2026 FATF Targeted Update Summarised: Part 2
The Financial Action Task Force (FATF) has published its 2026 Targeted Update on Implementation of the FATF Standards on Virtual Assets and Virtual Asset Service Providers.
The report assesses how jurisdictions are advancing their regulatory frameworks, supervision, and enforcement while highlighting the emerging money laundering, terrorist financing, and proliferation financing (ML/TF/PF) risks shaping the virtual asset ecosystem. Although implementation continues to improve, the FATF notes that many jurisdictions still face challenges moving beyond legislation to effective supervision and enforcement.
In this blog, we summarise the report's key findings surrounding AI in virtual asset crimes, the challenges and risks stablecoins, self-hosted wallets and DeFi pose.
Access 2026 FATF Targeted Update Summarised: Part 1 for updates on R.15’s global progress, the implementation and enforcement of the Travel Rule, developments in licensing and supervision, and the emerging risks shaping the next phase of virtual asset regulation.
Artificial Intelligence Is Accelerating Virtual Asset Crime
For the first time, the FATF identifies artificial intelligence as an emerging factor amplifying virtual asset-enabled financial crime.
According to the report, criminals are increasingly using AI-generated identities, deepfake interviews, and synthetic profiles to gain victims' trust during investment and recruitment scams before stealing virtual assets.
The FATF also highlights that AI coding assistants and autonomous AI agents may enable attackers to identify vulnerabilities in smart contracts, generate exploit code, and accelerate attacks against DeFi protocols and cross-chain infrastructure. Once assets are stolen, they can be rapidly fragmented through stablecoins, decentralised exchanges, bridges, and multiple VASPs, making tracing and asset recovery significantly more challenging.
The report concludes that AI should no longer be viewed solely as a technological development but as a structural risk factor that can significantly increase money laundering, terrorist financing, and sanctions evasion risks within the digital asset ecosystem.
Stablecoins Continue to Present Significant AML/CFT Challenges
Stablecoins remain one of the FATF's primary areas of concern.
The report highlights an emerging trend in which criminal organisations issue proprietary stablecoins specifically designed to avoid regulatory intervention. Unlike many established stablecoin issuers that retain the technical ability to freeze or block illicit assets when requested by competent authorities, these privately issued stablecoins are marketed as being resistant to asset freezes and regulatory oversight.
In one example, a Cambodia-based financial services conglomerate launched its own USD-pegged stablecoin after a third-party issuer froze more than USD 29 million in assets linked to suspected illicit activity. The FATF notes that such developments demonstrate how criminal organisations are actively attempting to reduce law enforcement's ability to disrupt illicit financial flows.
The report also notes that terrorist organisations, including ISIL and Al-Qaeda, increasingly favour stablecoins over Bitcoin, using rotating wallet addresses, multiple transfers, OTC brokers, and decentralised finance tools to obscure the movement of funds.
As a result, the FATF recommends that jurisdictions ensure stablecoin issuers are subject to robust AML/CFT requirements, including the technical capability to comply with lawful freeze and seizure orders.
Peer-to-Peer Transfers Through Self-hosted Wallets
The FATF continues to identify peer-to-peer (P2P) transactions conducted through self-hosted wallets as a significant risk area.
Because these transfers occur directly between users without an intermediary VASP, they typically fall outside AML/CFT obligations such as customer due diligence and suspicious transaction reporting. Although transactions remain visible on public blockchains, attribution is considerably more difficult when multiple self-hosted wallets are used to layer transactions across jurisdictions.
The 2026 survey found that 88% of responding jurisdictions (58 out of 66) consider P2P transactions to represent a high money laundering, terrorist financing, or proliferation financing risk. Despite this, only 23% of jurisdictions (31 of 133) reported collecting sufficient market data to assess the scale of P2P activity within their jurisdictions.
The FATF therefore encourages jurisdictions to improve monitoring of self-hosted wallet activity while strengthening data collection and risk assessments.
Offshore VASPs Remain a Global Supervisory Challenge
Offshore Virtual Asset Service Providers (oVASPs) continue to present one of the most significant regulatory challenges identified in the report.
The FATF notes that some offshore VASPs deliberately target customers in jurisdictions where they are not licensed, sometimes encouraging users to circumvent regulatory requirements through VPNs or by providing false information during onboarding. Others compete by maintaining weaker KYC standards and lower compliance costs, creating an uneven playing field for regulated VASPs.
The report also highlights the risks associated with nested relationships, where offshore VASPs gain access to liquidity and banking services through accounts held at licensed domestic VASPs while presenting themselves as ordinary retail customers. Where host institutions maintain weak AML/CFT controls, these arrangements may expose them to sanctions risks and significant regulatory action.
To address these risks, an increasing number of jurisdictions are adopting activity-based licensing models that require offshore VASPs actively serving domestic customers to become licensed regardless of their physical location. Enforcement measures now include public warnings, app-store removals, restrictions on domestic financial services, and criminal prosecutions.
Learn more about oVASPs, read Understanding and Mitigating the Risks of oVASPs: A Summary
DeFi Regulation Continues to Lag Behind Innovation
The FATF concludes that decentralised finance remains one of the most difficult areas for regulators.
Only 18% of responding jurisdictions (26 of 142) have conducted dedicated DeFi risk assessments, while 93% reported that they have not identified DeFi arrangements operating within their jurisdictions that qualify as VASPs under the FATF Standards.
Although 31% of jurisdictions stated that their AML/CFT risk mitigation measures apply to DeFi, only four jurisdictions have introduced licensing or registration requirements for qualifying DeFi arrangements, and just two have successfully licensed or registered them in practice. Only one jurisdiction reported taking enforcement action against a DeFi arrangement.
The FATF attributes these challenges to the difficulty of identifying individuals exercising control or sufficient influence over decentralised protocols, together with the technical complexity and cross-border nature of many DeFi ecosystems. To support regulators, the FATF has published a dedicated report examining regulatory challenges associated with decentralised finance.
In Conclusion
The 2026 Targeted Update demonstrates that global implementation of the FATF Standards continues to progress, with more jurisdictions introducing regulatory frameworks, licensing VASPs, and implementing the Travel Rule. However, the report makes it clear that effective supervision, enforcement, and international cooperation remain essential to achieving the objectives of Recommendation 15.
Request a demo and learn more about 21 Travel Rule - the Travel Rule solution that ensures Travel Rule compliance no matter what.
Disclaimer
This material is provided for educational and informational purposes only and is not intended to be a substitute for professional advice or detailed research.
