Rebecca Rettig, the Chief Operating Officer and Chief Legal Officer of Jito Labs, has challenged the prevailing notion that financial institutions must rely exclusively on private, permissioned networks to satisfy regulatory mandates. In a recent analysis published via a16z crypto, Rettig argued that banks can operate within the bounds of the Bank Secrecy Act (BSA) and global sanctions laws while utilizing permissionless blockchains. This perspective suggests a shift in how traditional finance (TradFi) interacts with decentralized infrastructure, emphasizing that compliance is achievable through application-layer controls rather than infrastructure-level restrictions.
Regulatory Frameworks and Risk Management
The core of the argument rests on the interpretation of existing financial regulations, which typically require reasonable controls commensurate with risk rather than the total elimination of risk or absolute control over the underlying network layer. Rettig notes that many institutions mistakenly believe that the open nature of public blockchains like Ethereum or Solana precludes them from meeting their legal obligations. However, the legal standard does not necessitate oversight of the entire blockchain protocol, but rather the specific transactions and customer interactions managed by the institution.
- The U.S. Office of the Comptroller of the Currency (OCC) confirmed in November 2025 that banks are permitted to pay network gas fees.
- Financial institutions are authorized to hold crypto assets related to their blockchain operations.
- Compliance is focused on the application layer rather than the foundational distributed ledger technology.
Privacy Technologies and the GENIUS Act
Advancements in cryptographic techniques are playing a pivotal role in bridging the gap between public transparency and banking confidentiality. Rettig highlighted that technologies such as zero-knowledge proofs (ZKPs) and confidential transfers allow banks to verify compliance to regulators without exposing sensitive customer positions or proprietary data to the public. Zero-knowledge proofs allow one party to prove to another that a statement is true without revealing any information beyond the validity of the statement itself.
Relevant laws require reasonable controls commensurate with risk, not zero risk or control over the underlying infrastructure.
This approach aligns with the recently passed GENIUS Act in the United States. This legislation reinforces the strategy of placing Anti-Money Laundering (AML) and sanctions controls at the application layer, where intermediaries interact with users, rather than attempting to regulate the neutral decentralized protocols themselves.
The move toward permissionless blockchain adoption by banks represents a significant evolution in digital asset integration. By leveraging advanced privacy tools and focusing on application-level monitoring, financial institutions may benefit from the liquidity and interoperability of public networks without compromising their standing with regulators. As the legal landscape clarifies, the distinction between private banking ledgers and public blockchains may continue to blur in favor of more robust, global financial systems.
Frequently Asked Questions
Quick answers to the most common questions about this topic.