Jito Labs executive argues permissionless blockchains are not off-limits for regulated finance

Jito Labs executive argues permissionless blockchains are not off-limits for regulated finance

N
News Editor
2026-09-11 08:15:11
Rebecca Rettig, chief operating officer and chief legal officer at Jito Labs, argues that regulated financial institutions do not need to confine themselves to permissioned blockchain systems in order to satisfy anti-money laundering and sanctions obligations. In a paper titled Compatibility of Permissionless Networks and Financial Integrity: A Practical Guide for Financial Institutions, she says current law is built around reasonable, risk-based controls rather than the elimination of all risk. The piece points to examples from Franklin Templeton, BlackRock and Apollo, each of which has used public blockchain infrastructure for fund-related products. Rettig’s analysis leans on the Bank Secrecy Act, FinCEN guidance, OFAC’s sanctions compliance framework and Office of the Comptroller of the Currency interpretive letters. She argues that inadvertent, indirect interaction with validators on permissionless networks is closer to using shared communications infrastructure than entering into a transaction with a chosen counterparty. The article also says privacy and compliance can coexist through cryptographic tools such as zero-knowledge proofs, provenance proofs and confidential transfers. It closes by proposing a nine-part risk framework and by linking that approach to the structure described in the recent U.S. GENIUS Act, where compliance duties sit with the issuing or customer-facing entity rather than the underlying public network.

Rebecca Rettig, chief operating officer and chief legal officer at Jito Labs, says regulated financial institutions can build and transact on permissionless blockchain networks without treating those systems as a compliance no-go zone. In her paper, Compatibility of Permissionless Networks and Financial Integrity: A Practical Guide for Financial Institutions, she argues that concerns tied to the Bank Secrecy Act, anti-money laundering and countering the financing of terrorism rules, and U.S. sanctions law should not block that use under current law.

Jito Labs executive argues permissionless blockchains are not off-limits for regulated finance 2

The article, translated by Chopper of Foresight News, says institutions can meet those obligations through an appropriate risk-based compliance framework applied at the operational level of the institution, rather than assuming they must rely on permissioned networks.

Traditional finance firms are already using permissionless networks

Rettig writes that many financial institutions are already using one of the most important advances in blockchain technology: permissionless networks.

Franklin Templeton has maintained the official share register for its on-chain U.S. government money fund on a permissionless blockchain since 2021, and connected to Solana in February 2025. BlackRock has issued shares of its tokenized money market fund on Ethereum since March 2024. In January 2025, Apollo expanded tokenized access to its diversified credit fund across six permissionless networks. According to the article, announcements involving traditional financial institutions launching products on permissionless networks now appear almost every week.

Even so, some traditional financial firms still see permissionless networks as unworkable. Many banks, broker-dealers and asset managers continue to prefer permissioned systems, where a gatekeeper or consortium decides who may validate transactions, who may use or participate in the network, and for what purpose.

Rettig argues that those institutions are making that choice because they mistakenly believe they have to. The underlying assumption, she says, is that a known and vetted set of participants is a prerequisite for complying with financial integrity laws, including the Bank Secrecy Act and its AML/CFT requirements, as well as U.S. sanctions law. In short, some compliance teams treat permissionless networks and those legal regimes as irreconcilable.

The paper’s central claim: the law requires reasonable control, not zero risk

Rettig says financial institutions do not need any regulatory or other precondition in order to own, review or control the underlying infrastructure on which their financial transactions and related information transfers depend. Regulators, she writes, have already recognized that institutions can adapt their financial integrity programs to technological changes such as permissionless networks.

The article frames the Bank Secrecy Act and sanctions laws in practical terms: institutions must maintain reasonable control over risk and implement controls that mitigate that risk. They are not required to eliminate risk entirely, which the paper describes as an impossible standard.

Under the Bank Secrecy Act, AML/CFT programs are meant to detect, record and deter illicit financial activity. They are not designed to comprehensively prevent money laundering or terrorist financing, and cannot do so. Federal banking regulators and the Financial Crimes Enforcement Network, or FinCEN, have made clear that financial integrity rests on a program that is “reasonably designed,” including “effective processes for identifying, measuring, monitoring, and controlling risk.”

The piece also cites FinCEN’s August 2020 enforcement statement, which said Bank Secrecy Act enforcement is not a “gotcha” exercise. A Treasury report on de-risking addressed a related concern directly: while banks often fear that any failure in their controls could expose them to major penalties, regulators noted that such penalties are uncommon and usually follow the collapse of an overall AML/CFT program, not limited flaws that can arise under a risk-based approach.

OFAC’s framework focuses on system weaknesses, not isolated mistakes

Rettig says sanctions compliance follows the same general logic. The Office of Foreign Assets Control, or OFAC, lays out five core components for an effective, risk-based sanctions compliance program:

  • management commitment
  • risk assessment
  • internal controls
  • testing and auditing
  • training

According to the article, OFAC calibrates its expectations based on an institution’s size, products, customers and geographic reach. Its Economic Sanctions Enforcement Guidelines weigh factors such as willfulness, the degree of knowledge, harm to sanctions targets and the adequacy of the compliance program when assessing apparent violations.

Rettig says the history and structure of enforcement support a “risk balancing rather than zero tolerance” approach. FinCEN and OFAC focus enforcement on reasonably knowable, systemic failures rather than isolated mistakes. That point is central to concerns about accidental violations on permissionless networks.

Her conclusion is that AML/CFT and sanctions frameworks require controls proportionate to identified risks, and that financial institutions can implement those controls on permissionless networks. Minor or inadvertent violations, she argues, should not in themselves create risk for financial institutions.

Inadvertent contact with sanctioned participants is not the same as a sanctions violation

The paper compares the use of permissionless networks to the use of infrastructure such as the public internet and telephone networks. Those are shared systems, and institutions neither know nor screen all other users and operators. Rettig says compliance strategy should reflect that reality.

She notes that many institutions hesitate to use permissionless networks because they fear unintentional or unknown interaction with sanctioned or illicit actors. Examples include paying network fees to validators run by sanctioned actors, transacting unknowingly with a sanctioned party, or receiving or trading crypto assets that may at some point in their history have touched illicit actors.

But the article argues that inadvertent, unknowing interactions with validators or other network participants in sanctioned jurisdictions are not the type of activity sanctions law is designed to target. The concern is broader than geography, because validators can be designated persons located anywhere. In such cases, the institution did not choose the validator, contract with it, export a product to it, provide it with funds, or otherwise engage in a negotiated transaction. Fees reach the validator through the same network rules that apply to all users.

What OCC Interpretive Letter 1186 means

Rettig points to regulatory support for that view. In November 2025, the Office of the Comptroller of the Currency issued Interpretive Letter 1186, confirming that banks may pay network fees on blockchain networks and may hold, as principal, the crypto assets needed to pay those fees.

That letter built on the reasoning in OCC Interpretive Letter 1174, issued in January 2021, where the agency concluded that banks may validate, store and record payment transactions by operating nodes. The article says receipt of fees by those nodes follows naturally from that conclusion.

Rettig highlights that the letter used Ethereum as an example, a permissionless network in which validators are selected pseudorandomly by protocol. She also notes that this line of OCC letters does not distinguish between permissioned and permissionless networks.

How validators and fees are assigned by protocol

When an institution submits a transaction through a permissionless network, the protocol assigns block proposal rights for the block containing that transaction to a single validator, usually through a pseudorandom process weighted by stake, the article says. Fee levels are set by protocol rules based on network demand and the computational resources consumed by the transaction.

That leaves institutions unable to choose the validator that processes a transaction, negotiate the fee, or know the validator’s identity before or after the transaction. Every other network user operates under the same rules.

The paper compares that relationship to a sender and the owner of the routers that carry an email, or a caller and the owner of the switch that completes a phone call. A U.S. financial institution does not violate sanctions simply because its internet protocol packets pass through infrastructure in a sanctioned jurisdiction. Rettig says the same analytical approach should apply to the consensus layer of a permissionless blockchain, which functions as neutral, protocol-mediated transmission.

She adds that the Bank Secrecy Act’s own regulatory definitions reflect that distinction. The law excludes persons that “only provide the delivery, communication, or network access services used by a money transmitter to support money transmission services.” The article says the Bank Secrecy Act separates neutral carriage from transactions, and sanctions analysis rests on the same feature of the relationship: the absence of choice, direction or negotiated dealing.

Although an institution transacting on a permissionless network does come into contact with unscreened operators, Rettig says that contact is different from the conduct sanctions law regulates because neither side chose the other. She also writes that in the nearly five years since OFAC issued its Sanctions Compliance Guidance for the Virtual Currency Industry, there has been no enforcement action based on a validator proposing a block that happened to contain a sanctioned party’s transaction, and no enforcement action based on a market participant paying protocol-level fees.

Privacy and compliance can coexist

The second major concern raised by institutions is privacy: can a bank transact on a public ledger without exposing customer positions, counterparties and strategies to competitors?

Rettig says early support for permissionless ledgers often treated full transparency as the compliance safeguard. Financial integrity, in her view, requires something narrower: the necessary information must be verifiable by the institution, its counterparties, and its regulators or supervisors.

She argues that cryptography is now advanced enough to let firms prove compliance-relevant propositions without making the underlying data public. An institution can prove, for example, that a counterparty is not on the Specially Designated Nationals list, or that reserves exceed liabilities, without disclosing the books or the identity of counterparties. Provenance proofs can show that assets never came from an identified illicit set without revealing the transaction graph. Confidential transfer designs encrypt on-ledger amounts and balances while preserving viewing keys that institutions can provide to reviewers.

Taken together, the article says, these techniques can give regulators stronger security assurances than closed systems while denying competitors usable intelligence. On that basis, Rettig argues privacy should no longer be treated as a reason not to build on permissionless networks.

What is already live and what remains in development

Some of those tools are already in production, while others remain in research and pilot stages. The article lists address rotation and account abstraction as already live, along with omnibus custody and tiered custody structures that remove customer-level details from the ledger, and messaging protocols that carry travel rule data alongside on-chain transfers.

Confidential transfer functionality using audit keys is already available, though institutional use remains limited. Non-public state proofs and provenance proofs tied to designated datasets are still in pilot testing and research.

The article gives one example: Privacy Cash, a privacy protocol built on Ethereum and Solana that uses zero-knowledge proofs for confidential transfers and swaps.

A nine-part risk framework for permissionless network activity

On implementation, Rettig proposes nine components for a financial integrity program adapted to permissionless networks. They include transaction-level controls for institutional customers and counterparties, broadly similar to what institutions already use today, together with network-level controls aimed at the infrastructure itself.

She says those controls do not require identifying validators, signing service-level agreements with protocols, or applying for membership through a gatekeeper. Those features may exist in permissioned systems, but the article says current financial integrity law does not require them.

The proposed framework is also presented as consistent with the recent U.S. GENIUS Act. According to the article, GENIUS uses a similar structure in which AML/CFT and sanctions controls sit at the application layer and are operated by entities that know the customer and control the assets.

As described in the piece, the GENIUS Act requires approved payment stablecoin issuers to show that they maintain AML and sanctions compliance programs and preserve the technical ability to carry out lawful orders to freeze or burn circulating stablecoins. Those duties fall on the issuer, not on the permissionless network over which the stablecoin circulates.

Rettig’s conclusion: avoiding permissionless networks is not a financial integrity strategy

The article closes by drawing a parallel to the open protocols of the internet. A generation ago, regulated financial institutions faced an open, global, permissionless network that anyone could join and that carried traffic from lawful and unlawful users alike. Those institutions moved business onto open internet protocols and built controls at the application layer. Rettig argues that the same approach can be used for permissionless blockchains today.

Avoiding permissionless networks is not, in her view, a financial integrity strategy. She says it amounts to ceding the role U.S. financial institutions can play in building a robust, data-rich and risk-based dollar financial system. Dollar activity on permissionless networks is already happening and will continue whether U.S. institutions participate or not.

She adds that the effectiveness of U.S. financial enforcement depends on monitoring fund flows, and that the structure of financial integrity law, including supervision and enforcement, depends on U.S. financial institutions observing the activity they are required to monitor. If traditional institutions stay away from permissionless networks because they misunderstand the law or remain concerned about past regulatory positions, the article says, they unnecessarily narrow their options for meeting customer demand.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.