On Sept. 10, a16z Crypto said financial institutions can use and participate in permissionless blockchain networks under existing legal frameworks, and that compliance requirements do not mean banks, broker-dealers, and asset managers must move to permissioned chains controlled by specific institutions.
According to a16z, some traditional financial institutions currently prefer permissioned chains because of concerns about anonymous participants and validators on permissionless networks, as well as potential sanctions or illicit finance risks.
Compliance controls can sit at the application layer
a16z said the U.S. Bank Secrecy Act, or BSA, and sanctions rules call for risk-based controls, not the complete elimination of all risk. Financial institutions can deploy KYC, wallet and transaction monitoring, and sanctions screening at the application layer they actually control.
The firm compared permissionless networks to open infrastructure such as the internet and said financial institutions do not need to identify or screen every participant in the network.
OCC guidance and privacy tools were part of the case
a16z also said the Office of the Comptroller of the Currency, or OCC, had previously confirmed that banks may pay network fees on blockchain networks and hold the crypto assets needed to pay those fees.
It added that as technologies such as zero-knowledge proofs, private transactions, and proof of provenance develop, financial institutions can meet regulatory requirements without disclosing client holdings, counterparties, or trading strategies. In a16z's view, compliance and privacy are not unavoidable barriers to using permissionless blockchain networks.
Traditional finance firms are already using public chains
a16z said traditional financial institutions including Franklin Templeton, BlackRock, and Apollo have already issued or offered tokenized financial products on permissionless blockchains such as Ethereum and Solana.
The firm said financial institutions should participate in permissionless networks by building risk-based compliance systems, rather than abandoning the infrastructure because of a misreading of current law.

