The ongoing legislative debate surrounding the CLARITY Act and the Blockchain Regulatory Certainty Act (BRCA) has brought to the forefront a fundamental tension in modern governance: how to apply traditional financial oversight to decentralized technologies without stifling innovation. At the heart of this controversy is the assertion that accountability must follow power. While critics, including former White House National Security Council official Carole House, have argued that current legislative efforts create dangerous loopholes, proponents contend that the bill correctly distinguishes between centralized financial intermediaries and the developers of permissionless software.
The Regulatory Landscape and the Origins of the CLARITY Act
To understand the current impasse, one must look at the evolution of FinCEN’s stance on virtual assets. In 2014, the Financial Crimes Enforcement Network (FinCEN) issued foundational guidance clarifying that the production and distribution of software, in and of itself, does not constitute the acceptance and transmission of value. This principle was further refined in 2019, emphasizing that the application of money-transmission laws should be contingent upon the specific activities an entity performs, rather than the labels attached to the technology or the individuals involved.
The CLARITY Act and its predecessor, the BRCA, seek to codify this distinction. Section 109 of the House-passed CLARITY Act establishes a functional test for developers. Under this provision, a developer qualifies as "non-controlling"—and thus outside the scope of traditional money-transmitter regulations—only when they lack the legal right or the unilateral, independent ability to control, initiate, or effectuate transactions involving a user’s assets without the approval of another party.
Chronology of the Debate
The friction between regulatory bodies and the crypto industry has accelerated over the last decade. In 2014, the regulatory environment was largely permissive, focusing on the novelty of digital assets. By 2019, as the industry matured, FinCEN’s guidance aimed to capture the increasing complexity of "decentralized" business models that functioned, in practice, like centralized banks.
In recent years, the discourse has shifted toward the "infrastructure" layer. The introduction of the BRCA and its integration into the broader CLARITY Act represents a legislative attempt to provide legal certainty for open-source contributors. Critics argue that this creates a "blind spot" for law enforcement. Proponents, however, argue that these protections do not grant immunity for criminal activity. The bill explicitly preserves the authority of the SEC, CFTC, and the Department of Justice to prosecute fraud, money laundering, and sanctions evasion. The debate is no longer about whether bad actors should be held accountable, but whether the act of publishing code should be treated as an inherently regulated financial service.
Functional Analysis: Control vs. Proximity
A central point of contention is the comparison between crypto developers and established financial entities like Visa or Mastercard. Critics of the current developer protections often point to these giants, arguing that if a system functions like a network, it should be regulated like one.
However, a functional analysis reveals a significant technical and legal discrepancy. Visa and Mastercard operate through a closed, proprietary infrastructure where they dictate network rules, control access, and possess the authority to unilaterally block participants. In contrast, many decentralized protocols are "permissionless." Once the code is deployed, the developer often loses the ability to alter or stop the transactions occurring on that network. To hold such a developer liable for the actions of users—whom they cannot identify or stop—is described by industry experts as "liability by proximity" rather than "accountability by power."
Data and Precedent: The Lessons of Section 230
The analogy to Section 230 of the Communications Decency Act is frequently cited by both sides. Section 230 protected the early internet by shielding platforms from liability for user-generated content, a move credited with enabling the rise of the modern web. The Government Accountability Office (GAO) report (GAO-21-385) provides a sobering look at what happens when these protections are curtailed.
Following the introduction of exceptions to Section 230 related to trafficking, the GAO observed a fragmentation of the online market. Rather than stopping illicit behavior, the regulation pushed activity into less transparent, harder-to-monitor, and often overseas jurisdictions. For policymakers, the implication is clear: when intermediaries are forced into roles they cannot technically fulfill, the result is often a migration of activity to "black box" environments, which ultimately hampers law enforcement’s ability to gather intelligence.
Official Responses and Legislative Intent
The Congressional Research Service (CRS) has noted that the exclusions in the CLARITY Act are specific to certain regulatory requirements and do not function as a blanket exemption from the rule of law. The bill creates clear, high-bar requirements for businesses that truly act as intermediaries, such as digital commodity exchanges and brokers. These entities remain subject to the Bank Secrecy Act, including mandatory KYC (Know Your Customer) protocols, suspicious activity monitoring, and strict compliance with U.S. sanctions programs.
The legislative intent, according to supporters of the bill, is to create a "two-tier" system: one that imposes heavy regulatory burdens on entities that possess the power to control user funds, and one that protects the underlying software developers who provide the tools for individual self-custody.
Broader Implications: AI and Future Tech
The debate is extending beyond the crypto sector, touching upon the development of artificial intelligence. If the government establishes a precedent that any developer of a powerful, autonomous system is responsible for every outcome that system produces, it would fundamentally alter the software industry.
The Clinton-era 1997 Framework for Global Electronic Commerce remains a touchstone for this discussion. That framework championed the "decentralized nature" of the internet and warned against "inflexible and highly prescriptive regulations" that could stifle nascent technologies. Critics of the current restrictive proposals argue that we are moving toward a "financial panopticon"—a system where technology must be designed with "backdoors" or central control points to satisfy surveillance requirements.
Conclusion: The Path Toward Regulatory Certainty
The assertion that "accountability should follow power" is widely accepted; the disagreement lies in the definition of power. If "power" is defined as the ability to control, stop, or influence a financial transaction, then the current legislative efforts to protect non-controlling developers are consistent with that principle.
However, if "power" is redefined as "the ability to create technology that others might use for illicit purposes," the regulatory landscape shifts from one of oversight to one of mandatory surveillance. For an open society, the distinction is critical. As the U.S. Congress continues to refine the CLARITY Act, the goal remains to balance the legitimate needs of national security and financial integrity with the necessity of fostering an environment where innovation and individual agency can thrive. The future of decentralized finance, and indeed the future of software development, may well depend on whether legislators choose to regulate functions of control or whether they choose to regulate the mere existence of the code itself.
