Skip to content

Invest1 publisher3 min readPublished

Revised CLARITY Act delegates the DeFi control test to the SEC, CFTC and Treasury

The new text defines a non-decentralized trading protocol by who can alter it, then leaves registration, conduct and Bank Secrecy Act questions to rules three agencies have not written. A procedural vote is set for Sept. 15.

The Investor · Invest desk

Illustration accompanying Revised CLARITY Act delegates the DeFi control test to the SEC, CFTC and Treasury

What happened

  • A revised CLARITY Act text posted on Senator Cynthia Lummis' website would have US regulators decide whether controllers of non-decentralized finance trading protocols owe securities, commodities and AML duties.
  • The text defines such a protocol as one a person or coordinated group can materially alter, or whose controllers can restrict users, or whose transactions are not governed solely by transparent, pre-established code.
  • The SEC and CFTC would write activity-based rules on registration, conduct, disclosure, recordkeeping and supervision, and the Treasury would set out how Bank Secrecy Act obligations apply to controllers.
  • Software and distributed ledger systems would not register in their own capacity, and sitting on an incident-response or security council would not by itself establish control over a protocol.
  • The text landed before a procedural Senate vote scheduled for Sept. 15, which needs 60 votes to advance and therefore Democratic support alongside Republican votes.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • decision Protocol governance becomes the compliance variable: keeping the ability to alter rules or restrict users puts an operator inside the category, and that choice gets made before any agency has said what the category costs.
  • constraint No operator can budget compliance off the statute, because the numbers that matter, registration thresholds and recordkeeping duties, exist only in rules not yet proposed.
  • contradiction Armstrong reads the bill as vote-ready while the ethics language that Gallego wanted settled first is still the prior draft's, so the industry's confidence rests on negotiations outside the released text.
  • exposure A failed vote leaves DeFi controllers with the same two agencies acting under existing authority, minus the statutory protections for software and for security-council participants.

Read as reported, the definition works as a list of alternatives: any one of the three conditions puts a protocol inside the category, so a protocol sits outside only by clearing all three [2][1]. Under that structure the threshold question is what counts as materially altering a protocol's functionality, operation or rules [2]. The bill directs regulators to determine whether controllers must comply [1], so the answer arrives in rules.

The five rule subjects belong to the SEC and the CFTC, the Bank Secrecy Act determination belongs to Treasury, and that puts three agencies between the statutory category and any obligation a controller could actually price [3][2][3][4]. The Sept. 15 procedural vote decides who holds the pen [4].

The disagreements holding up that vote are ethics, anti-money laundering protections and stablecoin rewards [8]. The controller definition is not among them, and the ethics section in the new text is largely unchanged from the prior version even though it has been one of the main points of contention [9].

Coinbase CEO Brian Armstrong told CNBC on Thursday that the bill was "ready to get a yes vote" [10], and said the must-have issues Coinbase had raised were resolved while ethics negotiations stayed active and looked close to a solution [11], without specifying which provisions had changed [12]. Ji Hun Kim of the Crypto Council for Innovation called the vote a "pivotal moment" for digital assets, innovation and American leadership [14], and told Cointelegraph that the US needs a framework combining consumer protections with business conduct standards [15]. Senator Ruben Gallego put the other side of it on Aug. 20: "A fast vote gets you a fast result, but I'm not sure it's the result you want," Gallego said [13].

Armstrong also said that if the legislation does not advance, the SEC and the CFTC could instead pursue rulemaking and innovation exemptions using their existing authority [16]. Take him at his word and both branches end in agency rulemaking, which means what the statute adds for an operator is two written carve-outs: one keeping software and distributed ledger systems off the registration line, and one keeping a security-council seat from counting as control by itself [5][6].

If the agencies read material alteration narrowly, an upgrade key survives with conduct and disclosure duties attached. A broad reading makes the keyholder the registrant. A vote that falls short of 60 means the carve-outs never bind anyone [7]. My read is that the delegation matters more than the definition, because the definition sorts nothing until the SEC, the CFTC and Treasury say what it sorts [2]. The read breaks if a rule proposal simply restates the statutory definition and stops, in which case the drafting done before Sept. 15 was the decisive act.

What to watch

  • The Sept. 15 tally against the 60-vote threshold, and which Democrats supply the margin.
  • Whether Treasury signals how Bank Secrecy Act obligations would attach to protocol controllers.
  • Whether a later draft narrows material alteration to exclude routine upgrades.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories