The Financial Action Task Force has been telling the world how to police crypto since 2018, when it published Recommendation 15 and handed regulators a playbook for virtual assets and the businesses that touch them. Every year since, it issues a report card on who is actually doing it. The 7th Targeted Update, released July 16 and analysed in depth by Chainalysis, is blunt in a way the prior six weren’t: legislation is finally arriving, but enforcement is nowhere close behind — and the criminal networks the rules were meant to stop have read the lag perfectly.
The headline number: paper is cheaper than enforcement
FATF surveyed 147 jurisdictions and the trend lines all point up. Eighty-six percent have now completed a virtual-asset risk assessment, up from 76 percent a year earlier. Eighty-three percent have passed Travel Rule legislation — the rule that obliges crypto businesses to pass counterparty identity data along with transfers — up from 73 percent. Among the 95 jurisdictions that require licensing virtual-asset service providers, 81 percent are now conducting supervisory inspections (up from 73) and 71 percent have taken enforcement actions.
On the surface, that is progress. But the update’s sharpest finding is in the gap between passing a law and doing anything with it. Sixty percent of jurisdictions that have Travel Rule legislation on the books have taken zero supervisory or enforcement action under it. When FATF scored jurisdictions on preventive anti-money-laundering controls — the safeguards meant to stop illicit activity before it moves — fewer than 10 percent, just 13 of 139, fully met the standard. The report’s message is explicit: the grace period for compliance on paper is over.
Banning is not monitoring
One of the update’s more uncomfortable findings concerns the jurisdictions that have chosen the simplest policy: prohibition. The share of jurisdictions banning VASPs outright has climbed to 23 percent, up from 11 percent in 2023. But FATF notes these bans have “not progressed” on enforcement. A prohibition with no monitoring does not make activity disappear; it pushes it into a blind spot where regulators cannot see it. For a technology whose entire value proposition is permissionless transfer, that is a feature for criminals and a dead end for supervision.
The licensing picture tells the same story from the other side. Seventy-three percent of jurisdictions require VASP licensing, but only 58 percent have actually issued a license. Only 40 percent satisfactorily meet the licensing criterion in mutual evaluations. The machinery exists; the throughput doesn’t.
The emerging risks the report flags
The update names five areas of escalating concern, several of which line up with what on-chain investigators are seeing in live cases:
Industrialised fraud. Cambodia-based scam centres and pig-butchering operations have become what FATF calls “significant generators of illicit proceeds.” The report cites a single Cambodia-based conglomerate that laundered at least USD 4 billion between August 2021 and January 2025, functioning as a node linking organised crime, underground banking, and virtual-asset laundering — and at least USD 37 million of that was attributed to North Korean cyber heists funding weapons programs. Spain’s Operation Borrelli separately dismantled a EUR 460 million investment-fraud network touching more than 5,000 victims. Chainalysis’ 2026 Crypto Crime Report puts scam activity at roughly USD 17 billion in 2025, with pig-butchering the single most damaging category.
Freeze-resistant stablecoins. After a third-party issuer froze over USD 29 million in its own wallets, that same conglomerate launched a USD-pegged stablecoin “marketed as immune to asset freezing,” issued across multiple public chains and a proprietary network. FATF warns that VASPs “may be unable to rely on issuer-level asset freeze/burn mechanisms as a compliance safeguard” and calls for stablecoin issuance to carry robust AML controls, extending the focus it established in its March 2026 stablecoin report. The urgency is not theoretical: the report notes terrorist organisations including ISIL and Al-Qaeda increasingly prefer stablecoins over Bitcoin for fundraising, consistent with Chainalysis’ finding that stablecoins now account for 84 percent of all illicit transaction volume.
AI as an amplifier. FATF does not treat AI as a standalone technical risk but as “a structural factor that can amplify ML/TF and sanctions-evasion risks” — deepfake recruitment scams that stole more than USD 1 million, AI-assisted smart-contract exploit development, and open-weight models used to bypass commercial AI safeguards. AI impersonation scams were the fastest-growing fraud subcategory in the prior year.
Convergence. Proliferation financing, terrorist financing, and sanctions evasion should “not be viewed as isolated risks” but as interconnected activity running over shared digital-asset rails. North Korea’s operators exploit VASPs, DeFi protocols, and third-party infrastructure including the very nodes and multi-party computation systems those systems depend on.
Offshore and P2P gaps. Offshore VASPs actively solicit customers, advise VPN use, and disguise themselves as ordinary users through nested accounts. Eighty-eight percent of jurisdictions rate peer-to-peer activity via unhosted wallets as high risk, yet only 23 percent collect metrics to measure it.
DeFi is still an undefined frontier
Perhaps the most consequential structural gap is governance, not enforcement. Ninety-three percent of jurisdictions have not identified any “qualifying DeFi arrangements” — the cases where an identifiable owner or operator exists who can be pulled into VASP regulation. Only four jurisdictions have imposed DeFi licensing requirements; two have licensed one; one has enforced. FATF has published a separate Targeted Report on Regulatory Challenges from Decentralised Finance to fill the guidance vacuum, but until a regulator can name who is accountable for a protocol, the rules simply don’t attach to it.
The crypto-native read
For anyone building or operating in this space, the update draws a fairly clear line between what is tolerated and what is not. Blockchain analytics — wallet screening, blacklist and whitelist controls, transaction tracing, and the capability to freeze flagged funds — is now listed by FATF as an expected baseline of a compliant AML/CFT program. A business that treats on-chain transparency as a feature to exploit rather than a control to deploy is on the wrong side of where enforcement is heading, even if its home jurisdiction hasn’t moved yet.
The deeper point is one FATF makes almost as an aside and Chainalysis stresses directly: unlike legacy finance, where visibility depends on intermediaries reporting after the fact, crypto’s on-chain record and mature analytics tooling make genuinely preventive controls possible — screening, blocking, and flagging risk before funds move instead of chasing them after. The tools to close the enforcement gap are already live. The update’s worry is that jurisdictions keep writing laws and skipping the part where they use them.
For builders, that argues for baking blockchain analytics and freeze controls into product design now, ahead of the regulator showing up. For investors, it is a reminder that the next wave of enforcement is not about whether crypto is regulated — it is — but about which jurisdictions and which operators can prove they actually enforce it. Licensing arbitrage still works today; the update’s trajectory says it is a depreciating asset, because the share of jurisdictions inspecting and sanctioning licensees rose meaningfully in a single year. The 7th report card says the gap between written law and applied law is the single biggest vulnerability in the system — and it is now the explicit target of the 8th.
