WASHINGTON: Five federal agencies on June 18, 2026, jointly proposed a rule requiring permitted payment stablecoin issuers to run bank-style customer identification programs, the first major rulemaking implementing the GENIUS Act’s anti-money-laundering provisions. The Financial Crimes Enforcement Network, the Office of the Comptroller of the Currency, the Federal Reserve, the FDIC, and the National Credit Union Administration filed the joint notice, which appeared in the Federal Register on June 22, opening a 60-day public comment window.
What the proposed stablecoin KYC rule would require
The GENIUS Act, signed earlier this year, treats permitted payment stablecoin issuers as financial institutions under the Bank Secrecy Act. The proposed rule fills in what that designation means in practice. Issuers would have to maintain a written, risk-based customer identification program as part of a broader AML and counter-financing-of-terrorism program, the agencies said in the joint announcement.
Before opening an account, an issuer would have to collect a customer’s name, date of birth (for individuals) or date of formation (for entities), an address, and an identification number such as a Social Security or taxpayer ID. Issuers would also need to verify identity within a reasonable time, keep records, screen customers against designated government watchlists, give customer notice, and follow procedures for handling cases where identity cannot be confirmed. The proposal permits limited reliance on other federally regulated financial institutions for parts of the verification process.
Stablecoins processed roughly $9 trillion in payments in 2025, a volume that has pushed Washington to set ground rules for an industry that previously operated outside the federal banking framework. Circle, Tether, PayPal’s PYUSD, and a handful of bank-issued dollar tokens would be the most directly affected by the proposal if finalized.
Who has to comply with the new stablecoin issuer rules?
The obligation falls on permitted payment stablecoin issuers and applies only to primary-market activity. Primary market means direct interactions between the issuer and a user: minting tokens, redeeming, repurchasing, burning, reissuing, or providing custodial services. Secondary-market activity, which is where most retail users operate, is excluded. Buying USDC on an exchange, sending stablecoins from a self-hosted wallet to a merchant, or trading one stablecoin for another on a decentralized exchange would not trigger the issuer’s CIP requirement.
The agencies preliminarily rejected a “global” customer-due-diligence model that would have required identity checks on every holder of a stablecoin, no matter how the holder acquired it, according to the proposed rule text. That choice keeps the compliance burden on institutional mint-and-redeem desks, while leaving exchanges and intermediaries to handle KYC at their own customer-onboarding layer under existing rules.
For founders building or integrating a dollar-pegged stablecoin, the practical line is whether the product touches the issuer’s primary market. A fintech that integrates USDC purely as a payment rail, with the user funding from a bank account at the exchange, does not pick up the new CIP duty. A wallet or treasury product that lets institutional clients mint directly with the issuer would sit on the regulated side of the line.
The agencies also clarified what counts as an “account” for stablecoin CIP purposes. The trigger is a formal contractual relationship with the issuer to mint, redeem, or hold stablecoins under custody, not a one-off purchase. That definition spares the issuer from running identity checks on every wallet address that ever holds a token, a workload that would have been operationally impossible. It also reflects how primary-market business already runs in practice, where institutional mint-and-redeem desks know their counterparties by name.
Compliance cost is the open question. Larger issuers such as Circle and PayPal already run customer identification at a scale comparable to a chartered bank, so the marginal cost of formal CIP is modest. Smaller and newer stablecoin issuers, including those tied to specific payment networks or fintech rails, will have to stand up written programs, audit trails, and watchlist screening that they may have outsourced or skipped. Industry comment letters are expected to push for reliance allowances on bank or exchange KYC to keep the burden from doubling up.
What comes next on the GENIUS Act timeline
Public comments on the CIP proposal are due August 21, 2026, sixty days after Federal Register publication. The CIP rule is one of several implementation deadlines tied to the GENIUS Act. The Treasury and the federal banking agencies are working toward broader final stablecoin rules, including capital, liquidity, and disclosure requirements, with a target of July 18, 2026, the FDIC said in a financial institution letter accompanying the proposal.
Fed Chair Jerome Powell supported the joint proposal. New Fed Governor Kevin Warsh abstained from the vote, an early signal of dissent on the central bank’s approach to stablecoin oversight. Industry comment letters from Circle, Coinbase, and the Blockchain Association are expected to focus on the recordkeeping cost for primary-market clients, the treatment of programmatic mint and redeem flows, and the line between an issuer’s CIP and an exchange’s existing KYC. The final rule could differ materially from the proposal once comments are processed. For builders, the next eight weeks are the window to weigh in before the framework hardens. GreyJournal has previously covered the CLARITY Act, the other major crypto-regulation bill working through Congress, and tracks finance and crypto policy as it lands.



