Independent digital-asset journalismSaturday, September 19, 2026
CRYPTO MAIN NEWS

Digital assets. Global context. Evidence first.

The global digital-asset briefingMarkets / Policy / Technology
Closed regulatory dossier on a desk in a federal rulemaking reading room.

The U.S. Senate rejected cloture on the motion to proceed to H.R. 3633 on September 15, 2026, by 49 votes to 50, with one senator not voting. The procedural result prevented the chamber from advancing the measure at that point. It was not final passage, enactment, or a conclusive vote on the bill’s merits, and it does not establish that the legislation is permanently dead.

The outcome leaves unresolved the revised CLARITY Act framework released by Sen. Cynthia Lummis on September 10. That draft proposed judging decentralized-finance activity by who can materially change, override, or restrict a protocol—not simply by whether software is decentralized in name.

The revised CLARITY Act asks who holds the switches

The Senate draft proposed a control-based test for determining when a person or coordinated group could face regulatory obligations around a DeFi system. The analysis would turn on whether someone can materially change the system’s functionality, operation, or consensus; whether its operation depends on more than pre-established, transparent source-code rules; or whether someone has authority to restrict, censor, or prohibit its use.

Administrative keys, upgrade authority, manual execution, blacklists, and pause functions illustrate the kinds of powers that could matter under that approach. They are analytical examples, however, not a statutory checklist. The harder question remains where influence ends and control begins, particularly when authority is divided among developers, governance participants, multisignature signers, front-end operators, and emergency bodies.

Evidence to examine Why it could matter
Smart-contract upgrades and administrative keys They may show who can materially change protocol operation.
Fee controls, pause powers, and blocking tools They may identify authority over access, execution, or economic functions.
Front ends, oracles, and governance processes They may reveal operational dependencies outside the core contracts.
Multisignature arrangements, delegation, and upgrade delays They may show whether authority is unilateral, coordinated, constrained, or dispersed.
Emergency procedures and organizational relationships They may clarify the scope, duration, and practical exercise of exceptional powers.

Registration would attach to people, not code

Under the proposed framework, registration, conduct, disclosure, recordkeeping, and supervision duties would attach to controlling people or groups that perform regulated functions. The draft would not require software code or a distributed ledger itself to register.

The activity-based functions described in the draft included brokerage, dealing, trading, execution, clearing, and custody. Applicable Bank Secrecy Act and anti-money-laundering duties could follow if a controlling operator became a financial institution under the proposed structure.

Those consequences remain contingent. The draft called for future rulemaking by the Commodity Futures Trading Commission in consultation with the Securities and Exchange Commission and the Treasury Department, alongside a parallel SEC section. It also called for notice-and-comment procedures and said there should be no presumption that a person or activity is—or is not—subject to the framework before a determination.

Blue-lit computer code illustrating the CLARITY Act test for control over decentralized finance protocols
The revised draft distinguishes publishing software from controlling trading functions around that software. Photo by Daniil Komov on Unsplash.

The draft protects several software activities

The revised text sought protections for activities such as validating or relaying transactions, operating nodes or oracles, supplying computing resources or bandwidth, and developing or publishing software and self-custody tools.

It also addressed people solely providing a data-reading interface, governance administration, participation in a smart-contract liquidity pool, or wallet and custody software. The word “solely” is important: combining a protected technical activity with control over regulated functions could produce a different analysis.

The proposal would preserve authority over fraud, manipulation, and false reporting. Its software protections therefore would not amount to a general exemption from conduct-based enforcement.

Security councils receive a narrow safe space

The draft proposed that participation in an incident-response or security council would not, by itself, establish control when the authority was predefined, temporary, rules-based, and documented; addressed a cybersecurity incident or imminent threat; used publicly disclosed onchain mechanisms; remained limited in scope and duration; and did not rest with one unilateral actor.

That protection would not extend the same way to powers used for unrelated upgrades, ordinary governance, or economic changes. The distinction attempts to preserve emergency safeguards without automatically treating every security participant as a controlling operator.

The unresolved policy risk runs in both directions. A broad control standard could encourage projects to remove useful safeguards merely to appear decentralized. A standard that focuses too narrowly on formal authority could miss de facto power exercised through operational relationships.

The 49-50 vote was a procedural defeat

The official Senate roll call records that cloture on the motion to proceed to H.R. 3633 was rejected on September 15 by 49 yeas to 50 nays, with one senator not voting. The Senate Democratic Caucus separately reported that cloture was not invoked.

The result blocked advancement at that stage. It did not enact the bill, reject every provision on its merits, or prove that the proposal can never return. No next vote date has been established in the cited record, and it remains uncertain whether sponsors will renegotiate, pursue reconsideration, or wait for another legislative window.

Supporters have described the issue as unfinished. Senate Banking Committee Chairman Tim Scott said SEC and CFTC action may proceed in the absence of legislation, while Sen. Dave McCormick said the policy debate would continue. Those are political statements, not evidence of a scheduled vote or agency action.

The official roll call does not explain why individual senators voted as they did. Before the vote, Reuters reported concerns among Democrats and some Republicans involving money laundering, ethics, and competition for bank deposits. Other disputed issues included DeFi and control provisions, prediction markets and tribal concerns, enforcement, and broader partisan procedure. These remain competing political explanations, not established causes of the outcome.

CFTC opens a separate prerule track

Two CFTC developments dated September 17 now add an administrative sequel to the stalled legislation, but they do not settle the CLARITY Act or expand the agency’s statutory authority.

An Office of Information and Regulatory Affairs record shows that the CFTC submitted an item titled “Regulation Crypto Asset Transactions and Regulation Crypto Asset Markets.” The entry carries RIN 3038-AF80, is classified at the “Prerule” stage, and remains pending review.

The public record is an early procedural marker, not proposed regulatory text. It does not disclose which assets would be covered, what obligations might apply to exchanges, or when the CFTC could move forward. An OIRA review is not a proposed rule, a Commission vote, or a final rule.

Staff relief covers a narrower derivatives interface

Also on September 17, CFTC staff announced a no-action position for qualifying passive software providers. Staff said it would not recommend enforcement for failures to register as introducing brokers or associated persons when eligible providers facilitate access to registered futures commission merchants, introducing brokers, and designated contract markets.

CFTC Letter No. 26-25 covers interfaces that provide market data, position information, and direct order submission for event contracts, perpetuals, and other CFTC-regulated derivatives. Qualifying providers must meet conditions that include risk and conflict disclosures, recordkeeping, compliance policies, written undertakings, and consent to jurisdiction.

Providers may not custody assets, generate express buy or sell signals, or exercise discretion over routing or execution. The letter does not authorize open DeFi or self-custody derivatives generally. It is a fact-specific, conditional, revocable staff position that does not bind the Commission.

Four legal and procedural tracks remain distinct

Track What is established What is not established
CLARITY legislation The Senate failed to advance the measure through cloture. The vote did not expand CFTC authority or settle the DeFi control question.
Existing authority The staff letter addresses access to registered intermediaries and markets for CFTC-regulated derivatives. It does not create new statutory authority.
Staff relief Qualifying passive software providers may receive conditional no-action treatment. The position is not a binding Commission rule or broad approval of DeFi.
Future rulemaking A crypto-market item is pending OIRA review at the prerule stage. No proposed text, covered-asset list, exchange duties, or timetable has been disclosed.

The sequence does not prove that the Senate vote caused the CFTC actions; routine agency and federal review procedures remain an alternative explanation. The next meaningful evidence would be publication of rule text, a change in the OIRA record, a Commission vote, or an amendment to Letter No. 26-25.

What DeFi teams should examine now

The revised text is still a proposal rather than law or an operative compliance rule. Even so, its control framework identifies the evidence that could shape future legislative or regulatory debates.

  • Document who can upgrade contracts, change fees, pause execution, or block users.
  • Map authority across front ends, oracles, governance bodies, multisignature signers, and delegates.
  • Record upgrade delays, approval thresholds, and relationships among participants.
  • Define emergency powers by trigger, scope, duration, disclosure method, and termination.
  • Separate incident response from ordinary governance and economic decision-making.

Lummis said the September 10 draft incorporated more than 114 provisions requested by Democratic colleagues. That figure is the sponsor’s characterization, and the draft preceded the failed cloture vote. The House had passed an earlier version of H.R. 3633, while the Senate proposal was an amendment in the nature of a substitute containing extensive revisions.

Frequently asked questions

Did the Senate pass the CLARITY Act?

No. The Senate rejected cloture on the motion to proceed by 49-50, with one senator not voting. The measure was not enacted.

Did the vote permanently kill the bill?

The vote blocked advancement at that stage, but the official record does not establish that the proposal is permanently dead. No next vote date is identified in the cited materials.

Was the vote a final decision on the bill’s merits?

No. It was a procedural cloture vote on the motion to proceed, not final passage or a section-by-section determination on the substance.

What would the revised draft mean for DeFi?

If enacted and implemented through future rulemaking, it would focus regulatory duties on people or coordinated groups that control relevant functions rather than requiring code or a distributed ledger itself to register. The proposal is not current law.

Would publishing software alone establish control?

The draft sought protection for developing and publishing software, along with several other technical activities. The protection’s application would depend on whether a person was solely performing a protected activity or also controlled regulated functions.

Primary materials

Investment disclaimer: This article is provided for general information only and does not constitute investment, financial, legal or tax advice. Digital assets are volatile, and all investment decisions and their consequences are your own responsibility.