AB 2285
Digital Financial Asset Banking Act.
Vote required
Majority
Fiscal committee
No
Appropriation
No
Current location
Judiciary
Take action
Record your position on this measure.
Sign in to record your position, submit testimony, or contact your legislator.
Sign in to take action- Introduced
- Passed Assembly
- Passed Senate
- To Governor
- Became Law
Bill overview
This bill, the Digital Financial Asset Banking Act, establishes regulations for digital financial assets in California. It prohibits individuals from engaging in digital financial asset business activities without proper licensing or meeting specific conditions. The bill defines key terms like ‘digital financial asset’ and ‘digital financial asset business activity,’ and it primarily focuses on regulating banks and credit unions to ensure they provide digital asset custody, staking, and transaction services securely and transparently. It also includes provisions for audits, disclosures to customers, and enforcement actions by the Department of Financial Protection and Innovation.
Key provisions
- Prohibits engaging in digital financial asset business activity without proper licensing or meeting specific conditions.
- Defines key terms such as ‘digital financial asset,’ ‘digital financial asset business activity,’ ‘digital asset custody services,’ and ‘digital asset transaction services.’
- Requires banks and credit unions to obtain approval to provide digital asset custody, staking, and transaction services.
- Mandates annual audits of custodial activities and holdings by financial institutions.
- Requires financial institutions to disclose certain information to customers regarding digital asset services.
- Establishes a framework for subcustodian oversight and compliance.
- Creates a new crime of perjury and imposes a state-mandated local program.
- Authorizes the Department of Financial Protection and Innovation to enforce the law with administrative and civil remedies.
Who is affected
Arguments in favor
Reasons to support this legislation.
No arguments in favor have been submitted.
Submit yoursArguments opposed
Reasons to oppose this legislation.
No arguments opposed have been submitted.
Submit yoursRead the latest version inline or switch to a previous version.
AB2285:v98#DOCUMENT
Bill Start
| Amended IN Assembly March 16, 2026 |
CALIFORNIA LEGISLATURE— 2025–2026 REGULAR SESSION
Assembly Bill
No. 2285
| Introduced by Assembly Member Valencia |
| February 19, 2026 |
An act to amend Section 3201 of add Division 1.26 (commencing with Section 3910) to the Financial Code, relating to financial regulation.
LEGISLATIVE COUNSEL'S DIGEST
AB 2285, as amended, Valencia. Digital Financial Assets Law: prohibitions. Asset Banking Act.
The Digital Financial Assets Law, on or after July 1, 2026, prohibits a person from engaging in digital financial asset business activity, as defined, activity or holding itself out as being able to engage in digital financial asset business activity, with or on behalf of a resident unless any of specified conditions is true. The law defines “digital financial asset” to mean a digital representation of value that is used as a medium of exchange, unit of account, or store of value, and that is not legal tender, whether or not denominated in legal tender and defines “digital financial asset business activity” to mean, among other similar things, exchanging, transferring, or storing a digital financial asset or engaging in digital financial asset administration, whether directly or through an agreement with a digital financial asset control services vendor.
This bill would make nonsubstantive changes to those provisions. bill, the Digital Financial Asset Banking Act, would generally regulate a bank or a credit union under the examination authority of the Department of Financial Protection and Innovation with respect to its provision of digital asset custody services, staking services, and digital asset transaction services, as those terms are defined, including by requiring certain disclosures to costumers and requiring certain financial safety measures. The bill would require a financial institution engaged in digital financial asset custody services to conduct an annual audit of its custodial activities and holdings that is either an independent audit or a review by the financial institution’s board of directors for accuracy and signed be each board member under penalty of perjury. By expanding the scope of the crime of perjury, this bill would impose a state-mandated local program.
This bill would authorize the department to enforce its provisions with administrative and civil remedies, as specified.The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement.This bill would provide that no reimbursement is required by this act for a specified reason.
Digest Key
Vote: MAJORITY Appropriation: NO Fiscal Committee: NOYES Local Program: NOYES
Bill Text
The people of the State of California do enact as follows:
SECTION 1.
Division 1.26 (commencing with Section 3910) is added to the Financial Code, to read:
DIVISION 1.26. Digital Financial Asset Banking Act CHAPTER 1. General provisions3910. As used in this chapter:(a) “Active staking” means intentional participation in staking services resulting in inaccessibility to one’s digital financial asset for an agreed-upon time in exchange for a staking reward minus a fee that is in a fixed amount or a percentage of the staking reward.(b) “Customer” means a person for whom a financial institution provides digital asset services, including a digital asset account holder or a person on whose behalf the financial institution acts in a fiduciary capacity.(c) “Department” means the Department of Financial Protection and Innovation.(d) “Digital asset” means a digital representation of value recorded on a cryptographically secured, distributed ledger or similar technology, including, but not limited to, a digital financial asset.(e) “Digital asset custody services” means the safekeeping or custody of a digital financial asset on behalf of a customer by a financial institution, including maintaining control over the digital financial asset and any associated key.(f) “Digital asset transaction services” means to facilitate the execution of a digital asset purchase or sale on behalf of a customer for compensation.(g) “Digital financial asset” means a digital representation of value that is used as a medium of exchange, unit of account, or store of value, and that is not legal tender, whether or not denominated in legal tender.(h) “Digital financial asset business activity” means any of the following:(1) Exchanging, transferring, or storing a digital financial asset or engaging in digital financial asset administration, whether directly or through an agreement with a digital financial asset control services vendor.(2) Holding electronic precious metals or electronic certificates representing interests in precious metals on behalf of another person or issuing shares or electronic certificates representing interests in precious metals.(3) Exchanging one or more digital representations of value used within one or more online games, game platforms, or family of games for either of the following:(A) A digital financial asset offered by, or on behalf of, the same publisher from which the original digital representation of value was received.(B) Legal tender or bank or credit union credit outside of the online game, game platform, or family of games offered by, or on behalf of, the same publisher from which the original digital representation of value was received.(i) “Digital wallet” means a digital interface or physical device that stores a digital asset or a private key in a manner that enables the owner to securely manage, transfer, and maintain independent control over the owner’s digital asset.(j) “Fiduciary capacity” means a capacity in which a financial institution possesses investment, management, or administration discretion of a digital financial asset on behalf of a customer that creates for the financial institution a strict duty to act in the best financial interest of the customer, including against its own interest.(k) “Financial institution” means a bank or credit union operating under the examination authority of the department.(l) “Key” means a pair of cryptographic codes associated with a digital asset wallet that consists of a public key and a private key that meets both of the following criteria:(1) The public key of the pair enables the receipt of a digital financial asset and the verification of a digital signature.(2) The private key of the pair enables the control, transfer, or management of a digital asset within the digital asset wallet.(m) “Material cybersecurity incident” means a cybersecurity breach or event that materially compromises the security, confidentiality, or integrity of a financial institution’s information system or a digital asset under the financial institution’s control.(n) “Nonfiduciary capacity” means providing digital asset custody services solely for safekeeping without discretionary authority to manage or transfer a digital financial asset and with respect to which legal title and control of the assets remain with the customer.(o) “Passive staking” means staking pooled assets by, or on behalf of, the financial institution wherein the customer may receive the customer’s digital financial asset upon demand in exchange for a staking reward minus an agreed-upon fee, in a fixed amount or a percentage of the staking reward, from the financial institution staking service provider.(p) “Pooled custody” means the collective holding of fungible digital financial assets of like kind belonging to different customers in a shared account or digital asset wallet.(q) “Segregated custody” means the holding separately from the digital financial assets of other customers of the fungible digital financial assets of an individual customer in an account or digital asset wallet.(r) “Slashing” means a penalty imposed by a blockchain protocol that results in the forfeiture or reduction of staked digital assets or staking rewards due to validator misconduct or failure.(s) “Staking” means committing fungible digital financial assets to a blockchain network to participate in the network’s operations by validating transactions, proposing and attesting to blocks, and securing the network.(t) “Staking reward” means any interest, yield, or other compensation earned by a customer from staking a digital financial asset on a blockchain network.(u) “Subcustodian” means a third party that a financial institution uses to hold a digital financial asset on the financial institution’s behalf as part of providing digital asset custody services to a customer. CHAPTER 2. Digital Asset Custody Services3915. (a) A financial institution that provides digital asset custody services in a nonfiduciary capacity shall act only upon the explicit instructions of the customer and shall not independently manage, transfer, or dispose of the digital financial assets.(b) A financial institution shall enter into a written custodial agreement with each customer before undertaking digital asset custody services that meets all of the following conditions:(1) The custodial agreement clearly specifies whether the financial institution is acting in a fiduciary capacity or a nonfiduciary capacity for that customer.(2) The custodial agreement includes both of the following prominent, written disclosures:(A) Whether or not a digital financial asset held in custody by the financial institution is insured by the Federal Deposit Insurance Corporation, the National Credit Union Administration, or any other federal or state deposit insurance or share insurance program.(B) Whether or not a digital financial asset held in custody by the financial institution is a deposit, obligation, or other liability of the financial institution.(3) The custodial agreement contains the terms of service for digital asset management, investment, or otherwise control and inconspicuously describes thresholds or other triggering events that may cause the financial institution to take action on the customer’s behalf.(4) Any change or update to the custodial agreement shall be provided to the customer no less than 45 days before it becomes effective.3916. A financial institution shall not hold less than a one-to-one full reserve of each digital asset owed or attributable to its passive staking customers, and the financial institution’s aggregate holdings of each such digital asset shall, at all times, be greater than the total amount of deposited assets.3917. (a) A financial institution shall not hold digital financial assets in a pooled custody arrangement or segregate digital financial assets by individual customer pursuant to a custodial agreement unless the financial institution maintains accurate records identifying each customer’s specific interest in the digital financial assets.(b) Pooled custody of assets, as described in subdivision (a), shall not relieve the financial institution of the requirement to individually account for and fully reserve each type of digital asset for the benefit of customers under Section 3916.3918. (a) A financial institution engaged in digital financial asset custody services shall conduct an annual audit of its custodial activities and holdings that is either of the following:(1) An independent audit.(2) A review by the financial institution’s board of directors for accuracy and signed by each board member under penalty of perjury.(b) The audit conducted under this section shall contain all of the following:(1) A review for any violation of Section 3916.(2) A review for any violation of Section 3917.(3) A review for a violation of Section 3929. CHAPTER 3. Subcustody of Digital Assets3920. (a) A financial institution shall not utilize a subcustodian to assist in providing digital asset custody services to its customers unless the use of a subcustodian is prominently disclosed on the first page of the customer’s custodial agreement.(b) A financial institution that utilizes a subcustodian shall ensure the compliance of its subcustodian with this division.(c) A financial institution shall not place a digital financial asset into subcustody unless the subcustodian meets all of the following criteria:(1) The subcustodian maintains insurance coverage sufficient to protect against the loss of digital financial assets due to cybersecurity breaches, theft, or other similar events.(2) The subcustodian is any of the following:(A) A bank chartered or licensed under the laws of this state, another state, or the United States.(B) A special purpose depository financial institution chartered or licensed under the laws of this or another state.(C) A digital asset company licensed as a digital financial asset business pursuant to Division 1.25 (commencing with Section 3101) or a money transmitter licensed pursuant to Division 1.2 (commencing with Section 2000).(d) (1) A financial institution shall document in a written subcustodial agreement any subcustodial arrangement and shall structure the arrangement so that the financial institution remains the custodial recordholder of the digital financial assets on behalf of its customers, and the digital financial assets remain the property of the financial institution’s customers.(2) The financial institution shall make any subcustodial agreement described in this subdivision available to the department upon request.(e) A financial institution shall ensure that a subcustodian’s insurance remains in effect and adequate to cover the value of digital financial assets held in subcustody.(f) (1) A subcustodian shall not commingle different types of digital financial assets for reserve purposes.(2) A subcustodian shall not commingle the assets of different financial institutions.3921. (a) A record relating to digital financial assets held in subcustody shall be subject to examination by the department to the same extent as a record relating to digital financial assets held directly by the financial institution.(b) (1) A subcustodian has the fiduciary duties to the customer imposed on the financial institution.(2) (A) A claim for breach of fiduciary duty by a customer shall be brought only against a financial institution.(B) This paragraph does not affect an indemnification provision in a subcustodial agreement. CHAPTER 4. Staking Services3925. (a) A financial institution shall not use a third party for staking services unless all of the following criteria are met:(1) The third party is a subcustodian or a digital financial asset company.(2) The financial institution maintains legal control over the staked assets and maintains appropriate oversight of the staking service.(3) The arrangement for staking services is governed by a written agreement that describes the rights and responsibilities of the financial institution and the subcustodian or digital financial asset company and requires compliance with this chapter.(b) A financial institution that uses a subcustodian or digital financial asset company for staking services shall remain responsible for ensuring compliance with all requirements of this chapter.3926. (a) A financial institution that stakes a digital financial asset on behalf of a customer shall maintain a reserve of each digital financial asset in an amount sufficient to facilitate a timely customer withdrawal or transfer.(b) A financial institution shall ensure that an appropriate portion of each digital financial asset type remains available to meet a passive staking customer request upon demand and an active staking customer request upon demand subject to any staking lockup or unbonding period disclosed to the customer pursuant to this division.3927. (a) A staking reward shall accrue to the benefit of the customer to whom the relevant digital financial asset belongs.(b) A financial institution shall not deduct a fee or commission from staking rewards unless that fee or commission has been disclosed to the customer in writing before beginning staking services and is either of the following:(1) For a staking reward that is greater than one hundred dollars ($100), not more than five dollars ($5).(2) For a staking reward that is greater than one hundred dollars ($100), not more than 5 percent of the total amount of the staking reward.(c) A financial institution shall not charge a fee to cover any nonprovable startup costs to provide active staking unless the financial institution provides to the customer an itemized receipt.(d) (1) Except as otherwise agreed to in writing by the customer, a financial institution shall pay any staking reward earned from staking services to the customer by crediting the customer’s account in the same type of digital financial asset that was used to provide staking services.(2) A payment made under this subdivision shall be made within two business days after the staking rewards are received or become available to the financial institution or third party used to provide staking services.3928. (a) A digital financial asset that a financial institution stakes on behalf of a customer shall remain the property of that customer, and a financial institution shall not record as an asset or liability of the financial institution a staked customer digital financial asset or any staking reward associated with that digital financial asset.(b) A financial institution shall safeguard any staked digital financial asset and not subject it to any lien, security interest, or claim of a creditor of the financial institution.(c) A financial institution shall not encumber, hypothecate, or otherwise use a customer’s staked digital financial asset for any purpose except to facilitate staking services on the relevant blockchain or distributed ledger and shall not expose that digital financial asset to risk of loss except to the extent required in the normal operation of the staking process.(d) A financial institution shall implement and maintain written internal policies and procedures to effectively identify, monitor, and manage risks associated with staking, including operational risks, cybersecurity threats, and slashing.(e) A financial institution shall maintain insurance coverage adequate to protect against potential losses arising from staking activities, including losses attributable to slashing, cybersecurity breaches, theft, or similar events, and shall ensure that insurance coverage remains in effect and sufficient to cover the current value of assets staked on behalf of customers.(f) Any record related to the financial institution’s staking services shall be available for independent audit and examination by the commissioner in the same manner as a record of a nonstaked custodial asset.3929. (a) Before initiating staking services for a customer’s digital financial assets, a financial institution shall provide the customer with a clear and conspicuous written disclosure, in plain language and presented in a manner that is readily accessible and understandable to the customer, of the terms and conditions of the staking services that includes, at a minimum, information regarding all of the following:(1) The fact that the financial institution may automatically stake an eligible digital financial asset in the customer’s account unless the customer affirmatively opts out of participation.(2) The key risks associated with staking, including the potential for loss of staked assets or staking rewards due to slashing or other network events, and cybersecurity or operational risks inherent in the staking process.(3) Any applicable lockup, unbonding, or notice period before a staked digital financial asset can be withdrawn or transferred and the implications of that period for the customer’s access to the customer’s digital financial assets.(4) The customer’s rights and obligations related to the staking service, including the right to discontinue participation in staking at any time and the entitlement to receive staking rewards earned on the customer’s digital financial assets.(5) The amount or rate of any fee or commission that the financial institution will deduct from a staking reward as compensation for providing staking services.(b) A customer’s agreement to participate in the staking services shall constitute authorization for the financial institution to stake the customer’s digital financial assets on a passive basis in accordance with this section.(c) A financial institution shall not provide active staking services to a customer unless the customer provides an affirmative agreement to participate in active staking services. CHAPTER 5. Money Laundering and Cybersecurity3935. A financial institution shall establish and maintain an antimoney laundering compliance program that is risk based and commensurate with the nature and scope of the financial institution’s digital asset custody and staking services that includes, but is not limited to, all of the following:(a) A system of internal controls to ensure ongoing compliance with the Bank Secrecy Act (31 U.S.C. Section 5311 et seq.) and other applicable antimoney laundering law.(b) Independent testing for compliance to be conducted by qualified internal audit personnel or an independent external party.(c) The designation of an officer responsible for coordinating compliance with the Bank Secrecy Act (31 U.S.C. Section 5311 et seq.) and the financial institution’s antimoney laundering program.(d) Appropriate risk-based procedures for conducting ongoing customer due diligence, including monitoring of customer transactions and updating customer information as necessary.3936. (a) A financial institution and any of its subcustodians shall maintain a cybersecurity program designed to protect the confidentiality, integrity, and availability of the financial institution’s information systems, digital asset custody, and staking software and hardware that is based on the financial institution’s risk assessment and designed to perform all of the following functions:(1) Identifying and assessing internal and external cybersecurity risks that threaten the security or integrity of nonpublic information stored on the financial institution’s information systems as it relates to the digital financial assets of its customers.(2) Using defensive infrastructure and the implementation of policies and procedures to protect the financial institution’s information systems, and the nonpublic information stored on those information systems, from unauthorized access, use, or other malicious acts.(3) Detecting cybersecurity events.(4) Responding to identified or detected cybersecurity events to mitigate any negative effects.(5) Recovering from cybersecurity events and restoring normal operations and services.(6) Fulfilling applicable regulatory reporting obligations.(b) Any information relevant to the financial institution’s cybersecurity program, including the relevant and applicable provisions of a cybersecurity program maintained by any subcustodian, shall be made available to the department upon request.(c) The cybersecurity program for a financial institution and any of its subcustodians shall align with applicable federal cybersecurity standards for financial institutions, including, but not limited to, the guidelines of the Federal Financial Institutions Examination Council (FFIEC) Information Technology Examination Handbook, the framework established by the National Institute of Standards and Technology (NIST), and any other standard deemed applicable by the department and shall comply with applicable federal financial privacy and data security requirements, as determined by the department.(d) (1) A financial institution shall notify the department within 72 hours after discovering any material cybersecurity incident that impacts the financial institution or its subcustodian’s digital asset custody or staking software or hardware or any digital financial asset held or managed through those systems.(2) The notice required by this subdivision shall include a description of the incident and its likely impact on the financial institution and its customers, as prescribed by the department.(e) A financial institution shall maintain, for at least seven years, detailed records of its compliance efforts under this section, including any policy, procedure, risk assessment, audit report, or training material related to its antimoney laundering program and cybersecurity program, and shall make those records available for inspection by the department upon request or during any examination. CHAPTER 6. Fiduciary Digital Asset Transaction Authority3940. (a) A financial institution shall not facilitate the purchase or sale of digital financial assets on behalf of a fiduciary account or customer unless the financial institution is acting in a fiduciary capacity pursuant to the express instruction of the customer.(b) Any fiduciary activity conducted through or with a subcustodian shall be conducted only through or with a subcustodian that is duly licensed or chartered to conduct digital asset business activity.(c) A financial institution that facilitates a digital financial asset transaction on behalf of a fiduciary account or customer shall act solely in a fiduciary capacity for the benefit of its customer and shall not engage in proprietary trading of a digital financial asset.(d) A financial institution that facilitates a digital financial asset transaction on behalf of a fiduciary account or customer may utilize subcustodians to execute transactions on behalf of fiduciary accounts. The financial institution may delegate discretionary authority to these subcustodians regarding the timing, sequence, and venue of transaction execution. Such delegation shall comply with the fiduciary responsibilities of the financial institution and be subject to ongoing oversight. The financial institution shall perform due diligence and maintain continuous monitoring of any subcustodian to ensure compliance with this division and the protection of fiduciary assets. Delegation of authority under this subdivision does not relieve the financial institution of its fiduciary obligations or its ultimate responsibility for compliance with the requirements of this division.(e) A financial institution that purchases a digital financial asset on behalf of a fiduciary account or customer shall ensure that the digital financial asset is transferred into the financial institution’s custody as soon as reasonably practicable after execution of the transaction is held in custody pursuant to this division and maintained under the financial institution’s control consistent with its fiduciary obligations.3941. (a) Before a financial institution facilitates the purchase or sale of digital financial assets on behalf of a fiduciary account or customer, the financial institution shall disclose, in a clear and conspicuous written form, to the person on whose behalf it acts all of the following:(1) The methodology or basis used to determine the execution price of the digital financial asset transaction.(2) Any spread, fee, commission, or other charge that will be applied to the transaction.(3) The expected timeline for settlement of the transaction and for the digital financial asset to be available in the customer’s fiduciary account.(b) (1) For any digital financial asset purchase or sale executed on behalf of a fiduciary account or customer, the financial institution shall create and retain an electronic record of the transaction, including, but not limited to, all of the following:(A) The date and time of execution.(B) The type and amount of digital financial asset purchased or sold.(C) The price at which the transaction was executed.(D) The identity of the custodian used.(E) Any fee, commission, or spread charged.(2) A record described in this subdivision shall be maintained for at least seven years and contain information to assess compliance with Section 3920.(3) A record described in this subdivision shall be made available to the department upon request or during examination.3942. A financial institution shall document its compliance with this chapter and shall be prepared to demonstrate that compliance to the department. CHAPTER 7. Enforcement3945. (a) The department may issue a written order directing a financial institution to take specific corrective action to remedy any violation of this division that states the grounds for issuance and the required remedial measures. (b) The financial institution shall, within 10 calendar days of receiving an order authorized by subdivision (a), respond in writing to the department detailing the corrective actions taken or planned to address the issues identified.3946. If the department believes that a financial institution is engaged in an unfair or deceptive practice with respect to conduct subject to this division, the department may serve upon the financial institution a written notice describing the alleged violation or practice and specifying a time and place for a hearing to be held within 15 calendar days of the notice, at which the financial institution may present evidence or argument. If, after that notice and hearing, the department finds that the financial institution has engaged in the alleged conduct, the department may issue a cease and desist order ordering the financial institution to immediately discontinue the specified conduct and to take affirmative action, if necessary, to prevent its recurrence.3947. (a) If the department finds that a financial institution’s conduct or condition is likely to cause immediate and irreparable harm to its customers or the public before a formal hearing can be concluded pursuant to Section 3946, the department shall issue a temporary emergency order that directs the financial institution to immediately cease or desist from a specified activity or to take any other action necessary to prevent or mitigate the harm. (b) An order under this section is effective upon service on the financial institution. (c) A financial institution subject to an order under this section shall be given the opportunity for an expedited hearing. Upon the financial institution’s request, a hearing shall be held within 10 calendar days after the issuance of the order to determine whether the order should be stayed, modified, or made permanent. If the financial institution does not request a hearing within the 10-day period, or if the financial institution fails to appear at the scheduled hearing, the temporary order shall remain in effect until the department either lifts it or replaces it with a cease and desist order or other final order under this chapter.3948. The department may impose a civil penalty for a violation of this division subject to all of the following:(a) For a first violation, the civil penalty shall not exceed five thousand dollars ($5,000) per violation.(b) For any subsequent offense, the civil penalty shall not exceed ten thousand dollars ($10,000) per violation.3949. (a) If the department finds that a financial institution has committed a material or repeated violation of this division, has willfully defied any lawful order issued by the department under this division, or is conducting its digital financial asset business activity in a manner that poses a significant risk to the safety of customer assets or to the soundness of the financial institution, the department may suspend or revoke the financial institution’s authority to provide any digital asset service subject to this division.(b) A suspension or revocation issued under this section shall become effective only after the financial institution has been given notice, a hearing opportunity, and a written decision by the department affirming the grounds for the action.
SEC. 2. No reimbursement is required by this act pursuant to Section 6 of Article XIII B of the California Constitution because the only costs that may be incurred by a local agency or school district will be incurred because this act creates a new crime or infraction, eliminates a crime or infraction, or changes the penalty for a crime or infraction, within the meaning of Section 17556 of the Government Code, or changes the definition of a crime within the meaning of Section 6 of Article XIII B of the California Constitution.
SECTION 1.Section 3201 of the Financial Code is amended to read:
3201.
On or after July 1, 2026, a person shall not engage in digital financial asset business activity, or hold itself out as being able to engage in digital financial asset business activity, with or on behalf of a resident, unless any of the following is true:
(a)The person is licensed in this state by the department pursuant to Section 3203.
(b)The person submits an application on or before July 1, 2026, and is awaiting approval or denial of that application.
(c)The person is exempt from licensure under this division pursuant to Section 3103.