Jones Day Analysis: SEC CUI Guidance Bans Payment for Order Flow, Requires MEV Protection Disclosures
Jones Day analyzes SEC CUI guidance, finding payment for order flow and third-party transaction compensation disqualifies providers from safe harbor protection.
SEC CUI Guidance Bans Payment for Order Flow and Mandates MEV Disclosures
On April 20, 2026, Jones Day published its analysis of the SEC staff statement on Crypto User Interface providers — and the headline finding is unambiguous: CUI providers that receive payment for order flow, or any compensation tied to the size, value, or success of a securities transaction from any party other than the end user, fall outside the safe harbor entirely. This is not a gray area. It is a categorical structural prohibition with direct consequences for every DeFi front-end, aggregator, and MEV-adjacent infrastructure layer operating in U.S. markets today.
The Jones Day analysis, titled SEC Staff Carves Out a Path: Crypto Interface Providers May Not Be Broker-Dealers, characterizes the safe harbor as meaningful but narrow. The conditions attached to it will force significant structural compliance reviews across the industry.
What the SEC Staff Statement Actually Requires
The SEC staff statement establishes that a CUI provider — any entity operating an interface through which users interact with digital asset trading infrastructure — can avoid broker-dealer registration under specific conditions. Jones Day's analysis clarifies those conditions with precision.
On compensation: The prohibition is not limited to classic payment for order flow arrangements with registered broker-dealers. It extends to any fee-sharing, routing compensation, or transaction-contingent payment from any trading venue, liquidity pool, or affiliated system. The indirect arrangement problem is explicit — a CUI provider that routes to an affiliated venue and receives compensation structured to reflect transaction volume or outcome is outside the safe harbor, regardless of how the fee is labeled.
On disclosures: CUI providers must publicly disclose all material conflicts of interest, fee structures, cybersecurity policies, confidentiality practices, and — critically — MEV-related protections. The SEC staff statement names MEV explicitly. Providers cannot simply assert they offer protection from front-running or sandwich attacks. They must describe the specific mechanisms in place, how those mechanisms work, and any limitations on their effectiveness.
On monetization scope: The only permissible source of transaction-contingent compensation under the safe harbor is the user directly. Any revenue model that involves a third-party venue, market maker, or protocol paying fees based on order routing or transaction outcomes triggers broker-dealer analysis.
Implications for DeFi Protocols and Infrastructure Operators
The implications reach well beyond front-end interfaces. Any protocol or infrastructure layer that sits between a user and order execution — and that participates in the economic flow of that execution — needs to examine its position carefully.
Aggregators and routing layers are the most immediate exposure point. If a DEX aggregator receives any fee from a liquidity source based on volume routed or value settled, that arrangement now carries explicit regulatory risk under the CUI framework. The compensation prohibition is directional — it runs from venue to interface — and it does not care whether the fee is called a "rebate," "integration incentive," or "partnership revenue."
MEV infrastructure faces a parallel question. Block builders, searchers, and auction systems that interact with user transaction flow occupy a position that the SEC staff is clearly beginning to analyze. The explicit inclusion of MEV protection disclosures in the CUI requirements signals that regulators understand the MEV supply chain and are mapping it onto existing investor protection frameworks.
Affiliated venue arrangements are structurally incompatible with the safe harbor. Any CUI provider that operates alongside a trading venue — even through a separate legal entity — must be prepared to demonstrate that no transaction-contingent compensation flows from that venue to the interface layer. Structural separation on paper is not sufficient if economic linkage exists in practice.
The broader signal here is that the SEC is drawing the compliance perimeter around execution quality and order routing — two areas that have defined DeFi's infrastructure debates for years. MEV is now a named regulatory variable, not a technical abstraction.
Where Birdai's Infrastructure Stands
Birdai's core infrastructure — the MEV Observatory, BirdSearch, and Birdai Auction — sits directly at the intersection of what this guidance addresses.
BirdSearch is built on millions of decoded transactions and hundreds of identified searcher patterns across the MEV supply chain. The SEC's explicit requirement for MEV protection disclosures positions BirdSearch as a compliance-layer tool, not merely an analytics product. Protocol teams and CUI providers that need to describe their MEV protections with specificity — to regulators, to users, and in public disclosures — need exactly the kind of transaction-level visibility that BirdSearch provides. Disclosure without data is assertion. Disclosure with data is compliance.
Birdai Auction requires direct attention in light of the PFOF prohibition. Any fee structure in which Birdai Auction receives compensation from a trading venue or liquidity provider that is contingent on transaction size, value, or outcome will need to be mapped against the CUI safe harbor conditions. The Jones Day analysis makes clear that indirect arrangements are in scope. Birdai's legal and product teams are conducting that structural review now. The goal is fee model architecture that serves users and preserves safe harbor eligibility — not a binary choice between revenue and compliance.
The MEV Observatory provides the empirical foundation for both. Regulatory analysis without on-chain verification is incomplete. Real-time MEV data gives compliance teams the ability to validate disclosure accuracy, monitor for emerging conflicts, and demonstrate to counterparties that stated protections are operational — not aspirational.
What to Watch Next
The SEC staff statement is guidance, not a final rule. But Jones Day's analysis treats it as a meaningful signal of enforcement posture, and that reading is correct. The next phase will likely involve staff comment letters or enforcement actions targeting CUI providers whose monetization structures do not survive safe harbor analysis — particularly those with disclosed PFOF-adjacent arrangements or no MEV disclosure at all.
Protocol teams should treat the April 2026 guidance as the starting gun for structural compliance review, not a theoretical exercise. Fee flows, venue affiliations, MEV protection mechanisms, and disclosure language all need to be audited against the CUI conditions Jones Day has now mapped in detail.
Track the SEC's next staff releases on digital asset market structure. The CUI framework is the opening move in a longer regulatory sequence targeting execution layer infrastructure.
Source: Jones Day, SEC Staff Carves Out a Path: Crypto Interface Providers May Not Be Broker-Dealers, April 20, 2026.