A common mistake is treating DeFi as exempt simply because it uses smart contracts or lacks a conventional intermediary. In practice, regulators may look at control points, governance structures, and service responsibilities. If those elements exist, compliance duties can still apply. Teams should assess substance over labels and avoid assuming technical decentralisation removes legal accountability.
Why This Matters for Security Teams
Assuming DeFi sits outside financial regulation because it uses smart contracts can create a false sense of safety. Regulators typically examine who controls the system, who can change parameters, who benefits from the service, and whether there are meaningful governance or operational choke points. That means decentralised branding does not automatically remove obligations tied to custody, brokerage, promotion, monitoring, or AML risk.
Security teams often focus on code correctness while missing the larger compliance picture. A protocol can be technically distributed and still have upgrade keys, admin roles, fee switches, front-end operators, or foundation governance that create accountability. NIST’s NIST Cybersecurity Framework 2.0 is useful here because it reinforces the need to understand governance, risk, and operational dependencies, not just technical controls. NHIMG’s Ultimate Guide to NHIs — Regulatory and Audit Perspectives also shows how hidden control points often matter more than labels.
In practice, many security teams encounter regulatory exposure only after a token launch, treasury event, or enforcement inquiry reveals that “decentralised” still had identifiable operators.
How It Works in Practice
The practical mistake is treating DeFi as a category that determines regulation on its own. In reality, organisations need to map the full service chain: protocol governance, smart contract admin rights, liquidity management, customer onboarding, hosted interfaces, oracle dependencies, and treasury control. If any party can direct, modify, pause, market, or profit from the system in a meaningful way, regulators may view that party as carrying obligations under securities, payments, AML, consumer protection, or operational resilience rules.
A better approach is to assess substance over form. Start by identifying where control actually sits, then document who can update contracts, control keys, set fees, whitelist addresses, or shut down access. Align that review with financial compliance expectations and identity governance discipline. The NIST SP 800-53 Rev. 5 Security and Privacy Controls is helpful for thinking about accountability, change control, and auditability, while the NIST SP 800-63 Digital Identity Guidelines supports stronger identity proofing where real-world responsibility exists.
- Inventory every administrative and governance path, including multisig signers, upgrade committees, and front-end operators.
- Separate protocol code from service responsibility, since regulation may attach to the service even when code is open.
- Document decision rights for pauses, upgrades, fee changes, and asset movement.
- Review marketing, custody, and user-facing operations alongside technical architecture.
- Track obligations by jurisdiction, because the same DeFi pattern can be treated differently across markets.
NHIMG’s Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs is relevant because governance keys and service accounts often function like high-risk non-human identities that need lifecycle control. These controls tend to break down when protocols are launched with upgradeable contracts, anonymous operators, and a user-facing web layer that obscures who actually runs the service.
Common Variations and Edge Cases
Tighter compliance review often increases launch friction, requiring organisations to balance decentralisation goals against legal exposure and operational burden. There is no universal standard for this yet, so current guidance suggests evaluating the protocol’s actual governance and control model rather than relying on a single “DeFi” label.
Some projects are genuinely more decentralised over time, but initial centralisation can still trigger obligations. Others present a split model where the smart contracts are open, but the interface, treasury, or roadmap remains controlled by an identifiable entity. A protocol that claims “no custody” may still process customer interactions through a hosted front end or controlled oracle set, which can matter under financial and sanctions rules. FATF’s FATF Recommendations — AML and KYC Framework are especially relevant when there is any real-world touchpoint to value transfer or customer onboarding. NHIMG’s Top 10 NHI Issues is useful for teams that need to see how exposed keys, poor rotation, and weak ownership models create accountability gaps.
Where the guidance gets murky is fully autonomous protocol behaviour with no clear operator, no upgrade path, and no user-facing service layer. Even there, legal analysis is still fact-specific, and organisations should not assume technical autonomy eliminates regulated activity. The hard question is not whether code is decentralised, but whether there is still a person or entity performing regulated functions behind it.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | DeFi admin keys and service accounts are non-human identities with real control risk. |
| OWASP Agentic AI Top 10 | Autonomous protocol operations can behave like goal-driven systems with emergent actions. | |
| CSA MAESTRO | Maps agentic control points, governance, and runtime policy to distributed system risk. | |
| NIST AI RMF | Supports risk governance when autonomy and uncertain control boundaries create compliance risk. | |
| NIST CSF 2.0 | GV.OV-01 | Oversight of governance and risk is central when regulation depends on actual control. |
Establish governance, accountability, and monitoring for decentralised or autonomous workflows.
Related resources from NHI Mgmt Group
- What do organisations get wrong when they assume passwordless login automatically means stronger security?
- What do organisations get wrong when they assume blockchain automatically removes the need for intermediaries?
- What do organisations get wrong when they assume low-code and AI automatically make development safer?
- What do organisations get wrong when they assume a foreign individual certificate automatically makes a transaction legally safe?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org