βBirdai
Back to Research
PolicyApril 20265 min read

Jones Day Analysis: SEC CUI Statement Bans PFOF, Requires MEV-Related Protections as Named Disclosure

Jones Day analysis confirms the SEC's April 13 CUI statement explicitly names MEV-related protections as a disclosure requirement and bans PFOF for crypto interfaces.

SEC's April 13 Staff Statement Makes MEV Disclosure a Named Compliance Requirement

On April 13, 2026, the SEC's staff issued a statement carving out a conditional path for crypto interface providers to avoid broker-dealer classification. Seven days later, Jones Day published a detailed analysis confirming what the headline summaries missed: MEV-related protections are explicitly named as a disclosure requirement, not inferred, not implied — named. For any team operating a decentralized front-end, aggregator, or on-chain trading interface under this framework, that distinction is the difference between a feature and a legal obligation. Read the Jones Day analysis here.

What the SEC Staff Statement Actually Says

The SEC staff statement, released April 13, 2026, establishes conditions under which Covered User Interface (CUI) Providers may operate without triggering broker-dealer registration requirements. Jones Day's April 20 analysis dissects two provisions with direct market structure consequences.

First, payment-for-order-flow is dead in this context. The statement explicitly prohibits CUI Providers from receiving any compensation based on the size, value, or success of a securities transaction from any party other than the user. That language closes the structural loophole that PFOF has historically exploited. There is no carve-out for soft rebates, routing incentives, or volume-tiered arrangements. If the compensation traces back to order execution, it is prohibited.

Second, MEV is treated as structural risk, not edge-case behavior. SEC staff characterized MEV as "an inherent structural risk in on-chain transaction architecture." That framing is significant. It signals that regulators are not treating MEV as incidental or rare — they are treating it as a baseline condition of on-chain markets that users must be informed about before transacting. The statement requires CUI Providers to disclose MEV-related protections as a named category. Protocols cannot satisfy this requirement with a generic "transactions may be front-run" boilerplate buried in terms of service.

What the statement does not resolve: antifraud liability. Jones Day specifically flags that the SEC staff statement leaves open all secondary liability questions related to MEV and connected trading venues. That silence is not comfort — it is a gap that enforcement action can fill at any time.

Implications for DeFi Protocols and Interface Operators

Any team operating a front-end that routes user transactions on-chain and falls within the SEC's definition of a CUI Provider now faces a concrete compliance checklist, not a principles-based aspiration. MEV disclosure is a named line item on that checklist.

The disclosure burden requires data. Telling users that MEV protections exist is not enough. A credible disclosure — one that would survive SEC staff scrutiny or, more relevantly, plaintiff discovery in an antifraud action — requires demonstrable evidence of what those protections are, how they perform, and what MEV exposure users actually face. That requires transaction-level observability at scale.

The PFOF prohibition has a secondary effect that protocol teams should model out. Revenue structures that relied on routing arrangements — even arrangements not formally labeled PFOF — need immediate legal review. If a liquidity provider, market maker, or order routing partner compensates an interface based on any execution metric, that arrangement is structurally prohibited under the staff statement's plain language.

The open antifraud question is the live wire. Jones Day's flag on secondary liability for MEV-connected trading venues is not academic. If a block builder, searcher, or auction operator is later characterized as a "connected trading venue" for purposes of antifraud analysis, the interface providers routing through them inherit exposure. Protocols need securities counsel opinions on this question now, before enforcement defines the answer for them.

Where Birdai's Infrastructure Sits in This Framework

Birdai's MEV Observatory was built to provide execution transparency across on-chain markets — tracking MEV extraction patterns, sandwich activity, and searcher behavior across millions of decoded transactions. Under the SEC's April 13 framework, that capability is no longer just a research product. For CUI Providers operating under the no-action conditions, the Observatory represents the kind of verifiable, continuous MEV monitoring that a credible disclosure program requires.

BirdSearch gives protocol teams and compliance functions the query infrastructure to pull transaction-level execution data on demand. When a regulator or plaintiff asks what MEV exposure looked like for users of a given interface during a specific period, that question needs an answer with data behind it — not an estimate.

The antifraud liability question identified by Jones Day has direct implications for Birdai Auction operators and the searchers participating in that infrastructure. The legal question of whether a block auction mechanism constitutes a "connected trading venue" under the SEC's secondary liability analysis is unresolved. Birdai is actively engaging securities counsel on this question. Protocol teams integrating Birdai Auction should do the same.

What to Watch Next

The April 13 staff statement is not a rule. It carries no binding legal authority, and enforcement staff are not bound by it. The next signal to watch is whether the SEC's Division of Enforcement treats the statement's MEV disclosure requirement as a baseline standard in any forthcoming action against a CUI Provider. The first enforcement matter that cites inadequate MEV disclosure will set the practical threshold for what "sufficient" looks like — and that threshold will be set against whatever data the named respondent failed to produce. Protocols that have built MEV observability into their compliance stack before that action arrives will be in a structurally different position than those that have not.

Source: Jones Day Insights, April 20, 2026 — "SEC Staff Carves Out a Path: Crypto Interface Providers May Not Be Broker-Dealers"

Back to Research
Cookies

We use only essential cookies and privacy-respecting, cookieless analytics: no cross-site tracking, no ad pixels. Details in our privacy policy.