a16z Crypto: A New Path for Financial Institutions to Go On-Chain
chaincatcherAuthor: Rebecca, COO and General Counsel at Jito Labs
Compiled by: Jiahua, ChainCatcher
Many financial institutions are leveraging one of the most groundbreaking advances in blockchain technology: permissionless networks.
Franklin Templeton began using permissionless blockchains as early as 2021 to record share information for its on-chain U.S. government money market fund, and added Solana to its supported networks in February 2025. BlackRock has been issuing tokenized money market fund shares on Ethereum since March 2024. In January 2025, Apollo also began offering tokenized investment access to its diversified credit fund across six permissionless networks.
Announcements of traditional financial institutions deploying products on permissionless networks appear almost weekly.
However, some traditional financial institutions still view permissionless networks as "difficult to navigate." Instead, many banks, brokerages, and asset managers are gradually shifting toward permissioned networks. In such systems, gatekeepers or consortia decide who can validate transactions, who can use or participate in the network, and for what purposes the network can be used.
These institutions choose permissioned networks because they mistakenly believe this is a prerequisite for meeting compliance requirements. The underlying logic is that only a clearly identified and vetted set of participants can satisfy financial compliance regulations, including anti-money laundering and countering the financing of terrorism rules under the Bank Secrecy Act, as well as U.S. sanctions regulations.
To put it bluntly, institutional compliance departments believe that permissionless networks are incompatible with the Bank Secrecy Act and sanctions regulations.
Our latest paper, "The Compatibility of Permissionless Networks and Financial Compliance: A Practical Guide for Financial Institutions," argues that financial institutions can indeed build products and transact on permissionless blockchain networks. Concerns about financial compliance regulations should not be a barrier to institutions using these networks, because existing laws are sufficient to address the relevant issues.
Financial institutions can fulfill their obligations by implementing controls where they actually have control, through an appropriate, risk-based compliance framework.
From a regulatory and other perspective, financial institutions have no obligation to own the underlying infrastructure, nor to screen, vet, or restrict the infrastructure that carries their financial transactions and related communications. In fact, regulators have explicitly acknowledged that financial institutions can adapt their financial compliance systems based on the technological innovation of "permissionlessness."
Are Permissionless Networks Really Incompatible with Financial Compliance Requirements?
The Bank Secrecy Act and sanctions regulations require financial institutions to implement reasonable controls over risks and take steps to mitigate those risks, but they do not require the complete elimination of risk. The latter is an unattainable standard.
Under the Bank Secrecy Act, a financial institution's anti-money laundering and countering the financing of terrorism program should focus on identifying, recording, and curbing illicit financial activity. These programs are neither intended to completely prevent money laundering or terrorist financing, nor can they achieve that goal.
U.S. federal banking regulators and the Financial Crimes Enforcement Network have made clear that the key to financial compliance is establishing a "reasonably designed" anti-money laundering program that includes "processes to effectively identify, measure, monitor, and control risks."
The Financial Crimes Enforcement Network further clarified in its August 2020 "Enforcement Statement" that regulators do not enforce the Bank Secrecy Act to punish institutions for isolated lapses.
The U.S. Treasury Department's report on "de-risking" directly addresses financial institutions' concerns. Banks often believe that any internal control issue could lead to massive fines. However, regulators have noted that such fines are uncommon and typically occur in cases where the entire anti-money laundering and countering the financing of terrorism system has broken down, rather than from occasional shortcomings in a risk-based approach.
Sanctions compliance systems follow similar logic.
The U.S. Treasury Department's Office of Foreign Assets Control, in its "Framework for Compliance Commitments," outlines five core elements of an effective sanctions compliance program: management commitment, risk assessment, internal controls, testing and auditing, and training.
The Office of Foreign Assets Control adjusts the specific implementation requirements of compliance measures based on an institution's size, product types, customer base, and the regions where it operates.
The "Economic Sanctions Enforcement Guidelines," when addressing suspected violations, consider factors such as whether the institution acted willfully, whether it was aware of the relevant conduct, the harm caused to sanctioned parties, and whether the compliance program was adequate.
Regulators' enforcement systems and historical practice support a "risk-balanced, not zero-tolerance" approach. The enforcement focus of the Financial Crimes Enforcement Network and the Office of Foreign Assets Control is on systemic deficiencies that institutions can reasonably identify, rather than isolated individual errors.
This enforcement orientation is directly relevant to financial institutions' concerns about permissionless networks.
Whether it is anti-money laundering, countering the financing of terrorism, or sanctions systems, the requirements are to implement corresponding controls for identified risks, and such controls can absolutely be implemented on permissionless networks. Violations caused by indirect pathways or unintentional conduct should not automatically become a reason for financial institutions to bear corresponding compliance risk.
Do Financial Institutions Need to Identify and Screen Every Validator?
Financial institutions should treat permissionless networks as infrastructure, just as they have long treated the public internet and telephone networks as infrastructure.
The public internet and telephone networks are shared systems, and financial institutions neither know nor screen the other users and operators within them. Financial institutions should adopt a compliance approach consistent with this for permissionless networks.
Currently, financial institutions are cautious about permissionless networks, with the primary concern being inadvertent contact with sanctioned entities or entities engaged in illicit activity, without their knowledge or active choice.
For example, financial institutions may worry about paying network fees to validators operating on behalf of sanctioned entities, inadvertently transacting with sanctioned entities, or receiving and trading cryptocurrencies that previously interacted with illicit entities.
However, unintentional contact with validators or other network participants located in sanctioned jurisdictions is not the conduct that sanctions regulations are designed to address.
This issue is not merely about geography. A validator could be a sanctioned entity operating anywhere, but the financial institution did not actively choose that validator, did not enter into a contract with it, did not export goods or services to it, and did not provide financing or engage in any other transaction with it.
The network fees that ultimately flow to validators result from the network protocol applying the same rules to all users.
Regulators have confirmed this point.
For example, in November 2025, the U.S. Office of the Comptroller of the Currency issued Interpretive Letter No. 1186, confirming that banks can pay network fees on blockchain networks and can hold the cryptocurrencies needed to pay those fees in their own name.
This interpretive letter continues the position of the Office of the Comptroller of the Currency in Interpretive Letter No. 1174, issued in January 2021, which stated that banks can operate nodes to validate, store, and record payment transactions. Since banks can operate nodes and participate in transaction recording, it is a natural extension of this conclusion that banks can receive the network fees earned by nodes.
The interpretive letter uses Ethereum as an example. Ethereum is a permissionless network whose protocol selects validators in a pseudo-random manner. This series of interpretive letters does not distinguish between permissioned and permissionless networks.
When a financial institution initiates a transaction on a permissionless network, the protocol assigns the right to propose a block containing that transaction to a specific validator. Typically, this process is pseudo-random and proportional to the validator's stake.
The network protocol determines the corresponding fees based on network demand and the computational resources consumed by the transaction. Therefore, financial institutions cannot choose the validator that processes their transactions, cannot negotiate fees with validators, and cannot know which specific validator processed the transaction before or after it occurs.
All users on the network must follow the same rules.
This relationship is somewhat analogous to that between an email sender and the router operator carrying that email, and between a telephone caller and the switch operator responsible for completing the call connection.
If a U.S. financial institution sends internet protocol data packets that pass through infrastructure located in a sanctioned jurisdiction, it would not be considered a sanctions violation solely for that reason. The same "neutral, protocol-automated transmission" analysis can apply to the consensus layer of permissionless networks.
The Bank Secrecy Act itself recognizes this distinction. The Act explicitly excludes entities that "provide delivery, communication, or network access services solely to support funds transfer services" from the regulatory definition.
The Bank Secrecy Act distinguishes between neutral transmission and transactional conduct, and sanctions analysis similarly focuses on whether there is active selection, direction, or transactional conduct between parties.
While financial institutions transacting on permissionless networks may indeed have some contact with unscreened network operators, this contact is not the same as the conduct regulated by sanctions regulations.
In the latter case, neither party actively chose the other.
From a broader perspective, it has been nearly five years since the Office of Foreign Assets Control issued its "Sanctions Compliance Guidance for the Virtual Currency Industry." During this period, there has been no enforcement action taken because a block proposed by a validator happened to contain a transaction involving a sanctioned entity, nor any enforcement action taken because market participants paid network fees at the protocol layer.
Can Public Ledgers Balance Privacy and Compliance?
The second concern raised by institutions is privacy: can banks transact on public ledgers without exposing customer positions, counterparties, and trading strategies to competitors?
The early primary argument in favor of permissionless ledgers was the belief that full transparency itself could be a compliance asset.
However, the actual requirements of financial compliance are narrower: necessary information must be verifiable by financial institutions, counterparties, and regulatory or supervisory authorities.
Today, cryptographic techniques have advanced to the point where institutions can prove a compliance-related fact without publicly disclosing all the data behind that fact.
For example, an institution can prove that a counterparty is not on the "Specially Designated Nationals" list, or that reserves exceed liabilities, without revealing the contents of the ledger or the identity of the counterparty.
Provenance verification can allow a party to prove that an asset originated from a previously identified set of illicit assets, without publicly disclosing the full transaction relationship graph.
Confidential transfer solutions can encrypt amounts and balances on the ledger while retaining a viewing key for financial institutions to provide to auditors during examinations.
These cryptographic techniques, when combined, can provide regulators with stronger verification assurances than closed systems, while not disclosing any information to competitors.
Therefore, privacy is no longer a barrier to using permissionless networks; on the contrary, it may become a reason for financial institutions to choose such networks.
Some of these technologies are already in practical use, while others are still in the research and development stage.
Address rotation and account abstraction have entered practical use. Aggregated accounts and layered custody structures can also retain detailed customer-level information off-ledger. Meanwhile, related communication protocols can transmit "travel rule" data alongside on-chain transfers.
Confidential transfer solutions with audit keys have begun deployment, but their application in institutional business is currently limited.
Solutions for proving that an entity is not sanctioned, and solutions for proving asset provenance against specific lists, are still in pilot and research stages.
However, relevant solutions do exist. For example, Privacy Cash is a privacy protocol deployed on Ethereum and Solana that uses zero-knowledge proofs to support confidential transfers and exchanges.
How to Build a Compliance Framework?
We propose a financial compliance framework applicable to activities on permissionless networks, consisting of nine components.
Among them, transaction-layer controls primarily target institutional customers and counterparties, and their form is typically similar to the controls financial institutions currently use; network-layer controls target the underlying infrastructure itself.
These measures do not require financial institutions to identify validators, nor to enter into service level agreements with specific protocols, nor to apply for network membership from gatekeepers. These are typical features of permissioned networks, but current financial compliance regulations do not impose such requirements.
This framework is also consistent with the recently passed "GENIUS Act" in the United States.
The GENIUS Act adopts a similar framework: anti-money laundering, countering the financing of terrorism, and sanctions controls should be implemented at the application layer, by entities that know customer identities and can control assets.
The Act requires issuers authorized to issue payment stablecoins, as clearly defined regulated entities at the application layer, to demonstrate that they have established anti-money laundering and sanctions compliance programs, and have the technical capability to freeze or destroy circulating stablecoins under lawful orders.
These obligations are borne by stablecoin issuers, not by the permissionless networks on which the stablecoins circulate.
Decades ago, regulated financial institutions also faced an open, global, permissionless network. Anyone could join this network, and it carried communication traffic from both legitimate and illicit users.
Financial institutions ultimately built their businesses on the open protocols of the internet, and established corresponding controls at the application layer.
Today, this approach can also be applied to permissionless networks.
Avoiding permissionless networks is not a financial compliance strategy; on the contrary, it is abandoning the role that U.S. financial institutions have long played in enhancing the resilience, information transparency, and risk management capabilities of the dollar-based financial system.
In fact, regardless of whether U.S. financial institutions participate, dollar-denominated activity is already occurring on permissionless networks and will continue to grow.
Whether U.S. financial enforcement can effectively cover relevant activities depends on whether regulators can see financial flows. The institutional design, implementation, and enforcement behind financial compliance regulations also rely on U.S. financial institutions actively observing and monitoring these activities.
If financial institutions choose to avoid permissionless networks due to misreading relevant laws or concerns about past regulatory positions, they will ultimately lose the opportunity to offer more products and services to customers using open networks.
This content is for informational and educational purposes only and does not constitute investment advice related to BTCC. BTCC makes every effort but cannot guarantee the truthfulness, accuracy, or originality of the content above.