I have spent enough time inside Washington to know that a bill almost never goes from negotiation to the president’s desk in six months. When it does, there is usually a crisis forcing it. The GENIUS Act did it with no crisis at all. The president directed federal agencies to build a digital asset framework by Executive Order on January 23, 2025, and the bill became law six months later, on July 18.
I was at Treasury during the pandemic, and I saw legislation move at that pace only when the system was under real stress, when the CARES Act was passed in 2020. No such crisis was forcing GENIUS, but it still cleared both chambers with bipartisan support in roughly six months. It tells you how seriously Washington is now taking digital assets.
That seriousness shows up as something more significant too. When I speak to regulators these days, I hear that digital assets are pushing them to rethink not just what they regulate, but how they regulate. Institutions that understand this will build better compliance programs.
A new regulatory philosophy
For most of the last few decades, financial services regulation has been rules-based. Regulatory compliance meant putting specified systems and processes in place and validating them on a schedule tied to your risk.
Oversight was largely fragmented. When I was running risk and controls at Citi, examiners from different banking agencies and markets regulators would come through to review our anti-money laundering (AML) program, each working off their own checklist.
But then, in April 2026, the OCC, Federal Reserve and FDIC jointly updated their model risk management guidance (SR 26-2) for the first time since 2011. That update is the clearest signal yet of three shifts happening at once.
The first is a move from rules to outcomes. The old regime asked whether you had checked the box, and if you missed a box you were in trouble. For years, the industry was too often examined on the procedure rather than the result. The direction now is towards demonstrable effectiveness: Can you show your program is actually doing what it was built to do?
The second is a move from periodic validation to continuous monitoring. Under the old regime you validated a model on a fixed schedule set by its risk tier. The expectation now is ongoing monitoring of how a model behaves and what it produces. For any institution bringing on-chain data into its screening and monitoring, that changes the architecture you need.
The third is a move from siloed agencies to coordinated oversight. More on that below, but it has the longest reach of the three.
None of the three changes will remove the obligations that were already there, because the law is still the law. It’s the implementation that is changing. The old regime asked whether you had validated and documented your model. The new standard increasingly asks whether that model is actually catching the illicit activity it was built to catch.
What outcomes-based supervision asks of you
As artificial intelligence (AI) moves deeper into the compliance stack, explainability becomes the new center of gravity. Efficiency is welcome (every institution wants less friction) but efficiency is not what regulators are testing for. They are testing for effectiveness, and they want to see that your model is not a black box. In practice that means:
- The ability to show you understand how your model works and how it is governed
- Controls that keep it from producing biased outcomes against your customers
- The ability for a third party to reproduce your model’s decisions and reconstruct why a given output was reached, as well as who approved it
Monitoring on-chain data
Good blockchain analytics solutions like Elliptic can show you the full provenance of funds across blockchains, going back as far as you want to look. But what do you do with that intelligence when you have it? I spend most of my time talking to financial institutions about that question. For example, if a client brings you a million dollars and you can see that a few hundred dollars of it once sat in a sanctioned or criminal wallet, what do you do?
The answer is determined by your risk appetite, clearly set and enforced. Most institutions land on zero tolerance for sanctioned entities, human trafficking and terrorist financing, with a higher threshold for something like crypto mixers, where legitimate use cases exist alongside illicit ones. It is important to understand the type of cryptoasset risk you’re dealing with before you can make determinations about your risk appetite towards it.
But whatever appetite you set for a specific type of risk, you then have to prove you are holding to it. If you tell your regulator you have zero tolerance for sanctioned entities, you have to be certain none are getting through. If your primary regulator comes in and finds that you have 0.2% exposure to sanctioned funds, the conversation won’t necessarily be about whether 0.2% is material. It’ll be about why you are out of your own stated policy.
From agency silos to coordinated oversight
The Treasury Secretary has been pushing the federal regulators to work together, and he has that convening ability because he chairs the Financial Stability Oversight Council (FSOC). This gives him a way to get every agency in one room on a regular basis.
You can see the coordination taking shape bit by bit. FinCEN, OFAC and Treasury have issued a joint notice of proposed rulemaking (NPRM) to scope permitted payment stablecoin issuers into the Bank Secrecy Act (BSA). Prudential regulators have issued numerous proposed rules to implement the GENIUS Act. The SEC and CFTC have signed a memorandum of understanding to work together. That last one may not sound like much from the outside. From the inside, getting two independent regulators to put cooperation on paper is a meaningful change.
For compliance teams, this is good news. More coordination should mean more consistency, fewer gray areas and a clearer administrative plan over time. This is not a free pass to reduce the focus on a strong program; it is meant to allow institutions to develop more robust and effective programs that are outcome-based.
The direction of travel is clear
The GENIUS rulemakings are still in flight: the BSA scoping for stablecoin issuers, the OCC’s capital and reserve rules, and the FDIC’s application procedures should land over the coming months and quarters, which is normal for rulemaking.
The CLARITY Act, which would clarify the jurisdictional lines between the SEC and the CFTC on digital assets, is a different matter. It has been held up partly by the debate over yield, and the calendar is unforgiving: Congress recesses in August and the midterms follow in November, which leaves little floor time. One thing I have learned in Washington is that predicting timing is a fool’s errand.
But here is the point I make to institutions that are tempted to wait. Things keep moving whether or not a given bill passes on schedule. I worked on the LIBOR transition which took multiple years of rulemaking and also involved legislation to close critical points for the industry. The work did not stop while we waited for the proposed rules and a finalized bill, and the institutions that were ready were the ones that didn’t wait. Even though the details still need to be worked out, the direction of travel is clear and the time to act is now.
Reading and understanding the regulatory picture is much of the work my colleagues and I do at Elliptic. Our Global Policy and Regulatory Group sits close to where regulatory decisions are being made in the US. We help financial institutions anticipate where supervision is heading and build compliance programs that are ready before they have to be. If you believe that is a conversation worth having, get in touch today.

