-1.70%
-2.50%
+0.40%
+3.50%
-0.30%
-6.70%
Why This Report Matters Now
The 49-page report tackles long-standing regulatory challenges in DeFi. While the FATF acknowledges genuine benefits like automated settlement and round-the-clock availability, it’s also naming the elephant in the room: illicit actors love DeFi’s opacity. According to the 2026 Crypto Crime Report, illicit flows into DeFi protocols rose 343% year over year.
The Control Test That Changes Everything
At the heart of this framework sits the “control or sufficient influence” (COSI) test. This is what determines whether a protocol falls under existing AML/CFT obligations, and it’s a smart piece of regulatory design. Rather than getting distracted by marketing language, FATF built a framework that looks at actual power structures.
Protocols now fall into three buckets:
- Centralized protocols, treated as VASPs and fully in scope
- Centralized protocols with unidentified controllers, also in scope
- Truly decentralized protocols, technically outside direct scope but still required to mitigate risk
Blockchain analytics tools become essential here, since applying the COSI test requires actually tracing who holds power over a protocol.
What Signals Real Control
The FATF didn’t leave this vague. To measure control, regulators look at concrete signals both on-chain and off.
On-chain indicators include governance concentration (when a handful of wallets hold most tokens), administrative privileges like private keys that can upgrade smart contracts, and fee or treasury flows that show who’s capturing economic value.
Off-chain indicators matter just as much. Who controls the front-end interface? Who owns the development repository? Who’s making public statements on behalf of the protocol? These factors cut through self-proclaimed decentralization and reveal who’s actually calling the shots.
Most Jurisdictions Are Behind
Here’s where the gap becomes obvious. The FATF’s 7th Targeted Update found that 93% of jurisdictions haven’t even identified which DeFi protocols would qualify under this framework. Only four have imposed licensing requirements. Just one has taken actual enforcement action.
That’s a massive enforcement gap, and it means most regulators are still catching up to a market that’s been operating without much scrutiny.
The FATF wants jurisdictions to move fast on three fronts:
- Conduct DeFi-specific risk assessments
- Deploy blockchain analytics for ongoing supervision, including transaction tracing and wallet clustering
- Increase oversight of front-end providers and oracle operators
The Hard Questions Nobody’s Answered Yet
This framework is functional and technology-neutral, which is smart design. But real implementation raises questions that don’t have clean answers.
What happens to immutable protocols where control mechanisms simply can’t be added after deployment? How do regulators coordinate when a single protocol’s components are scattered across multiple jurisdictions? And what happens when a protocol progressively decentralizes over time, moving from in-scope to out-of-scope as it matures?
There’s also a real risk that some jurisdictions will misclassify protocols as centralized based on minor, superficial control elements. The framework demands careful weighing of evidence, not mechanical checkbox application.
The FATF is also pushing for cybersecurity measures to run alongside AML/CFT controls, recognizing that in DeFi, these two concerns increasingly overlap. Making this work in practice will require sustained collaboration between regulators, protocol teams, and analytics firms.
Our Take
What makes this FATF report different from prior crypto regulation attempts is its focus on actual power structures rather than marketing labels. We’ve watched regulators struggle for years to define “decentralized” in a way that holds up to scrutiny. The COSI test finally gives them a workable tool, but the 93% compliance gap tells you everything about how far behind most jurisdictions actually are. Expect enforcement actions to accelerate over the next 12 to 18 months as regulators build out the analytics infrastructure this framework demands.
Follow Hashlytics on Bluesky, Facebook, LinkedIn, Telegram and X to Get Instant Updates



