h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Regulation & Policy

FATF Guidance in 2026: The Crypto Enforcement Gap Explained

FATF's 2026 update shows crypto anti-money-laundering rules are almost universal on paper. The problem: most countries with the rules have never enforced them.

In July 2026 the Financial Action Task Force published its seventh targeted update on virtual assets, and the headline number read like progress: 83 percent of surveyed jurisdictions now have crypto Travel Rule legislation in force, up from 73 percent a year earlier. Read one line further and the story flips. Of the 91 jurisdictions that have those laws on the books, 55 of them, roughly six in ten, have never taken a single supervisory or enforcement action to check that anyone is following them.

That gap, between rules written and rules enforced, is the actual state of crypto anti-money-laundering in 2026. FATF does not run exchanges, freeze wallets, or prosecute launderers. It writes standards and grades countries on how faithfully they copy them into national law and then apply them. The copying is nearly finished. The applying has barely started. This explainer covers what FATF guidance actually requires, why the enforcement gap matters more than the adoption rate, and what all of it means whether you hold Bitcoin (changing hands near $63,000 as this published, in the middle of a broad risk-off stretch), run a trading desk, or ship a protocol.

What FATF Is, and Why a Paris Watchdog Sets Rules for Your Exchange

FATF was created in 1989 by the G7 in Paris and sits at the OECD. Its original job was chasing drug money; after 2001 it took on terrorist financing, and later the financing of weapons proliferation. Its output is a set of 40 Recommendations that function as the global baseline for anti-money-laundering and counter-terrorist-financing, known in the trade as AML and CFT. Around 40 members sit at the table, but a wider Global Network of regional bodies extends the same standards to more than 200 jurisdictions.

Here is the part that surprises people: FATF has no treaty power and cannot fine anyone. It is not a court or a police force. Its entire leverage is reputational, backed by two lists (covered below) that make life expensive for countries that ignore it. In October 2018 it amended Recommendation 15 to pull virtual assets and the businesses that handle them into scope, and in June 2019 it issued the interpretive note and first risk-based guidance that included the crypto Travel Rule. Every year since, it has published a targeted update grading how the world is doing.

Why should a crypto holder care about a standard-setter in Paris? Because almost every rule your exchange enforces at signup, and every reason a withdrawal to your own wallet suddenly triggers extra questions, traces back to a FATF Recommendation that a national regulator copied into law. The watchdog you never signed up to deal with shapes the product you use every day.

The 2026 Scorecard: What the Seventh Targeted Update Says

The seventh targeted update, released in July 2026 and built on data through April, is the clearest snapshot of that effort. Start with the good news. Travel Rule legislation is now in force in 83 percent of surveyed jurisdictions (91 of 109), up from 73 percent a year earlier; counting the jurisdictions still writing it, 93 percent have the rule in force or in progress. Among the 69 jurisdictions that handle roughly 97 percent of global virtual-asset volume, 94 percent have rules enacted or pending, per Notabene’s breakdown of the report.

Technical compliance is also creeping up. The share of jurisdictions rated largely compliant with Recommendation 15 rose to 34 percent from 29 percent, while the partially compliant share fell to 43 percent. Virtual-asset risk assessments have been completed by 86 percent of jurisdictions, up from 76 percent. On paper, the trend line points the right way.

Then the floor drops out. Only about 40 percent of the jurisdictions with Travel Rule laws have taken any supervisory or enforcement action to confirm firms are actually complying, which means 55 of 91, close to six in ten, have done nothing to enforce the rule they passed. Chainalysis calculates that fewer than 10 percent of jurisdictions (13 of 139) fully meet the preventive AML and CFT standards, and that while 73 percent require VASP licensing, only 58 percent have actually issued any licenses. The table below lines the two stories up.

Measure20252026
Travel Rule law in force73%83% (91 of 109)
Travel Rule in force or in progress85%93% (102 of 109)
R.15 rated largely compliant29%34%
Virtual-asset risk assessment completed76%86%
Jurisdictions with laws that enforced themn/aabout 40% (36 of 91)
Jurisdictions that assessed DeFi riskn/a18%

The uncomfortable reading is that the adoption curve and the enforcement curve are moving at completely different speeds. One is near its top; the other has barely left the ground.

Recommendation 15 and the Birth of the VASP

To follow any of this you need two definitions, both introduced when Recommendation 15 was amended in 2018. The first is the virtual asset itself: a digital representation of value that can be traded or transferred and used for payment or investment. That deliberately excludes central bank digital currencies (those are just fiat in digital form) and anything already regulated as a traditional financial asset, such as a security.

The second, and the one that does the real work, is the virtual asset service provider, or VASP. A VASP is any business that performs one or more of the following activities for another person:

  • exchanging virtual assets for fiat currency, and back;
  • exchanging one virtual asset for another;
  • transferring virtual assets on behalf of someone else;
  • safekeeping or administering virtual assets, that is, custody;
  • providing financial services tied to an issuer’s offer or sale of a virtual asset.

Two words in that definition carry a lot of weight: for another person. FATF’s framework hangs on whether a business takes control of someone else’s assets or acts on their behalf. A custodial exchange that holds your coins clearly qualifies. A pure software provider that never touches user funds is harder to fit, and that ambiguity is where a great deal of the DeFi argument happens. Regulators and builders have spent years fighting over exactly how much control turns a piece of software into a service, and the seventh update shows they are nowhere near a shared answer.

Notice what the definition targets: the intermediary, not the asset and not the code. Somebody holding their own coins in a self-custody wallet is not a VASP and never becomes one. An exchange, a custodian, or an over-the-counter desk is. That single design choice, regulate the middleman, is why FATF’s framework works cleanly for centralized companies and falls apart the moment there is no middleman to point at, which is the DeFi problem we come back to shortly.

The Travel Rule, Explained Without the Jargon

The Travel Rule is the single most consequential piece of FATF crypto guidance, and its name is almost designed to mislead. Traditional banks have followed a version of it for wire transfers since the 1990s: information about who sent a payment and who is receiving it must accompany the transfer. In 2019 FATF extended the concept, which lives in Recommendation 16, to crypto.

In practice it means this: when one VASP sends a customer’s crypto to another VASP above a set threshold, it has to collect and hand over identifying details, the names of the originator and beneficiary, their wallet addresses, account references, and for the sender a physical address or national ID number. FATF’s own de minimis threshold is $1,000 (or the euro equivalent); the US Bank Secrecy Act uses $3,000; the EU version has no minimum at all. Most of the industry exchanges this data using a shared format called IVMS 101, so that different providers’ systems can actually read each other’s messages.

The misleading part is the word travel. Nothing rides along with the blockchain transaction. The coins move on-chain; the compliance data moves separately, over a private channel between the two firms. That split creates the industry’s most stubborn headache, known as the sunrise issue: because jurisdictions switch the rule on at different times, a compliant VASP in one country frequently has no compliant counterparty to send data to in another. The term was popularized by the compliance firm Notabene, whose explainer lays out how the staggered rollout leaves firms half-connected. As adoption climbs toward universal, the sunrise narrows, but in 2026 it is still a daily reality. And when the counterparty is not a VASP at all but a self-custody wallet, there is simply no one to send data to, so the rule tells the VASP to collect its own customer’s details and risk-rate the transfer instead.

The Enforcement Gap Is the Real Story

The enforcement gap deserves its own section because it, not the adoption rate, is the real state of play. Passing a law is cheap and fast; standing up a supervisor with examiners, data, and the willingness to sanction a licensed firm is expensive and politically awkward. The 2026 numbers show the world has done the cheap part and skipped the hard one.

Think about what that means for a launderer. They do not need to find a country with no rules; those countries stand out and get grey-listed. They need a country that has rules and no one checking them, a licensed-on-paper regime with an empty enforcement office. That is a flag of convenience, and the seventh update says roughly six in ten jurisdictions with Travel Rule laws currently offer exactly that. A rule nobody audits is, to a determined criminal, indistinguishable from no rule.

Why does supervision lag so badly? Part of it is resourcing: examining a crypto business demands blockchain-analytics tooling, staff who understand how mixers and cross-chain bridges work, and data-sharing arrangements that many regulators simply do not have yet. Part of it is sequencing, since a regulator has to license firms before it can meaningfully supervise them, and the seventh update shows licensing itself is incomplete in most places. And part of it is political: sanctioning a domestic exchange that employs people and pays taxes is a harder decision than passing a law that upsets no one. The result is a structural lag between the statute and the examiner, and criminals are patient enough to live in it.

Both Chainalysis and Notabene read FATF’s 2026 message the same way: the ask this cycle is not to write new rules but to enforce the ones already on the books. Notabene’s blunt advice to firms is to build to the rule, not to the enforcement posture, meaning do not wait for an examiner to appear before putting real controls in place. For a walk through what those controls look like inside a compliant exchange, from customer identification to suspicious-activity reporting, HOGE Wire’s guide to how crypto KYC and AML actually work covers the firm-level mechanics.

Offshore VASPs: The Blind Spot FATF Just Named

If the enforcement gap is the behavioral problem, offshore VASPs are its structural twin, and FATF named them directly in a dedicated report on March 11, 2026. An offshore VASP, or oVASP, incorporates in a light-touch jurisdiction while serving customers all over the world. The report found that only about a third of jurisdictions with licensing frameworks (39 of 114) regulate providers based on where the activity actually takes place rather than simply where the company is registered.

The mechanism the report highlights is the nested relationship. An unlicensed offshore platform opens an account at a licensed VASP while posing as an ordinary individual customer, then routes its clients’ flows through that account. The licensed firm, doing everything by the book for what it thinks is one retail user, ends up unknowingly laundering for an entire shadow exchange. Elisa de Anda Madrazo, then FATF’s president, said the report “exposes how oVASPs create blind spots that criminals are clearly exploiting, to scam vulnerable people through fraud or fuel terror around the world,” a description you can read in the FATF release.

The lesson stacks on top of the enforcement gap: even a jurisdiction doing everything right can be quietly undercut by a platform that books its business somewhere that is not. Compliance is only as strong as the weakest jurisdiction any of your counterparties can reach.

DeFi and Unhosted Wallets: The Part Nobody Has Solved

Now the part nobody has solved. FATF’s 2021 guidance took a swing at decentralized finance by saying that if any person or entity has “control or sufficient influence” over a DeFi arrangement, that party can be a VASP, no matter how decentralized the front end looks. The decentralized label, in other words, does not automatically exempt anyone.

The trouble is that almost no regulator applies the test. In the 2026 data, just 18 percent of jurisdictions have assessed DeFi-related risks, 93 percent report that they have not identified a single DeFi arrangement that qualifies as a VASP, and only four jurisdictions have imposed any DeFi licensing requirement, with two actually licensing an entity. The gap between the theory (someone is usually in control) and the practice (nobody has been named) is enormous. HOGE Wire’s look at who is actually on the hook in DeFi traces where that control line is being drawn.

Unhosted wallets, the self-custody addresses that hold your keys, sit in the same limbo. FATF’s survey found that 88 percent of jurisdictions rate peer-to-peer activity through unhosted wallets as high risk, yet only 23 percent collect any data to measure it. The risk is acknowledged almost everywhere and quantified almost nowhere. For holders, this is the reason moving assets into self-custody increasingly draws extra scrutiny at the exchange: the exchange keeps the compliance obligation even when the destination is your own wallet, which is a useful reminder that, as HOGE Wire has argued, control is not the same as ownership.

Stablecoins Became the Money-Laundering Rail

Follow the money and it increasingly moves in stablecoins. Chainalysis’s 2026 crime report found that illicit addresses received at least $154 billion in 2025, a 162 percent jump, though that still amounts to under 1 percent of all on-chain volume. What changed is the mix: stablecoins now account for roughly 84 percent of illicit transaction value, having overtaken Bitcoin, because a dollar-pegged token is fast, borderless, and does not swing in price while it is being layered.

The heaviest users are not lone scammers but states. North Korean operations stole around $2 billion in 2025, and Russia’s ruble-backed A7A5 token processed more than $93 billion in flows tied to sanctions evasion. The backdrop is a stablecoin market that has grown past $300 billion, dominated by Tether and USDC, per CoinGecko, so the same rail that settles legitimate dollars settles the illicit ones. Criminal networks have even started issuing their own tokens engineered to resist an issuer’s ability to freeze funds, the feature Huione marketed on its USDH product before US regulators moved on the group. Many of those flows begin with ordinary victims, which is why the mechanics of a modern scam matter; HOGE Wire’s piece on how a single signature has become the exploit shows how funds get siphoned before they ever hit a laundering chain.

That freeze-resistant push is a direct response to a real enforcement lever. The largest fiat-backed stablecoins are centrally issued, which means their operators can freeze specific addresses when law enforcement or a court asks, and both major issuers have done so repeatedly. That single capability makes a compliant stablecoin far more traceable and seizable than cash, and it is exactly what a launderer wants to avoid, which is why the sophisticated end of the market keeps trying to build tokens no issuer can claw back. The compliance value of a freezable stablecoin and its attractiveness to criminals are two sides of the same design.

The Grey List and the Black List: FATF’s Only Real Weapon

So what can a body with no police force actually do? It can name names. FATF maintains two lists, and inclusion on either is the closest thing it has to a weapon.

The call-for-action list, universally called the black list, flags the highest-risk jurisdictions and invites countermeasures. After the June 2026 plenary it held steady at three names: North Korea, Iran, and Myanmar. The increased-monitoring list, known as the grey list, covers countries with strategic deficiencies that have committed to time-bound fixes; it stood at 22 jurisdictions after June 2026, with Bosnia and Herzegovina and Iraq added and Algeria and Namibia removed for completing their action plans, per the plenary outcomes.

ListWhat it signalsMembers (June 2026 plenary)
Call for action (black list)Highest risk; countermeasures and enhanced due diligence expectedNorth Korea, Iran, Myanmar (no change)
Increased monitoring (grey list)Strategic deficiencies; time-bound action plans22 jurisdictions; added Bosnia and Herzegovina and Iraq; removed Algeria and Namibia

Being listed carries a real economic bill. Correspondent banks de-risk, cross-border payments slow down and cost more, and foreign investment tends to cool while a country works its way back off. Crucially for this topic, weak VASP supervision is now part of what a mutual evaluation examines, so a country that ignores its crypto sector can pay for it across its entire financial system. That is the mechanism by which a non-binding Paris standard becomes something finance ministers genuinely fear.

How the United States Actually Enforces This (Not the SEC)

A persistent myth deserves correcting: in the United States, the SEC does not police crypto anti-money-laundering. That job lives at the Treasury. FinCEN writes and enforces Bank Secrecy Act rules, and OFAC administers sanctions; the SEC’s fight is over whether a given token is a security, a separate question entirely. Conflating the two is one of the most common mistakes in crypto policy conversations.

Since FinCEN’s 2019 guidance, crypto exchanges and administrators have counted as money services businesses, which means they must register, run AML programs, file suspicious-activity reports, and follow the Travel Rule at the $3,000 US threshold. When a firm flouts that, the hammer comes from Treasury, not the securities regulator. The clearest recent example is Huione: in May 2025 FinCEN designated the Cambodia-based Huione Group a primary money laundering concern under Section 311 of the USA PATRIOT Act, finding it had laundered more than $4 billion between 2021 and 2025, including funds tied to North Korean cybercrime, and by October 2025 it finalized a measure cutting the group off from the US banking system. Treasury Secretary Scott Bessent said Huione “has established itself as the marketplace of choice for malicious cyber actors like the DPRK and criminal syndicates, who have stolen billions of dollars from everyday Americans,” in the FinCEN action.

Stablecoins are the newest front. The GENIUS Act, signed in 2025 as the first federal framework for US payment stablecoins, treats permitted issuers as Bank Secrecy Act institutions, and in April 2026 FinCEN and OFAC proposed rules requiring them to run full AML and sanctions programs. The scale of the problem is not hypothetical: the proposal notes that between 2015 and late 2025, FinCEN received roughly 55,000 suspicious-activity reports referencing specific stablecoins.

Huione is not an isolated case. The past two years have brought the largest anti-money-laundering settlements in crypto history, from Binance’s multibillion-dollar 2023 resolution to guilty pleas from other offshore-flavored exchanges, almost all of them driven by Bank Secrecy Act failures rather than securities charges. The pattern reinforces the point: in the United States, the expensive end of crypto enforcement runs through AML law, and the firms that learned it the hard way were the ones that treated compliance as optional until an examiner, or a prosecutor, finally arrived.

The View From Europe and the Rest of the World

Outside the US, the same FATF standards land in different machinery. The European Union wrote the Travel Rule into its Transfer of Funds Regulation, in force since December 30, 2024, and pointedly with no minimum threshold, so every transfer between providers carries data, not just the ones above $1,000. The EU’s broader AML rulebook, the Anti-Money-Laundering Regulation, and a brand-new authority, AMLA in Frankfurt, will directly supervise the highest-risk crypto firms and phase out anonymous accounts and privacy-preserving services.

MiCA, the EU’s headline crypto law, is a separate track: it governs market conduct and stablecoin prudential rules, while AML sits in the AMLA, AMLR, and Transfer of Funds stack. The through-line is simple. FATF sets the target and each bloc hits it with its own instrument, which is exactly why a global exchange runs different Travel Rule thresholds and onboarding flows depending on where you log in from.

DimensionUnited StatesEuropean Union
AML authority for cryptoFinCEN and OFAC (Treasury)AMLA (Frankfurt) plus national regulators
Travel Rule instrumentBank Secrecy ActTransfer of Funds Regulation
Travel Rule threshold$3,000No minimum
Stablecoin regimeGENIUS Act (2025)MiCA plus AMLR
Is a token a security?SEC (separate from AML)National regulators under MiFID II

The UK Takes the Gavel: What Changes Under Giles Thomson

The timing of all this coincides with a change at the top. On July 1, 2026 the FATF presidency passed from Mexico’s Elisa de Anda Madrazo to the United Kingdom’s Giles Thomson, who had served as vice-president since July 2025; India took a FATF vice-presidency for the first time. The handover matters because the president sets the two-year agenda.

Thomson’s UK presidency, running through June 2028, has named three priorities, according to its opening statement: fraud, which was flagged as a proceeds-generating offense in nearly 90 percent of countries during the last round of mutual evaluations; faster public-private and cross-border information sharing; and continued work on virtual assets, specifically stronger risk-based supervision and enforcement, better Travel Rule implementation, and the stablecoin, offshore-VASP, unhosted-wallet, and DeFi risks the seventh update flagged. Read against the enforcement gap, the agenda is a tell. The next two years of FATF crypto work are about making the existing rulebook bite, not adding chapters to it.

What It Means If You Hold, Trade, or Build

So what should you actually take from this? If you hold or trade, expect more questions, not fewer. Withdrawals to self-custody, transfers to another exchange, and larger deposits increasingly trigger source-of-funds and destination checks, because your provider carries the Travel Rule and risk-rating duty even when the wallet on the other end is yours. Where you choose to custody assets has quietly become a compliance decision as much as a security one.

If you build, the concept to internalize is the control test. If you or your company holds control or sufficient influence over a service, a front-end, an admin key, a fee switch, a treasury, a regulator can argue you are a VASP regardless of how decentralized the marketing sounds. Teams shipping token projects or autonomous agents should assume the intermediary question will eventually be asked and design for it rather than hope the label protects them.

Then there is the honest tension the whole system runs on. Critics point out that the apparatus collects enormous volumes of personal data to police an illicit share that remains under 1 percent, building honeypots and surveillance while the most sophisticated actors route around it through flags of convenience. Defenders answer that the flags of convenience are precisely the point: the network is only as strong as its weakest enforced link, and closing those links is what 2026 is supposed to be about. Both things are true at once, which is why the debate will outlast this year’s plenary.

The one-line summary: in 2026 the crypto AML rulebook is nearly written and nowhere near enforced. The adoption curve is close to its ceiling, the enforcement curve close to its floor. If you want to know where crypto regulation is heading next, stop watching the first curve and start watching the second.

Frequently Asked Questions

What is FATF guidance and is it legally binding?

FATF, the Financial Action Task Force, is the global standard-setter for anti-money-laundering and counter-terrorist-financing rules. Its 40 Recommendations and crypto guidance are not laws on their own; they bind only once a country writes them into national law. FATF’s leverage comes from peer review and its grey and black lists, which raise the cost of cross-border banking for jurisdictions that fall short.

What is the crypto Travel Rule?

It is FATF’s Recommendation 16 applied to crypto. When a regulated provider, called a VASP, sends a transfer above a threshold to another provider, it must collect and pass along originator and beneficiary information. FATF’s threshold is $1,000 or the euro equivalent; the US Bank Secrecy Act uses $3,000; the EU version has no minimum. The data moves over a separate channel, usually in the IVMS 101 format, not on the blockchain.

What is a VASP?

A virtual asset service provider is any business that, for its customers, exchanges crypto for cash or other crypto, transfers it, holds it in custody, or provides financial services for a token issuance. Exchanges, custodians and OTC desks are VASPs; a person holding their own coins in a self-custody wallet is not.

Does the SEC enforce crypto anti-money-laundering rules in the US?

No. In the US, crypto AML is enforced by FinCEN, which runs Bank Secrecy Act rules, and OFAC, which runs sanctions, both part of the Treasury. The SEC decides whether a token is a security, which is a separate question from money laundering.

Why does my exchange ask so many questions when I withdraw to my own wallet?

Because the exchange, not you, carries the compliance obligation. Even when your crypto goes to a self-custody wallet with no provider on the other side, the exchange still has to collect your information, risk-rate the transfer, and in many places treat unhosted-wallet activity as higher risk. FATF’s 2026 data shows regulators rate unhosted-wallet transfers as high risk almost everywhere.

Priya Reddy covers financial regulation and compliance for HOGE Wire.

Share 𝕏 Post Telegram