GENIUS Act Customer Identification Rules: Where Should Stablecoin KYC End?

Federal regulators are beginning to define how customer identification requirements will apply to payment stablecoin issuers under the GENIUS Act. A recent DEF and Solana Policy Institute comment letter argues that those obligations should remain tied to direct customer relationshipsnot extend broadly to secondary-market holders, self-custody wallets, DeFi protocols, or other non-custodial infrastructure.

The implementation of the GENIUS Act is beginning to put sharper boundaries around one of the most consequential questions in stablecoin regulation: who actually has to identify the customer?

In an August 21, 2026 comment letter, the DeFi Education Fund (“DEF”) and Solana Policy Institute (“SPI”) urged the Financial Crimes Enforcement Network (“FinCEN”) and other federal banking regulators to keep customer identification program (“CIP”) obligations focused on permitted payment stablecoin issuers (“PPSIs”) and their direct customer relationships—rather than allowing those requirements to expand into secondary markets, self-custody wallets, decentralized finance (“DeFi”) protocols, validators, or other non-custodial infrastructure.

The letter responds to the agencies’ proposed rule implementing the GENIUS Act’s requirement that PPSIs be treated as financial institutions under the Bank Secrecy Act (“BSA”) and maintain effective customer identification programs. The proposal was issued jointly by FinCEN, the Office of the Comptroller of the Currency (“OCC”), Federal Reserve, Federal Deposit Insurance Corporation (“FDIC”), and National Credit Union Administration (“NCUA”).

The Regulatory Question: Who Is Actually the Customer?

At the center of the rulemaking is an important distinction between the primary market and the secondary market for payment stablecoins.

A PPSI may have a direct relationship with a customer when, for example, that customer acquires or redeems stablecoins directly with the issuer. In that setting, the issuer is positioned to collect and verify identifying information.

The relationship changes once those stablecoins circulate.

A person might acquire the stablecoin through an exchange, receive it through a peer-to-peer transfer, hold it in a self-custody wallet, interact with it through a smart contract, or use it within a DeFi protocol without ever establishing a direct relationship with the issuer.

DEF and SPI argue that these activities should not, standing alone, create a CIP relationship with the PPSI. According to the letter, treating every wallet address or secondary-market holder as an issuer “account” would effectively eliminate the distinction between primary issuance and subsequent decentralized activity.

That distinction could become one of the most important boundaries under the GENIUS Act.

Custody and Control as the Regulatory Line

DEF and SPI frame their recommendations around three principles.

First, regulatory obligations should generally attach to entities that have custody of customer funds or technical control over those funds. Second, regulation should remain function-based and technology-neutral rather than depend on a particular technical architecture. Third, implementation should remain grounded in the GENIUS Act itself and existing FinCEN guidance.

Under that approach, a regulated stablecoin issuer maintaining a direct relationship with a customer would have CIP obligations.

But merely writing software, validating transactions, providing a self-custody interface, participating in a liquidity pool, or enabling interaction with a blockchain would not automatically create the same regulatory relationship.

This matters because the GENIUS Act's definition of a “digital asset service provider” expressly excludes certain distributed ledger protocols, self-custodial software interfaces, transaction validators, and liquidity pool participants. DEF and SPI argue that the final CIP rule should preserve those exclusions rather than indirectly bringing those actors back within the regulatory perimeter through expansive definitions of “account” or “customer.”

Secondary-Market Stablecoin Activity Should Not Automatically Trigger CIP

The proposed rule recognizes that purely secondary-market activity generally does not establish the type of formal relationship between a PPSI and a stablecoin holder that would create a customer relationship for CIP purposes.

DEF and SPI strongly support preserving that distinction.

They argue that extending CIP obligations to secondary-market activity would create both legal and practical problems. PPSIs generally do not possess the identifying information necessary to verify every person who subsequently receives or interacts with their stablecoins. Requiring them to obtain it could therefore impose substantial compliance burdens while potentially requiring the collection and storage of large quantities of personal information.

The letter asks regulators to make the boundary explicit: secondary-market activity should not, by itself, create an account or customer relationship with the stablecoin issuer.

That clarification would have implications far beyond issuers. Exchanges, DeFi protocols, wallet providers, liquidity providers, developers, and other participants all have an interest in where regulators ultimately draw the line between regulated intermediation and decentralized infrastructure.

What Counts as a “Formal Relationship”?

Another important issue is the proposed definition of an “account.”

The proposal uses the concept of a “formal relationship” between a PPSI and a customer. DEF and SPI support keeping that language but recommend additional guidance explaining what actually creates such a relationship.

Potential indicators could include:

  • a user directly opening an account or conducting a primary-market issuance or redemption transaction with the PPSI;

  • a contractual or terms-of-service relationship between the user and issuer;

  • the issuer collecting identifying information from the user; or

  • the issuer exercising custody, control, or operational authority over the user's assets or transactions.

By contrast, acquiring stablecoins on a secondary market, receiving them peer-to-peer, holding them in a self-custody wallet, or interacting with them through a smart contract without a direct issuer relationship should not alone constitute a formal relationship, according to the letter.

This is an important distinction for projects designing stablecoin infrastructure. Regulatory exposure may increasingly depend not simply on whether a protocol touches a regulated stablecoin, but on the function the project performs and the degree of custody, control, and customer intermediation it exercises.

Digital Identity Could Become Part of Stablecoin Compliance

The comment letter also addresses another developing area: digital identity and verifiable credentials.

Traditional CIP generally involves collecting and verifying identifying information. Blockchain-based systems create opportunities to approach that process differently.

DEF and SPI encourage regulators to recognize digital identity solutions and verifiable credentials as permissible non-documentary methods of identity verification. That could eventually include privacy-preserving technologies capable of verifying information without requiring unnecessary underlying personal data to be disclosed to every institution conducting verification.

Zero-knowledge proofs are one example.

Rather than requiring regulators to approve or mandate a particular technology, the letter advocates for a technology-neutral framework under which PPSIs could evaluate different identity tools based on whether they reliably establish a customer's identity.

That flexibility could become increasingly important as digital asset compliance infrastructure develops.

But Digital Identity Creates Its Own Privacy Risks

The letter also cautions against turning digital identity into another centralized repository of sensitive information.

Even where a credential allows a user to prove certain information without repeatedly revealing the underlying data, someone may still have to collect the personally identifiable information necessary to issue that credential.

That creates cybersecurity and privacy considerations.

DEF and SPI therefore recommend a risk-based approach rather than mandatory use of any particular identity system. They also warn against premature standardization that could lock the industry into today's technology before more secure or privacy-preserving alternatives develop.

For regulators, the challenge will be balancing reliable customer identification with data minimization and cybersecurity.

For industry participants, digital identity may increasingly become both a compliance question and a product architecture question.

Implementation Matters Too

DEF and SPI also urge regulators to preserve the proposed 12-month implementation period and consider phased implementation or supervisory flexibility where compliance requires technical changes such as smart-contract upgrades, multi-chain deployments, or third-party audits.

That point is particularly relevant for blockchain systems.

Unlike updating a conventional compliance manual, implementing a regulatory requirement in blockchain infrastructure can require software development, security reviews, contract migrations, audits, and coordination across multiple networks or service providers. The details of the implementation timeline can therefore materially affect both compliance costs and operational risk.

Why This Matters

The broader issue emerging from GENIUS Act implementation is not simply whether stablecoin issuers will have KYC obligations. The statute already establishes significant BSA and compliance responsibilities for regulated issuers.

The harder question is where those obligations stop once a stablecoin leaves the issuer and begins circulating through an open blockchain network.

That boundary matters.

If CIP follows every stablecoin into every wallet, protocol, smart contract, or peer-to-peer transaction, issuer-level regulation could effectively become network-level identity regulation.

If, instead, the final framework remains centered on custody, control, and direct customer relationships, regulators can impose meaningful compliance requirements on regulated intermediaries while preserving a different regulatory treatment for non-custodial infrastructure and decentralized activity.

The final rule's definitions of “account,” “customer,” and “digital asset service provider” will therefore be worth watching closely.

For stablecoin issuers and companies building around stablecoins, DeFi, wallets, payments, or digital identity, those definitions may ultimately determine not only what compliance is required—but where the regulated relationship begins and ends.

Learn More

This blog post is for informational purposes only and is not legal advice. Please consult with a Launch Legal attorney regarding your specific situation.