FATF DeFi compliance rules published on 21 July 2026 make one thing clear to UK banks, brokers and fintech platforms: easier technical access to decentralised finance does not transfer the legal responsibilities that come with it. The Financial Action Task Force (FATF) report, which updates the body’s 2021 guidance on virtual assets, confirms that regulated institutions bear anti-money laundering and counter-terrorism financing (AML/CFT) obligations when they use or integrate DeFi protocols, regardless of how those protocols are structured or marketed.
What the FATF Report Actually Says
The report sorts DeFi arrangements into three categories: those with an identifiable controller, those that are centralised in practice but whose controllers are difficult to identify, and those that are genuinely decentralised. The category does not remove the obligation; it determines how the institution must discharge it.
Where a controller can be identified, regulated firms must conduct customer due diligence (a formal process of verifying who you are dealing with) on the arrangement itself: confirm whether it is licensed or registered, assess whether it is adequately supervised, and review its AML/CFT framework.
Where no controller can be identified, or where the protocol is genuinely decentralised, institutions must apply AML/CFT measures directly to the underlying customers using the arrangement. Blockchain analytics can support that work, but the FATF DeFi report treats it as a supplementary tool, not a substitute for full compliance. If neither path can be completed, FATF recommends avoiding the protocol entirely.
To help institutions make the determination, the report sets out a list of on-chain and off-chain indicators of control, giving firms a checklist-style approach to the controller-identification question.
Why This Matters Now: Fireblocks Earn and the Gateway Problem
The timing is not coincidental. Institutional entry points into DeFi are multiplying. Fireblocks, a custody platform used by banks and brokers to access digital-asset infrastructure, launched its Earn product on 15 April 2026, giving institutional clients on-chain lending exposure through Aave and Morpho. According to the Fireblocks Earn launch announcement, the company has secured more than $10 trillion in digital asset transactions to date and counts more than 2,400 institutional clients.
The Earn product routes stablecoin holdings through Aave and a curated vault managed by Sentora via Morpho, with approval workflows, signing and position tracking handled on the Fireblocks side. What Fireblocks does not claim is that it, Aave, or Morpho performs know-your-customer (KYC) checks on every underlying user of those protocols. That gap falls squarely on the institution using the gateway, under FATF’s framework.
The Fireblocks Earn product is described by Fireblocks as connecting clients to Aave, which it calls the largest and most widely deployed lending protocol in DeFi, with interest rates that adjust dynamically based on supply and demand. Existing Fireblocks customers must apply for early access, according to the Fireblocks blog.
The industry has tried to resolve the controller-identification problem before. Aave Arc, launched in 2022 with Fireblocks as a whitelister, restricted its liquidity pool to institutions that had already passed KYC. Project Guardian’s 2022 pilot, involving JPMorgan’s Kinexys, DBS and SBI Digital Asset Holdings, used a modified Aave Arc alongside W3C Verifiable Credentials to limit access to authorised participants while settling on public blockchain infrastructure. Both approaches front-loaded the controller question. Broader gateway products widen the pool, and the identification work must follow accordingly.
The Regulatory Gap the FATF DeFi Compliance Rules Expose
The scale of unfinished regulatory work makes the institutional duty heavier, not lighter. The FATF 7th Targeted Update on VA/VASPs surveyed 142 jurisdictions. Of those, only 26 had assessed DeFi-related risks, and 132 had not identified a single qualifying DeFi arrangement operating in their territory. Only four jurisdictions had implemented licensing or registration requirements for such arrangements; only two had actually licensed or registered one in practice.
A further 9% of responding jurisdictions (12 of 142) reported that a risk assessment including DeFi-related risks is currently under way. Meanwhile, 31% (44 of 142) said their risk-mitigation measures already apply to DeFi arrangements, and 35% (50 of 142) said their competent authorities have engaged with the private sector to better understand DeFi business models.
Those numbers sit against a backdrop of rapid market growth. Total Value Locked (TVL) in DeFi, a measure of assets deposited into protocols, stood at USD 86.644 billion as of 10 May 2026, up from USD 46.86 billion on 10 May 2023, according to DeFiLlama data cited in the FATF report.
For UK institutions considering DeFi yield products, the practical read is straightforward. The platform providing access is not the compliance officer. If a regulated firm cannot complete the controller-identification process for a given protocol, the FATF framework leaves it with one option: don’t use it. The question of whether existing gateway products make that determination easy enough to answer will be the compliance stress test of the next 12 months.

