Could Stablecoins be the Future of Payments and Financial Integrity?

A Turkish exchange office in Istanbul, showing the exchange rates for Turkish Lira.

Going rate: A Turkish exchange office in Istanbul, showing the exchange rates for Turkish Lira. Image: Jerome Cid / Alamy Stock


Stablecoins are becoming important payment infrastructure, but policymakers are still trying to govern them through the financial crime frameworks built for traditional finance.

It is hard to ignore stablecoins, as they are no longer a niche debate for crypto enthusiasts. Hardly a day passes without a new regulatory announcement or debate warning of potential financial crime or stability risks. At the same time, the policy conversation is becoming more nuanced. In July, a UK–US joint statement explicitly recognised that ‘well-regulated stablecoins have the potential to promote efficiency and competition in our financial systems, modernise financial market infrastructure, and improve cross-border payments and transactions’.

Away from the headlines, adoption is accelerating at a remarkable speed. By April 2026, the stablecoin market had reached around $317 billion, up more than 50% since early 2025. The appeal is simple. Stablecoins are designed to maintain a stable value, which makes them less volatile than other cryptoassets. They also offer faster and cheaper cross-border payments, and in many emerging markets they are a good value-preservation tool, particularly where inflation is high and domestic currencies and banking systems are not well trusted.

At the same time, regulators have focused on the risks that stablecoins bring. The Financial Action Task Force (FATF), for example, has highlighted the illicit finance risks associated with stablecoins, describing them as ‘the most popular virtual asset used in illicit transactions’. Yet the real debate has moved beyond whether stablecoins are here to stay. That question has been answered by market growth and adoption. The more relevant issues are what role stablecoins will play in the future and how policymakers can preserve their benefits while addressing financial crime risks.

To assess these questions and explore the future of stablecoin regulation, the Centre for Finance and Security at RUSI convened two expert roundtables in partnership with Stripe in March and June this year. The roundtables brought together policymakers, regulators, financial institutions, blockchain analytics firms, technology providers and industry experts in London and Brussels. The discussions pointed towards a common conclusion: stablecoins should be understood as payment infrastructure, not another category of cryptoassets.

Stablecoins as a New Payment Rail

Much of the early growth in stablecoins took place where traditional financial systems struggled to meet users’ needs, were too slow or too costly. As a result, economies experiencing currency volatility, expensive remittance corridors and humanitarian crises became natural entry points for adoption.

Today, however, stablecoins are moving beyond these initial use cases. They function increasingly as an infrastructure layer through which funds settle. In other words, they are becoming a payment rail.

quote
Anyone can look up how assets move between addresses over time, even if attributing those addresses to real-world actors remains hard. The payment system itself is no longer opaque; it is arguably a glass box

Stablecoins solve the practical problems that traditional payment systems have struggled with for years. They allow liquidity to be moved within minutes instead of days while avoiding many of the costs created by multistage correspondent banking chains. End users are often not even aware that stablecoin infrastructure underpins the transaction. They see pesos converted into euros or euros into Kenyan shillings. But the infrastructure layer delivers instant foreign exchange conversion at a reduced cost.

Recognising stablecoins as infrastructure matters because it changes the nature of the policy debate. Besides consumer protection, infrastructure puts forward questions about resilience and strategic dependence. This is particularly key for Europe. Approximately 98% of fiat-backed stablecoins are denominated in US dollars. If stablecoins continue to be mainly denominated in US dollars, then European firms will find themselves relying on rails that sit outside European regulatory systems, a familiar experience where tech adoption lags the US.

This does not mean financial stability concerns should be overlooked. In fact, those risks remain. But an exclusively risk-averse approach also carries costs. Policymakers risk leaving the EU and the UK dependent upon non-European stablecoin infrastructure and missing out on the opportunity to shape the development of technology themselves.

The Limits of Traditional AML/CFT Frameworks

As stablecoins become part of the payment infrastructure, the debate is shifting from who controls the rails to how risks moving across them should be managed. This exposes the limits of today’s anti-money laundering and counterterrorist financing (AML/CFT) frameworks, which were designed around identifiable intermediaries and centralised oversight. Stablecoins operate differently, creating a number of related tensions.

First, stablecoin compliance needs to operate in real time. Traditional cross-border payments move slowly, and AML/CFT frameworks have been shaped around this reality, where systems rely on post-transaction monitoring and batch screening. Stablecoins reimagine this approach given settlements could move irrevocably, reducing the value of a retrospective approach.

Paradoxically, the stablecoin architecture offers part of the solution to this problem. Stablecoin infrastructure is programmable, meaning compliance controls can be built at the smart contract level. If programmed well, smart contracts can support automated detection of suspicious behaviour patterns or temporary suspension of transactions before settlement. Many of these capabilities already exist but are underutilised within current AML/CFT frameworks.

Enjoy our analysis and research? Ensure it shows up first on Google

Help your search results show more from RUSI. Adding RUSI as a preferred source on Google means our analysis appears more prominently.

Realising and using this potential requires clarity and decisions about where different compliance responsibilities should sit. To use these capabilities responsibly, a distinction needs to be made between protocol‑level controls (embedded in the token logic), issuer‑level controls (Know Your Customer checks, off‑chain monitoring), and interface‑level controls (wallets, exchanges). Moreover, policymakers should focus on determining which safeguards are most appropriate at each layer. However, these measures also raise governance concerns, particularly around potential trade-offs with privacy and questions about who decides which assets get frozen and based on what evidence.

Second, regulators need to clarify responsibilities for activity in the secondary market.

Current regulatory frameworks and FATF standards focus mainly on exchanges and other regulated intermediaries, where AML/CFT controls are relatively mature. However, the most acute AML/CFT problem in the stablecoin ecosystem lies beyond this regulatory perimeter, in the secondary market. Chainalysis estimates that 84% of the illicit virtual-asset volume is linked to stablecoins in 2025. FATF notes that these risks are heightened in the secondary market, particularly through peer-to-peer transactions via unhosted wallets, which are parts of the ecosystem that current rules touch only lightly.

This creates a practical and legal challenge for issuers and regulated intermediaries. On public blockchains, they can observe secondary-market activity that appears suspicious. But they often have no identifying customer information and not enough guidance on their obligations once the token moves beyond a direct client relationship.

Should an issuer freeze tokens linked to suspicious activity where there is no direct customer relationship? Should suspicious activity reports be filed based only on blockchain address? What does a reasonable compliance obligation look like once tokens have left the primary market? When there is no clear guidance, firms find themselves at risk of investing resources and investigating alerts that may never result in enforcement action while remaining exposed to reputational and regulatory criticism.

Third, policymakers should establish common standards for transaction attribution.

Today, blockchain analytics providers perform much of the practical work of identifying and risk-scoring transactions. These firms use clustering techniques to identify addresses controlled by the same actor and apply off‑chain intelligence to turn patterns into named entities or risk scores. These tools have become indispensable to modern AML/CFT practice.

Subscribe to the CFS Newsletter

Receive a monthly newsletter and emails about upcoming events hosted by the Centre for Finance and Security Research Group

Yet important differences remain between providers. They rely on different intelligence sources, apply different methodologies and adopt different confidence thresholds. As a result, one provider may flag a transaction as high risk while another considers the same activity benign. It is not always obvious whether the discrepancies are a result of particular flaws in methodology or legitimate differences in the information and evidence they have available. For regulators and reporting entities alike, this inconsistency creates uncertainty. This is why it is key to have an agreed confidence threshold or policy benchmarks for what counts as hard facts versus judgements, to ensure that labels, whichever are applied, can be traced to factual evidence.

A System Problem?

These tensions are symptomatic of a wider structural issue. Along with exposing gaps within existing AML/CFT frameworks, stablecoins also highlight a growing mismatch between regulatory assumptions and technological reality.

FATF’s Recommendation 16 (known as the Travel Rule) proves the point. The rule was initially designed for traditional wire transfers and was extended to virtual assets in 2019. It requires virtual asset service providers (VASPs) to collect originator and beneficiary information in much the same way as banks exchange payment information today.

In principle, firms should determine whether another regulated VASP sits on the other side of a transaction (and whether it fits within their risk appetite), before transmitting information. Travel Rule logic assumes that payments move between identifiable counterparties. Yet, counterparty discoverability is problematic in a liquidity pool or decentralised finance setting where one might not know who is on the other side of the transaction.

More fundamentally, there is also a conceptual clash between the assumptions underpinning these rules and the characteristics of public blockchains. Traditional finance operates as a black box. Regulators and counterparties cannot see the full path of funds and as a result rely on bank-to-bank information exchange to understand who is sending and receiving payments. For stablecoins this is different. Transaction histories are transparent, at least on public chains. Anyone can look up how assets move between addresses over time, even if attributing those addresses to real-world actors remains hard. The payment system itself is no longer opaque; it is arguably a glass box.

This distinction matters because today’s regulatory architecture continues to treat blockchain payments as if they were simply another version of traditional bank transfers. Rules written for opaque systems are being retrofitted onto infrastructure that is more transparent. This results in operational friction. The policy challenge is to ask whether rules designed for 20th-century payment systems are the best way of governing 21st-century payment infrastructure.

What Next for Policy?

Considering these challenges, four priorities should shape the next phase of policy development.

Subscribe to the RUSI Newsletter

Get a weekly round-up of the latest commentary and research straight into your inbox.

First, regulators should recognise and supervise real-time, programmable compliance as part of meeting AML/CFT obligations. As discussed, stablecoins have the programmability to embed certain controls directly in their system. Regulators should encourage innovation in these areas and set clear expectations around governance. In practice, this means moving towards ‘financial integrity by design’ such as building appropriate safeguards into the architecture of the system.

Second, authorities should clarify the responsibilities of issuers and regulated intermediaries for secondary-market activity. Current uncertainty does not benefit either industry or regulators. There is a need for clearer guidance on when and how issuers are expected to freeze tokens or file suspicious activity reports. Better-defined expectations would help firms allocate compliance resources more efficiently and reduce the risk of consequential decisions by private actors without an adequate legal basis.

Third, policymakers and industry should develop minimum standards for blockchain analytics and transaction attribution, including confidence thresholds and evidentiary requirements. Common standards would improve regulatory confidence and give firms greater certainty when making compliance decisions.

Fourth, FATF and national regulators should use forthcoming work on Recommendation 16 guidance to rethink how AML/CFT obligations apply to programmable financial infrastructure. Future guidance should address practical questions around counterparty discoverability and pre-transfer risk assessment.

Building In, Not Bolting On

Stablecoins challenge both the existing payment systems and the regulatory architecture that governs them. The challenge ahead is to ensure that the regulatory design understands and keeps pace with the underlying architecture of the system it aims to govern effectively. This calls for building safeguards in, not bolting them on after the fact. Viewing stablecoins as another compliance problem to shoehorn into existing rules is a mistake. They offer an opportunity to design more effective safeguards within the payment system itself. Thus, the central policy question becomes whether AML/CFT policy can take advantage of the innovative aspects of 21st-century financial infrastructure. Time will tell.

© RUSI, 2026.

The views expressed in this Commentary are the authors', and do not represent those of RUSI or any other institution.

For terms of use, see Website Terms and Conditions of Use.

Have an idea for a Commentary you'd like to write for us? Send a short pitch to commentaries@rusi.org and we'll get back to you if it fits into our research interests. View full guidelines for contributors.


WRITTEN BY

Arzu Abbasova

Research Analyst

Centre for Finance and Security

View profile

Tom Keatinge

Director, CFS

Centre for Finance and Security

View profile



Explore our related content