July 16, 2026 – The Financial Action Task Force (FATF) published its seventh updated report on the implementation of standards for virtual assets. The report’s message is clear and paradoxical: the global legal framework for cryptoasset regulation is being built at an unprecedented pace, yet the volume of illicit funds that organized crime groups channel through these same technologies is growing even faster.
This paradox constitutes the core of the current problem in anti-money laundering (AML) and counter-terrorist financing (CFT) governance in the crypto ecosystem: the structural gap between legislative progress and the actual effectiveness of enforcement.
According to Chainalysis data, in 2025 illicit crypto addresses received at least $154 billion, representing a 162% growth from 2024. TRM Labs offers a more conservative figure of $158 billion. Regardless of the metric used, the conclusion is invariant: the absolute volume of illicit crypto funds has entered the hundreds of billions range.
More relevant is the structural shift in asset composition. Stablecoins have displaced bitcoin as the most widely used virtual asset in illegal transactions. Chainalysis indicates that of the total $154 billion in illicit transactions in 2025, stablecoins accounted for 84%. TRM Labs adds that illicit entities received $141 billion in stablecoins during 2025, the highest figure in five years.
The FATF warns that crypto-related crimes have become “more sophisticated and interconnected” over the past year. Scam networks intertwine with investment fraud networks, and darknet market providers are migrating toward DeFi platforms to circumvent the KYC controls of centralized exchanges. An emblematic case is that of a Cambodian financial group that, between 2021 and 2025, laundered at least $4 billion through organized fraud, underground banking, and blockchain-based transfer networks.
At the legislative level, the construction of the global framework shows quantifiable progress. As of April 2026, of the 149 jurisdictions assessed by the FATF, 51 (34%) were rated as “substantially compliant,” up from 29% in 2025. 83% of surveyed jurisdictions have adopted laws to implement the “travel rule,” with another 11% in the process of doing so. The rate of completion of virtual asset risk assessments rose from 76% in 2025 to 86%.
However, these figures mask structural deficiencies in the implementation phase.
First, the increase in compliance ratings is concentrated on technical compliance—that is, the adoption of legal texts. The FATF stresses that “significant gaps” persist in converting those risk assessments into concrete measures that reduce crypto crime. Of the 91 jurisdictions that have legislated the travel rule, 55 (60%) have not issued any supervisory finding, directive, or enforcement action related to travel rule compliance. The disconnect between the existence of the law and its enforcement is systemic.
Second, the implementation of licensing regimes also lags. 73% of jurisdictions require licenses for virtual asset service providers (VASPs), but only 58% have actually granted licenses, and barely 40% fully meet the necessary standards in mutual evaluations.

Third, the effectiveness of prohibition frameworks is questionable. 23% of jurisdictions have banned VASP operations, up from 11% in 2023. But the FATF indicates that those that adopted prohibition face ongoing challenges in identifying and sanctioning illicit activities of unauthorized VASPs. Prohibiting does not equate to regulating effectively.
The supervisory is undergoing a structural reconfiguration. According to CertiK’s report of April 28, 2026, AML compliance has displaced securities violations as the primary regulatory risk for crypto firms. The U.S. Department of Justice and the Financial Crimes Enforcement Network (FinCEN) imposed AML-related fines totaling $900 million in the first half of 2025. In the same period, SEC cryptoasset fines fell 97% year-over-year to $142 million.
Notable cases: OKX reached a $504 million settlement with the DOJ in February 2025, and KuCoin paid $297 million in January 2025, both for operating without a license and violating the Bank Secrecy Act. In Europe, AML fines surged 767% in the same half. Sanctions-related crypto transaction volume grew more than 400% year-over-year in 2025.
These data indicate that supervisors’ strategy has shifted from asset classification to fund flow supervision. This shift has profound implications for the design of compliance systems: the effectiveness of transactional monitoring and controls has become the focal point, above mere reporting compliance.
Enforcement lag is not solely due to poor implementation of rules, but to the fact that criminals’ technical evolution outpaces regulators’ response capacity.
The case of “anti-freeze” stablecoins is the most telling. The FATF reports that after a major stablecoin issuer froze more than $29 million belonging to a criminal group, that organization created its own dollar-pegged stablecoin in response. This “bespoke stablecoin” is marketed as immune to freezes, deployed across multiple public chains and on a proprietary chain. The FATF warns that authorities’ ability to freeze or destroy assets at the issuer level can no longer be taken for granted.
The DeFi regulatory void constitutes another systemic risk. The FATF’s specific report of July 21, 2026, notes that nearly 93% of surveyed jurisdictions have not yet applied FATF standards to DeFi arrangements that meet the criteria. Of 142 jurisdictions, only 26 have conducted risk assessments, 4 have established licensing rules, and only 2 have registered or licensed relevant platforms. Total value locked (TVL) in DeFi reached $86.6 billion in 2026, an increase of approximately 85% since 2023. The gap between this volume and regulatory coverage is a significant risk.
The regulation of offshore VASPs faces similar structural difficulties. The FATF, in its March 2026 report, highlights that gaps in the supervision of these providers are being massively exploited for fraud, laundering, and terrorist financing. Cross-border cooperation and information sharing remain critical obstacles.
Artificial intelligence further aggravates the problem. The FATF mentions the use of deepfakes, synthetic identities, and automated recruitment for scams in virtual asset-related crimes, scaling up criminals’ operational capacity.
Faced with these structural challenges, the crypto sector’s compliance strategy requires a fundamental overhaul.
First, compliance strategy must shift from “reacting to enforcement” to “embedding the rule in design.” The FATF warns that the travel rule problem is no longer “whether the law exists” but “whether anyone is checking it.” For compliance officers, the fact that a counterparty has a legal obligation but no one oversees it, or that it has no obligation at all, produces in practice the same effect: incomplete data, unresponsive answers, and costs concentrated on entities that do comply. Operators should build their systems as if supervision were already in place, not wait for the first inspection and then remediate.
Second, stablecoin issuers must incorporate technical compliance functionalities from the design stage. The FATF recommends that jurisdictions require issuers to have the technical capability to freeze, destroy, or blacklist when necessary, and to integrate into smart contracts functions such as allowlists and denylists. These architectures must be present from launch, not as after-the-fact patches.

Third, DeFi projects must confront the reality of effective control. The FATF makes clear that if in a DeFi arrangement there are identifiable persons retaining “control or sufficient influence,” FATF standards already apply, regardless of the degree of decentralization proclaimed. Many DeFi projects still exhibit centralized elements in practice—concentration of governance tokens, administrative privileges, upgrade control, etc.
For platforms that refuse to cooperate, jurisdictions may resort to prohibiting local operations as a last-resort measure. Projects should proactively assess their control structure and incorporate AML controls at the smart contract or interface level.
Fourth, cross-border compliance cooperation must be elevated to a strategic priority. The FATF notes that jurisdictions with significant VASP activity, which concentrate approximately 97% of the global virtual asset market, largely determine the overall risk level. Operators must establish substantial compliance presence in those key jurisdictions, rather than relying on offshore structures to evade regulation.
The FATF’s seventh update report draws a clear picture: the global legal framework for cryptoassets is advancing rapidly, but material enforcement remains systemically behind. Criminals exploit stablecoins’ freeze-immunity properties, DeFi gaps, offshore VASP jurisdictional loopholes, and emerging technologies like AI, and their adaptation speed consistently outpaces regulators’ response capability.