Regulators Say Crypto Compliance Laws Are Outpacing Enforcement: Here's What Has to Change
Regulators worldwide have passed more crypto compliance laws than they can actually enforce, creating a widening gap that criminals are actively exploiting. According to the Financial Action Task Force (FATF), a global policymaking body that tracks virtual asset regulation, 86% of jurisdictions have conducted risk assessments and 83% have passed Travel Rule legislation (which requires exchanges to share customer data like traditional banks do). But fewer than 10% of those jurisdictions have actually implemented preventive anti-money laundering and counter-terrorism financing (AML/CFT) measures to stop illicit activity before it happens.
Why Is Enforcement Lagging So Far Behind Legislation?
The problem is stark: 60% of jurisdictions with Travel Rule laws have taken zero supervisory or enforcement action on them. Among the 95 jurisdictions requiring virtual asset service provider (VASP) licensing, only 81% are conducting supervisory inspections, and just 71% have taken enforcement actions. Even more troubling, 73% of jurisdictions require VASP licensing, but only 58% have actually issued one.
This enforcement gap matters because criminals are moving faster than regulators. The FATF's latest report, released July 16, 2026, flags five escalating threats that are reshaping how illicit actors operate in crypto. These include industrialized fraud networks, proprietary stablecoins designed to resist asset freezing, artificial intelligence amplifying money laundering and sanctions evasion, and the convergence of proliferation financing, terrorist financing, and sanctions evasion into shared criminal infrastructure.
What New Criminal Tactics Are Emerging in Crypto?
One of the most concerning developments is the rise of "freeze-resistant" stablecoins. After a third-party issuer froze over $29 million in wallets, the same criminal conglomerate launched a USD-pegged stablecoin marketed as immune to asset freezing, issued across multiple public blockchains and a proprietary chain. The FATF warns that virtual asset service providers "may be unable to rely on issuer-level asset freeze/burn mechanisms as a compliance safeguard" and is calling for stablecoin issuance to be subject to robust AML/CFT requirements.
Terrorist organizations including ISIL and Al-Qaeda are also increasingly favoring stablecoins over Bitcoin for fundraising and transfers. Stablecoins now account for 84% of all illicit transaction volume, a dramatic shift from the early days of crypto crime when Bitcoin dominated.
Artificial intelligence is accelerating every stage of criminal activity. The FATF frames AI not as a standalone technical risk but as "a structural factor that can amplify ML/TF and sanctions-evasion risks." Real-world cases include deepfake recruitment scams that have stolen over $1 million, AI-assisted smart contract exploit development, and the use of open-weight AI models to bypass commercial AI safeguards. According to Chainalysis, AI impersonation scams were the fastest-growing fraud subcategory in the past year.
How Can Regulators Close the Enforcement Gap?
The FATF's message to regulators is unambiguous: the grace period for paper-only compliance is over. Jurisdictions need to move from passing laws to actively enforcing them. The report lays out three clear priorities for the public sector:
- Know Your Risks: Even jurisdictions that have banned virtual assets need to assess their exposure comprehensively, including domestic VASPs, offshore VASPs serving local customers, and stablecoin issuers. Banning activity alone is not enough to ensure compliance; only an effective monitoring regime can accomplish that.
- Deploy Blockchain Analytics at Scale: Unlike traditional financial systems where transaction visibility depends on intermediary reporting after the fact, crypto's on-chain transparency and sophisticated analytical tools lend themselves to genuinely preventive measures. Screening, blocking, and flagging risks before funds move can create a fundamentally safer financial environment.
- Address DeFi Regulatory Blind Spots: 93% of jurisdictions have not identified qualifying decentralized finance (DeFi) arrangements where there is an identifiable owner or operator that can be subject to VASP regulation. Only four jurisdictions have imposed licensing requirements, two have licensed one, and one has enforced. The FATF has published a Targeted Report on Regulatory Challenges from Decentralized Finance to provide further guidance.
The FATF's recommendations to the private sector explicitly list wallet screening, blacklisting and whitelisting, blockchain analytics tools, and freezing and blocking capabilities as expected components of a compliant AML/CFT framework.
The enforcement gap is particularly dangerous because organized crime is becoming more sophisticated. A single Cambodia-based conglomerate laundered at least $4 billion between August 2021 and January 2025, serving as a node connecting organized crime fraud, underground banking, and virtual asset-based laundering. At least $37 million of that was attributed to North Korean cyber heists supporting weapons of mass destruction programs. Spain's Operation Borrelli dismantled a separate 460 million euro investment fraud network affecting more than 5,000 victims worldwide.
The challenge ahead is clear: regulators must move from legislative action to enforcement action, and they must do so quickly. The tools to close the gap already exist, but deploying them at scale requires political will, funding, and coordination across jurisdictions. Until enforcement catches up with legislation, the gap between what regulators intend and what actually happens on-chain will continue to widen.