“…completed or otherwise permanently ceased all essential managerial efforts that it represented or promised it would engage in under the covered investment contract and is not making and does not intend to make any new representations or promises to engage in essential managerial efforts…”
That is the escape hatch of SEC Regulation Crypto Assets (SEC 2026-76, proposed August 18, 2026). Read it again: the safe harbor turns on what an issuer represented or promised.
Where do those representations live? In the marketing. The ads. The landing pages. The roadmap creative. The presale campaign.
For agencies running crypto campaigns, the SEC just made your ad record into securities-classification evidence.
What the SEC Actually Proposed
SEC Regulation Crypto Assets would create “a clear and fit-for-purpose framework for certain investment contracts involving crypto assets” — the Commission’s words, following its March 2026 interpretation of how the securities laws apply to crypto. Four moving parts:
- A startup exemption. One-time, non-exclusive, up to $5 million over four years, with public filings at the start and end of the period and principles-based narrative disclosures to investors.
- A fundraising exemption. Two tiers modeled on Regulation A: up to $20 million (Tier 1) or $75 million (Tier 2) per 12-month period, with financial statements (audited at Tier 2) and ongoing reporting.
- An investment contract safe harbor. If an issuer satisfies the conditions, “a crypto asset would be deemed not to be subject to an investment contract” — meaning it falls outside the definition of “security.”
- State-law preemption. A new “qualified purchaser” definition would preempt state securities registration and qualification for exempt offerings and certain secondary-market trades.
One thing never changes: issuers remain subject to the antifraud and antimanipulation provisions of the federal securities laws — under every exemption, all the time.
The Commission’s own rationale is about keeping crypto onshore: existing rules, it says, “could complicate an issuer’s transaction planning and, in turn, impede capital formation,” and without fit-for-purpose rules, “some issuers may choose to conduct their crypto asset transactions offshore.” Chairman Paul Atkins called the proposal “another step by the Commission to onshore innovation in crypto asset markets.”
The comment period runs 60 days after the release publishes in the Federal Register. This is a proposal, not a final rule. But the direction is set — and the direction is that the marketing record decides what a crypto asset legally is.
The Safe Harbor Is a Promise Test
Here is the condition again, in plain English. To claim the safe harbor, an issuer must show that it:
- finished — or permanently stopped — all essential managerial efforts it represented or promised it would make, and isn’t making or promising new ones; and
- filed a public certification with an analysis supporting that.
Two tokens, same blockchain, opposite outcomes:
- Token A’s ads said “our team of 40 engineers is building the network — mainnet upgrade Q3, staking rewards Q4, three exchange listings next year.” That is a running list of promised managerial efforts. Token A is sitting in investment-contract territory.
- Token B’s ads said “a functional asset, live on-chain since launch, no roadmap, no promises, the team does not manage it.” Token B is the safe-harbor shape.
The difference between “security” and “not a security” is now, in substantial part, what the marketing said. A roadmap promise in a creative is a representation of essential managerial efforts. A “join the presale” landing page is a representation. A “we’re building X” claim in a video ad is a representation. Atkins framed the proposal as giving crypto entrepreneurs “clear pathways to raise capital under the federal securities laws.” The pathway runs through the promises. The promises run through the ads.
Your Creative Review Is Now a Legal Review
Run the scenario. Your client is a crypto exchange with a token that has been marketed for eighteen months. The SEC’s classification framework — and any plaintiff’s lawyer, and any state regulator — will ask one question first: what did the marketing promise, and when?
That question turns your agency’s ordinary artifacts into legal evidence:
- Every creative that mentions a roadmap, an upgrade, a listing, staking, or “the team”
- Every landing page with a tokenomics section or a “vision” statement
- Every campaign that ran during a presale or token generation event
- Every version of each, because the promise changed over time — the record is the versions, not the final ad
- Every approval — who signed off on the claim, and when
Now add the write era. Half of those creatives were drafted by an AI agent, and nobody can say which. “Who approved the promise?” becomes “who approved the promise an AI wrote?” — and if the answer is “the AI’s vendor logs it somewhere,” you have an attestation, not a record.
That is not a copywriting question anymore. It is a discovery question. The SEC doesn’t need to ask your client what they promised — the ads are the answer.
One Record, Four Readers
The US proposal is not the only regime reading the marketing record. It is the fourth:
| Reader | What it reads | What it requires |
|---|---|---|
| SEC (US) | Representations and promises of managerial efforts | A record of what was claimed, when, and by whom |
| MiCA (EU) | Marketing communications for crypto assets | Authorized CASPs only — about 283 of 3,000+ firms — with communications that are fair, clear, and not misleading, and Article 67/68 record-keeping |
| FCA (UK) | Financial promotions for crypto | Promotions approved by authorized persons, clear/fair/not-misleading, risk warnings whose prominence matches the return claims; the UK authorization gateway opens September 30 |
| Platforms (Google, Meta) | Ad compliance with local regulation | Google requires local-regulatory compliance for crypto ads; Meta treats financial services as a Special Ad Category |
Same fields for all four: what was claimed, when, to whom, in which jurisdiction, and who approved it. One record, four readers.
Concretely, that record is one creative, one row, four fields:
Creative 41-B, “Mainnet Upgrade Q3 — Stake to Earn,” ran EU/UK/US July 12 – August 2, 2026. Claim: essential managerial effort (network upgrade) promised to holders. Approved: account lead (human sign-off, July 11, 09:14 UTC) on an AI-assisted draft. Jurisdiction reads: SEC — representation of managerial efforts; MiCA — marketing communication needing CASP identification and a fair/clear/not-misleading check; FCA — financial promotion needing authorized-person approval; Google — crypto ad requiring local-regulatory compliance.
That row is the product. No horizontal platform ships it — and the horizontal PPC market still doesn’t, 15 consecutive weeks of monitoring, zero full-stack finance PPC platforms.
- Synter — “audit trail on every write” on its MCP page, zero compliance documentation, 241 posts with zero finance content.
- Windsor — writing campaigns from Claude since May 22; its July audit-log claim is a single changelog line, documented nowhere.
- Supermetrics — “SuperMCP” branding and write-side agents; no claims layer.
- Optmyzr — full-screen AI workspace and MCP keyword apply; no claims layer.
- auditsocials-compliance-mcp — the closest thing to a “compliance” server, and it checks ad copy before publish. Content-checking is not operations governance: it doesn’t tell you what ran, where, when, or who approved it.
The market taught AI to write the promises. Nobody built the record of them.
What to Tell Your Crypto Clients This Week
The rule isn’t final — and that is precisely why this week matters.
- The comment period is the window. 60 days from Federal Register publication. Exchanges that want the safe harbor’s shape — or the exemption thresholds — changed should be filing comments, and their agencies should be part of that conversation.
- Audit in-flight claims. Any live creative promising roadmap items, upgrades, listings, or staking is a representation of managerial efforts. Decide, per market, whether the promise stays or goes — and document the decision.
- Archive the archive. The discovery record starts at token launch, not at the SEC’s first request: every ad version, landing page, presale campaign, and approval since day one.
- Ask the platform question. Does your PPC stack produce that record per jurisdiction — or does it hand you screenshots and a UI session?
Three Questions Before Your Next Crypto Campaign
- Can you produce every claim your client’s ads have made — per market, per creative, with dates — since the token launched? The safe harbor and the antifraud provisions both read this record.
- Can you show who approved each claim, including the AI-written ones? Self-attestation from the tool that wrote the ad is not an answer.
- Can you export it in the time a regulator gives you? A request is answered with files — in 90 seconds, not 90 days.
What Ott Ships
Ott’s Activity Logging records every campaign change — timestamped, attributed to the human, tool, or AI agent that made it, with before/after values, stored independently of Meta, and exportable in about 90 seconds. Jurisdiction tags know the difference between an FCA-regulated broker, a MiCA-licensed exchange, an ESMA market, and an Alberta licensee. Creative Analysis carries that jurisdiction awareness to the creative layer — which creative made which claim, under which regime, approved by whom.
SEC Regulation Crypto Assets is in comment. Its shape may change; its direction won’t. The marketing record is becoming classification evidence in the US, a licensing requirement in the EU, and a financial-promotion regime in the UK. The market spent the summer teaching AI to write ads — and the regulators just made the claims in those ads the legal definition of the asset.
Only one platform spent that summer building the receipt.