Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

Howey Test

← Back to Glossary
By NHI Mgmt Group Updated August 26, 2026 Domain: Governance, Ownership & Risk

The Howey Test is a legal standard used to decide whether a transaction qualifies as an investment contract and therefore falls under securities regulation. It examines whether money is invested in a common enterprise with an expectation of profit derived from the efforts of others, which is central to many token offering reviews.

Expanded Definition

The Howey Test is a U.S. legal standard used to determine whether a transaction is an investment contract and therefore subject to securities law. In practice, it asks whether there is an investment of money in a common enterprise with a reasonable expectation of profit derived primarily from the efforts of others. That structure is especially important in token and digital asset reviews, where the legal character of an arrangement depends on substance, not branding.

For NHI and agentic AI governance, the relevance is indirect but real: teams building tokenized access models, profit-sharing automations, or AI-mediated financial workflows often need to understand whether the mechanism they are designing resembles a security offering. Definitions vary across vendors and advisory commentary, but the core legal inquiry remains anchored to the original Howey Test framework. NHI Management Group treats this as a governance boundary issue, not a product naming issue. The most common misapplication is assuming a token, app credit, or reward point is automatically outside securities analysis, which occurs when the economic reality still promises profits from the efforts of a central operator.

Examples and Use Cases

Implementing Howey-sensitive designs rigorously often introduces legal and product constraints, requiring organisations to weigh distribution speed and monetisation flexibility against securities risk and disclosure overhead.

  • A startup issues a token that funds platform development and advertises future appreciation based on the team’s roadmap, triggering a Howey-style review before launch.
  • A community project sells fractional interests in a revenue-generating digital asset, which may create a common enterprise even if the offering is framed as utility access.
  • An AI platform routes customer funds into an automated strategy and promises returns managed by the operator, making the “efforts of others” prong central to legal analysis.
  • Governance teams compare token issuance language against Ultimate Guide to NHIs because controlled keys, wallets, and automation can concentrate operational authority in ways that affect compliance posture.
  • Risk reviewers use NIST Cybersecurity Framework 2.0 to separate security controls from legal classification, ensuring technical safeguards do not masquerade as regulatory clearance.

Use cases are often context dependent, and the same digital mechanism may be treated differently depending on marketing, governance, and beneficiary expectations.

Why It Matters in NHI Security

The Howey Test matters in NHI security because automation, custody, and delegated control can blur the line between operational tooling and regulated financial activity. When identities, wallets, signing keys, or agent permissions are used to manage value-bearing transactions, the organisation inherits both security risk and legal exposure. Misunderstanding that boundary can lead to misfiled offerings, weak approvals, or a false sense that technical controls alone resolve regulatory obligations.

This is where NHI governance becomes consequential: the same service account or agent that can mint, transfer, or rebalance assets may also create evidence of centralised managerial effort. In that sense, the test is less about technology labels and more about control, expectation, and profit attribution. NHI Management Group’s research shows that 79% of organisations have experienced secrets leaks, with 77% of those incidents causing tangible damage, and 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, underscoring how quickly operational mistakes become business events. Organisations typically encounter the compliance and security fallout only after a launch, audit inquiry, or enforcement action, at which point the Howey Test becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01Clarifies business context and legal obligations that shape digital asset governance.
NIST AI RMFGOVERN 1.2Requires governance of AI-enabled systems whose outputs may affect financial or legal outcomes.
NIST Zero Trust (SP 800-207)JEALimits implicit trust in agents that move value on behalf of an operator.
OWASP Agentic AI Top 10A10Agentic systems can overreach into regulated actions when prompts and tools are unconstrained.
OWASP Non-Human Identity Top 10NHI-01Non-human identities controlling wallets or contracts require governance over privilege and misuse.

Review tool access, prompts, and approvals before agents execute transactions with value implications.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org