Regulatory requirements in crypto fall overwhelmingly on exchanges, custodians and payment firms rather than on the protocols they connect to. That pattern follows from how financial regulation identifies its subject.
Rules attach to persons who perform activities
Financial law regulates conduct by identifiable parties. An obligation needs someone capable of complying, records to keep and an entity that can be supervised or penalised.
Autonomous software running across many machines does not fit that structure. There is no filing address, no officer to hold accountable and no operator to suspend.
Intermediaries do fit. They are incorporated, they hold licences, they have staff and premises, and they are therefore the natural point of attachment for any obligation.
Custody is the strongest trigger
Holding other people's assets attracts the heaviest requirements in almost every jurisdiction, because that is where the greatest harm from failure occurs.
Segregation of client assets, capital adequacy, independent verification and insolvency arrangements all follow from custody rather than from trading.
This is why non-custodial services face a materially lighter burden, and why platforms often restructure so that customer assets remain in wallets the customer controls.
Fiat access is the other lever
Converting between currency and crypto requires a bank relationship, and banks operate under their own supervisory obligations.
Those obligations flow down through the relationship. A platform that wants reliable banking must satisfy its bank's compliance standards, which frequently exceed the legal minimum.
Regulators therefore reach much of the sector indirectly, through the small number of institutions that connect it to the conventional payment system.
The edges are genuinely unsettled
Whether an interface to a protocol, a front-end website or a governance token holder can be treated as an operator is actively disputed in several jurisdictions.
Arguments turn on control: who can change the software, who takes a fee, who decides what users see, and who benefits from the activity.
Different authorities have taken different positions on these questions, and the answers continue to develop through enforcement and litigation rather than through settled rules.
What it means in practice
Users encounter regulation at the points where they meet a business, which is account opening, deposits, withdrawals and tax reporting.
Activity conducted entirely between self-custodied wallets encounters fewer checkpoints, though it does not thereby become exempt from tax or from sanctions law, which apply to persons regardless of the tools used.
Because obligations vary by jurisdiction and change over time, anything specific should be confirmed locally rather than assumed from a general description.