Law, Regulation & Liability · 2026-07-28

Targeted Report on Regulatory Challenges from Decentralised Finance

Financial Action Task Force (FATF)Original paperMarkdown source
decentralisationregulatory frameworksaccountabilityauthorityrisk assessmentgovernance-by-design
Key Insight

FATF reframes DeFi regulation around observable control rather than claims of decentralisation, but its fallback for systems without an identifiable controller shifts enforcement toward adjacent intermediaries without defining the legitimacy, evidence standards, or redress required for that indirect control regime.

Review

The FATF report treats decentralisation as a claim to be tested against the actual distribution of decision rights. Its central move is to separate decentralised software from the wider DeFi arrangement that maintains, upgrades, presents, funds, and profits from it. Recommendation 15 applies where a person exercises control or sufficient influence, even when smart contracts execute transactions automatically and the project markets itself as decentralised. This moves the regulatory inquiry away from labels and legal form toward the authority to change parameters, direct treasury assets, control interfaces, select oracles, manage upgrade keys, concentrate voting power, determine development priorities, or receive material economic benefits.

That control-centred analysis is the report's main institutional contribution. It recognises that governance is distributed across layers rather than located in a single corporate operator. Protocol maintainers, foundations, token delegates, multisignature signers, front-end operators, investors, oracle providers, and infrastructure administrators may each hold a different part of the system's effective authority. The report therefore makes it harder to use a DAO transition, dispersed token ownership, pseudonymous wallets, or automated execution as a formal escape from regulatory responsibility. Decentralisation becomes an evidentiary question about who can cause, prevent, reverse, or profit from consequential system changes.

The report also documents an implementation failure. Of 142 responding jurisdictions, only 26 had assessed DeFi risks, 132 had not identified a qualifying arrangement in their territory, four had established licensing or registration requirements, and two had licensed or registered an arrangement in practice. These figures indicate that the principal gap is not the absence of a global standard. It is the limited capacity of states to discover systems, attribute control, establish jurisdiction, and intervene at the speed of cross-chain transactions. A functional regulatory perimeter is therefore dependent on technical intelligence, institutional coordination, and evidence-sharing capabilities that many jurisdictions do not possess.

The methodology combines the 2026 FATF survey, prior guidance, jurisdictional examples, enforcement cases, market research, and private-sector intelligence. This supports supervisory guidance and typologies, but does not evaluate which interventions reduce illicit finance. The report offers no comparative baseline, outcome measure, counterfactual, or threshold for determining when a control indicator becomes sufficient for legal attribution. Its practices are operationally suggestive rather than empirically validated.

The category of "truly decentralised" arrangements exposes the report's unresolved governance problem. FATF accepts that systems with no identifiable controller fall outside direct application of its standards, then recommends alternative measures through stablecoin issuers, VASPs, front ends, financial institutions, analytics providers, identity systems, allow-lists, block-lists, and embedded transaction controls. This does not remove governance. It relocates it to actors adjacent to the protocol. These actors gain the capacity to classify addresses, deny access, freeze assets, restrict transactions, and determine which credentials are acceptable, often across borders and through proprietary risk models.

The report does not specify the legitimacy conditions for this indirect enforcement architecture. It does not define evidentiary thresholds for wallet attribution, acceptable false-positive rates, notice requirements, contestation procedures, correction of analytics errors, liability for wrongful blocking, or cross-jurisdictional appeal. Blockchain analytics is treated as an investigative capability while its probabilistic inferences and vendor dependencies remain underexamined. Proof-of-KYC and identity-linked attestations are presented as compliance mechanisms without an equivalent treatment of issuer competence, credential revocation, selective exclusion, data minimisation, or the consequences of turning access credentials into programmable financial permissions.

A second gap concerns the boundary between influence and responsibility. Branding, roadmap control, fee flows, interface operation, and delegated voting are listed as indicators, but the report does not establish how they should be weighted, combined, or separated by function. Treating every influential actor as a potential controller can prevent accountability evasion, but can also create overlapping obligations with unclear scope and encourage defensive withdrawal by open-source contributors and infrastructure providers.

The report should be developed into a testable control-attribution framework. Jurisdictions need a function-by-function decision model that records the authority exercised, evidence relied upon, duration and revocability of that authority, economic benefit, capacity to mitigate harm, and legal nexus. Control determinations should be versioned because governance rights, keys, token concentration, and operational dependencies change over time. Supervisory decisions should distinguish discovery evidence from adjudicative evidence and provide notice, challenge, correction, and appeal mechanisms for persons and addresses affected by indirect controls.

FATF has established that DeFi is not beyond governance merely because execution is decentralised. The next step is to govern the governance process itself. Without common attribution thresholds, auditability of analytics, constraints on delegated enforcement, and remedies for wrongful intervention, a control-based approach may replace the fiction of protocol neutrality with an opaque network of public and private gatekeepers. The report makes responsibility more locatable, but the resulting authority is not yet accountable.

Key Insight

FATF reframes DeFi regulation around observable control rather than claims of decentralisation, but its fallback for systems without an identifiable controller shifts enforcement toward adjacent intermediaries without defining the legitimacy, evidence standards, or redress required for that indirect control regime.

Appears in these collections

Continue exploring

Related reviews

More in Law, Regulation & Liability
Law, Regulation & Liability · 2026-05-04

AI Agents Under EU Law: A Compliance Architecture for AI Providers

arXiv working paper

The paper’s decisive analytical move is to relocate AI agent compliance from model classification to action inventory: what the agent can touch, change, disclose, delegate, or trigger is the real regulatory map. Its unresolved weakness is that it treats provider compliance architecture as the main control surface while leaving legitimacy, redress, and affected-party power underdeveloped.

Law, Regulation & Liability · 2026-03-26

Legal Frictions for Data Openness: Reflections from a Case-Study on Re-use of the Open Web for AI Training

HAL / CNRS / Open Knowledge Foundation

The report’s deepest contribution is to show that openness without enforceable constraints is not neutral openness at all, but a governance vacuum in which shared informational resources are converted into proprietary advantage by actors with the scale to extract without reciprocating.