Moving the Control Point Off the Network Layer: Reading the Permissionless-AML Compatibility Argument From Japan

What was actually published
The paper is titled "The Compatibility of Permissionless Networks and Financial Integrity: A Practical Guide for Financial Institutions," runs 27 pages, is dated August 23, 2026, and was posted to SSRN the following day. Its authors are Rebecca Rettig, chief operating officer and chief legal officer at Jito Labs and formerly chief legal and policy officer at Polygon Labs; Omid Malekan, adjunct professor at Columbia Business School; and Michael Mosier, co-founder of the law firm Arktouros.
The authors' backgrounds matter. Mosier served as acting director of FinCEN, head of sanctions compliance and enforcement at OFAC, deputy chief of the Justice Department's money laundering section, and a director at the National Security Council, and was the first in-house counsel at Chainalysis. This is a document written from the industry side by someone who knows the regulator's side from within.
One point deserves precision: the paper is not a16z crypto's own proposal. The firm published an adapted version on its site on September 10, and that republication is what set off the news cycle. Japanese coverage describing it as a16z's recommendation is attributing it slightly incorrectly.
The shape of the argument
The claim is clean. Nothing in the Bank Secrecy Act or US sanctions law requires a permissioned validator set or a restricted group of participants. Institutions can therefore meet their obligations without controlling the underlying network. Controls belong at the application layer they operate and command: customers, counterparties, and transactions.
The framework the paper proposes has nine components: governance and risk assessment; customer-level know-your-customer and due diligence; wallet and counterparty screening; onchain transaction monitoring and reporting; Travel Rule and Funds Transfer Rule compliance; risk-based sanctions controls; third-party risk management; wallet and key management and cybersecurity; and testing, auditing, training, and compliance expertise.
The analogy invoked is the internet, where users do not select or screen the individual operators routing their traffic. On the possibility of paying a network fee to a validator in a sanctioned jurisdiction, the paper argues such protocol-level interaction differs in kind from selecting, contracting with, and funding a sanctioned party. It cites a November 2025 OCC interpretive letter confirming that banks may pay blockchain network fees and hold the crypto assets needed to pay them.
The most practically useful passage concerns regulators' posture. Banking regulators and FinCEN require a reasonably designed programme with effective processes to identify, measure, monitor, and control risks. FinCEN stated in its August 2020 enforcement statement that its approach is not a game of gotcha. Treasury's de-risking report observed that while banks believe any control failure exposes them to substantial fines, such fines are in fact rare and follow the collapse of an entire programme rather than the limited shortcomings a risk-based approach will sometimes produce. The diagnosis is that practitioners are confronting not the law but their own over-defensive reading of it.
Where it is weak
Part of the reasoning rests on absence of evidence. In the roughly five years since OFAC issued sanctions compliance guidance for the virtual currency industry, no enforcement action has been identified that rested solely on a validator processing a sanctioned transaction or a participant paying protocol-level fees. That is factually correct, but the absence of enforcement is not a safe harbour. OFAC designated Tornado Cash in August 2022, so it is not without appetite for reaching the infrastructure layer. The designation was lifted in March 2025 following an appellate ruling the previous year, and that history equally demonstrates that the legal interpretation is unsettled.
The second weakness the paper concedes itself. Answering the objection that public ledgers expose balances and transaction histories, it points to zero-knowledge techniques that could prove a counterparty is not on a sanctions list, or that reserves exceed liabilities, without disclosing identities or financial records. But it states plainly that these technologies remain at pilot or research stage and have not been deployed at institutional scale. The solution to institutions' largest concern is not yet deployable.
The same week in Japan
Japan produced movement in the other direction that same week. On August 6, the Financial Services Agency and the National Police Agency jointly asked the Japan Virtual and Crypto Assets Exchange Association to strengthen fraud prevention, including pre-registration of withdrawal addresses and a holding period before newly registered addresses can be used. GMO Coin introduced a 24-hour restriction on August 29, and Coincheck announced on September 10 that its own measure begins September 15. The holding period is undisclosed, and no early release is offered.
What is striking is that the control point is the same on both sides. The paper a16z amplified and Japan's authorities both place controls on intermediaries rather than on the network. Japan's Payment Services Act and anti-criminal-proceeds law were designed that way from the start, and the US GENIUS Act imposed obligations on stablecoin issuers on the same logic. Only the direction differs. The paper uses application-layer control to make public chains usable; Japan's authorities use the same layer to slow the rate at which assets leave the regulated perimeter.
For Japanese institutions the decisive point is that this is a document about US law. In Japan, the gap between what the statutes forbid and what supervisory practice tolerates is wide. The August 6 request was not legislation but administrative guidance, and it became industry practice within weeks. An argument built on the absence of a statutory prohibition does not transfer directly.
[Business Development Insights]
- The paper is a useful instrument for separating legal barriers from self-imposed de-risking. Most of the reason Japanese institutions avoid public chains is not statutory prohibition but wariness of unpredictable administrative guidance. Simply adopting an internal approval format that states these two separately moves the discussion forward, and the nine-component framework serves as a ready template for an internal checklist.
- Reasoning grounded in US law carries no authority in Japan. Translating it requires building a mapping table covering identity verification under the anti-criminal-proceeds law, JVCEA self-regulatory rules, and administrative guidance of the kind issued on August 6. No such document exists domestically, and whichever firm claiming regulatory orchestration builds it first can set the de facto standard.
- What the paper concedes as immature is itself the commercial opportunity. Mechanisms for proving in zero knowledge that a counterparty is not sanctioned, or that reserves exceed liabilities, address the transaction-visibility concern Japanese institutions raise most often. For a firm holding both validator operations and regulatory capability, the entry space is large and the competition thin.
[Sources]
bitbank plus, "a16z proposes that public blockchains can meet US AML rules" (September 11, 2026) https://bitbank.cc/knowledge/breaking/article/1mirk6-x_l3 The Crypto Times, "a16z Says Permissionless Blockchains Can Meet U.S. AML Rules" https://www.cryptotimes.io/2026/09/10/a16z-says-permissionless-blockchains-can-meet-u-s-aml-rules/ Rebecca Rettig, Omid Malekan and Michael Mosier, "The Compatibility of Permissionless Networks and Financial Integrity: A Practical Guide for Financial Institutions" (SSRN, August 23, 2026) https://papers.ssrn.com/sol3/papers.cfm?abstract_id=7343938 a16z crypto, "A financial integrity framework for permissionless networks" https://a16zcrypto.com/posts/article/financial-integrity-framework-permissionless-networks TRM Labs, "TRM Talks: How Institutions Can Use Permissionless Rails with Rebecca Rettig and Michael Mosier" https://www.trmlabs.com/resources/trm-talks/how-institutions-can-use-permissionless-rails-with-rebecca-rettig-and-michael-mosier DeFi Education Fund, "DeFi Debrief: Week of August 24, 2026" https://defieducationfund.substack.com/p/defi-debrief-week-of-august-24-2026-b03 OCC, "Interpretations and Actions, November 2025" https://www.occ.treas.gov/topics/charters-and-licensing/interpretations-and-decisions/2025/interpretations-and-actions-nov-2025.html NADA NEWS, "Coincheck temporarily restricts transfers to newly registered addresses in response to National Police Agency request" https://www.nadanews.com/367549/ BITTIMES, "Coincheck to restrict transfers to newly registered destinations from September 15" https://bittimes.net/news/228512.html
Akihisa Ishida
Cabinet Inc. Founder CEO
Disclaimer
This report has been prepared solely for informational purposes regarding crypto assets and related markets, and is not intended to recommend, solicit, or offer the purchase, sale, holding, or any other transaction of any specific crypto asset. It does not constitute investment advice, investment solicitation, or the sale or intermediation of financial products as defined under the Financial Instruments and Exchange Act or any other applicable laws and regulations, nor does it constitute tax, legal, or accounting advice.
The information contained in this report is based on sources believed to be reliable at the time of preparation; however, we make no representation or warranty, express or implied, as to its accuracy, completeness, timeliness, or usefulness. Crypto assets are subject to significant price volatility and may result in the loss of principal or other financial losses. Any investment decision shall be made solely at the user's own discretion and responsibility, and we accept no liability whatsoever for any damages arising out of or in connection with the use of this report.
Blockchain Business Consultation
From idea-stage brainstorming and technical validation (PoC) to implementation and operations, Cabinet provides end-to-end business development consulting. Start with a free consultation today.
$150 Million of $900 Million: Decomposing the Numbers at Robinhood Chain
Does Bitcoin Really Explain the 19%? A Disclosure-Layer Gap and How to Read Crypto KPIs
Sign Up for Newsletter
Beyond the content of this report, we will deliver the latest industry information and exclusive reports by email.

