This is the US regulatory playbook unfortunately. Unlike in Europe and elsewhere, where regulators really try to be clear about what is and isn't ok, in the US the regulators seem to try to be as vague as possible and then just take action occasionally.
As such in new areas it does act to stifle innovation because people who are risk averse have to wait until someone else does something, the regulator enforces, it goes to court and the court decides.
When I worked at a fintech I actually was in a meeting with the OCC[1] and a prospective bank client we talked them through our plans and they said "when you get big enough you'll need to register with us and we'll have some requirements for you". We said we wanted to start that process right away and so asked for the requirements so we could start baking them into our software and they literally said "We'll call you when we think you're big enough. Until then we'll call you if we think you're in violation". They wouldn't tell us what the regulations were or how to proactively avoid breach.
This is entirely unlike other jurisdictions where you can generally find all the regulations on the regulator's website and in some cases (eg Singapore) the regulator will actively work with you on developing new regulation if they think what you're doing is innovative and valuable.
For example, here is the German crypto asset regulation. It's incredibly straightforward and easy to find. There is no grey area about what the regulator does and does not consider a security, what you can and cannot do and what existing national and EU regulation they consider to be included. [2]
[1] I should say this was not crypto related but this is a playbook that US financial regulators seem to adopt broadly
[2] https://www.dechert.com/content/dam/dechert%20files/knowledg... or https://www.nortonrosefulbright.com/en/knowledge/publication...