Most financial transactions today involve an intermediary such as a bank or broker that helps track where money comes from and where it goes. Traditionally, this system has made sure that financial activity can be monitored and verified. But imagine a financial service that does not need a bank, broker or other traditional intermediary. You can borrow, lend, or trade assets simply by connecting a digital wallet to a blockchain-based application. If you want to lend, a smart contract automatically matches you with a borrower and transfers interest payments to you once repayment conditions are met.

This is the basic idea behind decentralised finance, or DeFi, a rapidly growing landscape. According to a recent report by the Financial Action Task Force (FATF), the value of assets locked in DeFi arrangements reached around $86.6 billion in 2026, an increase of about 85% since 2023. The technology offers genuine benefits: people can send money across borders faster, transparently, and with only a smartphone and access to the internet. But DeFi’s rapid growth also creates a difficult question for regulators: who is responsible when a financial service is delivered by code rather than a traditional financial institution?

The FATF report makes a key observation that further complicates this question: the technology may be decentralised, but control over the technology may not be. A DeFi application may operate through smart contracts, but decisions about how those contracts work can still be influenced by a group of identifiable people. Developers may still be able to change or update the system, a small group may own most of the voting power, or a company may run the website people use to access the service.

The report therefore urges regulators to look closely at how control is distributed and identify who actually controls or influences a DeFi arrangement. It recommends that where a DeFi arrangement is effectively controlled by identifiable people, those individuals or entities should come within existing regulatory framework like AML laws. This could include developers, governance-token holders, investors or others who can meaningfully influence how the arrangement operates. Where such arrangements provide financial services, jurisdictions should consider licensing or registration requirements.
FATF also recommends that countries assess the risks DeFi poses within their own markets, such as risk stemming from cross-border activity. Regulators should guide banks, virtual asset service providers and other businesses that interact with DeFi, while exploring new tools such as blockchain analytics and digital identity to manage illicit finance risks.

Importantly, FATF is careful not to suggest that all DeFi arrangements should be regulated like traditional financial institutions, since they may not fit easily within existing rules and frameworks. Instead, the report calls for a practical approach that focuses on real-world risks and how the system actually works. Regulation should focus on what a DeFi arrangement actually does, who has influence over it, and what risks it creates, rather than simply how it describes itself.
The FATF report is a reminder that the next stage of VDA regulation will require regulators to look beyond individual products and borders. As financial services built around VDAs become increasingly interconnected, effective oversight will depend not only on stronger domestic rules, but also on greater international coordination to ensure that regulatory gaps do not become opportunities for financial crime.