Why Policy Needs Cypherpunks | Samuel Jacques Cloutier - Hash Directors
Ethereum Denver·Mon, Mar 9, 2026, 12:00 AM
🚀 Get Ready for ETHDenver 2026! 🚀 We're already hard at work preparing for next year's biggest Web3 event! Keep your eyes peeled for more info on ETHDenver 2026—it’s going to be epic! 🌟
Transcript
want to say thank you to Yev and Philiser for uh opening us up today. We're going to move on to our next talk which is why policy needs cipher punks by Samuel Jacier uh from hash directorships. Hi everyone. Thanks for coming and kudos to the organizers for being willing to put a talk with a slide like this after the attorney general and before the White House. I think that's great.
Most of you here have never likely never heard about the FATF, the OECD or KARF before, right? So, buckle up because I'm going to show you how they're responsible responsible for the billions you have to spend on KYC and compliance and the erosion of your privacy and what to do about it. But first, let's lay some groundwork. I'm sure most of you here have heard this quote before. It's from the Cippher Punk Manifesto from 1993.
Governments wanted to ban encryption for private use and the cipher punks fought back. They didn't care what the governments wanted. They knew what was right and they fought for it with code. Just imagine how the internet would look like today if we couldn't use encryption. We owe a huge debt to the people who pushed back.
Sometimes pushing back's necessary. I was a subject matter expert for the Cam Nan's government for digital asset services for the last seven years and I developed the regulatory framework there. I helped draft well over 20 pieces of legislation responsible for implementing KYC, AML and global standards. Laws that allow governments to supervise and regulate. Laws that give governments more power over people like you and me.
I led those projects to stop criminals, to stop bad people from abusing honest people. I did it for all the right reasons. But as I became more experienced doing policy, I noticed a few concerning issues and decided to speak up about them when I left the government a few months ago. Policy is what's what leads to laws. It's the process of taking a problem and issue and translating it into an actionable solution like a law.
Ideally, the needs of the population should lead the development of new policy. Citizens need something and people like me would find ways to fulfill that need. The citizens impacted by the laws then provide feedback to the lawmakers and the system revises the laws. That's the legislative policy cycle. When I joined the government to draft policy, that's what I thought I'd be doing.
But the first day when I joined the civil service, I was asked if I knew what the FETF was. I had no idea what it was at the time, but it quickly became the primary driving factor for my career for the next 7 years. The financial action t financial action task force is a global standard setting body that defines the standards for anti-moneyaundering that are applied around the world. It maintains and manages 40 standards for KYC and ML. The US had a large role to play in the creation of the FATF back in the late 80s.
The Bank Secrecy Act was actually a template used for the initial standards and now that law and others implement the FATF standards here in the US. Global bodies like the FATF centralize and harmonize policies around the world. Global harmonization has its advantages. It ensures all countries play by the same rules. It enforces cooperation and information sharing.
Harmonization also facilitates enforcement. Problem is though, it also has its drawbacks. Once a global standard becomes the baseline, deviations difficult, dampening innovation, decisions also shift from elected bodies to super national forums that are harder for citizens to scrutinize and influence. Global standards are one sizefits-all that can create unintended side effects for smaller or differently structured jurisdictions. Remember the policy development process?
Well, let's throw in a global standard setting body in there like the FETF for fun. Let's assume there's a need to change a law that implements one of the FETF standards like the Bank Secrecy Act. Like before, the needs identified and communicated to the policy development process. They however now need to ensure compliance with the global standards. So they send a delegate to the FATF plenary.
In the plenary the 40 member jurisdictions listen to proposed change and in turn then must take the proposal back to their countries for their policy teams to review. The policy teams review the proposal, make changes and suggestions and then go back to the FETF. The feedback typically revises the intended proposal because each of those countries have different laws, values and objectives. The new policy is then implemented in all the countries. The result is a new laws passed different than what you originally wanted and you had very little input in the policy process.
Sometimes the needs come directly from the FETF bypassing you altogether. I don't know about you, but this really is concerning for me. Policy should always come from the local citizens, not foreign entities. But doesn't the US control the FETF? In the FETF, decisions are made by consensus.
Every country's vote is equal. So, countries like China, South Africa, or Brazil, or EU countries have equal say when decisions are made. The president of the FATF sets priorities for his or her term. Countries like China can shape technical outputs by staffing, drafting, chairing, and coalition building in working groups. Many think the FATF standards ensure criminals are caught and prevented from spending their proceeds.
Right. Well, probably. Maybe. I have three principal issues with the FETF. One, it centralizes policy development away from the countries themselves and removes accountability of lawmaking from those who are actually impacted by those laws.
You. Secondly, member countries have vastly different understandings of due process, different cultures, and different respect for human rights. That means countries are able to export norms which may be foreign to us like surveillance or lack of privacy. Finally, countries are assessed for effectiveness in implementing the standards, but the standards themselves are not assessed for effectiveness. Once a standard's added, it doesn't get removed.
Any good project requires a feedback mechanism. You release an app, it doesn't bring in revenue, you change the app. The last time something was removed from the FTF standards was in 2012, and it was really minor. Either the recommendations and the AML standards are perfect and highly effective or nobody's dared to assess and revise them. In fact, the FETF process revises standards constantly, but to add to them, not to remove or revoke.
There's a deeper problem with the standards themselves, too. The entire AML infrastructure bends the long-established principle of criminal justice, innocent until proven guilty. If we're presumed innocent, why do banks frequently hold wires we receive and ask for us to prove and show they aren't the proceeds of a crime? In the eyes of anti-moneyaundering, we aren't presumed innocent. We're presumed of being capable of demonstrating the absence of criminality.
What this means is that there's an inherent assumption that every dollar that goes through your account is the potential proceed of a crime and that we're capable of proving that it isn't. Essentially, AML is about proving a negative, something that's logically impossible. If you ask the FATF though, that hold on your account is a preventative measure. So, it doesn't impede your rights at all. In practice, though, it sure seems like our money is being held without due process.
Criminals will always find ways to make and spend money, and you could be one of those criminals. You certainly can't prove you aren't. The standards will have to keep growing in complexity and number until a port until a point where institutions have perfect information on what we do and who we are. Even then, they still won't be 100% sure we're not criminals. The standards will never catch all criminals.
It's impossible. And the more the standards grow, the more you and I, honest people, have to carry the burden of complying. I'm a governance professional. I live by compliance. And I'd easily defend the position that my country, the Cayman Islands, is amongst the most compliant and transparent jurisdictions in the world.
Cayman takes compliance very seriously, and so do I. The problem isn't compliance or following laws or catching criminals. It's blindly following a set of standards that are based on a shaky presumption and which don't get regularly reviewed for effectiveness. Good governance means implementing policies that are effective, policies that yield results. FATF standards have a real cost to our society.
They impose a regulatory burden, cause friction and inefficiencies, and they erode due process and privacy for honest people. Any good governance model has that feedback mechanism. If the app you created doesn't bring in users, then you redesign it. You improve it and that's how your app gets better. Policy is no different.
Remove the feedback mechanism and policy never improves. Maybe it's time for us to look at how AML policy is drafted. Maybe it's even time for us to participate in its development. And there's no time like the present. This is the OACD.
It's another global standard setting body like the FATF. Right now, as we speak, it's developing and implementing a new framework which will require every regulated crypto company and some unregulated DeFi protocols in the future to collect your personal information, store it, and send it to tax authorities automatically once a year. Your name, your address, your tax residence, your date of birth, types of tokens you bought or sold or transferred, their values, etc. And don't think DeFi is safe from this framework. Regulated banks have been doing this via the CRS, the common reporting standards.
And KARF just seeks to implement this for crypto transfers, but the legislation's been drafted such that it expands definition slightly and potentially include DeFi arrangements like staking, tokenization, lending, wrapping. It includes a test of control which will be applied to DeFi protocols to see if they're in scope. That test hasn't been formalized yet, but the OECD made it it made its intent clear. KARF will include DeFi in the future. This is being implemented in the US and on a global scale.
The Treasury and IRS have an active rulemaking item specifically for KARF and have already written CARF into the logic of the US crypto broker regs. The revised form 1099DA that just went live this year is the first initial phase of KARF. If you don't know what a 1099DA is, please look it up. Were you aware this was being put in place? Did you see the consultation by the OECD in 2023?
This is a global standard, so it's harder for us to know about it and participate in its development. It seems to me like we were bypassed in that policy process. I see a lot of really innovative projects doing KYC in a way that prevents preserves privacy here. This new framework, CARF, would completely obliterate your efforts. Karf requires entities to collect data directly, store it, and send it automatically.
I don't want to be all doom and gloom. Fact is, there's simple things we can do as a community. For CARF, tighten the scope to only include already regulated entities. Don't expand it to DeFi. The US hasn't signed the master agreement yet, so there's still time.
For the FATF, a costbenefit analysis is long overdue on the AML standards. If the FATF won't assess how effective their standards are, maybe we should. Most importantly, give resources to people whose job it is to actually catch criminals. Imagine if the hundreds of billions spent on compliance went to law enforcement instead. Wouldn't that be more efficient effective than seizing 1.
1% of criminal proceeds? Let's shift our focus from blind compliance to actually developing effective policies and practices that catch criminals. Let's review the standards, their cost, and their benefits to society. The goal is catching criminals, not blind compliance. Some say more transparency is the solution.
Well, then if we have to bear all for the sake of a minority of criminals, if we have to weaken our cryptography, censor ourselves, or allow authorities to know everything that we're doing, shouldn't that same standard also apply to our governments? I say it's time for another sort of cyber punk manifesto. Thank you.
Automatic transcript — names and jargon may be misspelled.