Summary

The FATF just released its first DeFi-specific report: Acknowledging DeFi’s operational benefits, the global AML/CFT standard-setter explains how jurisdictions, supervisors, VASPs, and financial institutions can engage with DeFi responsibly, applying existing AML/CFT standards proportionately.

Putting the framework into practice: The report provides detailed guidance on how jurisdictions should evaluate each DeFi arrangement based on concrete indicators to determine whether existing AML/CFT obligations apply. Put simply: calling oneself “decentralized” is not enough to avoid oversight.

Blockchain intelligence is a key to the puzzle: On-chain tracing tools provide the insights for builders and regulators to effectively apply the FATF’s recommendations.

The FATF Weighs in on DeFiDecentralized finance (DeFi) has long posed a regulatory challenge. DeFi arrangements, also known as protocols, can offer significant operational benefits: automated settlement, programmable financial services, and round-the-clock availability. But their varied governance structures make it difficult to determine when and how existing anti-money laundering and counter-terrorist financing (AML/CFT) obligations should apply. The central question: who, if anyone, exercises enough control over an arrangement to be held responsible for compliance?DeFi’s “regulatory challenges” are the focus of a new 49-page report by the Financial Action Task Force (FATF), the global standard-setter for Anti-Money Laundering/ Combating the Financing of Terrorism AML/CFT. The FATF acknowledges in its report that institutions are eager to utilize DeFi’s benefits, and that jurisdictions should enable these interactions. But the same properties that make DeFi attractive to legitimate users also appeal to illicit actors. Our 2026 Crypto Crime Report found that illicit flows into DeFi protocols rose 343% year-on-year, making effective risk mitigation — not restriction — essential to ensuring DeFi can continue to grow safely.One big question at the center of the report is coverage. How can a jurisdiction know if a DeFi protocol should be regulated under the same rules the FATF sets for Virtual Asset Service Providers (VASPs) such as crypto exchanges and stablecoin issuers? The FATF’s answer is the “control or sufficient influence” (COSI) test. It determines whether a protocol should be within regulators’ scope.While the FATF offers a framework through which jurisdictions can consider COSI, it does not lay out a single playbook for doing so. But it does point to one essential capability: blockchain analytics. Blockchain analytics provides the on-chain intelligence that makes this framework operational — helping supervisors apply the COSI test, enabling regulated entities to engage with DeFi safely, and giving DeFi protocols the tools to embed compliance without sacrificing efficiency and innovation.Testing for control and influenceThe FATF’s framework recognises that DeFi exists on a spectrum. Rather than treating all protocols the same, it distinguishes three categories based on who, if anyone, exercises control or sufficient influence: