The Regulator's Covenant: When AI Meets FINRA, Who Writes the Rules?
CryptoAlex
It begins with a quiet tremor that no oracle predicted. Not a flash loan on Ethereum, not a rug pull on Solana, but a whisper from a Treasury Secretary in Washington. Scott Bessent, the keeper of America's financial soul, stood before a microphone and proposed something that will echo through the cathedrals of code: a new independent agency to regulate frontier AI models, modeled after FINRA, the self-regulatory organization that oversees broker-dealers. My code was the covenant, not just the contract. But now, the covenant faces a new notary.
Bessent's vision grafts the DNA of financial regulation onto the body of artificial intelligence. The agency would sit under the SEC, the same commission that has waged war on crypto with the Howey Test, treating tokens as securities. The same SEC that charged Coinbase for operating an unregistered exchange. The same SEC that sees innovation not as a garden to tend, but as a forest fire to contain. In the silence of the bear, we heard the truth. And the truth is this: the regulator's hammer is swinging toward AI, and blockchain must listen, because the echoes will reach us.
Why should a Web3 community founder care about a proposal targeting large language models? Because the logic is identical. The arguments for regulating AI as a systemic financial risk mirror the arguments for classifying crypto assets as securities. Both rest on the premise that unbridled technological power requires a centralized guardian. Both assume that a government-appointed body can understand the chaos of emergent intelligence. Both ignore the fundamental lesson of decentralization: trust is compiled, not claimed.
Every broken token taught me how to hold value. I have watched DeFi protocols lose 40% of their liquidity in a week because a single smart contract bug drained trust. I have seen L2 rollups promise scalability only to choke on their own data. And I have learned that no amount of centralized oversight can prevent the failures that arise from misaligned incentives. The Bessent proposal is an attempt to impose a top-down incentive model on something that defies top-down control. It will fail, but the damage it causes along the way will be real.
Let us examine the proposal through the lens of blockchain philosophy. FINRA was created in 2007 to regulate securities firms with rules that took decades to refine. It enforces compliance through examinations, fines, and suspensions. It is effective for a slow-moving industry where rules change annually, not hourly. But AI models evolve weekly. Parameters double every few months. New attack vectors surface daily. A regulatory body modeled on FINRA will be running a marathon against sprinters. It will always be behind, and in its desperation to catch up, it will impose blanket constraints that throttle innovation.
The specific mechanism Bessent proposes is telling: the agency will define 'frontier AI models' by some threshold—likely compute, parameters, or capability—and subject them to pre-market testing, ongoing monitoring, and post-market liability. This is exactly the logic of securities registration. You file a prospectus, you wait for approval, you comply with disclosures, and you face lawsuits if your token—or in this case, your model—causes harm. But an AI model is not a security. It is a tool that can be used for both healing and harm, depending on the hands that hold it. Regulating the tool as if it were the crime itself is a category error that will lead to absurd outcomes.
Consider the compliance cost. For a crypto startup, SEC registration can cost millions in legal fees. For an AI startup, equivalent compliance could cost tens of millions. This will create a moat around incumbents. OpenAI, Google, and Anthropic have the resources to hire armies of lawyers and compliance officers. Small teams building open-source models will be crushed before they can even define their frontier. The result is not safety, but monopolization. The very thing decentralized technologies were born to fight.
I have been inside this machine. In 2020, during DeFi Summer, I audited Uniswap V2's smart contracts not for vulnerabilities, but for philosophy. I wanted to understand how code could enforce fairness without a central authority. I found that transparency was the ultimate form of respect for users. Immutable rules, visible to all, created a trust that no regulator could guarantee. The Bessent proposal inverts this: it asks us to trust a small group of appointed officials to define 'safe' AI, just as the SEC defines 'safe' investments. But we have seen what happens when a small group holds that power. They become captured. They become slow. They become the very bottleneck they were meant to remove.
Now for the contrarian angle. Perhaps some regulation of frontier AI is inevitable. Perhaps even desirable. The risk of a misaligned AGI causing catastrophic harm is real. But the solution is not a centralized agency modeled on financial regulation. It is a decentralized, transparent, and programmable framework built on the principles of Web3. Imagine a DAO that governs AI model releases, where validators stake tokens to attest to safety audits, and where slashing occurs if a model is later found harmful. Imagine on-chain registries of red-team results, with cryptographic proof that tests were conducted fairly. Imagine a market for AI safety insurance, where premiums adjust based on real-time risk assessments from oracles. This is the path we should take, not the path of Washington.
The proposal also reveals a hidden battle for political influence. Bessent is signaling that the SEC's power should expand into AI, which pits the commission against other agencies like the FTC and NTIA. It is a bureaucratic land grab, not a thoughtful regulatory design. And it is a land grab that will be exploited by lobbyists from the very companies it claims to regulate. In the crypto world, we have seen this before: the more regulation, the more power flows to those who can afford to influence it. The little guys—the two-person startups building price oracles, the DAOs experimenting with quadratic voting, the indie researchers training small models—will be erased.
During the bear market of 2022, I retreated into silence. I deleted social media and read Vitalik Buterin's early essays. I found solace in his vision of a 'crypto city' where governance is modular, transparent, and permissionless. That vision is now under threat not just from bad actors within crypto, but from well-intentioned regulators outside it. They do not understand that code is the only honest liar. They see a black box and want to open it with a crowbar. But the box does not open that way. It opens only when the keys are distributed among many hands.
Where does this leave us? The Bessent proposal is a signal that the regulatory paradigm is shifting. It will not pass overnight. It will face opposition from libertarians, from the AI industry, and from crypto advocates who fear the precedent. But it is a wedge. If AI can be regulated like securities, then what stops the SEC from regulating any decentralized protocol that uses AI? What stops them from classifying an autonomous agent as a security issuer? The slippery slope is real, and we must build guardrails now.
My code was the covenant, not just the contract. I wrote that line after realizing that smart contracts are more than legal agreements—they are promises encoded in math. The covenant of decentralized technology is that power is diffused. The Bessent proposal is a covenant of another kind: a promise of safety through centralization. It is a trade we should not accept. We can build AI safety without sacrificing the spaces we have built for freedom. We can audit models on-chain, vote on risk thresholds with tokens, and punish failures with smart slashing. We can create a regulatory covenant written in code, not in Washington.
In the silence of the bear, we heard the truth. The truth is that the market cycles taught us resilience. The truth is that every crash cleansed the system of those who were not building for the long term. The same will happen with regulation. Those who survive will be those who have already embedded transparency, auditability, and decentralization into their DNA. They will not fear the regulator's covenant because they have already written a better one.
The final question is rhetorical, but it demands an answer: Who writes the rules for the machines that will write the future? If we do not take responsibility, someone else will. And their covenant will not be ours.
— Based on an analysis of Scott Bessent's proposal to regulate frontier AI models, with reflections on the intersection of blockchain philosophy and regulatory design.