Anti-money-laundering (AML) and know-your-customer (KYC) frameworks impose customer-identification, transaction-monitoring, and suspicious-activity-reporting requirements on Bitcoin-related businesses worldwide. The principal standard-setter is FATF (Financial Action Task Force), whose 2019 Recommendation 15 and the associated "Travel Rule" application to virtual assets created the structural framework that flows through to national-level implementations. The Travel Rule requires Virtual Asset Service Providers (VASPs — FATF's term, equivalent to MiCA's CASPs) to share originator and beneficiary information for transactions above specified thresholds (typically USD/EUR 1,000–3,000). Compliance is uneven: major US, EU, and UK exchanges are substantially compliant; smaller and emerging-jurisdiction exchanges vary widely. Treatment of self-custody (unhosted-wallet) transfers is the most-contested aspect, ranging from intrusive counterparty-information collection to risk-based monitoring. Privacy-tool regulation (CoinJoin, Wasabi/Samourai, Tornado Cash) is the leading edge of AML/KYC tension with Bitcoin's self-custody and privacy properties.


Why this note matters

AML/KYC frameworks are the principal regulatory mechanism by which Bitcoin operations are linked to traditional financial-system identification and reporting infrastructure. Every centralized exchange, custodian, and Bitcoin-related service that operates in any major jurisdiction is subject to AML/KYC requirements; the operational and privacy implications flow through to all Bitcoin users who interact with regulated services.

Understanding the FATF Travel Rule and its national implementations is the precondition for engaging the regulatory-vs-self-custody-privacy tension that characterizes much of contemporary Bitcoin policy. The framework also shapes Bitcoin’s interaction with the broader financial system: KYC information collected by exchanges connects Bitcoin holdings to fiat-system identity in ways that have substantial downstream operational consequences.


FATF and the international framework

The Financial Action Task Force is an inter-governmental body of 39 member jurisdictions (plus 2 regional organizations) that sets international standards on AML, counter-terrorist-financing (CTF), and counter-proliferation-financing. FATF’s framework is non-binding under international law but member jurisdictions face economic and diplomatic consequences for non-compliance — specifically, FATF maintains a “grey list” and “black list” of jurisdictions with inadequate AML frameworks, which can affect international banking relationships and aid eligibility.

FATF’s principal Bitcoin-related provisions:

  • Recommendation 15 (October 2018) — extends AML/CTF obligations to “virtual assets” and “virtual asset service providers” (VASPs). The Recommendation requires member jurisdictions to license or register VASPs and to apply AML/CTF supervision.
  • Travel Rule (June 2019) — extends Recommendation 16 (originally a wire-transfer requirement) to virtual asset transfers between VASPs. VASPs must transmit originator and beneficiary information for transfers above specified thresholds.
  • Updated guidance (October 2021) — clarifies application to DeFi, NFTs, peer-to-peer transactions, and various edge cases.

The threshold question. FATF recommends a threshold of USD/EUR 1,000 for Travel Rule application. National implementations vary: some jurisdictions apply lower thresholds (Singapore: SGD 1,500); some apply higher (Switzerland: CHF 1,000); some apply no threshold (every transfer subject to information sharing). The threshold determines the compliance burden and the regulatory reach.

VASP definition complexity. FATF’s VASP definition includes exchanges, custodians, brokers, and certain other intermediaries. The definition’s edge cases (DeFi protocols, software-only services, peer-to-peer platforms) are subject to ongoing FATF interpretation; national implementations vary in how these edges are treated.


National implementations

United States. FinCEN’s CVC and MSB frameworks (see US regulatory landscape). Travel Rule implementation through FinCEN’s BSA enforcement; reporting requirements through Form 8300 and SAR (Suspicious Activity Report) filings. Threshold: USD 3,000 for Travel-Rule application historically; specific Bitcoin-related thresholds and reporting requirements evolving.

European Union. MiCA framework (see EU MiCA framework) integrates Travel Rule for transfers above EUR 1,000. The TFR (Transfer of Funds Regulation) specifically addresses Bitcoin-and-crypto transfers.

United Kingdom. Post-Brexit framework. FCA (Financial Conduct Authority) AML supervision; Travel Rule implementation aligned with FATF guidance.

Singapore. MAS (Monetary Authority of Singapore) Payment Services Act framework; Travel Rule integrated; relatively crypto-friendly with strong AML compliance focus.

Switzerland. FINMA framework; Travel Rule integrated; banking-secrecy historically robust but AML compliance has tightened.

UAE. Dubai VARA framework; Abu Dhabi ADGM framework; crypto-friendly with substantial AML compliance.

Hong Kong. Pro-crypto-trading framework post-2023; AML compliance integrated.

Various emerging-market jurisdictions. Implementation varies widely; many jurisdictions are below FATF compliance standards, producing FATF-greylist-risk.

The geographic compliance landscape. Major financial-center jurisdictions are substantially FATF-compliant for crypto. Emerging-market and certain politically-isolated jurisdictions (Russia, Iran, North Korea) are not. The compliance differential creates regulatory-arbitrage opportunities and FATF-greylist enforcement pressure.


The self-custody question

The principal point of AML/KYC-and-Bitcoin tension is the self-custody (unhosted-wallet) treatment:

The competing positions:

  • Aggressive enforcement position. VASPs must collect originator and beneficiary information even for transfers to/from self-custody wallets. The framing: self-custody users are equivalent to bank-account-holders for AML purposes.
  • Risk-based position (FATF’s current framework). VASPs apply risk-based monitoring to self-custody transfers but are not required to collect counterparty identity information for self-custody. The framing: self-custody users are different from bank-account-holders; intrusive identity-collection is not warranted.
  • Privacy-preserving position. Self-custody transfers should be entirely outside AML/KYC frameworks. The framing: AML/KYC frameworks apply to financial intermediaries, not to individuals exercising sovereign control over their own assets.

FATF’s current guidance is the risk-based position. National implementations vary; the EU’s MiCA framework adopted the risk-based position; some jurisdictions have taken more aggressive positions; some less.

The structural tension. Bitcoin’s design philosophy treats self-custody as the default and intermediated custody as the operational exception (per cypherpunk principles). AML/KYC frameworks are designed for intermediated finance; applying them to self-custody creates conceptual friction. The risk-based-monitoring approach is a compromise that imposes operational burden on VASPs without directly requiring self-custody users to surrender identity.


The privacy-tool regulatory frontier

The most-contested AML/KYC-and-Bitcoin questions concern privacy-enhancing tools:

  • CoinJoin and Wasabi/Samourai history: Wasabi Wallet (Zksnacks operations) ceased serving US users in 2024 in response to regulatory pressure; Samourai Wallet’s developers were criminally charged in 2024. The substantive event-level engagement is in Tornado Cash sanctions and the privacy-tool regulatory landscape (Controversies).
  • Lightning privacy: Lightning’s privacy properties (onion routing; channel-level privacy) create AML/KYC complications. Lightning Service Providers face the same VASP-classification questions; the regulatory framework is still evolving.
  • Stealth addresses and Silent Payments: Newer privacy-enhancing protocols (Silent Payments specifically) provide receiver-privacy that complicates the typical KYC-at-exchange model. The regulatory implications are not yet engaged at depth in any national framework.

The Tornado Cash precedent. US OFAC sanctions on the Tornado Cash protocol (August 2022) and subsequent criminal charges against developers (April 2024) established a precedent for regulatory enforcement against privacy-tool developers. The principle that smart-contract code itself could be sanctioned was overturned by the November 2024 Fifth Circuit ruling, after which OFAC formally delisted the protocol in March 2025 — but the episode nonetheless shaped the broader Bitcoin-privacy-tool regulatory landscape, and developer-liability enforcement continued under money-transmission law (see Tornado Cash sanctions and the privacy-tool regulatory landscape).


Counter-arguments and tensions

Privacy-vs-AML tradeoff. The fundamental tension: financial-privacy is a legitimate interest; AML enforcement against actual money laundering is a legitimate interest. Frameworks that aggressively enforce AML risk overriding legitimate privacy; frameworks that prioritize privacy risk inadequate AML enforcement. The empirical balance is contested.

The effectiveness question. Critics argue that AML/KYC frameworks are operationally ineffective at preventing actual money laundering — sophisticated criminals work around the frameworks, while ordinary users bear the compliance burden. UN-and-IMF studies have suggested that AML programs catch a small fraction of total laundered funds. Defenders argue that some enforcement is better than none, and that the framework has deterrent effects beyond direct catches.

Self-custody-vs-intermediated regulation. The regulatory framework’s awkward fit with self-custody creates ongoing tension. Critics of aggressive enforcement argue that AML frameworks should apply only to intermediaries, not to individuals. Defenders argue that bright lines are difficult to draw and that risk-based approaches are appropriate.

The Travel Rule’s privacy implications. The Travel Rule transmits sender and receiver identity information across VASPs. This creates a structural mass-identity-collection-and-sharing infrastructure that critics argue is disproportionate to AML benefits. Defenders argue the framework parallels traditional wire-transfer reporting.

The Tornado Cash precedent and software-as-sanctioned. The OFAC sanctions on smart-contract code raised concerns about whether software development itself could be sanctioned. The Fifth Circuit ruling partially limited this; the broader precedent remains contested. See Tornado Cash sanctions and the privacy-tool regulatory landscape for substantive event-level engagement.


Open questions for further development

  • How does FATF’s framework evolve as Bitcoin Layer-2 (Lightning, Fedimint, Cashu) grows? Current guidance was designed for base-layer crypto.
  • What is the long-run trajectory of self-custody regulatory treatment? Risk-based approaches may tighten or loosen.
  • How does the privacy-tool regulatory landscape evolve post-Tornado-Cash? Court rulings and OFAC enforcement priorities shape this.
  • Will alternative AML approaches emerge? Zero-knowledge-proof-based compliance, regulatory-sandboxes, and other approaches are being explored but not yet deployed at scale.
  • How does the AML framework interact with sovereign Bitcoin adoption? Sovereigns adopting Bitcoin as legal tender may have different AML postures; the policy interaction is unsettled.

Canonical sources for this note

  • FATF Virtual Assets and VASP guidance: fatf-gafi.org
  • FinCEN public guidance on CVC and MSB
  • MiCA Travel-Rule integration: eur-lex.europa.eu
  • Coin Center AML analysis: coincenter.org
  • Bitcoin Policy Institute AML analysis
  • Various academic legal scholarship: privacy-law, AML-law, Bitcoin-law programs
  • Chainalysis Crypto Crime Report — empirical engagement with crypto-related financial crime (industry-aligned framing)
  • Various Treasury sanctions and FinCEN enforcement actions — primary regulatory data