A tokenized security may be a share recorded directly on a distributed ledger, a token that triggers an update in a conventional register, a claim against a custodian, or a product that merely tracks a share’s return. Yet the interface may use the same verb in every case: “transfer”. That is exactly where the risk of confusion begins.

The final report published in August 2026 by the Permanent Editorial Board of the American Law Institute and Uniform Law Commission gives a narrow but important answer under US commercial law. Article 8 of the Uniform Commercial Code, or UCC, can already accommodate a digital token as the mechanism for instructing the transfer of registered ownership of an uncertificated security. The report does not say that the token automatically is the security. It explains how technical movement can acquire legal effect when the issuer or its transfer agent links that movement to the official register.

This distinction complements the taxonomy issued by SEC staff in January. GatherHub compared the two texts with the banking regulators’ capital position and three independent legal analyses. The result is a four-model map: behind the word “tokenized”, a holder may own the security, an indirect entitlement, only an instruction key, or merely economic exposure.

The decisive register is not always the blockchain

For an uncertificated share held directly, registered ownership appears in the official file maintained by the issuer or its transfer agent. Article 8 provides for registration of a transfer following an effective instruction from the appropriate person, subject to the other legal conditions. The ALI report shows that the parties may agree that control of a token is the exclusive mechanism for sending that instruction.

Suppose Alice is the registered owner of a share and also controls its associated token. When she transfers the token to Bilal, the system automatically sends the transfer agent an instruction to replace Alice with Bilal in the register. The token is an authenticated command. Its movement and the change in ownership are connected by the issuer’s rules and applicable law; they are not naturally the same event.

This arrangement explains a seemingly paradoxical statement: a blockchain can be indispensable to the process without being the final legal register. In another architecture, it may form part of the official securityholder file. The visible technology alone therefore cannot reveal where ownership is maintained.

The report mainly addresses direct holding. In an intermediated structure, a broker or bank holds the security and credits the customer with what Article 8 calls a “security entitlement”. A token can represent that indirect interest without registering its holder as a shareholder with the issuer. A wallet proves control of a digital record; it does not by itself reveal the full chain of legal rights.

Four models, four answers to “what do you own?”

The SEC taxonomy first distinguishes two issuer-sponsored methods. Under the integration method, the distributed ledger forms part of the master securityholder file, so an onchain transfer changes the holder of the security. Under the notification method, the security remains recorded offchain; the token itself conveys none of the share’s rights, but transferring it instructs the conventional register to change.

Two further models involve a party unaffiliated with the issuer. Under the custodial model, that third party holds the security and issues a token representing the customer’s indirect entitlement. Under the synthetic model, the token delivers an economic return without passing ownership of the reference security. Depending on its economic reality, it may be a structured debt security or a security-based swap. GatherHub previously verified that mechanism behind some “tokenized stocks” with no shareholder rights.

| Model | Decisive register | Holder’s right | Added risk | |---|---|---|---| | Issuer, integration method | Official file incorporating DLT | Direct ownership of the security | Registry or key failure | | Issuer, notification method | Conventional register updated after the signal | Right after effective registration | Gap between token and register | | Third-party custodian | Custodian books and intermediary chain | Indirect entitlement to a held security | Insolvency, segregation, reconciliation | | Third-party synthetic | Product contract | Claim or exposure, not the share | Issuer credit, collateral, regulatory classification |

This comparison is GatherHub’s original contribution: the useful criterion is not “onchain versus offchain” but the answer to three consecutive questions. Who maintains the legally decisive file? Which event modifies that file? Against which entity can the holder enforce rights? Two tokens transferred on the same network can produce opposite answers.

The dangerous second between token and registration

The ALI report identifies a concrete operational risk: the “gap period”. If Bilal receives control of the token before the transfer agent registers him as owner, there is an interval in which the interface can display the token even though the legal transfer is incomplete.

That interval matters for “protected purchaser” status. In simplified terms, a purchaser who gives value, lacks notice of adverse claims and obtains Article 8 control may acquire the security free of certain adverse claims. For an uncertificated security, registration in the purchaser’s name is one way to obtain that control. Until registration occurs, a stop-transfer demand, court order or prior claim may still intervene.

The PEB describes two ways to narrow the gap. The first makes the token transfer and register update simultaneous or nearly so. The second uses a “control agreement”: the issuer agrees to follow the purchaser’s instructions without further consent from the registered owner before the final name change. This mechanism may also support secured lending, with a lender obtaining control over the security without immediately becoming its registered owner.

Promises of atomic settlement must therefore be tested at the legal layer, not merely timed onchain. A transaction can be irreversible inside a block while remaining incomplete in the securityholder file. Conversely, a properly integrated architecture can bring the two events very close together without claiming that code replaces law.

Equal capital treatment, but only for identical rights

The joint position published in March by the OCC, Federal Reserve and FDIC reinforces this distinction. For bank capital purposes, the technology used to issue and transact in a security does not generally change its treatment. A permissioned or permissionless blockchain does not create a different risk weight by itself.

That equivalence is conditional. The regulators define an eligible tokenized security as one that, under applicable law, confers legal rights identical to those of its non-tokenized form, including ownership rights. Tokens that fail this test fall outside the clarification. “Same asset” cannot therefore be inferred from a price shown on a screen; the same rights must be demonstrated.

The SEC adds a further boundary. A single class of securities may exist in several formats or on several networks if rights remain substantially similar. For a regulated fund, however, different priorities across formats or chains could raise share-class issues. Technical multiplicity must not quietly create an economic hierarchy.

A practical test before trusting the word “tokenized”

Serious documentation should allow a reader to reconstruct six steps: issuance of the security, creation of the token, identity of the registrar, the event that triggers transfer, the moment rights become enforceable, and the procedure if a key is stolen or the records diverge.

The final step is not incidental. The report considers a hacker who gains control of a seller’s token and causes shares to be transferred to an innocent buyer. If the legitimate owner intervenes before registration, the owner may still be able to stop the transfer. If the buyer is already registered and qualifies as a protected purchaser, the buyer may take the security free of the previous owner’s claim. Key security then becomes a commercial-law problem, not merely a cybersecurity concern. Analyses by Morgan Lewis, Norton Rose Fulbright and Dechert corroborate these distinctions while emphasizing their regulatory limits.

For an investor or integrator, three documents are more useful than a seamless demo: the terms of the security, the rules of the register or transfer agent, and the contract linking the token to those rights. The next questions concern reconciliation delays, correction mechanisms, segregation of assets held by a third party, and the rank of the claim if that party becomes insolvent.

The ALI’s final report does not resolve securities regulation, KYC, sanctions, tax, privacy or cybersecurity. Its contribution is more exact: existing US commercial law can accommodate a token as a transfer instruction or control mechanism. But it requires readers to look beyond the wallet. Controlling the key allows someone to act on the system; owning the security still depends on the architecture that turns that action into a legal right.