[Paper Review] Is it true that "it cannot be regulated because it is decentralized"? Decoding the FATF DeFi Report
◆This Report◆
"Targeted Report on Regulatory Challenges from Decentralised Finance (DeFi)" (Financial Action Task Force, July 21, 2026)
Overview: A report that organizes the risks of money laundering, terrorist financing, and proliferation financing associated with DeFi, clarifies the scope of existing FATF standards, identifies factors for determining controllers or those with significant influence, and summarizes the responses required of national authorities and private sector entities.
In DeFi, there are no bank tellers or exchange representatives. What moves on the other side of the screen is code placed on a blockchain. However, if someone holds the key to rewrite that code, sets the fees, and operates the app that users interact with, can that financial service truly be called "nobody's"?
In July 2026, the FATF published a report summarizing the regulatory treatment of DeFi. The report does not follow the name "DeFi." It tracks the code, keys, funds, voting rights, and the human authority remaining behind the website. Although it is a document on financial crime countermeasures, as you read through it, you realize that the ambiguity of what "decentralization" refers to is at the heart of the problem.
Furano sees in this the problem of control that company law and financial regulation have long dealt with. What Phrona is concerned about is who will fix the broken system and respond to the victims after control has been erased. First, we will trace the arguments in the report and then consider the fork in the road for DeFi that lies ahead.
The name "Decentralized"
Phrona: When I look at a DeFi screen, it feels like a shop without any clerks. When you operate it, the code runs, and the exchange or borrowing is completed. It doesn't feel like anyone is vetting me.
Furano: That feeling is not wrong. The FATF also recognizes automation, 24/7 operation, cross-border use, and traceability via public ledgers as advantages of DeFi. However, not seeing a clerk and not having a manager are two different things.
Phrona: There might be someone holding the key to the back door.
Furano: Exactly. The FATF distinguishes between the DeFi protocol, which is just the code on the blockchain, and the "DeFi arrangement," which includes the developers, legal entities, DAOs, front-ends, and fund managers surrounding it. Regulators look at the latter.
Phrona: So, just looking at the code means you might misjudge the nature of the financial service.
Furano: For example, even if transactions are public, the owner of the wallet is unknown. Even if the code is public, attackers can also read that code. The convenience of being able to connect multiple protocols also becomes a convenience for criminals to complicate their fund trails.
Phrona: The same features work as freedom for users and as a lack of time for investigators. If funds are moved to another chain in a few minutes, you cannot wait for a response to an inquiry.
Furano: That is what the FATF is dealing with. Fraud, ransomware, money laundering after hacking, professional money laundering networks, and proliferation financing. It does not label DeFi as the cause of crime. It is investigating the conditions that allow criminal funds to be moved quickly, split across multiple services, and have their connection to real people obscured.
Phrona: Then, this report is not a new DeFi ban.
Furano: It is neither a law nor a new comprehensive standard. It is a practical document for applying Recommendation 15, which was expanded to virtual assets in 2019, and the 2021 guidance, to the current DeFi landscape. Rather than flashy new rules, it is about who to apply existing rules to. It is proceeding with that dull and troublesome work.
Key Points
The FATF acknowledges the automation and openness of DeFi, but does not believe that the function of financial intermediation has disappeared because of it. If a person or entity provides exchange, transfer, custody, or lending services to others and effectively operates them, they may bear existing obligations as a Virtual Asset Service Provider (VASP).
The distinction between a protocol and an arrangement exists for that reason. If you look beyond just the smart contract to the deployer, the change keys, the price information, and the user interface, the location of authority becomes apparent. What the FATF is looking for are the people and organizations that make financial functions possible around the code.
Because transaction history can be tracked on a public ledger, it is sometimes easier to investigate than cash. However, there is no information linking addresses to individuals, and funds move across multiple services at high speed. There is a distance between being able to see and being able to stop.
The work of finding control
Furano: The central term the FATF uses is "control or sufficient influence." For a company, you would investigate the president, directors, and major shareholders, right? In DeFi, instead of job titles, you pick up the authorities one by one.
Phrona: Who holds the stop button. Who changes the fees. Those kinds of details, right?
Furano: Upgrade keys, emergency stop rights, changes to collateral ratios or liquidation conditions, oracle selection, and treasury movement. We also look at who holds the governance tokens and whose proposals are passing in actual votes. Websites, APIs, development roadmaps, and brand management are clues on the off-chain side.
Phrona: Even if voting rights are split among 10,000 wallets, it is hard to call it decentralized if the same person holds them. If voter turnout is low, decisions can be made by a small group of regulars.
Furano: That is why we do not set a single numerical standard. It is a bit ambiguous. But that ambiguity is also there to prevent people from creating loopholes like 'it is safe if you split the tokens below X percent'.
Phrona: Instead, judgments will likely vary by country. One country might see the same developer as just a software provider, while another might see them as the de facto operator.
Furano: The report broadly divides DeFi into three categories: those where a controller can be identified; those that effectively have a controller but cannot be identified due to anonymity or other reasons; and those where there is truly no one with significant authority. FATF standards apply to the first two.
Phrona: The second one is strange. It is not that there is no person in charge, but that they cannot be found. It is closer to a state where the destination for responsibility has vanished, rather than freedom.
Furano: Moreover, countries have barely found those destinations. According to the report's survey, 132 jurisdictions, or about 93%, have not yet implemented FATF standards for the DeFi in question. Out of 142 responding jurisdictions, only two had actually registered or licensed DeFi.
Phrona: It does not seem to be because all DeFi is perfectly decentralized.
Furano: The FATF diagnosis is the same. It is not a regulatory loophole, but a lack of investigative and analytical power by the authorities. If you find a controller, you require identity verification and the reporting of suspicious transactions. If they cannot be found, or if they truly do not exist, you mitigate risk at connection points like exchanges, banks, stablecoin issuers, and front-ends. This is the report's answer.
Phrona: Even if you cannot stop the code, you can narrow the paths for people to enter. The landscape has started to look a little different.
Key Points
What to note about the three-category classification is the difference between the second and third types. If there are management keys or concentrated voting rights but the holder cannot be identified, it does not mean the regulatory target has disappeared, but rather that enforcement is difficult. In the third type, there is no person or legal entity capable of fulfilling the obligations. Authorities also investigate the off-chain side, such as development companies, foundations, user interfaces, domains, and data providers. However, managing a website does not make one the controller of the entire protocol. Front-ends can be targeted as independent intermediary services. Responsibility differs by layer. Truly decentralized protocols are not left alone either. Regulated financial institutions and VASPs are made to investigate the risk level of their connection points and, if necessary, require additional identity verification. If the asset has a freeze function held by the issuer, it may be stopped from the outside. What cannot be regulated directly is supplemented by intervention from the periphery.
Eliminating, splitting, and layering authority
Phrona: Does DeFi with truly no controller actually exist in reality? If you try to find a perfect example, it seems like people will remain somewhere.
Furano: It is dangerous to say it is perfect. However, if you line up three examples with different ways of placing authority, the problem becomes easier to understand. They are Liquity, THORChain, and Uniswap.
Phrona: Liquity was a mechanism for borrowing stablecoins using crypto assets as collateral, right?
Furano: There is a development company called Liquity AG. However, the V2 core contracts are immutable and cannot be upgraded. Governance is limited to allocating rewards for liquidity, and the company does not even operate the central official front-end. It is not that the creators have disappeared, but they have carved out a wide area that even the creators cannot move later.
Phrona: Rather than distributing authority to everyone, they are reducing the amount of authority from the start.
Furano: THORChain is different. It is a network that exchanges crypto assets across different blockchains, and it explains that it is not a mechanism controlled by a central company or DAO. But it is not immutable. If developers propose new software and more than two-thirds of the nodes adopt it, the change becomes effective.
Phrona: One person cannot change it, but a collective can. Can that collective be called a controller under the law? This suddenly becomes difficult.
Furano: And then there is Uniswap. The core trading contracts have immutable parts. UNI holder governance can move protocol fees and the treasury. Uniswap Labs provides the main web app and wallet. Code, joint governance, and corporate services are layered on top of each other.
Phrona: Even though it looks like a single name to the user, different people are operating in different scopes within it.
Furano: That is why asking "Is Uniswap decentralized?" is too crude. Which contracts can be changed, by whom, and within what scope? Which entry points are managed by whom? The FATF framework breaks the habit of viewing DeFi as a single box.
Phrona: Rather than ranking decentralization, it seems more useful to map out authority. Calling it a map might be a bit too neat, but at least it is more credible than a self-introduction that says "it is decentralized."
Point Commentary
Liquity V2 official documentation states that governance handles the allocation of protocol liquidity incentives and does not have the authority to change core contracts. Liquity AG also does not operate a central frontend. This is an example of consciously minimizing human discretion regarding core financial functions. However, this does not mean that the oracles providing prices or external user interfaces have become unmanned.
THORChain's official FAQ explains that there is no central governing body or DAO, and changes become effective when more than two-thirds of nodes adopt a new version. This mechanism cannot be definitively classified as FATF's third category. This is because it requires a fact-by-fact evaluation of how much power the continuously coordinating groups or developers have, even if individual nodes do not have sufficient influence.
Uniswap's protocol documentation states that core contracts are immutable, while UNI governance decides on fee activation and treasury spending. Uniswap Labs' terms of service clearly distinguish between the company's web app and wallet, and the underlying protocol. It is a good example of how different types of authority are separated within a single brand.
Power concentrated at the entry point
Furano: Even if you order identity verification for a protocol without a ruler, there is no one to implement it. So, regulators head to the entry point.
Phrona: Exchanges, banks, wallets, and stablecoin issuers. The places that everyday users touch.
Furano: Yes. Even if the protocol keeps running, if exchanges refuse deposits, major apps restrict access, and issuers freeze assets, it becomes difficult for many people to use. Tech-savvy users can bypass this with other interfaces or direct operations, but large-scale financial services need easy entry points.
Phrona: The fact that it cannot be stopped and the fact that it is easy to use are becoming separated.
Furano: Moreover, to manage decentralized finance, surveillance and judgment are concentrated in a small number of central companies. Which transactions to reject, which protocols to judge as high-risk. That authority is not light.
Phrona: Finance created to get out of banks meets banks and large corporations again at the entry point. It feels less like returning, and more like the gates themselves have become more important than before.
Furano: It is a rational choice for regulators. They have no choice but to use parties that can execute orders. However, from the user's perspective, a situation is created where even if the code is neutral, access is not.
Phrona: That difference is usually invisible. While the app is running, users treat the protocol and the entry point as the same thing. They only realize they were separate on the day it is closed.
Furano: Therefore, DeFi regulation does not end with legal issues regarding protocols. It also becomes a matter of competition policy concerning who holds commercial access. If the entry points are concentrated in a few companies, those few companies effectively determine the scope of available finance.
Phrona: If you only count the decentralization of code, you overlook the centralization occurring on the side of daily life.
Key Points
Connection point regulation is a long-standing method for networks that cannot be directly regulated. By controlling the points that funds and users must pass through, the scale of usage can be suppressed without deleting the underlying protocol. The FATF asks financial institutions and VASPs to investigate the control relationships, identity verification mechanisms, sanctions compliance, and asset freezing capabilities of the DeFi services they connect to. This includes the decision to avoid connections if obligations cannot be met.
The effects are not uniform. General users and institutional investors are strongly influenced by regulated entry points because they require audited interfaces, fiat currency exchange, custody, and accounting processes. Users who can call contracts directly from self-custody wallets can easily bypass them. What regulation shrinks is not the existence of the code, but the scope of what can be used safely within society.
This method has the side effect of power concentration. Stablecoin issuers and major exchanges become not only windows for executing orders from courts and regulatory authorities but also gatekeepers that preemptively judge risk. If we are to evaluate the decentralization of DeFi, we must count not only the number of on-chain nodes but also how many companies control the entry points for users.
The Price of Being Fixable
Phrona: If developers don't want to be subject to regulation, they will make it so that even they cannot change it. It seems likely that people will start thinking that way.
Furano: They will. However, immutable design did not start as a countermeasure to the FATF. There have always been reasons for it: censorship resistance, not needing to trust an operator, and reducing governance attacks. It is better to think of regulation as merely making that choice slightly more advantageous.
Phrona: But if you give up authority, you can't fix it even if there is a bug.
Furano: Emergency stops, adjustments to collateral conditions, and compensation for victims all become difficult. The ability for humans to intervene is evidence of control, but it is also the ability to repair.
Phrona: It's the room for someone to say "I'll take responsibility" after an accident. If only the code remains, there is no one to apologize to or consult with.
Furano: Law generally assumes a party that can receive orders, change behavior, and explain the results. DeFi can split those three things among different people, or in the end, leave them with no one.
Phrona: Eliminating control does not necessarily lead to freedom. You also lose someone you can rely on when you are in trouble.
Furano: I think this is the core of what we should be thinking about beyond the FATF report. The more you build it to be accountable, the easier it is for regulators to find that person. The more you build it to be unfindable, the harder it is for users to seek relief.
Phrona: It doesn't seem like a problem that ends by choosing one or the other. Can't we separate the parts that absolutely must not be changed, like the foundation of a house, from the parts that can be moved in an emergency?
Furano: That is where the design competition lies. Time-delayed changes, emergency authority held by multiple entities, governance with limited scope of authority. We need to stop thinking of control as zero or one hundred and instead work out what authority is for, who gets it, and under what conditions.
Phrona: In the end, it might be a matter of deciding the width of the door through which humans can return, rather than completely driving them out. Even if regulators from the outside also come through that door.
Key Points
The powers cited by the FATF as evidence of control include upgrades, stops, parameter changes, and fund transfers. From the developer's perspective, these are also necessary tools for safety management. Therefore, regulatability and recoverability overlap to a large extent. The person regulators can order is also the person who can save users in the event of an accident.
There is no simple optimal solution here. However, saying "both are important" is the same as deciding nothing. It is necessary to specify the scope of immutability and the scope where human judgment remains for each use case. The weight of permissible immutability differs between small-amount exchanges and loans that hold life savings. If emergency authority is to be retained, the holders, activation conditions, time limits, and post-event explanations should be made public. If authority is to be eliminated, users should be informed that neither repairs nor compensation will be possible.
The causal link that regulation encourages the minimization of governance is hard to say has been proven yet. Even so, as long as having the power to change is a clue to legal responsibility, it will be a factor in a developer's decision-making. Regulation that ignores this incentive might not increase the number of people it wants to make comply, but rather decrease the number of people who can receive orders.
DeFi Diverging
Furano: It is unlikely that DeFi will move in a single direction from here on. Regulated on-chain finance will increase. This will take the form of using smart contracts and automated trading while clarifying operating companies, identity verification, audits, and legal responsibilities.
Phrona: Using DeFi technology, but requiring permission for use. That is the part that is getting closer to banks.
Furano: On the other side, protocols that protect immutable contracts, self-custody wallets, and permissionless use will remain. Even if they are difficult to connect to mainstream financial institutions, they may hold value as hard-to-stop payments or as a final escape route.
Phrona: It seems like it will be quite broad in the meantime. On top of a core contract that anyone can use, we can place an entry point for institutions that have completed identity verification. We can create different screens for each region. It's like having multiple piers on the same river.
Furano: In reality, there will likely be many of these hybrid types. It is better to use the FATF classification to examine the differences between layers rather than to stick a single label on the entire project.
Phrona: In that case, the answer to the question "Has DeFi succeeded?" will also be divided.
Furano: Automated market makers, tokenization, on-chain collateral, and programmable payments will likely enter regulated finance widely. As a technology, it is a success. However, it is not guaranteed that finance that anyone can use without permission and that is difficult for companies or nations to stop will become the mainstream.
Phrona: The more widely a technology is used, the more the reason for seeking that technology in the first place may fade. Only the convenience is carried forward first.
Furano: Even so, I don't think permissionless protocols will disappear. Even if they are not mainstream, there is meaning in the very existence of options outside the mainstream. The problem is the entry point to get there and the preparedness for when you encounter an accident in that place.
Phrona: What the FATF asked was who is in control. Thinking that far, I want to ask back. When we choose finance that is controlled by no one, are we also accepting the possibility that we will be rescued by no one?
Key Points
The future of DeFi cannot be captured by a binary of regulated versus unregulated. It is closer to reality to think that on-chain finance that clarifies the operating entity and performs identity verification, permissionless protocols that minimize governance authority as much as possible, and hybrid types that combine public cores with regulated entry points will coexist.
The FATF report did not create this divergence anew. As of 2021, the FATF had already published the idea of applying existing standards to those who have control or sufficient influence. What the 2026 report added are specific work procedures for examining keys, tokens, oracles, funds, user interfaces, and development structures. If countries incorporate these procedures into their domestic laws and supervision, the divergence that existed before will likely accelerate.
The spread of DeFi technology and the spread of the institutional philosophy of permissionlessness must be measured separately. A future where the former permeates banks and securities markets while the latter remains in complementary areas is entirely possible. At that time, DeFi will not have disappeared. It will have unraveled into multiple forms of finance while separating uses and users.
This article was first published on the Projeteam, Inc. website.
FATF'sDeFiReport: The Destination of Regulation—People and Organizations Remaining Outside the Code
This is a reconstruction of the above in a dialogue format. The original article delves deeper into the logic of the FATF report and the issues of responsibility inherent in DeFi governance from an institutional perspective. You may find the discussion more three-dimensional if you read it as well.
Seung-Cheol Xu's Magazine
この記事は noteマネー にピックアップされました

