§24. Legal, Policy, and Jurisdictional Posture
Copy/paste (plain text):
Jason St George. "§24. Legal, Policy, and Jurisdictional Posture" in Next Generation Stores of Value: Privacy, Proofs, Compute. Version v2.0. /v/2.0/read/part-v/24-legal-policy-posture/ Legal, Policy, and Jurisdictional Posture
Layer 6 sits where protocol meets law and politics. If the triad is to be sustainable, it must support lawful privacy, defend itself against bans without being defined by them, and avoid capture by any single jurisdiction.
Lawful Privacy as Protocol Design
“Lawful privacy” is often a euphemism. Here it means something precise:
-
By default, settlement and compute flows are private.
-
By design, participants can opt into selective disclosure via viewing keys and receipts.
Constitutional Constraint: Policy = Predicates
Policy compliance is defined as ZK-checkable predicates over credentials and receipts, plus selectively disclosed audit windows via viewing keys.
It is not defined as global graph inspection or universal traceability. Any policy requiring ubiquitous transaction tracing is treated as incompatible with the monetary design.
What Lawful Privacy Is Not
Lawful privacy is not a promise that users can ignore legal obligations. It is a design posture in which the protocol minimizes unnecessary disclosure while allowing users to produce scoped, auditable evidence when they choose or are legally required to do so. Specifically:
-
Lawful privacy does not guarantee immunity from subpoena, tax reporting, sanctions enforcement, or employment obligations.
-
It does not mean that regulators will accept predicate-only compliance in all jurisdictions. Some jurisdictions will reject it.
-
It does not mean that users can evade capital controls or hide from governments. The protocol provides technical confidentiality, not legal immunity.
-
It does mean that the protocol itself does not require surveillance infrastructure, and that disclosure is always at the holder’s discretion rather than built into the protocol.
The legal posture is defensive, not antagonistic: the thesis designs for resilience under legal heterogeneity, not for confrontation with law.
Social Coercion Metrics: When “Optional” Becomes Mandatory
The protocol already acknowledges that lawful privacy is a technical guarantee, not a social guarantee (§4: Threat Model): it cannot prevent coercion to disclose keys, but it can raise the cost of mass surveillance, preserve optionality, and make coercion visible through telemetry. The remaining question is when optional disclosure becomes mandatory in practice.
Forced Disclosure Incidence.
Reported cases where employers, banks, landlords, visa processes, exchanges, or benefits agencies require viewing keys.
Selective Disclosure Scope.
Average breadth of information disclosed per audit event.
Dossier Reconstitution Risk.
Probability that repeated selective disclosures can reconstruct the user’s full graph.
Non-Custodial Practicality Index.
Share of flows that can be completed without a KYC chokepoint at equivalent service quality.
Lawful privacy fails socially before it fails cryptographically. If viewing keys become routine prerequisites for employment, banking, housing, travel, or benefits, optional disclosure becomes administrative disclosure—the social-layer expression of the Administrative Repression pattern introduced in §4: Threat Model. The protocol cannot stop all coercion, but it can measure whether coercion is becoming systemic. These four metrics feed the Agency Preservation Board (§23: Extended Telemetry).
| Requirement | How Satisfied (Protocol) | What Current Law Actually Requires |
|---|---|---|
| AML screening | ZK proof of “sender cleared-set” | Originator identity data (Travel Rule) |
| Jurisdictional limits | ZK range proof of amount | Exact amount above reporting thresholds |
| Tax audit | Time-bounded viewing key | Records sufficient to reconstruct transactions |
| Counterparty verification | ZK set-membership proof | Named-party identification |
Lawful privacy: what the protocol can satisfy versus what current law demands. The right-hand column is not a design boundary the protocol can hold by engineering; it is the law as written, and predicate compliance is unlawful under it in most major jurisdictions until the law changes.
Read the table honestly.
An earlier draft of this table headed its right column “Cannot Require,” implying the protocol holds a boundary that regulators must respect. That framing is wrong and has been corrected. The Travel Rule (FinCEN; FATF Recommendation 16; the EU Transfer of Funds Regulation) obliges obligated entities to transmit and retain actual originator and beneficiary identity data — name, account, amount — not set-membership proofs. A regulated institution cannot lawfully satisfy that obligation with predicates, no matter how sound the cryptography. The accurate statements are:
-
Within the current law, predicate compliance is an engineering option that is not yet a legal option. It requires legislative or rule-level change in every major jurisdiction before a regulated counterparty can rely on it. The protocol’s contribution is to make that change expressible: when a jurisdiction moves, the machinery exists to comply with far less surveillance than universal tracing would need.
-
Outside regulated perimeters, the predicates are simply private. P2P settlement between non-obligated parties is not a Travel Rule event anywhere today. The design buys lawful headroom at the edges while the institutional perimeter remains a policy question, not a protocol one.
-
Who curates the cleared set is a hard, unresolved question. A “sender cleared-set” proof requires an oracle maintaining the set: a sanctions-list curator inside a privacy protocol is simultaneously a chokepoint, a legal attack surface, and a party with liability. The thesis does not have an answer and declines to pretend otherwise.
Securities Law: The Value-Capture Mechanism Is Its Own Legal Risk
The strongest legal threat to the asset is not a ban. It is classification, and the threat comes from inside the thesis rather than outside it. The §10: Work Credits: Energy-Anchored Claims is, in its design commitments, a fact pattern regulators have a name for: fees routed to holders by protocol decision (burns as pro-rata value return), returns derived from the efforts of operators and developers, an expectation of profit from holding, and governance-adjustable fee splits. Under the Howey framework — investment of money, in a common enterprise, with a reasonable expectation of profit derived from the efforts of others — each element is arguably present, and the stronger the value-capture design as an economic argument, the stronger the securities case as a legal one. The irony is structural and must be stated plainly: the thesis’s best economics is affirmative evidence for the classification that would end institutional holdability in the jurisdictions that matter most.
-
A burn is a distribution. Economically the thesis concedes it is a buyback (§10: Work Credits: Energy-Anchored Claims); legally a buyback is a managerial act returning value to holders. “The burn is not a dividend” is an engineering statement, not a legal one.
-
Governance-adjustable fee routing is discretionary management. The reference designs let token governance alter fee splits — the 70/20/10 default, treasury share, burn fraction. Discretion over the return to holders is the “efforts of others” prong wearing a multisig.
-
The checklist cannot treat classification as exogenous. §25: Operator & Investor Checklist asks whether the asset’s legal classification is clear enough for treasury or fund mandates, as though clarity were weather. Classification is partly a consequence of design choices made in this thesis, and the choices that maximize value capture are the choices that maximize Howey exposure.
This is a genuine design tension, not a footnote. The available escapes move in opposite directions, and the thesis should name the corridor rather than drift through it. Removing holder-returning mechanics (no burns, fee destruction only at point-of-sale, purely consumptive fees) weakens Conditions 2–3 of the lemma and moves the asset toward a pure service medium — legally cleaner, monetically thinner. Keeping them maximizes the cash-flow claim and the securities exposure together. A third path — issuance and fee policy fixed ex ante in a constitution beyond governance reach, with no discretionary re-routing ever possible — is the only version of value capture that does not depend on “efforts” anyone could alter, and it is also the version closest to what a store-of-value constitution should look like anyway (§22: Layer 6: Governance & Telemetry). Red Line 7 tracks whether lawful participation remains possible; the securities question determines whether Red Line 7 can be satisfied at all in the largest capital pools.
This section is analysis, not advice.
Jurisdictions differ, enforcement posture shifts, and no statement here is legal advice. The point of writing it down is that a thesis which publishes fifteen red lines but leaves its largest legal vulnerability implicit would be failing its own standard.
Defense-in-Depth Against Bans and Sanctions
Regimes may attempt to ban privacy assets, sanction addresses, mandate KYC at all edges, or classify triad services as “unlicensed financial institutions.”
The live precedent for this section is not a statute but a sanctions action: the designation of Tornado Cash by the US Treasury’s OFAC in 2022 — and the subsequent prosecution of its developers — established that a non-custodial, autonomously operating privacy protocol as such can be treated as a sanctionable entity, and that writing and publishing mixing code can expose its authors to liability. The action was partially reversed on appeal in 2024 (the Fifth Circuit held immutable smart contracts are not “property”), but the operating lesson survives the reversal: the threat vector for privacy infrastructure has not primarily been domestic statutes; it has been secondary-sanctions reach through USD intermediaries, exchange delisting under compliance burden, and personal liability for developers. Three consequences for this stack:
-
Developer and operator liability is a first-class risk surface, not a footnote to Layer 5’s corridor design. Anonymous or distributed development, jurisdictional separation of maintainers from operators, and legal entity structure (§24: Legal, Policy, and Jurisdictional Posture) are not conveniences; they are the difference between a delistable product and a prosecution target.
-
Exchange delisting is the working enforcement mechanism, not the ban itself. Monero and Zcash were not outlawed in most jurisdictions; they were made practically inaccessible by travel-rule compliance burden at regulated venues. Corridor design must assume the fiat on-ramp is the chokepoint that closes first (§10: Work Credits: Energy-Anchored Claims engages the substitute channel this creates).
-
Non-custodial is a legal argument, not a shield. The strongest available defense is precisely the non-custodial architecture this thesis specifies — no controller, no admin keys, no ability to freeze — because it is the fact pattern that defeated the Tornado Cash designation in court. The design should maximize those properties deliberately, because they are load-bearing in litigation, not only in threat models.
Layer 6 cannot prevent law from existing, but it can:
-
Avoid giving any single jurisdiction a kill switch.
-
Maintain jurisdictional diversity in hardware profiles, proof factories, corridor LPs, and foundation incorporation.
-
Provide fallback modes: local-first clients, mesh/satellite relays, minimal CLI modes that maintain basic functionality under degraded conditions.
The legal posture is resilience under legal heterogeneity: the stack does not advertise itself as a tool to evade law, but designs for continued operation across a diverse legal landscape where some jurisdictions are friendly, some hostile, and most ambiguous.
Labs, Foundations, and Neutral Router Commitments
Key commitments:
Neutral router charters.
Router operators commit to content-agnostic routing. Deviation is punished in-protocol and reputationally.
Foundation / lab structure.
Legally separate entities with public charters that define roles and explicitly renounce certain powers.
Multi-jurisdiction footprint.
Incorporations and key staff spread across legal regimes to avoid single-point capture.
Tip: hover a heading to reveal its permalink symbol for copying.