Have you ever sent digital dollars straight from your wallet to a friend without anyone in the middle asking for your passport? That simple act sits at the heart of a growing policy fight. Five U.S. agencies recently floated bank-style identity rules for payment stablecoin issuers. One industry voice answered quickly: keep those checks where they belong, on the direct relationship between issuer and customer, and leave independent peer-to-peer transfers alone.
Why the Boundary Between Issuers and Everyday Users Matters Now
The timing feels deliberate. Comment letters landed just before the deadline, and the wider framework under the GENIUS Act is already marching toward January 2027. That is when unlicensed payment stablecoin issuance faces new restrictions across the country. In my view, the real tension is not whether identity checks should exist at all. Most serious players accept primary-market verification. The sharper question is whether those same requirements should chase tokens once they leave the issuer’s direct control.
Regulators proposed that permitted issuers create written, risk-based customer identification programs. These programs would sit inside broader anti-money laundering and counter-terrorist financing systems. Before opening an account, an issuer would gather a customer’s name, address, date of birth or formation, and an identification number. Then the issuer would use documentary or non-documentary methods to form a reasonable belief that it actually knows who the customer is. Records of the identification information would generally stay on file for five years after the account closes. Verification records would stay available for five years after they are created.
Sounds familiar if you have ever opened a bank account. That is intentional. The GENIUS Act treats permitted payment stablecoin issuers as financial institutions under the Bank Secrecy Act. The proposal follows that logic. Yet the same proposal also recognizes something crucial: simply owning or controlling an issuer’s stablecoin does not create an account. A transfer that only touches the issuer through its smart contract generally falls outside the proposed definition as well.
Primary Market Versus Secondary Market Activity
Here is where the distinction becomes practical. Issuing, redeeming, converting, repurchasing, or providing custody for a payment stablecoin usually creates a direct customer relationship. Those activities sit inside the proposed customer identification program. Downstream transfers between users, when the issuer does not intermediate, facilitate, or approve them, sit outside that relationship.
The agencies themselves labeled much of this secondary-market activity. Think transfers from self-hosted wallets, purchases through intermediaries, exchange trades, or direct payments to merchants. They estimated that roughly 99 percent of stablecoin transaction volume happens in these secondary markets. Issuers, the proposal notes, have limited ability to collect identities from people who never interact with them directly. That acknowledgment feels important. It suggests regulators already understand the practical limits of chasing every token movement.
They should not extend to downstream, peer-to-peer stablecoin transactions.
That sentence captures the industry group’s core request. Support the goal of preventing illicit use. Support the proposal’s main approach. But draw a firm line so the rules stay focused on the issuer-customer relationship rather than every subsequent hop.
What Issuers Would Actually Collect and Keep
Let’s walk through the mechanics without the legal fog. An issuer opens a relationship with a customer who wants to mint or redeem stablecoins. Before that account is live, the issuer gathers four basic pieces of information: name, address, date of birth or date of formation for entities, and an identification number. Then it verifies the information using whatever combination of documents or electronic methods fits the risk profile.
Once verified, the issuer keeps the identification data for five years after the account ends. It keeps the verification records for five years after they were created. The program itself must be written and risk-based, meaning higher-risk customers can trigger deeper checks while lower-risk ones stay lighter. All of this sits inside the issuer’s larger AML and sanctions compliance framework.
I’ve found that the five-year retention periods tend to raise fewer objections than the scope question. Most regulated financial firms already live with similar record-keeping. The bigger operational worry is duplication. Stablecoin issuers regularly deal with banks, exchanges, and other institutions that have already performed their own customer due diligence. Requiring the issuer to redo every check from scratch would create friction without much extra security.
Reliance on Other Institutions and Digital Identity Options
The proposal already allows limited reliance. An issuer can lean on certain work done by another federally regulated financial institution if the reliance is reasonable, backed by a contract, and supported by annual certification. The issuer still remains responsible for compliance. That structure is helpful, yet the industry group asked for clearer language covering affiliates, intermediaries, and state-regulated entities. Without that clarity, firms may default to the safest but least efficient path: full re-verification every time.
Digital identity tools received special attention. The proposal already permits both documentary and non-documentary verification methods. It also asked the public whether the final rule should explicitly address digital identities or verifiable credentials. The industry response was supportive of flexibility. Interoperable verification technology can reduce friction while still meeting the core requirement of forming a reasonable belief about identity. In my experience, rigid paper-only rules age quickly in a digital asset environment. Leaving room for credential systems that travel with the user across platforms looks like common sense.
Perhaps the most interesting aspect is how this flexibility could lower barriers for smaller or newer issuers. Larger institutions already have mature compliance departments. Newer entrants often do not. Clear permission to use modern digital identity solutions, combined with sensible reliance rules, could keep the market open without weakening safeguards.
How the Agencies Framed Secondary Market Reality
Regulators did not ignore the numbers. By their own estimate, the overwhelming majority of stablecoin movements never touch the original issuer again after the initial issuance or redemption. That volume travels between wallets, across exchanges, and into merchant payments. Trying to force identity collection at every step would require issuers to monitor activity they do not control and cannot reasonably observe. The proposal therefore treats pure secondary-market activity as outside the customer identification program.
This framing matters for everyday users. Someone who buys stablecoins on an exchange and later sends them to a relative or pays a freelance invoice should not suddenly become an “account” of the original issuer. The issuer never saw the second or third hop. Extending the rules to those hops would blur responsibility and create enforcement headaches for both firms and agencies.
At the same time, the proposal does not create a free-for-all. Other rules still apply. Sanctions screening, lawful order compliance, and broader AML program requirements remain in place. The customer identification program is only one piece of a larger puzzle that also includes licensing, reserve standards, and reporting obligations.
Timeline Pressure and the January 2027 Horizon
The comment period closed in late August. Agencies will now review submissions and may adjust the definitions of “account,” “customer,” and related terms before publishing a final rule. Once the final rule appears, issuers would have twelve months to come into compliance. No publication date has been set yet, but the broader GENIUS Act timeline is already fixed in many minds. Restrictions on unlicensed payment stablecoin issuance are expected to begin on January 18, 2027.
That date creates real pressure. Rulemaking delays earlier in the process already shortened the preparation window. Issuers that wait for perfect clarity may find themselves racing to build systems, hire staff, and test processes under a tight clock. Clear boundaries around peer-to-peer activity would at least let firms focus their resources on the relationships they actually control.
I keep coming back to the practical question of enforcement. If regulators later decide that secondary-market transfers somehow create an account relationship, the compliance burden would expand dramatically. Issuers would need visibility into wallet activity they currently lack. Users would face repeated identity requests for ordinary transfers. The friction could push activity toward less transparent channels, which is rarely the outcome policymakers intend.
Balancing Illicit Finance Risks With Usability
No serious observer claims stablecoins are free of risk. Like any payment instrument, they can be misused. The industry group itself stated support for the goal of preventing illicit use of digital assets. The disagreement is about the most effective place to apply identity checks. Focusing on the primary relationship between issuer and customer concentrates resources where the issuer has the most leverage and the clearest visibility.
Secondary markets already involve other regulated entities in many cases. Exchanges, payment processors, and custodians often perform their own customer due diligence. Layering identical requirements on the original issuer for activity it does not intermediate adds cost without necessarily adding protection. The proposal’s reliance provisions attempt to address that overlap. Strengthening those provisions would help.
Digital identity tools offer another path. If a user can present a reusable, cryptographically verifiable credential that already satisfies the core data elements, both the issuer and the user save time. The proposal’s request for feedback on digital identities and verifiable credentials shows that regulators are at least open to the conversation. Final language that explicitly protects that flexibility would be welcome.
What Still Needs Clarification Before the Final Rule
Several open questions remain. How exactly will reliance work across affiliates and state-regulated partners? Will the final text name digital identity solutions or simply leave the door open through broad non-documentary language? How will agencies treat direct redemptions that sometimes sit close to the primary relationship line? And how will the customer identification rule interact with separate proposals on licensing, reserves, AML programs, and sanctions compliance?
Those interactions will shape the actual day-to-day burden. A clean, narrow definition of customer and account reduces uncertainty. A broader definition that somehow reaches pure peer-to-peer transfers would force issuers to invent monitoring systems for activity outside their control. The difference is not academic. It affects product design, user experience, and the competitive landscape between large and small issuers.
In my view, the agencies’ own secondary-market estimate already supplies the strongest argument for restraint. When 99 percent of activity occurs away from the issuer, designing rules as if every hop creates a new customer relationship looks mismatched to reality. Keeping the focus on direct relationships respects that reality while still advancing the anti-money laundering objectives of the GENIUS Act.
Practical Implications for Issuers and Users
For issuers the near-term task is preparation. Even if the final rule stays close to the proposal, building a written risk-based program takes time. Documenting procedures, training staff, integrating verification tools, and establishing record-keeping systems cannot happen overnight. Firms that already treat customer identification seriously will adapt more easily. Those that have operated with lighter processes will face a steeper climb.
Users should notice little change for ordinary peer-to-peer transfers if the boundary holds. Minting or redeeming through an issuer will look more like opening a financial account. Sending tokens between self-hosted wallets or paying a vendor should continue without new identity prompts from the original issuer. That separation preserves the utility that made stablecoins popular in the first place: fast, low-friction movement of value.
The risk of over-extension is real. If final rules blur the line, users might face repeated verification demands or higher fees as issuers pass on compliance costs. Some activity could migrate to platforms outside the U.S. regulatory perimeter. Neither outcome serves the long-term goal of a safer, more transparent payment stablecoin market.
Looking Ahead to Final Rules and the 2027 Start Date
Agencies now hold a stack of comment letters. They will decide how much of the industry feedback to incorporate. Definitions of account and customer will receive close scrutiny. The treatment of digital credentials and third-party reliance will influence how modern the final framework feels. And the twelve-month compliance window after publication will determine how rushed the implementation period becomes.
The January 2027 date for broader restrictions already looms. Every month of rulemaking delay compresses the time available for systems development and testing. Clear, workable customer identification rules that respect the difference between primary and secondary activity would give the market a stable foundation to build on. Vague or expansive rules would create the opposite effect.
Stablecoins sit at an interesting crossroads. They offer the speed and reach of digital assets with the price stability users expect from money. Regulators correctly want to bring the strongest issuers inside a clear supervisory framework. The industry correctly wants that framework to match how the technology actually works. Drawing a firm line at the edge of the direct issuer relationship is one practical way to meet both goals.
Whether the final rule holds that line will shape the next chapter of payment stablecoin use in the United States. For now the message from one major industry voice is unambiguous: identity checks belong at the point of issuance and redemption, not in the middle of every peer-to-peer transfer that follows. The coming months of agency review will show how far that message travels.
The conversation is far from over. Final definitions, reliance mechanics, and digital identity language still need to land. Until they do, issuers will keep preparing for a world in which customer identification becomes standard for permitted payment stablecoins, while everyday users hope the peer-to-peer corner of the market stays as open as it is today. That balance is worth getting right.