TL;DR: Stablecoin compliance requirements in the United States now flow from the GENIUS Act, which makes a permitted issuer a financial institution under the Bank Secrecy Act and requires the technical capability to seize, freeze, or burn its own tokens as a precondition to issuing them at all. As of August 2026 no federal agency has issued a final implementing rule, which under the statute's effective-date mechanics locks the operative date at January 18, 2027. The hardest problem is not the rulebook — it is that FinCEN assesses most illicit stablecoin activity as occurring on the secondary market, where issuers have no customer relationship.
What the GENIUS Act Requires
The Guiding and Establishing National Innovation for U.S. Stablecoins Act was signed on July 18, 2025 as Public Law 119-27. It creates a category called a permitted payment stablecoin issuer, and restricts that category to three types of entity formed in the United States: a subsidiary of an insured depository institution, a federally chartered qualified issuer supervised by the OCC, or a state qualified issuer.
That U.S. formation requirement has a consequence the statute does not spell out but OFAC leans on heavily: every permitted issuer is a U.S. person, and therefore carries full blocking, rejecting, recordkeeping, and reporting obligations independent of any program mandate.
The reserve rules are prescriptive. At least 1:1 backing, restricted to an enumerated list — cash and Federal Reserve balances, insured demand deposits, Treasury bills, notes, or bonds with 93 days or less remaining maturity, overnight repos and reverse repos backed by those Treasuries, government money market fund shares invested solely in the above, and tokenized forms of the same. Rehypothecation is prohibited except for repo margin, standard custodial obligations, and generating redemption liquidity. Paying holders any form of interest or yield is prohibited outright.
Disclosure runs monthly, not quarterly. Issuers must publish reserve composition including total outstanding coins, average tenor, and geographic custody location, have the month-end report examined by a registered public accounting firm, and obtain CEO and CFO certification. False certification carries the same criminal penalties as Sarbanes-Oxley Section 906 — which is worth naming plainly to whoever is signing.
Whether a stablecoin issuer is state- or federally-regulated turns on a single number: $10 billion in consolidated outstanding issuance. Below it, a state regime that Treasury certifies as substantially similar to the federal framework can supervise. Cross it, and the issuer has 360 days to transition to federal oversight or stop issuing new coins.
The Freeze Requirement Is a Licensing Condition

The provision most likely to reshape how stablecoins are engineered is Section 4(a)(6)(B). An issuer may issue payment stablecoins only if it has the technological capability to comply, and will comply, with the terms of any lawful order.
The statute defines a lawful order as one requiring a person to seize, freeze, burn, or prevent the transfer of stablecoins it issued, specifying the coins or accounts with reasonable particularity, and subject to review or appeal. This is not a compliance obligation layered on top of a product. It is a precondition to having the product at all.
FinCEN's proposed Section 1033.240 goes further than most issuers appear to have modeled. The block, freeze, and reject capability extends explicitly beyond the issuer's own customers and accounts to secondary market activity, including blocking stablecoins traded by designated persons where the issuer exercises possession or control through smart contracts. And the capability must exist on an ongoing basis, not merely at the point of issuance.
FinCEN describes two concrete order types issuers should expect. Seizure warrants, which frequently carry fixed response windows and prohibitions on frustrating implementation. And orders requiring the issuer to burn coins and reissue an equivalent amount to a government-controlled wallet — an operation that touches supply accounting, reserve reconciliation, the monthly attestation, and the CFO certification simultaneously.
Where the Rulemaking Actually Stands
The statute required implementing regulations within one year of enactment, meaning July 18, 2026. That deadline passed with every rule still at the proposed stage.
The proposals that matter most for a compliance officer are the joint FinCEN and OFAC rule published April 10, 2026, which establishes proposed 31 CFR part 1033 for AML program requirements and part 502 for sanctions compliance, and the joint Customer Identification Program rule published June 22, 2026. The OCC's separate AML rule contains no independent standard — it simply cross-references FinCEN and OFAC, and states that compliance with their regulations constitutes compliance with its own.
The effective-date mechanics are worth understanding because they are counterintuitive. The Act takes effect on the earlier of 18 months after enactment, which is January 18, 2027, or 120 days after final regulations are issued. Since 120 days before January 18, 2027 falls around September 20, 2026, any final rule issued from late September onward cannot pull the date forward. The Comptroller of the Currency said publicly in August 2026 that the OCC would have a final rule out by November, which still lands past the statutory date. January 18, 2027 is effectively fixed.
One correction worth making, because it circulates widely: the state certification deadline is not July 18, 2026. Section 4(c)(4)(A) sets it at one year after the Act's effective date, which means January 2028. July 18, 2026 was the rulemaking deadline.
How MiCA Differs
The EU has been operating a stablecoin regime since June 30, 2024, when the e-money token and asset-referenced token titles of MiCA began to apply. Institutions with exposure on both sides of the Atlantic are running two different frameworks.
The sharpest contrast is that MiCA quantifies capital and reserve composition in the regulation itself, while the GENIUS Act delegates both and none of the delegated rules are final. In the other direction, the GENIUS Act's freeze capability mandate is more prescriptive than anything in MiCA.
What the Compliance Program Has to Contain
Under the proposed rules, a permitted issuer must both establish and maintain an AML program with risk-based policies, procedures, and controls that identify, assess, and document money laundering and terrorist financing risks; mitigate them consistent with the assessment; and support ongoing customer due diligence. FinCEN specifies that the risk assessment must consider how accounts are opened and which blockchains the stablecoin is deployed to — a requirement with no analogue in traditional banking.
The rest is recognizable to any BSA officer: a designated compliance officer, independent testing, training, SAR and CTR filing, 314(a) response procedures, 314(b) voluntary sharing, Section 311 special measures, and enhanced due diligence for correspondent and private banking relationships. FinCEN's own modeling assumes a weighted annual average of 190 SAR filings and 266 unfiled suspicious activity cases per issuer.
The Customer Identification Program rule requires name, date of birth, address, and identification number — a taxpayer identification number for U.S. persons, or a passport number and country of issuance, alien identification card number, or other government document for non-U.S. persons.
The sanctions program is where the statute breaks new ground. OFAC notes in its own proposal that this represents the first time federal law has explicitly mandated that a particular class of U.S. person maintain an effective sanctions compliance program. The five required elements are senior management commitment with adequate resourcing and authority, risk assessment, internal controls including the technical capabilities described above, independent testing and auditing with retained records of results and resulting enhancements, and risk-based training. Institutions that already run mature sanctions screening and ownership analysis under the 50 percent rule will recognize most of the shape; what is new is that the program itself is a legal requirement rather than a mitigating factor.
The Travel Rule applies at $3,000. FinCEN proposes adding payment stablecoins to the definition of transmittal order so coverage is unambiguous, though it frames this as clarification rather than expansion, on the basis that issuers are already subject to both the Recordkeeping Rule and the Travel Rule as money services businesses.
The Gap Nobody Has Closed
FinCEN defines the primary market as the issuer interacting directly with a holder — minting, converting, redeeming, burning, custody. The secondary market is everything else: exchange trading, self-hosted wallet transfers, peer-to-peer sends, decentralized exchange activity.
FinCEN's own data shows how lopsided this is. The median stablecoin issuer it reviewed had roughly 100 primary market customers in a year, mostly institutional, with a truncated average around 1,000. Those tokens circulate among millions of holders.
FinCEN also states plainly that it assesses most illicit activity involving stablecoins as occurring on the secondary market. And it is not proposing to require issuers to monitor that market or file SARs on it, having preliminarily concluded the burden could outweigh the benefit.
That is the tension a compliance officer has to manage. FinCEN does not require secondary market monitoring. OFAC's strict liability regime effectively does, for sanctions purposes, because liability attaches without knowledge or reason to know. An issuer that reads the FinCEN rule narrowly and skips secondary market screening still carries the full sanctions exposure. The gap between what is required and what is prudent is the single most important thing to get right here.
Operational Reality
Blockchain analytics are treated as an input to risk assessment rather than a mandated control, but FinCEN's description of what SAR-filing issuers already do amounts to a de facto expectation: investigating linkages between customers and high-risk or sanctioned entities, flagging transactions with identified high-risk on-chain addresses, and identifying activity inconsistent with customers' reported location.
Adversaries actively defeat this. FinCEN cites the Garantex indictment, in which operators allegedly moved the exchange's stablecoin operational wallets to a new address daily specifically to evade blockchain analytics. Treasury's 2026 National Money Laundering Risk Assessment describes the cash-out side as running through diffuse networks of over-the-counter brokers in third countries that use proxy accounts to circumvent due diligence or exploit providers with weaker controls. For banks and fintechs serving crypto clients, that fiat leg is the exposure point — not the on-chain leg.
Reserve composition is a live gap rather than a documentation exercise. Nearly a quarter of the largest stablecoin's attested reserves as of December 2025 sat in corporate bonds, gold, Bitcoin, secured loans, and other investments, none of which appear on the permitted list. Any issuer seeking permitted status faces real portfolio restructuring.
Supervision is also fragmented in a way worth planning around. FinCEN proposes delegating BSA examination authority to the prudential regulators for issuers they supervise, and to the IRS for issuers not examined by the OCC, Federal Reserve, FDIC, or NCUA — meaning state qualified issuers under the $10 billion threshold.
Where Sphinx Fits
Most of the work this framework creates is investigative volume against pseudonymous counterparties: screening hits on wallet addresses, alerts on primary market institutional customers who are themselves intermediaries for thousands of downstream users, and lawful orders arriving with fixed response windows. Sphinx's agents work inside the systems that hold that data and produce documented case files rather than scores, which matters when the examination question is not what you decided but how you reached it. Firms building this alongside a broader crypto AML compliance program generally find the two programs share most of their infrastructure.
Judgment stays where it belongs. Determining whether an order actually qualifies as a lawful order under the statutory definition, calibrating due diligence for an institutional customer intermediating thousands of downstream users, and deciding when on-chain patterns constitute reportable suspicion without an identified customer are all decisions a person has to own.
Frequently Asked Questions
When do GENIUS Act requirements actually take effect?
January 18, 2027, in practical terms. The statute sets the effective date at the earlier of 18 months after enactment or 120 days after final implementing regulations are issued. No agency had issued a final rule as of August 2026, and the 120-day window that could have pulled the date forward closed in late September 2026. The state certification deadline is separate and falls in January 2028, not July 2026.
Does the GENIUS Act require stablecoin issuers to freeze tokens?
Yes, and it is a condition of being allowed to issue at all. Section 4(a)(6)(B) permits issuance only if the issuer has the technological capability to comply with any lawful order — defined as an order to seize, freeze, burn, or prevent the transfer of coins it issued. FinCEN's proposed rule extends that capability to secondary market activity where the issuer exercises control through smart contracts, and requires it to be maintained on an ongoing basis.
Do issuers have to monitor secondary market transactions?
FinCEN is not proposing to require it, having concluded the burden could outweigh the benefit — while simultaneously assessing that most illicit stablecoin activity occurs there. OFAC's strict liability regime cuts the other way: sanctions liability attaches without knowledge, so an issuer that skips secondary market screening still carries full exposure. Treat FinCEN's position as the floor, not the standard.
How does MiCA compare to the GENIUS Act?
MiCA quantifies what the GENIUS Act delegates. It sets own funds at the highest of EUR 350,000, 2 percent of average reserve, or a quarter of prior-year fixed overheads, and requires at least 30 percent of e-money token funds in separate credit institution accounts. The GENIUS Act leaves capital and liquidity standards to regulators who have not written them. Conversely, the GENIUS Act's freeze and burn capability mandate has no MiCA equivalent.
Does the Travel Rule apply to stablecoin transfers?
FinCEN proposes applying the Recordkeeping Rule and Travel Rule to permitted issuers at the $3,000 threshold, and adding payment stablecoins to the definition of transmittal order to remove ambiguity. FinCEN characterizes this as clarification rather than expansion, since issuers are already covered as money services businesses. Whether a stablecoin-specific rule should be codified separately remains an open question in the proposal.

.png)