Clarity Act Fails: SEC, CFTC, and Agentic Compliance Risk
The Senate cloture vote on the CLARITY Act collapsed on 15 September 2026, falling well short of the 60-vote threshold required to advance. For accounting firms, CFOs, and compliance teams operating in the digital asset space, the immediate consequence is straightforward: the statutory clarity the industry had hoped for is not coming, at least not soon, and the Bank Secrecy Act accountability standard applies today, including to AI-driven agents acting on your behalf. Your crypto compliance reporting obligations have not changed; the path to meeting them just became more complex.
What Happened in the Senate on 15 September 2026
The CLARITY Act was the primary legislative vehicle for defining how cryptoassets are regulated in the United States, and specifically for resolving the longstanding jurisdictional split between the Securities and Exchange Commission and the Commodity Futures Trading Commission. That split, which has defined regulatory uncertainty for years, was supposed to be resolved by Congress drawing explicit definitional lines.
Why the Vote Failed
The cloture vote failed because a number of Democrats who had been actively negotiating with Republicans through prior months switched to nays at the critical moment. The breakdown tracked three broad fault lines: disagreements over yield-bearing digital asset products, ethics provisions tied to elected officials holding cryptoassets, and protections for open-source developers. Those negotiations had been running for months, but the final days before the vote saw an increasingly adversarial tone between the two sides, making compromise impossible in the time available.
A procedural "motion to reconsider" was filed, which technically keeps the bill from being declared officially dead. In practice, however, the path to passage looks very narrow. The depth of prior negotiation and the political deterioration in the final weeks make a rapid revival unlikely.
A Legislative Outcome That Was Already Priced In
The bill had already attracted significant commentary about its prospects. For context on the political dynamics leading up to the vote, see our earlier coverage of how the Clarity Act Senate defeat reshapes Bitcoin accounting, which traces the market and accounting consequences of the vote. The outcome was not entirely a surprise to compliance professionals who had been tracking the negotiating calendar, but the scale of the defeat and the speed of the political breakdown were notable.
What Replaces the Legislation: SEC and CFTC Rulemaking
With Congress unable to define the market structure by statute, the work passes to the regulators. Both the SEC and the CFTC have indicated that they already hold authority over most digital asset markets under their founding statutes. The SEC will assert oversight over securities markets, and the CFTC will cover derivatives and spot commodity markets. The exact perimeters of those categories remain the central unresolved question.
How Firms Will Now Get Answers
In the absence of a statute, market participants will need to determine their regulatory obligations through three channels: agency rulemakings, litigation outcomes, and no-action letters. Each of these is slower, less certain, and more resource-intensive than a clear legislative text. For a firm running crypto bookkeeping software or maintaining a digital asset accounting software stack, this creates a specific operational challenge: the compliance parameters you build into your systems today may need to be revised as agency guidance evolves.
Rulemakings take time and are subject to legal challenge. Litigation produces precedent that is fact-specific and may not transfer cleanly to your firm's product set. No-action letters provide comfort only to the requesting party and under the precise facts stated. None of these is a substitute for statutory certainty, and all three require active legal and compliance monitoring.
The SEC Chair's Position
SEC Chair Atkins had already signalled before the vote that the Commission believes it holds the authority it needs over digital asset markets and that independent rulemaking would proceed regardless of the legislative outcome. That position gives the agency a clear mandate to move, but the rulemaking calendar and the likely scope of those rules remain uncertain. Firms should not expect the definitional questions to be resolved quickly through agency action alone.
The Bank Secrecy Act Does Not Wait on Washington
Whatever the eventual market structure settlement between the SEC and the CFTC, one body of law is not in question: the Bank Secrecy Act. BSA obligations apply to money services businesses, broker-dealers, and other covered entities regardless of which agency holds primary market-structure oversight. The collapse of the CLARITY Act changes nothing about those obligations.
The Core Compliance Standard
The BSA requires covered institutions to maintain adequate anti-money laundering programs, conduct know-your-customer checks, file suspicious activity reports, and, critically, ensure that they do not facilitate illicit financial flows. That last requirement is the one that matters most as transaction volumes grow and the technology used to move funds becomes faster and more automated. The standard for "defensible" compliance does not change based on which agency's letterhead appears on the rulebook.
Illicit Flows at Machine Speed
The FBI's Internet Crime Complaint Center reported adjusted losses of $893.3 million attributable to AI-nexus crimes in 2025, the first year the agency tracked that specific category. That figure is not a peripheral data point; it illustrates the operational reality that illicit actors are deploying the same automation technology that legitimate institutions are adopting. Transactions originate and settle at volumes that no human review team can monitor in real time. The threat is not theoretical.
This has a direct implication for how compliance programs are designed. Human review alone is no longer sufficient at scale. Institutions are deploying AI agents to screen wallets, execute payments, and file reports at machine speed. That is a rational response to the volume problem, but it creates a compliance question that sits squarely in the domain of crypto accounting software and digital asset accounting software: who is accountable for what the agent does?
Agentic Risk and the Accountability Principle
The accountability question raised by agentic compliance systems is the most consequential one that the failure of the CLARITY Act leaves unanswered at the legislative level, and the one that existing law already answers at the operational level. An agent acting on your behalf does not move your accountability elsewhere. That principle applies whether the agent is a human employee, a third-party vendor, or an AI system executing transactions autonomously.
What Auditable Agentic Compliance Looks Like
For accounting firms and CFOs working with crypto bookkeeping software, the practical implications are concrete. Any AI agent integrated into your compliance stack needs to satisfy three conditions to be defensible under BSA and existing AML standards.
First, the agent must be auditable. Every decision the agent makes, whether to approve a wallet screening, flag a transaction, or generate a report, must produce a record that can be reviewed by a human and presented to a regulator. An agent that operates as a black box is not compliant, regardless of its accuracy rate.
Second, the agent must be accountable. There must be a named human or institutional owner for each agent's outputs. When a SAR is filed by an automated system, the institution filing it remains responsible for the accuracy and adequacy of that filing. The automation does not create a safe harbour.
Third, the agent must be human-governed. Oversight structures need to exist that allow a human compliance officer to intervene, override, or shut down an agent's operations. A system that cannot be overridden is a liability, not an asset, from a regulatory standpoint.
Why the Timing of This Guidance Matters
Elliptic, the blockchain analytics firm that published the source analysis for this article, noted that its guidance on agentic compliance standards was published now rather than later precisely because agentic risk was never going to wait on Washington's calendar. The CLARITY Act vote is the clearest demonstration yet of why firms cannot delay building accountability structures into their automated systems until the legislative environment settles. It may not settle for years.
For firms that have integrated digital asset accounting software with automated screening or reporting functions, the question to ask right now is whether those systems produce the audit trails and governance records that would survive regulatory scrutiny. That question is independent of whether the CFTC or the SEC ultimately holds jurisdiction over a given asset class.
Accounting and Operational Implications for Firms
The shift to agency rulemaking creates a specific set of obligations for accounting practices and finance teams that work with digital assets.
Compliance Program Design Under Regulatory Uncertainty
When the regulatory perimeter is set by statute, a firm can build its compliance program to a known standard. When it is set by rulemaking, litigation, and no-action letters, the program needs to be designed for adaptability. That means modular architecture in your crypto accounting software stack, documented assumptions about jurisdictional classification, and a review cadence that tracks agency rulemaking calendars rather than legislative ones.
It also means that the compliance burden is higher for firms that act as agents or intermediaries for digital asset clients. If you are screening transactions on behalf of a client using an automated tool, your firm is accountable for the adequacy of that screening. The fact that the tool is automated, or that the regulatory perimeter is unclear, does not reduce that accountability. For a deeper look at how blockchain analytics feed into that screening obligation, see our analysis of blockchain analytics and sanctions compliance obligations.
Record-Keeping Requirements
BSA record-keeping requirements remain fully in effect. For institutions using digital asset accounting software that interacts with automated agents, this means that the software's output logs, agent decision records, and any overrides applied by human reviewers all constitute compliance records that may be requested in an examination. Firms should review their data retention policies to ensure that agent outputs are captured and held for the required periods.
Third-Party and Vendor Risk
Many accounting firms and CFOs rely on third-party providers for wallet screening, transaction monitoring, or reporting automation. The accountability principle applies to those relationships as well. Your vendor's agent is still your agent for regulatory purposes. Vendor due diligence processes should include review of the auditability and governance structures of any AI-driven tools embedded in the service, and contractual provisions should address what happens when an agent produces a compliance failure.
What Firms Should Do Before Agency Rulemakings Land
The practical to-do list for compliance-focused accounting firms and CFOs is not long, but each item is substantive.
Review your agentic inventory: identify every automated system in your compliance and accounting stack that makes decisions about transactions, wallets, or reports without real-time human approval. Document who owns each system and what audit trail it produces.
Test your override capability: confirm that each automated agent can be paused or overridden by a named compliance officer within a defined response window. If that capability does not exist, it needs to be built before the next examination cycle.
Map your jurisdictional assumptions: for each digital asset your firm handles, document the current assumption about whether it is a security, a commodity, or an uncategorised asset, and identify the source of that assumption. As agency rulemakings proceed, those assumptions will need to be updated and the change history retained.
Monitor the rulemaking calendar: both the SEC and the CFTC will be publishing notices of proposed rulemaking as they work through digital asset market structure questions. Assign a named owner in your firm to track those publications and assess their impact on your compliance program design.
Source: Elliptic
Frequently Asked Questions
Does the failure of the CLARITY Act change my BSA compliance obligations?
No. The Bank Secrecy Act remains fully in force. BSA obligations, including AML program requirements, KYC checks, and SAR filing, apply regardless of which agency holds primary market-structure oversight over a given digital asset class. The legislative outcome does not create any gap or grace period in those obligations.
Which agency now has oversight over crypto markets in the US?
The SEC has indicated it will assert oversight over digital assets that qualify as securities under existing law, and the CFTC holds authority over derivatives and spot commodity markets. Where a given asset falls between those categories remains to be determined through agency rulemakings, litigation, and no-action letters rather than by statute.
If an AI agent files a suspicious activity report on my behalf, is my firm still liable for its accuracy?
Yes. The institution filing the report remains responsible for its accuracy and adequacy. Automation does not transfer accountability. If the agent produces an inaccurate or inadequate SAR, the regulatory exposure sits with the institution, not with the software.
What records do firms need to keep for AI-driven compliance agents?
Under BSA, standard record-keeping periods apply to compliance records, generally five years. For automated systems, firms should retain agent decision logs, any human overrides, and the parameters the agent was operating under at the time each decision was made. Regulators examining an AML program will want to see that the automated process was governed and auditable.
How should accounting firms adjust their crypto bookkeeping software stack given the regulatory uncertainty?
The key adjustment is designing for adaptability rather than a fixed regulatory assumption. That means documenting the jurisdictional classification assumptions embedded in your workflows, building a review cadence tied to agency rulemaking calendars, and ensuring that any automated components produce audit trails sufficient to demonstrate compliance under either the SEC or the CFTC framework as it eventually develops.
