Search This Blog

Monday, 15 August 2022

What is a "Stablecoin Used as a Means of Payment"?

The UK government is doing a lot of strange things with existing financial regulation, while trying to absorb new concepts, such as those relating to cryptoassets. Buried amidst the pile of economy-shrinking, post-Brexit deckchair rearrangement in the new Financial Services Bill (explanatory notes here) is an attempt to regulate 'stablecoins used as a means of payment'. This post tries to make sense of that. 

Existing UK regulatory view of stablecoins

In a previous policy statement, the Financial Conduct Authority explained its view that 'stablecoins’ (a.k.a. ‘stable tokens’) are cryptoassets that are structured in order to (try to) stabilise their value, e.g. by ‘pegging’ them to a fiat currency or different types of assets (including other cryptoassets (‘crypto-collateralised’)) or specified financial investments (regulated securities) or commodities (‘asset-backed’)).  

That interpretation means that stablecoins may currently fall within existing e-money/payments regulation and/or securities regulation (as a derivative, a unit in a collective investment scheme/fund, a debt security, or another type of specified investment) provided they meet all the applicable critieria, regardless of the fact they are issued using 'distributed ledger technology' or on a 'blockchain'. Those regulatory criteria vary depending on the nature of the underlying assets, the rights granted by such tokens and other relevant 'arrangements' or other activities, like whether advice is given. 

The FCA has said that 'algorithmically stabilised tokens' or stablecoins which attempt stabilisation through algorithms that control the supply of the tokens to influence price, for example, should only be regulated to the same extent as other (financially) 'unregulated' tokens are. Examples of unregulated cryptoassets or tokens include 'bitcoin' (classified as an 'exchange token' rather than as a means of payment) or 'utility tokens' that merely grant access to a game or system, for example.

Aside from stablecoins and other cryptoassets that trigger existing regulation, the FCA explained that it needs new statutory powers to regulate cryptoassets.

The new approach to Stablecoins - DSAs

The new Financial Services Bill itself makes no reference at all to 'cryptoassets' or even 'stablecoins', but the explanatory notes do. 

Of course, this instantly expands the lawyers' playground of unintended consequences, so I'm not really complaining professionally. 

The explanatory notes essentially recite the earlier FCA consultation [although the notes ominously refer to Bitcoin as an example of "cryptoassets used primarily as a means of investment" rather than 'exchange', perhaps signalling a shift in the government's approach to the regulation of cryptoassets and related activities more widely, due to be announced later in 2022.]

In relation to stablecoins, the explanatory notes say that the Bill empowers the Treasury to: 

  • establish an FCA authorisation and supervision regime, drawing broadly on existing electronic money and payments regulation, to mitigate conduct, prudential and market integrity risks for issuers of, and payment service providers using, stablecoins; 
  • regulate (via the Bank of England) any systemically significant stablecoin-based payment system, in a similar way that Visa, Mastercard and a range of other designated "payment systems" are controlled by the Payment Systems Regulator (PSR);
  • empower the PSR to regulate payment systems using stablecoins, following designation by the Treasury, to address issues relating to competition innovation, user interests and access; 
  • apply the Financial Markets Infrastructure Special Administration Regime (FMI SAR), which is a bespoke administration regime for recognised payment and settlement systems and recognised service providers, to stablecoin firms that have been recognised by HM Treasury, with appropriate modifications. This will ensure appropriate tools are in place to mitigate the risks to financial stability associated with a systemic stablecoin firm’s failure; 
  • Amend or disapply existing financial regulators' rules to avoid systemic stablecoin firms being subject to conflicting requirements in areas relating to financial stability. 

For these purposes, however, the Bill uses the term "digital settlement asset" instead of 'stablecoin':

""digital settlement asset" [or "DSA"] means a digital representation of value or rights, whether or not cryptographically secured, that— 

(a) can be used for the settlement of payment obligations, 

(b) can be transferred, stored or traded electronically, and 

(c) uses technology supporting the recording or storage of data (which may include distributed ledger technology)."

For most purposes a DSA "includes a right to, or interest in, a [DSA]." This reflects the definition of "cryptoasset" in the Money Laundering Regs.

The Bill gives the Treasury power to regulate DSAs by applying e-money/payments and payment systems regulation to them, including the power to change the statutory definition itself! 

The Bill creates the concept of "DSA service providers" which includes anyone directly involved in: 

  • issuance/creation of DSAs, 
  • safeguarding or safeguarding and administration (custody) of the DSAs including the private cryptographic keys (or means of access) [not clear whether this service must include the keys/means of access, or would be satisfied if the provider only safeguarded the keys/means of access];
  • exchange or arranging the exchange of DSAs for money and/or other DSAs or vice versa ("digital settlement asset exchange providers" is defined pretty much like cryptoasset exchange providers under the Money Laundering Regs), 
  • rule/standards-setting; and 
  • any service that facilitates, or supports, a transfer of money or digital settlement assets to be made using the payment system, including any infrastructure provider in relation to the system.

Unintended consequences?

Right now your brain should be fizzing with other things that could be DSAs; and even whether any existing components of payment systems or services could qualify as DSAs or DSA services and therefore require a currently unregulated/unauthorised service provider to become authorised as a "DSA service provider".

It is also worth watching the evolution of "data objects" as a new class of personal property with distinct rights and remedies.


Thursday, 4 August 2022

UK Govt Takes 'Do Nothing' Approach To Regulating Artificial Intelligence

The UK government has triumphantly announced that it's, er, taking a 'wait and see' approach to whether 'artificial intelligence' technologies require direct regulation. You might've detected a certain level of cynicism when it comes to my evaluation of this UK government's regulatory plans, and you'd be forgiven for thinking that my view is simply that they can't do anything right, or in a way that inspires any trust. So it is with their approach to regulating AI. While I'm sympathetic to allowing 'good' innovation and businesses to flourish before tying it up in red tape, I'm also aware that nobody can pick what wins in practice and there's a middle ground. Besides, there are many significant challenges with AI, a key one being that nobody really knows when AI is being used, let along whether that use is to their disadvantage. To leave this technological development to a patchwork of non-binding regulatory guidance seems careless until you look at what else this government has been up to, at which point you assume malicious intent.

The existing regulatory landscape

The government's paper is well, paper thin, so it's no surprise that this section amounts to the usual Brexiteer 'boosterism' and a desire to avoid references to the EU. Britain is for the British, so we'll have none of your comparative jurisprudence here, thank you very much. 

Needless to say this doesn't play to any firm with pan-European, much less global, ambitions.

Strangely, for a paper that recommends doing nothing, the government admits that "the proliferation of activity; voluntary, regulatory and quasi-regulatory, introduces new challenges that we must take action to address" including "lack of clarity", "overlaps", "inconsistency" and "gaps in our approach"... 

These issues across the regulatory landscape risk undermining consumer trust, harming business confidence and ultimately limiting growth and innovation across the AI ecosystem, including in the public sector. By taking action to improve clarity and coherence, we have an opportunity to establish an internationally competitive regulatory approach that drives innovation and cements the UK's position as an AI leader.

No 'definition' of AI

Here the government is obliged to dismiss the fact that the EU has stolen a march on the regulatory front to address exactly the challenges that the paper just outlined. The European Commission proposed a regulation in April 2021; and, Hell, they even have their own twitter feed and web page

But we can't talk about that EU stuff... except that the government accuses the EU of having a 'relatively fixed definition' of AI, while the UK plan is: 

"to set out the core characteristics of AI to inform the scope of the AI regulatory framework but allow regulators to set out and evolve more detailed definitions of AI according to their specific domains or sectors". 

In other words, the government wishes to perpetuate the very "challenges we must take action to address"...

While these 'core characteristics' that will inform the UK's non-regulatory scope are not actually specified with any clarity, it seems possible to distill them as follows: 

  • the logic or intent behind the output of systems can often be extremely hard to explain; 
  • errors and undesirable issues within the training data may be replicated;
  • AI often demonstrates a high degree of autonomy, operating in dynamic and fast-moving environments by automating complex cognitive tasks; 
  • decisions can be made without express intent or the ongoing control of a human.

Look away now if you don't want to see the EU definition (still being debated, to be fair):

‘artificial intelligence system’ (AI system) means software that is developed with one or more of the techniques and approaches listed in Annex I and can, for a given set of human-defined objectives, generate outputs such as content, predictions, recommendations, or decisions influencing the environments they interact with; 

ANNEX I 

(a) Machine learning approaches, including supervised, unsupervised and reinforcement learning, using a wide variety of methods including deep learning; 

(b) Logic- and knowledge-based approaches, including knowledge representation, inductive (logic) programming, knowledge bases, inference and deductive engines, (symbolic) reasoning and expert systems; 

(c) Statistical approaches, Bayesian estimation, search and optimization methods.

Cross-sectoral Principles

Citing the OECD's AI Principles, the UK government hopes regulators will somehow ensure that: 

  • AI is used safely; 
  • AI is technically secure and functions as designed; 
  • AI is appropriately transparent and explainable; 
  • 'considerations of fairness' are embedded into AI; 
  • legal persons' responsibility for AI governance will be defined;
  • there are routes to redress or contestability.

Conclusion

Apparently this framework will enable "AI-first" start-ups to:

"...understand the rules more easily and spend more time and resource on product development or fundamental AI research, and less on legal costs." 
Never mind the continuing "lack of clarity", "overlaps", "inconsistency" and "gaps in our approach".

It's hardly an investors' charter, is it?


Wednesday, 3 August 2022

Changes to UK Anti-Money Laundering Regime

The UK's anti-money laundering regulations suffer from an enormously long name, so I will shorten them to the "MLRs" for the purpose of explaining some changes that take effect on 1 September 2022 (except where noted). Perhaps the highlight is that account information service providers (AISPs) will no longer need to comply with the MLRs. This note is a summary for information purposes only, not advice. It does not include changes to the authorities' obligations or offences. If you need advice on any of the changes, please let me know.

  • The meaning of a trust or company service provider covers the formation of all forms of business arrangement or "firm", not just companies and other legal persons, including limited partnerships registered in England and Wales or Northern Ireland. TCSPs must conduct customer due diligence when they are providing certain services (outlined in regulation 12(2)(a), (b) or (d) of the MLRs). 
  • Cryptoasset transfers will be covered by a new Part 7A from 1 September 2023. The provisions apply to a cryptoasset exchange provider or a custodian wallet provider (referred to as a "cryptoasset business"), whether acting for the transferor ('originator'), the transferee ('beneficiary') or just as an intermediary. Cryptoasset businesses acting for originators of transfers (as well as intermediaries involved in the transfer) must include certain information about the originator and beneficiary of the transfer. Where the information is missing, the cryptoasset business acting for the beneficiary of a transfer (as well as intermediaries involved in the transfer) must request it and consider not making the cryptoasset available (subject to a risk assessment). Similar rules apply in relation to transfers from/to 'unhosted wallets'  (private or self-custody wallets). Cryptoasset businesses must inform the Financial Conduct Authority (“FCA”) of any "repeated" non-compliance. 
  • The definition of art market participant in the MLRs will not apply to artists who sell their own works of art over the EUR 10,000 threshold.
  • From 1 April 2023, firms covered by the MLRs will have to report to the registrar of companies any material discrepancies between information they hold on the beneficial ownership of a customer and information on the companies register. The registrar has clear powers to deal with such discrepancies. 
  • Any change in control of a registered cryptoasset business must now be pre-approved by the FCA (a particularly slow and painful process!), which of course may object and publish a notice of the objection. The FCA and HMRC can now also publish notices of refusals to register applicants. 
  • Supervisory authorities can now request suspicious activity reports (SARs) from their members, to assist in meeting their supervisory functions. 
  • At long last, account information service providers (or AISPs) will no longer need to comply with the MLRs.

Again, this note is a summary of some changes for information purposes only, not advice. If you need advice on any of the changes, please let me know.

Tuesday, 2 August 2022

Data Objects: A New Class Of Personal Property in English Law?

The UK Law Commission is recommending changes to English law to better recognise and protect digital assets, especially crypto-tokens. The Commission uses the term 'cryptoasset' to mean "a composite of a crypto-token and any associated or linked property or other legal rights that are recognised in law as existing as a consequence of having legal rights in relation to that crypto-token." Consultation responses are invited by 4 November 2022. If you have queries concerning the consultation, please get in touch.

The key recommendation is the recognition of "data objects" as an additional form of personal property to "things in possession" and "things in action". The criteria for a digital asset to qualify as a data object would be: 

  1. it comprises data represented in an electronic medium, including computer code, electronic, digital or analogue signals; 
  2. its existence is independent of any person and the legal system; 
  3. it is 'rivalrous' (consumption by one person prevents simultaneous consumption by another). 

Among digital assets such as files, records, email accounts, in-game digital assets, domain names, carbon credits, the Commission considers that only crypto-tokens (as distinct from the broader concept of a cryptoasset) would qualify as "data objects". 

The Commission stops short of recommending possessory rights in data objects, but recommends developing the concept of "control" through the courts, since a person in "control" of a data object can exclude others from it, use it, transfer it and identify themselves as the person able to do these things. 

The paper includes an extensive discussion of the consequences of expanding the law of personal property in this way; and how existing law would apply to data objects.  

Update: 

Interesting to consider in this context the government's Bill to include "digital settlement assets" and related service providers within the scope of existing financial services regulation.


Monday, 11 July 2022

Of Subscription Traps, Fake Reviews and Savings Club Funds

In April, the UK government [well, let's face it, the civil service] announced plans to deal with a range of consumer problems known to successive Conservative regimes and never tackled. But no date was set for introducing the measures and, given the change of government, they might fall by the wayside again. Here are some problems from which officials thought consumers needed protection, and measures proposed to address them:

  • Subscription traps: the plan was to add pre-contract information for subscription contracts and require traders to send reminders before a free/introductory offer ends or a contract auto-renews; 
  • Fake reviews: the idea was to declare certain practices to be unfair under the Consumer Protection from Unfair Trading Regulations, such as: 
    • commissioning another person to write or submit a fake review;
    • advertising for people to submit or commission fake reviews; and 
    • hosting consumer reviews without taking reasonable steps to ensure they are genuine. 
This reflects some of the changes to the EU Unfair Commercial Practices Directive by the Enforcement and Modernisation Directive, that took effect in May 2022. Fair enough, but I do hope we'll still see genuinely funny reviews (e.g. effusive praise for a white mug).
  • Safeguarding funds in prepayment/'saving' schemes: The government says this is to deal with problems such as Farepak. But Farepak went to the wall having used its customers Christmas hamper money for property investments in October 2006. Wrapit, the failed wedding list company, was another example. The Treasury belatedly began calling for such funds to be ring-fenced from the retailer's assets in 2010 (though it mistook Farepak for a 'gift card' or 'closed loop' stored value programme, where amounts at stake are smaller and not dedicated to a specific purchase by the customer over a lengthy period of time). The requirement would be that retailers or intermediaries offering dedicated pre-purchase schemes, like Christmas savings clubs, must fully safeguard contributors’ money by setting it aside from the company's own assets in a properly constituted trust account, or by taking out an insurance policy (which would also need to be held in trust for potentially affected customers). One suspects this would spell the end of such schemes, but given the deep recession facing the UK that might be no bad thing: at least customers wouldn't lose their money if they keep it in a bank instead (assuming they have at least a basic bank account).
  • Regulatory teeth: The Competition and Markets Authority is to be given the power to enforce  consumer legislation directly, so it can award compensation and impose financial penalties for breaches without going to court [the Tories don't like courts], including turnover-based fines (up to 10% of global annual turnover, rather than 4% in the EU) and fixed monetary penalties for failing to co-operate with an investigation, breaching an undertaking, or breaking a consumer law. 
  • Alternative dispute resolution: Leaving the EU meant the end of consumers' access to non-court dispute resolution schemes ('ombudsman') for low value issues [where nobody wants to go to court]. These were set up and funded through the EU rather than national governments. Having lost that scheme, the government now realises it was worthwhile [a very common occurrence]. Britain's very own ADR service providers will need to be accredited under a common set of standards, which presumably will look a lot like the EU programme.
But, as I said at the outset, maybe none of this will actually happen, leaving UK consumer law even more diverged from EU law.


Friday, 24 June 2022

The Suspicious Timing of The UK Government Review of The Consumer Credit Act

The UK government recently issued a brief press release promising a consultation "by the end of this year" on plans to review the Consumer Credit Act 1974 (CCA). I think you'll agree that the timing and lack of detail is more than a little suspicious.

The release spouts the usual guff about supposed Brexit benefits:

"Leaving the EU has provided additional opportunity for regulatory reform and the government will examine which parts of EU retained legislation can be repealed or replaced to ensure regulation is better suited to the needs of the British people." 

The Economic Secretary also claims that "The Consumer Credit Act has been in place for almost 50 years - and it needs to be reformed to keep pace with the modern world." 

It's a little disingenuous, then, for the press release not mention that the CCA and related regulations were extensively amended in 2010 to implement the EU Consumer Credit Directive of 2008 (CCD1).  

I mean, why pass up an opportunity to blame the EU for legislation you plan to 'reform' all on your own?

It's verging on suspicious that the press release also presents the UK government's review of the CCA as somehow politically independent and part of a more general review of "EU retained legislation" without so much as pointing a finger at the extensive process for reviewing CCD1, which began in 2014 before Brexit was even conceived and culminated in a report in 2020 before Brexit took effect. 

Suspicions are confirmed, however, when the press release makes no mention of the previous week's announcement by the Council of the EU, on 9 June 2022, that it had agreed its approach to a detailed proposal for a new consumer credit directive (CCD2). 

Perhaps the minister is unaware that the UK played a significant role in the development of CCD2? If so, it will come as an enormous surprise when it is revealed that the government has adopted the same approach in its next revision of the CCA, just as it did in 2010. 

But, hey, blue passports!


Monday, 28 March 2022

FCA Circles The Wagons Over Cryptoassets

Hot on the heels of the crackdown on advertising cryptoassets in the UK, the Financial Conduct Authority has also sent a notice to all the firms it supervises who 'interact' with cryptoassets or related services. There's nothing new here but a sense that the FCA has suddenly realised that the UK authorities are way behind the crypto-curve (particularly in light of recent sanctions), and there's a mad scramble to avoid another LC&F scandal - or worse.

The FCA expects firms to ensure that consumers understand what aspects of their services are regulated and clearly distinguish those elements which are not regulated. The firm is responsible for identifying and managing potential risks related to cryptoassets. 

There is a reminder that it is a criminal offence to provide cryptoasset exchange services or custodian wallet services by way of business in or from the UK without being registered with the FCA under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (or have temporary permission to do so while your application is pending). 

All authorised and registered firms must have appropriate systems and controls to counter the risk of being misused for financial crime, so firms should be reviewing whether cryptoasset businesses they interact with are listed on the FCA’s Unregistered Cryptoasset Businesses page, for example. 

The FCA's Dear CEO letter also remains relevant in terms of how to achieve best practice where clients and customers may be using cryptoassets, or where firms are providing services to customers offering cryptoassets. 

Firms should assess the risks posed by a customer whose wealth or funds derive from the sale of cryptoassets, or other cryptoasset related activities, using the same criteria that would be applied to other sources of wealth or funds (even if the evidence trail may be weaker). 

While there are no specific prudential (capital) treatments that explicitly mention cryptoassets, firms subject to the investment firm prudential regime (IFPR), have obligations (under MIFIDPRU 7) to assess and mitigate the potential for harm to clients, to the markets in which the firm operates and to itself, that could arise from all of their business - even if the activity is unregulated or carried out on a principal, agency some other basis. Assessing adequate financial resources should involve assessing and managing risks and exposures from cryptoassets and deducting from regulatory capital any cryptoasset that is accounted for as an intangible asset.  

All FCA regulated firms must observe the Principles for Business in the Handbook, and Principle 10 requires a firm to arrange adequate protection for clients’ assets. The FCA’s Client Assets Sourcebook (CASS) provides detailed rules for firms to follow when holding regulated assets in custody, as part of their investment business. Where cryptoassets are security tokens (and so count as specified investments), firms carrying out regulated activities involving custody of those cryptoassets are likely subject to CASS. 

The FCA will continue to monitor the use of cryptoassets in custody arrangements and act where appropriate.