Statement Summary
In a recent speech, a SEC Commissioner discussed the “Innovation Exemption,” designed to enable the trading of tokenized securities on crypto networks through automated market makers. This exemption aims to prevent disruptions in equity markets while promoting domestic trading of tokenized assets. The Commissioner emphasized the need for regulatory flexibility to support the adoption of new technologies like cryptographic tools and decentralized networks, which can enhance privacy and security. They argued that existing financial regulations focused on excessive data collection complicate efforts to identify illicit activities and proposed a shift towards attribute-based verification to reduce redundancy in data gathering. The speech called for honest dialogue between regulators, market participants, and the public to embrace technological change while ensuring security and privacy.
Original Statement
Thank you to Ken and SIFMA for having me here today during my penultimate week as a Commissioner. Perhaps the title of this session should have been “The Soon-to-be-ex Regulatory Outlook.” Even in my waning days, I am still on the hook for giving my disclaimer, so here goes: My views are my own as a Commissioner and not necessarily those of the SEC or my fellow Commissioners.
Before I turn to the main topic—rethinking financial surveillance in light of old problems and new technologies, let me take a minute to talk about the so-called “Innovation Exemption” we announced last week. Actually two exemptions in one order, the Innovation Exemption is a time- and size-limited exemption to facilitate the trading of tokenized securities on crypto networks via automated market makers. It is, as Chairman Atkins explained, a bridge toward durable rulemaking.
We invite comments on the exemption, and I am grateful that SIFMA already has availed itself of that invitation with a preliminary reaction. In crafting the exemption, we sought not to disrupt the smooth functioning of equity markets, but to ensure that the introduction of tokenized securities does not disrupt the finest equity markets in the world. Tokenization is coming, and I would rather it happen here than have overseas markets offer tokenized exposure to U.S. equities without a domestic alternative.
The goal is a final ruleset governing the intermediaries and venues that facilitate the trading of tokenized securities in ways not envisioned by the existing regulatory framework. I share SIFMA’s desire to get the rulemaking process underway as soon as possible. The exemption is only a small part of what I hope will be the Commission’s continued and developing commitment to working with market participants to draw on new technologies to empower and protect investors.
Embracing Change
Embracing change, however, is not easy. In conjunction with my impending move to Virginia Beach, despite initial enthusiasm about the possibilities, I am finding change rather unpleasant. The glimpses I have gotten of potential new places to live have intensified my desire to stay where I am. The traffic and road construction seem more intense, the landscape less verdant, and the sun-drenched apartments already off-the-market. The uncertainties of life in a new place cast the old place in an unrealistically rosy light.
Some of my concerns about the impending move are valid, but worries mulled too intensely also can distract from the real possibilities that change brings. The introduction of new technologies likewise often not only inspires awe and excitement but also engenders fears and concerns as realities sink in. Even as people dream about a new technology’s possibilities, they also ask legitimate questions about its potential harmful consequences and the likelihood that bad actors will use the technology to menace society.
These questions are good, but if over-cogitated, they will cause us to reject change in favor of the status quo. We need to ask, in addition to questions that probe technology’s downsides, questions to ensure that we do not unduly restrict technological change. Are well-intentioned protective measures harming people by denying them the benefit of new technologies that could improve their lives? Are restrictions designed to prevent bad people from using technology unduly inconveniencing good people? Are controls around the use of the new technology impeding Americans’ right to make choices for themselves and their families?
Are attempts to stuff new technologies into a straitjacket of prescriptive rules written with old technologies in mind, squelching the potential of those new technologies to change society for the better? These questions, both the ones that probe the downsides of moving forward and the ones that explore the consequences of standing still, are relevant to the technology being developed in the crypto world.
Technological Opportunities
Today society is at a crossroads. Down one path lies the status quo: more data collection, more intermediary surveillance, more “know your customer” requirements that turn our financial rails into a panopticon. Down the other path lies an opportunity to use new technologies to improve our ability to catch criminals while collecting less personal information than ever before, and monitoring more sparingly to protect Americans’ privacy.
Just as too many crypto enthusiasts have an unhealthy fixation on “number go up,” too many in the regulatory world (not just people who work in government, but also their many non-governmental data collection cheerleaders) are unduly fixated on “data go up.” In these data maximalists’ view, the more data the government and its private sector deputies collect, the better. The excessive regulatory focus on data accumulation is often the product of innate protective instincts.
Sometimes, however, the human penchant for knowing what others are doing or a fear that regulators will be blamed for not foreseeing a problem drive government data vacuuming. Once government starts collecting a particular piece of data, arguments to stop the collection generally inspire puzzled resistance: If you love America and hate crime and financial crises, how could you want the government to have information?
The steady accumulation of personal information by the government without subsequent checks of initial justifications for collecting it has become our reality. Every additional field of personal and confidential business data the government collects and retains incrementally increases the likelihood the government or a private party will mishandle it by accident or on purpose.
The know your customer (KYC) and anti-money laundering (AML) frameworks operate on a simple theory: if financial institutions, under regulatory mandates, collect enough information about enough people, law enforcement will be able to find the criminals hiding among the law-abiding majority. We build ever bigger data haystacks on the theory that we will find a needle or two inside. The bigger haystack, however, makes it harder to find the needles.
Rethinking Data Collection
Consider the actual architecture of this haystack. Financial institutions following government mandates run Customer Identification Programs (CIPs) to collect and verify prospective customers’ names, birthdays, addresses, and identification numbers, among other things. Ongoing surveillance obligations require financial institutions to understand the nature and purpose of a customer’s relationships and activities on an ongoing basis.
When something looks unusual, or even when it does not but a specific regulatory threshold has been crossed, financial institutions must file Currency Transaction Reports (CTRs) and Suspicious Activity Reports (SARs). Each one contains detailed personal and transactional information. Your firms know the drill and they know just how costly monitoring and reporting on customers is. The expense of running this system seems to dwarf its effectiveness at stopping bad actors.
And we rarely pay much attention to the costs borne by the innocent people and businesses whose information is, unbeknownst to them, being tracked, haystacked, and potentially hacked. For decades, the approach to ferreting out illicit finance and uses of the financial system to facilitate other illicit activity has been the same: collect more and more data. The approach is not working particularly well, and technology has outpaced our legacy approach, so it is time for a change.
Public ledgers are more transparent and more difficult to alter than any paper record ever was. Cryptography allows us to be confident that a fact is true without knowing the underlying data. New technology offers us a genuine opportunity, not just an excuse to deregulate.
For example, attribute-based credentials could greenlight individuals holding verifiable credentials that attest to specific facts: age, citizenship, accredited investor status, absence from sanctions lists, without revealing the underlying data that generated those facts. A zero-knowledge proof can tell a counterparty “Yes, this person meets your requirement” without that counterparty knowing your name, income, or address.
Tools exist to limit the information individuals need to provide and the number of entities to which they must provide it. What is missing is the regulatory framework that would allow and encourage their adoption.
We need to move the federal government, and the institutions it regulates, away from prescriptive collection requirements and toward attribute-based verification wherever technologically feasible. We should look at our rules with fresh eyes and ask at every step: Do we need this specific piece of information? Do we instead need only to know a specific fact that this information happens to prove? Are the thresholds for collecting information on a particular transaction too low?
In answering this question, we need to resist the temptation to thresholds based on the ability of new technologies to easily and cheaply collect lots of data. And finally, if we do need a particular piece of information, does more than one firm need to collect it?
Pertinent to that last question, we should make it easier for registered entities to rely on third-party identity verification for CIP purposes. Right now, with limited exceptions, our CIP rules generally require each regulated entity to independently collect and verify customer information, even when a customer has already been vetted by another registered entity.
This duplicative collection means that the same person’s sensitive information gets copied, stored, and put at risk across dozens of institutions. If a customer has already been verified by one regulated, trustworthy entity, why not make it the norm for every subsequent institution to rely on that work? This area is ripe for experimentation, and the potential cost-savings for firms like yours are immense.
Another question we should ask in light of the new technology is whether we are forcing an intermediary into a situation simply because we want to collect information. The government looks to intermediaries to collect data, but some new technologies operate without intermediaries. Government will have to adjust its methods accordingly.
Intermediaries will continue to play a central role in our financial system, but they and their customers and counterparties may use disintermediated, permissionless tools. A network is truly permissionless when its core protocol operates through automated, immutable code rather than through the discretionary actions of an identifiable party, when there is no custodial intermediary standing between users and their assets, and when all participants and transactions are treated neutrally.
This base-layer infrastructure allows us to reduce unnecessary data collection while maintaining (and indeed, enhancing) the transparency of the underlying transaction record. Public blockchain networks typically produce permanent, public, auditable ledgers of every transaction that law enforcement can analyze using increasingly sophisticated blockchain forensics tools.
Conclusion
Americans deserve both security and privacy. Using new technologies, we can both be more protective of people’s data and more effective at rooting out illegal conduct. Tradeoffs will continue, as will the temptation to use new technologies in ways that the government of a free people should not. Honest conversation at this juncture will help regulators, regulated entities, and regular Americans benefit from technological change.
Thank you not only for your attention today, but for our many interactions over the years. We have not always agreed, but your willingness to listen and push back when you thought I was wrong helped me to do my job better.