You think the rules changed? In 2025, they didn't just change; they got messy. If you are building a crypto project or running an investment firm, you are likely staring at a compliance landscape that looks nothing like it did two years ago. The Securities and Exchange Commission (SEC) is no longer playing by the old playbook, and neither should you.
Here is the reality check: the era of blanket enforcement is fading, but that doesn’t mean you can relax. Under Chairman Paul Atkins, who took over in April 2025, the SEC shifted gears. We went from Gary Gensler’s "everything is a security" stance to something more nuanced, often called Project Crypto. But nuance is dangerous if you don't know where the lines are drawn. You need to understand what this new environment actually demands of your business.
The Shift from Enforcement to Guidance
Let’s look at the numbers. In fiscal year 2024, the SEC brought 784 enforcement actions, with more than half involving crypto. Fast forward to the first half of 2025 under the new leadership? Enforcement dropped by 42%, and crypto-related cases fell to just 28%. This isn’t because regulators stopped caring. It’s because they are trying to define the boundaries before punishing people for crossing them.
Project Crypto, announced in August 2025, is the current focus. The goal here is clarity. The SEC wants to establish safe harbors and exemptions for digital assets. For you, this means the risk profile has changed. You aren't as likely to get sued for launching a token tomorrow, but you are under intense scrutiny to document how you classify that asset. If you assume you are safe because the hammer hasn't fallen yet, you might be wrong when it finally does.
Regulation Best Interest (Reg BI) Is Still a Nightmare
While everyone talks about crypto, traditional finance firms are drowning in paperwork for Regulation Best Interest (Reg BI). This rule requires broker-dealers to act in the best interest of their retail customers. Sounds simple, right? Wrong.
Deloitte reports that 63% of firms struggle to prove they comply with Reg BI. Why? Because documenting conflicts of interest is hard. If you sell a product that pays you a higher commission, you have to tell the client, explain why it’s still the best option, and keep records proving you did so. One mid-sized broker-dealer told us they spend 40% more time on documentation now than they did last year, yet they still received deficiency letters. The cost? About $315,000 annually for a mid-sized firm, mostly going toward monitoring systems and staff time.
| Challenge Area | Common Failure Point | Recommended Action |
|---|---|---|
| Conflict Disclosure | Vague language about fees | Use plain-English fee breakdowns |
| Documentation | Incomplete meeting notes | Automate CRM logging |
| Product Suitability | Failing to assess complex products | Implement tiered suitability checks |
AI Governance: The New Compliance Frontier
Artificial Intelligence isn't just a buzzword anymore; it’s a regulatory target. The SEC’s 2025 examination priorities explicitly list AI governance. If you use algorithms to trade, recommend investments, or manage risk, you need a framework. And most firms don't have one that passes muster.
A staggering 78% of capital markets organizations claim they have formal AI governance frameworks. But only 32% feel confident those frameworks meet regulatory expectations. That gap is where fines happen. One compliance officer noted that their firm spent $250,000 a year on AI monitoring tools, yet regulators still questioned their oversight during exams. The problem isn't the tool; it's the lack of human accountability behind the algorithm. You need to show who owns the AI model, how it’s tested, and what happens when it makes a bad call.
The State-Federal Patchwork Problem
Here is the part nobody warns you about: while Washington might be deregulating, states are stepping up. California, New York, and Texas have all proposed their own digital asset regulations. These rules often conflict with federal rollbacks. Imagine complying with SEC guidance in D.C., then having to adjust for stricter state-level disclosure rules in San Francisco or New York City.
This creates a compliance patchwork. Multi-state firms report that managing these diverging requirements is their top operational headache. If you operate across borders, you need a strategy that accounts for both federal leniency and state strictness. Don't assume a federal exemption protects you from state enforcement.
Crypto-Specific Pitfalls to Avoid
Even with Project Crypto underway, specific pitfalls remain deadly. FINRA reported an 18% increase in deficiency letters related to crypto disclosures. The biggest error? Failing to clearly disclose that retail crypto offerings were provided through unregistered affiliates. 72% of broker-dealers messed this up.
- Unregistered Affiliates: If your brokerage sells tokens via a separate entity, say so loudly. Don't bury it in footnotes.
- Custody Rules: Recent penalties hit advisers who failed to distribute GAAP-compliant financial statements. Keep your books clean and audited.
- Rule 105 Violations: A private fund adviser paid $250,000 recently for violating Regulation M. Understand the trading restrictions around offerings.
How to Build a Resilient Compliance Program
So, what actually works? Successful firms share three traits. First, they coordinate across departments. Marketing, legal, and tech must talk. Second, they run quarterly impact assessments on regulatory changes. Third, they document everything, especially AI decisions.
You also need the right people. It takes 8-12 months for a new hire to become proficient in general securities regs. Add another 4-6 months for crypto specialization. If you are scaling fast, budget for this learning curve. Don't expect a junior associate to handle a complex token classification issue without senior review.
Finally, engage with regulators early. One chief compliance officer avoided enforcement action by self-reporting a Rule 105 violation after talking to the SEC’s Office of Risk and Strategy. Proactive dialogue beats reactive defense every time.
Key Takeaways
- Enforcement is down, but scrutiny is high: Fewer lawsuits, but more detailed examinations.
- Reg BI is costly: Budget heavily for documentation and conflict disclosure.
- AI needs oversight: Tools alone won't save you; you need human governance frameworks.
- Watch the states: Federal deregulation doesn't mean state deregulation.
- Document everything: In crypto, clear disclosure of affiliate relationships is non-negotiable.
Has the SEC stopped enforcing crypto laws?
No. While the number of enforcement actions decreased by 42% in the first half of 2025, the SEC remains active. The shift is toward defining clear regulatory boundaries through initiatives like Project Crypto rather than blanket litigation. Investors and firms still face significant risks if they fail to adhere to existing disclosure and anti-fraud provisions.
What is Regulation Best Interest (Reg BI)?
Reg BI is a SEC rule requiring broker-dealers to act in the best interest of their retail customers when making recommendations. It includes four main obligations: Disclosure, Care, Conflict of Interest, and Compliance. Firms must fully disclose material facts, exercise reasonable diligence, identify and mitigate conflicts, and maintain policies to achieve compliance.
Do I need special compliance training for crypto?
Yes. General securities knowledge is not enough. Specialized areas like token classification, custody rules for digital assets, and cross-border jurisdictional issues require additional training. Industry benchmarks suggest adding 4-6 months of specialized training beyond standard securities proficiency.
How much does AI compliance cost?
Costs vary, but mid-sized firms report spending upwards of $250,000 annually on AI monitoring tools and governance frameworks. However, technology costs are often lower than the cost of remediation following a regulatory deficiency letter regarding inadequate AI oversight.
Are state crypto laws conflicting with federal rules?
Increasingly, yes. States like California, New York, and Texas are proposing independent digital asset regulations. These may impose stricter disclosure or registration requirements than anticipated federal rollbacks, creating a complex patchwork for multi-state operators.