FATF warns 93% of countries lack DeFi regulation for centralized platforms
In brief
- FATF mandates DeFi platforms with identifiable controllers be regulated as financial businesses
- 93% of surveyed jurisdictions have not applied FATF standards to any DeFi arrangement
- Only 26 of 142 FATF members assessed DeFi risks; just 2 licensed platforms
- FATF requires AML controls built into smart contracts and user interfaces
- Non-compliant platforms face bans from operating in regulated jurisdictions
Centralization persists despite the promise
Centralized elements frequently persist in DeFi platforms through concentrated governance tokens, administrative privileges, control over upgrades, and fees flowing to insiders. The FATF report lays out on-chain and off-chain signs of control, including upgrade keys, kill switch functions, power to set fees or risk parameters, concentrated voting power, control of websites or apps, and corporate entities employing developers or holding treasuries.
Yet enforcement remains sparse. Nearly 93% of the jurisdictions that responded to a recent FATF survey have not applied the standards to any qualifying DeFi arrangement. Only 26 out of 142 FATF member jurisdictions have assessed the risks of DeFi arrangements at all. Four have licensing rules on the books, while just two have ever used them to register or license a platform.
The enforcement gap
The watchdog wants countries to close the gap by requiring, or at least encouraging, DeFi projects to build anti-money-laundering controls into smart contracts or interfaces. Where a platform refuses to cooperate, the report says, a jurisdiction can as a last resort ban it from operating in its territory.
centralized elements "frequently persist in practice," the report found, through concentrated governance tokens, administrative privileges, control over upgrades, and the fees and rewards that flow to insiders
FATF President Giles Thomson underscored the urgency. The goal is to stop criminals exploiting new technology to launder dirty money while supporting responsible financial innovation. This framing—enforcement paired with innovation support—reflects the watchdog's attempt to avoid blanket prohibition.
The timing matters. North Korea's state-linked hackers were behind two April attacks that drained more than $570 million from DeFi platforms, including the $285 million exploit of Solana perpetuals exchange Drift Protocol, pulled off in just 12 minutes, and a $292 million hack of KelpDAO. Together they made up some 76% of the year's crypto-hacking losses. The scale of these breaches underscores why regulators see DeFi's centralized governance structures as a vulnerability.
Frequently asked questions
What does FATF say about DeFi regulation?
FATF published a report stating that decentralized finance platforms with identifiable controllers should be regulated like other financial businesses. The watchdog sorts DeFi into three groups: platforms with identifiable controllers, those centralized in practice with hidden operators, and genuinely leaderless projects.
How many countries have actually applied FATF's DeFi standards?
Nearly 93% of surveyed jurisdictions have not applied FATF standards to any qualifying DeFi arrangement. Only 26 of 142 FATF member nations have assessed DeFi risks at all, and just two have ever used licensing rules to register or license a platform.
What does FATF want DeFi projects to do?
FATF wants countries to require or encourage DeFi projects to build anti-money-laundering controls into smart contracts or interfaces. If a platform refuses to cooperate, a jurisdiction can ban it from operating in its territory.
What signs of control does FATF look for in DeFi?
FATF identifies on-chain and off-chain signs of control, including upgrade keys, kill switch functions, power to set fees or risk parameters, concentrated voting power, control of websites or apps, and corporate entities employing developers or holding treasuries.


