21 July 2026
FATF ¦ Targeted Report on Regulatory Challenges from Decentralised Finance
The new scale of DeFi risk: Why control, not labels, defines AML risk
Decentralised finance (DeFi) has moved far beyond a niche experiment. By 2026, total value locked in DeFi had risen sharply, and the sector has become increasingly attractive not only to retail users and developers, but also to institutional investors, virtual asset service providers (VASPs), and other regulated firms. That broader participation matters. The more DeFi becomes connected to mainstream finance, the more it can transmit money laundering, terrorist financing, proliferation financing, fraud, and cyber risk into the wider system.
What makes DeFi especially challenging is not just its growth, but its structure. It offers speed, global reach, automation, and open access. Those same features also make it efficient for illicit actors. Rapid cross-chain transfers, pseudonymous participation, smart contract automation, and composability across protocols allow criminal funds to be layered, fragmented, and merged with legitimate activity at a pace traditional controls struggle to match.
Why “decentralised” is not the same as unregulated
A central point is that the FATF framework is technology-neutral. It does not care whether financial activity is carried out through a website, a smart contract, a wallet app, or a conventional platform. What matters is whether a natural or legal person is providing financial services and whether that person exercises control or sufficient influence over the arrangement.
That distinction is critical in DeFi. Many arrangements present themselves as decentralised, yet still retain centralised features through governance token concentration, upgrade rights, admin keys, treasury control, front-end operation, or influence over code development and infrastructure. In practice, the label “decentralised” can mask real points of control.
The result is a regulatory blind spot. If a protocol is effectively run by identifiable persons, those persons may fall within the scope of AML/CFT obligations even if the underlying technology is automated. If no person has meaningful control, then the arrangement may fall outside the FATF perimeter – but that does not mean it is risk-free.
The core compliance question: who controls the arrangement?
The most difficult issue for supervisors is identifying control or sufficient influence. In DeFi, control can be direct or indirect, visible or obscured, formal or informal. It may sit with developers, founders, foundations, corporate entities, governance token holders, multisignature signers, oracle operators, front-end providers, or other actors who shape how the protocol works and who benefits from it.
Control can show up in many ways. A person may be able to modify smart contracts, pause or terminate a protocol, adjust fees or collateral thresholds, manage treasury assets, select oracle feeds, or determine who can participate in key functions. Economic benefit also matters. If specific people receive protocol-level fees, token emissions, or other revenue streams tied to decision-making power, that may be a strong indicator of control.
For regulators and compliance teams, this means looking beyond marketing. A protocol may claim to be decentralised while a small group still holds the levers that matter. Supervisory analysis has to focus on function, governance, and practical influence, not branding.
The typology problem: how criminals use DeFi
Illicit actors are not using DeFi in a simplistic way. They are using it as an infrastructure layer for sophisticated obfuscation. Professional laundering networks route funds through decentralised exchanges, mixers, bridges, swaps, and chain-hopping sequences to break the transaction trail. Fraudsters exploit hype and technical complexity to deceive users, while ransomware groups and hackers convert stolen assets through DeFi channels before investigators can react.
The risks are not theoretical. Governance attacks can let bad actors gain voting power, alter protocol settings, and drain funds. Oracle manipulation can distort asset pricing and trigger fraudulent liquidations. Cross-chain bridge flaws can allow large-scale theft and laundering across fragmented networks. In some cases, attackers use DeFi’s speed and automation to layer funds faster than law enforcement or AFC teams can intervene.
This is one of the most important shifts in financial crime risk today. DeFi does not just host illicit activity – it can accelerate it, automate it, and distribute it across chains and jurisdictions in a way that makes recovery harder.
The regulatory gap is still wide
Despite the pace of market development, implementation of AML/CFT standards remains uneven. Many jurisdictions have not yet fully assessed DeFi-related risks or identified qualifying arrangements within their territory. Licensing and registration requirements are still rare, and only a small number of jurisdictions have actually brought DeFi arrangements into a formal supervisory perimeter.
That creates a clear opening for regulatory arbitrage. When controls differ across borders, protocols and actors can route activity toward the weakest jurisdiction or operate across borders in ways that make enforcement difficult. The lack of a clear jurisdictional anchor, combined with pseudonymity and global accessibility, makes DeFi especially difficult to supervise under traditional models.
The practical issue is how regulators can act effectively when the technology is designed to reduce reliance on intermediaries and obscure the location of meaningful control.
What good supervision looks like
A risk-based approach is essential. Jurisdictions need to assess their exposure to DeFi based on materiality, market size, and local use patterns. They should pay particular attention to the largest and most systemically relevant protocols, rather than spreading resources too thinly across low-activity projects.
Supervisors also need stronger tools for identifying controllers. That means using blockchain analytics, open source intelligence (OSINT), governance records, transaction tracing, wallet clustering, supervisory engagement, and intelligence from financial intelligence units (FIUs) and law enforcement. It also means understanding that control can be shared across several actors and functions, rather than resting with a single obvious person.
Where control exists, licensing or registration should follow. Where controllers cannot be identified but the arrangement is still clearly centralised in practice, authorities may need to treat it as unregulated for practical purposes while applying alternative risk mitigation measures. Where an arrangement is truly decentralised, direct AML/CFT obligations may not fit – but regulated entities interacting with it still need robust controls.
The private sector cannot treat DeFi as a black box
Banks, VASPs, payment firms, and other regulated entities are increasingly touching DeFi, whether directly or through customer demand. That means their own AFC systems must adapt. A business relationship with a DeFi arrangement should trigger a risk assessment, not a default assumption that the on-chain nature of the product removes the need for due diligence.
If the arrangement is regulated and identifiable, customer due diligence (CDD) should cover the DeFi entity itself, including its AML/CFT framework. If the arrangement is not regulated, firms should assess the underlying users, the protocol’s integrity, and whether any embedded controls exist, such as KYC checks, allow-lists, block-lists, or real-time blockchain analytics.
The main point is simple: regulated firms cannot outsource their risk. If they interact with protocols that offer unrestricted access and no effective controls, they need to be prepared for higher residual risk and stronger monitoring.
Enforcement will depend on speed and coordination
DeFi-related cases move quickly. To keep up, authorities need operational coordination, not just formal memoranda. Joint task forces, rapid information sharing, blockchain analytics, cross-border intelligence, and public-private partnerships are becoming essential.
Asset freezing and recovery will usually depend on adjacent control points rather than the protocol alone. Stablecoin issuers, custodial VASPs, front-end operators, and admin-key holders can all become important intervention points. Where illicit funds are still in motion, those actors may be the only practical route to freeze, block, or disrupt movement before the assets disappear across chains or into fiat.
This is also why public-private cooperation matters so much. Blockchain analytics firms and compliant market participants often see the pattern first. If they can share that information quickly and lawfully, authorities have a better chance of tracing funds before the trail goes cold.
The future of DeFi compliance will be technical, not just legal
The emerging compliance model is increasingly embedded. Smart contract audits, protocol-level controls, identity-linked attestations, zero knowledge proof solutions, and automated sanctions screening are all becoming part of the conversation. Regulators are also looking more closely at front-end providers and oracle operators, since they shape how users access protocols and how data enters the system.
That does not mean every DeFi product should be forced into the same mould as traditional finance. It does mean that the industry’s compliance future will depend on engineering choices as much as legal ones. The protocols that want sustainable institutional adoption will need to show who controls them, what risks they manage, and how they handle illicit finance exposure.
The bottom line
DeFi is not a peripheral issue. It is a live financial crime and supervisory challenge with cross-border impact. The central lesson is that decentralisation as a slogan is not enough. Regulators, investigators, and obliged entities need to identify who actually controls a protocol, what financial services it provides, and whether the risks can be managed in practice.
Where control exists, the rules apply. Where control is hidden, supervisors need better tools to uncover it. Where no control exists, adjacent risk points still need attention. The sector’s next phase will be shaped by whether it can combine innovation with credible financial crime safeguards. Without that, DeFi will remain attractive not just to innovators and investors, but to the criminals who move fastest through the cracks.
Dive deeper
- FATF ¦ Targeted Report on Regulatory Challenges from Decentralised Finance ¦ Link