Revised CLARITY Act Targets Non-Decentralized DeFi Operators
A revised version of the CLARITY Act, published ahead of a procedural Senate vote scheduled for 15 September, would require US regulators to determine whether people or groups controlling so-called "non-decentralized finance trading protocols" must comply with securities, commodities, and anti-money laundering rules. For accounting firms, auditors, and CFOs with DeFi exposure, the revision matters because it draws a regulatory line directly through the question of control, a concept with immediate implications for how those protocols are classified, recorded, and screened on your books.
What the Revised Text Actually Says
The updated language, published on Senator Cynthia Lummis's website, defines a "non-decentralized finance trading protocol" as one where functionality, operation, or rules can be materially altered by a single person or a coordinated group. The definition also captures protocols whose controllers can restrict user access, or whose transactions are not governed solely by transparent, pre-established code running on-chain.
The Control Test and Why It Is Pivotal
That definition is doing a great deal of legal work. A protocol does not need to be custodial to fall inside it. If a multisig council, a foundation, or a core developer team retains the practical ability to upgrade contracts, pause activity, or exclude participants, the protocol may qualify as "non-decentralized" under the bill's terms. For firms assessing counterparty risk in DeFi positions, that is the key threshold to map against existing holdings and integrations.
The revised text includes two specific carve-outs. First, software and distributed ledger systems would not be required to register in their own capacity, meaning the code itself is not the regulated entity. Second, participation in an incident-response or security council would not, by itself, constitute control. Those carve-outs will matter to legal teams drafting governance frameworks, but they are narrow and do not resolve the broader question of where the control line sits in practice.
Regulatory Assignments: SEC, CFTC, and Treasury
Under the proposal, the Securities and Exchange Commission and the Commodity Futures Trading Commission would each develop activity-based rules covering registration, conduct, disclosure, recordkeeping, and supervision for affected protocol operators. The precise split of jurisdiction between the two agencies, a long-running source of friction in US digital asset policy, is not resolved in the bill itself but delegated to rulemaking.
Bank Secrecy Act Obligations via Treasury
Separately, the Treasury Department would establish how existing Bank Secrecy Act obligations apply to controllers of non-decentralized protocols. That is a material addition. BSA obligations include customer identification, suspicious activity reporting, and recordkeeping requirements that most DeFi operators have not historically implemented. If Treasury determines that a protocol's controller meets the definition, those obligations would attach to the individual or group running it, not to the smart contract.
For compliance teams, this creates a two-track monitoring problem: tracking which protocols in a firm's portfolio have identifiable controlling parties, and then assessing whether those parties are meeting or are likely to meet BSA standards. Firms already using crypto accounting software to track on-chain positions will need to layer AML status flags alongside price and volume data.
Where the Senate Vote Stands
The procedural vote scheduled for 15 September requires Republican senators to attract Democratic support, and that support remains uncertain. Three specific fault lines have slowed progress: ethics restrictions on lawmakers holding digital assets, the strength of anti-money laundering protections in the bill, and rules around stablecoin yield.
Ethics Provisions: Largely Unchanged
Despite being cited as a central sticking point, the ethics section in the revised text remained largely unchanged from the prior version. Senator Ruben Gallego, a Democrat, indicated in August that he would not support advancing the bill until lawmakers resolved disputes over both ethics and stablecoin yield provisions. His stated position at that time was direct: a fast vote might produce a fast result, but not necessarily the right one.
Industry Signals
Crypto Council for Innovation CEO Ji Hun Kim described the September vote as a "pivotal moment" for digital assets, innovation, and American leadership, and argued that the US needs a framework combining consumer protections with business conduct standards. Coinbase's CEO Brian Armstrong said publicly that the bill was ready for a positive vote and that the must-have issues his firm had previously raised had been resolved, while ethics negotiations remained active and appeared close to a conclusion. Armstrong did not specify which provisions changed, and the published text does not reflect that claim in the ethics section.
The Fallback Scenario
Armstrong also noted that if the legislation does not advance, the SEC and CFTC retain the ability to pursue rulemaking and innovation exemptions using their existing authority. That path would be slower, less predictable, and potentially more fragmented across the two agencies, making planning for firms with DeFi-facing operations considerably harder in the near term.
Accounting and AML Implications for B2B Readers
The revised CLARITY Act does not create obligations today. It is proposed legislation at a procedural stage. But the direction it signals is clear enough to inform current work.
Reclassification Risk for DeFi Holdings
If a DeFi protocol in a firm's portfolio is subsequently determined to be "non-decentralized" under the eventual regulatory framework, its classification may need to change. A protocol that looked like a decentralized infrastructure holding could attract the regulatory treatment of a registered trading venue or broker. That shift has direct consequences for how positions are measured, disclosed, and stress-tested under both US GAAP and IFRS.
Accounting teams should begin documenting the governance structures of material DeFi exposures now, specifically noting whether any identifiable party holds upgrade keys, admin roles, or pause authority. That documentation will be necessary for any future classification defence and feeds directly into the kind of disclosure narratives auditors will scrutinise.
BSA Readiness for Protocol Operators
For clients who are themselves operators of DeFi protocols with governance controls, the Treasury track in this bill deserves immediate attention. If Treasury concludes that a protocol's controller qualifies as a financial institution under BSA, that operator would need a customer identification programme, transaction monitoring, and SAR filing capability. None of those are trivial to implement in a DeFi context, and the lead times involved mean preparation should start well before any final rule is published.
Digital Asset Accounting Software and Audit Trails
Whatever the legislative outcome, one practical implication is already visible: firms need crypto accounting software and digital asset accounting software capable of tagging positions by governance profile, not just by asset type or price. If a holding changes its regulatory status because its controlling party comes into scope, the accounting treatment may need to be restated retroactively. Clean, structured data from the point of acquisition makes that exercise manageable. Retrofitting it after a rule drops is significantly more costly.
Firms that have already built out structured on-chain data capture, wallet-level tagging, and counterparty profiling, as part of OFAC or BSA compliance work, are better positioned than those who have not. The CLARITY Act's AML provisions are an extension of the same logic applied to protocol-level exposure.
What to Watch Before and After 15 September
The procedural vote is not a final passage vote. Even if the motion to proceed clears, the bill will face further amendment, negotiation, and potentially a conference process before it could be enacted. The ethics section alone has enough unresolved tension to extend that timeline. Firms should treat the September vote as a signal rather than a trigger, but a strong signal is still worth acting on.
Key Indicators to Track
Watch for three things in the days immediately following the vote. First, whether Democratic co-sponsors emerge, which would indicate the ethics and AML gaps have narrowed materially. Second, whether Treasury issues any guidance or public comment on its BSA mapping exercise, which would provide earlier clarity on the compliance threshold. Third, whether the SEC or CFTC signals any parallel rulemaking activity, particularly if the vote fails, which would indicate the regulatory timeline accelerates through the agencies rather than Congress.
The legislative outcome matters, but the direction of travel on DeFi governance and AML has been set. Whether the CLARITY Act becomes law in its current form, is amended, or triggers agency rulemaking as an alternative, US regulators are working toward a framework that treats control over a DeFi protocol as a regulated function. Firms that treat that conclusion as a planning assumption now, rather than waiting for final rules, will carry less remediation risk when those rules land.
For earlier context on the CLARITY Act's legislative background and what Treasury's push for passage signalled, see our earlier coverage: Bessent Presses Senate to Pass the CLARITY Act. For the AML enforcement environment that surrounds this debate, our piece on OFAC Sanctions and Xinbi Guarantee: What the $8.4B Illicit Marketplace Means for Crypto Accounting provides useful parallel context.
Frequently Asked Questions
Does the revised CLARITY Act create compliance obligations right now?
No. The bill is proposed legislation and had not passed as of the publication date of this article. However, it signals the direction of US regulatory intent clearly enough to warrant preparatory work, particularly governance documentation and AML readiness assessments for firms with DeFi exposure.
How does the bill define a "non-decentralized" protocol?
Under the revised text, a protocol qualifies as non-decentralized if its functionality, operation, or rules can be materially altered by a person or coordinated group; if its controllers can restrict user access; or if its transactions are not governed solely by transparent, pre-established code. It is a control-based definition, not a custody-based one.
Would smart contracts themselves need to register?
The bill explicitly carves out software and distributed ledger systems from registration requirements. The regulated entity, if the bill passes, would be the human or group exercising control, not the code itself.
What Bank Secrecy Act obligations could apply to DeFi protocol controllers?
The bill directs Treasury to determine how existing BSA obligations map to controllers of non-decentralized protocols. BSA obligations can include customer identification programmes, transaction monitoring, recordkeeping, and suspicious activity reporting. Treasury's determination would define the specific scope.
How should accounting firms prepare their crypto bookkeeping software and workflows now?
Firms should start tagging DeFi positions in their digital asset accounting software by governance profile, noting whether any identifiable party holds admin, upgrade, or pause authority over the protocol. That structured data will be essential for reclassification analysis, audit defence, and AML status monitoring if and when final rules are published.
Source: Cointelegraph
