neural networks, and large language models to process and protect data faster and more effectively than historically possible to deliver results at a disruptively low cost for usage across multiple industries.

Our team has substantial expertise in the creation and development of AI-enabled software products. We license our technology and expertise in numerous fields, with an increasing emphasis on addressing diverse markets through established partners who will integrate our technology into field-specific applications.

Over the last year, while maintaining our strong emphasis on identity authentication for financial services, the Company has undertaken a multi-pronged process to position itself better to leverage the growing opportunities offered by the expanded capabilities, use, and acceptance of AI technologies. This process has included:

•Reducing the size of the non-production-focused executive and consulting teams to reduce overhead and releasing sales staff that did not meet their targets

•Adding senior business development advisors in Ghana, Nigeria, Kenya and Malta primarily compensated based on revenue received

•Developing joint ventures with proven industry partners with access to target markets

•Increasing focus on the cryptocurrency market (especially Stablecoins) and developing products designed to meet specific needs and opportunities in that sector

•Updating services offered via the Orchestration Layer platform in response to market feedback

•Expanding our IP portfolio to strengthen our existing position related to presentation attack detection and tokenization and include implementations such as:

i.Embedded ownership verification for cryptographic assets, a technology that we believe to have significant potential with the expansion in the ownership of crypto-assets including potential deregulation (or loosening or clarification of regulation) in the United States together with the global growth of stable coins including Central Government Digital Currencies.

ii.StableKey (or “Stable IT2”) which is a revolutionary technology that generates a “key” directly from the biometric of the user which key has a mathematical correlation to all of the user's passwords, PINS, and other “secrets” for every account and use case meaning that those secrets never need to be stored in their entirety.

•Strengthening our international 3rd party cybersecurity and data handling certifications including NCSC Cyber Essentials Plus, certified by The IASME Consortium Ltd, SOC2 certification, and D-Seal approval (the world’s first certification that includes not just data and AI model security but also the ethical and responsible use of data).

•Opening an office in Tokyo (with funding from the City of Tokyo and the Japanese government) to pursue opportunities in the APAC region.

•Participating in the K-Startup Grand Challenge 2025, South Korea’s premier acceleration program for innovative foreign startups. Backed by the Ministry of SMEs and Startups, the program supports high-potential global

4

Table of Contents

technology companies in establishing a presence in South Korea and expanding across the broader Asia-Pacific region.

•Establishing go-to-market partnerships in Nigeria and Ghana

•Participation in the Trust Valley program in the Geneva region of Switzerland

•Participation in the Founders Arena wealth management program

Markets

Trust Stamp has evaluated the market potential for its services across several verticals. (Note - none of the reports, articles, and/or data sources referenced below were commissioned by the Company, and none of them are incorporated by reference).

Data Security and Fraud

•In 2024 alone, numerous large-scale cybersecurity incidents resulted in the exposure of billions of personal records worldwide, including the so-called “Mother of All Breaches” involving over 26 billion records aggregated from multiple prior breaches, a breach of National Public Data affecting approximately 2.9 billion records including Social Security numbers, and significant compromises at major organizations such as Dell (49 million customer records), Twilio (33 million phone numbers), and Roll20 (15 million accounts). The U.S. healthcare sector alone reported 14 breaches each affecting over one million individuals, impacting an estimated 238 million residents, while other notable incidents included data exfiltration from Kadokawa/Niconico in Japan, a 1.2-terabyte leak of Disney internal communications, and widespread mobile app exposures affecting over 1.7 billion users. These breaches underscore persistent systemic vulnerabilities across industries and geographies, with material legal, operational, and reputational risks.

•In 2024, global losses from payment card fraud alone reached approximately $33.8 billion, according to the Nilson Report, surpassing the previous year’s figures and driven by escalating card‐not‐present and e‐commerce fraud. In the broader digital payments sphere, including ACH, digital wallets, BNPL, and e‐commerce, the Merchant Risk Council estimates merchants lose about 3.2 % of annual e‐commerce revenue to fraud, while Juniper Research forecasts online payment fraud losses totaling $362 billion globally by 2028, encompassing all payment channels. Furthermore, McKinsey projects $400 billion in cumulative card fraud losses over the next ten years, with authorized push payment fraud growing at an 11 % CAGR through 2027. Taken together, these figures underscore a mounting global financial liability from payment fraud that is poised to climb steadily unless countered by effective prevention strategies.

In March 2026, we announced the completion of two strategic transactions intended to expand our capabilities in cybersecurity, risk, compliance, and related trust and security solutions. Effective February 26, 2026, we acquired 100% of the outstanding share capital of Lexverify Ltd, and effective March 9, 2026, we subscribed for a 50% ownership interest in Cyberfish CyberPsychology Solutions Ltd.

We believe these transactions strengthen our position in the data security and fraud market by adding complementary technologies and domain expertise. Lexverify brings experience in risk, compliance, and privacy-related solutions, including applications involving large language models, while Cyberfish contributes expertise in crisis simulation and business disruption scenario training. We believe the combination of these capabilities with our existing AI-powered trust, identity, and security solutions may create opportunities for product development, enhanced client offerings, and cross-selling across industries with significant security, compliance, and operational resilience needs.

Both Lexverify and Cyberfish participated in accelerator programs associated with the UK National Cyber Security Centre, and we believe these relationships reflect the relevance of their technologies to cybersecurity resilience. We also expect these transactions to enhance our leadership resources and support our broader strategic growth initiatives.

5

Table of Contents

Financial and Societal Inclusion

•According to the “Global Findex Database 2021,” published by the World Bank, 1.4 billion people were unbanked as of 2021.

•131 million small and medium-sized enterprises in emerging markets lack access to finance, limiting their ability to grow and thrive (UNSGSA Financial Inclusion Webpage, Accessed March 2023).

•The global market for Microfinance is estimated at $250.4 billion in the year 2024, and is projected to reach $506 billion by 2030 according to the 2025 report titled “Microfinance - Global Market Trajectory & Analytics” published by Global Industry Analysts, Inc. To accelerate our work in this market, the Company joined the Mastercard Lighthouse MASSIV program in Spring 2025 designed to empower sustainability and social impact through strategic partnerships aiming to assist participants to scale on a global level.

Trust Stamp’s biometric authentication, liveness detection, and information tokenization enable individuals to verify and establish their identities using data derived from biometrics. While individuals in this market lack traditional means of identity verification, Trust Stamp provides a means to authenticate identity that preserves an individual’s privacy and control over that identity.

Alternatives to Detention (“ATD”)

•The ATD market includes Federal, State, and Municipal agencies for both criminal justice and immigration purposes. Trust Stamp addresses the ATD market with applications built on Trust Stamp’s privacy-preserving solutions allowing individuals to comply with ATD requirements using ethical and humane technology methodologies. Trust Stamp has developed innovative patented technologies for use in the ATD market encompassing biometrics, geolocation, and tokenization as well as a proprietary, tamper-resistant, battery-free “Tap-In-Band” that can complement or replace biometric check-in requirements and provide a lower-cost and more humane alternative to traditional “ankle bracelet” technology.

•In December 2024, we announced a go-to-market agreement with a leading provider of software solutions to the U.S. Federal Government. Based on the priorities of the current administration and express funding provision in the 2026 appropriations bill, the Company and its partner are actively communicating with the government on opportunities to implement the Company’s technology for identified and funded needs but no substantive progress is anticipated until there is an approved appropriations bill for the Department of Homeland Security.

Stablecoins and other Cryptocurrencies

•As of mid-2025, the total stablecoin market capitalization sits around $170 billion, with sources varying between $160B and $200B depending on which coins are included. Tether (USDT) still dominates the pack, with other major players like USDC, BUSD, and DAI following behind. Analysts project the market cap of stablecoins to double to around $300–400 billion by 2030, driven by incremental adoption in payments and DeFi. Predicting this growth, the Company invested in developing and patenting technologies that it believes to be important assets to participate in the stablecoin and other cryptocurrency markets, including a patent related to embedding identity data in the metadata of cryptographic tokens and the trademark “StableKey”. The Company anticipates cryptocurrencies playing a growing role in its customer base in parallel to, and in some cases involving, its traditional financial services customers.

The Company announced a biometrically secured proprietary non-custodial software wallet in December 2025 which will be able to function as both a wallet directly managing access credentials for digital assets and as a “wallet of wallets”. The wallet will be offered directly to end-users and financial institutions. At the end of December 2025, our R&D team delivered an Minimum Viable Product ("MVP") of our Stablecoin-focused Wallet of Wallets (“WoWTM”) and we signed an LOI with a fellow Nasdaq company for a first deployment. During January 2026, our Director of Innovation relocated to Switzerland to participate in the Trust Valley program and identify opportunities in Switzerland for our StableKey technology and WoW. Final design of the WoW wallet awaits clarity regarding the in-flux legislation related to the ability of stablecoins to pay interest or similar returns. While our WoW product has not yet been taken to market, it offers advanced capabilities and utilizes proven proprietary technologies. Therefore, we believe that if we establish product-market fit, the economic potential could be substantial.

6

Table of Contents

Healthcare Technology

We believe the healthcare sector represents a significant opportunity for the application of our identity authentication and privacy protection technologies. Healthcare providers, pharmacies, and related service organizations increasingly require secure, privacy-conscious methods to verify identity, protect sensitive personal information, and support digital workflows across patient onboarding, records access, and service delivery.

We have for several years recognized the potential of our technology in healthcare-related use cases, and during 2025 we advanced these efforts from exploration toward commercial implementation. We currently have a revenue generating commercial implementation with a Malta-based company that also operates in Dubai. In addition, we are in advanced negotiations to deploy our technology for an international pharmacy and primary care group in the European Union and MENA region and are in discussions with a well established EU hospital group regarding a tele-medicine partnership in Africa.

We believe our capabilities are well suited to healthcare environments, where organizations must balance security, regulatory compliance, user accessibility, and protection of highly sensitive data. Our technology may help healthcare-sector customers enhance trust in digital interactions while reducing the need to expose or retain unnecessary personal information. While our healthcare initiatives are still developing, we believe this sector may become an increasingly important component of our commercial growth strategy.

Other Markets

The Company is developing products and working with partners and industry organizations in other sectors that offer significant market opportunities for our existing and pipeline IP. We anticipate licensing our technology in numerous fields, typically through established partners who will integrate our technology into field-specific applications.

Africa

The African Continental Free Trade Area (AfCFTA) is a landmark agreement that binds 54 African nations and an estimated 1.47 billion people into the world’s largest free trade area. AfCFTA has significant economic potential for Africa, as it aims to create a single market for goods and services across 55 countries, representing over 1.3 billion people with a combined GDP of approximately $3.4 trillion. By reducing trade barriers, the agreement could contribute an additional $450 billion to Africa’s GDP by 2035, lifting 30 million people out of extreme poverty and increasing the incomes of 68 million people, according to the World Bank. Over the next decade, Africa’s share of the world population is projected to reach 21%, up from 13% in 2000. More than 50% of young people entering the workforce will be in sub-Saharan Africa. By 2050, the region’s working-age population will still be rising while it is falling virtually everywhere else, and Africa will be home to an estimated 2.5 billion people, or 25% of all humanity.

Globally, 850 million people did not have identity documents in 2023, with 542 million pe in Africa. Of that 542 million, 95 million are children who have never had their birth recorded, and 120 million are children without a birth certificate. The single initiative of implementing universal tokenized identity in African countries has the potential to significantly boost the implementing countries' economies. According to the United Nations Economic Commission for Africa (UNECA), countries adopting digital ID programs could unlock economic value equivalent to 3% and 13% of their GDP by 2030.

A transition to digital records for births, marriages, deaths, and electronic identity documents represents a transformative opportunity for developing nations and builds a foundation for economic growth. Establishing a robust digital infrastructure for vital records enhances administrative efficiency, fosters inclusive development, strengthens governance, and unlocks economic potential. Yet, developing African countries are often unable or unwilling to fund the initial capital expenditure required to make the transition.

Trust Stamp participated in financial inclusion projects in Africa for a number of years through Mastercard’s previous implementation of our technology and we established a regional R&D center in Rwanda in 2021 to focus on ensuring equity in the development and implementation of biometric technology in Africa. In 2023 we started direct outreach to African countries and we are in serious and extended dialogue with four countries as well as our work with Africa’s largest provider of mobile telecommunications services.

7

Table of Contents

With the assistance of the Mastercard Lighthouse MASSIV program, we intend to build upon this work to maximize the opportunities to meet the critical need for secure identity programs for both governments and NGOs and have established go-to-market focused agreements with partners in Nigeria and Ghana.

Our multi-year investment in the African market has progressed from market cultivation to revenue generation. In January 2026, we received our first purchase order for the use of our Irreversibly Transformed Identity Token (“IT2”) from an African telecommunications company situated across a dozen African and Middle Eastern markets and serving hundreds of millions of subscribers. The initial purchase order is for the IT2 in a specific market but based upon our customer’s communications, we anticipate both the geographic scope and product range expanding in 2026. We are also in discussion with another major telecoms provider in Africa for similar services and are making progress towards an agreement. Based on these two engagements and market discovery, we will be actively pursuing similar telecoms opportunities in other African countries and elsewhere.

In parallel, our first African nation-state project continues to progress albeit at a slower pace than we would hope. We anticipate announcing specific revenue commitments in the third quarter of 2026.

During January 2026, at their request, we worked with the office of the Vice President of Nigeria and various federal and local government ministries to arrange for a Trust Stamp team to visit Nigeria for two weeks during February 2026 to identify areas of government operations where our technology can be implemented. We believe the visit was very successful in building potential partnerships at a Federal and Regional level in Nigeria, and significant PR regarding this potential was generated by the Nigerian government and published online. Individual project discussions are now ongoing between our Company and the various federal and local government ministries that we met with on this trip.

United Kingdom

With our growing team in the UK, we have started to identify banking sector opportunities there and will be pursuing those opportunities going forward. We are also engaging with the fast accelerating UK age-verification market that is (largely unsuccessfully) seeking to comply with new government mandates. To this end, on March 9, 2026, the Company (through its wholly-owned subsidiary, Trust Stamp Malta Limited) agreed to subscribe for fifty percent (50%) of the authorized share capital of CyberFish CyberPsychology Solutions Ltd, a private company incorporated in England and Wales that is a graduate of the UK National Cybersecurity Center’s startup program (“CyberFish”). On the same date, the Company (through Trust Stamp Malta Limited) entered into a Consulting Agreement with CyberFish. Under the Consulting Agreement, CyberFish agreed to provide consulting services relating to market development in the United Kingdom, including market entry and expansion strategy, business development, partnership identification, and related services.

Principal Products and Services

We adhere to the best practices outlined in the National Institute of Standards and Technology (“NIST”) and International Organization for Standardization (“ISO”) frameworks, and our policies and procedures in managing personally identifiable information (“PII”) comply with General Data Protection Regulation (“GDPR”) requirements wherever such requirements are applicable.

The IT2 replaces biometric templates and scans with meaningless numbers, letters, and symbols to remove sensitive data from the reach of criminals using a proprietary process by which a deep neural network irreversibly converts biometric and other identifying data, from any source, into the secure tokenized identity. This IT2 is unique to the user, is different every time it is generated from a live subject, and cannot be reverse-engineered and rebuilt into the user’s face or other original identity data.

8

Table of Contents

Each token can be stored and compared to all other tokens from the same modality, allowing the Company’s AI-powered analytics to predict if a single subject has generated two or more tokens, even if the subject has passed conventional KYC with, e.g., falsified identity documents. Using this technology, an IT2 can be employed for re-authentication purposes, including account recovery, password-less login, new account creation, and more, across the organization or even within a consortium of organizations, all in a low-cost and low-friction delivery that is fast and secure.

Our technology is being used for enhanced due diligence, KYC/AML compliance, synthetic identity fraud reduction and “second chance” approval for customer onboarding and account access, together with the delivery of humanitarian and development services. The solution allows organizations to approve more users, keep bad actors from accessing systems and services, and retain existing users with a superior user experience.

Our hashing and matching technology can maximize the effectiveness of all types of identity data while rendering it safer to use, store, and share. Whatever the source of identity data, it can be stored and compared as an IT2. See the chart below for examples.

9

Table of Contents

The Lexverify acquisition immediately added capability for LLM-powered compliance monitoring of communications and documents, and the Cyberfish investment provides us with risk-scenario products that we regard as having significant and immediate potential for our existing customer base and others. Together, the two transactions provide us with the expertise to build unique scenarios to train LLM, together with other LLM based products that will be announced during 2026.

Products Under Development

We have continued rapid investment in the development of technologies to rebut the growing dangers of AI-powered attacks. We are currently in production-testing of new tools to combat both Injection and Generative Adversarial Network Attacks and we plan to submit our newest innovations for third-party certification in Q2 2026. We believe that this sustained investment in intellectual property differentiates us from many larger competitors that are farming legacy technology

Distribution

Through licensing we allow customers to utilize our technology in a wide variety of applications. Uses can include (e.g.):

•The provision of services and hashing to enterprises, NGOs, and government, to overlay on third-party biometric and identity data.

•Hash licensing, translation, and certification services for biometric vendors.

•Management of zero-knowledge-proof services, whether as a tributary between Identity Lakes or operating consortium lakes.

•Tokenized identity creation for large scale deployments, such as humanitarian and government identity programs.

LicensingAgreements

License agreements are typically a hosted offering, on-premise solution, or both pursuant to which the customer pays for the initial product development plus a license fee for the use of Trust Stamp’s technologies on a periodic and/or volume-based basis. In addition to consuming and paying for Trust Stamp’s services for their own use, some key customers also serve as channel partners by offering Trust Stamp products to their own customer base, whether as stand-alone products, or integrated into their own services as upgraded product offerings.

SaaS Agreements

Software-as-a-Service ("SaaS") agreements are typically serviced through the Company’s Orchestration Layer platform, which is being utilized in new global identity authentication system with Fidelity Information Services, LLC ("FIS"). The platform includes our proprietary tokenization technology and is designed to provide easy integration with and access to, Trust Stamp’s products, chargeable on a per-use basis. The Orchestration Layer facilitates no-code and low-code implementations, making adoption faster and even more cost-effective for a broader range of potential customers. It is expected to accelerate the Company’s evolution, from being exclusively a custom solutions provider, to also offering a modular and highly scalable SaaS model with low-code implementation.

Competition

We can potentially work with any identity data from any source, potentially breaking vendor and modality lock-in, but our primary market target is the biometric service industry, which is growing exponentially while being threatened by a consumer, media, and legislative backlash against storing biometric data. The IT2 can potentially be overlaid on any biometric or other identity data provider.

In general, we compete for customer budgets with any company in the identity authentication industry. Major competitors in this space include companies such as NEXT Biometrics, IDEMIA, Synaptics, Cognitec, Innovatrics, Suprema, FaceTec, Rank One Computing, Acuant, Jumio, Onfido, Ping, and Mitek. However, we believe that, due to the uniqueness of our technology solution, the Company does not currently have any direct competitors for the core IT2 solutions upon which the growth in our business plan is focused.

10

Table of Contents

We believe that given sufficient time and resources, we can augment any biometric modalities including face, hand, iris, voice, gait, and behavior, together with any other identifying data which places us in a unique position versus providers of biometric services.

We are unaware of any other provider being able to offer or support a proliferation of tokenized authentication modalities in this fashion, and therefore we believe there are no other companies that directly compete with us in this space. If our go-to-market strategy is successful, biometric service providers can be channel distributors, and not necessarily competitors.

Growth Strategy

Our strategy is to:

•Expand the scope and range of services that we provide to and through our existing clients.

•Continue to add significant new clients for our current and future services.

•Offer our services via channel partners with substantial distribution networks.

•Offer our technology on a “low code” basis, providing access via an orchestration layer and/or open-APIs to enable implementation by a broader range of clients.

•The addition of alternate authentication tools including non-facial-biometric options and non-biometric-knowledge and device-based tools facilitating two and multi-factor authentication.

•Offer our IT2 technology for use by other biometric and data services providers to protect and extend the usability of their data.

•Provide ready-to-use / customizable platforms that leverage our IT2 technology in specialized markets.

Human Capital

Given the geographic diversity of its team, and to facilitate cost-effective administration, Trust Stamp secures the services of its permanent team members through a variety of administrative structures that include wholly owned subsidiaries, professional employer organizations, and consulting contracts. Over 2024 and 2025, our team size was rationalized to maximize the impact of investable dollars. As of December 31, 2025, the Company had 4 full-time and 1 part-time team members that work out of the United States, 24 full-time members that work out of Malta, 13 full-time team members in Poland and Central Europe, 2 full-time and 1 part-time team members in the United Kingdom, 14 full-time team members and 1 part-time team members working in the Philippines, 12 full-time team members working in Rwanda, 2 full-time team members in Denmark, and 1 full-time team member working in India. In addition, our permanent team is augmented by long-term contractors and as needed by contract development and other staff on a short-term basis.

Outsourcing

We design and develop our own products. We use an outsourcing company, 10Clouds, for additional development staff as needed. 10Clouds is considered a related party. 10Clouds is considered a related party due to being the Company's third party contractor for software development and investor in the Company. In addition, we also utilize SourceFit, a company in the Philippines, for PEO services, representing approximately 3% of our operating expenses during the year ended December 31, 2025. Amazon Web Services provides cloud hosting and processing services, representing approximately 10% of our operating expenses during the year ended December 31, 2025.

Key Customers

The Company’s initial business consisted of developing proprietary privacy-first identity solutions and implementing them through custom applications built and maintained for a few key customers. In the fourth quarter of 2022, the Company added to its product offerings a modular SaaS model intended for low-code or no-code implementation (“the Orchestration Layer”). The Orchestration Layer has been successful in attracting interested customers with over one hundred (100) financial institutions onboarded as of the date of this report, but those institutions have been slow to go into full production which has impacted revenue expectations. An analysis of the slow adoption revealed that many of the institutions would need some level of customization, and in the fourth quarter of 2024 and the first quarter of 2025, the Company invested in the modification of the modules to meet the broader range of needs and preferences identified by the enrolled institutions. The Company is now seeing a growth in transaction volumes and is focused on maintaining and accelerating that growth.

11

Table of Contents

Historically, the Company generated most of its income through two long-term partnerships, comprising a relationship with an S&P 500 bank and a relationship with Mastercard International (“Mastercard”) with the Mastercard partnership diminishing in significance over and post 2024 as Mastercard’s market focus changed.

Effective July 1, 2025, the Company's agreement with the S&P 500 bank was extended to May 31, 2031, subject to either party having the right to terminate for cause and a right for the customer to cancel for convenience on giving 6 months' notice.

Under the terms of the extension, the Company receives a guaranteed minimum income stream for services, together with hosting and other fees and reimbursement of expenses incurred, which are subject to agreed markups of 10% or 20%. Minimum billing for services in the 1st year of the renewal is set at $154,000 per month with annual CPI-related increases. Under the arrangement, total minimum monthly billings will exceed $215,000 per month, subject also to CPI-related increases. The difference between both figures is the inclusion of third-party vendor fees billed to the customer. Based on the strength of the relationship and current and anticipated service needs, the Company anticipates actual billings exceeding contractual minimums.

In March 2019, the Company entered into a technology services agreement with Mastercard International (the "TSA”). Under the TSA, IT2 technology was being implemented by Mastercard for Humanitarian & Development purposes as an element of its Community Pass and Inclusive Identity offerings in developing economies. Based on a changing market focus by Mastercard, effective December 31, 2024, the limited exclusivity for development-related purposes granted to Mastercard expired and the software schedule and associated services terminated on February 6, 2026. The expiry permitted the Company to commence working directly with governments in developing countries and also engage with international NGO that had previously worked with Mastercard.

In 2022, the Company expanded its key customer base to include an investment from and a relationship with FIS, a relationship-focused upon the implementation of our Orchestration Layer in FIS’ Global KYC product offering.

The Orchestration Layer is a low-code platform that is designed to be a one-stop shop for Trust Stamp services and provides easy integration to our products; chargeable on a per-use basis. The Orchestration Layer utilizes the Company’s next-generation identity package, offering rapid deployment across devices and platforms, with custom workflows that seamlessly orchestrate trust across the identity lifecycle for a consistent user experience in processes for onboarding and KYC/AML, multi-factor authentication, account recovery, fraud prevention, compliance, and more. The Orchestration Layer facilitates no-code and low-code implementations of the Company’s technology making adoption and updating faster and cost-effective for a broader range of potential customers.

As of December 31, 2025, 97 financial institutions, representing over $350 billion in aggregate assets, had been onboarded through FIS. As of the same date, 110 customers (including both FIS and non-FIS customers) had been onboarded to the Orchestration Layer, including those that have fully implemented the platform and those currently undergoing implementation.

The first (non-FIS) client onboarded to the Orchestration Layer in the third quarter of 2022 has generated $576 thousand of revenue for the Company to date, including $151 thousand during the year ended December 31, 2025.

Overall Orchestration Layer transaction volumes increased by approximately 20% over 2025 with a circa 200% increase in FIS-related transactions, but the rate of implementation and transaction volumes are far lower than we consider satisfactory and the channel structure in place does not provide us with adequate opportunities to work with the individual institutions and accelerate implementation. To address this we have budgeted for additional sales support staff and for participation in industry events where we can directly engage with the enrolled institutions. We will be carefully monitoring and reporting on progress throughout 2026.

On February 20, 2025, the Company executed a Master Technology Service Agreement ("MTSA") (effective January 1, 2025) with QID Technologies LLC (“QID”) to provide technical services as agreed from time to time and documented by statements of work. The MTSA provided for an initial minimum payment of $100,000 per calendar month, with the budgeted payment thereafter not to exceed $300,000 per month without mutual agreement. The MTSA will remain in effect for one year and will be renewed automatically for successive one-year periods, until it is terminated. Either Party may terminate for convenience by giving notice of non-renewal no less than 90 days’ before the expiry of each one-year term. The Company owns a 10% equity interest in QID but is not involved in its management. Reaching the maximum monthly revenue of $300,000 would require QID ramping up its customer-facing activities, a process that is not controlled by the Company. QID is currently a finalist in an RFP for a major project that would utilize our technology, but at this

12

Table of Contents

time, the ramp-up process has taken longer than anticipated, and despite assurances by QID’s majority owner as to their ongoing commitment to the enterprise, there is no certainty as to the speed at which the services will be delivered and consequently the billing levels in a given month.

Regulation

Our business is not currently subject to any licensing requirements in any jurisdiction in which we operate, other than the requirement to hold a business license in the City of Atlanta (with which we are in compliance), and the requirement to hold a trading license in Rwanda (with which we are in compliance). Given the significant focus on the use of biometrics in many countries, we do anticipate additional regulation being introduced in one or more jurisdictions in which we operate, and such requirements could be burdensome and/or expensive or even impose requirements that we are unable to meet.

We are subject to substantial governmental regulation relating to our technology and will continue to be for the lifetime of our Company. By virtue of handling sensitive PII and biometric data, we are subject to numerous statutes related to data privacy, and additional legislation and given the current focus on the collection, storage, and use of biometrics, additional regulation should be anticipated in every jurisdiction in which we operate. Examples of regulations we could be subject to are:

•Health Insurance Portability and Accountability Act (HIPAA)

•Health Information Technology for Economic and Clinical Health Act (HITECH)

•The General Data Protection Regulation 2016/679 (GDPR)

•ePrivacy Directive

•The California Privacy Rights Act (CPRA)

•The California Consumer Privacy Act (CCPA)

•Biometric Information Privacy Act (BIPA)

•Act on the Protection of Personal Information (APPI)

•United Kingdom General Data Protection Regulation (UK GDPR)

•Artificial Intelligence Act (EU AI Act)

•Nigeria Data Protection Act 2023

HIPAA and HITECH

Under the administrative simplification provisions of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), as amended by the Health Information Technology for Economic and Clinical Health Act “HITECH”), the U.S. Department of Health and Human Services (“HHS”) issued regulations that establish uniform standards governing the conduct of certain electronic healthcare transactions and requirements for protecting the privacy and security of protected health information (“PHI”), used or disclosed by covered entities and business associates. Covered entities and business associates are subject to HIPAA and HITECH. Our subcontractors that create, receive, maintain, transmit, or otherwise process PHI on behalf of us are HIPAA “business associates” and must also comply with HIPAA as a business associate.

HIPAA and HITECH include privacy and security rules, breach notification requirements, and electronic transaction standards.

The privacy rules cover the use and disclosure of PHI by covered entities and business associates. The privacy rules generally prohibit the use or disclosure of PHI, except as permitted under certain limited circumstances. The privacy rules also set forth individual patient rights, such as the right to access or amend certain records containing his or her PHI, or to request restrictions on the use or disclosure of his or her PHI.

The security rules require covered entities and business associates to safeguard the confidentiality, integrity, and availability of electronically transmitted or stored PHI by implementing administrative, physical, and technical safeguards. Under HITECH’s Breach Notification Rule, a covered entity must notify individuals, the Secretary of the HHS, and in some circumstances, the media of breaches of unsecured PHI.

13

Table of Contents

In addition, we may be subject to state health information privacy and data breach notification laws, which may govern the collection, use, disclosure, and protection of health-related and other personal information. State laws may be more stringent, broader in scope, or offer greater individual rights with respect to PHI than HIPAA, and state laws may differ from each other, which may complicate compliance efforts.

Entities that are found to be in violation of HIPAA as the result of a failure to secure PHI, a complaint about our privacy practices, or an audit by HHS, may be subject to significant civil and criminal fines and penalties and additional reporting and oversight obligations if such entities are required to enter into a resolution agreement and corrective action plan with HHS to settle allegations of HIPAA non-compliance.

GDPR

The European Union's General Data Protection Regulation ("GDPR") imposes onerous accountability obligations requiring data controllers and processors to maintain a record of their data processing and policies. It requires data controllers to implement more stringent operational requirements for processors and controllers of personal data, including, for example, transparent and expanded disclosure to data subjects (in a concise, intelligible, and easily accessible form) about how their personal information is being used, imposes limitations on retention of information, increases requirements pertaining to health data and pseudonymized (i.e., key-coded) data, introduces mandatory data breach notification requirements, and sets higher standards for data controllers to demonstrate that they have obtained valid consent for certain data processing activities. Fines for non-compliance with the GDPR will be significant—the greater of €20 million or 4% of global turnover. The GDPR provides that European Union member states may introduce further conditions, including limitations, to make their own further laws and regulations limiting the processing of genetic, biometric, or health data.

ePrivacy Directive

The ePrivacy directive sets out the rules relating to the processing of personal data across public communications networks. This directive requires businesses to ensure consent requests are made and that consent is received from the user before the use of cookies is made. Businesses must communicate the privacy rules with accurate and specific information regarding the data contained in the cookie. Information must be communicated before the consent requests are made, in plain language. Organizations must ensure that users are able to withdraw consent in the same simple manner as the initial consent request.

CPRA and CCPA

The California Privacy Rights Act ("CPRA") and the California Consumer Privacy Act ("CCPA") define and establish various rights that consumers residing in California have over the privacy of their data along with the responsibilities of businesses when collecting personal information. It requires businesses that control the collection of consumers’ personal information to inform them of the category, purpose, and duration the business intends to retain such information. It lists the consumers’ right to correct their data and have their data deleted. Customers may also exercise their right to limit the sale or sharing of their personal or sensitive personal information. Fines for non-compliance can range from $100 to $750 per consumer per incident. Additionally, in certain cases, the California Privacy Protection Agency may impose administrative fines ranging from $2,500 to $7,500 for each violation.

BIPA

The Biometric Information Privacy Act ("BIPA"), which was enacted in 2008, addresses the collection, use, and retention of biometric information by private entities. Under the law, a private entity must inform an individual, or their legally authorized individual, that the biometric information is being collected and stored, and the specific purpose and the length of time for the collection, storage, and use of the biometric information, before obtaining or possessing their biometric information for the purposes of capturing, storing or sharing it. In addition, prior to collecting any biometric information, the regulation required businesses to obtain a written release for the collection of the biometric information from the individual, or the individual’s legally authorized representative after notice has been given. BIPA provides statutory damages of up to $1,000 for each negligent violation, and up to $5,000 for each intentional or reckless violation.

APPI

14

Table of Contents

The Act on the Protection of Personal Information (APPI) is Japan’s primary data protection law, first enacted in 2003 and significantly amended in 2016 and 2020 to align with global standards like the EU’s GDPR. It applies to businesses handling personal data, regardless of nationality or residency. The APPI defines personal data as any information that can identify an individual and classifies sensitive data to include details such as race, medical history, and criminal records. While consent is generally required for data collection, other legal bases exist, such as contractual necessity or compliance with legal obligations. Individuals are granted rights to access, correct, delete, and cease the use of their personal data. The Personal Information Protection Commission (PPC) enforces compliance, though penalties under the APPI are lower than those under GDPR, with a maximum fine of JPY 1 million.

UK GDPR

The United Kingdom General Data Protection Regulation (UK GDPR) applies to all organizations processing personal data of UK residents, regardless of where the organization is based. It defines personal data as any information that can identify an individual and includes special categories of sensitive data, such as health, race, and biometric data. Businesses must have a legal basis for processing data, such as consent, contractual necessity, or legal obligation. Individuals have rights over their data, including access, correction, deletion (right to be forgotten), and data portability. The Information Commissioner's Office (ICO) oversees compliance and can impose severe fines for breaches, reaching up to £17.5 million or 4% of global turnover. The UK also has additional rules for law enforcement and national security-related data processing.

EU AI Act

The EU AI Act establishes a unified regulatory framework for the deployment and use of AI across member states of the EU, including standardized rules for bringing AI systems to market. It adopts a risk-based approach, classifying AI systems by their potential impact and imposing corresponding obligations, including bans on harmful uses, strict requirements for high-risk systems, and transparency obligations for potentially misleading applications.

The EU AI Act is designed to be adaptable to future AI developments and places a strong emphasis on ethical considerations. It also distinguishes between single-purpose AI systems and general-purpose AI models, recognizing that the latter may pose broader systemic risks. As a result, general-purpose AI is subject to additional rules on market entry, governance, and oversight to ensure accountability and maintain public trust.

Nigeria Data Protection Act of 2023

The Nigeria Data Protection Act of 2023 has been enacted to safeguard the fundamental rights and freedoms, and the interests of data subjects, as guaranteed under the Constitution of the Federal Republic of Nigeria. Among other things, the objectives of this act include: the protection of personal information; establishment the Nigeria Data Protection Commission for the regulation of the processing of personal information; promotion of data processing practices that safeguard the security of personal data and privacy of data subjects; protection of data subjects' rights, and provision of means of recourse and remedies, in the event of the breach of the data subjects' rights; and strengthening the legal foundations of the national digital economy and guarantee the participation of Nigeria in the regional and global economies.

Intellectual Property

Patents

A summary of the Company’s issued patents and pending patent applications on March 31, 2026 is provided in the table below.

15

Table of Contents

16

Table of Contents

17

Table of Contents

18

Table of Contents

Trademarks

The following is a summary of Trust Stamp’s issued and pending Trademarks as of March 31, 2026.

Serial / Registration Number Filing Date Trademark Country Status

19

Table of Contents

20

Table of Contents

The Company added 3 patents during the year ended December 31, 2025 increasing our total patents issued to 26as of December 31, 2025. Patents issued during the year ended December 31, 2025 include:

•On May 27, 2025, the Company received Notice of Issuance for a patent that is a continuation of “Interoperable Biometric Representation.” This patent covers systems and methods for securely authenticating users by combining multiple authentication factors, including biometric and cryptographic techniques, to verify identity and enable secure access to digital services. The invention is designed to enhance the protection of sensitive authentication data while improving the reliability of identity verification.

•On July 8, 2025, the Company received Notice of Issuance for a patent that is a continuation of “Shape Overlay For Proof of Liveness.” This patent relates to systems and methods for generating and managing secure digital identity credentials using biometric and cryptographic techniques to authenticate individuals across digital platforms. The technology is designed to enable reliable identity verification while protecting sensitive personal data from unauthorized access or misuse.

•On December 30, 2025, the Company received Notice of Issuance for a patent entitled “Systems and Processes For Multifactor Authentication and Identification.” This patent relates to systems and methods for generating and managing privacy-preserving biometric identity tokens that enable individuals to be authenticated without exposing or storing the underlying biometric data. The technology is designed to support secure identity verification across digital systems while reducing the risk of misuse or compromise of sensitive personal information.

21

Table of Contents

Subsidiaries and Affiliates

Given the geographic diversity of our team and to facilitate cost-effective administration, Trust Stamp conducts various aspects of its operations through subsidiaries. All subsidiaries share resources across the entire Trust Stamp organization. The officers and directors of Trust Stamp have influence over the operations of all subsidiaries and employees across jurisdictions. Only one of our subsidiaries, Biometric Innovations Limited, has its own management team.

T Stamp Inc. Corporate Structure Chart as of March 30, 2026

Operational Subsidiaries

Biometric Innovations Limited. (formerly “Trust Stamp Fintech Limited”). Biometric Innovations Limited is our Company’s United Kingdom ("UK") operating subsidiary. It was established to act as the contracting entity for development contractors in the UK, and it has its own board and management team. The purpose of this entity was to establish beachhead operations in the country to service a contract entered by the Company with the National Association of Realtors and Property Mark. This entity serves as a sales and marketing function for the product “NAEA” which was developed for the contract between the listed parties. On June 11, 2020, the Company entered into a stock exchange transaction with Biometric Innovations Limited, becoming a 100% owner of the entity. The stock exchange transaction was not pursuant to any formal written agreement.

Trust Stamp Malta Limited. Trust Stamp Malta Limited is a wholly owned subsidiary of T Stamp Inc. It operates an R&D campus in the Republic of Malta, for which it has entered into a lease with a local commercial landlord in Malta, Vassallo Group Realty Ltd. The goal of Trust Stamp Malta Limited is to advance our biometric authentication technology. As part of the creation of this entity, we entered into an agreement with the government of Republic of Malta for a repayable advance of up to €800,000 to cover 75% of the first 24 months of payroll costs for any employee who begins 36 months from the execution of the agreement on July 8, 2020.

Trust Stamp Rwanda Limited. Trust Stamp Malta Limited established Trust Stamp Rwanda Limited and in April 2021 opened an office in Kigali, Rwanda. It operates as an R&D campus together with a back-office facility for the purpose of the Company's expansion into Africa.

Trust Stamp Denmark ApS. Trust Stamp established Trust Stamp Denmark ApS on June 6, 2021 as a wholly owned subsidiary in Copenhagen, Denmark. Trust Stamp Denmark ApS focuses on developing and marketing GDPR compliant products in the European Union from a strategic Danish base that can passport authorized products throughout the European Union. In furtherance of that goal, Trust Stamp Denmark ApS has obtained D-Seal Certification.

Quantum Foundation.Trust Stamp Malta Limited established Quantum Foundation on October 13, 2022 as a wholly-owned subsidiary in the Republic of Malta. The purpose of the entity is to support the development of early-stage leading edge technology companies in the Republic of Malta.

Lexverify Ltd. Trust Stamp completed the acquisition of 100% of the issued and outstanding share capital of Lexverify Ltd., a private limited company incorporated in England and Wales, on February 27, 2026. Lexverify participated in the UK

22

Table of Contents

National Cyber Security Center accelerator that is designed to identify and support technologies with significant potential to strengthen national and international cybersecurity resilience. Trust Stamp believes this acquisition provides new expertise in the training and use of large language models as well as providing an additional access point to the UK market for the Company.

Cyberfish CyberPsychology Solutions Ltd. Trust Stamp Malta limited acquired 50% of CyberFish CyberPsychology Solutions Ltd, a private company incorporated in England and Wales, on March 9, 2026. Along with Trust Stamp and Lexverify, Cyberfish participated in the UK National Cyber Security Center accelerator. Trust Stamp director, Berta Pappenheim, will continue to serve as CEO of Cyberfish.

Non-Operational Subsidiaries

Stable Key, LLC. Trust Stamp established Stable Key, LLC as a North Carolina entity as of May 15, 2025, as a wholly owned subsidiary in Durham, North Carolina. Stable Key focuses on blockchain technology and cryptocurrency wallets as well as decentralized identity technology that are compliant with GENIUS Act and US and North Carolina banking regulations. In furtherance of that goal, Trust Stamp applied to the North Carolina Innovation Council to sandbox decentralized KYC, but was provided authorization to build this type of technology without a sandbox requirement. As of the date of this report, this entity has no operations.

Trust Stamp Nigeria Limited. Trust Stamp Malta Limited established Trust Stamp Nigeria Limited on January 31, 2024 as a wholly-owned subsidiary in Lagos, Nigeria. The establishment of the entity is aimed at exploring business opportunities and conducting operations in Nigeria. As of the date of this report, this entity has no operations.

Tstamp Incentive Holdings. On April 9, 2019, management created a new entity, Tstamp Incentive Holdings (“TSIH”) to which the Company issued 21,368 shares of Class A Common Stock that the Board of Directors of TSIH could use for employee stock awards in the future. The purpose of the entity was to provide an analogous structure to a traditional stock incentive plan. As of December 31, 2025 and the date of this report, no shares of Class A Common Stock are held by TSIH as all shares have been issued pursuant to employee Restricted Stock Units. The Company has completed the process of administratively dissolving TSIH with the dissolution effective as of February 13, 2025.

Trusted Mail Inc. The Company established Trusted Mail Inc. for development of an encrypted e-mail product (Trusted Mail ®) using the Company’s facial recognition technology. Trusted Mail technology is held by Trusted Mail, Inc., which is a majority-owned subsidiary of Trust Stamp Inc.. The remainder of Trust Mail Inc. is owned by FSH Capital, LLC and Second Century Ventures, which are related parties of the Company. As of the date of this report, this entity has no operations, and is essentially dormant.

Cheltenham AI LTD. The Company established Chelthenham AI LTD on July 29, 2019 as a UK private limited company to provide AI services in the UK. As of the date of this report, this entity has no operations and is essentially dormant.

Finnovation LLC. The Company established Finnovation LLC to provide an innovative FinTech, Blockchain and Digital Identity innovation incubator. As of the date of this report, this entity has no operations and is essentially dormant.

TSI GovTech Corporation. Trust Stamp established TSI GovTech Corporation to contract for data management and server operations in Canada. As of the date of this report, this entity has no operations and is essentially dormant.

Global Server Management Inc. The Company established Global Server Management Inc. to contract for data management and server operations in Canada. As of the date of this report, this entity has no operations and is essentially dormant.

Available Information

Our website is www.truststamp.ai. As soon as reasonably practicable after such material is electronically filed or furnished to the Securities and Exchange Commission ("SEC"), our annual reports, quarterly reports, and current reports on form 8-K and all amendments to those reports are available on this website, free of charge.

Alternatively, you may access these reports at the SEC’s website at www.sec.gov.

23

Table of Contents

Item 1A. Risk Factors

The SEC requires the Company to identify risks that are specific to its business and its financial condition. The Company is still subject to all the same risks as companies in its business, and all companies in the economy. These include risks relating to economic downturns, political and economic events, and technological developments (such as cyber-attacks and the ability to prevent such attacks). Additionally, early-stage companies are inherently riskier than more developed companies, and the risk of business failure and complete loss of your investment capital is present. You should consider general risks as well as specific risks when deciding whether to invest.

Below is a summary of material risks, uncertainties and other factors that could have a material effect on the Company and its operations:

•We are a comparatively early-stage company that has incurred operating losses in the past, expect to incur operating losses in the future, and may never achieve or maintain profitability.

•Our technology continues to be developed, and there is no guarantee that we will ever successfully develop the technology that is essential to our business to a point at which no further development is needed.

•We may be subject to numerous data protection requirements and regulations.

•We operate in a highly competitive industry that is dominated by a number of exceptionally large, well-capitalized market leaders and the size and resources of some of our competitors may allow them to compete more effectively than we can.

•We rely on third parties to provide services essential to the success of our business.

•We currently have two customers that account for substantially all of our revenues.

•We expect to raise additional capital through equity and/or debt offerings to support our working capital requirements and operating losses.

•Our auditor has included an “Emphasis of Matter Regarding Liquidity” note in its report on our consolidated financial statements for the year ended December 31, 2025. Our consolidated financial statements do not include any adjustments that may result from the outcome of this uncertainty.

•As the vast majority of our revenue is US Dollar denominated and a significant percentage of our expenses are incurred in other currencies, we are subject to risks relating to foreign currency fluctuations.

Risks Related to Our Company

We have not yet generated profits. Our Company was incorporated under the laws of the State of Delaware on April 11, 2016, and we have not yet generated profits. The likelihood of our creation of a viable business must be considered in light of the problems, expenses, difficulties, complications, and delays frequently encountered in connection with the growth of a business, operation in a competitive industry, and the continued development of our technology and products. We anticipate that our operating expenses will increase for the near future, and there is no assurance that we will be profitable in the near future. You should consider our business, operations, and prospects in light of the risks, expenses and challenges faced as an emerging growth company.

We have historically operated at a loss, which has resulted in an accumulated deficit. For the fiscal year ended December 31, 2025, we incurred a net loss of $8.33 million, compared to a net loss of $12.54 million for the fiscal year ended December 31, 2024. There can be no assurance that we will ever achieve profitability. Even if we do, there can be no assurance that we will be able to maintain or increase profitability on a quarterly or annual basis. Failure to do so would continue to have a material adverse effect on our accumulated deficit, would affect our cash flows, would affect our efforts to raise capital and is likely to result in a decline in our Class A Common Stock price.

24

Table of Contents

Our consolidated financial statements for the fiscal year ended December 31, 2025 have been prepared on a going concern basis. We have not yet generated profits and have an accumulated deficit of $69.78 million as of December 31, 2025. We may not have enough funds to sustain the business until it becomes profitable. Even if we raise additional funding through future financing efforts, we may not accurately anticipate how quickly we may use such funds and whether such funds would be sufficient to bring the business to profitability. The Company’s ability to continue as a going concern in the next twelve months following the date of the consolidated financial statements is dependent upon its ability to produce revenues and/or obtain financing sufficient to meet current and future obligations and deploy such to produce profitable operating results.

Our cash could be adversely affected if the financial institutions in which we hold our cash fail. The Company maintains domestic cash deposits in Federal Deposit Insurance Corporation (“FDIC”) insured banks. The domestic bank deposit balances may exceed the FDIC insurance limits. In addition, given the foreign markets we serve, we maintain cash deposits in foreign banks, some of which are not insured or partially insured by the FDIC or other similar agency. These balances could be impacted if one or more of the financial institutions in which we deposit monies fails or is subject to other adverse conditions in the financial or credit markets.

Our technology continues to be developed, and it is unlikely that we will ever develop our technology to a point at which no further development is required. Trust Stamp is developing complex technology that requires significant technical and regulatory expertise to develop, commercialize and update to meet evolving market and regulatory requirements. While we constantly monitor and adapt our products and technology as criminal methods of breaching cybersecurity advance, there is no guarantee we will consistently be able to develop technology that can effectively counteract such criminal efforts. If we are unable to successfully develop and commercialize our technology and products, it will significantly affect our viability as a company.

If our security measures are breached or unauthorized access to individually identifiable biometric or other personally identifiable information is otherwise obtained, our reputation may be harmed, and we may incur significant liabilities. In the ordinary course of our business, we may collect and store sensitive data, including personally identifiable information (“PII”), that is owned or controlled by ourselves or our customers, and other parties. We communicate sensitive data electronically, and through relationships with multiple third-party vendors and their subcontractors. These applications and data encompass a wide variety of business-critical information, including research and development information, commercial information, and business and financial information. We face a number of risks relative to protecting this critical information, including loss of access risk, inappropriate use or disclosure, inappropriate modification, and the risk of our being unable to adequately monitor, audit, and modify our controls over our critical information. This risk extends to the third-party vendors and subcontractors we use to manage this sensitive data. As a custodian of this data, Trust Stamp therefore inherits responsibilities related to this data, exposing itself to potential threats. Data breaches occur at all levels of corporate sophistication (including at companies with significantly greater resources and security measures than our own) and the resulting fallout stemming from these breaches can be costly, time-consuming, and damaging to a company’s reputation. Further, data breaches need not occur from malicious attack or phishing only. Often, employee carelessness can result in sharing PII with a much wider audience than intended. Consequences of such data breaches could result in fines, litigation expenses, costs of implementing better systems, and the damage of negative publicity, all of which could have a material adverse effect on our business operations and financial condition.

We are subject to substantial governmental regulations relating to our technology and will continue to be for the lifetime of our Company. By virtue of handling sensitive PII and biometric data, we are subject to numerous statutes related to data privacy and additional legislation and regulation should be anticipated in every jurisdiction in which we operate. Examples of federal (US) and European statutes we could be subject to are:

•Health Insurance Portability and Accountability Act (HIPAA)

•Health Information Technology for Economic and Clinical Health Act (HITECH)

•General Data Protection Regulation (GDPR)

•Artificial Intelligence Act (AI Act)

•UK General Data Protection Regulation (UK GDPR)

Any such access, breach, or other loss of information could result in legal claims or proceedings, liability under federal or state laws that protect the privacy of personal information under HIPAA and/or “HITECH”. Notice of breaches must be made to affected individuals, the Secretary of the Department of Health and Human Services (“HHS”), and for extensive

25

Table of Contents

breaches, notice may need to be made to the media or state attorneys general. Penalties for violations of these laws vary. For instance, penalties for failure to comply with a requirement of HIPAA and HITECH vary significantly, and include significant civil monetary penalties and, in certain circumstances, criminal penalties with fines up to $250,000 per violation and/or imprisonment. A person who knowingly obtains or discloses individually identifiable health information in violation of HIPAA may face a criminal penalty of up to $50,000 and up to one-year imprisonment. The criminal penalties increase if the wrongful conduct involves false pretenses or the intent to sell, transfer or use identifiable health information for commercial advantage, personal gain, or malicious harm.

Further, various states, such as California, have implemented similar privacy laws and regulations, such as the California Confidentiality of Medical Information Act, that impose restrictive requirements regulating the use and disclosure of health information and other personally identifiable information. Where state laws are more protective, we have to comply with the stricter provisions. In addition to fines and penalties imposed upon violators, some of these state laws also afford private rights of action to individuals who believe their personal information has been misused. California’s patient privacy laws, for example, provide for penalties of up to $250,000 and permit injured parties to sue for damages. The interplay of federal and state laws may be subject to varying interpretations by courts and government agencies, creating complex compliance issues for us and data we receive, use and share, potentially exposing us to additional expense, adverse publicity, and liability. Further, as regulatory focus on privacy issues continues to increase and laws and regulations concerning the protection of personal information expand and become more complex, these potential risks to our business could intensify. Changes in laws or regulations associated with the enhanced protection of certain types of sensitive data, such as PII, along with increased customer demands for enhanced data security infrastructure, could greatly increase our cost of providing our services, decrease demand for our services, reduce our revenues and/or subject us to additional liabilities.

Compliance with U.S. and international data protection laws and regulations could cause us to incur substantial costs or require us to change our business practices and compliance procedures in a manner adverse to our business. Moreover, complying with these various laws could require us to take on more onerous obligations in our contracts, restrict our ability to collect, use and disclose data, or in some cases, impact our ability to operate in certain jurisdictions. We rely on our customers to obtain valid and appropriate consents from data subjects whose biometric samples and data we process on such customers’ behalf. Given that we do not obtain direct consent from such data subjects and we do not audit our customers to ensure that they have obtained the necessary consents required by law, the failure of our customers to obtain consents that are in compliance with applicable law could result in our own non-compliance with privacy laws. Such failure to comply with U.S. and international data protection laws and regulations could result in government enforcement actions (which could include civil or criminal penalties), private litigation and/or adverse publicity and could negatively affect our operating results and business. Claims that we have violated individuals’ privacy rights, failed to comply with data protection laws, or breached our contractual obligations, even if we are not found liable, could be expensive and time consuming to defend, could result in adverse publicity and could have a material adverse effect on our business, financial condition and results of operations.

We anticipate sustaining operating losses for the foreseeable future. It is anticipated that we will sustain operating losses into 2026 as we continue with research and development, and strive to gain new customers for our technology and market share in our industry. Our ability to become profitable depends on our ability to expand our customer base, consisting of companies willing to license our technology. There can be no assurance that this will occur. Unanticipated problems and expenses are often encountered in offering new products which may impact whether the Company is successful. Furthermore, we may encounter substantial delays and unexpected expenses related to development, technological changes, marketing, regulatory requirements, and changes to such requirements or other unforeseen difficulties. There can be no assurance that we will ever become profitable. If the Company sustains losses over an extended period of time, it may be unable to continue in business.

If our products do not achieve broad acceptance both domestically and internationally, we will not be able to achieve our anticipated level of growth. Our revenues are derived from licensing our identity authentication solutions. We cannot accurately predict the future growth rate or the size of the market for our technology. The expansion of the market for our solutions depends on a number of factors, such as

•the cost, performance and reliability of our solutions and the products and services offered by our competitors;

•customers’ perceptions regarding the benefits of biometrics and other authentication solutions;

•public perceptions regarding the intrusiveness of these solutions and the manner in which organizations use biometric and other identity information collected;

26

Table of Contents

•public perceptions regarding the confidentiality of private information;

•proposed or enacted legislation related to privacy of information;

•customers’ satisfaction with biometrics solutions; and

•marketing efforts and publicity regarding biometrics solutions.

Even if our technology gains wide market acceptance, our solutions may not adequately address market requirements and may not continue to gain market acceptance. If authentication solutions generally or our solutions specifically do not gain wide market acceptance, we may not be able to achieve our anticipated level of growth and our revenues and results of operations would suffer.

We operate in a highly competitive industry that is dominated by multiple very large, well-capitalized market leaders and is constantly evolving. New entrants to the market, existing competitor actions, or other changes in market dynamics could adversely impact us. The level of competition in the identity authentication industry is high, with multiple exceptionally large, well-capitalized competitors holding a majority share of the market. Currently, we are not aware of any direct competitors of the Company able to offer our main technological offerings. Nonetheless, many of the companies in the identity authentication market have longer operating histories, larger customer bases, significantly greater financial, technological, sales, marketing, and other resources than we do. At any point, these companies may decide to devote their resources to creating a competing technology solution which will impact our ability to maintain or gain market share in this industry. Further, such companies will be able to respond more quickly than we can to new or changing opportunities, technologies, standards, or client requirements, more quickly develop new products or devote greater resources to the promotion and sale of their products and services than we can. Likewise, their greater capabilities in these areas may enable them to better withstand periodic downturns in the identity management solutions industry and compete more effectively on the basis of price and production. In addition, new companies may enter the markets in which we compete, further increasing competition in the identity management solutions industry.

We believe that our ability to compete successfully depends on a number of factors, including the type and quality of our products and the strength of our brand names, as well as many factors beyond our control. We may not be able to compete successfully against current or future competitors, and increased competition may result in price reductions, reduced profit margins, loss of market share and an inability to generate cash flows that are sufficient to maintain or expand the development and marketing of new products, any of which would adversely impact our results of operations and financial condition.

We face competition from companies with greater financial, technical, sales, marketing, and other resources, and, if we are unable to compete effectively with these competitors, our market share may decline, and our business could be harmed. We face competition from well established companies. Many of our competitors have longer operating histories, larger customer bases, significantly greater financial, technological, sales, marketing, and other resources than we do. As a result, our competitors may be able to respond more quickly than we can to new or changing opportunities, technologies, standards, or client requirements, more quickly develop new products or devote greater resources to the promotion and sale of their products and services than we can. Likewise, their greater capabilities in these areas may enable them to better withstand periodic downturns in the identity management solutions industry and compete more effectively on the basis of price and production. In addition, new companies may enter the markets in which we compete, further increasing competition in the identity management solutions industry.

We believe that our ability to compete successfully depends on a number of factors, including the type and quality of our products and the strength of our brand names, as well as many factors beyond our control. We may not be able to compete successfully against current or future competitors, and increased competition may result in price reductions, reduced profit margins, loss of market share and an inability to generate cash flows that are sufficient to maintain or expand the development and marketing of new products, any of which would adversely impact our results of operations and financial condition.

The Company may be unable to effectively protect its intellectual property. The Company has many issued patents related to its products and technology, and many pending patent applications as of the date of this report. There is no guarantee that the Company will ever be issued patents on the applications it has submitted. In addition, in order to control costs, we have filed patent applications only in the United States. This may result in our having limited or no protection in other jurisdictions. Our success depends to a significant degree upon the protection of our products and technology. If we are unable to secure patents for our products and technology, or are otherwise unsuccessful at protecting our technology, other

27

Table of Contents

companies with greater resources may copy our technology and/or products, or improve upon them, putting us at a disadvantage to our competitors.

Successful infringement claims against us could result in significant monetary liability or prevent us from selling some of our products. We believe our products and technology may be highly disruptive to a very large and growing market. Our competitors are well capitalized with significant intellectual property protection and resources and they (and/or patent trolls) may initiate infringement lawsuits against our Company. Such litigation could be expensive and could also prevent us from selling our products, which would significantly harm our ability to grow our business as planned.

Our failure to attract and retain highly qualified personnel in the future could harm our business. As the Company grows, it will be required to attract and retain additional qualified professionals, staff for research and development, regulatory professionals, sales and marketing professionals, accounting professionals, legal professionals, and finance experts. The Company may not be able to attract and retain qualified individuals for such positions, which will affect the Company’s ability to grow and expand its business.

We rely on third party service providers. Our third-party partners provide a variety of essential business functions, including hosting, contract labor, and others. It is possible that some of these third parties will fail to perform their services or will perform them in an unacceptable manner. If we encounter problems with one or more of these parties and they fail to perform to expectations, it could have a material adverse impact on the Company.

We currently have two customers that account for substantially all of our current revenues. During the Company’s technology stack development, we have focused on strong relationships with a number of significant partners and customers to guide the customer and product discovery process. As such, our historical financial results identify that for a number of years we generated substantially all of our revenue from those two customers.

In the opinion of our management, we would be able to continue operations without our current customers. However, the unanticipated loss of the Company’s current customers could have an adverse effect on the company’s financial position.

We face risks related to distributing our products and services through channel partnerships, such as our partnership with FIS. When selling our products and services through indirect sales channels, such as through FIS, we are reliant on the efforts of those channel partners to successfully market and sell our products to end-customers. To the extent that FIS is unsuccessful at selling our products and services, our results of operations may suffer. Further, as of the date of this report, our only channel partnership is with FIS, which may increase the risk of harm to our Company if FIS is unsuccessful in selling our products and services. While we may seek to attract and retain additional indirect channel partners that will be able to market our products effectively and provide timely and cost-effective customer support and services, we may not succeed in doing so, and this could limit our ability to grow revenues and achieve profitability. Selling through channel partnerships is also a relatively new endeavor for us. Historically, we have generated a majority of sales through direct sales. Managing indirect sales channels may require more management attention than managing our direct sales force. If the indirect sales channels grow, management attention may be diverted, impairing our ability to execute other parts of our strategy.

We face risks related to our target customers. The majority of the customers that we are targeting are large organizations with complex and expansive operations. These kinds of companies often have long and often unpredictable enterprise sales cycles, which can result in significant time and effort to close a deal with those companies (and there is no guarantee that a deal will occur). This can make sales forecasting difficult for our Company, which can lead to operational challenges. For example, we often need to hire staff ahead of closing on a new client contract to be ready to perform if and when the contract closes. If we are unable to effectively forecast sales, we may incur unnecessary or avoidable expenses, or exhaust our cash reserves, which could have a material negative impact on our Company’s financial condition and results of operations.

Our future success is dependent on the continued service of our small management team. As of March 30, 2026, seven directors and four executive officers provide leadership to Trust Stamp. Two of the directors are also executive officers. Our success is dependent on their ability to manage all aspects of our business effectively. Because we are relying on our small management team, we lack certain business development resources that may hurt our ability to grow our business. Any loss of key members of our executive team could have a negative impact on our ability to manage and grow our business effectively. We do not maintain a key person life insurance policy on any of the members of our senior management team. As a result, we would have no way to cover the financial loss if we were to lose the services of our directors or officers.

28

Table of Contents

We expect to raise additional capital through equity and/or debt offerings to support our working capital requirements and operating losses. In order to fund future growth and development, the Company will likely need to raise additional funds in the future by offering shares of its Common or Preferred Stock and/or other classes of equity, or debt that convert into shares of Common or Preferred Stock, any of which offerings would dilute the ownership percentage of investors in this offering. In order to issue sufficient shares in this regard, we may be required to amend our certificate of incorporation to increase our authorized capital stock, which would require us to obtain consent of a majority of our shareholders. Furthermore, if the Company raises capital through debt, the holders of our debt would have priority over holders of Common and Preferred Stock and the Company may be required to accept terms that restrict its ability to incur more debt. We cannot assure you that the necessary funds will be available on a timely basis, on favorable terms, or at all, or that such funds if raised, would be sufficient. The level and timing of future expenditure will depend on a number of factors, many of which are outside our control. If we are not able to obtain additional capital on acceptable terms, or at all, we may be forced to curtail or abandon our growth plans, which could adversely impact the Company, its business, development, financial condition, operating results, or prospects.

We are subject to risks related to foreign currency exchange rates. We operate on a global basis. We have operations (through our subsidiaries and/or directly) in many foreign countries and territories, including, but not limited to, United Kingdom, Poland, Rwanda, Denmark, and Malta. The translation from any currencies to United States Dollars for financial statement presentation resulted in a foreign currency loss of $2 thousand for the year ended December 31, 2025, and $5 thousand loss for the year ended December 31, 2024. Fluctuations in foreign currencies between the Company and its subsidiaries are recorded to Accumulated other comprehensive income on the balance sheet instead of Other expense as there is currently no intention to settle intercompany accounts in the foreseeable future. The translation from any currencies to United States Dollars for financial statement presentation resulted in Accumulated other comprehensive income of $11 thousand as of December 31, 2025, and $181 thousand as of December 31, 2024. Foreign currency translation losses, coupled with varying inflation rates across the countries we operate in, could have a material adverse effect on our business.

We are an emerging growth company, and the reduced reporting requirements applicable to emerging growth companies could make our Class A Common Stock less attractive to investors. We are an emerging growth company, as defined in the Jumpstart Our Business Startups Act (the "JOBS Act"). For as long as we continue to be an emerging growth company, we may take advantage of exemptions from various reporting requirements that are applicable to other public companies that are not emerging growth companies, including not being required to comply with the auditor attestation requirements of Section 404 of the Sarbanes-Oxley Act of 2002, reduced disclosure obligations regarding executive compensation in our periodic reports and proxy statements, exemptions from the requirements of holding non-binding advisory votes on executive compensation and stockholder approval of any golden parachute payments not previously approved, and an exemption from compliance with the requirement of the PCAOB regarding the communication of critical audit matters in the auditor’s report on the consolidated financial statements. We could be an emerging growth company for up to five years following the year in which we completed our IPO, although circumstances could cause us to lose that status earlier. We will remain an emerging growth company until the earlier of (1) the last day of the fiscal year (a) following the fifth anniversary of the date of the closing of our IPO, (b) in which we have total annual gross revenue of at least $1.07 billion or (c) in which we are deemed to be a large accelerated filer, which requires the market value of our common stock that are held by non-affiliates to exceed $700.00 million as of the prior June 30th, and (2) the date on which we have issued more than $1.00 billion in non-convertible debt during the prior three-year period.

In addition, the JOBS Act provides that an emerging growth company can take advantage of an extended transition period for complying with new or revised accounting standards. This allows an emerging growth company to delay the adoption of certain accounting standards until those standards would otherwise apply to private companies. We have elected to use this extended transition period for complying with new or revised accounting standards that have different effective dates for public and private companies until the earlier of the date we (i) are no longer an emerging growth company or (ii) affirmatively and irrevocably opt out of the extended transition period provided in the JOBS Act. As a result, our consolidated financial statements may not be comparable to companies that comply with new or revised accounting pronouncements as of public company effective dates.

We cannot predict if investors will find our Class A Common Stock less attractive because we may rely on the reporting exemptions and the extended transition period for complying with new or revised accounting standards. If some investors find our Class A Common Stock less attractive as a result, there may be a less active trading market for our Class A Common Stock and our share price may be more volatile.

29

Table of Contents

Our internal controls over financial reporting and our disclosure controls and procedures may not prevent all possible errors that could occur. Our management is responsible for establishing and maintaining adequate internal control over financial reporting to provide reasonable assurance regarding the reliability of our financial reporting and the preparation of consolidated financial statements for external purposes in accordance with accounting principles generally accepted in the United States of America (“U.S. GAAP”). Ensuring that we have adequate internal financial and accounting controls and procedures in place to produce accurate consolidated financial statements on a timely basis is a costly and time-consuming effort that needs to be re-evaluated frequently. Failure on our part to have effective internal financial and accounting controls would cause our financial reporting to be unreliable, could have a material adverse effect on our business, operating results, and financial condition, and could cause the trading price of our common stock to fall dramatically.

A control system, no matter how well designed and operated, can provide only reasonable, not absolute, assurance that the control system’s objectives will be satisfied. Internal control over financial reporting and disclosure controls and procedures are designed to give a reasonable assurance that they are effective to achieve their objectives. We cannot provide absolute assurance that all of our possible future control issues will be detected. These inherent limitations include the possibility that judgments in our decision making can be faulty, and that isolated breakdowns can occur because of simple human error or mistake. The design of our system of controls is based in part upon assumptions about the likelihood of future events, and there can be no assurance that any design will succeed absolutely in achieving our stated goals under all potential future or unforeseeable conditions. Because of the inherent limitations in a cost-effective control system, misstatements due to error could occur and not be detected. This and any future failures could cause investors to lose confidence in our reported financial information, which could have a negative impact on our financial condition and stock price.

In future periods, if the process required by Section 404 of the Sarbanes-Oxley Act reveals any material weaknesses or significant deficiencies, the correction of any such material weaknesses or significant deficiencies could require remedial measures which could be costly and time-consuming. In addition, in such a case, we may be unable to produce accurate financial statements on a timely basis. Any associated accounting restatement could create a significant strain on our internal resources and cause delays in our release of quarterly or annual financial results and the filing of related reports, increase our costs and cause management distraction. Any of the foregoing could cause investors to lose confidence in the reliability of our financial statements, which could cause the market price of our common stock to decline and make it more difficult for us to finance our operations and growth.

Item 1B. Unresolved Staff Comments

None.

Item 1C. Cybersecurity

Risk Management and Strategy

We review cybersecurity risk as part of our overall System and Organization Controls ("SOC 2") with a goal of ensuring that cybersecurity risk management remains a top priority in our business strategy and operations.

Our risk management strategy includes, among other elements:

•Identification: We aim to proactively identify sources of risk, areas of impact, and relevant events that could give rise to cybersecurity risks, such as changes to our infrastructure, service providers, or personnel.

•Assessment: We conduct risk assessments to identify cybersecurity threats. We also conduct likelihood and impact assessments with the goal of identifying reasonably foreseeable internal and external risks, the likelihood and potential damage that could result from such risks, and the sufficiency of existing policies, procedures, systems, and safeguards in place to manage such risks.

•Management: Following our risk assessments, we design and implement reasonable safeguards to address any identified gaps in our existing processes and procedures.

We engage third parties, including consultants and auditors, to evaluate the effectiveness of our risk management program, control environment, and cybersecurity practices through security audits, penetration testing, and other engagements.

30

Table of Contents

The Company's cybersecurity policies and procedures are fully integrated into its broader risk management framework, reflecting a holistic approach to cybersecurity risk management. Cybersecurity risk assessments are conducted to identify potential threats and vulnerabilities, with detailed mitigation strategies developed and implemented accordingly.

Trust Stamp has adopted an Information Security Incident Response Plan that establishes policy and protocol to follow in response to an information security incident or event impacting Trust Stamp. This policy applies to all Trust Stamp employees holding management responsibilities. Incidents are reported by users via various methods including verbally, email, or other methods. The Development Operations team via the Chief Technology Officer or Executive Vice President is the main point of contact for technical support issues. It is to be expected that potential security incidents will be raised through this channel.

The Company engages third-party cybersecurity assessments to ensure an objective evaluation of its cybersecurity stance, including the effectiveness of its risk management strategies.Oversight of cybersecurity risks posed by third-party service providers is systematically managed, ensuring that all external risks are identified and mitigated.

The Company did not have any material cybersecurity breaches during the year ended December 31, 2025.

Board of Director's Governance

The Board of Directors (the "Board") includes members with substantial cybersecurity expertise, ensuring informed oversight of cybersecurity risks.Documentation of the Board's involvement in cybersecurity oversight is maintained, highlighting the frequency and topics of discussions related to cybersecurity risks and incident response. The Board is updated on cybersecurity risks and incidents through established reporting mechanisms, ensuring they are well-informed to make strategic decisions regarding the Company's cybersecurity posture.

Management's Governance

Management's roles and responsibilities in cybersecurity oversight are clearly defined, with specific committees or positions designated for managing cybersecurity risks. The day-to-day management of cybersecurity is the responsibility of the Chief Technology Officer who oversees our technology team. These include procedures for incident response and regular reporting of cybersecurity information to the Board of Directors (the "Board"), ensuring effective communication and oversight. Cybersecurity risk management is seamlessly integrated into the Company's overall business strategy and decision-making processes, demonstrating a proactive approach to managing cybersecurity risks.

The Company has established clear criteria for determining the materiality of cybersecurity incidents, which include assessing potential or actual financial impacts, reputational damage, and operational disruptions. Documented incidents are meticulously recorded, detailing their nature, scope, and financial implications, ensuring transparency and accountability. The timeliness of Form 8-K filings following material cybersecurity incidents is strictly adhered to, with a thorough process in place for documenting any reasons for delayed disclosures. This ensures compliance with SEC requirements and maintains stakeholder confidence in the Company's cybersecurity posture.

Item 2. Properties

The Company contracts for use of office space at 3017 Bolling Way NE, Floor 2, Atlanta, Georgia, 30305, United States of America, which serves as its corporate headquarters and primary operational hub. The Company also leases office space (through a subsidiary) in Malta, which primarily serves as a research and development space. The Company contracts for coworking arrangements in other office spaces (either directly or through its subsidiaries) in Denmark, Rwanda, and Japan to support its dispersed workforce. Minimum lease commitments related to these agreements are described in Note 13 to the consolidated financial statements provided under Item 8 of this report. We believe our existing properties are in good condition and are sufficient and suitable for the conduct of our business.

Item 3. Legal Proceedings

From time to time, the Company may be involved in a variety of legal matters that arise in the normal course of business. The Company is not currently involved in any litigation, and its management is not aware of any pending or threatened legal actions relating to its intellectual property, conduct of its business activities, or otherwise. See “Risk Factors” for a summary of risks our Company may face in relation to litigation against our Company.

31

Table of Contents

Item 4. Mine Safety Disclosures

Not applicable.

32

Table of Contents

PART II

Item 5. Market for Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities

Common Stock

As of December 31, 2025 and 2024, our Class A Common Stock is traded on the Nasdaq Capital Market ("Nasdaq") under the symbol “IDAI”. Trust Stamp received approval from Nasdaq to have our Class A Common Stock listed on the Nasdaq Capital Market under the symbol “IDAI” with trading commencing on January 31, 2022.

Holders

As of March 30, 2026, there were approximately 2,713 registered holders of record of our Class A Common Stock and the last reported sale price of our Class A Common Stock on the Nasdaq was$2.32 per share on March 30, 2026.

The number of shares of our Class A Common Stock that are freely tradable as of March 30, 2026 was 5,005,243.

Performance Graph

We are a smaller reporting company, as defined by Rule 12b-2 of the Exchange Act and are not required to provide the information required under this item.

Dividend Policy

To date, we have not paid any dividends on our Class A Common Stock and do not anticipate paying any dividends in the foreseeable future. The declaration and payment of dividends on the Class A Common Stock is at the discretion of the Board and will depend on, among other things, our operating results, financial condition, capital requirements, contractual restrictions, or such other factors as the Board may deem relevant. We currently expect to use all available funds to finance the future development and expansion of our business.

Securities Authorized for Issuance Under Equity Compensation Plans

On April 9, 2019, management created a new entity, Tstamp Incentive Holdings (“TSIH”) to which the Company issued 21,368 shares of Class A Common Stock that the Board of Directors of TSIH could use for employee stock awards in the future. The purpose of the entity was to provide an analogous structure to a traditional stock incentive plan. As of December 31, 2025 and the date of this report, no shares of Class A Common Stock are held by TSIH as all shares have been issued pursuant to employee Restricted Stock Units. The Company has completed the process of administratively dissolving TSIH with the dissolution was effective February 13, 2025.

Executive Compensation Philosophy

The Board of Directors determines the compensation given to our executive officers in their sole discretion. The Board reserves the right to pay our executives or any future executives a salary, and/or issue them shares of Class A Common Stock issued in consideration for services rendered and/or to award incentive bonuses which are linked to our performance, as well as to the individual executive officer’s performance. This package may also include long-term stock-based compensation to certain executives, which is intended to align the performance of our executives with our long-term business strategies. Additionally, the Board of Directors has granted and reserves the right to grant performance-based equity awards in the future, if the Board of Directors in its sole determination believes such grants would be in our best interests.

Incentive Bonus

The Board of Directors may grant incentive bonuses to our executive officers and/or future executive officers in its sole discretion, if the Board believes such bonuses are in our best interest, after analyzing our current business objectives and growth, if any, and the amount of revenue we are able to generate each month, as revenue is a direct result of the actions and ability of such executives.

33

Table of Contents

Long-Term, Stock Based Compensation

In order to attract, retain and motivate executive talent necessary to support the Company's long-term business strategy we may award our executives and any future executives with long-term, stock-based compensation in the future, at the sole discretion of the Board.

Recent Sales of Unregistered Securities:

34

Table of Contents

*The share numbers in the table above reflect the shares issued after giving effect to both Reverse Splits, described in Note 1 to the consolidated financial statements provided under Item 8 of this report.

(1) On December 21, 2023, the 104,889 common stock purchase warrants to purchase shares of Class A Common Stock of the Company at a price of $20.10 per warrant were exercised for total proceeds of $2,108,262.

(2) On December 21, 2023, the 85,314 common stock purchase warrants to purchase shares of Class A Common Stock of the Company at a price of $20.10 per warrant were exercised for total proceeds of $1,714,798.

(3) On September 3, 2024, the 240,000 common stock purchase warrants to purchase shares of Class A Common Stock of the Company at a price of $4.8345 per warrant were exercised for total proceeds of $1,160,280.

(4) On October 31, 2025, 95,494 common stock purchase warrants to purchase shares of Class A Common Stock of the Company at a price of $4.8195 per warrant were repriced to $4.20and exercised for total proceeds of $401,075. The warrants to purchase the remaining 95,493 shares of the Company’s Class A Common Stock for $4.8195per warrant remain outstanding as of the date of this report.

(5) On October 31, 2025, the warrants to purchase the 370,370and 277,778shares of Class A Common Stock (for a total of 648,148 shares) were exchanged for new warrants.

(6) On October 31, 2025, 414,202 and 207,101 common stock purchase warrants to purchase shares of Class A Common Stock of the Company at a price of $8.45 per warrant were repriced to $4.20and exercised for total proceeds of $1,739,648and$869,824, respectively.

(7) The warrants to purchase the 1,301,945 and 1,209,099 shares of Class A Common Stock remain outstanding as of the date of this report.

(8) The aggregate purchase price for the acquisition of Lexverify Ltd. is payable entirely in shares of the Company’s Class A Common Stock, par value $0.01 per share, with the number of shares. The purchase price was structured in four tranches, consisting of: (i) an initial tranche equal to twenty-five percent (25%) of the purchase price (the “Completion Consideration”) to be issued on or within one business day following the Closing Date, and (ii) the remaining seventy-five percent (75%) of the purchase price (the “Deferred Consideration”) to be issued in three equal tranches on the dates that are 90, 180, and 270 days after the Closing Date, respectively, subject to the terms of the Securities Purchase Agreement governing this transaction. On the Closing Date, the Company issued 157,508 shares of Common Stock to the stockholders of Lexverify in satisfaction of the Completion Consideration. On the Closing Date, the Company issued 39,377 shares of Common Stock to the the stockholders of Lexverify in satisfaction of the Completion Consideration. As of March 30, 2026, the shares of Common Stock to satisfy the Deferred Consideration remain to be issued by the Company to the stockholders of Lexverify.

35

Table of Contents

Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations

The following discussion and analysis of our financial condition and results of operations should be read in conjunction with our consolidated financial statements and the accompanying notes thereto included elsewhere in this Annual Report on Form 10-K. This discussion contains forward-looking statements based upon current plans, expectations, and beliefs, involving risks and uncertainties. Our actual results may differ materially from those anticipated in these forward-looking statements. You should review the section titled “Statement Regarding Forward-Looking Statements” for a discussion of forward-looking statements and the section titled “Risk Factors” for a discussion of factors that could cause actual results to differ materially from the results described in or implied by the forward-looking statements contained in the following discussion and analysis and elsewhere in this Annual Report on Form 10-K. Our historical results are not necessarily indicative of the results that may be expected for any period in the future.

Overview

Trust Stamp was incorporated under the laws of the State of Delaware on April 11, 2016 as “T Stamp Inc.” T Stamp Inc. and its subsidiaries (“Trust Stamp”, “we”, or the “Company”) develop and market identity authentication software for enterprise and government partners and peer-to-peer markets.

Trust Stamp primarily develops proprietary artificial intelligence-powered solutions, researching and leveraging machine learning artificial intelligence, including computer vision, cryptography, and data mining, to process and protect data and deliver insightful outputs that identify and defend against fraud, protect sensitive user information, facilitate automated processes, and extend the reach of digital services through global accessibility. We utilize the power and agility of technologies such as GPU processing, edge computing, neural networks, and large language models to process and protect data faster and more effectively than historically possible to deliver results at a disruptively low cost for usage across multiple industries.

Our team has substantial expertise in the creation and development of AI-enabled software products. We license our technology and expertise in numerous fields, with an increasing emphasis on addressing diverse markets through established partners who will integrate our technology into field-specific applications.

Over the last 12 months, while maintaining our strong emphasis on identity authentication for financial services, the Company has undertaken a multi-pronged process to position itself better to leverage the growing opportunities offered by the expanded capabilities, use, and acceptance of AI technologies. This process has included:

•Reducing the size of the non-production-focused executive and consulting teams to reduce overhead.

•Releasing sales staff that did not meet their targets.

•Negotiating a services contract to offset the cost of the technical team members while maintaining significant R&D and product development capabilities.

•Refocusing go-to-market strategies on joint ventures with proven industry partners with access to target markets

•Expanding our IP portfolio to strengthen our existing position related to presentation attack detection and tokenization and include implementations such as:

i.Embedded ownership verification for cryptographic assets, a technology that we believe to have significant potential with the expansion in the ownership of crypto-assets including potential deregulation (or loosening or clarification of regulation) in the United States together with the global growth of stable coins including Central Government Digital Currencies.

ii.A simple user interaction utility called “Shape Overlay” that augments biometric verification and combats deepfakes and injection attacks by having the user interact in real-time with their captured image.

iii.Stable Key (or “Stable IT2”) which is an innovative technology that generates a “key” directly from the biometric of the user which key has a mathematical correlation to all of the user's passwords, PINS, and other “secrets” for every account and use case meaning that those secrets never need to be stored in their entirety.

iv.A patent for “Interoperable Biometric Representations” that potentially breaks vendor lock-in by allowing users of biometric technologies to compare like-modality templates from different sources.

36

Table of Contents

•Strengthening our international 3rd party cybersecurity and data handling certifications by adding Cyber Essentials, certified by The IASME Consortium Ltd, to our SOC2 certification to our NCSC Cyberessentials Plus certification and obtaining a renewed D-Seal certification (the world’s first certification that includes not just data security but also the ethical and responsible use of data).

•Opening an office in Tokyo (with funding from the City of Tokyo and the Japanese government) to pursue opportunities in the APAC region.

•Retaining an investment bank to explore strategic partnership and M&A opportunities across multiple sectors, two of which were consummated in February and March 2026 when our Company acquired Lexverify and Cyberfish.

Recent Developments

Resignation of Board Director and Appointment of New Board Director

On March 6, 2026, the Board of Directors accepted the resignation of Andrew Scott Francis as a Director of the Company to allow him to have a greater focus on serving as the newly appointed CEO of the Company’s African operations. This was documented as part of a unanimous written consent by the Board of Directors, including Mr. Francis. Mr. Francis will continue to serve in his position as Chief Technology Officer of the Company, as well as continue to attend meetings of the Board of Directors in a non-voting, ex officio advisor capacity.

Concurrently, on March 6, 2026, the Board of Directors of the Company, after receiving a recommendation from the Nomination and Corporate Governance Committee, elected David Curmi to the Company’s Board of Directors as a “Class III” member. Mr. Curmi will also serve as a member of the Compensation Committee of the Board of Directors.

The Company offered a Letter of Appointment to Mr. Curmi that was executed on March 21, 2026. The foregoing description of the Letter of Appointment is intended to be a summary, and is qualified by reference to the full text of the Letter of Appointment filed as an exhibit to this Annual Report on Form 10-K.

CyberFish CyberPsychology Solutions Ltd Share Purchase Agreement, Shareholders Agreement, and Consulting Agreement

On March 9, 2026, Trust Stamp Malta Limited, a wholly-owned subsidiary of the Company, entered into a Share Purchase Agreement (the “SPA”) with CyberFish CyberPsychology Solutions Ltd, a private company incorporated in England and Wales (“CyberFish”). Pursuant to the SPA, Trust Stamp Malta Limited agreed to subscribe to fifty percent (50%) of the authorized share capital of CyberFish in exchange for £190,000 (the “Total Consideration”), consisting of (i) a cash payment of €30,000 payable to Malta Enterprise on behalf of CyberFish and (ii) a cash payment of £30,000 payable to CyberFish (together, the “Cash Consideration”) and (iii) non-cash consideration with an agreed value equal to the remaining balance of the Total Consideration following deduction of the Cash Consideration, comprising the provision of software development, engineering, and related technical services by Trust Stamp Malta Limited and/or other Company group entities. Malta Enterprise is a Maltese national development agency that previously provided CyberFish a start-up loan, which is partly being repaid as part of this transaction.

On March 9, 2026, the SPA closed, and Trust Stamp Malta Limited acquired 50% of CyberFish in exchange for the consideration described above. The non-cash consideration became effective as of the closing date and was not a condition to the closing of the SPA.

Berta Pappenheim, a member of the Company’s Board of Directors, is the CEO, co-founder, and a director of CyberFish – and prior to the closing of the SPA, she owned 100% of CyberFish. Ms Pappenheim is no longer regarded as an independent director of the Company.

Also on the March 9, 2026, in connection with the closing of the SPA, and to govern the parties’ ongoing relationship as shareholders of CyberFish, Trust Stamp Malta Limited entered into a Shareholders Agreement (the “Shareholders Agreement”) with (i) Berta Pappenheim and (ii) CyberFish. The Shareholders Agreement contains provisions governing, among other things, the governance and management of CyberFish, board composition and voting, shareholder consent matters, information and reporting rights, financing expectations, and transfer restrictions with respect to shares of CyberFish.

37

Table of Contents

Also on March 9, 2026, Trust Stamp Malta Limited entered into a Consulting Agreement (the “Consulting Agreement”) with CyberFish. Under the Consulting Agreement, CyberFish agreed to provide consulting services relating to market development in the United Kingdom, including market entry and expansion strategy, business development, partnership identification, and related services. CyberFish designated Berta Pappenheim as key personnel to perform the services on its behalf. The Consulting Agreement contemplates that the services will be performed for an average of three (3) days per week over a rolling six-week period. In consideration for the services, Trust Stamp Malta Limited will pay CyberFish fees of £65,000 per year, payable in twelve equal monthly installments. Either party may terminate the Consulting Agreement upon 30 days’ prior written notice, and Trust Stamp Malta Limited may terminate the Consulting Agreement immediately upon certain events, including material breach, breach of confidentiality, certain legal or compliance impediments, or misconduct or gross negligence, in each case as provided in the Consulting Agreement. The Consulting Agreement includes customary confidentiality provisions and provides that intellectual property created pursuant to or in connection with the services will vest exclusively in Trust Stamp Malta Limited, subject to the terms of the Consulting Agreement.

The foregoing descriptions of the SPA, Shareholders Agreement, and Consulting Agreement are intended to be summaries, and are qualified by reference to the full text of these agreements filed as exhibits to this Annual Report on Form 10-K.

Acquisition of Lexverify Ltd.

On February 27, 2026(the “Closing Date”), the Company completed the acquisition of one hundred percent (100%) of the issued and outstanding share capital of Lexverify Ltd., a private limited company incorporated in England and Wales (“Lexverify”) pursuant to a share purchase agreement dated February 27, 2026 (the “SPA”) by and among the Company and the shareholders of Lexverify (each, a “Seller” and collectively, the “Sellers”). While limited in size, the Company believes this acquisition provides new expertise in the training and use of large language models as well as providing an additional access point to the UK market for the Company.

The aggregate purchase price for the acquisition (the “Purchase Price”) is payable entirely in shares of the Company’s Class A Common Stock, par value $0.01 per share (the “Common Stock”), with the number of shares determined based on the closing price of the Company’s Common Stock on Nasdaq on the Closing Date. The Purchase Price was structured in four tranches, consisting of: (i) an initial tranche equal to twenty-five percent (25%) of the Purchase Price (the “Completion Consideration”) to be issued on or within one business day following the Closing Date, and (ii) the remaining seventy-five percent (75%) of the Purchase Price (the “Deferred Consideration”) to be issued in three equal tranches on the dates that are 90, 180, and 270 days after the Closing Date, respectively, subject to the terms of the SPA. On the Closing Date, the Company issued shares of Common Stock to the Sellers in satisfaction of the Completion Consideration. As of the date of this Annual Report, shares of Common Stock remain to be issued by the Company to the Sellers to satisfy the Deferred Consideration.

If the Company fails to timely issue any portion of the consideration when due under the SPA, the Company is required to pay interest on the overdue amount at a rate of four percent (4%) per annum above London Interbank Offered Rate ("LIBOR").

Pursuant to the SPA, the Company may withhold issuance of Deferred Consideration in connection with a warranty claim asserted by the Company under the SPA and may set off amounts owed by any of the Sellers against such Seller’s Deferred Consideration, in each case subject to the terms and conditions set forth in the SPA.

If a change of control of the Company occurs prior to the issuance of 100% of the Deferred Consideration, then, subject to the terms of the SPA, the Company is required to issue the remaining Deferred Consideration to the Sellers prior to such change of control.

The SPA contains customary representations, warranties, covenants, confidentiality provisions, and limitations on liability. In addition, certain Sellers who were employees, officers, or directors of Lexverify as of the Closing Date agreed for a period of twelve (12) months following the Closing Date, subject to the terms of the SPA, not to compete with Lexverify’s business as conducted at Completion and not to solicit certain customers, clients, employees, or consultants of Lexverify.

Additionally, pursuant to the SPA, the Company agreed to approve the continuing employment of Lexverify’s employees on substantially similar compensation and benefit terms to comparable team members of the Company, including equity participation opportunities.

The foregoing description of the SPA is intended to be a summary, and is qualified by reference to the full text of the SPA, filed as an exhibit to this Annual Report on Form 10-K.

38

Table of Contents

Key Business Measures

In addition to the measures presented in our consolidated financial statements, we use the following key non-GAAP business measures to help us evaluate our business, identify trends affecting our business, formulate business plans and financial projections, and make strategic decisions.

Adjusted EBITDA

This discussion includes information about Adjusted EBITDA that is not prepared in accordance with U.S. GAAP. Adjusted EBITDA is not based on any standardized methodology prescribed by U.S. GAAP and is not necessarily comparable to similar measures presented by other companies. A reconciliation of this non-GAAP measure is included below.

Adjusted EBITDA is a non-GAAP financial measure that represents U.S. GAAP net income (loss) adjusted to exclude (1) other expense, (2) other income, (3) interest expense, (4) interest income, (5) stock-based compensation, (6) change in fair value of warrant liabilities (7) impairment of assets, (8) depreciation, and (9) certain other items management believes affect the comparability of operating results.

Management believes that Adjusted EBITDA, when viewed with our results under U.S. GAAP and the accompanying reconciliations, provides useful information about our period-over-period results. Adjusted EBITDA is presented because management believes it provides additional information with respect to the performance of our fundamental business activities and is also frequently used by securities analysts, investors and other interested parties in the evaluation of comparable companies. We also rely on Adjusted EBITDA as a primary measure to review and assess the operating performance of our Company and our management, and it will be a focus as we invest in and grow the business.

Adjusted EBITDA has limitations as an analytical tool and should not be considered in isolation from, or as a substitute for, analysis of our results as reported under GAAP. Some of these limitations are:

•Adjusted EBITDA does not reflect our cash expenditures or future requirements for capital expenditures or contractual commitments.

•Adjusted EBITDA does not reflect changes in, or cash requirements for our working capital needs.

•Although Depreciation and amortization are non-cash charges, the assets being depreciated and amortized will often have to be replaced in the future, and Adjusted EBITDA does not reflect any cash requirements for such replacements.

•Adjusted EBITDA does not include the impact of certain charges or gains resulting from matters we consider not to be indicative of our ongoing operations.

Due to these limitations, Adjusted EBITDA should not be considered as a measure of discretionary cash available to us to invest in the growth of our business. We compensate for these limitations by relying primarily on our U.S. GAAP results and using Adjusted EBITDA only as a supplement to our U.S. GAAP results.

39

Table of Contents

Reconciliation of Net Loss to Adjusted EBITDA

For the year ended December 31,

Net loss before taxes and equity method investment $ (8,077,259) $ (10,597,348)

Add: Change in fair value of warrant liability 3,574 (1,497)

Adjusted EBITDA loss (non-GAAP) for the year ended December 31, 2025, decreased by 20.93%, to $5.77 million from $7.29 million for the year ended December 31, 2024. During the year ended December 31, 2025, the Company had a decrease of $2.05 million in Selling, general, and administrative expenses when comparing the year ended December 31, 2025 to the year ended December 31, 2024. This decrease in Selling, general and administrative expenses was primarily driven by a reduction of $1.68 million in salaries and compensation, including stock-based compensation, which decreased by 25.93% from the year ended December 31, 2024. The salaries and compensation expenses decreased due to reductions in sales teams and the departure of certain members of the Company's management. Furthermore, the Company executed a new amendment with our S&P 500 bank customer that was effective as of July 1, 2025 and extends services through May 31, 2031 with minimum gross revenue exceeding $12.7 million over the balance of the contract term. The new contract amendment drove a $666 thousand increase in revenue during the year ended December 31, 2025. The Company also executed a new Statement of Work effective on January 1, 2025 under the Master Technology Services Agreement between the Company (through its subsidiary, Trust Stamp Malta Ltd.) and QID. The new Statement of Work with QID provides for service fees payable to the Company of a minimum $100,000 per month during the first six months, and up to $300,000 per month thereafter. In accordance with ASC 606 guidance, the Company recognized $600 thousand in Net Revenue from the Statement of Work with QID during the year ended December 31, 2025. The gains in Net revenue during the year ended December 31, 2025 were partially offset by the non-exclusive software license issued to QID during the year ended December 31, 2024 that resulted in the recognition of $1.00 million in Net revenue.

During the year ended December 31, 2024, the Company signed a license agreement with Boumarang in exchange for 5,000,000 prepaid warrants from Boumarang that were valued at $1.00 per warrant or $5.00 million and accounted for by recording as an investment and Other income. Subsequently, the Company recorded a $4.38 million impairment to Other income for the Boumarang prepaid warrants as a result of a change in fair value identified by an observable market transaction. The net impact to Other income was an increase of $705 thousand during the year ended December 31, 2024. Additionally, the Company recorded a $1.17 million loss to other expense due to the Company entering into a Termination and Release Agreement between the Company and an institutional investor that terminated the remaining stock purchase warrants in exchange for the Company making a $1,650,000 payment to the institutional investor. The Company also recorded a loss of $360 thousand to other expense related to the difference in the cash paid for the warrants and the fair market value of the warrants issued on September 10, 2024.

Components of Results of Operations

Net revenue

We derive our revenue primarily from professional services, although our business model continues transitioning to focus on recurring Software-as-a-Service ("SaaS") revenue streams.

Historically, the Company generated most of its income through long-term partnerships, comprising a relationship with an S&P 500 bank customer and a relationship with Mastercard International (“Mastercard”). Effective July 1, 2025, the Company's agreement with our S&P 500 bank customer was extended to May 31, 2031, subject to either party having the right to terminate for cause and a right for the customer to cancel for convenience on giving six months' notice. Under the terms of the extension, the Company receives a guaranteed minimum income stream for services, together with hosting and

40

Table of Contents

other fees and reimbursement of expenses incurred, which are subject to agreed markups of 10% or 20%. Minimum billing for services in the 1st year of the renewal is set at $154,000 per month with annual CPI-related increases. Under the arrangement, total minimum monthly billings will exceed $215,000 per month, subject to CPI-related increases. Based on the strength of the relationship and anticipated service needs, the Company anticipates annual billings exceeding the agreed minimum.

The Company (through its subsidiary, Trust Stamp Malta Ltd.) and QID agreed to enter into a Master Technology Services Agreement, under which QID will contract with the Company for business development, product development, and product operations for identity and privacy services and solutions in return for monthly service fees starting January 1, 2025, and capped at $3.6 million annually. The Company recognized $600 thousand in revenues from this agreement for the year ended December 31, 2025.

The Company also continued to expand the Orchestration Layer platform, which is being utilized by several customers including FIS’ new global identity authentication system. The Orchestration Layer platform is a SaaS platform that includes the Company’s proprietary tokenization technology, and facilitates no-code, and low-code implementations, making adoption faster and even more cost-effective for a broader range of potential customers. The Company expects this platform to accelerate its evolution, from being exclusively a custom solutions provider, to also offering a modular and highly scalable SaaS model with low-code implementation.

Cost of services provided

Cost of services provided generally consists of the cost of hosting fees and cost of labor associated with professional services rendered. Depreciation and amortization expense is not included in cost of services provided.

During the year ended December 31, 2025, Cost of services increased in absolute dollars primarily as a result of increased service requests by our S&P 500 bank customer. We expect the margin will continue to improve until it stabilizes over time.

Research and development

Research and development expenses (“R&D”) consist primarily of personnel costs, including salaries and benefits. Personnel costs are allocated to R&D for time spent working on the preliminary project stage and post-implementation maintenance as well as time spent on bug fixes associated with internal-use software activities, front-end application development in which technological feasibility has not been established, and services rendered to customers under funded software-development arrangements.

During the year ended December 31, 2025, we continued to invest in internal personnel to support our research and development efforts. As a result, research and development expenses increased in absolute dollars.

Selling, general, and administrative

Selling, general, and administrative (“SG&A”) expenses were generally composed of payroll, legal, and professional fees.

We expect that the sales and marketing expenses within the SG&A expenses will increase in absolute dollars as we continue to invest in our potential and current customers, in growing our business, and enhancing our brand awareness.

Depreciation and amortization

The increase in depreciation and amortization is primarily due to a continued investment in internally developed software and patent registrations which will be used for future productization.

Interest expense, net

Interest expense, net consists primarily of interest expense paid or accrued for promissory notes payable. The Company earned interest income in the form of interest on employee stock loans.

41

Table of Contents

Other income

Other income is mainly driven by miscellaneous income earned that is unrelated to the main focus of the Company’s business operations including the gain or loss on sale of assets.

Other expense

Other expense is mainly driven by miscellaneous expenses unrelated to the Company's primary business operations.

Results of Operations

The following table summarizes our consolidated statements of operations for the years ended December 31, 2025 and 2024.

For the years ended December 31,

Operating expenses:

Non-Operating Income (Expense):

Change in fair value of warrant liability 3,574 1,497

Net loss from equity method investment, related party (75,030) —

Loss on extinguishment of debt (159,035) —

Net loss attributable to non-controlling interest — —

42

Table of Contents

Comparison of the Years Ended December 31, 2025 and 2024

Net revenue

For the years ended December 31,

During the year ended December 31, 2025, Net revenue increased to $3.14 million, or an 1.85% increase from Net revenue of $3.08 million for the year ended December 31, 2024. During the year ended December 31, 2025, the $3.14 million in Net revenue consisted of $2.02 million from an S&P bank, $600 thousand license fee from QID under the license and assignment agreement between the Company and QID, $151 thousand from Triton, $141 thousand from FIS, $137 thousand from Mastercard, $69 thousand from ID Dataweb, Inc and various other customers for the remaining $20 thousand.

During the year ended December 31, 2025 the increase in Net revenue was primarily attributable to the contract amendment with our S&P 500 bank customer executed on July 1, 2025. The amendment extended the term of the existing agreement until May 31, 2031, with minimum gross revenue exceeding $12.7 million. It provides for changes to the fee structure as well as a new feature development and platform updates. This development resulted in an increase of $666 thousand during the year ended December 31, 2025 when compared to the year ended December 31, 2024.

The Company also had an increase of $62 thousand in Net revenue during the year ended December 31, 2025 as a result of expanded scope of services provided to ID Dataweb, Inc. beyond the original agreement, which was limited to driving license verification. Additional functionalities delivered under a separate statement of work included support for passport and military identification verification, as part of its broader initiative to expand coverage beyond the initial scope.

The Company also had an increase in the number of financial institutions enrolled with the Orchestration Layer increased Net revenue by $52 thousand during the year ended December 31, 2025 when compared to the year ended December 31, 2024. The Orchestration Layer is designed to be a one-stop-shop for Trust Stamp services and provides for easy integration to our products; chargeable on a per-use basis and is accelerating the Company’s evolution from being exclusively a custom solutions provider to also offering a modular and highly scalable SaaS model with low-code implementation. Since its launch in the third quarter of 2022, there have been 110 enterprise customers on the Orchestration Layer platform, including 97 financial institutions, as of December 31, 2025.

During the year ended December 31, 2025, the Company recognized revenue from services performed under a Statement of Work executed pursuant to the Master Technology Services Agreement ("MTSA") with QID, which became effective on January 1, 2025. The Company provided services to QID of $100 thousand per month from January 2025 - June 2025 which was the maximum allowed under the agreement. Starting in July 2025, the agreement allows for billing up to $300 thousand per month thereafter, which the Company did not reach during the year ended December 31, 2025 due to delays in customer implementation. Revenue is recognized in accordance with ASC 606 using the cost incurred input method, which aligns revenue recognition with the proportion of costs incurred relative to total expected costs for the contract. For the year ended December 31, 2025, the Company recognized $600 thousand under this agreement. As the MTSA was not in effect, no revenue was recognized during the year ended December 31, 2024.

Separately from the MTSA, the Company recognized a $1.0 million license fee during the year ended December 31, 2024, under a license and assignment agreement between the Company and QID. This revenue represented a one-time item and did not recur in the year ended December 31, 2025.

The increases to Net revenue were partially offset by an amendment to the Mastercard agreement executed in February 2025 that reduced fixed monthly license fees. As a result, during the year ended December 31, 2025, the Company recognized $348 thousand for software license fees and -$211 thousand for other services, meanwhile, during the year ended December 31, 2024 the Company recognized $345 thousand for software license fees and $79 thousand for other services.

43

Table of Contents

Cost of services

For the years ended December 31,

Cost of services (“COS”) increased by $318 thousand or 29.77% for the year ended December 31, 2025, compared to the year ended December 31, 2024. The primary driver of the increase in COS during the year ended December 31, 2025 compared to the year ended December 31, 2024 was due to $93 thousand increase in usage of driver license validations under our existing contract with the S&P 500 bank. The Company also had an increase of $88 thousand due to an increase in web services costs resulting from increased third party vendor expenses. Additionally, there was an increase of $75 thousand in internal developer COS allocations as a result of work completed for the QID Master Services Agreement.

Moreover, more development hours were charged directly to COS for the year ended December 31, 2025 when compared to the year ended December 31, 2024 resulting in an increase of $44 thousand in COS. This was mainly due to less work being requested from one of our major customers.

Research and development

For the years ended December 31,

Research and development (“R&D”) expenses increased by $33 thousand, or 1.57% for the year ended December 31, 2025, compared to the year ended December 31, 2024. The increase in R&D expense was primarily driven by an increase of $87 thousand in stock-based compensation allocation during the year ended December 31, 2025 compared to the year ended December 31, 2024 due to an increase in the Company's stock price in the award date fair value of employee stock-based compensation on the award date, an increase in the Company's stock price.

Another increase of $16 thousand was noted in R&D expense during the year ended December 31, 2025 primarily due to higher personnel-related costs associated with the expansion of the Company’s development team and annual merit adjustments.

The increases in R&D expense were partially offset by decreases in R&D expenses during the year ended December 31, 2025 primarily driven by a $69 thousand decrease in outsourced software development with 10Clouds as the Company transitioned this work internally resulting in cost savings as internal work is more cost effective. Comparatively, outsourced development costs decreased by 62% when comparing the year ended December 31, 2025 to the year ended December 31, 2024.

Selling, general, and administrative

For the years ended December 31,

Selling, general, and administrative expense (“SG&A”) decreased by $2.04 million, or 23.95%, for the year ended December 31, 2025, compared to the year ended December 31, 2024. The decrease in SG&A expense was driven by a $1.68 million decrease in salaries, stock-based compensation, payroll costs, and sales commissions during the year ended December 31, 2025, compared to the year ended December 31, 2024. The $1.68 million decrease includes a $324 thousand reduction in stock-based compensation awards during the year ended December 31, 2025. The decrease in salaries, stock-based compensation, payroll costs, and sales commissions is a result of reductions to the sales team, from 9 team members employed during the year ended December 31, 2024 to no team members during the year ended December 31, 2025. In addition, the EVP of Mergers and Acquisitions left the Company in December 2024 and was not subsequently replaced and the CFO role was vacated in January 2025 and filled internally leaving a vacant role that was not subsequently replaced.

44

Table of Contents

The Company also had a $237 thousand decrease in legal and professional fees primarily attributable to the cessation of consulting services previously provided by a third-party vendor during the year ended December 31, 2025. The Company also had a decrease of $155 thousandin travel costs attributable to the reduction in employees during the year ended December 31, 2025. Additionally, there were decreases in various other expenses amounting to $116 thousand attributable to marketing, taxes, rent, dues and subscription, IT services, and other operating expenses during the year ended December 31, 2025 compared to the year ended December 31, 2024.

The decreases in SG&A were partially offset by increases for other operating expenses including accounting and audit fees amounting to $141 thousand during the year ended December 31, 2025.

Depreciation and amortization

For the years ended December 31,

Depreciation and amortization (“D&A”) increased by $38 thousand, or 5.17% for the year ended December 31, 2025, compared to the year ended December 31, 2024. The primary driver for the increase in D&A is due to an increase of $47 thousand in software amortization when comparing the year ended December 31, 2025 to the year ended December 31, 2024, brought about by the increase in Capitalized internal-use software of noted as of December 31, 2025.

These increases were partially offset by a $7 thousand decrease in D&A expense related to the disposal and sale of office furniture in the Malta office which occurred during the year ended December 31, 2025.

Operating loss

For the years ended December 31,

The Company’s Operating loss decreased by $1.71 million or 18.22% for the year ended December 31, 2025 compared to the year ended December 31, 2024. The decrease in Operating loss was mainly related to substantial decrease in SG&A expense and an increase in Net revenue.

Interest expense, net

For the years ended December 31,

Source: SEC EDGAR (public domain) · 10-K for the period ended 2025-12-31, filed 2026-03-31 · accession 0001718939-26-000024

Filing HTML rendered to line-structured narrative text by the shipped reducer (datafeeds.edgar_fulltext.visible_text, keep_table_headers=True): scripts and inline-XBRL headers are dropped, and table content is reduced to its short label cells — numeric table data is not rendered and is therefore not counted. The same rendering is used for every year, so a year-over-year comparison is like for like.

The text is our rendering of the filing, not a facsimile: original pagination, typography and tables are not reproduced, and the numbers live in the financial statements (FA).

The outline locates item HEADINGS in this document. Only Items 1A and 7 have certified boundaries elsewhere in the terminal (the redline and the narrative-overlap number); every span here runs from one heading found to the next heading found.

How the outline was chosen. It is the longest chain of item headings that runs forward through both the document and the standard item order: 22 headings are on that chain and 19 further heading-shaped lines are not — the table-of-contents echo of every item, cross-references and exhibit-list mentions. Each entry's length is measured from its heading to the next heading on the chain.