
Institutional
Regulatory Gray Zones in Crypto: The Aftermath of Ambiguity
A regulatory gray zone forms when overlapping or guidance-only frameworks leave crypto companies unsure which regulator applies or what compliance requires. That ambiguity can advantage those who avoid compliance and stall responsible companies.
AUG 18, 2026
Last updated AUG 18, 2026 · V1
TL;DR
- A regulatory gray zone exists when overlapping, unsettled, or guidance-only frameworks leave companies unable to know which regulator has jurisdiction or what compliance requires.
- Ambiguity makes compliance a cost only some players pay, so projects that neglect identity checks (KYC), anti-money-laundering controls (AML), and proper handling of customer funds offer lower fees and get an upper hand.
- Gray zones push activity offshore through regulatory arbitrage, so the safeguards a customer gets depend on where the firm is registered, and the customer’s own country carries little weight.
- The FTX fiasco has demonstrated that a company without proper audits or controls out-competed careful rivals until it collapsed in November 2022, contaminating the whole industry.
- Clear rules provide definitions and rules that equalize everyone, letting responsible firms compete on a level field and keeping activity within reach of law enforcement.
- However, clarity helps only when the rules are well-designed.
- The live U.S. attempt to draw that boundary includes the already enacted GENIUS Act for stablecoins and the CLARITY Act for market structure, and until the remaining rules settle, gray-zone advantage keeps favoring the least scrupulous projects.
What exactly is a “regulatory gray zone” in crypto?
A regulatory gray zone exists when overlapping, unsettled, or agency-guidance-only frameworks leave firms unable to know in advance which regulator has jurisdiction or what compliance requires. The uncertainty is structural. It comes from the framework itself, and no single firm creates it.
The current U.S. landscape could show this pattern in several forms:
- State money-transmission licenses, which differ across all 50 states.
- Federal AML obligations that apply regardless of state licensing.
- Competing jurisdictional claims from the SEC and the CFTC, two federal regulators that each argue crypto assets fall under their authority.
- Rules set by enforcement action, with statute lagging behind.
Guidance is weaker than law, which keeps the zone gray. The March 2026 joint SEC–CFTC statement on token classification offered direction, yet agency guidance can be rescinded without a vote.
A statute cannot be undone that easily. That difference in durability is why guidance-only frameworks still count as gray.
Does a “regulatory gray zone” concern staking?
Mostly not, but there are some exceptions.
The March 17, 2026 joint SEC-CFTC interpretive release placed solo, self-custodial staking of digital commodities outside the federal securities laws, and it confirmed that ancillary features or alternate reward schedules do not change that treatment.
For a provider that acts as a non-discretionary agent, the practical uncertainty that made some platforms hesitant to offer staking is largely resolved. The relief is conditional and holds only where the provider takes no discretion over staking decisions, does not guarantee rewards, and does not interact with the user’s assets beyond the technical delegation of staking power.
The part on staking is an agency interpretation, not a statute, so it binds only the agencies that issued it and only for as long as they leave it in place.
This is why the CLARITY Act is paramount for durability: it would harden the current agency position into law that is hard to revert. If enacted, the CLARITY Act would place the current agency position into statute. It remains pending in Congress as of the date of writing.
Companies that want to understand how staking obligations relate to regulatory frameworks face the same uncertainty.
Why does ambiguity turn compliance into a competitive disadvantage?
Ambiguity makes compliance a cost that some firms pay and other firms avoid, which contradicts the usual logic of regulation. A U.S.-based, audited exchange spends a lot of resources to interpret unclear standards. A company that avoids that work spends nothing.
The audited exchange could carry several recurring costs:
- Legal interpretation of standards that are not written in plain statute.
- Custody controls that keep customer assets segregated and protected. Custody refers to who holds the customer’s funds and how those funds are safeguarded.
- KYC and AML programs that screen users and monitor transactions.
- Slower product cycles, because each release has to be double-checked due to unclear rules.
A company that ignores those obligations could offer lower fees and roll out features faster. As a result, ambiguity rewards the company that does less, which is the core of the problem. This is an industry-wide, structural and economic dynamic.
NOTE: Everstake’s institutional staking service is non-custodial and does not hold or manage customer assets, and therefore does not require custody controls, this information is provided for educational purposes.
How could gray zones push activity offshore?
Gray zones could push activity offshore because firms might choose where to incorporate, hold assets, and seek licenses based on which regime is lightest. Basically, a company can register in whichever country asks the least of it.
This practice is called regulatory arbitrage. It creates competitive distortions even between firms serving identical customers.
The result is a consumer-protection inversion. The safeguards a customer receives depend on where the firm is registered, and the customer’s own country has little bearing on those safeguards.
Two people in the same city can hold accounts at two exchanges with different compliance standards. Neither customer necessarily knows the difference until something breaks.
Offshore activity also reduces law-enforcement visibility. Supervisors and investigators find it typically harder to examine books, compel records, and act quickly when a firm is located outside their jurisdiction.
| Factor | Onshore, audited firm | Lightly regulated offshore firm |
| KYC / AML program | Required and examined | Often minimal or absent |
| Regulator visibility | Direct supervision | Limited or indirect |
| Fee level | Higher, reflecting compliance cost | Lower, reflecting skipped work |
| Customer recourse if firm fails | Defined legal channels | Often uncertain |
What does FTX tell us about what thrives in the gray zone?
The fall of FTX is the clearest adjudicated case of what a gray zone can lead to. Court findings and regulators concluded that the firm lacked proper audits and internal controls before it collapsed in November 2022.
The record here is a matter of established fact. In November 2023, a federal jury convicted founder Sam Bankman-Fried on 7 counts, and in March 2024 he was sentenced to 25 years in prison.
The courts and prosecutors characterized the conduct as fraud. Those conclusions belong to the bodies that reached them.
Gray zones do more than tolerate bad actors by letting such actors out-compete compliant firms on fees and speed until the risks become visible.
How do clear rules actually strengthen the good actors?
Clear rules strengthen responsible firms by defining the perimeter and introducing more clarity, so every company knows the same obligations apply. The perimeter is the boundary, the same field that establishes which activities are regulated and which firms must follow which rules.
Clear rules specify who may hold customer funds and who must register. They also state who is subject to anti-fraud, insider-trading, and AML requirements. Those rules unify the playing field by providing industry-wide definitions.
A defined perimeter produces three practical effects:
- Responsible firms compete on a level field, because the same baseline binds everyone.
- Institutions gain the certainty they need to enter a market with known rules.
- Activity stays onshore, keeping it within reach of supervisors and investigators.
The U.S. market-structure debate is an attempt to draw that perimeter in real time. The CLARITY Act addresses how tokens and market participants are classified, and the GENIUS Act (which is already enacted) sets a framework for stablecoins, which are crypto tokens designed to hold a steady value against a currency like the dollar.
Everstake has operated as a non-custodial validator and staking provider across 130+ networks to date, and advocated for clear rules and being able to compete on controls and reliability.
A defined perimeter rewards those who already do the work, which is the standard Everstake’s institutional staking service is built around.
Unresolved questions
It is important to emphasize that clarity alone does not make a framework good.
There are several unresolved questions:
- Where the perimeter set is contested, including whether the SEC or the CFTC holds jurisdiction and what counts as a security.
- Overly rigid rules can drive builders and firms offshore, producing the same outcome that ambiguity does.
- The industry has an obvious self-interest.
These contradictions are the reason to continue discussions and strive for a fair outcome and better regulatory design for the industry.
What happens if the rules never get clarified?
If the rules never get clarified, the status quo persists, and its costs might compound over time. A so-called regulation-by-enforcement might prevail, where the companies discover what a regulator considers illegal only once it brings a case against them.
With no written rule set in advance, planning remains difficult:
- Companies cannot plan arrangements and product roadmaps with confidence.
- Activity continues to drift offshore toward lighter regimes.
- Gray-zone advantage keeps accruing to the least scrupulous operators.
Well-designed regulation can support the industry and give companies a stable base to plan from.
The details are still being discussed in Congress and the agencies. How the perimeter gets drawn will determine whether clarity helps careful firms or adds new burdens.
FAQ
What is a regulatory gray zone in crypto?
A regulatory gray zone is a situation where overlapping or guidance-only frameworks leave a firm unable to know which regulator applies or what compliance requires. In the U.S., this includes competing SEC and CFTC claims plus state-by-state money-transmission licensing across 50 states.
Why does regulatory uncertainty hurt compliant firms?
Regulatory uncertainty hurts compliant firms because ambiguity turns compliance into a cost only careful operators pay.
What is regulatory arbitrage in crypto?
Regulatory arbitrage is when companies choose where to incorporate, hold assets, and seek licenses based on which regime is lightest.
Does FTX prove that light regulation is dangerous?
FTX is an adjudicated case where a firm lacked proper audits and controls before collapsing in November 2022. Its founder was convicted on 7 counts in November 2023 and sentenced to 25 years in March 2024.
What are the CLARITY Act and the GENIUS Act?
The CLARITY Act is a U.S. market-structure proposal addressing token classification and regulator jurisdiction. The GENIUS Act has set a framework for stablecoins. Both aim to define the perimeter that responsible firms operate within.
Do clear rules produce a better crypto market?
Clear rules do not automatically produce a better market, because clarity helps only when the rules are well-designed.
Disclaimer:
This article is provided for informational and educational purposes only and does not constitute legal, regulatory, tax, financial, or investment advice. The views expressed do not represent the official position or opinion of Everstake or its affiliates. References to laws, regulations, guidance, or specific firms reflect information available as of the date of writing and may have since changed.
Share with your network