US crypto & fintech regulation, in plain English
Every major rule from FinCEN, OCC, OFAC, the SEC and CFTC — explained, with who it affects and what to do. Free, always current, no signup.
Major rule trackers
The GENIUS Act: federal rules for payment stablecoins
Signed into law — illicit-finance rules being finalized (expected mid-2026)
The first major U.S. digital-asset law. It creates a federal licensing and supervision regime for payment-stablecoin issuers: 1:1 reserves in cash or short-dated Treasuries, bank-like safety-and-soundness standards, and full BSA/AML obligations. Treasury, FinCEN, and OFAC are now writing the implementing rules.
Open trackerU.S. Congress · SEC · CFTCThe CLARITY Act: who regulates crypto — the SEC or the CFTC?
Advancing through Congress — joint SEC/CFTC guidance already issued
The market-structure bill that aims to end the SEC-vs-CFTC turf war over crypto. It sets statutory rules for when a digital asset is a security (SEC) versus a digital commodity (CFTC), replacing years of enforcement-by-litigation with a defined regulatory perimeter.
Open trackerOFAC Adds New Individuals or Entities to the SDN List
OFAC has designated one or more new persons to the SDN List, blocking all property and interests in property subject to U.S. jurisdiction and prohibiting U.S. persons from transacting with them. All crypto, fintech, and financial institutions must update their sanctions screening systems promptly to capture these new designations and avoid violations.
OFAC Formally Publishes Iran-Related General Licenses Y and Z
OFAC has published two Iran-related general licenses — GL Y and GL Z — in the Federal Register, formalizing authorizations previously posted on OFAC's website. Given that Iran sanctions are among the highest-risk programs for crypto and fintech firms, compliance officers should carefully review these GLs to understand what transactions are permitted and ensure their screening systems are calibrated accordingly.
OFAC Publishes General License 2 Under DRC Sanctions Regulations
OFAC has formally published General License 2 under the Democratic Republic of the Congo Sanctions Regulations in the Federal Register, having previously made it available on its website. Compliance teams should incorporate this GL into their sanctions policies to clarify which DRC-related transactions are permissible.
OFAC Publishes General License 12 for ICC-Related Sanctions
OFAC has formally published General License 12 under the International Criminal Court-Related Sanctions Regulations in the Federal Register, though it was previously available on OFAC's website. Compliance teams should review GL 12 to understand what categories of transactions are authorized under this sanctions program and ensure internal policies and screening procedures reflect the license's scope.
KalshiEX Proposes Listing Standards for Security Futures Products
KalshiEX LLC, a prediction market exchange, has filed a proposed rule change with the SEC establishing listing standards for security futures products. This is relevant to compliance officers tracking how non-traditional trading venues are expanding into regulated securities and futures territory, which carries implications for product eligibility, customer disclosures, and applicable regulatory obligations.
Coinbase Derivatives Files Rules for Cash-Settled Futures on Stocks and ETFs
Coinbase Derivatives, LLC has filed new rules with the SEC covering cash-settled futures on individual equities and ETFs, including perpetual single-stock futures. Compliance officers at crypto-adjacent broker-dealers and exchanges should monitor this development as it signals expanding regulated derivatives offerings from a major crypto platform, with implications for customer margin, product disclosures, and applicable futures/securities rules.
OFAC Formally Publishes Venezuela General Licenses 5X and 5Y
OFAC has published two updated general licenses — GL 5X and GL 5Y — under the Venezuela Sanctions Regulations in the Federal Register, formalizing authorizations previously posted to OFAC's website. Compliance officers dealing with Venezuela-related transactions, including those involving digital assets or payments, should review these GLs to understand the permitted scope of activity.
OFAC Removes Individuals from SDN List Under Ethiopia Sanctions
OFAC has delisted certain persons previously blocked under Ethiopia sanctions authorities, removing them from the SDN List. Compliance officers must update their sanctions screening systems promptly to reflect these removals and avoid false positives that could unnecessarily block legitimate transactions.
Bitnomial Exchange Proposes Security Futures Listing and Margin Rules
Bitnomial Exchange, LLC has filed a proposed rule change with the SEC covering security futures product listing standards and customer margin requirements. As a crypto-native exchange expanding into regulated security futures, this filing is relevant for compliance teams tracking how digital asset venues are building out their regulated derivatives frameworks and associated customer protection rules.
SEC Grants Temporary Relief for Tokenized Stock Trading Venues and Liquidity Providers
The SEC has issued a temporary conditional exemption allowing certain distributed ledger-based trading venues to operate tokenized NMS stocks without being classified as a registered 'Exchange,' and permitting certain liquidity providers in those markets to avoid the 'Dealer' definition. This is a significant development for firms building or participating in tokenized securities platforms, as it signals the SEC is actively shaping the regulatory perimeter for on-chain capital markets. Compliance officers at firms handling tokenized securities should monitor the accompanying request for comment to understand the conditions attached and the direction of future rulemaking.
OFAC Adds New Individuals or Entities to the SDN Sanctions List
OFAC has designated one or more persons to its Specially Designated Nationals and Blocked Persons List, meaning all property and interests in property subject to U.S. jurisdiction are blocked and U.S. persons are prohibited from transacting with them. Crypto and fintech firms are required to screen customers and transactions against the SDN list in real time, making any new addition an immediate compliance trigger. Failure to block transactions involving newly designated parties can result in significant civil and criminal penalties.
OCC Updates Cybersecurity Examination Work Program for Banks
The OCC has revised its Cybersecurity Supervision Work Program (CSW), which examiners use to assess cybersecurity risk at national banks and federal savings associations, updating its structure and references to reflect the evolving threat landscape and adoption of standardized frameworks. For compliance and risk officers at banks, neobanks, and trust companies under OCC supervision, this signals updated examiner expectations around cybersecurity controls and preparedness. Crypto custodians and fintechs with bank charters or partnerships should also take note, as vendor and third-party cybersecurity risk is often assessed through this lens.
CFTC Updates Whistleblower Award Rules for Greater Transparency
The CFTC is amending its whistleblower program rules to improve efficiency, transparency, and predictability of the claims process, modeled on similar SEC regulations. The amendments also reflect an internal reorganization moving the Whistleblower Office to the Office of General Counsel. Compliance officers at crypto and derivatives firms should be aware that a more streamlined whistleblower process may increase the likelihood of internal misconduct being reported externally to the CFTC.
FDIC Joins Interagency Third-Party Risk Management Guidance Proposal
The FDIC is participating in the same four-agency interagency proposal to update third-party risk management guidance for banking organizations, signaling broad regulatory alignment on vendor oversight expectations. FDIC-supervised institutions, including state non-member banks that frequently partner with fintechs and crypto firms, should treat this proposal as a preview of future examination standards. The agencies intend to rescind and replace existing guidance, making this a significant structural change for compliance programs.
OFAC Publishes Further SDN List Additions
OFAC has designated additional persons to its SDN List, triggering immediate obligations for U.S. persons and institutions to block assets and refuse transactions involving those parties. Institutions operating in crypto and payments must ensure their real-time screening tools reflect these new designations to remain compliant. Repeated OFAC actions on the same day can indicate a coordinated enforcement campaign worth monitoring for thematic patterns.
OFAC Issues Additional SDN List Designations
OFAC has added one or more persons to the SDN List, blocking all U.S.-jurisdictional property interests and prohibiting U.S. persons from engaging in transactions with the newly designated parties. This is a routine but compliance-critical action requiring immediate screening list updates across all customer-facing and counterparty-facing systems. Crypto exchanges and payment processors are particularly exposed given the speed and pseudonymity of digital asset transactions.
OCC Joins Interagency Proposed Third-Party Risk Management Guidance
The OCC is co-issuing the same interagency third-party risk management proposal alongside the Fed, FDIC, and NCUA, signaling a unified supervisory approach across the federal banking agencies. National banks and federal savings associations should treat this as a near-certain indicator of forthcoming binding expectations on vendor oversight. The proposal's emphasis on risk-proportionate controls is particularly relevant for institutions using crypto or fintech service providers.
OCC, Fed, FDIC & NCUA Propose Unified Third-Party Risk Management Guidance
Four federal banking regulators are jointly proposing updated third-party risk management guidance that emphasizes risk-proportionate oversight and replaces existing agency-specific guidance. The proposal encourages institutions to tailor their vendor management programs to the actual risk level of each relationship, size, and complexity of the organization. This is directly relevant to any bank or fintech that relies on third-party technology providers, crypto rails, or payment processors.
Fed Proposes Third-Party Risk Management Guide for Community Banks
The Federal Reserve is seeking comment on a proposed guide specifically for community banking organizations on managing third-party relationship risks. The guide draws on supervisory experience and addresses key risk categories most common to smaller institutions. Compliance officers at community banks or fintechs partnering with them should note this could reshape due diligence and oversight expectations for vendor relationships.
OFAC Adds New Names to SDN Sanctions Blacklist
OFAC has designated one or more individuals or entities to its Specially Designated Nationals and Blocked Persons (SDN) List, meaning all property and interests in property subject to U.S. jurisdiction must be blocked and U.S. persons are prohibited from transacting with them. Crypto firms and financial institutions must screen against the updated SDN List immediately to avoid sanctions violations. Failure to block prohibited transactions can result in significant civil and criminal penalties.
OFAC Adds New Names to SDN Sanctions Blacklist
OFAC has designated one or more individuals or entities to its Specially Designated Nationals (SDN) list, blocking all property and interests in property subject to U.S. jurisdiction and prohibiting U.S. persons from transacting with them. Crypto and fintech firms must screen all customers, counterparties, and wallet addresses against the updated SDN list immediately, as facilitating transactions with a newly listed person — even unknowingly — can trigger severe civil and criminal penalties.
OCC/Fed/FDIC Raise Asset Threshold for 18-Month Exam Cycle to $6 Billion
An interim final rule from the OCC, Federal Reserve, and FDIC raises the total asset threshold that allows certain well-managed, well-capitalized insured depository institutions and U.S. branches of foreign banks to qualify for an extended 18-month on-site examination cycle. Smaller banks and trust companies that fall below the new threshold may see reduced examination frequency, affecting the pace of supervisory feedback on compliance programs. Fintech-partnered banks and crypto-custody trust companies under the threshold should be aware that less frequent exams do not reduce compliance obligations.
OFAC Updates Identifying Information on Sanctioned Entries
OFAC has published updates to the identifying information for one or more entries on its sanctions lists, which may include name variations, aliases, addresses, or other identifiers used for screening purposes. Crypto firms, MSBs, and payment processors must maintain current sanctions list data to avoid facilitating prohibited transactions. Failure to screen against the most up-to-date list version can result in enforcement exposure.
SEC Extends Review of VanEck JitoSOL (Solana Staking) ETF Listing
The SEC has designated a longer review period before deciding whether to approve or disapprove Nasdaq's proposal to list and trade shares of the VanEck JitoSOL ETF, a commodity-based trust tied to a Solana liquid staking token. This signals continued regulatory scrutiny of crypto-asset ETF products, particularly those involving staking mechanics. Compliance officers at exchanges and custodians supporting digital asset ETFs should monitor this proceeding as it may set precedent for how staking-based crypto products are classified and regulated.
Regulators Clarify How They Will Oversee Core Tech Providers to Community Banks
The OCC, Federal Reserve, and FDIC have issued an interagency statement explaining how they will apply risk-based supervision and enforcement to core service providers — such as technology and data processors — that serve community banking organizations. This matters for fintechs and crypto firms acting as technology vendors or service providers to banks, as it signals heightened regulatory scrutiny of the bank-vendor relationship and the factors examiners will weigh when taking supervisory or enforcement action against those providers.
OCC Proposes Tailored Third-Party Risk Rules and Eases Core Provider Oversight Burden
The OCC announced a proposal to tailor third-party risk management requirements to actual risk levels, aiming to reduce compliance burden on community banks while maintaining safety standards — accompanied by new supervisory clarity on core service providers. Fintech and crypto firms that serve as third-party vendors to OCC-supervised banks should expect that the banks' due diligence, contracting, and monitoring obligations toward them may be recalibrated based on risk tier.
Agencies Propose Updated Third-Party Risk Management Guidance — Comment Period Open
The FDIC, Federal Reserve, NCUA, and OCC have jointly proposed updated guidance to help financial institutions manage risks in third-party relationships and are seeking public comment. Crypto firms, fintechs, and payment companies that serve as third-party vendors to regulated financial institutions — or that rely on third-party technology providers themselves — should review the proposal, as it will shape the due diligence, contracting, and oversight standards their bank clients must apply.
Federal Agencies Seek Public Comment on New Third-Party Risk Management Guidance
The FDIC, Federal Reserve, NCUA, and OCC are jointly requesting comment on proposed guidance designed to help regulated financial institutions better manage third-party relationship risks. This is directly relevant to fintechs and crypto firms that either rely on third-party vendors or are themselves vendors to regulated banks, as the final guidance will define the risk management expectations those institutions must meet.
OFAC Updates SDN List: Records Modified and Persons Removed
OFAC has updated identifying information for one or more individuals or entities on the Specially Designated Nationals (SDN) List, and has removed one or more persons from the list entirely. Compliance officers must ensure their sanctions screening systems are refreshed promptly to avoid false positives or missed matches. Outdated SDN data is a common source of both compliance failures and unnecessary transaction blocks.
OFAC Formally Publishes Venezuela General Licenses 50A and 51A
OFAC has published General Licenses 50A and 51A under the Venezuela Sanctions Regulations in the Federal Register, following their earlier release on OFAC's website. These GLs may amend or supersede prior authorizations, and compliance officers need to confirm their Venezuela-related controls reflect the current versions. Given Venezuela's status as a comprehensively sanctioned jurisdiction, even minor GL updates can materially affect permissible activities.
OFAC Formally Publishes Venezuela General Licenses 30B and 51
OFAC has added General Licenses 30B and 51 under the Venezuela Sanctions Regulations to the official Federal Register record; both were previously posted on OFAC's website. Any firm with exposure to Venezuela-related transactions or counterparties must ensure their compliance programs align with the specific authorizations and limitations in these GLs. Venezuela remains a high-risk sanctions jurisdiction requiring ongoing vigilance.
OFAC Publishes General License 35 for Global Terrorism & Drug Trade Sanctions
OFAC has formally published General License 35 under the Global Terrorism Sanctions Regulations and the Illicit Drug Trade Sanctions Regulations, which was previously available only on OFAC's website. Compliance officers should ensure their sanctions screening programs and permissible transaction guidance reflect the authorizations and conditions contained in this GL. Failure to stay current with active general licenses can result in inadvertent sanctions violations.
Bitnomial Exchange Registers with SEC as National Securities Exchange
The SEC has acknowledged receipt of Bitnomial Exchange LLC's notice of registration as a national securities exchange under the Securities Exchange Act of 1934. This signals expanding regulated infrastructure for crypto derivatives trading, which compliance officers should monitor as it may affect where digital asset products can be listed and traded under securities law. Firms routing or clearing crypto derivatives should assess whether their counterparty or venue relationships are affected.
OFAC Formally Publishes Iran-Related General Licenses CC and DD
OFAC has published Iran-related General Licenses CC and DD in the Federal Register; both were previously issued and posted on OFAC's website. Iran is one of the most heavily sanctioned jurisdictions, and any authorized carve-outs under these GLs must be precisely understood and incorporated into compliance programs. Crypto and fintech firms should pay particular attention given OFAC's history of enforcement actions involving Iran-related transactions in digital assets.
OFAC Publishes General License 5 Under Nicaragua Sanctions Regulations
OFAC has formally published General License 5 under the Nicaragua Sanctions Regulations, making it part of the official regulatory record after prior availability on OFAC's website. Compliance teams must ensure their sanctions policies reflect any authorized transactions or conditions under this GL. Nicaragua-related transaction monitoring and screening rules should be reviewed for consistency with GL 5.
KalshiEX Registers with SEC as National Securities Exchange
The SEC has acknowledged KalshiEX LLC's notice of registration as a national securities exchange under the Securities Exchange Act of 1934. KalshiEX operates a prediction/event contracts marketplace, and its registration as a securities exchange may have downstream implications for how similar products are regulated. Compliance officers at fintechs and exchanges offering event contracts or derivatives should monitor this development closely.
Coinbase Derivatives Registers with SEC as National Securities Exchange
The SEC has acknowledged Coinbase Derivatives LLC's notice of registration as a national securities exchange under the Securities Exchange Act of 1934. This is a significant development for the crypto industry, as it expands the regulated exchange infrastructure for crypto derivatives under the securities law framework. Compliance officers at exchanges, custodians, and broker-dealers should monitor this registration for implications on product offerings, counterparty relationships, and regulatory obligations.
OFAC Suspends Iran General Licenses, Tightening Sanctions Restrictions
OFAC has indefinitely suspended three general licenses and one licensing policy under the Iranian Transactions and Sanctions Regulations, reflecting a shift in U.S. foreign policy toward Iran. Any transactions or activities that were previously permitted under those now-suspended licenses are no longer authorized. Compliance officers must immediately review whether their firms or customers were relying on any of the affected licenses and halt any such activity.
Regulators Clarify: Mobile Driver's Licenses & Digital IDs Can Satisfy KYC Rules
Five federal regulators — OCC, FinCEN, the Federal Reserve, FDIC, and NCUA — jointly issued FAQs confirming that state-issued mobile driver's licenses and other government-issued verifiable digital credentials (VDCs) can be used to satisfy Customer Identification Program (CIP) requirements under the Bank Secrecy Act. This is significant guidance for crypto and fintech firms because it provides regulatory clarity on accepting digital identity documents during onboarding, reducing reliance on physical ID checks. Compliance officers should review the FAQs carefully to understand the conditions and limitations under which VDCs qualify as acceptable identity verification methods.
FinCEN GTO: Southwest Border MSBs Must Report Cash Transactions $1K–$10K
FinCEN has issued a Geographic Targeting Order (GTO) requiring certain money services businesses operating along the U.S. southwest border to report and retain records of cash transactions between $1,000 and $10,000 — well below the standard $10,000 CTR threshold — and to verify the identity of customers presenting such transactions. This is a significant AML/BSA escalation for covered MSBs in the targeted geography, effectively lowering the transaction monitoring and KYC trigger point for cash dealings. Non-compliance with a GTO carries the same penalties as violations of the Bank Secrecy Act.
SEC Proposes Modernized Rules for Registered Transfer Agents
The SEC is proposing to overhaul the regulatory framework governing registered transfer agents, including new rules, amendments to existing rules, and updates to registration and reporting forms (Form TA-1 and Form TA-2). Crypto and fintech firms that act as — or rely on — transfer agents for digital securities should pay close attention, as modernized rules could reshape recordkeeping, operational, and compliance obligations in that space. Trust companies and broker-dealers involved in securities processing may also face updated requirements.
Regulators Clarify What Banks Can (and Can't) Tell Customers About SARs
Five federal regulators — OCC, Federal Reserve, FDIC, FinCEN, and NCUA — jointly clarified the rules around SAR confidentiality when institutions communicate with customers about potentially fraudulent transactions. The statement addresses a persistent compliance tension: institutions must protect SAR confidentiality (including not 'tipping off' subjects) while still being able to warn or question customers about suspicious activity without inadvertently disclosing a SAR has been filed. Compliance officers should review customer-facing fraud communication workflows to ensure staff are not crossing the tipping-off line.
FinCEN Proposes Cutting Off UAE Branches of Banque Misr Over Money Laundering Risk
FinCEN is proposing to designate the UAE-based branches of Banque Misr as a primary money laundering concern under Section 311 of the USA PATRIOT Act. If finalized, U.S. financial institutions would be prohibited from opening or maintaining correspondent accounts for Banque Misr UAE, required to take reasonable steps to block transactions involving Banque Misr UAE flowing through foreign correspondent accounts, and required to apply enhanced due diligence to foreign correspondent accounts to prevent their use for such transactions. Any firm that maintains foreign correspondent banking relationships — including crypto exchanges and fintechs with banking partners — must ensure Banque Misr UAE exposure is identified and addressed.
OFAC Updates SDN List: New Terrorism-Linked Designations and Removals
OFAC has both added new persons to and removed certain persons from the SDN List under its counterterrorism authority (Executive Order 13224, as amended). U.S. persons must block property of newly listed individuals and may now transact with those removed, making prompt screening-system updates essential for all regulated firms.
OFAC Adds New Names to SDN Sanctions Blacklist
OFAC has designated one or more additional persons on the Specially Designated Nationals (SDN) List, meaning all U.S. persons and entities are prohibited from transacting with them and any property under U.S. jurisdiction must be blocked. Crypto exchanges, custodians, and payment processors must screen customers and counterparties against the updated SDN List immediately to avoid violations.
OFAC Adds New Names to SDN List, Updates Existing Entry
OFAC has designated one or more individuals or entities to the Specially Designated Nationals (SDN) List, blocking all U.S.-jurisdictional property interests and prohibiting U.S. persons from transacting with them; vessel identifications are also included. Additionally, identifying information for one existing SDN List entry has been updated. Compliance teams must immediately screen these new and updated entries against customer and counterparty databases to avoid sanctions violations.
OCC Proposes Two-Tier Framework for Violations: Substantive vs. Technical
The OCC is proposing to split regulatory violations into 'substantive' and 'technical' categories to better calibrate supervisory responses, including when Matters Requiring Attention (MRAs) are issued. For banks and trust companies engaged in crypto or fintech activities, this could affect how examiners escalate findings related to BSA/AML, KYC, or digital asset compliance gaps. Comment period is open, giving institutions an opportunity to shape the final framework.
OCC Revises Enforcement Action and MRA Policies and Procedures
The OCC has released updated internal policy manuals governing how bank enforcement actions and Matters Requiring Attention (MRAs) are issued and managed. These revisions signal a shift toward greater consistency and transparency in how the OCC responds to supervisory findings, which is directly relevant to banks and trust companies navigating crypto, BSA/AML, and fintech-related examination findings. Compliance officers should review the updated PPMs to anticipate examiner expectations.
OCC Announces Clearer, More Consistent Enforcement and Supervisory Standards
The OCC announced coordinated actions to improve transparency in how it issues MRAs and enforcement actions, including two revised policy manuals and a proposed rule change to the violations framework. For banks and trust companies—including those offering crypto custody or digital asset services—this means greater predictability in how examination findings will be escalated. Compliance teams should treat this as an opportunity to reassess their internal remediation and examiner-relations processes.
OCC & FDIC Finalize Rule Defining 'Unsafe or Unsound Practice' and MRA Standards
The OCC and FDIC have jointly issued a final rule that formally defines 'unsafe or unsound practice' under the Federal Deposit Insurance Act and restructures the supervisory framework for issuing MRAs and other supervisory communications. This rule directly affects how examiners at both agencies will identify and escalate compliance deficiencies—including those related to digital assets, BSA/AML, and fintech partnerships—at banks and insured depository institutions. Institutions should update their compliance risk frameworks to align with the new definitions and thresholds.
OFAC Issues Two New Iran General Licenses (GL AA and GL BB)
OFAC has formally published two new Iran-related General Licenses — GL AA and GL BB — in the Federal Register, having previously made them available on its website. General Licenses carve out specific categories of otherwise-prohibited transactions, so compliance teams need to understand exactly what activity each GL authorizes and whether any of their customers or counterparties may rely on these licenses. Failure to correctly apply or scope a GL can result in unauthorized Iran-related transactions.
OFAC Publishes New Sector Determination Under Iran Executive Order 13902
OFAC has formally published in the Federal Register a sector determination issued under Executive Order 13902, which authorizes broad sanctions on sectors of the Iranian economy. Although the determination was previously posted on OFAC's website, its Federal Register publication gives it broader legal notice and reaffirms its binding effect. Compliance teams must ensure their sanctions screening programs block transactions involving any newly designated Iranian sectors and related parties.
OFAC Suspends Five Iran General Licenses Amid U.S. Policy Shift
OFAC has indefinitely suspended five general licenses under the Iranian Transactions and Sanctions Regulations, reflecting a change in U.S. foreign policy toward Iran. Compliance officers must immediately review any transactions or relationships that relied on those now-suspended licenses, as activity previously authorized may now be prohibited. Failure to update screening controls and customer communications promptly could expose firms to sanctions violations.
OFAC Sanctions New Persons and Vessels — SDN List Updated
OFAC has added one or more persons and associated vessels to the SDN List, blocking all U.S.-jurisdiction property interests and prohibiting U.S. persons from engaging in transactions with them. The inclusion of vessels is notable for firms involved in trade finance or commodity-linked digital asset transactions, but all financial intermediaries must screen the new designations immediately.
OFAC Designates One Additional Person to the SDN Blocked List
OFAC has placed one individual on the SDN List, blocking their U.S.-jurisdiction assets and barring U.S. persons from transacting with them. All regulated financial institutions — including crypto exchanges, custodians, and payment processors — are required to screen against current SDN data in real time or near-real time.
OFAC Adds New Names to the SDN Blocked Persons List
OFAC has designated one or more individuals as Specially Designated Nationals, blocking all U.S.-jurisdiction property and prohibiting U.S. persons from transacting with them. Crypto and fintech firms must screen these new entries immediately, as facilitating transactions with SDNs — including in digital assets — can result in severe civil and criminal penalties.
SEC Proposes New Crypto Asset Offering Exemptions and Security Safe Harbor
The SEC is proposing 'Regulation Crypto Assets,' which would create two new exemptions from securities registration — one for offerings up to $5 million over four years and another for offerings up to $75 million per year — with principles-based disclosure requirements for issuers. Critically, the proposal also includes a conditional safe harbor that could allow certain crypto assets to be deemed not to involve an investment contract, potentially removing them from the definition of 'security.' Crypto exchanges, token issuers, broker-dealers, and legal/compliance teams need to evaluate how these exemptions and the safe harbor conditions interact with their current token listing and offering practices.
CFTC Proposes Lighter Registration Rules for RIAs Managing Crypto/Commodity Pools
The CFTC is proposing to exempt certain SEC-registered investment advisers from CPO registration when managing commodity pools for sophisticated investors, add a related CTA exemption, and raise the Small Pool Exemption threshold to account for inflation. Broker-dealers, RIAs, and fund managers that touch crypto or commodity-linked products should assess whether they currently rely on no-action relief that this proposal would supersede. This could reduce duplicative compliance burdens for firms already registered with the SEC.
CFTC Seeks Input on Derivatives Contracts for AI Compute Resources
The CFTC is requesting public comment to better understand derivatives markets built around computing resources (e.g., AI/cloud compute), signaling potential future oversight of this emerging asset class. Compliance officers at crypto and fintech firms should monitor this closely, as it may foreshadow new regulated derivatives products that intersect with digital infrastructure. Firms involved in tokenized compute markets or AI-linked financial products could face future CFTC jurisdiction.
OCC Comptroller Signals Support for Digital Assets and GENIUS Act Next Steps
Comptroller Gould publicly addressed the OCC's role in advancing digital asset innovation and supporting the administration's digital currency priorities at the Wyoming Blockchain Symposium, including next steps related to the GENIUS Act. This signals that the OCC is actively shaping the federal regulatory framework for stablecoins and digital assets, which has direct implications for banks and trust companies considering or already offering crypto-related services. Compliance officers should treat this as an indicator of near-term guidance or rulemaking activity from the OCC in the digital asset space.
Want this mapped to your own program?
PliOS watches these sources for you and flags exactly which of your policies each new rule affects. Start with a free, AI-guided gap assessment — no credit card required.
Run My Free Assessment