Many financial institutions are taking advantage of one of the most innovative advancements in blockchain technology — permissionless networks.
Franklin Templeton has kept the official share register of its onchain U.S. government money fund on permissionless blockchains since 2021 and added the Solana network in February 2025. BlackRock has issued shares of its tokenized money market fund on Ethereum since March 2024. And in January 2025, Apollo made tokenized access to its Diversified Credit Fund available across six permissionless networks. Additional announcements touting traditional financial institutions’ deployment of products on permissionless networks continue on a near-weekly basis.
Yet, some TradFi institutions still treat permissionless networks as somehow unavailable. Instead, many banks, broker-dealers, and asset managers have been trending toward permissioned networks — systems in which a gatekeeper or consortium decides who may validate transactions, who may use or participate in the network, and for what purpose. These institutions are currently choosing permissioned networks because they believe — wrongly — they must. The premise underlying that choice is that a known, verified set of actors is a precondition to compliance with financial integrity laws: the Bank Secrecy Act (BSA), with its anti-money laundering (AML) and countering the financing of terrorism (CFT) requirements; and U.S. sanctions laws.
To put it simply, institutional compliance departments think permissionless networks are irreconcilable with the BSA and sanctions laws.
Our new paper, “The Compatibility of Permissionless Networks and Financial Integrity: A Practical Guide for Financial Institutions,” explains that financial institutions can build and transact on permissionless blockchain networks. Concerns about financial integrity laws should not deter such usage and today can be addressed under existing law. Institutions can satisfy their obligations through appropriate, risk-based compliance frameworks that place controls at the layer the institutions operate.
There is no precondition — regulatory or otherwise — for financial institutions to own, screen, or censor the underlying infrastructure over which their financial transactions, and the communications about them, travel. In fact, regulators explicitly have recognized that financial institutions can adapt their financial integrity compliance programs to technological innovations like permissionlessness.
The BSA and sanctions laws require financial institutions to have reasonable control over risks, and put controls in place to mitigate such risks. They do not require the total elimination of risk — an impossible threshold.
Under the BSA, financial institutions’ AML/CFT programs must focus on detection, documentation, and deterrence of illicit financial activity. These programs are not intended to prevent money laundering or terrorist financing wholesale, nor can they. The federal banking regulators and FinCEN have explicitly stated that the key to financial integrity is a “reasonably designed” AML program that includes “effective processes to identify, measure, monitor and control risks.”
FinCEN stated the point more plainly in its August 2020 Statement on Enforcement, describing its approach to BSA enforcement as something other than a “gotcha” game. Treasury’s report on de-risking addressed the underlying fear directly, observing that while banks believe any failure in banking controls exposes them to substantial fines, the regulators note that such fines are rare and follow the collapse of an entire AML/CFT program, rather than the limited shortcomings a risk-based approach will sometimes produce.
The sanctions regime works on similar logic. OFAC’s Framework for Compliance Commitments identifies five essential components of an effective risk-based sanctions compliance program:
OFAC scales its expectations on implementation to an institution’s size, products, customers, and geography.
The Economic Sanctions Enforcement Guidelines weigh willfulness, awareness of the conduct, harm to sanctions objectives and the adequacy of the compliance program when the agency decides how to address an apparent violation.
The agencies’ respective enforcement regimes and history support the “risk-balanced-not-zero-tolerance” approach. FinCEN and OFAC focus enforcement efforts on reasonably knowable, systemic deficiencies rather than isolated slips. This posture bears directly on the inadvertent-violation concern institutions raise about permissionless networks.
Both AML/CFT and sanctions regimes ask for control proportionate to identified risk, which institutions can achieve on a permissionless network. Any attenuated or inadvertent violations of those regimes should not create risk for financial institutions.
Financial institutions should understand the use of permissionless networks as akin to the use of infrastructure, much as they already treat the public internet and the telephone network. Both of these are shared systems whose other users and operators they neither know nor screen. They should calibrate their compliance approach accordingly.
Instead, financial institutions’ hesitation to engage with permissionless networks focuses on potential inadvertent or unknowing interactions with sanctioned or illicit actors — for example, paying network fees to a validator operated by a sanctioned actor, unknowingly transacting with a sanctioned actor, or receiving or transacting with cryptoassets that may have touched illicit actors at some point in their history.
But inadvertent, unknowing interactions with validators or other network participants in a sanctioned jurisdiction are not the kind of activity the sanctions laws were written to address. The concern is broader than geography, since a validator could be a designated person operating from anywhere: The institution has not selected, contracted with, exported to, financed, or otherwise dealt with the operator, and the fee reaches it through rules that apply identically to every user of the network.
Regulators have confirmed this. For example, in November 2025, the OCC addressed this concern by issuing Interpretive Letter 1186, confirming that a bank may pay network fees on blockchain networks and may hold as principal the crypto-assets needed to pay them. The letter reasons from Interpretive Letter 1174 of January 2021, in which the OCC concluded that a bank may validate, store, and record payment transactions by serving as a node. Accepting the fee paid to a node follows from that conclusion. The letter uses the example of the Ethereum blockchain, a permissionless network whose protocol selects validators pseudo-randomly. None of the letters in this line distinguishes permissioned networks from permissionless ones.
When an institution submits a transaction via a permissionless network, the protocol assigns the right to propose the block that will include that transaction to a unique validator, generally pseudo-randomly and in proportion to stake. Protocol-defined rules set the fee as a function of network demand and the computational resources the transaction consumes. As a result, an institution does not choose the validator that will process its transaction. It cannot bargain over the fee, and it has no way to learn who the validator is before or after the transaction. Every other user of the network transacts under identical rules.
This bears some resemblance, as mentioned above, to the relationship between an email sender and the owners of the routers that carry the message, or between a caller and the owners of the switches that complete the call. A U.S. financial institution whose internet protocol packets traverse infrastructure in a sanctioned jurisdiction is not considered to violate sanctions on that basis: The same analysis of neutral, protocol-mediated carriage applies to a permissionless network’s consensus layer. That distinction is codified in the BSA’s own regulatory definition, which expressly excludes those who “merely provide the delivery, communication, or network access services used by a money transmitter to support money transmission services.” The BSA also distinguishes neutral carriage from transacting, and the sanctions analysis turns on the same feature of the relationship, the absence of selection, direction or dealing.
Although an institution transacting on a permissionless network does have some contact with operators it has not screened, that contact is different from what sanctions laws police: In the latter case, no party involved selected any other. To put this in perspective, in the nearly five years since OFAC published its Sanctions Compliance Guidance for the Virtual Currency Industry, no enforcement action has been predicated on a validator having proposed a block that happened to contain a sanctioned party’s transaction, and none has rested on a market participant’s payment of protocol-level fees.
The second concern institutions raise is privacy: Can a bank transact on a public ledger without exposing client positions, counterparties, and strategies to its competitors?
The early case for permissionless ledgers rested on total transparency as a compliance asset. Financial integrity requires something narrower: that the necessary information be verifiable by the institution, its counterparty, and its regulator or supervisor. Cryptography has advanced far enough that an institution can prove a compliance-relevant proposition without publishing the data that establishes it: that a counterparty sits outside the Specially Designated Nationals (SDN) List, for instance, or that reserves exceed liabilities, with the book and the counterparty’s identity remaining undisclosed. Proofs of provenance permit a party to show that an asset never came from an identified illicit set without exposing its transaction graph. Confidential-transfer designs encrypt amounts and balances on the ledger while retaining a viewing key an institution can furnish to an examiner.
Together, these cryptographic advances give a supervisor better assurance than a closed system provides. And it does so while giving a competitor nothing at all, which turns privacy from an objection into a reason to build on permissionless networks.
Some of these techniques are in production today; some are still in the research and development phase. Address rotation and account abstraction are in production, as are omnibus and tiered custody structures that keep client-level detail off the ledger and the messaging protocols that carry Travel Rule data alongside an onchain transfer. While confidential transfers with an auditor key are shipping, they are currently thinly used at institutional scale. Proofs of unsanctioned status and provenance proofs against a designated set remain in pilot testing and research. Yet solutions do exist: Privacy Cash, for example, is a privacy protocol that sits on top of Ethereum and Solana and uses zero-knowledge proofs to enable confidential transfers and swaps.
We set out nine components of a financial integrity program adapted to permissionless-network activity: Transaction-level controls that apply to the institution’s customers and counterparties in largely the same form they take today, and network-level controls address the infrastructure itself.
These controls do not require identification of validators, service-level agreements with a protocol, or petitions to a gatekeeper for membership, among other features of permissioned networks: The current financial integrity laws do not require any of this.
| # | Component | Layer |
|---|---|---|
| 1 | Governance and documented risk assessment | Both |
| 2 | Customer-layer KYC (CIP, CDD, EDD) | Transaction |
| 3 | Wallet and counterparty screening | Transaction |
| 4 | Transaction monitoring and reporting adapted to onchain data | Transaction |
| 5 | Travel Rule and Funds Transfer Rule compliance | Transaction |
| 6 | Sanctions controls proportionate to what the institution controls | Transaction |
| 7 | Third-party risk management for node, staking, and analytics vendors | Network |
| 8 | Wallet/key management and cybersecurity | Both |
| 9 | Testing, audit, training, and converged expertise | Both |
The proposed framework is also consistent with recent U.S. legislation, the GENIUS Act. GENIUS likewise adopts a framework where AML/CFT and sanctions controls sit at the application layer, operated by entities with knowledge of customers and control over assets. GENIUS requires permitted payment stablecoin issuers, as identifiable regulated entities at the application layer, to certify the existence of AML programs and sanctions compliance programs, and to maintain the technical capability to execute lawful orders to freeze or burn outstanding stablecoins. These obligations run to the issuer, not to the permissionless networks on which stablecoins circulate.
***
A generation ago, regulated financial institutions confronted an open, global, permissionless network that anyone could join and that carried the traffic of legitimate and illegitimate users alike. Institutions moved their businesses onto the open protocols of the internet and built their controls at the application layer. The same can be done now for permissionless networks.
Avoiding permissionless networks is not a financial integrity strategy; it is an abdication of the role that U.S. institutions have always played in making the dollar-based financial system resilient, data-enriched, and risk-based. And dollar-denominated activity on permissionless networks is already happening and will continue,whether or not U.S. institutions take part. The reach of U.S. financial enforcement rests on line of sight into financial flows, and the architecture behind the financial integrity laws — their implementation and enforcement — depends on U.S. institutions observing the activity they are asked to monitor. To not participate in the innovation and benefits borne by permissionless networks — based on a misinterpretation of relevant laws or concerns based on past regulators’ positions — unnecessarily limits the choices that traditional financial institutions make in serving the needs of their customers.
***
Rebecca Rettig is the Chief Operating Officer and Chief Legal Officer of Jito Labs, a technology startup that develops Solana blockchain software and infrastructure.
***
This article is adapted from The Compatibility of Permissionless Networks and Financial Integrity: A Practical Guide for Financial Institutions, by Rebecca Rettig, Omid Malekan, and Michael Mosier.
***
The views expressed here are those of the individual AH Capital Management, L.L.C. (“a16z”) personnel quoted and are not the views of a16z or its affiliates. Certain information contained in here has been obtained from third-party sources, including from portfolio companies of funds managed by a16z. While taken from sources believed to be reliable, a16z has not independently verified such information and makes no representations about the current or enduring accuracy of the information or its appropriateness for a given situation. In addition, this content may include third-party advertisements; a16z has not reviewed such advertisements and does not endorse any advertising content contained therein.
This content is provided for informational purposes only, and should not be relied upon as legal, business, investment, or tax advice. You should consult your own advisers as to those matters. References to any securities or digital assets are for illustrative purposes only, and do not constitute an investment recommendation or offer to provide investment advisory services. Furthermore, this content is not directed at nor intended for use by any investors or prospective investors, and may not under any circumstances be relied upon when making a decision to invest in any fund managed by a16z. (An offering to invest in an a16z fund will be made only by the private placement memorandum, subscription agreement, and other relevant documentation of any such fund and should be read in their entirety.) Any investments or portfolio companies mentioned, referred to, or described are not representative of all investments in vehicles managed by a16z, and there can be no assurance that the investments will be profitable or that other investments made in the future will have similar characteristics or results. A list of investments made by funds managed by Andreessen Horowitz (excluding investments for which the issuer has not provided permission for a16z to disclose publicly as well as unannounced investments in publicly traded digital assets) is available at https://a16z.com/investments/.
Charts and graphs provided within are for informational purposes solely and should not be relied upon when making any investment decision. Past performance is not indicative of future results. The content speaks only as of the date indicated. Any projections, estimates, forecasts, targets, prospects, and/or opinions expressed in these materials are subject to change without notice and may differ or be contrary to opinions expressed by others. Please see https://a16z.com/disclosures for additional important information.