Hester Peirce Says DeFi Doesn't Need an Exemption. She's Right.
SEC Commissioner Hester Peirce's Sept. 17 remarks reframe DeFi regulation around a single question: who controls the protocol? If nobody does, there's no intermediary to exempt. That's cleaner than it sounds, and harder to prove than builders think.
I went back through Hester Peirce's Sept. 17 remarks twice, and one line did more work than the rest of the speech combined. Investors don't need an exemption to trade peer to peer through permissionless smart contracts, she said. Not should get one. Not we're considering one. They don't need one at all.
That's a small distinction with big consequences.
Because an exemption is a strange thing to request when there's nobody to exempt. Exemptions are what you ask for when you're covered and want out. If a smart contract has no operator taking orders or holding customer keys, there's no entity for the agency to license in the first place.
The Line Peirce Drew
The SEC and CFTC don't slice DeFi by product. They slice it by function. Custody is one question. Access is another. Routing, meaning how order flow gets matched, is a third. Fees are a fourth. And intervention, the power to pause, freeze, or upgrade a contract, is the fifth. Notably, each one sits inside a separate legal framework, and none of them collapses neatly into the others.
That matters because most protocols touch several buckets at once.
Take a simple case. Trading is peer to peer. No custody. No intermediary. Fine. Now flip on a fee switch and a treasury starts collecting revenue. Who controls that treasury? Is it a multisig, a token vote, or three people with keys? Does a core team still hold an admin function that can halt the contract in an emergency?
The key detail isn't whether the code is open source. It's who can flip the switch.
From a compliance standpoint, that's the whole ballgame. Control is the hinge. A protocol nobody can steer looks like software. A protocol someone can steer looks, to a regulator, like a business wearing a contract as a costume.
So where's the line? Is it a two-of-three multisig? A 48-hour timelock? A foundation that funds development but holds no keys? Nobody has answered that, and Peirce's speech doesn't either. To her credit, she seems to know it.
The Cost of Asking for a Pass
The precedent here's important. Once you accept a tailored exemption, you've accepted the agency's jurisdiction over you. Every future feature gets measured against the terms of that relief. Builders who watched the last four years of enforcement know how that movie ends.
No exemption, no admission. That's the trade Peirce is offering, and it's the one the industry should actually want.
The flip side is uncertainty, and it's real. Developers are making control decisions right now with no published threshold. A grant here, an upgradeable proxy there, and you're arguing about your own legal status in front of staff who've already formed a view.
For markets, this pushes toward duller architecture. Fewer admin keys. More immutability. Renounced ownership where it's possible. I think that's healthy. It's also slower and less flexible, and some products genuinely can't be built that way.
What regulators are really signaling: control, not code, is the test. That's a manageable standard. It's also one that catches teams who call themselves decentralized while keeping a back door.
My Take
If you're building, my advice is boring and hard to argue with. Write down every human who can alter the protocol after launch. Names, roles, keys, timelocks. If that list is empty, say so publicly and mean it. If it isn't, assume someone will ask you about it under oath.
Watch two things from here. First, whether the SEC and CFTC settle on the same words for the same functions, because separate frameworks only work if they don't contradict each other. Second, the next enforcement action that turns on an admin key or a fee switch. That case will draw the line far more clearly than any speech.
Peirce is right that permissionless trading doesn't need a permission slip. The hard part is proving you're permissionless.