The United States regulatory perimeter as a set of open questions
Which agency covers what, which questions remain genuinely unsettled, and which parts of the framework have never been in doubt.
The regulatory perimeter is the boundary that decides which activities fall inside a regulated category, which agency supervises them, and which registration or licence is required. For digital assets in the United States, the perimeter is unusual because the statutes predate the technology by decades and were written around intermediaries. The result is a set of specific, identifiable open questions rather than a general absence of law, and separating those questions from the parts that were never in doubt is the useful exercise.
The question that sits under most of the others
Whether a particular token is offered and sold as a security governs almost everything downstream. The test derives from a 1946 Supreme Court decision concerning citrus groves, which held that an investment contract exists where there is an investment of money in a common enterprise with an expectation of profits derived from the efforts of others. The Howey test is applied to the arrangement surrounding an asset, not only to the asset itself, and that distinction does a great deal of work: the same token can be part of an investment contract when sold by a promoter who has made undertakings about future development, and can trade later in circumstances where those undertakings no longer characterize the transaction.
The unresolved part is what happens at the boundary and afterwards. There is no statutory process by which an asset that was distributed as part of an investment contract is recognized as having ceased to be one, no registration form designed for a token distribution, and no disclosure regime tailored to the facts that matter for a network. A registration statement and a prospectus are built around an issuer with financial statements and continuing obligations, which describes some token projects and not others. That mismatch, rather than disagreement about the test itself, is where most of the dispute has been.
Where the agencies clearly sit, and where they do not
| Authority | Clearly within reach | Open question |
|---|---|---|
| Securities regulator | Offers and sales of investment contracts; conduct of registered intermediaries; fraud | Whether secondary trading of a given token is a securities transaction, and how exchange, broker and clearing agency definitions map onto protocols |
| Derivatives regulator | Futures, options and swaps on digital assets; fraud and manipulation in underlying spot markets | Whether it should have registration authority over spot trading venues, which no federal statute currently provides |
| Banking supervisors | Whether banks may custody, hold or issue; capital and liquidity treatment | The conditions for bank participation and how custodied assets appear in a custodian's own financial statements |
| Financial crime authorities | Money transmission registration, anti-money laundering programs, travel rule obligations, sanctions | How obligations designed for intermediaries apply to software developers and non-custodial systems |
| States | Money transmitter licensing, trust charters, consumer protection | The relationship between state licensing and any future federal framework |
The gap in the middle of that table is the structural fact most worth understanding. A spot trading venue for an asset treated as a commodity rather than a security is not, under current federal statutes, subject to a federal registration regime comparable to a securities exchange or a futures exchange. It is regulated primarily through state money transmitter licences and federal financial crime rules. That means the customer protections most people assume exist, including segregation of customer assets, capital requirements, and rules on conflicts between a venue and its own trading arm, have no single federal source. Filling that gap is what market structure legislation proposals are about, and their recurring components are a statutory definition of a digital commodity, a division of jurisdiction between the two market regulators, a registration category for spot venues, and a path by which an asset sold under an investment contract can later trade outside that framework.
Stablecoins and custody
Payment stablecoins raise a narrower and more tractable set of questions, which is why they have consistently been the first candidate for legislation. The recurring items are: who may issue a fiat-backed stablecoin, what the reserve must consist of and how often it is reported, whether holders have a legal right to redeem at par and on what timetable, whether the issuer may pay interest, how federal and state supervisory paths coexist, and what happens to holders if the issuer fails. Those are the design choices any stablecoin legislation has to make, and the differences between proposals are mostly differences in how they answer them. Reserve quality and redemption mechanics are also what determine whether a token holds its peg under stress, which is observable as peg deviation and in aggregate through stablecoin circulating supply.
Custody has its own unresolved thread. The definition of a qualified custodian was written for securities and cash, and applying it to an asset controlled by a key raises questions about what possession means, whether a custodian must be able to demonstrate exclusive control, and how staking or other on-chain activity fits inside a custodial arrangement. A related accounting question concerns whether a firm holding digital assets for customers must present those assets and a corresponding liability on its own balance sheet, a position that supervisory staff adopted and later withdrew, and which had a direct effect on whether regulated banks were willing to offer custody at all.
What has never been unsettled
Three areas have been stable throughout, and conflating them with the open questions produces confusion. Fraud is prosecutable regardless of how an instrument is classified, and most enforcement in the sector has concerned misappropriation, misrepresentation and wash trading rather than classification. Financial crime obligations apply to intermediaries that accept custody of customer assets: know your customer procedures, monitoring, reporting, and sanctions screening are requirements, not preferences. And sanctions law applies to conduct, so dealing with a designated person is prohibited irrespective of the medium.
It is also worth recording that perimeter questions can be resolved by courts rather than by agencies or legislatures. The route by which United States spot bitcoin products reached the market in January 2024 ran through litigation, in which a court held in 2023 that refusing to approve a spot product while approving a futures-based product on the same asset required an explanation the agency had not given. That is a reminder that the perimeter moves through several channels at once, and that a description of it is accurate only as of a date.
The next page in this track turns to the European framework and the wider international picture, which answers several of the same questions in a single instrument. Related material sits in glossary entries on the individual concepts, and the risk pages cover how regulatory change transmits into markets.