Crypto Firms Still Face Full AML Rules After Clarity Vote

12 min read
3 views
Sep 22, 2026

The Clarity Act did not pass the Senate, yet crypto firms still sit under the same AML stack. What banks now expect after onboarding is the part most teams keep missing.

Financial market analysis from 22/09/2026. Market conditions may have changed since publication.

Here is the part that still surprises people after a loud week in Washington. A bill can stall, headlines can spin, and nothing about the daily grind of crypto AML rules actually moves. I have watched teams treat a procedural vote like a finish line. It is not. If you run a covered digital asset business in the United States, customer identification, sanctions screening, and suspicious activity reporting still sit on your desk the same way they did last month.

Why The Clarity Act Vote Did Not Soften Bank Secrecy Duties

On September 15 the Senate failed to advance cloture on the House version of the Digital Asset Market Clarity Act. The tally was 49 to 50. That is eleven votes short of the sixty needed to open debate. It was a procedural stop, not a funeral for the text. A handful of senators who voted no later said talks were not over. Ethics language around elected officials and digital asset holdings remains a live fight. No second vote is on the calendar as I write this.

So what actually changed for compliance officers? Almost nothing. Market structure bills argue about who sits on top of a market. They do not usually rewrite the Bank Secrecy Act. I keep coming back to that distinction because it is the one founders miss when they skim a summary and assume the hard part is over.

Market structure legislation was never going to displace the Bank Secrecy Act; it would have clarified which regulator sits on top of it.

That line, from a sponsor-bank specialist who works with digital asset programs every week, is the whole story in one sentence. Covered crypto companies still need to know their customers. They still need beneficial ownership checks. They still screen names against sanctions lists. They still run anti-money laundering controls. They still file reports when activity crosses the line their systems are built to catch.

What Covered Firms Must Keep Doing Tomorrow Morning

If you want a blunt inventory, start here. None of these items disappeared because cloture failed.

  • Customer identification at onboarding and when risk shifts
  • Beneficial ownership work for legal entities
  • Ongoing sanctions screening, not a one-and-done list check
  • Transaction monitoring that can explain why a flag fired
  • Suspicious activity reporting when the facts support a filing
  • Record keeping that a bank examiner can actually follow

I have found that the last point is where programs look polished on paper and messy in practice. Pretty policy binders do not impress a sponsor bank if identity data, wallet labels, and payment trails live in three different tools that never talk to each other.

Faster rails make that mess more expensive. Stablecoins and other digital assets settle quickly. Reversals are ugly. The window to catch a bad transfer shrinks. In my experience, that is why banks keep saying the bar is going up even while Congress argues about titles and jurisdictions.

If anything, it raises the bar. As stablecoins and other digital assets make payments faster and harder to reverse, the window to catch a problem gets smaller.

Onboarding Is Not A Finish Line Anymore

Old habit: verify someone once, stamp the file, move on. That habit is dying. Account behavior changes. Wallet clusters change. Counterparties change. A customer who looked ordinary in January can look like a mule corridor in June. Firms that treat verification as a single event will keep walking into the same exam comment.

Think of identity as a living map rather than a passport photo. You still need the photo. You also need to notice when the person in the photo starts driving a different route every night. Changes in volume, new geographies, sudden self-custodial hops, and odd hours all rewrite the risk attached to an existing relationship.

Perhaps the most interesting aspect is how little of this is new law. It is old expectation meeting new speed. Banks already knew that risk is not static. Crypto just makes the static story harder to sell.


How Sponsor Banks Actually Review A Crypto Program

When a sponsor bank looks at a crypto company, it rarely starts with a slogan about innovation. It starts with the lifecycle. Who is the customer. Who owns the company. Which wallets sit behind the account. How funds enter. How funds leave. What happens when a name hits a list at 2 a.m.

Reviews commonly cover customer and business verification, beneficial ownership, sanctions, fraud controls, wallet screening, and transaction monitoring. Banks also want proof that those controls work under live traffic, not only in a pre-launch tabletop. Written procedures help. Operating evidence helps more.

Separate vendors can create quiet gaps. Identity lives in one system. Wallet risk lives in another. Payments live in a third. Nobody owns the join. That is the blind spot banks keep describing. A pretty dashboard is not the same thing as a single risk story.

A bank needs confidence that you know who is behind an account or a wallet, and that you will see it when that risk profile changes.

I will say this plainly. If your team cannot answer “who is this wallet today” without opening four tabs, you are not ready for a serious banking conversation. That is not a moral judgment. It is an operational one.

Connected Controls Beat Isolated Checklists

Connected controls sound like consultant speak until you watch a real case. A name clears screening. Two weeks later the same person sends value through a fresh cluster that has been used in prior typologies. If the wallet tool never updates the customer file, the first check was theater.

Banks want to know two simple things after day one. Does this account still belong to the verified party. Does later activity still match the stated use. You can reduce friction for honest users by combining signals instead of asking the same person to upload the same document every time a rule fires. That is the grown-up version of “know your customer.”

Control layerWhat banks look forCommon failure
IdentityWho owns the relationshipOne-time check, stale files
OwnershipWho sits behind the entityIncomplete beneficial owners
SanctionsContinuous name and wallet hitsBatch jobs that lag live flow
WalletsAttribution that updatesLabels that never feed cases
MonitoringExplainable alertsNoise with no narrative

Use that table as a self-audit, not as decoration. If any row is “we plan to connect that next quarter,” a bank will hear the plan as a gap.

Federal Split Oversight Would Not Erase Other Layers

Under the proposed Clarity framework, federal market oversight would split between the securities regulator and the commodities regulator. Qualifying digital commodities and registered spot-market intermediaries would sit closer to commodities supervision. Securities and related activity would stay with the securities side. That answers a jurisdictional question. It does not mop the floor.

State money-transmitter licensing can still apply. Federal sanctions rules still apply. Existing duties for covered financial institutions still apply. Service mix and customer mix still decide which extra layers attach. I have seen founders celebrate a draft org chart in a bill and forget the license they already hold in three states. That is how you get a false sense of relief.

Even if a future text passes, the compliance stack will look more like a sandwich than a single plate. Market structure on top. Bank secrecy in the middle. State and sanctions rules underneath. Ignore any layer and the whole thing leans.


Self-Custodial Wallets Do Not Require Putting Names On-Chain

This is where the debate gets loud and sloppy. Some people hear “identity” and picture a passport hash burned into a public ledger forever. That is not the only design, and it is usually a bad one. Personal data that cannot be deleted does not belong on a glass bulletin board.

Verification for self-custodial wallets and decentralized finance can happen at regulated access points. Fiat on-ramps. Off-ramps. Application interfaces. Other doors where a licensed firm already meets a user. Keep names, identity documents, and sensitive records in controlled systems. Leave the open network to move value, not biographies.

Counterparties also do not need every scrap you collected. Often they need a claim. This user passed an identity check. This user controls the stated wallet. This user is not on a sanctions list. Confirm the claim. Do not ship the underlying file across the internet because a protocol is open source.

Confirming a claim, rather than handing over the underlying data, is what lets firms meet their obligations without putting personal information on-chain or forcing open software to behave like a conventional intermediary.

That approach separates protocol code from the duties of companies that wrap interfaces and payment rails around it. The goal is not to pretend every self-custodial wallet is a checking account. The goal is enough verified context around a regulated interaction to manage the risk you can actually see.

What The Failed Vote Means For DeFi Builders

The Clarity draft tried to answer adjacent questions with registration exemptions for some software developers, wallet providers, and validator operators. Failure to advance means those answers stay unfinished. Firms keep applying existing law while Congress and the agencies argue about where decentralized services fit.

That uncertainty is uncomfortable. It is also not a license to do nothing. If your product sits next to fiat rails, if you hold customer funds, if you present an interface that looks like a broker to a normal person, you should assume someone will ask who your user is. Hoping a future exemption arrives before the next exam is not a control.

I have a bias here, and I will own it. Builders who design off-chain verification at the edges tend to sleep better than builders who wait for a perfect statute. The first group can still ship. The second group writes threads.

AI Agents Need A Person Behind The Switch

Identity gets stranger when software opens an account, trades, or pays on behalf of a human or a company. Who controls the agent. Who approved this specific action. What is the software allowed to do. Those are three questions, not one.

Verifying the human or business behind the agent creates accountability. An authorization process decides whether the agent may start the transfer in front of you. That authority should be limited in scope, bound in time, and easy to revoke. Institutions should check permission when the transaction happens, not lean on an approval granted last spring while the model has been improvising since Tuesday.

This stopped being science fiction when major US platforms began shipping tools for machine-directed finance. Users can set rules for rebalancing, execution, and position management. Some protocols let agents pay for data, research, interfaces, and compute without a person clicking every time. Fine. Then the record has to name the principal, the agent, the approved action, and the limits that applied at initiation.

As agents begin interacting with financial systems and moving money autonomously, there needs to be a clear, verifiable chain connecting the person, the business, the agent and the transaction.

In my experience, the teams that will struggle are the ones still celebrating “one KYC and we are done.” Agents break that model. Authority drifts. Models retry. Permissions expand because somebody left a toggle on. Continuous checks on who may act, and whose money is moving, will replace the old snapshot file.

  1. Identify the principal who owns the outcome
  2. Bind the agent to a narrow mandate
  3. Time-box that mandate and make revocation boringly easy
  4. Re-check permission at the moment of value movement
  5. Keep a record that an examiner can read without a decoder ring

Skip a step and you will get a pretty demo and a painful reconstruction later.


Why Speed Makes Weak Programs Look Worse

Paper checks used to buy time. Wire cutoffs used to buy time. Blockchain settlement is less polite. Once value moves, the argument often becomes forensic instead of preventative. That is why banks talk about connected identity, wallet, and transaction data as one process rather than three hobbies.

Fraud rings already understand the timing. They test small. They wait. They swing. If your monitoring only wakes up for large notional size, they will live under the threshold until the corridor is warm. Continuous behavior review is not a luxury add-on. It is how you notice the warm-up.

Is that expensive? Yes. Is it optional for a firm that wants durable banking access? Not really. I would rather see a smaller product with clean joins than a huge product with orphan alerts.

A Practical Way To Brief Your Board This Week

Boards hear “the bill failed” and some of them exhale. Give them a tighter story.

  • The vote was procedural. Market structure is unfinished. Bank secrecy is not.
  • Our legal duties on identification, screening, and reporting did not pause.
  • Sponsor banks will keep asking for lifecycle evidence, not slogans.
  • Self-custodial users can be checked at access points without public personal data.
  • If we ship agent features, authority must be limited, timed, and revocable.

Then show one diagram. Customer. Wallet. Payment. Alert. Case. Report. If any arrow is missing, that is the work plan. Keep the politics in a short appendix. Directors can read the news later. They need to know whether the program still holds water.

Where Teams Waste Months After A Headline

I keep seeing the same three stalls. First, waiting for a second vote before fixing data joins. Second, arguing philosophy about decentralization while fiat still touches the product. Third, buying another screening tool without appointing an owner for the combined risk view.

Tools are fine. Owners are better. If nobody is measured on whether identity changes update wallet risk the same day, the stack will drift. Drift is how good companies walk into ugly findings.

Another stall is over-collecting data “just in case.” That creates privacy risk without improving decisions. Collect what you need to support a claim. Store it under control. Share attestations, not dumps. You can be serious about crime risk without building a museum of passports.

Sanctions, Reporting, And The Unsexy Middle

Sanctions screening still has to run as names and wallets evolve. A hit that lands after funds have gone is a failure dressed up as a late email. Suspicious activity reporting still depends on humans who can write a story a government analyst can use. Models can prioritize. They cannot shrug at narrative.

I have read too many draft filings that list timestamps and no theory of the case. That is not monitoring. That is logging. If your analysts cannot say why the pattern matters, the system is producing chores rather than intelligence.

Working loop for covered crypto activity:
  Identify the party
  Attribute the wallet
  Screen the names and addresses
  Watch the behavior
  Escalate with a story
  File when the standard is met
  Refresh the file when anything material changes

Print that loop. Put it near the on-call rota. When someone asks whether the Clarity vote changed the job, point at the paper.

What Legitimate Users Should Feel Instead Of Friction Theater

Compliance that only adds clicks will lose good customers and keep the patient criminals who will fill any form. Better programs blend signals. Device reputation. On-chain history. Declared purpose. Prior relationship. Source of funds when the risk calls for it. Ask once for the hard document. Reuse the result across the lifecycle unless something material breaks.

That is how you stay human. People tolerate a serious check when they understand why it exists. They hate repeating the same selfie because two vendors refuse to share a token. Fix the plumbing and the product feels kinder without getting sloppy.

Would I rather live in a world with fewer forms and faster rails? Sure. I would also rather not explain to a partner bank why a wallet we “kind of knew” funded a problem we noticed too late. Grown programs hold both thoughts at once.

Politics Will Keep Moving. Your Controls Should Not Wait.

Talks may restart. Ethics clauses may shift. A later package may split federal oversight more cleanly. None of that is a reason to freeze hiring for investigations, delay wallet attribution work, or treat agent permissions as a product easter egg.

The industry already pours serious money into the election cycle. Fine. Advocacy and operations are different sports. You can fund a debate and still run screening on Friday night. Do both. Do not confuse the first for the second.

If you take one thing from this piece, take this. The failed cloture vote left existing customer identification, anti-money laundering, sanctions, and suspicious activity duties in place for covered US crypto businesses. Sponsor banks still expect identity, wallet, and transaction controls to stay connected for the life of the relationship. Self-custodial users can be verified at the edges without writing private lives onto a public chain. Agents need limited, revocable authority tied to a real principal.

That is the job. It was the job last week. It will be the job while the next draft circulates. The firms that treat the headline as a pause will spend next year explaining gaps. The firms that tighten the joins will still have plenty to argue about in public. They will just have fewer surprises in private.

And if a colleague forwards you a thread that says AML vanished because a motion failed, send them back to the lifecycle. Ask who is behind the wallet today. Ask what the agent is allowed to do this hour. Ask whether the alert and the customer file share a brain. Those questions are not glamorous. They are how this market stays banked.

Cryptocurrencies and blockchains will do for money what the internet did for information.
— Yoni Assia
Author

Steven Soarez passionately shares his financial expertise to help everyone better understand and master investing. Contact us for collaboration opportunities or sponsored article inquiries.

Related Articles

?>