The SEC is moving to take over the Consolidated Audit Trail (CAT)—the massive, $10B+ database tracking every single US equity trade. And it’s doing it right after Citadel Securities sued over the same system.
That’s not a coincidence. That’s a power play.

Context: Why Now?
CAT was born after the 2010 Flash Crash, mandated by Rule 613 under Regulation NMS. It’s supposed to give regulators a complete picture of every order, modification, cancellation, and execution across all US exchanges. In theory, it’s the ultimate tool to catch market manipulation. In practice, it’s been a decade-long nightmare of cost overruns, missed deadlines, and data security scandals.
SROs—the 17 national exchanges and FINRA—have been running it. But the SEC is now signaling it wants the keys. According to my sources, the move comes after Citadel’s lawsuit, which challenges the database’s privacy safeguards and the legal basis for its operation. The timing screams: “We’re not backing down.”
Core: The Real Battle Is About Data Sovereignty
Let’s cut through the legal jargon. The SEC’s plan to directly control CAT isn’t just about efficiency. It’s about eliminating the conflict of interest where SROs—who are also regulated entities—run the surveillance system. The SEC wants to own the data feed, not just watch it.
Based on my analysis of the regulatory framework, this shift would require a formal amendment to Rule 613, triggering the Administrative Procedure Act’s notice-and-comment process. That’s 12-18 months of legal battles. And Citadel is already armed with an APA lawsuit.

The hidden cost? If the SEC takes over, it will likely tighten data quality standards. Brokers that once got away with sloppy reporting from SROs will face direct federal enforcement. I’ve tracked compliance costs from the DeFi summer to the institutional ETF sprint—this is a step-change. Expect a 20-40% spike in RegTech spending as firms scramble to adapt.
But the real fear for market makers like Citadel isn’t just compliance. It’s intellectual property. Their algorithms—the core of their business—are encoded in the order flow data. If that data leaks or is misused, it’s game over. That’s why they’re fighting CAT with everything they’ve got.
Contrarian: The SEC’s “Sunk Cost” Trap
Here’s the angle no one’s talking about: the SEC might be pushing for direct control because it’s already poured too much into CAT to walk away. The project has a history of cost overruns—from an initial estimate of $300M annually to over $1B. It’s a classic sunk cost fallacy.
But there’s a twist: switching control to the SEC could actually kill the project. If the SEC inherits a system that’s still broken, it will face the same operational headaches—and public scrutiny. Meanwhile, the exchanges (SROs) might be the real winners here. They’d be relieved of the burden of running CAT, freeing up resources and eliminating liability.
Another blind spot: foreign brokers. CAT collects data on non-US entities trading in US markets. If the SEC takes over, it gains unprecedented “data sovereignty” over global traders. This could spark international friction—especially with EU GDPR rules. But the SEC doesn’t seem to care. They’re building a walled garden, and everyone else is outside.
Takeaway: What to Watch Next
The next 12 months will be a regulatory chess match. Watch for three signals: 1. Citadel’s lawsuit outcome—if it stalls, the SEC might bypass rulemaking with an executive order. 2. Congressional hearings on CAT funding—who pays? Brokers or taxpayers? 3. A wave of SEC enforcement actions on data quality—they’ll want to prove the new system works.
For crypto traders, this is a canary. If the SEC can seize control of a TradFi database, how long before they demand the same for blockchain? The message is clear: regulatory infrastructure is becoming a weapon.
Speed is the only currency that matters here. In the jungle of alerts, silence is gold. We rode the wave, now we read the tide.
— Matthew Thomas, chasing the green candle that never sleeps.