The CLARITY fight is bigger than crypto. It’s revealing the case for more control of the internet.
A critic of CLARITY, in coming for crypto, inadvertently (or not) reveals a tech authoritarian dream.
A critic of CLARITY, in coming for crypto, inadvertently (or not) reveals a tech authoritarian dream.
A recent op-ed’s critique of the developer protections in the CLARITY Act rests on an appealing slogan: “Accountability follows power.” But the provisions the author, Carole House, attacks embody precisely that principle. They distinguish between people who control other people’s assets or transactions and people who merely create software that users operate for themselves.
House instead proposes something much more radical: that every powerful software system must have an identifiable intermediary whom the government can compel to monitor and control its users. That goes well beyond “accountability.” Applied consistently, it would suppress publicly-available open software for anyone to use, chill protected expression, and make the legality of publishing code depend on whether its author remains capable of policing everyone who might use it.
Section 109 of the House-passed CLARITY Act—drawn from the Blockchain Regulatory Certainty Act (BRCA)—does not confer immunity based on “what kind of entity” someone is or “how they’re organized.” It establishes a functional test, where a developer qualifies as non-controlling only when, in the regular course of business, the developer lacks the legal right or unilateral and independent ability to control, initiate on demand, or effectuate transactions involving users’ assets without another party’s approval.
The provision also expressly preserves the application of money-transmission, anti-money-laundering and counterterrorist-financing laws to conduct outside its protected activities. It does not immunize fraud, sanctions evasion, money laundering or any other crime. It says that writing software, providing self-custody tools or supporting decentralized infrastructure does not, by itself, make someone a money transmitter. The operative CLARITY language is here, and the standalone BRCA is here.
That distinction is not a “loophole.” It reflects the traditional boundary of money-transmission regulation. FinCEN, the federal bureau responsible for administering the Bank Secrecy Act, has long distinguished between accepting and transmitting value for another person and merely producing software that enables people to transact.
In 2014, FinCEN stated explicitly that “the production and distribution of software, in and of itself, does not constitute acceptance and transmission of value.” Its 2019 guidance reaffirmed that the application of money-transmission law depends on the underlying activities a person performs—not the labels applied to the person or technology. That position remained in force throughout both Democratic and Republican administrations, including during House’s own service on the White House National Security Council. Codifying that basic distinction is neither radical nor partisan. It is regulatory common sense. FinCEN’s software ruling and 2019 guidance are unambiguous on this point.
A person who accepts customers’ money and transmits it for them is acting as an intermediary. A person who publishes software that lets users transact without surrendering control is not performing the same function.
House’s comparisons with Visa, Mastercard, and hawala networks obscure this central point. Those systems involve identifiable operators or networks of agents possessing ongoing power over the services they provide. Visa and Mastercard establish network rules, admit or exclude participants, monitor activity and deny access to their infrastructure. Hawala dealers accept customers’ instructions and arrange transfers through coordinated networks of counterparties.
A developer who publishes a self-custody wallet, contributes to open-source code or provides infrastructure without unilateral control over users’ assets does not possess comparable authority. “Accountability follows power” cannot be allowed to become “liability follows proximity to technology.”
The article’s Section 230 analogy is similarly backwards. Section 230 was one of the legal foundations that allowed the modern internet to flourish because it prevented online services from becoming automatically liable for every statement made by every user. It did not eliminate accountability for people who created illegal content, and it contained exceptions from its enactment.
Congress later added a controversial trafficking-related exception. But the difficulty of drawing that exception is not proof that intermediary protection was a mistake. It demonstrates why lawmakers should hesitate before making infrastructure providers responsible for the conduct of strangers. The Government Accountability Office found that, in the aftermath of the trafficking exception to 230, platforms moved overseas, the market fragmented, and law enforcement found it harder to gather tips and evidence about trafficking. The activity did not disappear; it migrated to less visible and less accountable venues. That is the predictable result when intermediaries unable to distinguish lawful from unlawful user conduct face sweeping liability. The lesson for crypto is to target people who control or knowingly participate in illegal transactions—not impose financial-institution obligations on developers who cannot monitor or stop them.
Moreover, if we accept House’s characterization of Section 230 as status-based, the analogy with the BRCA fails. Section 230 generally protects a class of people, providers and users of interactive computer services, from being treated as the publishers or speakers of third-party content. The BRCA provision asks a direct functional question: does this person possess the unilateral ability to control or effectuate the financial transaction? House criticizes laws based on status while attacking a proposal expressly tied to conduct and control. That is a false equivalence.
Nor does CLARITY simply abolish every other form of accountability. Its decentralized-finance exclusions are limitations on specified SEC and CFTC regulatory requirements. The House of Representatives passed text expressly preserves the agencies’ anti-fraud and anti-manipulation authorities—provisions which remain in the Senate version. The nonpartisan Congressional Research Service likewise explains that the excluded activities remain subject to those authorities. See the bill text and the CRS overview.
More importantly, CLARITY would create new categories of federally regulated crypto intermediaries, including digital commodity exchanges, brokers and dealers. It would subject those businesses to the Bank Secrecy Act and require anti-money-laundering programs, customer identification, transaction records, suspicious-activity monitoring and compliance with U.S. sanctions.
Whatever one thinks of the rest of the legislation, it is therefore misleading to portray its developer protections as an abandonment of financial accountability. The same bill places extensive obligations on businesses that control customer-facing financial activities while declining to impose those obligations on people who merely publish software or help users hold their own assets. That is accountability following power.
House also warns that CLARITY’s protections for software developers might influence the treatment of artificial-intelligence developers. That is not necessarily an argument against them.
Software developers should ordinarily be responsible for their own unlawful conduct—not presumptively treated as the regulated intermediary for every autonomous action a user might perform with their code. Where an AI developer controls an agent, directs its transactions, misrepresents its capabilities or participates in unlawful activity, ordinary legal principles can attach liability to that conduct. But the government should not establish a general rule that software may exist only if its creator remains capable of surveilling, interrupting, and controlling every use.
That broader premise is the most troubling part of House’s argument. She invokes Clinton-era internet policy, including Section 230, while advocating its opposite. The early internet’s legal architecture generally protected users, developers, and infrastructure providers from automatic responsibility for conduct they did not control.
Indeed, the Clinton administration’s 1997 Framework for Global Electronic Commerce directed the federal government to recognize “the unique qualities of the Internet including its decentralized nature and its tradition of bottom-up governance.” It cautioned against “inflexible and highly prescriptive regulations” that might inhibit new electronic-payment systems. That is far closer to the approach taken by the BRCA than the one House now proposes. The Clinton directive is available from the White House archives.
House’s invocation of telephone wiretap mandates makes the direction of her argument especially clear. A rule requiring every system to contain an intermediary capable of identifying users, censoring transactions, and implementing government sanctions is far from technologically neutral regulation and appears more like a mandate to design communications and financial networks for surveillance.
Truly decentralized systems—including Bitcoin—cannot satisfy that demand because no central administrator possesses the powers House wants the government to commandeer. Her logic therefore leaves only two options: prohibit such systems or force them to be redesigned around controllable intermediaries.
The absence of centralized control is not a defect, but a security feature. Distributing power can protect users from private monopolies, financial exclusion, and government abuse. Those safeguards matter especially when sanctions, financial intelligence, and law-enforcement powers ultimately answer to presidents whom Americans may have strong reasons not to trust—whether this one or the next one. Or even in matters where financial intermediaries themselves are acting in bad faith.
Evidently, House is not defending the market-driven, pro-innovation approach of the Clinton administration. The logical endpoint of her proposal is authoritarian rather than liberal: an online financial system in which lawful technology must always contain an intermediary that the government can compel to identify, monitor, and control its users.
The correct principle is indeed that accountability should follow power. A custodian that controls customer assets should bear custodial duties. An exchange that executes customer orders should be regulated for that activity. A person who commits fraud, launders money, or assists a sanctions violation should remain answerable for that conduct.
But responsibility cannot follow power that a person does not possess. Calling the absence of centralized control a “loophole” simply assumes that all lawful technology must be designed as a point of government control.
Anyone who believes in an open society and liberal values should resist calls for forced reintermediation and pervasive surveillance. Anyone who believes in innovation, competitive markets, and technology-neutral rules—including the principles behind the Clinton administration’s internet framework—should support clear protections for non-controlling developers in CLARITY and the BRCA.