CBSRCross-Border Stablecoin Register · the evidence layer for agentic finance

Cross-Border Stablecoin Register · v0.11.0 · 20 August 2026 · doi:10.5281/zenodo.20730358

It will refuse to answer 152 of 152 questions today. That is why it can be trusted.

Every system that reads regulation will give you an answer. CBSR is the one that can prove when it should not. Each record carries six orthogonal axes — kind of claim, force of the instrument, strength of provenance, source, freshness, independent review. All six must pass before a record may be cited as current law. Today none do. That is not a coverage failure; it is fail-closed working correctly. When the evidence chain is not closed, the right move is to stop, not to guess.

CC-BY-4.0 (data) / Apache-2.0 (code)  ·  every release archived to Zenodo for a DOI  ·  twelve jurisdictions × fifteen dimensions  ·  independently maintained, unsponsored


the artifact  ·  what one record looks like

One proposition. Six axes. All of them showing.

This is a real record from the register. It is among the best-sourced of the 152 — confirmed against the official text — and it is still not decision-ready today. The marked axis below is the reason. Moving that axis does not take more code; it takes a second person reading the instrument.

hk-frs-permitted_activity_yield-001 Hong Kong  ·  HKMA

The licensee must not pay any interest on issued stablecoins.

Instrument
Stablecoins Ordinance (Cap. 656)
Pinpoint
Schedule 2, s.15 — Non-interest bearing
Official text
elegislation.gov.hk/hk/cap656
claimtier1_legal
instrumentin_force_enacted
provenanceresolution_text
sourceofficial
freshnessunknown
reviewunreviewed

Four axes pass, two do not. freshness is the binding one: the provision itself has not moved, but nobody has re-checked the source inside the SLA window, so the register declines to project it as current law. This is what “I don't know” looks like when it is written down as a field.

Every record in the register has this shape. No hidden confidence score, no summary whose provenance cannot be named — six fields, each of which can be pointed at and questioned.


the argument  ·  three problems, one gap

A model has intelligence and no institutional memory. A financial institution carries accountability, and accountability runs on provenance. The thing that sits between the two does not exist yet, which is why it has to be built.

The three below are not three phrasings of one problem. Each stands on its own, and while any one of them is unsolved an agent that moves money has no ground to stand on.

01

AI has intelligence. It does not have institutional memory.

A model can summarize a statute better than most people. What it cannot answer are the questions that decide whether the summary is usable at all — and when it cannot, it looks exactly like when it can.

  • which version
  • which jurisdiction
  • in force, or not
  • which rule prevails
  • what the exceptions are
  • who carries the liability
  • the date it changes
  • where it was read
02

Finance is becoming agentic.

The old shape was human → interface → transaction. The shape now forming is intent → agent → policy → execution, and nobody is watching the middle two steps transaction by transaction.

A system that selects a payment rail, routes liquidity, settles across a border, or manages a treasury position does not need a compliance memorandum written for a person. Compliance can no longer live as a PDF — not because the format is poor, but because the thing reading it is no longer a person.

03

Institutional knowledge has to become machine-readable.

Not converting PDFs into JSON, which only changes the container. It means writing down as fields every judgment a careful human reader keeps to themselves — this one is only industry practice, that statute has not commenced, this cell I never saw the official text for — and having the build enforce them.

A judgment that is not written down is a judgment software cannot read, and a judgment software cannot read is one an agent will act as though nobody ever made.


from legal text to machine-actionable institutional intelligence

Each step in this chain loses something, and each loses it differently. What this project does is make what is lost at each step something written down and something that can be pointed at.

01Law

The primary instrument. Statute, regulation, supervisory rule, commencement order.

02Evidence

Whether what was read is official text or a paraphrase. With a pinpoint, and the date it was read.

03Knowledge

One sourced (jurisdiction × instrument × dimension) proposition, schema-validated.

04Rules

Constraints, interaction sets, precedence, and the date on which an instrument starts to bite.

05Intelligence

A verdict resolved for one directed edge, with the mechanism and the provision it rests on.

06Agent

Typed MCP tools. What reaches the model is structure, not prose it has to parse again.

07Action

Routing, settlement, treasury, filing. By here the provenance is either still attached or was dropped long ago.

None of these steps is automatic. Steps 02 and 04 are the slowest and the most human on the chain, and they are the two most often skipped — after which step 07 continues to look entirely normal.


the gap  ·  one question, two answers

Both answers below were produced for the same question. Only one of them can be checked.

A general model, unaided

Q: Can a euro-area e-money token issuer offer into the United States today?

“Yes, subject to registration at federal level as a permitted payment stablecoin issuer and to state money transmitter licensing. Cross-border offering is additionally subject to the applicable anti-money-laundering requirements.”

  • 01It reads a regime that is enacted but not yet commenced as if it were operative. There is no federal issuer status available to obtain today.
  • 02It carries no date. An answer with no date never goes stale, and never turns out to have been wrong.
  • 03It carries no provision. You cannot check it. You can only decide whether to believe it.
The same model, reading CBSR

Q: Can a euro-area e-money token issuer offer into the United States today?

“EU → US is Category T, regime in transition. The destination has adopted a comprehensive regime that is not yet operative, so today there is no inbound authorization to obtain and no prohibition to cite. The edge resolves to Category II on 18 January 2027, the outer date for the GENIUS Act §18 comparability gate. Here is the record it rests on.”

  • The verdict arrives with its class, its gating mechanism, and the provision it rests on.
  • It carries an as_of date and a register version, so it can be shown to have been wrong later.
  • It treats “not yet in force” as a named state rather than a hedge in prose.

The second answer is not more confident. It is less confident, in writing, in a form software can act on. That is the whole design. A language model fails here not because it reasons badly but because it has nothing to reason over: the text it is paraphrasing may have moved since it was trained, and it has no way to know.


the proof  ·  one border, two directions, two answers

USEU

EUUS

US EU UK CN HK JP
clears (Cat I) gated (Cat II) blocked regime in transition

Feasibility is directional. The binding rule sits at the destination's inbound gate, with a drag from the origin. Today US → EU clears and EU → US does not, though nothing bars it: the US regime is written and not yet in force. Move the date past 18 January 2027, the outer cap on the GENIUS Act §18 comparability gate, and that edge resolves to Category II along with seven others into the US. In this register 56 of the 66 jurisdiction pairs read differently depending on which way the money moves. A flat compliance table has one cell per pair. That is the whole problem.


what is underneath  ·  six surfaces, one record

One record, presented six ways for six kinds of reader. Each surface is computed from dataset.json; none of them is a display copy kept in step by hand.

01

The corridor layer

All 132 directed edges across twelve jurisdictions, each read at the destination's inbound gate, carrying its feasibility class, the mechanism that gates it, and the date it changes.

Corridors and the time engine →
02

Agent access

An MCP server of roughly thirty typed tools, and the field contract a grounded answer has to carry. A model reasons from a citation it can point at rather than a paraphrase it cannot defend.

MCP, the contract, the failure modes →
03

KYA · Know Your Agent

KYC asks who the customer is and KYB asks who the business is. Nobody has settled who the agent is. A working framework, published for comment rather than asserted as settled.

Four questions, four assurance levels →
04

The intelligence stack

Five layers from primary law to agent action, over the six build layers that implement them, three orthogonal evidence axes, and a CI pipeline that refuses a claim its evidence cannot carry.

The architecture, the gates, the negative tests →
05

The research

Six working papers carry the framework the register is built on; eight short-form pieces track the legislative record itself. One is filed in the US SEC Crypto Task Force docket, one published on Duke Law's FinReg Blog.

Papers and the analysis index →
06

Standards and development targets

Where this work sits in the rules-as-code and RegTech traditions, and which development targets its data can speak to — stated as subject-matter alignment, never as endorsement.

Rules as code, RegTech, the SDG mapping →

scope  ·  one vertical, done properly

Cross-border stablecoins are the first vertical, not the boundary of the method. It was chosen as the starting point because it satisfies two conditions at once: the rules arrived within a single year, and the cost of a wrong answer is measurable.

What exists today

All of it verified, versioned, machine-queryable, and graded against the citable bar. Everything in this column can be opened, disputed and cited today.

  • 12 jurisdictions × 15 regulatory dimensions
  • 132 directed corridors, 6 feasibility classes
  • 152 sourced records · 46 structural candidates · 0 decision-ready
  • 16 dated reclassifications
  • ~30 typed MCP tools
  • 6 working papers, 1 SEC docket filing

why the right column is empty

Because filling it in requires no evidence, and this project's entire credibility rests on everything written down being defensible. Machine-readable regulatory data across eight domains and twelve jurisdictions each is not one person's work; claiming otherwise costs the left column its credibility too. The left column is real, which is the only reason the right one has to read like this.


who reads it

Today that answer lives in law-firm memoranda. A digital-assets partner in London or Hong Kong bills north of $1,000 an hour to write one. It arrives as prose, it is stale a quarter after you buy it, and no software can read it. Chain analytics goes the other way: it tells you where the money went, never whether it may go there. CBSR sits in that gap.

Grounding an agent

A team giving an AI system a sourced basis to act on regulation: typed tools, answers that carry citations, and a version number that can be checked afterwards.

Scoping a corridor

A payments team pricing the legal path between two jurisdictions before they build, and reading the date it changes.

Entering a market

An issuer or fintech checking where a token can be offered, through which gate, and whether that gate yet exists.

Supervision and RegTech

A supervisor or policy team tracking what changes the day a pending law commences, and testing whether an AI system's regulatory answers are traceable.

Research and teaching

A citable, reproducible dataset with a DOI, which a student or researcher can put their own questions to without first rebuilding it.


open call  ·  jurisdiction maintainers

Twelve legal systems. One person reading them.

Primary-source verification is the slow half of this work, and it is done by hand. The register is honest about what that costs: of 152 sourced records, 46 pass the structural filter and 0 clear all six axes today. The rest are published as a per-cell worklist rather than smoothed over.

A jurisdiction maintainer is one person who reads one legal system and keeps its cells honest. It is the single contribution that moves that number. It does not need to be full-time and it does not replace anyone's day job. It needs someone who already reads primary law in one of these systems and is willing to write down what they read, with a pinpoint, in a form that can be argued with.


what you may rely on

This is a dated snapshot, not a live feed, and the distinction is the whole contract. Each release is versioned, archived to a DOI, and true as of the date it carries. Between releases nothing is promised: law moves, and this register does not move with it until the next build. There is no uptime commitment, no support queue, and no undertaking that any corridor still reads today what it read at the dateline — verify against the primary source before you rely on it.

What is promised instead is narrower and checkable: every claim carries the provision it rests on and the date it was read, the citable subset is enforced by the build rather than asserted in prose, and the unverified backlog is published as a per-cell worklist rather than left implicit. Treat it the way you would treat a dated legal memorandum, because that is what it is.