{{item.title}}
{{item.text}}
{{item.text}}
Read "our take" on the latest developments and what they mean.
What happened? On August 18th, the Treasury Department issued a proposal to implement Section 3 of the GENIUS Act, establishing how the Act's restrictions on stablecoin issuance, offer, and sale will apply in practice.
What would the proposal do? The proposal defines several foundational concepts left open by the GENIUS Act that determine when stablecoin activity falls within US jurisdiction and who may participate in that activity. Specifically, the proposal:
What’s next? Comments on the proposal are due 60 days after publication in the Federal Register. If finalized without changes, the rules governing “unlawful issuance” (bullet 3 above) would take effect January 18th, 2027, and the offer-and-sale rules (bullet 2 above) would take effect July 18th, 2028.
The rules are taking shape, but key choices remain
Treasury has handed firms a concrete, workable target: a location- and knowledge-based test and (if it had to be made explicit) clear expectations that controls be implemented and periodically updated. Because the proposal defines issuance and DASP activity by function rather than label, that target applies broadly: entities that may have not anticipated being subject to core location-verification and due diligence requests (e.g., white-label partners, distributors, market makers, redeeming platforms) are now squarely on the hook. The stakes are real, since issuance violations carry steep fines and even criminal penalties.
Just as consequential, the proposal lays the groundwork for the first legally-sanctioned path to move stablecoins across borders. The qualifying-foreign-issuer regime, together with the reciprocity and lawful-order framework, defines how foreign-issued coins can lawfully reach US holders, turning cross-border stablecoin distribution from a gray area into a regulated channel with clear, if demanding, entry conditions.
Another important signal is what Treasury didn't finalize. By floating both a strict-liability alternative and a Regulation S–style offshore transaction framework, Treasury has effectively invited the industry to decide whether reasonable diligence even survives as a defense. While final architecture is unsettled for now, the core capability underneath it (knowing who your recipients are and where they're located) is required under every version on the table. Firms should build that common foundation now rather than wait for a final rule.
What should firms do now? As they prepare, banks and digital asset market participants should consider:
What happened? On August 11th, FinCEN issued a final rule that permanently removes the Corporate Transparency Act (CTA) requirement for US companies and US persons to report beneficial ownership information (BOI), effective August 14th. FinCEN has stated that the intent behind the rule is to “cut red tape” and “remove a burdensome reporting requirement for millions of small business owners.”
What else does the rule contain? The rule revises the definition of "reporting company" to cover only non-US businesses that have registered to do business in the US, “permanently” exempting all US businesses from reporting obligations. It also relieves US persons of any obligation to provide BOI to reporting companies or to update or correct information previously submitted to obtain a FinCEN identifier. FinCEN has confirmed it will delete previously reported information submitted by now-exempt US persons from the BOI database.
What's next? Comments are due 60 days after the proposal is published in the Federal Register.
US beneficial ownership reporting is gone, but beneficial ownership compliance lives on
FinCEN's final rule is a significant reversal of one of the most ambitious AML initiatives in decades, removing beneficial ownership reporting obligations for an estimated 33 million companies. While FinCEN characterizes the rule as "permanent," the CTA itself remains effective and a future administration could reverse course. This potential for regulatory change – in addition to other still-remaining compliance obligations – means that companies that have already built robust BOI compliance processes should resist dismantling them.
This rule change does not absolve firms of their compliance requirements under other regulations and laws. FinCEN’s Customer Due Diligence (CDD) rule, for example, requires that financial institutions identify and verify the beneficial owners of legal-entity customers, and firms must continue to collect and verify BOI as part of account opening and monitoring regardless of whether customers have a CTA reporting obligation. As the elimination of the BOI registry removes a verification tool that some institutions had anticipated using to cross-check customer-provided information, firms will need to maintain robust reporting capabilities.
Meanwhile, with US companies no longer in scope, non-US companies remain the only firms with BOI reporting requirements. Financial institutions with foreign legal entity customers should confirm that their CDD and periodic review workflows are calibrated to the CTA's remaining requirements and that front line staff understand the distinction between domestic and foreign entity customers in the post-rule environment.
What happened? On August 14th, the CFPB announced it will stop publishing consumers' unverified complaint narratives and the associated data visualizations in its public Consumer Complaint Database.
What will the CFPB maintain? The CFPB will continue collecting consumer complaints and maintaining the Consumer Complaint Database. The Bureau indicated that it will continue monitoring complaint information, sharing complaint data with other regulators, and responding to Freedom of Information Act (FOIA) requests. Previously published complaint narratives will also remain available as part of the public domain for FOIA purposes.
Public complaint narratives are going away in response to longstanding industry criticism, but underlying data and issues will remain
For financial institutions, the publication of consumer narratives posed a unique reputational challenge because complaints were publicly available even though the underlying allegations were not verified. Notably, industry criticism was generally not directed at the complaint database itself. Instead, the debate centered on whether a supervisory and consumer-response tool should also function as a public-facing transparency mechanism. By retaining complaint collection and analysis while eliminating public narratives, the CFPB appears to be drawing a sharper line between those two objectives. The CFPB's decision to respond to longstanding industry feedback and remove these narratives should reduce some of the headline and other risk historically associated with this information. The change removes a source that plaintiffs' counsel, advocacy groups, media, and competitors have historically mined for detail, and it eliminates the public visualizations that have been used to construct company-specific complaint "scorecards."
That said, institutions should not view this change to mean reduced regulatory scrutiny of consumer complaints. Rather, the Bureau's expectations regarding complaint intake, investigation, response quality, and complaint-management governance remain intact, and complaint data will continue to inform regulatory and supervisory activities. As institutions assess the impact of the change, they may wish to confirm that complaint-response processes continue to produce timely, accurate, and well-documented responses; evaluate whether existing monitoring programs rely on public complaint narratives or CFPB visualizations that will no longer be available; and maintain the same level of discipline around complaint documentation, trend analysis, and escalation. Reduced public visibility does not diminish the importance of complaint data as a source of insight into emerging conduct, operational, and customer-experience risks.
What happened? On July 31, the NAIC Center for Insurance Policy and Research released its first national assessment of homeowners property insurance market dynamics, analyzing state-level Market Conduct Annual Statement (MCAS) data from 2018 through 2024. The report covers 715 homeowners companies, 103.3 million policies in force and $165.2 billion in direct premium written in 2024. It is intended to help regulators understand market health, affordability, availability, competition and consumer experience.
What are the key findings? The NAIC’s analysis presents a mixed picture: the homeowners insurance market remains broadly stable, while affordability, availability and insurer participation pressures are becoming more visible in parts of the market, specifically:
What’s next? The NAIC is expected to release a public report in early 2027 based on its 2026 Homeowner Property Insurance Market Data Call. That data call, launched in March 2026, collected ZIP-code-level information from insurers on premiums, policies, claims, losses, limits, deductibles, nonrenewals and coverage types.
A clearer view of where homeowners insurance markets are healthy and where pressure is building
The significance of the NAIC analysis extends beyond the individual market findings. It reflects a broader evolution toward increasingly data-informed insurance supervision while reinforcing that homeowners insurance is not a single national market. Conditions can vary significantly by geography based on weather risk, rebuilding costs, claims experience, market participation, and mitigation efforts, making localized intelligence increasingly important to effective oversight.
As regulators gain a more localized view of the market, those differences may become more visible. ZIP-code-level analysis could show pockets within otherwise healthy state markets where premium increases, nonrenewals, deductibles, coverage types or claims experience are moving differently from broader averages. This information could give regulators a clearer basis for identifying where affordability or availability pressures are concentrated and for asking how insurer pricing, underwriting and market participation decisions reflect local conditions.
For insurers, this shift makes the quality and traceability of the information behind their market decisions increasingly important. The move toward more localized, data-driven oversight brings several areas into focus:
Fed reminds banks of underwriting obligations for borrowers without work authorization. On August 13th, the Fed issued SR 26-4, reminding Board-supervised entities of their existing credit risk management obligations with respect to borrowers who are not legally authorized to work in the United States. The guidance does not create new requirements but flags elevated risk related to source of repayment, collateral recovery, and documentation and verification for borrowers not authorized to work in the United States.
NYDFS issues cybersecurity alert on vulnerability affecting some managed service providers. On August 11th, NYDFS alerted regulated entities to an active cybersecurity threat aimed at a known vulnerability in N-able's N-central remote monitoring and management platform, used by some managed service providers to access client systems. Threat actors exploiting the vulnerability can create persistent access even after compromised credentials are revoked and move into customer networks and information systems with administrator privileges. Guidance suggests DFS-regulated entities should determine whether they or their third-party service providers use N-central, and work with those providers to assess and remediate exposure.
Treasury issues operational guidance for employer contributions to Trump Accounts. Treasury issued new operational guidance for employer-sponsored Trump Account contribution programs, clarifying plan-administration requirements and permitting reliance on employee self-certification of beneficiary eligibility.
FDIC adopts two-phase review process for deposit insurance applications. On August 10th, the FDIC announced a new two-phase process for reviewing deposit insurance applications. The new procedures are intended to encourage new bank formation, accelerate the speed of the review process, and improve the efficiency of the application process.
CFTC staff advisory addresses incentive program filings for prediction markets. On August 12th, the CFTC's Division of Market Oversight issued an advisory reminding designated contract markets of their obligations when self-certifying market-maker, liquidity, trading, and incentive programs under CFTC Regulations 40.5 and 40.6.
CFTC held inaugural Innovation Advisory Committee meeting. On August 20th, the Innovation Advisory Committee held its inaugural meeting with sessions covering crypto asset market structure, artificial intelligence, and prediction markets.
CFTC seeks comment on the development of compute derivatives markets. On August 21st, the CFTC published a request for comment seeking input on the potential listing and trading of derivatives tied to the price of computing power used in artificial intelligence. The request focuses on issues including market liquidity and standardization, susceptibility to manipulation, customer protections, and perpetual compute futures. Comments are due by October 20th, 2026.
CFTC proposes registration exemptions for certain commodity pool operators and trading advisors. On August 21st, the CFTC published a notice of proposed rulemaking intended to reduce overlapping regulatory requirements for certain commodity pool operators and commodity trading advisors, including by providing registration exemptions for certain SEC-registered investment advisers and increasing the small commodity pool exemption threshold from $400,000 to $800,000. Comments are due by October 5th, 2026.
{{item.text}}
{{item.text}}