New FATF guidelines for DeFi: control over the protocol and AML obligations
In July 2026, the FATF published a report on the regulatory challenges associated with DeFi. The document is not binding, but it sets out the direction for national supervisory authorities regarding DeFi projects, crypto-asset service providers and banks working with this sector.
When is a DeFi project subject to AML/CFT obligations under the FATF?
The FATF report settles the debate over the meaning of ‘decentralisation’. If any entity exercises control over or exerts sufficient influence on a protocol, the project is subject to Recommendation 15 and AML/CFT obligations – regardless of its stated operating model or marketing messaging.

The FATF divides the DeFi market into three groups:
- centralised DeFi projects with identifiable controlling entities,
- centralised DeFi projects with entities exercising control that cannot be identified,
- truly decentralised DeFi projects.
The FATF standards cover the first two groups. Countries should require such entities to register or obtain a licence to ensure compliance with Recommendation 15. Truly decentralised platforms remain outside the scope of these standards.
A FATF study on the implementation of Recommendation 15, published in parallel, shows that the implementation of these rules by countries to date has been very limited in practice: 132 out of 142 jurisdictions surveyed have not yet identified any regulated DeFi solutions within their territory; only four have introduced a licensing or registration requirement for such entities; and a mere two have actually granted a licence to or registered a DeFi solution.
The report also introduces a list of indicators to assess the actual level of control over a project. This covers both on-chain elements (including update keys, the ability to change parameters, control over oracles, the flow of fees and profits, and the concentration of governance tokens), as well as off-chain elements (including front-end development, multisig keys, a company employing developers, influence over the roadmap, and branding).
Who are the new FATF guidelines for DeFi aimed at?
The report is primarily relevant to:
- creators, developers, foundations and companies developing DeFi protocols,
- front-end operators providing access to protocols,
- holders of governance tokens and signatories of multisig wallets,
- oracle and off-chain infrastructure providers,
- VASPs (virtual asset service providers),
- banks and stablecoin issuers.
It is worth noting that the DeFi market is highly concentrated – according to FATF data, the 12 largest protocols account for over 60 % of the global total value locked (TVL), and the 20 largest protocols account for over 70 % of total DeFi liquidity, which should influence the prioritisation of supervisory measures targeting the largest entities.
The report also highlights the scale of the threats: in April 2026 alone, two cyber-attacks on DeFi platforms (Drift Protocol and KelpDAO), attributed to groups linked to North Korea, caused combined losses exceeding 570 million USD, which accounted for approximately 76 % of annual losses resulting from hacking incidents involving virtual assets.

How can a DeFi project be prepared for the new FATF guidelines and AML obligations?
- Map out the actual scope of control over the project, including administrative keys, multisig wallets, permissions to change parameters, the token ownership structure and voting delegations.
- Describe the decision-making structure in documentation prepared for the authorities and designate a point of contact for law enforcement agencies and the financial intelligence unit.
- Verify the obligation to obtain a licence or registration – for companies in their country of incorporation, and for individuals in the place where they conduct their business.
- Implement AML mechanisms in smart contracts or interfaces, such as blocking sanctioned addresses, risk scoring and KYC verification prior to performing high-risk functions.
- Assess product risk in accordance with Recommendation 15 and analyse the protocol in accordance with Recommendation 10 and the correspondence record in accordance with Recommendation 13, if you are acting as a financial institution or a VASP.
- Regularly audit smart contracts and monitor suspicious transaction patterns.
Would you like to check whether the way your DeFi project is organised and managed could give rise to AML/CFT obligations under the new FATF guidelines? Contact our team – we can help you assess your project’s operating model, identify regulatory risks and prepare the appropriate AML procedures and documentation.