SEC Commissioner Hester Peirce says real, permissionless DeFi shouldn't need an SEC exemption. Her comments show how federal regulators are picking apart what counts as control and who acts as an intermediary in crypto trading.
When does a DeFi protocol stop being just open software and start acting as a regulated intermediary? SEC Commissioner Hester Peirce has staked out her view: if a platform is truly permissionless and decentralized, it shouldn't need an SEC exemption to run. But the federal rules are still split. The SEC and CFTC each draw their own lines on what counts as control in decentralized finance.
Defining control in DeFi
The SEC's latest order on tokenized securities venues (TSVs) shows the agency is focused on who really runs things. Under this order, a TSV that uses automated market maker pools to trade tokenized stocks has to follow strict rules. The SEC looks at "provides" in practical terms. If someone deploys a trading contract, changes rules or parameters, sets fees, or can pause trading, that's control. Just putting a whitelist in the code isn't enough. Even with automation, people can still pick venues, set fees, or decide who gets in. That keeps the venue outside what Peirce calls "truly decentralized."
In September 2026, the SEC granted a five-year conditional exemption for Tokenized Securities Venues, allowing them to trade tokenized NMS stocks via permissioned automated market makers and liquidity pools.
Peirce's view isn't binding policy. The SEC hasn't set a formal definition for "truly decentralized." Instead, the agency's orders and staff statements focus on specific powers: custody, access, software settings, fees, recommendations, routing, and execution. Each of these actions falls under a different law and brings its own legal effects. The result is a patchwork of rules.
SEC and CFTC split on intermediaries
The SEC's Division of Trading and Markets has put out a staff statement explaining when it won't object to certain crypto asset securities interfaces running without broker-dealer registration. This only covers a narrow set of cases, and only for a limited time. It applies to interfaces where users prepare transactions with self-custodial wallets. The user must hold the keys, set transaction details, and sign off. The interface has to show several execution routes, filterable by clear factors, and run on pre-set, verifiable rules. The staff position leaves out providers who solicit trades, recommend investments, hold user assets, execute or settle trades, or route orders. Fee structure matters too: only flat or neutral percentage fees paid by users are allowed. Payments from third parties based on trade size or frequency are not.
The CFTC's Market Participants Division has taken a different tack. Its staff letter gives conditional enforcement relief to passive software providers who don't register as introducing brokers, as long as users trade directly with designated contract markets or through registered intermediaries. These providers can promote derivatives, point users to certain firms, and get transaction-based fees. But they can't hold assets, give buy or sell signals, or decide how trades are routed or executed. The relief depends on disclosures, marketing controls, written promises, recordkeeping, and Division notification. This setup allows more promotion than the SEC's, but still draws a hard line at operational control.
The SEC's conditional relief for TSVs includes strict limits on the types of instruments traded, trading volumes, and participant access. The exemption is designed as a bridge toward durable rulemaking, with a five-year window and a formal public comment process under File No. 4-927.
Operational powers and regulatory boundaries
At the core of these rules are six types of control: custody, access, recommendations, routing, fees, parameters, and pause authority. Each agency addresses these in its own way. The SEC's TSV order covers a specific securities venue model. Its staff statement applies to certain crypto interfaces. The CFTC's letter covers derivatives software in the registered market. Technical design, disclosures, access rules, marketing limits, and recordkeeping all help decide if a provider must register or face enforcement.
For DeFi builders and users, the real question is who holds the keys-both literally and figuratively. Who controls access and assets? Who can recommend, route, or execute trades? Who sets fees or changes the software? Who can pause the system? The answers decide which regulator and which law applies. As reported earlier, even in decentralized trading, operational power can shift how markets work and how regulators look at them.
Decentralization still undefined
Even though Peirce says removing the trusted intermediary weakens the case for regulation, federal law still doesn't have a single test for decentralization. The SEC and CFTC actions create a fact-by-fact map of who keeps control, with different boundaries for each order and staff statement. A protocol's core code might be locked, but its frontend could still steer users, collect fees, or block access. Software that connects users to regulated firms might leave orders and assets outside the provider's hands, but the legal analysis always comes back to who controls what, and how.
For now, "truly decentralized" is just a phrase. It has no legal force. The result is a patchwork of rules, where every protocol, interface, and governance setup has to be checked on its own. Until federal agencies agree on a single standard, DeFi projects will keep navigating a shifting set of definitions and enforcement priorities. Peirce's view may offer a principle, but the real test is in the details of control, not in talk about decentralization.
The SEC and CFTC have each set out their own ways to judge DeFi platforms, but neither has given a full definition of decentralization. This leaves developers and users to sort through a mix of operational, technical, and legal factors when building or using DeFi protocols. The lack of clarity means even small changes in how a protocol or interface is run can bring big regulatory consequences.
In DeFi, the line between self-custody and intermediary control is often blurry. Permissionless smart contracts might run trades automatically, but the surrounding setup-interfaces, whitelists, fee models, and governance-can bring new forms of control. As federal regulators keep updating their approach, the question of what counts as "truly decentralized" will keep shifting for the industry.