This thesis, submitted at the Institute for Law and Finance at Goethe University Frankfurt, provides a critical legal and technological analysis of the effectiveness of the Financial Action Task Force framework in addressing money laundering risks arising from decentralized finance. It examines how decentralized blockchain-based systems fundamentally challenge the assumptions underlying traditional anti-money laundering regulation.The study argues that FATF Recommendations, originally designed for centralized financial systems, are structurally incompatible with decentralized architectures that operate without identifiable intermediaries such as Virtual Asset Service Providers. Through an integrated legal and technological assessment, the research demonstrates how privacy-enhancing tools, including non-custodial wallets, cryptocurrency mixers, zero-knowledge proof mechanisms, and cross-chain bridges, obscure ownership trails and significantly impair regulatory oversight.While these technologies are designed to enhance user privacy, they simultaneously enable sophisticated money laundering techniques, including chain hopping, transaction obfuscation, and the untraceable movement of assets across blockchain networks. The thesis further identifies critical regulatory gaps in the application of core FATF standards, particularly in relation to customer due diligence, beneficial ownership transparency, and the implementation of the Travel Rule.A case study of Bosnia and Herzegovina illustrates the practical consequences of fragmented regulatory implementation. Divergent adoption of FATF standards across its entities reflects the broader “Sunrise Issue,” whereby asynchronous global implementation of the Travel Rule generates cross-border inconsistencies and enforcement challenges.To address these structural deficiencies, the thesis proposes a reinterpretation of FATF standards based on the principle of functional equivalence, extending AML obligations to any actor or protocol exercising effective control over financial transactions, irrespective of formal legal classification. It further advocates for the integration of RegTech, tokenization, and machine learning as tools to reconcile regulatory oversight with technological innovation.The research concludes that the current FATF framework remains fundamentally misaligned with the operational realities of decentralized finance. Ensuring the continued integrity of the global financial system will require the adoption of technologically adaptive, risk-based, and internationally coordinated regulatory approaches. Only through such innovation can AML enforcement remain effective in an increasingly decentralized digital economy.
Tokenized deposits—commercial bank deposits represented as transferable digital tokens on distributed ledgers—are no longer hypothetical. Major U.S. banking institutions are deploying them at institutional scale, but the legal framework governing them has not kept pace. The GENIUS Act of 2025 recognizes that tokenized deposits are bank deposits governed by banking law rather than by the Act’s stablecoin framework. Yet tokenized deposits differ from conventional deposits in important respects: they are programmable, can settle atomically on distributed ledgers, and may be transferred by artificial intelligence agents acting without contemporaneous human intervention. The existing legal framework, including the Electronic Fund Transfer Act (EFTA), UCC Article 4A, and the FDIC’s resolution architecture, was not designed for these features. This Article identifies three consequential gaps in that framework and proposes targeted reforms to address them. First, the EFTA’s authorization framework does not clearly address smart-contract-governed transfers or AI-agent-initiated payments, leaving liability allocation uncertain. Second, Article 4A’s acceptance-based finality regime does not map cleanly onto on-chain settlement, creating uncertainty regarding payment finality, discharge, and error allocation. Third, smart-contract execution creates novel challenges for FDIC receivership, including asset transfers that continue after a bank’s failure. For each gap, the Article proposes reforms directed to the appropriate actor: congressional amendments to the EFTA, Uniform Law Commission amendments to UCC Articles 4A and 3, and FDIC rulemaking addressing resolution and recordkeeping, including a shadow ledger mandate and a regulatory kill switch for permissioned networks. Together, these reforms adapt existing law to govern a new mode of payment without displacing the banking framework that makes it trustworthy.
Gina-Gail S. Fletcher, Veronica Root Martinez, Steven L. Schwarcz
Traditional financial systems rely on a dense network of intermediaries—banks, brokers, exchanges, and clearinghouses—that not only facilitate transactions but also serve as compliance gatekeepers. By implementing capital adequacy rules, disclosure regimes, and anti-money laundering and know-your-customer conventions, these entities constrain opportunism, provide reliable recordkeeping, and enable regulators to monitor systemic risk. Decentralized finance (“DeFi”) disrupts this model by replacing intermediaries with smart contracts: self-executing digital agreements that automatically perform transactions on blockchain or other encrypted computer code. While proponents tout DeFi as a more efficient and “purer” form of finance, its disintermediation eliminates the chokepoints that historically enabled oversight and consumer protection. As a result, DeFi magnifies familiar risks that fueled the Great Depression and the 2008 Global Financial Crisis, while also introducing novel vulnerabilities tied to computer code, governance, and cross-border anonymity. This Article argues that because DeFi platforms disaggregate traditional intermediary functions, effective regulation must focus on (i) embedding compliance safeguards directly into platform design and (ii) holding accountable the actors who build, operate, and maintain those platforms. These safeguards are essential to preserve market integrity, mitigate systemic risk, and protect investors in the absence of conventional intermediaries. Specifically, regulators should develop reforms that require platforms to incorporate technological and governance tools that replicate the critical compliance and risk-management functions historically supplied by intermediaries. Constructing such a regulatory regime will require substantial multijurisdictional coordination, both in harmonizing regulatory expectations and in building cross-border enforcement capacity. Fortunately, a range of existing international coordination mechanisms can be leveraged to facilitate this global effort.
This research undertakes a comparative analysis of Thailand’s anti-money laundering (“AML”) regulatory framework in relation to the most recent recommendations issued by the Financial Action Task Force (“FATF”) concerning money laundering risks associated with Security Token Offerings (“STOs”) conducted via blockchain technology. The objective is to identify potential regulatory gaps and areas for improvement in Thailand’s existing AML measures, particularly in the areas of regulatory oversight, licensing requirements, customer due diligence (“CDD”), recordkeeping obligations, and the reporting of suspicious transactions by virtual asset service providers (“VASPs”). The methodological basis of the research is the comparative analysis method, examining Thailand’s applicable AML laws and regulations alongside FATF guidelines, relevant literature, and case law. The research found that Thailand’s applicable AML laws, including the relevant regulations, are inadequacies and inefficiencies in the regulatory oversight of securities offerings that utilize emerging technologies. Specifically, the current regulatory framework is insufficient in effectively preventing or mitigating risks related to money laundering and the financing of terrorism for investors. As a result, it does not adequately ensure the security and integrity of investments in decentralized systems, therefore, it fails to provide sufficient safeguards to protect investors from inadvertently becoming involved in unlawful activities. These shortcomings indicate a lack of alignment with international standards issued by the FATF. This research is useful to legislative authorities, lawyers, law students, and regulatory bodies, especially in Thailand, and only limited to the regulation of money laundering in Thailand and does not provide empirical research.
<b>RESUMO:</b> A última década testemunhou a consolidação das Finanças Descentralizadas (DeFi) e a busca por maior eficiência nos mercados de capitais através da tokenização de Ativos do Mundo Real (RWA). Este artigo propõe o Unified Structured Finance Protocol (USFP), uma arquitetura DeFi híbrida projetada para a tokenização e negociação de produtos estruturados (como Debêntures, ETFs e COEs) no contexto regulatório brasileiro. O problema de pesquisa central é: Como desenvolver um <i>framework</i> de protocolo DeFi que preserve a eficiência e a liquidez da descentralização, ao mesmo tempo em que acomoda os requisitos rigorosos de <i>Anti-Money Laundering</i> (AML), <i>Know Your Customer</i> (KYC), e relatórios regulatórios exigidos para a tokenização de valores mobiliários no Brasil? Os objetivos são: 1) Propor o <i>Unified Structured DeFi Note</i> como um meta-ativo tokenizado. 2) Detalhar uma arquitetura de protocolo que integra um Módulo de Compliance (<i>RegTech</i>) e um AMM Regulado (RL-AMM). 3) Analisar o encaixe conceitual dessa arquitetura no panorama regulatório brasileiro (CVM/BACEN). A contribuição principal (Tese) é que a viabilidade de protocolos DeFi para o mercado de capitais brasileiro reside na separação funcional entre a liquidação descentralizada (<i>trustless</i>) e o acesso permissionado (<i>trusted</i>) [8]. Esta abordagem define um novo modelo de Infraestrutura de Mercado de Capitais Programável (<i>D-CMI – Decentralized Capital Market Infrastructure</i>), essencial para a tokenização de RWA regulamentados. A centralização intencional dos pontos de controle de acesso (KYC/AML) e de relatórios permite que o regulador mantenha a supervisão, enquanto as operações de <i>payoff</i> e negociação se beneficiam da eficiência <i>on-chain</i>