FATF Reports Rising Crypto Travel Rule Adoption but Enforcement Gap Persists
Key Takeaways
- •FATF found that 83% of surveyed jurisdictions have passed legislation implementing the crypto Travel Rule.
- •Only 40% of jurisdictions with Travel Rule laws have taken supervisory or enforcement measures.
- •The Travel Rule requires virtual asset service providers to collect and transmit originator and beneficiary information for qualifying transfers.
- •FATF identified DeFi, unhosted wallets, DPRK cyber theft and freeze-resistant stablecoins as areas of heightened concern.
- •The report indicates that global crypto oversight is shifting from passing laws to enforcing compliance through supervision and penalties.

The Financial Action Task Force (FATF), the Paris-based intergovernmental body that sets global anti-money-laundering and counter-terrorism-financing standards, reports that an increasing number of jurisdictions are enacting cryptocurrency regulations, but enforcement continues to lag significantly behind legislative progress.
In its Seventh Targeted Update on the implementation of FATF standards for virtual assets and virtual asset service providers (VASPs), the global watchdog found that 83% of surveyed jurisdictions have passed legislation implementing the Travel Rule, up from 73% in 2025.
However, the report also reveals that only 40% of jurisdictions with Travel Rule legislation on the books have actually taken supervisory or enforcement actions. In other words, while more countries now have formal rules in place, far fewer are actively policing compliance in a meaningful way. That gap has emerged as the central challenge identified in the update.
Laws Are Outpacing Enforcement
The Travel Rule stands as one of the most consequential compliance standards in the cryptocurrency sector. It extends FATF Recommendation 16 — a longstanding requirement that banks share sender and beneficiary details for wire transfers — to virtual asset transactions. It requires virtual asset service providers to collect and transmit originator and beneficiary information for qualifying transfers. In practical terms, regulators want crypto intermediaries to know who is sending and receiving funds, particularly when transfers cross between regulated platforms.
FATF first applied its standards to virtual assets in 2019, and the Travel Rule has since become the litmus test for whether a jurisdiction is serious about crypto AML compliance. According to FATF, most surveyed jurisdictions have now moved the rule into law — a significant shift from the earlier period when many countries were still weighing whether to regulate VASPs at all. The EU, for instance, embedded Travel Rule obligations into its broader Markets in Crypto-Assets (MiCA) regulation, which began taking effect in 2024.
Yet legislation is only an initial step. A rule that sits on the books without active supervision produces limited change. Exchanges, brokers, custodians, and payment firms require guidance, inspections, credible enforcement risk, and functional technical systems. Regulators need trained staff and appropriate tools. Cross-border cooperation mechanisms must work effectively. FATF's data indicates that implementation across these dimensions remains uneven.
Why the Enforcement Gap Matters
Crypto compliance has long faced a weakest-link problem. If one jurisdiction maintains strict rules while another enforces nothing, illicit actors can route activity through the weaker jurisdiction. This dynamic creates systemic pressure because cryptocurrency transactions are global by design. FATF's primary lever for pressuring laggard jurisdictions is its monitored jurisdictions list — often referred to as the grey list — which flags countries with strategic deficiencies in their AML/CFT frameworks and can carry reputational and financial consequences.
The enforcement gap is especially relevant for scams, money laundering networks, ransomware groups, and state-linked hacking operations. FATF's report specifically flags organized crime-linked scam centers, DPRK cyber theft, unhosted wallets, DeFi, and stablecoins designed to resist freezing as areas of heightened concern.
These categories illustrate how the risk landscape has evolved. The focus is no longer limited to rogue exchanges or conspicuous dark-market activity. It now encompasses large-scale scam compounds, sophisticated cyber operations, decentralized services, wallet infrastructure, and stablecoin architectures that may restrict the ability of issuers or intermediaries to freeze illicit funds — a considerably more complex environment for regulators to navigate.
DeFi Remains the Hardest Fit
DeFi presents one of the most difficult challenges within the FATF framework. The Travel Rule presupposes the existence of an intermediary capable of collecting and transmitting information. In DeFi, that intermediary may not exist in any traditional sense. A protocol may consist of smart contracts, frontends, governance participants, developers, validators, relayers, or some combination of these components.
Regulators consequently face a fundamental question: who bears responsibility? If a team controls a frontend, the frontend might become the enforcement point. If a DAO governs protocol parameters, governance participants could come under pressure. If users interact directly with smart contracts, enforcement becomes substantially more difficult.
FATF has been urging countries to prevent the label of "decentralized" from becoming a regulatory loophole. Translating that principle into practical supervision, however, is far from straightforward, which is why the enforcement gap carries heightened significance in the DeFi context.
Stablecoins Under the Microscope
Stablecoins feature prominently in the report's risk assessment. They represent one of crypto's most widely adopted use cases while simultaneously serving as one of the easiest instruments for rapidly moving value across borders. USDT, USDC, and other stablecoins have become core settlement assets for traders, businesses, remittance services, DeFi users, and, at times, illicit networks.
FATF's concern regarding freeze-resistant stablecoins centers on control. When a stablecoin issuer can freeze addresses, regulators may compel issuers to act against illicit funds. When a stablecoin is designed to resist freezing or lacks a clear issuer control point, that enforcement pathway weakens considerably.
This raises difficult questions about censorship resistance, user protection, and law enforcement access — questions that show no signs of resolution. Cryptocurrency users frequently value assets that cannot be easily frozen, while regulators worry those same characteristics can facilitate criminal activity.
The Next Phase: Supervision
The headline figure — 83% legislative adoption — demonstrates that cryptocurrency regulation has become mainstream. The more consequential number may prove to be the 40% enforcement rate. The next phase of global crypto oversight will be defined less by whether countries have written rules and more by whether they supervise firms, penalize violations, and cooperate across borders.
Exchanges and custodians will need to strengthen their Travel Rule compliance systems. DeFi frontends may face increased scrutiny. Stablecoin issuers will remain under sustained pressure.
For the industry, the message is clear: the compliance debate has moved beyond whether cryptocurrency should be regulated. It now centers on whether existing rules are being enforced consistently enough to satisfy global standard setters.
This article is based on FATF's Seventh Targeted Update on virtual assets and VASPs.