Blockchain Regulation Matrix
The Blockchain Regulation Matrix (BRM) establishes a framework outlining the concerns of regulating the blockchain from both the government and the consumer perspective, and in doing so, provides a pragmatic and clear approach to Web3 regulation. The BRM outlines regulation aspects of the blockchain by viewing it as a blockchain stack in many layers starting with the electricity physically supporting the blockchain at the base layer, all the way to the process of offloading crypto to fiat currency. With centralization and decentralization on either side of the matrix, the primary objective of the BRM is to understand where and how regulation of the blockchain should be developed specific to each layer.
Beginning with the electricty supporting the blockchain, as you hover over the images of each row, you'll see the specifics for that topic within that layer. The left side refers to projects that are centralized, while the right side refers to projects that are decentralized. For example, if there was an organization or business that wanted to provide electricity to miners in their area, that would be a centralized project. However, if there was a solar farm operating as a DAO that wanted to provide electricity to miners, that could be a decentralized project.
There are two illustrations of the Blockchain Regulation Matrix below, a short-form immediately below and a long-form afterwards.
Hover over the icons to preview each topic, and click any icon to pin its details — the address bar then links straight to that cell, ready to share.
Permanent Storage Layercentralized
This row applies to protocols providing immutable data storage to their users.
Partially addressedHosting law (DSA, DMCA) reaches gateways and pinning services, awkwardly.
Government Concerns
- Takedown capability exists at gateways and pinning services — and so does takedown liability (CSAM, DMCA)
- Data-residency and sovereignty rules colliding with globally replicated storage
Consumer Risks
- 'Permanent' storage that quietly dies when the pinning company does — pinning is not permanence
- Gateway censorship silently making stored content unreachable
Cons to over-regulation
- Hosting-liability regimes strict enough to make storing any user content untenable
- Compliance costs concentrating storage in a few giant providers — recreating the centralization the layer exists to avoid
Cons to lack of regulation
- Consumers cannot distinguish marketing 'permanence' from funded, replicated permanence
- No standards for what happens to stored data in provider insolvency
Does blockchain technology currently exist to fulfill these obligations, and if so, what is it?
- Content-addressing: hashes prove integrity regardless of which host serves the data
- Encrypted storage with client-held keys — providers physically cannot read or leak content
- Filecoin-style storage deals with cryptographic proof the data is actually being stored
Current regulatory landscape
- enactedEU Digital Services Act — EU, 2022. Hosting-provider notice-and-action duties apply to gateways and pinning services; fit for operatorless networks is unresolved.
- guidanceDMCA / Section 230 framework — US, ongoing. Safe-harbor and takedown mechanics assume a host who can remove content — the assumption this layer breaks.
Notable incidents
- Illicit content in permanent storage (2019–) — Studies documenting illegal material written into permanent ledgers and storage networks — content no party can remove — remain the layer's hardest policy problem.
- IPFS-hosted phishing waves (2022–23) — Phishing sites pinned to decentralized storage evaded conventional takedowns, forcing gateway-level filtering as the practical control point.
