a16z Crypto paper argues financial institutions can use permissionless blockchains within existing compliance rules

a16z Crypto paper argues financial institutions can use permissionless blockchains within existing compliance rules

N
News Editor
2026-09-11 04:07:07
A new paper highlighted by a16z Crypto argues that financial institutions do not need to rely on permissioned blockchains to satisfy anti-money laundering, counter-terrorist financing, and sanctions obligations. Written by Rebecca, chief operating officer and chief legal officer at Jito Labs, the piece says current law already allows banks, broker-dealers, and asset managers to build products on permissionless networks as long as controls are applied where institutions actually have control. The article points to recent examples of institutional adoption, including Franklin Templeton’s use of permissionless chains for its on-chain U.S. government money fund share records since 2021, BlackRock’s tokenized money market fund shares on Ethereum from March 2024, and Apollo’s tokenized access to its Diversified Credit Fund across six permissionless networks from January 2025. It also cites public positions from FinCEN, OFAC, and the Office of the Comptroller of the Currency, arguing that enforcement is based on risk management and system design rather than an impossible zero-risk standard. The paper also addresses two practical objections: whether institutions must identify every validator, and whether public ledgers can protect trading privacy. It says neutral protocol-level transmission should be treated more like internet or phone infrastructure, and that tools such as confidential transfers, audit keys, address rotation, account abstraction, and zero-knowledge-based systems are starting to make privacy-preserving compliance workable on public chains.

a16z Crypto says financial institutions can build products and conduct transactions on permissionless blockchain networks without falling outside existing financial compliance rules, pushing back on the idea that only permissioned systems can support regulated activity.

The article was written by Rebecca, chief operating officer and chief legal officer at Jito Labs, and compiled in Chinese by ChainCatcher. It cites a new paper titled Compatibility of Permissionless Networks and Financial Compliance: A Practical Guide for Financial Institutions. The paper’s central argument is that current financial compliance law already has room for permissionless infrastructure, and that firms should place controls at points they actually control rather than treating compliance as a requirement to control the underlying network itself.

Institutional blockchain use is already expanding

The piece says many financial institutions are already using permissionless networks. Franklin Templeton began using permissionless blockchains in 2021 to record share information for its on-chain U.S. government money fund and added Solana as a supported network in February 2025. BlackRock started issuing tokenized money market fund shares on Ethereum in March 2024. Apollo, in January 2025, began offering tokenized investment access to its Diversified Credit Fund across six permissionless networks.

According to the article, announcements of traditional financial institutions deploying products on permissionless networks now appear almost every week.

Even so, some institutions still view permissionless networks as effectively unusable. Many banks, broker-dealers, and asset managers have instead been moving toward permissioned networks, where a gatekeeper or consortium decides who can validate transactions, who can use or join the network, and what the network may be used for.

The author says that choice often rests on a mistaken premise: that compliance demands a closed set of known and vetted participants. In that view, only a network with identified participants can satisfy legal obligations under the Bank Secrecy Act, anti-money laundering and counter-terrorist financing rules, and U.S. sanctions law. Put bluntly, the article says many compliance teams have treated permissionless networks as incompatible with the Bank Secrecy Act and sanctions rules.

The paper’s main claim: law requires reasonable controls, not the elimination of all risk

The article argues that, from a regulatory standpoint or any other, financial institutions are not required to own the infrastructure they use. Nor do they need to screen, inspect, or restrict the infrastructure that carries their transactions and related communications. It says regulators have already recognized that firms may adapt their compliance systems to the technical reality of permissionless networks.

On the question of whether permissionless networks can meet compliance requirements, the paper’s answer is yes. The article says the Bank Secrecy Act and sanctions rules require institutions to apply reasonable controls and reduce risk, but they do not require firms to eliminate all risk. That standard, it says, would be impossible to meet.

Under the Bank Secrecy Act, AML and CFT programs are meant to identify, record, and deter illicit finance. They are not designed to completely stop money laundering or terrorist financing, and cannot do so in practice.

U.S. federal banking regulators and the Financial Crimes Enforcement Network, or FinCEN, have already said that the key is a “reasonably designed” AML program that includes “processes to identify, measure, monitor, and control risks effectively.” The article adds that FinCEN’s August 2020 enforcement statement made clear that BSA enforcement is not about punishing firms for isolated mistakes.

It also points to a U.S. Treasury report on de-risking, which directly addressed institutional concern about penalties. Banks often fear that any weakness in internal controls could lead to massive fines. Regulators, the author says, have indicated that such penalties are not common and usually arise when an AML and CFT system has broadly broken down, not when a risk-based approach shows occasional localized shortcomings.

How the article frames sanctions compliance

The same logic, the article says, applies to sanctions. The Office of Foreign Assets Control, or OFAC, lays out five core elements of an effective sanctions compliance program in its Framework for Compliance Commitments:

  • management commitment
  • risk assessment
  • internal controls
  • testing and auditing
  • training

The article says OFAC adjusts expectations based on an institution’s size, product mix, customer base, and business geography. Its Economic Sanctions Enforcement Guidelines also weigh factors such as intent, knowledge, harm to sanctions targets, and whether a compliance program was adequate when evaluating suspected violations.

That enforcement structure and historical practice support a risk-balancing approach rather than a zero-tolerance one, according to the author. In this reading, FinCEN and OFAC focus on systemic deficiencies that an institution could reasonably identify, not on rare, isolated errors.

The article ties that directly to permissionless networks. AML, CFT, and sanctions rules call for controls matched to identified risks, it says, and those controls can be implemented on permissionless infrastructure. Indirect or unintentional contact should not automatically mean a financial institution has taken on the same compliance risk as if it had actively chosen the other party.

Do institutions need to identify and screen every validator?

The article says financial institutions should treat permissionless networks as infrastructure, much as they already treat the public internet and telephone networks.

Those systems are shared environments. Financial institutions do not know, and do not screen, every other user or operator on them. The author says the same basic compliance framing should apply to permissionless blockchains.

Current caution, the piece says, is driven largely by fears of accidental contact with sanctioned actors or illicit parties. Institutions may worry about paying network fees to a validator run by a sanctioned party, transacting unknowingly with a sanctioned actor, or receiving or trading crypto assets that had some historical contact with illicit parties.

The article argues that unintended contact with a validator or another network participant in a sanctioned jurisdiction is not the conduct sanctions law is designed to regulate. Geography is only part of the concern. A validator may be a sanctioned person operating anywhere, but the institution has not selected that validator, signed a contract with it, exported goods or services to it, financed it, or otherwise chosen to transact with it.

Network fees reach validators because the protocol applies the same rules to all users. The article says regulators have already acknowledged this point.

As an example, it cites the Office of the Comptroller of the Currency’s Interpretive Letter 1186, issued in November 2025, which confirmed that banks may pay network fees on blockchain networks and may hold the crypto assets needed to pay those fees in their own name. The piece says this followed OCC Interpretive Letter 1174 from January 2021, which concluded that banks may validate, store, and record payment transactions by running nodes. If banks may run nodes and participate in transaction recording, the article says, then receiving node-generated network fees follows naturally from that logic.

The OCC letters used Ethereum as an example. Ethereum is a permissionless network where validators are selected by the protocol on a pseudorandom basis. The article notes that those interpretive letters did not distinguish between permissioned and permissionless networks.

It then walks through how transaction handling works on a permissionless chain. When a financial institution submits a transaction, the protocol assigns block proposal rights for the block containing that transaction to a validator, usually through a pseudorandom process weighted by stake. The protocol also determines fees based on network demand and the computational resources used by the transaction. As a result, the institution cannot choose the validator that processes its transaction, cannot negotiate the fee with that validator, and often cannot know before or after the fact which validator handled the transaction.

Every network user is subject to the same rules. The article compares that relationship to an email sender and the router operators that carry the message, or to a phone caller and the switch operators that complete the connection.

It adds that if a U.S. financial institution sends internet protocol packets through infrastructure located in a sanctioned jurisdiction, that alone does not make the transmission a sanctions violation. The article says the same “neutral, protocol-driven transmission” analysis can be applied to the consensus layer of a permissionless blockchain.

The Bank Secrecy Act, it says, recognizes this distinction as well. The statute’s regulatory definitions exclude parties that “only provide delivery, communication, or network access services used by a money transmission service to support money transmission services.” In other words, the article says, the BSA distinguishes neutral transmission from the transaction itself, and sanctions analysis similarly turns on whether there was active selection, instruction, or transactional dealing between the parties.

For that reason, the author argues that while institutions transacting on permissionless networks may have some contact with unscreened network operators, that contact is not the same as the conduct sanctions law is aimed at. In that latter case, neither side has actively chosen the other.

The article also points to enforcement history. Nearly five years have passed since OFAC published its Sanctions Compliance Guidance for the Virtual Currency Industry, it says, and in that period there has been no enforcement action based on the fact that a validator proposed a block that happened to include a sanctioned party’s transaction. Nor has there been any enforcement action based on market participants paying protocol-level network fees.

Can public ledgers preserve privacy and still satisfy compliance?

A second institutional concern is privacy: whether banks can transact on public ledgers without exposing customer positions, counterparties, and trading strategies to competitors.

The article says one early case for permissionless ledgers was that full transparency itself could be a compliance asset. But it argues that compliance requirements are narrower than that. What matters is whether necessary information can be verified by the institution, its counterparty, and regulators or supervisors.

It says modern cryptography is now advanced enough to let institutions prove facts relevant to compliance without publicly disclosing all of the underlying data. An institution, for example, can prove that a counterparty is not on the Specially Designated Nationals, or SDN, list, or prove that reserves exceed liabilities, without revealing ledger contents or counterparty identities.

Proofs of provenance can allow a party to show that an asset never came from a particular identified pool of illicit assets, without publishing the full transaction graph. Confidential transfer systems can encrypt amounts and balances on a ledger while preserving a viewing key that can be given to examiners during an inspection.

Taken together, the article says, these tools can give regulators stronger verification than a closed system while disclosing nothing to competitors. In that framing, privacy is no longer a barrier to permissionless networks and could become a reason institutions choose them.

Some of these tools are already in use, while others remain in development. Address rotation and account abstraction have entered real-world use. Omnibus accounts and tiered custody structures can also keep customer-level details off-ledger. At the same time, messaging protocols can transmit Travel Rule data alongside on-chain transfers.

Confidential transfer systems with audit keys have started to be deployed, though their institutional use remains limited so far. Systems that prove an entity is not sanctioned, as well as systems that prove asset provenance against specific lists, are still in pilot or research stages.

The article gives one existing example: Privacy Cash, a privacy protocol deployed on Ethereum and Solana that uses zero-knowledge proofs to support confidential transfers and swaps.

A nine-part framework and the GENIUS Act

On implementation, the author says the paper proposes a financial compliance framework for permissionless network activity made up of nine components.

Transaction-layer controls are aimed mainly at an institution’s customers and counterparties, and take forms broadly similar to the controls already in use today. Network-layer controls are directed at the underlying infrastructure itself.

The article stresses that the framework does not require institutions to identify validators, sign service-level agreements with a protocol, or apply to a gatekeeper for network membership. Those are described as common features of permissioned systems, not requirements imposed by existing financial compliance law.

It also says the framework aligns with the recently passed U.S. GENIUS Act. The act follows a similar logic, according to the article: AML, CFT, and sanctions controls should sit at the application layer and be carried out by entities that know the customer and can control the assets.

Under the article’s description, the law requires authorized issuers of payment stablecoins, as identified and regulated application-layer entities, to demonstrate that they have AML and sanctions compliance programs in place and the technical ability to freeze or burn circulating stablecoins when presented with a lawful order. Those obligations fall on the stablecoin issuer, not on the permissionless network where the stablecoin circulates.

The article’s closing argument

The piece ends with a historical comparison. Decades ago, regulated financial institutions were confronted with another open, global, permissionless network that anyone could join and that carried communications for both lawful and unlawful users. They eventually built businesses on open internet protocols and placed controls at the application layer.

The author says permissionless blockchain networks can be approached in the same way. Avoiding them is not a compliance strategy. In the author’s view, it means stepping away from the role U.S. financial institutions have long played in improving the resilience of the dollar-based financial system, increasing information visibility, and strengthening risk management.

Dollar-denominated activity is already taking place on permissionless networks and will continue whether U.S. financial institutions participate or not, the article says. Effective U.S. financial enforcement depends on regulators being able to see those flows, and the design, execution, and enforcement of compliance law also depend on financial institutions observing and monitoring that activity.

Its final warning is that if firms stay away from permissionless networks because they misread the law or remain anchored to older regulatory views, they may give up the chance to offer customers more products and services through open networks.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.