The legislative landscape for digital assets in the United States is currently defined by a high-stakes debate over where the line should be drawn between software development and financial intermediation. At the heart of this controversy is Section 109 of the House-passed CLARITY Act, a provision derived from the Blockchain Regulatory Certainty Act (BRCA). This specific section has become a focal point for a broader philosophical and legal clash regarding the principle that accountability should follow power. While critics argue that the provision creates dangerous loopholes for illicit activity, proponents maintain it is a necessary codification of long-standing regulatory boundaries that distinguish those who control financial assets from those who merely provide the technological tools for others to use.
The Functional Test of the CLARITY Act
The CLARITY Act seeks to establish a comprehensive federal framework for the regulation of digital assets, with a particular focus on payment stablecoins and the broader blockchain ecosystem. Section 109, which mirrors the language of the BRCA, introduces a functional test to determine when a developer or service provider should be classified as a regulated financial institution. Under this test, a developer is considered "non-controlling" if, in the regular course of business, they lack the legal right or the unilateral, independent ability to control, initiate, or effectuate transactions involving a user’s assets without that user’s specific approval.
This distinction is critical because it shifts the regulatory focus from the "status" of an entity to its actual "conduct." In the traditional financial system, intermediaries like banks and payment processors (such as Visa or Mastercard) have the power to freeze accounts, reverse transactions, and monitor every movement of capital. Because they possess this power, they are burdened with significant regulatory obligations under the Bank Secrecy Act (BSA) and Anti-Money Laundering (AML) statutes. The CLARITY Act argues that developers of open-source software, self-custody wallets, and decentralized infrastructure do not possess this same power and, therefore, should not be held to the same standards as centralized financial intermediaries.
A Chronology of Regulatory Guidance and Precedent
The debate over developer liability is not new; it is the continuation of a dialogue that began at the dawn of the commercial internet. Understanding the current legislative push requires a look at the historical timeline of how the U.S. government has viewed software and financial transmission.
1996–1997: The Clinton Administration’s Framework
During the early years of the World Wide Web, the Clinton administration released the "Framework for Global Electronic Commerce." This directive urged the federal government to recognize the decentralized nature of the internet and avoid "inflexible and highly prescriptive regulations" that could stifle innovation. This era established the precedent that infrastructure providers should not be held automatically liable for the actions of their users—a principle that enabled the growth of the modern digital economy.
2014: FinCEN’s Initial Software Ruling
As Bitcoin and other cryptocurrencies began to gain traction, the Financial Crimes Enforcement Network (FinCEN) issued an administrative ruling clarifying that the mere production and distribution of software does not, in and of itself, constitute the acceptance and transmission of value. This established a clear boundary: writing code is an act of expression and engineering, not a financial service.
2018: The FOSTA-SESTA Amendment to Section 230
The debate over intermediary liability reached a fever pitch with the passage of FOSTA-SESTA, which carved out an exception to Section 230 of the Communications Decency Act regarding sex trafficking. While intended to combat crime, a subsequent report by the Government Accountability Office (GAO) found that the move led many platforms to move overseas, fragmented the market, and actually made it harder for law enforcement to gather intelligence. This served as a cautionary tale for those looking to impose sweeping liability on technology providers.
2019: Reaffirmation of Activity-Based Regulation
FinCEN released updated guidance in 2019, reaffirming that the application of money-transmission laws depends on the underlying activities a person performs, rather than the label of the technology they use. This guidance remained consistent across both Democratic and Republican administrations, emphasizing that developers of unhosted wallets or decentralized protocols are generally not "money transmitters."
Supporting Data and the "Liability Follows Proximity" Risk
Critics of the CLARITY Act, most notably former National Security Council official Carole House, argue that the "accountability follows power" slogan is being misused to shield powerful software systems from oversight. House suggests that every powerful software system should have an identifiable intermediary that the government can compel to monitor and control its users.
However, data from the blockchain industry suggests that forcing reintermediation could have the opposite of its intended effect. Truly decentralized systems like Bitcoin or Ethereum operate on global, open-source protocols where no single entity has the power to censor transactions or freeze assets. If the U.S. mandates that all such software must include a "kill switch" or a centralized controller, developers would likely move their operations to jurisdictions with more favorable laws. This "regulatory arbitrage" would deprive U.S. law enforcement of the transparency that public blockchains currently provide.
Furthermore, the analogy often drawn between blockchain developers and "hawala" networks (informal value transfer systems) is viewed by proponents of the BRCA as flawed. Hawala networks rely on a coordinated network of human agents who exercise ongoing power over transfers. In contrast, a developer who publishes a self-custody wallet provides a tool that allows a user to interact directly with a blockchain. Once the software is released, the developer often has no ongoing relationship with the user and no ability to intervene in their transactions.
Official Responses and Agency Authorities
It is a common misconception that the CLARITY Act or the BRCA would grant total immunity to the crypto industry. The legislative text explicitly preserves the authority of major federal agencies to combat illicit activity.
The House-passed version of the CLARITY Act preserves the anti-fraud and anti-manipulation authorities of the Securities and Exchange Commission (SEC) and the Commodity Futures Trading Commission (CFTC). According to an overview provided by the nonpartisan Congressional Research Service (CRS), while certain decentralized finance (DeFi) activities are excluded from specific registration requirements, they remain subject to strict enforcement regarding market integrity and consumer protection.
Moreover, the CLARITY Act actually expands the regulatory net by creating new categories of federally regulated crypto intermediaries. This includes:
- Digital Commodity Exchanges: Platforms that facilitate the trading of digital assets.
- Brokers and Dealers: Entities that execute orders on behalf of customers.
- Stablecoin Issuers: Entities that must maintain 1:1 reserves and meet rigorous transparency standards.
These businesses would be fully subject to the Bank Secrecy Act, requiring them to implement robust AML programs, conduct customer identification (KYC), and monitor for suspicious activity. By placing these obligations on businesses that actually control customer funds while exempting software developers, the bill seeks a middle ground that targets the points of centralized risk.
Broader Impact and the AI Connection
The implications of this debate extend far beyond the realm of cryptocurrency. As artificial intelligence (AI) agents become increasingly capable of performing autonomous tasks, including financial transactions, the question of developer liability will become a central pillar of AI law.
If the government establishes a precedent that software creators are responsible for every autonomous action a user performs with their code, it could chill the development of open-source AI. Under such a regime, an AI developer might be treated as a regulated intermediary for any transaction an AI agent initiates, even if the developer has no control over the agent’s specific goals or methods.
Proponents of the CLARITY Act argue that the government should not establish a general rule that software may only exist if its creator remains capable of surveilling and interrupting every use. Instead, they advocate for a system where liability attaches to conduct: if an AI developer directs a transaction or participates in fraud, they should be held accountable. But the mere act of publishing code should remain a protected activity.
Implications for Privacy and Global Competitiveness
The push for "forced reintermediation"—requiring every financial system to have a controllable middleman—is viewed by many civil liberties groups as a blueprint for a financial panopticon. In an era where financial data is a primary tool for surveillance, the ability to transact without a central intermediary is seen as a vital safeguard against government overreach and financial exclusion.
From a competitive standpoint, the U.S. risks losing its lead in the next generation of financial technology if it adopts a mandate for surveillance-by-design. Countries that embrace the decentralized nature of blockchain technology while targeting actual bad actors may become the new hubs for financial innovation.
The correct principle, as stated by proponents of the BRCA, is that responsibility cannot follow power that a person does not possess. A custodian that controls customer assets should bear custodial duties, and an exchange that executes orders should be regulated. However, treating the author of a piece of software as if they were a global bank ignores the fundamental reality of how decentralized technology works.
As the CLARITY Act moves through the legislative process, the outcome will signal whether the United States intends to uphold the liberal, innovation-friendly values that defined the early internet, or if it will pivot toward a model of pervasive financial surveillance. The decision will shape the future of software development, digital privacy, and the global financial architecture for decades to come.
