FATF Details DeFi Regulation for AML/CFT Compliance
XDC
+0.40%
LINK
+3.50%
UST
-0.30%
TEL
-6.70%
The Financial Action Task Force (FATF) has released its first DeFi-specific report, and the message is clear. Calling your protocol “decentralized” will not exempt it from regulatory oversight. The global AML/CFT standard-setter just closed a loophole that many protocols have relied on for years.

Why This Report Matters Now

The 49-page report tackles long-standing regulatory challenges in DeFi. While the FATF acknowledges genuine benefits like automated settlement and round-the-clock availability, it’s also naming the elephant in the room: illicit actors love DeFi’s opacity. According to the 2026 Crypto Crime Report, illicit flows into DeFi protocols rose 343% year over year.

The Control Test That Changes Everything

At the heart of this framework sits the “control or sufficient influence” (COSI) test. This is what determines whether a protocol falls under existing AML/CFT obligations, and it’s a smart piece of regulatory design. Rather than getting distracted by marketing language, FATF built a framework that looks at actual power structures.

Protocols now fall into three buckets:

  • Centralized protocols, treated as VASPs and fully in scope
  • Centralized protocols with unidentified controllers, also in scope
  • Truly decentralized protocols, technically outside direct scope but still required to mitigate risk

Blockchain analytics tools become essential here, since applying the COSI test requires actually tracing who holds power over a protocol.

What Signals Real Control

The FATF didn’t leave this vague. To measure control, regulators look at concrete signals both on-chain and off.

On-chain indicators include governance concentration (when a handful of wallets hold most tokens), administrative privileges like private keys that can upgrade smart contracts, and fee or treasury flows that show who’s capturing economic value.

Off-chain indicators matter just as much. Who controls the front-end interface? Who owns the development repository? Who’s making public statements on behalf of the protocol? These factors cut through self-proclaimed decentralization and reveal who’s actually calling the shots.

Most Jurisdictions Are Behind

Here’s where the gap becomes obvious. The FATF’s 7th Targeted Update found that 93% of jurisdictions haven’t even identified which DeFi protocols would qualify under this framework. Only four have imposed licensing requirements. Just one has taken actual enforcement action.

That’s a massive enforcement gap, and it means most regulators are still catching up to a market that’s been operating without much scrutiny.

The FATF wants jurisdictions to move fast on three fronts:

  • Conduct DeFi-specific risk assessments
  • Deploy blockchain analytics for ongoing supervision, including transaction tracing and wallet clustering
  • Increase oversight of front-end providers and oracle operators

The Hard Questions Nobody’s Answered Yet

This framework is functional and technology-neutral, which is smart design. But real implementation raises questions that don’t have clean answers.

What happens to immutable protocols where control mechanisms simply can’t be added after deployment? How do regulators coordinate when a single protocol’s components are scattered across multiple jurisdictions? And what happens when a protocol progressively decentralizes over time, moving from in-scope to out-of-scope as it matures?

There’s also a real risk that some jurisdictions will misclassify protocols as centralized based on minor, superficial control elements. The framework demands careful weighing of evidence, not mechanical checkbox application.

The FATF is also pushing for cybersecurity measures to run alongside AML/CFT controls, recognizing that in DeFi, these two concerns increasingly overlap. Making this work in practice will require sustained collaboration between regulators, protocol teams, and analytics firms.

Our Take

What makes this FATF report different from prior crypto regulation attempts is its focus on actual power structures rather than marketing labels. We’ve watched regulators struggle for years to define “decentralized” in a way that holds up to scrutiny. The COSI test finally gives them a workable tool, but the 93% compliance gap tells you everything about how far behind most jurisdictions actually are. Expect enforcement actions to accelerate over the next 12 to 18 months as regulators build out the analytics infrastructure this framework demands.

Follow Hashlytics on Bluesky, Facebook, LinkedIn, Telegram and X to Get Instant Updates

Disclaimer: Content displayed above are for informational purposes only and do not constitute financial, investment, or trading advice.