The U.S. Treasury Department on April 8, 2026, issued a joint notice of proposed rulemaking (NPRM) through FinCEN and OFAC requiring all permitted payment stablecoin issuers (PPSIs) to comply with Bank Secrecy Act obligations for the first time. The rule mandates full AML/CFT programs, suspicious...
"This proposal will protect the U.S. financial system from national security threats without hindering American companies' ability to forge ahead in the payment stablecoin ecosystem." — Scott Bessent, U.S. Treasury Secretary
The U.S. Treasury Department on April 8, 2026, issued a joint notice of proposed rulemaking (NPRM) through FinCEN and OFAC requiring all permitted payment stablecoin issuers (PPSIs) to comply with Bank Secrecy Act obligations for the first time. The rule mandates full AML/CFT programs, suspicious activity reporting at the $5,000 threshold, blockchain transaction monitoring, and technical capabilities to block, freeze, and burn stablecoins on lawful order.
The proposal arrives at a market inflection point. Stablecoins now exceed $315 billion in total supply. FATF data from March 2026 shows stablecoins accounted for 84% of $154 billion in illicit crypto transaction volume during 2025. The Treasury's rulemaking implements the GENIUS Act — signed by President Trump in July 2025 — and establishes the first concrete enforcement framework for stablecoin-specific financial crime obligations. A 60-day comment period begins upon Federal Register publication, with full enforcement expected by January 18, 2027.
FinCEN and OFAC published a joint NPRM on April 8, 2026, implementing Section 4 of the GENIUS Act (signed July 18, 2025). The rule classifies PPSIs as financial institutions under the Bank Secrecy Act — the same legal designation applied to banks, broker-dealers, and money services businesses.
This is not incremental guidance. The proposal imposes the full spectrum of BSA obligations on entities that, until now, operated in a compliance gray zone between money transmitter licensing and bank-grade oversight.
The core requirements fall into five categories: AML/CFT program establishment, suspicious activity reporting, transaction blocking capabilities, sanctions compliance, and secondary market monitoring. Each carries specific operational mandates that will require issuers to build or substantially upgrade their compliance infrastructure.
The NPRM follows a separate Treasury rulemaking issued April 1, 2026, which establishes principles for determining when state-level stablecoin regimes qualify as "substantially similar" to the federal framework — a key mechanism under the GENIUS Act's dual oversight structure.
The proposed rule requires PPSIs to implement risk-based AML/CFT programs that mirror banking standards. Specific obligations include:
Customer Identification: PPSIs must establish customer identification programs for minting and redemption activity. The rule applies the same know-your-customer (KYC) framework used by banks and broker-dealers.
Suspicious Activity Reports (SARs): Issuers must file SARs with FinCEN at the $5,000 threshold — the same level applied to banks. This requires monitoring all minting, redemption, and transfer activity for patterns indicative of money laundering, terrorist financing, or sanctions evasion.
Compliance Officers: Each PPSI must designate a qualified, U.S.-based AML officer with no financial crime convictions. The officer must have sufficient authority and resources to implement and enforce the compliance program.
Independent Testing: AML/CFT programs must undergo independent testing by external auditors or unaffiliated internal staff. This provision aims to prevent the self-certification practices that have drawn regulatory criticism in the crypto sector.
Risk-Based Calibration: FinCEN stated that "AML/CFT programs should be appropriately risk-based, with PPSIs directing more resources toward higher-risk customers and activities." The proposal allows proportional implementation but establishes a compliance floor that exceeds current industry practices.
The most operationally demanding provision requires PPSIs to monitor secondary market transactions on blockchains — including peer-to-peer transfers and smart contract interactions.
This goes beyond traditional banking AML, which focuses on account-level activity. Stablecoin issuers would need systems capable of tracking on-chain movement of their tokens after initial issuance, flagging suspicious patterns, and escalating alerts through defined reporting workflows.
The provision reflects a structural reality of stablecoin architecture: unlike bank deposits, stablecoins circulate freely on public blockchains after minting. A single USDT token may pass through dozens of wallets, DEX pools, and cross-chain bridges before returning to the issuer for redemption. Treasury's position is that the issuer bears monitoring responsibility across this lifecycle.
The technical capability requirements extend further. PPSIs must possess the ability to:
These capabilities already exist in the smart contract architecture of most major stablecoins. Both Tether (USDT) and Circle (USDC) have blacklist functions embedded in their token contracts. The rule transforms these voluntary capabilities into legal mandates with enforcement consequences.
The sanctions component requires PPSIs to adopt compliance programs built around five elements defined by OFAC:
The OFAC framework aligns with existing guidance for traditional financial institutions. The distinction is scope: stablecoin issuers must apply these controls not only to direct customers but to on-chain activity involving their tokens. FATF data indicates 86% of illicit crypto flows in 2025 were tied to sanctions-related activity, with stablecoins serving as the primary transfer mechanism.
The GENIUS Act creates a dual regulatory structure with a hard threshold: issuers with $10 billion or less in outstanding stablecoins may operate under state-level oversight if their state regime is "substantially similar" to federal standards. Above $10 billion, federal regulation is mandatory.
Treasury's April 1 NPRM defines "substantially similar" through two categories:
Uniform Requirements (No State Discretion):
State-Calibrated Requirements (Flexible Standards):
States can expand the approved reserve asset list only if the OCC has designated additional assets as "similarly liquid Federal Government-issued assets." Enforcement mechanisms include issuance halts and mandatory wind-down procedures for non-compliant issuers.
The threshold creates a clear market segmentation. Tether's USDT ($184 billion market cap) and Circle's USDC ($78 billion) both exceed $10 billion by wide margins and fall under mandatory federal jurisdiction. The state pathway serves smaller, emerging issuers — and notably, potential bank-subsidiary stablecoin programs that may start below the threshold.
Issuers that cross $10 billion must transition to federal oversight within 360 days, obtain a waiver, or cease new issuance until their supply falls below the threshold.
The $315 billion stablecoin market will absorb compliance costs unevenly. Three tiers of impact emerge:
Tier 1 — Large Issuers (>$10B): Tether and Circle already maintain substantial compliance teams. Circle, as a U.S.-domiciled entity that completed its IPO in 2025, has invested in BSA-adjacent compliance infrastructure. The incremental cost of meeting the new requirements is manageable relative to the revenue generated by their reserve portfolios. The more significant impact for Tether, which is not U.S.-domiciled, is the question of whether and how PPSI requirements apply to offshore issuers whose tokens circulate within U.S. markets.
Tier 2 — Mid-Size Issuers ($1B–$10B): This tier includes newer entrants and bank-subsidiary stablecoin programs. Operating under state regimes, they face lower regulatory overhead but must still meet the "substantially similar" standard. Compliance program buildout — including SAR filing systems, sanctions screening, and independent auditing — will represent a material fixed cost that reduces margins for lower-volume issuers.
Tier 3 — Small Issuers (<$1B): The steepest relative adjustment. Companies operating under state money transmitter licenses with limited compliance teams will need to build AML/sanctions programs from scratch or outsource to compliance-as-a-service providers. As of November 2025, Treasury had received 333 public comments on the initial GENIUS Act rulemaking, with state regulators seeking enforcement parity with federal agencies.
The compliance cost structure may accelerate market consolidation. Fixed AML/CFT overhead favors scale, potentially widening the gap between the two dominant issuers and the long tail of 250+ smaller stablecoins identified in the FATF's March 2026 report.
Treasury's rulemaking did not emerge in isolation. The FATF published a targeted report on stablecoins and unhosted wallets on March 3, 2026, providing the empirical foundation for aggressive regulatory action.
Key FATF findings:
The FATF specifically noted that stablecoins' price stability and high liquidity have made them "a preferred tool for illicit actors" — a characterization that underscores the shift from Bitcoin-era money laundering to stablecoin-centric financial crime.
The FATF report recommended that countries impose AML obligations on stablecoin issuers and consider tools including "wallet freezing and banning or restricting functions embedded in smart contracts." Treasury's April 8 proposal implements these recommendations almost verbatim for the U.S. jurisdiction.
The regulatory calendar is compressed:
| Date | Event | |------|-------| | July 18, 2025 | GENIUS Act signed into law | | September 2025 | Treasury issues Advanced Notice of Proposed Rulemaking | | November 2025 | 333 public comments received on initial rulemaking | | March 2, 2026 | OCC publishes proposed GENIUS Act implementing regulations | | March 3, 2026 | FATF publishes targeted report on stablecoins | | April 1, 2026 | Treasury NPRM on state regime "substantial similarity" principles | | April 8, 2026 | Joint FinCEN/OFAC NPRM on AML/sanctions obligations | | ~June 2026 | 60-day comment period closes | | July 18, 2026 | Statutory deadline for implementing regulations | | January 18, 2027 | Full enforcement begins (latest) |
The July 2026 deadline — exactly one year from the GENIUS Act signing — creates a compressed rulemaking window. Industry participants have roughly two months to comment and six months to build or upgrade compliance infrastructure before enforcement begins.
The April 8 NPRM marks the operational phase of U.S. stablecoin regulation. The GENIUS Act provided the statutory framework; Treasury is now filling in the enforcement details.
The economic implications are straightforward. Compliance infrastructure costs money. The fixed-cost nature of AML/CFT programs — compliance officers, SAR filing systems, blockchain monitoring tools, independent audits — creates economies of scale that benefit large issuers and disadvantage small ones. In a market where reserve yield is the primary revenue source, compliance overhead directly compresses margins.
The secondary market monitoring requirement is the provision with the most long-term structural significance. It extends issuer liability beyond the minting-redemption relationship into the on-chain lifecycle of the token — a regulatory concept without precedent in traditional finance. How issuers implement this obligation, and how FinCEN enforces it, will shape the compliance architecture of the stablecoin market for the foreseeable future.
The 60-day comment period will test whether industry participants view these requirements as proportionate or overreaching. The FATF's 84% illicit volume statistic gives Treasury substantial cover for an aggressive stance. Whether that statistic reflects the actual risk profile of stablecoins or an artifact of their market dominance in overall crypto transaction volume remains an open analytical question — one that the comment period may help resolve.