()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.

Crypto firms still face full AML rules after CLARITY Act vote

Lawrence Mondal
Edited by
News
Crypto firms still face full AML rules after CLARITY Act vote - 1

The Senate’s failure to advance the CLARITY Act has left existing customer identification, anti-money laundering, sanctions, and suspicious activity reporting requirements unchanged for covered U.S. crypto businesses.

Summary
  • The failed Senate vote has not altered existing Bank Secrecy Act obligations for covered crypto companies.
  • Sponsor banks expect identity, wallet, and transaction controls to remain connected throughout the customer relationship.
  • Self-custodial wallet users can be verified at access points without placing personal information on-chain.
  • AI agents require limited, revocable authority tied to an identifiable person or company.

CLARITY Act vote leaves existing AML duties intact

Prove Global Head of Digital Assets and Sponsor Banks Fernando Castellanos told crypto.news that the bill dealt mainly with market structure and would not have replaced the Bank Secrecy Act requirements already imposed on covered crypto businesses.

Customer identification, beneficial ownership checks, sanctions screening, AML controls and suspicious activity monitoring remain in force, according to Castellanos. Crypto companies must also continue filing required reports when their systems detect activity that meets applicable reporting standards.

“The failed vote does not change the compliance obligations that already apply to covered crypto businesses,” Castellanos said.

“Market structure legislation was never going to displace the Bank Secrecy Act; it would have clarified which regulator sits on top of it.”

On Sep. 15, the Senate rejected cloture on the motion to proceed with H.R. 3633, the House version of the Digital Asset Market Clarity Act. The failed procedural vote received 49 votes in favor and 50 against, leaving the measure 11 votes below the 60 required to open debate.

The result did not amount to a final vote on the bill itself. Seven Democratic senators who opposed cloture later described the outcome as “not the end” and said they remained committed to bipartisan negotiations. No second vote has been scheduled, although the seven Democrats reopened talks as lawmakers continued to dispute ethics provisions covering elected officials and their digital asset interests.

While the bill remains unresolved, Castellanos said moving funds through blockchain networks does not remove the need to determine who controls an account or stands behind a transaction. Faster settlement and transactions that are difficult to reverse leave firms with less time to identify suspected fraud or illicit activity.

“If anything, it raises the bar,” he said. “As stablecoins and other digital assets make payments faster and harder to reverse, the window to catch a problem gets smaller.”

According to Castellanos, firms must therefore maintain identity and risk checks after onboarding instead of treating verification as a one-time step. Changes in account behavior, wallet activity, or transaction patterns can alter the risk attached to an existing customer.

Sponsor banks expect connected crypto risk controls

When sponsor banks assess a crypto company, Castellanos said they examine controls across the entire customer and transaction lifecycle. Reviews commonly cover customer and business verification, beneficial ownership, sanctions screening, fraud prevention, wallet screening and transaction monitoring.

Banks also seek evidence that each control works under actual operating conditions, rather than relying solely on written compliance policies or tests conducted before launch. Castellanos said separate tools can create blind spots when identity, wallet and transaction data do not flow into the same risk process.

“A bank needs confidence that you know who is behind an account or a wallet, and that you will see it when that risk profile changes.”

Under the proposed CLARITY framework, federal oversight would be divided between the Securities and Exchange Commission and the Commodity Futures Trading Commission. The bill’s split federal oversight would place qualifying digital commodities and registered spot-market intermediaries under CFTC supervision while preserving SEC authority over securities and related transactions.

Such a division would answer which federal regulator supervises certain assets and activities, but it would not erase separate compliance layers. State money-transmitter licensing, federal sanctions rules and existing obligations for covered financial institutions could still apply depending on a company’s services and customers.

For sponsor banks, connected controls help determine whether an account or wallet still belongs to the verified party and whether later activity matches the customer’s expected use. Castellanos said firms can reduce friction for legitimate users by combining several risk signals instead of repeatedly asking customers to complete isolated checks.

DeFi identity checks can remain off-chain

Verification for self-custodial wallets and decentralized finance does not require personal information to be written to a public blockchain, according to Castellanos. Firms can perform checks at points where regulated companies already interact with users, including fiat on-ramps, off-ramps, application interfaces and other access points.

Keeping names, identification documents and other sensitive records outside public ledgers avoids exposing information that cannot later be removed. Regulated companies can still retain the records needed to meet their obligations within controlled systems.

Castellanos said counterparties also do not need every piece of information collected during verification. A firm may only need confirmation that a user has passed an identity check, controls a stated wallet or does not appear on a sanctions list.

“Confirming a claim, rather than handing over the underlying data, is what lets firms meet their obligations without putting personal information on-chain or forcing open software to behave like a conventional intermediary.”

Such an approach separates a protocol’s open-source code from the compliance duties of regulated companies using interfaces or payment rails around it. Castellanos said the objective is not to treat every self-custodial wallet like a bank account, but to establish enough verified information around a regulated interaction to manage its identified risks.

The CLARITY proposal addressed related questions through registration exemptions for some DeFi software developers, wallet providers and validator operators. Its failure to advance means firms must continue applying existing law while Congress, the SEC and the CFTC consider how decentralized services fit within U.S. financial rules.

AI agents require limited and revocable authority

Identity controls become more complex when an AI agent opens an account, trades assets or initiates a payment for a person or company. Castellanos said institutions must establish who controls the agent, who approved a specific action, and what the software is permitted to do.

Each question requires a separate check. Verifying the human or business behind an agent establishes accountability, while an authorization process determines whether the agent has permission to initiate the transaction under review.

According to Castellanos, such authority should be limited in scope, bound to a set period, and capable of being withdrawn. Institutions should verify permission when a transaction occurs instead of relying on an approval granted earlier, especially when software can move funds without fresh human input.

The issue has become more immediate as U.S. crypto platforms add tools for machine-directed finance. In June, the Coinbase for Agents launch allowed authorized software agents to trade crypto, manage portfolios, make payments and perform financial tasks through user accounts.

Coinbase said users can set rules for portfolio rebalancing, trade execution and position management. Its x402 protocol also allows agents to pay for data, research, application programming interfaces and computing services without direct human involvement in each payment.

For financial institutions supporting similar services, Castellanos said authorization must connect the transaction to the responsible human or company. The record should identify the principal, the agent, the approved action and the limits applied when the transaction was initiated.

“As agents begin interacting with financial systems and moving money autonomously, there needs to be a clear, verifiable chain connecting the person, the business, the agent and the transaction,” he said.

Castellanos said institutions will need to move from verifying a customer once to continuously checking who has authority to act and whose funds or account an AI agent is using.