New federal hemp rules could put billions of dollars in processing volume under review. Acquirers have two choices: understand what their merchants are actually selling—or eliminate the risk altogether.
For acquiring banks and payment processors, the coming changes to federal hemp law are not simply a cannabis-industry problem.
They are a portfolio intelligence problem.
As the federal definition of hemp changes, products that have historically existed within a federally lawful hemp framework may no longer qualify under that same framework. Product formulations, THC and THCA thresholds, cannabinoids, seed genetics and other characteristics can suddenly matter to the legal and risk classification of a merchant’s inventory.
For an acquirer with five hemp merchants, that is a compliance review.
For an institution supporting hundreds or thousands of merchants—each operating websites containing dozens, hundreds or thousands of SKUs—it becomes something fundamentally different: a data problem that cannot realistically be solved manually.
And without the technology to solve it, institutions may be left with the most conservative option available: Terminate the merchant. Restrict the vertical. Or close the BIN.
That approach reduces regulatory exposure. It can also eliminate enormous amounts of perfectly legitimate processing volume. RegX was built to provide another option.
The Risk Is Moving From the Merchant to the Product
Traditional merchant underwriting asks relatively static questions.
Who owns the company? What does the merchant sell? What is its MCC? Where does it operate? What is its processing history? Does its website comply with applicable requirements?
Those questions remain important.
But emerging hemp regulation creates a much more difficult requirement: What is this merchant selling right now?
Not what the merchant sold when it was boarded six months ago. Not what the underwriting file says it sells. Not what its homepage says it sells. What is actually available for purchase across the merchant’s digital environment today? That distinction matters.
A merchant can remain the same legal entity, maintain the same ownership, process under the same MID and operate through the same website while its underlying product risk changes dramatically.
One new SKU can alter the compliance profile.
A reformulated product can alter it.
A cannabinoid can alter it.
A change in concentration can alter it.
A new state restriction can alter it.
A legislative change can potentially reclassify an entire category overnight.
The MID hasn’t changed. The risk has. That is precisely where conventional periodic underwriting begins to break down.
Multiply That Problem Across an Acquiring Portfolio
Consider the problem from the perspective of an acquiring institution.
A portfolio contains 1,000 merchants.
Those merchants collectively offer 100,000 products.
Products change continuously. Websites change. Certificates of Analysis change. Shipping policies change. Claims change. Regulations change.
Now introduce a federal regulatory event that potentially changes the permissibility or risk profile of an entire product category.
The institution needs to determine which merchants are affected, which products create the exposure, what changed, which jurisdictions are implicated and whether the problem can be corrected.
Doing that manually is not merely expensive.
At sufficient scale, it becomes operationally impossible.
This creates a dangerous asymmetry for financial institutions.
The bank can carry the exposure of thousands of individual products while having visibility only at the merchant level.
The Rational Response Becomes De-Risking
When an institution cannot reliably identify risk inside a portfolio, the rational response is often to eliminate the category containing the risk.
Payments has seen this pattern before.
If an acquiring bank knows that some merchants within a BIN may become noncompliant but cannot determine which merchants—or which products within those merchants—create the exposure, portfolio-level action becomes considerably easier than SKU-level investigation.
That can mean suspending onboarding.
It can mean terminating a merchant category.
It can mean exiting an entire vertical.
And in the most extreme circumstances, it can mean shutting down an entire BIN or program.
The institution has solved the compliance problem.
It has also potentially destroyed millions or billions of dollars in otherwise permissible payment volume.
The problem isn’t necessarily that the entire portfolio became prohibited.
The problem is that the institution lacked the intelligence required to distinguish what was permissible from what was not.
AI Changes the Economics of Compliance
This is where artificial intelligence becomes more than an efficiency tool.
It becomes risk infrastructure.
RegX.ai is designed to continuously analyze merchant environments at a level of granularity that conventional underwriting was never designed to achieve.
Instead of treating a merchant as a static underwriting file, RegX evaluates the merchant’s actual digital commerce environment.
The objective is not simply to generate another risk score.
It is to answer the questions an acquiring institution actually needs answered:
What changed?
Where is the exposure?
Why does it matter?
Can it be remedied?
And does the merchant actually need to be terminated?
That last question may ultimately be worth billions of dollars to the acquiring industry.
Analyze. Decide. Remedy.
RegX approaches compliance through three fundamental actions:
ANALYZE
RegX analyzes merchant websites, product catalogs and relevant compliance signals to identify products, claims, documentation and other characteristics that may create regulatory or policy exposure.
Instead of manually reviewing thousands of pages across thousands of merchants, institutions can use technology to identify the areas that actually require attention.
DECIDE
Detection alone is not enough.
A system that produces thousands of alerts simply creates another operational burden for the compliance department.
RegX is designed to contextualize what it finds against applicable rules and institutional policies so that risk teams can make decisions based on actionable intelligence rather than raw website data.
The objective is to move from:
“This is a hemp merchant.”
to:
“These specific products or conditions require review for these specific reasons.”
That is a fundamentally different level of risk visibility.
REMEDY
And this may be the most important component.
Historically, payments compliance has too often been binary:
Approve or terminate.
But many merchant compliance problems are remediable.
A product can be removed.
A shipping jurisdiction can be restricted.
A claim can be changed.
Documentation can be updated.
A SKU can be blocked.
A merchant can correct a deficiency.
RegX allows institutions to move toward a third model:
Analyze → Decide → Remedy → Verify.
Termination becomes the appropriate outcome when risk cannot or will not be corrected—not the default response because the institution lacks sufficient information to make a more precise decision.
The December Hemp Changes Are a Warning of a Much Larger Problem
Hemp makes the problem particularly visible, but it is not unique to hemp.
Modern commerce moves faster than traditional underwriting.
Merchants change products continuously. State legislatures change requirements. Federal agencies change enforcement priorities. New compounds enter the market. Products cross categories. Marketing language evolves.
Yet much of acquiring compliance still relies on snapshots.
An institution underwrites a merchant at onboarding, periodically reviews the account and reacts when monitoring, complaints, regulatory developments or other signals indicate that something may have changed.
That architecture was built for a slower marketplace.
Today’s acquiring institutions increasingly need continuous merchant intelligence.
The question is no longer simply:
Was this merchant compliant when we boarded it?
The question is:
Is this merchant compliant today—and can we identify exactly what changed when the answer becomes no?
Protecting the BIN Without Destroying the Volume
Risk teams and revenue teams should not have opposing objectives.
Both ultimately need the same thing:
the ability to distinguish acceptable commerce from unacceptable commerce with sufficient confidence to act.
Without that visibility, institutions are forced to manage uncertainty by reducing exposure.
With it, they can manage the underlying risk.
That distinction becomes increasingly valuable as regulated and emerging industries grow.
If only a fraction of a multi-billion-dollar portfolio requires remediation, terminating the entire portfolio is not sophisticated risk management.
It is the consequence of insufficient information.
The Future of Acquiring Compliance Is Precision
The next generation of payments compliance will not be built around reviewing more spreadsheets or hiring enough analysts to manually inspect the internet.
The scale of digital commerce has already made that model obsolete.
Artificial intelligence gives acquiring institutions the ability to evaluate merchant activity at machine scale while preserving human governance over consequential risk decisions.
That is the model RegX.ai is building.
Not AI replacing the compliance department.
AI giving the compliance department visibility it could never achieve manually.
When regulations change, institutions should not have to choose between accepting unknown exposure and terminating an entire portfolio.
They should be able to identify the affected merchants.
Identify the affected products.
Understand the rule.
Determine the exposure.
Request remediation.
Verify the correction.
And terminate only when termination is actually warranted.
Analyze. Decide. Remedy.
Because the future of acquiring isn’t about eliminating every complicated merchant.
It’s about finally having the technology to understand them.
About RegX.ai
RegX.ai is an AI-powered merchant compliance and risk intelligence platform designed for acquiring banks, processors, ISOs and payment institutions operating in complex and rapidly changing industries.
RegX transforms merchant monitoring from periodic, manual review into scalable product-level intelligence—helping institutions identify regulatory and policy exposure, prioritize risk, manage remediation and preserve legitimate processing volume.
This article is provided for informational purposes only and does not constitute legal, regulatory or compliance advice. Financial institutions should evaluate applicable federal and state law, card-network requirements and their own risk policies with qualified legal and compliance professionals.

