Key Highlights
- a16z crypto says financial institutions do not need permissioned blockchains to meet U.S. AML and sanctions requirements.
- The firm argues that existing laws require reasonable risk controls rather than eliminating all potential exposure.
- Its proposed framework includes KYC, wallet screening, transaction monitoring, sanctions controls, and third-party risk management.
a16z crypto has published a new framework arguing that financial institutions can operate on permissionless blockchain networks while meeting existing U.S. anti-money laundering (AML), counter-terrorist financing (CFT), and sanctions requirements.
The paper, titled “The Compatibility of Permissionless Networks and Financial Integrity: A Practical Guide for Financial Institutions,” addresses a concern that has limited some traditional financial institutions from using public blockchains: the possibility of interacting with unknown validators, wallets, or other network participants.
Rather than requiring institutions to identify or control the underlying blockchain infrastructure, the paper argues that compliance controls can be applied at the layers where financial institutions have direct knowledge and control, such as customers, counterparties and transactions.
a16z challenges permissioned-blockchain approach
The paper comes as several financial institutions have begun deploying tokenized products on public blockchains.
a16z crypto points to Franklin Templeton, which has maintained the share register for its onchain U.S. government money fund on permissionless blockchains since 2021 and added Solana in 2025.
It also cites BlackRock’s tokenized money market fund, which has operated on Ethereum since 2024, and Apollo’s tokenized access to its Diversified Credit Fund across six permissionless networks.
Despite those developments, a16z argues that some banks, broker-dealers and asset managers continue to favor permissioned networks because of concerns that public blockchains may be incompatible with financial integrity requirements.
The paper takes a different view, arguing that U.S. AML and sanctions laws do not require financial institutions to control the blockchain infrastructure through which their transactions are processed.
Financial integrity rules focus on risk management
A central argument in the paper is that U.S. financial integrity laws do not require institutions to eliminate every possible compliance risk.
Instead, a16z points to the Bank Secrecy Act (BSA) and sanctions rules as requiring institutions to maintain reasonably designed programs capable of identifying, monitoring, and managing relevant risks.
Under this approach, an institution using a permissionless network would remain responsible for screening its customers and counterparties, monitoring transactions and reporting suspicious activity.
However, it would not necessarily be responsible for identifying every validator or other participant involved in processing a blockchain transaction.
The paper compares this relationship to shared infrastructure such as the internet, where users generally do not select or screen the individual operators responsible for routing their communications.
Unknown validators are a key compliance question
One issue examined in the paper is the possibility that a financial institution could unknowingly pay a network fee to a validator located in a sanctioned jurisdiction.
a16z argues that such protocol-level interactions are different from directly selecting, contracting with, or providing funds to a sanctioned party.
The paper points to an OCC interpretive letter issued in November 2025, which it says confirmed that banks may pay blockchain network fees and hold the crypto assets necessary to pay those fees.
It also references an earlier OCC interpretation allowing banks to validate, store, and record payment transactions by operating blockchain nodes.
According to a16z, these interpretations do not establish a separate compliance requirement for permissionless networks.
The paper further notes that, in the nearly five years since OFAC issued its sanctions compliance guidance for the virtual currency industry, it has not identified an enforcement action based solely on a validator processing a sanctioned transaction or a market participant paying protocol-level fees.
Proposed framework places controls at multiple layers
a16z’s framework proposes nine components for financial institutions using permissionless networks, covering: governance and risk assessment, customer-level KYC and due diligence, wallet and counterparty screening, onchain transaction monitoring and reporting, Travel Rule and Funds Transfer Rule compliance.
It also adds risk-based sanctions controls, third-party risk management, wallet and key management and cybersecurity, and testing, auditing, training and compliance expertise.
The framework separates controls relating to customers and transactions from those involving the underlying network infrastructure.
That distinction matters because a permissionless blockchain does not generally provide a central operator capable of approving participants or screening validators.
Privacy does not necessarily conflict with compliance
The paper also addresses another concern surrounding public blockchains: the visibility of transaction data.
While public ledgers can expose wallet balances, transaction histories, and counterparties, a16z argues that financial institutions do not necessarily need to publish all compliance-related information onchain.
The paper highlights cryptographic techniques that can allow institutions to prove specific facts without revealing the underlying data.
For example, Zero-knowledge systems could potentially demonstrate that a counterparty is not on a sanctions list or that reserves exceed liabilities without publishing the counterparty’s identity or complete financial records.
Other approaches include confidential transfers, viewing keys, address rotation, account abstraction, and different custody structures.
However, the paper acknowledges that some of these technologies remain at the pilot or research stage and have not yet been widely deployed at institutional scale.
GENIUS Act provides a recent regulatory example
a16z also connects its proposed approach to the GENIUS Act, arguing that the legislation places important AML and sanctions obligations on regulated stablecoin issuers rather than on the permissionless networks through which those stablecoins circulate.
Under the framework described in the paper, identifiable entities operating at the application layer are responsible for customer and transaction controls.
The distinction is relevant to institutions considering stablecoins and tokenized financial products on public blockchain networks.
a16z has also focused on onchain market infrastructure
The latest paper follows a broader series of a16z crypto research examining the infrastructure requirements of onchain financial markets.
On September 3, a16z argued that higher blockchain throughput was shifting attention toward predictable transaction execution, reliable access to blockspace, and privacy for pending transactions.
That research focused on transaction inclusion and ordering rather than AML compliance. The latest paper addresses a different part of the infrastructure question by examining how institutions can manage financial-integrity risks while using permissionless networks.
a16z’s recent work also extends into post-quantum cryptography.
On September 9, LayerZero introduced Akita, a lattice-based polynomial commitment scheme designed for post-quantum security in zero-knowledge proving systems. Its first deployment is planned for Jolt, the zero-knowledge virtual machine developed in partnership with a16z crypto.
LayerZero said Akita can reduce proof sizes and improve Jolt’s proving performance compared with existing approaches. Those figures are LayerZero’s claims and are separate from a16z’s financial-integrity framework.
The Akita project concerns zero-knowledge infrastructure and post-quantum security, rather than AML or sanctions compliance.
Public blockchains face a different institutional test
The paper frames the issue less as whether permissionless networks can support regulated financial activity and more as how institutions manage the associated compliance risks.
Financial institutions would still need to manage risks involving their customers, transactions, and service providers. Permissionless networks can make this more complicated because institutions do not control the underlying infrastructure or know every participant involved in processing transactions.
a16z argues that these risks can be addressed through controls at the customer, transaction and service-provider levels, rather than by requiring the underlying blockchain to become permissioned.
The paper comes as financial institutions evaluate stablecoins, tokenized funds, tokenized credit and other blockchain-based financial products on public networks such as Ethereum and Solana.
For institutions considering this infrastructure, the central question is whether they can maintain adequate compliance controls over their own activities without controlling every participant in the underlying network.
The paper leaves open how regulators and financial institutions will apply this approach as more regulated financial activity moves onto public blockchains.
Also Read: BitGo Enables Self-Custody Wallet Access to Hyperliquid Perpetuals
