Summary
FATF's July 22 report argues that most DeFi has identifiable or de facto controllers and should fall under licensing and supervision, extending AML/CFT expectations beyond centralized VASPs to DeFi control points (frontends, funders, governance actors). Non-binding but able to drive jurisdictional rulemaking and grey-list pressure.
Key Points
- FATF report (July 22): effective decision-making authority remains concentrated across much of DeFi; controllers should be licensed/supervised like other financial operators.
- Test: whether identifiable persons/entities retain influence — founders, developers, front-end operators, treasury signers, governance actors with ongoing control.
- Holding governance tokens alone may not remove accountability if a party can still direct how the service functions.
- Extends to "hidden" operators — nominally decentralized but functionally centralized.
- Substance-over-label: a project's "decentralized" branding will not by itself keep it outside AML rules.
- Only 26 of 142 jurisdictions surveyed have assessed DeFi-related risks.
- FATF guidance is non-binding but persistent shortcomings can weigh on a jurisdiction's standing and contribute to grey-list placement.
- Likely regulatory chokepoints: front ends, funders, token governance participants.
- VASP classification brings AML supervision, customer due diligence, reporting, sanctions screening.
- Banks/exchanges may limit exposure to platforms failing due diligence — liquidity/access risk for non-compliant DeFi.
- Opportunities: clearer compliance pathways could support institutional adoption of compliant DeFi infrastructure.