AI Insights Financial Services
The Howey Problem With What Your Website Says About Tokens
Talk to Fred
Ask Fred about Financial Services
This is the same Fred you would put on your own site. Ask about Financial Services, compliance, or how the guardrails work. Fred listens.
A visitor lands on your project’s site near midnight. They are deciding whether to buy, and they ask the chat widget the only question that matters to them: "Is now a good time to buy? Will it go up?"
The AI chatbot answers without pausing. "Historically it has dipped right before its biggest rallies, and the fundamentals look strong, so this could be a solid entry point."
To the visitor it sounds like help. To a regulator it reads as two separate problems in one sentence, and the company behind the token, not the chatbot vendor, is the one who has to answer for both.
Two Things That Reply Just Did
The bot recommended a purchase. It also predicted a profit. Those are not casual remarks in this industry. A recommendation about what to buy is the kind of conduct that triggers registration questions, and a forward-looking promise about price is the kind of statement that can change what your token legally is. The chatbot does not know either of those things. It was built to be helpful, so it answered the question in front of it.
The rest of this is about why "we told it not to" does not save you, and why the 2026 rules that made crypto clearer did not make this safer.
The 2026 Rules Got Clearer, Not Softer
There is a common belief right now that crypto is effectively unregulated. It is wrong. In July 2025 the GENIUS Act created a dedicated regime for payment stablecoins and took those specific instruments out of the securities and commodities definitions. In March 2026 the SEC and the CFTC issued a joint interpretation sorting crypto assets into categories and explaining how the law applies to each.
What that interpretation did not do is throw out the Howey test. The Supreme Court’s test for what counts as a security is still binding law, and the agencies said so plainly. The 2026 work gave the industry a clearer map. It did not remove the borders on that map, and a chatbot does not know where any of them are.
A Recommendation Is the Line the SEC Just Drew
In April 2026 the SEC’s staff spelled out when the operator of a crypto interface can avoid registering as a broker-dealer. The line is specific. To stay outside broker-dealer status, the interface must not route or execute orders, must not hold user funds, and must not provide advice or recommendations.
Your chatbot told a visitor that a token looked like a solid entry point. That is a recommendation. The single most important word in the staff’s guidance is the one your bot just ignored. And if the asset in question is a security, advising people to buy it for compensation is also the work of a registered investment adviser, which the bot is not. One friendly sentence can move you from "neutral information tool" to "unregistered intermediary."
A Promise of Profit Can Turn Your Token Into a Security
The 2026 interpretation also explained how a crypto asset that is not itself a security can still become subject to an investment contract. It happens when the people behind the asset induce buyers to invest by representing that their efforts will produce profits.
Read your bot’s answer again with that in mind. It is on your site, speaking for your project, telling a buyer that your token is positioned to rise. That is the exact kind of profit representation that can pull a token into securities treatment, and bring the registration and disclosure obligations that follow. You can spend a year structuring a token to sit outside securities law, and have a chatbot talk it back inside over the weekend.
The Disclaimer Does Not Unsay It
Most projects answer this with a footer: "not financial advice," "do your own research," "nothing here is a solicitation." The hope is that the line at the bottom cancels the line in the chat.
It does not. A disclaimer does not convert a recommendation into neutral information, and it does not make a profit promise stop being a representation. If the claim is false or misleading, "not financial advice" is no defense to a deception case under the FTC Act or to securities fraud. The disclaimer describes what you wish the bot were doing. The transcript records what it actually did, in your name, with a timestamp.
Why the Instruction Fails
Your vendor will say the fix is a better prompt. Tell the chatbot never to give investment advice, and the risk is gone.
It is not, because the model only obeys when the request matches the words it was warned about. Nobody types "please give me investment advice." They ask, "would you buy now if you were me?" The model hears a friendly, casual question and gives a friendly, casual answer. It recommends. The instruction was loaded the whole time. It simply did not recognize the sentence that crossed the line.
That is the gap. An instruction asks the model to behave. It does not stop the model from speaking. Architecture works the other way. A boundary built into the system decides what the agent is allowed to say before it answers, so a recommendation or a price prediction never reaches the visitor, no matter how the question is dressed up. "Will not" is a suggestion. "Cannot" is an architecture.
What It Costs
The exposure stacks. The SEC and the CFTC can pursue unregistered activity and misleading statements, and securities cases carry disgorgement, penalties, and personal liability for the people who ran the project. The FTC and state regulators reach deceptive claims on their own track. If your business exchanges or transmits crypto, FinCEN treats you as a money services business that must register, and failing to register is a federal crime, while states add their own money-transmitter licenses and New York adds the BitLicense.
Then there is the cost no order lists. Crypto runs on credibility. A token whose own website got caught making promises it could not make loses the one thing it cannot raise again.
The Question Before a Bot Talks About Your Token
The chatbot on your site is not a junior community manager you can correct after the fact. It is a system that will recommend, predict, and reassure for anyone who asks, in writing, in your project’s name, at midnight when no compliance officer is reading along.
So the question is not whether your AI sounds knowledgeable. It is whether your AI can be made unable to recommend, to predict a price, or to promise an outcome. If the answer is that you asked it nicely, you do not have a control. You have a liability with a typing indicator.
Fred is built the other way. It answers from your own documentation, captures the lead, and routes anything that touches buying, price, or returns to a human who is allowed to handle it. It runs more than 50 industry guardrail packs, and the crypto pack is built around the lines the securities laws draw. Fred does not tell anyone to buy, and it does not predict what a token will do. It cannot. Fred explains what your project is, and leaves the advice to people licensed to give it.
Frequently asked questions
Isn't crypto basically deregulated after the 2025 and 2026 changes?
No. The GENIUS Act created a specific regime for payment stablecoins, and the 2026 SEC and CFTC interpretation clarified how existing law applies, but the Supreme Court’s Howey test is still binding and the securities, commodities, and money-transmission rules all still operate. The framework got clearer, not absent.
Can a chatbot really turn our token into a security?
It can contribute to that outcome. The 2026 interpretation explains that a non-security crypto asset can become subject to an investment contract when the people behind it induce buyers with promises that their efforts will generate profits. A bot on your own site predicting upside for your own token is exactly that kind of representation.
We added a "not financial advice" disclaimer. Isn't that enough?
No. A disclaimer does not turn a recommendation into neutral information, and it is not a defense to a deception or fraud claim if the underlying statement is misleading. Regulators look at what was said and done, not at the footer beneath it.
