NewsCryptoRevised CLARITY Act Adds DeFi Control Test and Limits Protections to Spot Markets

Revised CLARITY Act Adds DeFi Control Test and Limits Protections to Spot Markets

Author: Coindoo·

Key Takeaways

  • A DeFi protocol could be treated as non-decentralized if identifiable people can materially alter its operation, bypass transparent predetermined code, or restrict access.
  • Meeting the control test would not automatically trigger registration; regulators would first determine applicable obligations based on the controller’s activities.
  • The revised DeFi protection covers cash and spot-market activity but not derivatives such as event contracts used in prediction markets.
  • Security councils receive protection only for temporary, publicly disclosed emergency powers that prevent unilateral control.
  • The Senate’s September 15 procedural vote requires 60 votes and would only begin the legislative process, not enact the bill.
Revised CLARITY Act Adds DeFi Control Test and Limits Protections to Spot Markets

The revised CLARITY Act retains the market structure established in the July draft but substantially rewrites Section 20209, which addresses software developers and decentralized finance (DeFi). The changes seek to distinguish autonomous software and genuinely decentralized activity from platforms that describe themselves as decentralized while identifiable people retain operational control.

The bill would protect code development and qualifying decentralized activity while allowing regulators to apply existing requirements to people who control financial functions. Key changes include an explicit DeFi control test administered through the Commodity Futures Trading Commission (CFTC), registration based on the activities performed, and a narrower DeFi protection covering only digital-commodity cash and spot markets. The revision also creates a limited exception for security councils, while leaving the broader prediction-market dispute unresolved.

Lummis describes the revision as a compromise

Senator Cynthia Lummis said the revised text reflects negotiations held during August and contains “over 100 changes requested by Democrats.” In an announcement, she said the bill specifies when “decentralized-in-name-only DeFi protocols” must register with the CFTC and limits DeFi provisions to spot and cash transactions in response to Native American concerns about prediction markets.

“This updated Clarity Act text reflects bipartisan hard work over August—specifying when “decentralized-in-name-only DeFi protocols” must register with the CFTC and limiting the DeFi provisions to spot and cash transactions, in response to Native American concerns about prediction…” — Senator Cynthia Lummis (@SenLummis), September 10, 2026

X post: https://x.com/SenLummis/status/2098124286871433416?ref_src=twsrc%5Etfw

The senator also highlighted the revised treatment of controlled DeFi protocols and the decision to limit DeFi protections to cash and spot transactions. However, requested changes do not necessarily indicate Democratic support. A September 15 vote will show whether the revisions have secured enough votes to begin debate.

Four material changes from the July draft

A new test for when a DeFi protocol is controlled

The July draft already included a control test in provisions addressing securities and Bank Secrecy Act requirements. The revised version adds a corresponding framework to the Commodity Exchange Act section administered by the CFTC.

Under the new language, a protocol may be classified as “non-decentralized” if it meets at least one of three conditions. A person or coordinated group may have authority to materially alter the protocol’s operation or consensus rules; the system may not operate solely through predetermined, transparent onchain code; or someone may be able to restrict, censor or prohibit its use.

The test focuses on authority rather than branding. Describing a platform as decentralized would not determine its legal treatment if a company, foundation or coordinated group could still change its operation or prevent users from accessing it.

Control would not automatically require registration

Satisfying the control test would not by itself require registration. The CFTC, in consultation with the Securities and Exchange Commission and the Treasury Department, would first have to conduct a public rulemaking to determine which obligations apply based on the functions performed by the controlling party.

The bill lists brokerage, dealing, trade execution, clearing and custody as examples. A controller performing one of those functions could be regulated in the same manner as a similarly situated market intermediary. Treasury would separately specify how existing Bank Secrecy Act and anti-money-laundering requirements apply when a controlling party becomes subject to registration.

The bill does not presume that every developer, governance participant or protocol operator is subject to those rules. It also states that software code and distributed ledger systems cannot be required to register in their own capacity. Regulators would assess the conduct of people controlling regulated activities rather than the existence of the underlying code.

DeFi protections would cover only spot markets

The clearest narrowing concerns the protection for DeFi-related activity. The July version used broader Commodity Exchange Act language, although anti-fraud, anti-manipulation and false-reporting enforcement remained available.

The revised draft separates general software development from activities involving a DeFi trading protocol. Protection for maintaining a protocol, operating a liquidity pool or providing an interface would apply only against digital-commodity cash and spot-market rules. It would not extend across the entire Commodity Exchange Act.

The distinction is significant for prediction markets because event contracts fall under the derivatives framework rather than the spot-market framework. A DeFi prediction platform could not rely on the Section 20209 spot-market shield to avoid rules governing event contracts.

The prediction-market dispute remains only partly addressed

In July, 12 Democratic senators raised concerns about prediction markets that resemble sports betting or casino gaming. They argued that broad federal protections could allow such platforms to bypass state regulation, Tribal gaming rights and the Indian Gaming Regulatory Act. The senators’ concerns were detailed in a letter available at

Limiting the DeFi provision to spot markets addresses the specific possibility that a prediction platform could use a DeFi exemption to avoid derivatives oversight. It does not settle the broader jurisdictional dispute.

The revised bill does not include the explicit Indian Gaming Regulatory Act savings clause requested by the senators. It also does not impose their proposed ban on CFTC-registered platforms listing contracts that resemble sports bets. The change closes one potential DeFi route without resolving every concern raised in the July letter.

Security councils receive a limited exception

The revised text explains when participation in a security council would not, by itself, establish control over a protocol. The exception applies to predetermined and temporary emergency powers used in response to a documented cybersecurity incident or imminent threat.

Those powers must operate through publicly disclosed, onchain authorization rules, remain limited in scope and duration, and prevent any single person from exercising unilateral control. They cannot be used for unrelated protocol upgrades, governance decisions or economic changes.

A council with broader or permanent authority could therefore still contribute to a finding that the protocol is controlled.

Federal preemption would not eliminate every state power

The draft gives the CFTC exclusive jurisdiction over registered digital-commodity intermediaries for activities covered by federal law. It nevertheless preserves defined areas of state and local enforcement.

States could pursue registered parties for fraud, deceit, manipulation and violations of the Commodity Exchange Act. They could also enforce generally applicable consumer-protection, banking, payments, property, contract and criminal laws against unregistered parties.

Certain protected software and DeFi activities would be shielded from state securities, commodities and digital-asset laws. State anti-money-laundering, anti-fraud and anti-manipulation powers would remain available.

The wider market structure remains intact

The revision does not replace the broader framework negotiated in the July draft. The bill would still divide oversight between the SEC and CFTC, establish federal registration categories for digital-commodity exchanges and brokers, and set rules for custody, disclosures and customer protection.

The new language focuses on how that framework applies to DeFi projects with identifiable controllers. It does not create a separate registration system for blockchains or software developers. The revised bill text is available at

September 15 vote will serve as a procedural test

The Senate is expected to hold a procedural vote on September 15. Sixty votes are required to advance the bill, meaning Republicans need Democratic support before senators consider amendments or final passage.

Lummis’ claim that the new draft incorporates more than 100 Democratic requests identifies areas where negotiators sought compromise, but it does not establish how many senators will support the motion.

Even a successful procedural vote would not make the bill law. The Senate would still need to debate and pass the legislation, while the House would have to approve the Senate’s changes or reconcile the two versions.

The revision gives senators more precise language on controlled DeFi, prediction markets and regulatory responsibility. The September 15 vote will determine whether those concessions are sufficient to secure the 60 votes required to begin debate.

This article is for informational purposes only and does not constitute legal or financial advice.