Guide · 6 min read · For controllers and finance leads
Governing agent spend while the GENIUS rules keep moving
The GENIUS Act's statutory rulemaking deadline passed on July 18, 2026 with no final package, and the open comment periods run into late August. How to govern agent and stablecoin spend now, so that whatever text finally lands, you can show which policy version governed each transaction.
July 18, 2026 was the GENIUS Act's statutory deadline for implementing regulations: one year from enactment, the agencies were supposed to have the rulebook for permitted payment stablecoin issuers finished. The date came and went without a final package. What exists instead is a stack of proposals with comment periods that run into late August, which means the final text is realistically a Q4 story, and possibly later.
If your company is deploying agents that move money, or building on the stablecoin rails the GENIUS Act covers, that is an uncomfortable place to plan from. You cannot fully build to rules that do not exist yet. You can, however, build the one thing every plausible version of the rules will ask of you: proof of which policy governed each transaction at the moment it happened.
Where the rulemaking actually stands
As of this week, the picture looks like this:
- The statutory rulemaking deadline of July 18, 2026 (one year after enactment) passed with no coordinated final package from the agencies.
- The OCC's proposed AML and sanctions compliance standards for payment stablecoin issuers closed for comment on July 24.
- The FDIC's parallel Bank Secrecy Act and sanctions framework takes comments through August 4.
- The five-agency customer identification program (CIP) proposal for stablecoin issuers takes comments through August 21.
- The statute's own backstop still stands: the regime takes effect on January 18, 2027 at the latest, whether or not the final rules leave much time to prepare.
Comment review, interagency reconciliation, and final publication all sit downstream of those August dates. The practical read: issuers, and the enterprises building on them, will spend Q4 preparing for text they have not seen, against an effective date that does not move.
Why 'wait for the final text' is the wrong plan
The tempting move is to freeze: do nothing irreversible until the rules are final. But agent spend does not freeze with you. Agents are already issuing refunds, buying API calls over x402, and moving stablecoins today, and every ungoverned transaction between now and the final rule is a transaction you may later have to explain with no evidence.
The question an examiner or auditor asks is rarely 'did you predict the final rule correctly'. It is 'show me what controls were in effect when this transaction happened, and prove it'. That question has the same answer under every draft currently on the table, because it does not depend on the final thresholds or program details at all.
Policy-versioned enforcement
The mechanism is boring, and that is the point. Every spend decision is evaluated against an explicit, versioned policy. When you save a policy edit, the version increments and the history is preserved. Every decision record carries the version that decided it.
When the final OCC or FDIC text lands and your counsel translates it into new thresholds, approval tiers, or blocked counterparties, you edit the policy. New transactions run under v9; everything before the edit provably ran under v8. There is no ambiguous middle period, because the ledger records exactly when the cutover happened and which decisions fell on which side of it.
Hash-chained receipts
Version stamps only matter if the records cannot be quietly edited later. Axiru writes every decision, including the denials and the failures, to an append-only ledger where each receipt carries a hash of the previous one. Change any historical record and the chain breaks visibly.
That converts your compliance story from narrative to evidence. Instead of 'our policy at the time was roughly X', you produce the receipt: this transaction, this policy version, this rule matched, this approver, this outcome, hash-linked into a chain that has not been altered. Whatever the final GENIUS rules require, that artifact is the substrate they will be checked against.
What Axiru enforces today, stated plainly
Because this is a compliance article, precision about our own product matters:
- Stripe outflows (refunds, credits, adjustments) are under live policy enforcement today, with approval routing and receipts.
- USDC transfer intents on Solana are in early access: policy decisions and signed pre-authorizations for stablecoin transfers, for early-access organizations.
- x402 agent payments run through our pre-authorization path; most teams start in shadow, scanning their existing x402 spend logs before turning enforcement on.
- The exposure scanner reads x402, MPP, or CSV spend logs in your browser and shows where money can move without a decision being recorded. Nothing is uploaded.
What to do before the text lands
Between now and Q4: inventory every surface where an agent can move money, put a versioned policy in front of the highest-volume one, and start accumulating receipts. When the final rules publish, you will be editing a policy, not retrofitting a control system under an effective-date clock that has been running since the day the statute was signed.
Run the exposure scanner →Replay your Stripe data in shadow mode →
Sources
Primary documents and reporting for the dates cited above:
GENIUS Act, S.1582 (Public Law 119-27) →OCC proposal: AML and sanctions standards for stablecoin issuers →FDIC proposal: BSA and sanctions compliance standards →Five-agency CIP proposal for stablecoin issuers →