The Financial Action Task Force (FATF) has finally issued its first dedicated report on decentralized finance (DeFi), offering a clear, functional framework for how global anti-money laundering (AML) rules should apply. Instead of banning DeFi or treating all protocols the same, the FATF focuses on a simple question: who actually controls or influences the protocol?
Why the FATF issued a DeFi-specific report

DeFi protocols promise automated, 24/7 financial services without traditional intermediaries, but their varied governance models have made it hard for regulators to know when existing AML/CFT obligations apply. The FATF’s 49-page Targeted Report on Regulatory Challenges from Decentralised Finance (published July 21, 2026) acknowledges DeFi’s benefits while warning that the same features attract illicit actors. On-chain data shows illicit flows into DeFi rose 343% year-on-year, making risk mitigation essential for safe growth
The core idea: a functional, “control or sufficient influence” test

The report’s centerpiece is the “control or sufficient influence” (COSI) test. This determines whether a DeFi arrangement falls within the FATF Standards and should be treated like a Virtual Asset Service Provider (VASP). The approach is technology-neutral: having smart contracts or open-source code does not automatically exempt a protocol from regulation.
Three categories of DeFi under the FATF framework

The FATF places protocols on a spectrum and defines three categories:
- Centralized DeFi: Identifiable persons or entities exercise clear control or sufficient influence. These are in scope and should comply with VASP-level AML/CFT obligations.
- Centralized with unidentified controllers: The protocol is controlled, but the controllers are hidden. These are also in scope, and supervisors should work with authorities and analytics firms to identify who is behind them.
- Truly decentralized: No person or entity exercises control or sufficient influence. These fall outside the FATF Standards, though they still require risk-based mitigation by supervisors and counterparties.
How regulators decide who is in control

To apply the COSI test, the FATF lists concrete on-chain and off-chain indicators.
On-chain indicators include:
- Governance concentration: A small set of wallets holding enough tokens to direct financial operations, with attention to wallet clustering and voting behavior.
- Administrative privileges: Private keys that can upgrade contracts, change parameters, pause the protocol, or override controls
- Fee and treasury flows: Who receives protocol fees, controls treasury funds, or directs economic value.
Off-chain indicators include:
- Control over front-end interfaces, development repositories, and public communications about the ability to modify the protocol.
The report stresses that security features like kill switches or pause mechanisms are encouraged and should not, by themselves, trigger classification as centralized. The key question is whether control is material to the provision of financial services.
What this means for jurisdictions and supervisors

So far, most countries have not identified qualifying DeFi protocols in their territory, and very few have imposed licensing or taken enforcement action. The FATF urges faster progress with specific steps:
- Conduct DeFi-specific risk assessments that consider cross-border activity and governance complexity.
- Use continuous blockchain analytics (transaction tracing, wallet clustering, network analysis) to identify controllers and monitor high-risk protocols.
- Collaborate with blockchain analytics providers to uncover hidden controllers.
- Strengthen oversight of front-end providers and oracle operators, including automated screening and geo-blocking.
- Encourage smart-contract audits alongside embedded controls and ongoing monitoring.
Implications for financial institutions and stablecoin issuers

Banks, crypto exchanges, and other regulated entities should take a risk-based approach when dealing with DeFi. They must evaluate counterparties’ governance, AML/CFT controls, and cybersecurity posture, applying enhanced due diligence for higher-risk exposures such as bridges or mixers.
Stablecoin issuers have a distinct role because stablecoins are the primary collateral in DeFi and now account for 84% of illicit transaction volume. The FATF expects freeze and burn capabilities as a baseline, and warns that criminal networks are issuing “freeze-resistant” stablecoins to evade controls.
Guidance for DeFi protocols and builders
Where a protocol lands on the COSI test determines its obligations.
- If centralized (or with hidden controllers): The protocol must meet VASP-level requirements, including licensing, customer due diligence, transaction monitoring, sanctions compliance, and Travel Rule compliance where applicable. The FATF also recommends embedding automated freezing, on-chain risk scoring, and transaction blocking into the protocol.
- If truly decentralized: The protocol is out of scope, but supervisors will still monitor it, and regulated touchpoints must apply due diligence. Protocols can gain a competitive edge by voluntarily adopting screening, monitoring, and governance controls, as institutional capital is already flowing toward safer designs.
Implementation challenges and the road ahead
The framework is functional and proportionate, but practical questions remain. Jurisdictions must avoid mechanically labeling any protocol with minor centralized features as fully centralized. Other open issues include how to treat immutable protocols, how to assess real-world influence when on-chain voting is misleading, and how to allocate regulatory responsibility across borders.
Progressive decentralization is another gray area: many projects start centralized and gradually hand over control. The report does not define the exact transition point but makes clear that strong security and risk controls are always good practice.
Bottom line for the crypto ecosystem

The FATF’s DeFi report moves the conversation from “is DeFi regulated?” to “who is responsible, and how do we supervise them?” By focusing on control and influence, the framework aims to protect the financial system without stifling innovation. For builders, the message is straightforward: if you have control, you have compliance obligations; if you don’t, you still benefit from designing in safety and transparency from day one.

