THOUGHT LEADERSHIP

Regulation Crypto Assets doesn’t just affect crypto companies – and why AI's needed to stay compliant

Sep 02, 2026

Regulation Crypto Assets doesn’t just affect crypto companies – and why AI's needed to stay compliant

The SEC has proposed a new set of rules called Regulation Crypto Assets (Regulation CA) in the US. By name, it’s aimed at making it easier for crypto projects to raise money legally, boosting innovation. Most of the media coverage treats it that way.

That framing misses the bigger story. Regulation CA changes everything about how companies across all sectors raise capital, not just crypto. But it will also introduce compliance gaps that are out of humans’ scope. Continuous AI verification can solve it, and FLock.io knows how.

How the new rule changes fundraising for everyone, not just crypto

Previously (for almost a century!), to fundraise you had two options: go public, or use an exemption. The former lets you sell to anyone, but it’s expensive, slow and means you take on real legal liability. The latter means less paperwork and no full registration, but each exemption comes with its own limitation, like only letting you sell to wealthy accredited investors, or you can’t advertise it, or the amount you can raise is capped.

But restrictions will be lifted for one type of asset, when Regulation CA enters into force in October 2027.

[ 👋 Hi there! If you’re here to find out more about FLock, follow us on X and email us at hello@flock.io to learn what we do in helping companies meet compliance in AI.]

Regulation CA creates two exemptions

Regulation CA creates two exemptions:

  1. Startup exemption (raise up to $5 million)
  2. Fundraising exemption (up to $75 million a year).

They only work for a “covered investment contract” i.e. a crypto token that is bundled with an investment deal but is not itself a stock or a bond. Genuine equity and debt are explicitly pushed back to the old frameworks, says the SEC.

If you go through these exemptions, the SEC hands out all the perks of going public but on the terms of the private one. Tokens sold under the startup exemption “would not be restricted securities” – meaning no holding period, freely tradable right away. The exemption “would not limit an issuer’s ability to sell … to retail investors”. This means ordinary people, not just the wealthy – and “general solicitation … would be permitted”, so you can advertise it openly.

As for where it’s traded, these tokens can plug straight into the crypto market: Binance, Coinbase, and other exchanges that trade 24/7, front deep retail order books, and reach anyone in the world with a phone. Regulation CA gives an issuer public-market reach (retail buyers, open advertising, instantly tradable tokens on global crypto exchanges) on private-market obligations.

The rule has huge compliance gaps that humans can’t fix

Regulation CA creates several compliance gaps that humans will struggle to solve on their own.

Problem one: file-and-declare, with enforcement only after the fact

Reg CA leans heavily on self-certification. Under the startup exemption you begin by filing a notice that says you intend to do the work you promised investors within four years. And under either exemption you can later file a second form declaring that your obligations are finished and the investment deal has “ceased to exist.” Nobody at the SEC signs off on those filings in advance.

To be fair, this is not new or unique to crypto. Reg D )the biggest fundraising channel in the country) works almost entirely on a file-and-proceed basis, and the securities laws lean heavily on catching bad actors after the fact. Fraud liability still applies under Reg CA, investors can still sue, and state regulators keep their own fraud powers.

The worry is the combination. If you combine self-certification and light disclosure with the broad-reach features above, there is a marked difference. Suddenly there is a much larger population of retail-facing, freely tradable tokens that no one examines until something goes wrong. It’s policed by an enforcement system that has never had the resources to check the long tail of small issuers. There is always a bigger fish to fry.

It leaves two major loopholes unaddressed.

1. Self-declared exits.

Companies can stop following securities laws simply by filing a “we’re done” form claiming they’ve finished their work, with zero SEC review or verification. A rule that lets a company declare its own way out of the securities laws is leaning a lot of weight on a form it will almost never audit.

2. Unenforceable investor caps.

The cap that holds a non-wealthy buyer to 10% of income or net worth relies on self-reporting. In a pseudonymous crypto market, anyone can bypass this limit using multiple wallets, and the cap disappears entirely once tokens trade on exchanges.

Once the token trades on Binance or Coinbase – where most retail actually buys – no per-investor limit applies to anyone. The most concrete investor protection in the proposal turns out, in the venue that matters most, to be close to unenforceable.

Problem two: the incentive for startups to ‘tokenise’ just for the discount

The next concern is that companies might raise in tokens simply to benefit from the better terms. Ones that would otherwise have fallen under Reg A or Reg CF would move into Reg CA.

Reg CA won’t ruin the whole stock market because it cannot be used for normal company shares or corporate debt. You can't sell regular stock or bonds through Reg CA. Also, the fundraising limits ($5 million or $75 million) are the same as traditional rules, so it doesn't allow companies to raise larger amounts of money.

The loophole is at the startup level. At the early stage, the temptation to fake a crypto angle is massive. Under Reg CA’s $5M Startup Exemption, you can advertise to the general public, sell to ordinary retail buyers without income caps, and avoid publishing audited financial statements. It gives you maximum reach with the fewest legal requirements.

Even a major crypto venture capital firm, Andreessen Horowitz (a16z), warned the SEC about this. They warned that founders might issue tokens not because the project actually needs a token, but because it gives founders a fast, easy way to dump tokens onto regular investors and cash out. “Without hard caps... projects may use the Proposal to facilitate large-scale distributions that function more like exit liquidity events than capital-raising transactions intended to fund network development.”

Problem three: the exit, which reaches beyond crypto

A share of Apple or Microsoft is a security forever. The company can never file a piece of paper and suddenly declare, “Our stock is no longer a security, so we don't have to follow SEC disclosure rules anymore.”

But under Regulation CA, companies can raise money from the public using the legal protections of a security, but then strip those investor protections away simply by checking a box. Investors end up holding high-risk digital assets with zero ongoing financial transparency.

It threatens all of fundraising, not just crypto. Since 1933, American financial law has operated on a strict deal. If you want access to public money and instant trading, you MUST provide ongoing financial transparency. Regulation CA breaks this. If founders figure out they can raise public money and get rid of SEC oversight just by structuring their deal as a token instead of a share of stock, many non-crypto startups will feel pressure to restructure their fundraisers.

There should be an independent, accountable third party

The better fix isn’t to ask the SEC to vet every deal. It can’t at this scale, which is exactly why the rule falls back on self-certification in the first place. The fix is to insert an independent, accountable third party between the issuer and the public, so that someone with their own license and liability on the line has to stand behind a deal before it reaches retail investors.

This is how Hong Kong polices its IPOs, but adapted to crypto. That accountability layer would have three parts:

1. A broker-dealer as sponsor.

Much like the sponsor and bookrunner that a Hong Kong listing requires, a licensed intermediary would run genuine due diligence and formally sign off on the offering, putting its own regulatory standing behind the deal rather than letting the issuer wave itself through. A gatekeeper who can be sanctioned is a gatekeeper who actually reads the fine print.

2. An independent legal opinion.

A qualified attorney would certify the deal’s legal footing, checking that the token really fits the exemption, that the structure is what it claims to be. It would be an outside professional judgment on the record, not the issuer’s own assertion.

3. A smart-contract auditor.

Not a financial auditor, but a technical one, who verifies that the contract is immutable — that its code cannot be quietly altered after the fact. This is the crypto-native check the older exemptions never needed, and it may be the one that matters most: it converts “we’ve finished our work and stepped away” from a claim you take on faith into something anyone can verify on-chain.

FLock.io’s solution uses AI for continuous verification

Forcing crypto issuers to hire human auditors or law firms re-imports an old Wall Street disease: conflicts of interest. When gatekeepers are paid by the companies they police, they are incentivised to turn a blind eye to stay hired.

The real solution is automated, neutral AI verification. Instead of trusting paid human auditors or self-certified forms, every company raising money under Reg CA should be monitored by an automated, neutral AI platform.

Most SEC compliance checks in crypto are objective data points that machines can easily monitor 24/7, such as:

Smart contract code

The AI checks on-chain code to confirm the team can't secretly change the rules or steal funds (verifying true immutability).

Team activity

It tracks developer code updates and public communications to check if the team has actually stepped back, or if they are still running the project.

Marketing checks

It crawls social media and ad copy to make sure the company isn't using illegal, misleading hype to sell tokens.

Because key crypto compliance rules are objectively trackable, an AI platform can monitor issuers continuously around the clock. It verifies smart-contract code, tracks team developer activity and scans promotional channels without the expense, bias or delays of human committees.

Machines don't get bribed, don’t have conflicts of interest, and can monitor thousands of crypto projects simultaneously around the clock.

Weekly newsletter

No spam. Just the latest releases and tips, interesting articles, and exclusive interviews in your inbox every week.

Read about our privacy policy