# Summary of Digital Commodities and Blockchain Technology Regulatory Framework
This comprehensive legislation establishes a new regulatory framework specifically for digital commodities and blockchain technology, creating a balanced approach that protects investors while fostering innovation.
## Key Components
1. **New Regulatory Structure**:
- Creates new categories for digital commodity exchanges, brokers, and dealers under the Commodity Futures Trading Commission (CFTC)
- Establishes "qualified digital asset custodians" as a new regulatory category
- Defines "mature blockchain systems" with special regulatory treatment
2. **Core Requirements**:
- Mandates segregation of customer assets and strict custody requirements
- Requires robust risk management systems
- Sets capital requirements for digital commodity brokers and dealers
- Establishes new disclosure and reporting obligations
- Defines "blockchain control persons" with special restrictions on selling digital commodities
3. **Innovation-Focused Provisions**:
- Creates a "Strategic Hub for Innovation and Financial Technology" (FinHub) at the SEC
- Establishes "LabCFTC" as a dedicated innovation lab within the CFTC
- Provides exemptions for SEC-registered entities from certain CFTC requirements
- Includes provisions for expedited hiring of digital commodities experts
4. **Studies and Research**:
- Mandates studies on decentralized finance (DeFi)
- Requires a study on non-fungible tokens (NFTs)
- Directs a study on financial literacy among digital commodity holders
- Requires a study on tokenized securities and derivatives
5. **Exclusions**:
- Excludes decentralized finance activities from regulation
- Excludes certain blockchain-related activities from regulatory requirements
The legislation aims to create a functional regulatory framework that acknowledges the unique benefits and risks of digital commodities while ensuring investor protection, preventing market manipulation, and promoting the responsible development of this emerging technology within the United States. It seeks to prevent the shift of digital commodity development to less regulated countries by establishing a clear, balanced regulatory path.
HR 2659 creates a federal task force to address cyber threats from China's state-sponsored actors, specifically targeting groups like Volt Typhoon identified in a 2024 CISA advisory. The task force, led by CISA and FBI directors, coordinates federal agencies responsible for critical infrastructure security to detect and respond to cyberattacks. It must produce annual reports - including classified assessments of infrastructure risks and recommendations - to Congress within 540 days of formation and for five years after. These reports will guide federal efforts to protect critical infrastructure (like energy grids and transportation systems) and inform owners/operators through a public awareness campaign.
HR 1770, the Consumer Safety Technology Act, requires federal agencies to study and pilot new technologies to improve consumer safety. Title I mandates the Consumer Product Safety Commission to run a one-year AI pilot program to track product injuries, identify hazards, monitor recalls, and check imports, then report findings to Congress. Title II directs the Commerce Secretary to study how blockchain technology can prevent fraud in consumer transactions, including public input and a 6-month report to Congress. Title III requires the Federal Trade Commission to report on its enforcement actions against deceptive practices involving digital tokens and recommend improvements to protect consumers. The bill affects the Consumer Product Safety Commission, Commerce Department, and FTC, focusing on research and reporting rather than immediate regulatory changes.
HR 1709, the "Understanding Cybersecurity of Mobile Networks Act," requires the Assistant Secretary of Commerce to produce a report within one year of enactment examining cybersecurity vulnerabilities in mobile service networks and devices. The report must assess how mobile providers address security risks, customer awareness of cybersecurity when purchasing services, encryption practices, barriers to adopting stronger security measures, and the prevalence of surveillance technologies like cell site simulators. It specifically excludes 5G networks and focuses on real-world vulnerabilities affecting U.S. mobile networks and devices used by consumers, businesses, and government agencies. The study aims to inform future policy by gathering data from providers, industry experts, and government agencies, without mandating immediate changes to security standards.
The ANCHOR Act requires the National Science Foundation to develop a plan within 18 months to improve cybersecurity and telecommunications for the U.S. Academic Research Fleet - comprising university- and lab-operated oceanographic research vessels. The plan must assess each vessel's specific needs for internet speed, data transfer, telemedicine, and remote expert access during missions, alongside cost estimates for upgrades like satellite equipment and staff training. It also mandates evaluating shared solutions to reduce costs and outlining funding strategies involving NSF, Navy research offices, and vessel operators. The bill directly affects research vessels conducting ocean science, aiming to modernize their digital infrastructure without altering scientific methods.
The TAKE IT DOWN Act requires major social media platforms and websites hosting user-generated content to establish a 48-hour removal process for nonconsensual intimate visual depictions (including deepfakes) upon verified request. It defines "nonconsensual intimate visual depictions" as images or videos of identifiable people shared without consent, with criminal penalties for sharing such content with intent to cause harm. The law exempts law enforcement activities, medical purposes, and content shared for legitimate educational reasons. Platforms must remove these materials quickly but are protected from liability if they act in good faith. This law directly affects social media companies and individuals whose intimate images are shared without consent.
HR 859 requires manufacturers to clearly state before purchase whether internet-connected consumer devices (like smart speakers or home monitors) contain a camera or microphone. It directly affects device manufacturers, excluding phones, laptops, and dedicated cameras (which consumers reasonably expect to have such features). The Federal Trade Commission enforces this as an unfair/deceptive practice under existing law, with guidance issued within 180 days of enactment. The law applies only to devices made after the FTC issues its guidance, not older models.
This bill requires the Department of Homeland Security (DHS) to create a new department-wide policy and process to protect sensitive research and development projects from unauthorized access or disclosure during acquisitions. It directly affects DHS research programs by mandating specific security safeguards for their work. Key provisions include requiring DHS to develop this policy within one year, submit a GAO report on compliance with existing national security guidelines (NSPM-33), and provide a congressional briefing on implementing the new security framework. The bill focuses on establishing concrete security protocols for DHS research, not on funding or broader policy changes.
HR 788 requires the Department of Energy (DOE) and Small Business Administration (SBA) to establish formal agreements for joint research and development (R&D) projects. This mandates that small businesses must be included in these collaborative efforts, aligning DOE and SBA missions to advance shared goals like clean energy innovation. The bill creates a two-year reporting requirement for the agencies to Congress, detailing coordination, research achievements, and future collaboration opportunities. It does not authorize new funding and ensures R&D activities comply with existing research security rules.
HR 152, the Federal Disaster Assistance Coordination Act, requires FEMA to study and streamline how disaster assistance applicants and agencies collect and share information. It directs FEMA to develop plans within two years to simplify paperwork for applicants, reduce duplication in damage assessments, and explore technologies like drones for faster assessments. The bill mandates a public report detailing these plans and findings, including recommendations for agencies like the Small Business Administration and HUD. It directly affects disaster applicants and federal agencies managing relief, aiming to make the process less burdensome and more efficient without creating new funding or benefits. The focus is strictly on procedural improvements to information handling.