BitBullNews Crypto Policy & Regulation Watch – July 21-28: Perimeter Hardens
Content
Crypto regulation moved closer to products and business models this week.
The United States still lacks a completed digital-asset market-structure law. The CLARITY Act remained short of a Senate floor vote through July 27. Yet the absence of legislation did not stop regulators from defining where existing rules may apply.
SEC Commissioner Hester Peirce turned attention to crypto vaults and onchain lending. Her July 22 statement drew a line between software that executes a fixed strategy and managers who select assets, set lending terms or redirect user funds. The more discretion a product contains, the harder it becomes to argue that the arrangement is simply autonomous software.
FINRA reached a different milestone. Its July 24 information-request deadline required every member firm to disclose current and planned crypto activities, including direct access provided through affiliates or external companies. The exercise is not a licensing decision, but it gives FINRA a detailed map of how broker-dealers are entering the market.
Europe and the United Kingdom are further into implementation. ESMA refreshed its MiCA register on July 24, while the FCA confirmed a defined authorization window ahead of the UK regime’s October 2027 commencement. Nexo’s European structure provided a live example of what implementation now looks like: one consumer-facing platform, several regulated service providers and separate products sitting outside the cited authorization scope.
The message across jurisdictions is consistent. Crypto regulation is becoming less concerned with labels and more concerned with functions, counterparties and control.
Weekly Regulatory Scorecard
| Jurisdiction | Development | Status At July 28 | Market Significance |
|---|---|---|---|
| United States | SEC statement on crypto vaults and lending | Commissioner statement published July 22; not a Commission rule | Managed yield products may implicate securities, investment-company and adviser rules |
| United States | CLARITY Act | Advanced from committee 15–9; no Senate floor vote through July 27 | Federal market-structure legislation remains unfinished |
| United States | FINRA crypto activity request | Responses due July 24 from all member firms | Broker-dealer crypto exposure is being mapped at the firm, affiliate and third-party levels |
| European Union | ESMA MiCA register | Updated July 24; five datasets published weekly | Authorization and non-compliance can be checked by legal entity |
| European Economic Area | Partner-based compliance model | Custody, trading and futures can be delivered by different regulated counterparties | Brand-level compliance claims do not define every service’s legal perimeter |
| United Kingdom | FCA crypto authorization gateway | Expected to open September 30, 2026 and close February 28, 2027 | Firms now have a fixed preparation and application timetable |
| United States | OFAC digital-asset sanctions action | Four individuals and nine entities designated July 24 | Screening must cover wallets, affiliates, payment rails and ownership networks |
Sources: SEC, U.S. Senate, FINRA, ESMA, FCA, company legal disclosures and the U.S. Treasury.

The SEC Moved From Tokens To Control
Peirce’s statement did not create a new rule. It did something more useful for product teams: it identified the features most likely to pull a vault or lending strategy inside the federal securities-law perimeter.
Her starting point was straightforward. Moving an activity onchain does not remove legal obligations that would apply to the same economic activity offchain. Tokenized securities remain securities, and a smart contract does not neutralize the role of a manager who decides where user capital goes.
Crypto vaults can sit anywhere on a wide spectrum. At one end, an immutable contract follows a fixed allocation without ongoing human decisions. At the other, a curator selects protocols, reallocates funds, changes risk limits or appoints another party to manage those decisions.
The second model carries more regulatory exposure because users may depend on the managerial efforts of an identifiable operator.
SEC Vault And Lending Perimeter
| Product Design Feature | Potential Regulatory Issue | Evidence A Firm Should Maintain |
|---|---|---|
| Immutable contract with fixed allocation rules | May reduce reliance on ongoing managerial effort, but does not create an automatic exemption | Contract immutability, administrator powers, upgrade controls, fee logic and emergency rights |
| Curator selects or replaces yield strategies | Potential investment-contract and investment-adviser analysis | Investment mandate, decision process, compensation, disclosures and conflicts policy |
| Vault pools assets and invests in securities | Possible investment-company, unit investment trust or managed-fund treatment | Asset classification, portfolio composition, redemption terms and investor eligibility |
| Operator sets interest rates and accepted collateral | Lending arrangements may involve securities or advisory issues | Rate-setting methodology, eligible assets, counterparty criteria and governance records |
| Manager controls loan-to-value and liquidation thresholds | Users may rely on active risk management rather than code alone | Risk models, change logs, approval authority and liquidation procedures |
| Vault holds tokenized securities | Onchain execution does not remove securities-law status | Underlying instrument analysis, transfer restrictions and regulated intermediary roles |
| Loan instrument resembles a note | The lending claim itself may require securities analysis | Borrower purpose, distribution model, maturity, expected return and risk disclosures |
This table summarizes regulatory questions raised by Commissioner Peirce. Her statement is not a Commission rule, order or definitive legal classification of any specific product.

The Word “DeFi” Does Not Set The Legal Perimeter
The industry often treats decentralization as a binary condition. The SEC statement points toward a functional test instead.
A product may execute through smart contracts while still relying on a small group to:
- Select the available strategies.
- Change collateral requirements.
- Set borrowing costs.
- approve upgrades.
- control emergency functions.
- receive performance-linked compensation.
Those facts can matter more than whether the interface uses the words “vault,” “protocol” or “DeFi.”
For compliance teams, the immediate task is not to decide whether a product is decentralized in the abstract. It is to map every decision right.
Who can change the code? Who selects protocols? Who receives fees? Who can freeze withdrawals? Who decides when an asset becomes unacceptable collateral? Those answers reveal where managerial reliance and regulatory responsibility sit.
The statement also matters for tokenized funds. A vault that automatically allocates into tokenized securities may still resemble an investment company or separately managed account, even when portfolio execution occurs entirely onchain.
CLARITY Remained Stuck Between Committee And The Floor
The Senate Banking Committee advanced the CLARITY Act by a 15–9 vote on May 14, sending the bill toward the Senate floor. The official Senate roll-call record through July 27 showed votes on nominations and another resolution, but no floor vote on the digital-asset market-structure bill.
That distinction matters. Committee passage shows that a bill has enough support to continue. It does not establish final language, a floor coalition or an enactment date.
The negotiation also moved beyond the original division of responsibility between the SEC and CFTC.
New crypto ethics language was released on July 22. Senate Banking Committee minority staff issued a sharply critical fact sheet arguing that the proposal contained enforcement and conflict-of-interest loopholes. That document represents the minority staff’s political and legal analysis, not a neutral regulatory determination. Its existence nevertheless confirms that public-official ethics remains part of the legislative negotiation.
The unresolved package now includes several distinct debates:
- SEC and CFTC jurisdiction.
- Treatment of decentralized protocols and software developers.
- Stablecoin rewards and yield products.
- Anti-money-laundering obligations.
- Customer-asset protections.
- Ethics and conflicts involving government officials.
- The relationship between a future statute and ongoing agency interpretations.
The market should therefore treat CLARITY as a legislative asset with uncertain duration, not as an enacted framework.

FINRA Built A Broker-Dealer Crypto Map
FINRA’s July 24 deadline marked a shift from policy discussion to supervisory inventory.
The regulator asked all member firms to report their current and planned crypto activities. FINRA said it intends to use the information to adapt regulatory programs, modernize oversight, support compliance and identify industry trends. Firm-specific responses will remain private, although FINRA may publish anonymized aggregate findings.
The request also clarified several definitions that firms had interpreted inconsistently.
Allowing clients to buy crypto ETFs does not, by itself, mean a broker provides direct crypto trading or custody. Providing access to Bitcoin or Ether through an affiliate does fall within FINRA’s third-party activity question. Making an ETF available to customers also does not make the broker an authorized participant; that term applies to firms that create and redeem fund shares directly in the primary market.
FINRA Crypto Activity Map
| Business Activity | FINRA Treatment In The Request | Supervisory Implication |
|---|---|---|
| Direct crypto trading through an affiliate | Report as third-party crypto trading access | Affiliate structure does not remove the activity from the firm’s regulatory inventory |
| Third-party custody of Bitcoin or Ether for brokerage customers | Report as crypto custody access | Vendor governance and customer disclosures become examination issues |
| Customer access to crypto ETFs | Not treated as direct crypto trading or custody for the relevant checkbox | Securities-product distribution remains distinct from direct asset activity |
| Acting as an ETF authorized participant | Report only when the firm creates or redeems shares directly with the fund | Primary-market operations must be separated from ordinary brokerage access |
| Planned crypto products or services | Included alongside current activities | Supervisors are mapping future exposure before products launch |
| Firm-level responses | Not publicly disclosed by FINRA | Responses may become a baseline for future risk monitoring and examinations |
| Industry-wide results | May be published in aggregate | Market participants may eventually receive a clearer view of broker-dealer adoption |
Source: FINRA’s 2026 Crypto Asset Activity Information Request and published FAQs.
The practical risk is inconsistency.
A firm’s FINRA submission should match its board materials, product roadmap, affiliate agreements, public marketing and vendor inventory. A business unit describing an arrangement as “ETF access” while another document describes direct crypto execution could create a credibility problem during examination.
The same applies to plans. FINRA asked about both current and intended activity. A firm that later launches a crypto service omitted from its response may need to explain when the plan changed and how compliance reviewed it.
MiCA Compliance Became A Legal-Entity Exercise
ESMA updated its interim MiCA register on July 24.
The register contains five separate datasets covering non-stablecoin white papers, asset-referenced-token issuers, e-money-token issuers, authorized crypto-asset service providers and non-compliant entities. ESMA publishes updates weekly using information supplied by national competent authorities and the European Banking Authority.
The weekly schedule creates a practical limitation. A national authorization or withdrawal may appear in a domestic register before it reaches ESMA’s central files. Companies, counterparties and journalists should therefore check both the ESMA register and the relevant national regulator when timing matters.
The register also does not approve the contents of listed crypto-asset white papers. ESMA states that responsibility remains with the issuer or offeror. Inclusion proves that a document has been notified and recorded; it does not function as an investment endorsement.
The more difficult issue is service scope.
A group may operate a recognized brand while several legal entities provide custody, execution, transfer, derivatives or lending. Saying that a platform is “MiCA-aligned” does not identify which company is regulated or which services fall within its permission.
EEA Service-Perimeter Case Study
| Customer-Facing Service | Publicly Identified Provider | Authorization Basis Cited By Nexo | Scope Note |
|---|---|---|---|
| Crypto custody and administration | Tangany GmbH | MiCAR authorization and BaFin supervision | Tangany is identified as the regulated counterparty for custody and crypto-asset transfers |
| Crypto-asset transfers | Tangany GmbH | MiCAR authorization | Coverage applies to the stated transfer service, not automatically to every product on the platform |
| Spot trading through “Exchange On Nexo” | DLT Securities GmbH, branded as DLT Finance | MiCAR and MiFID II authorization | DLT Securities is identified as the regulated execution counterparty |
| Perpetual futures execution | DLT Securities GmbH | MiFID-related investment-firm permissions | Derivatives exposure sits under a different legal framework from spot crypto custody |
| Margin collateral administration for perpetuals | Tangany GmbH | Tangany’s regulated custody role | Custody of collateral does not make the underlying derivative a MiCA product |
| Earn rewards | Separate Nexo product | Outside the cited Tangany and DLT authorizations | Nexo states that Earn is not deposit-taking and is outside MiCAR |
| Crypto-backed borrowing | Separate Nexo product | Outside the cited Tangany and DLT authorizations | Nexo states that Borrow is not covered by those authorization or protection schemes |
The table reflects Nexo’s public EEA disclosures. It does not replace verification through ESMA, BaFin or the relevant contractual documentation.

Partner-Based Compliance Is Becoming A Market Structure
The Nexo example illustrates a model likely to become more common in Europe.
A consumer may experience one interface, account history and brand relationship. Behind that interface, different regulated entities perform different functions. This allows a platform to maintain distribution while outsourcing regulated execution or custody to authorized specialists.
The model can accelerate market access, but it creates additional counterparty and disclosure risk.
Customers need clear answers to four questions:
- Which legal entity holds the assets?
- Which company executes each transaction?
- Which regulator supervises that specific activity?
- Which products sit outside the authorization being advertised?
The fourth question is the most important. Nexo’s own disclosure separates Earn and Borrow from the MiCA and MiFID authorizations cited for custody, trading and futures. It also states that those products are not covered by deposit-guarantee or investor-compensation schemes.
This does not mean the separate products are unlawful. It means the regulatory protection attached to one service should not be assumed to cover another.
The United Kingdom Has The Clearest Clock
The UK still has more than a year before its new crypto regime begins, but firms already know the expected sequence.
The FCA published final rules and guidance on June 30 for firms that receive permission under the Financial Services and Markets Act. The broader regime is expected to commence on October 25, 2027. It will move UK crypto supervision beyond the existing anti-money-laundering and financial-promotion framework into authorization, prudential standards, custody, market conduct and operational resilience.
The authorization gateway is expected to open on September 30, 2026 and close on February 28, 2027. Existing FCA anti-money-laundering registration will not convert automatically into FSMA authorization. Already-authorized financial firms will need to vary their permissions for crypto activities.
United Kingdom Implementation Calendar
| Date Or Stage | Requirement | Consequence For Firms |
|---|---|---|
| June 30, 2026 | FCA published final rules and guidance | Firms can begin designing applications against a defined rule package |
| September 30, 2026 | Expected authorization gateway opening | New applicants may apply; existing FSMA firms may submit permission variations |
| February 28, 2027 | Expected gateway closing date | Applications after this point lose the benefit of the standard application-period route |
| Before October 25, 2027 | FCA assesses applications and permission variations | Firms should maintain evidence on governance, capital, safeguarding and operational resilience |
| October 25, 2027 | New crypto regime expected to commence | In-scope activity requires appropriate FSMA authorization or a valid statutory transition |
| On-Time Application Still Pending | Saving provision may allow continued service | Firm may continue while the application or qualifying appeal remains unresolved |
| Late Application Still Pending | Transitional provision applies at commencement | Firm may service pre-existing contracts but cannot enter new UK customer contracts |
| No Application | Business must be run off before commencement | Continued in-scope activity could breach the UK general prohibition |
Sources: FCA crypto-regime and authorization-gateway guidance.

The UK timetable changes the operational conversation.
U.S. firms are still waiting to see whether Congress completes the market-structure framework. UK firms already need to prepare legal-entity charts, financial projections, safeguarding systems, senior-manager responsibilities and product-level permission maps.
The application form was still being finalized when the FCA published its gateway guidance, but the regulator had already released an information document and financial-data template showing the expected scope of submissions.
Waiting until the gateway opens would leave firms only five months to assemble a full application.
OFAC Showed That Enforcement Remains Network-Based
The week’s enforcement action came from the U.S. Treasury rather than a market regulator.
On July 24, OFAC designated four individuals and nine entities connected to the sanctions-evasion network of Iranian financier Babak Zanjani. Treasury said the wider operation included financial services, digital-asset trading, gold and precious gems, transportation and infrastructure businesses.
The action targeted entities supporting the previously designated digital-asset exchanges Zedcex and Zedxion. OFAC said addresses attributed to the exchanges had processed funds on behalf of wallets attributed to Iran’s Islamic Revolutionary Guard Corps.
The network extended beyond exchange wallets.
Treasury described Zedpay as an integrated wallet, transfer and fiat-settlement provider for Zedxion. It also identified corporate entities that supported exchange infrastructure or interacted with associated wallets.
The compliance lesson is broader than screening an exchange name against a sanctions list.
A defensible control framework should cover:
- Designated wallet addresses.
- Newly generated addresses linked through transaction behavior.
- Corporate owners and controlled entities.
- Integrated payment and settlement providers.
- Executives and beneficial owners.
- Tokens or NFT projects connected to the sanctioned network.
- Cross-border counterparties providing technical or financial support.
The policy environment may be becoming more supportive of regulated crypto activity. Illicit-finance enforcement is not becoming softer.
What Compliance Teams Should Do Now
Map Every Decision Right Inside Yield Products
Vault operators should document who can select strategies, change contracts, set fees, modify risk parameters and stop withdrawals.
The legal analysis should reflect actual control, not the decentralization language used in marketing.
Reconcile FINRA Responses With Internal Records
Broker-dealers should compare their submitted activity inventory with board papers, affiliate agreements, vendor contracts, public websites and product roadmaps.
Future examinations may test whether the firm’s regulatory submission matched what the business was building.
Verify MiCA At The Service Level
A brand name is not a regulatory permission.
Before relying on a MiCA claim, identify the contracting entity, the exact authorized service and the responsible national regulator. Check ESMA and national registers, allowing for ESMA’s weekly publication lag.
Separate Regulated Services From Adjacent Products
Custody authorization does not automatically cover lending. A trading permission does not necessarily cover yield products. MiFID derivatives execution and MiCA spot-asset services should not be presented as the same regulatory protection.
Start UK Applications Before The Gateway Opens
The FCA expects applications to be tailored to each business model. Firms should complete their activity classification, legal opinions, governance map, prudential forecasts and safeguarding design before September 30.
Screen Networks, Not Only Names
OFAC’s action shows how exchanges, wallets, payment companies, affiliated businesses and token projects can form one sanctions-evasion system.
Transaction monitoring should connect blockchain activity with ownership and corporate-intelligence data.
Regulatory Risk Dashboard
| Signal | Current Reading | Interpretation | Confirmation Needed |
|---|---|---|---|
| U.S. Market-Structure Legislation | No Senate floor vote through July 27 | Statutory jurisdiction remains unresolved | Scheduled floor action and final negotiated text |
| CLARITY Committee Status | Advanced 15–9 on May 14 | Bipartisan support exists but is insufficient for enactment | Senate passage and reconciliation with the House |
| Crypto Ethics Negotiation | New language released July 22 and contested by minority staff | Ethics remains part of the legislative coalition problem | Bipartisan enforcement and conflict-of-interest framework |
| SEC Vault Guidance | Commissioner statement, not binding rule | Regulatory attention is moving toward control and managerial discretion | Commission-level guidance, rulemaking or adjudication |
| Managed Onchain Lending | Rates, LTV and liquidations may be actively controlled | “DeFi” branding does not remove potential adviser or securities issues | Product-specific legal analysis |
| FINRA Information Request | Responses due July 24 from all member firms | Broker exposure is now documented across current and planned activity | Aggregate findings or updated examination priorities |
| ESMA MiCA Register | Updated July 24 and published weekly | EU authorization is increasingly verifiable by entity | Reconciliation with national registers and service scope |
| Partner-Based EU Models | Custody, trading and lending may sit with different entities | One platform can contain several regulatory perimeters | Clear contracts and customer disclosures |
| UK Authorization Gateway | September 30, 2026–February 28, 2027 | Implementation timetable is fixed and approaching | Final application readiness and FCA processing capacity |
| UK Regime Commencement | Expected October 25, 2027 | Existing AML registration will not be enough | FSMA permission for each regulated activity |
| Digital-Asset Sanctions Risk | Four people and nine entities designated July 24 | Enforcement targets networks rather than isolated wallets | Continuous affiliate, ownership and wallet monitoring |
The regulatory perimeter hardened this week without a major new crypto law.
The SEC’s focus moved toward vaults, lending strategies and managerial control. Commissioner Peirce’s statement was not binding rulemaking, but it made the analytical direction clear: putting an investment or lending process inside a smart contract does not remove federal securities-law questions.
CLARITY remained unfinished. The Senate Banking Committee had already advanced the bill, but the official floor record showed no vote through July 27. Ethics language added another contested issue to a negotiation already covering agency jurisdiction, DeFi, stablecoin rewards and customer protection.
FINRA moved faster than Congress. Its information request gave the regulator a firm-by-firm inventory of direct crypto access, affiliate models, third-party custody and planned activity. That data can shape future supervision before the statutory market-structure framework is complete.
Europe is operating on a different timetable. ESMA’s MiCA register now provides a regularly updated authorization and non-compliance record. The Nexo structure shows what this means in practice: one interface, regulated custody and execution partners, and separate lending and yield products outside the authorizations cited for other services.
The UK has gone further in implementation planning. Its gateway opens in September, closes in February and leads toward an October 2027 regime. Firms know when to apply and what happens if they apply late or not at all.
OFAC supplied the final warning. Regulatory openness and sanctions enforcement can advance at the same time. Legal crypto activity is gaining clearer routes into financial markets. Networks tied to illicit finance are being mapped across exchanges, wallets, affiliates and settlement providers.
The winning compliance model will not rely on a license headline. It will show, service by service, who controls the product, who holds the assets, who executes the transaction and which regulator stands behind each activity.
Data Sources & References
- SEC — Statement On Crypto Vaults And Lending Strategies
- Senate Banking Committee — CLARITY Act Committee Vote
- U.S. Senate — Recent Roll-Call Votes
- Senate Banking Minority Staff — Crypto Ethics Fact Sheet
- FINRA — 2026 Crypto Asset Activity Information Request
- ESMA — Markets In Crypto-Assets Regulation And Register
- Nexo — EEA Product And Regulatory Disclosures
- FCA — New Cryptoasset Regulatory Regime
- FCA — How The Cryptoasset Gateway Will Operate
- U.S. Treasury — July 24 Digital-Asset Sanctions Action