RSS Amplifier

netz⭕️money · Aug 1, 2026

Accountability Architecture

0
Sign in to vote or save

netzmoney, alipasha.xyz · netz⭕️money

Accountability Architecture - Zone Cartography

Five very different accountability systems — an international arbitration-enforcement regime, EU platform regulation, US multi-agency financial enforcement, crypto-DAO liability law, and a handful of brand-new EU institutions — converge independently on the same specific weakness: each can compel a formal, binding decision, yet once resistance begins, each depends on legal or structural levers beyond its own control to make that decision stick.

TD Bank paid $3.09 billion for anti-money-laundering failures, but individual accountability at a comparable rate has historically been rare in similar cases. Courts in the UK and Singapore are making it easier to win recognition of a claim against a resistant sovereign state, while actual collection remains untouched. A landmark 2022 US ruling exposed DAO participants to personal liability; a new state law built to shield them has never been tested against a real regulatory challenge. And several of the EU’s newest institutions — an anti-money-laundering authority, a digital-identity mandate, new technology oversight rules — are already open for business, years before their full powers activate.

Two live developments will test whether this holds: a first-ever judicial appeal of an EU platform fine, and whether any regulator ever brings an individual, not just corporate, accountability case at comparable scale.

Covenants, without the sword, are but words, and of no strength to secure a man at all.

— Thomas Hobbes, Leviathan

This is the sixth report in the nemo 3 series. Reports 1 through 3 each found an unoccupied Center in their respective domains. Report 4 (Reserve Architecture) found Coexistence among five phenomena occupying differentiated positions within one shared functional space. Report 5 (Monetary Jurisdiction) also found Coexistence, but in a more complete form: three architectures with no evidenced connection to one another at all.

This report finds Coexistence for a third time — five phenomena, again with no evidenced connection between them, converging independently on the same specific weakness: none can make a formal decision durable once its target resists it.

In 2026, five very different accountability systems — an international treaty court, an EU platform regulator, a coalition of US financial regulators, a crypto governance experiment, and a handful of brand-new EU institutions — all arrive at the same wall. Each of them can hand down a formal, binding decision. None of them, on the evidence this report gathered, can guarantee that decision survives if the party it targets decides to fight back.

Start with the clearest example. In October 2024, four separate US regulators — the Department of Justice, FinCEN, the Office of the Comptroller of the Currency, and the Federal Reserve — coordinated to hit TD Bank with $3.09 billion in combined penalties and an open-ended cap on its US asset growth, the largest anti-money-laundering settlement in US history. The bank paid. The institution answered for it, fully and immediately. But independent research tracking a broader pattern across many comparable US corporate settlements found that only about a third were ever accompanied by an individual prosecution of anyone involved — and the ones that were tended to reach mid-level staff, not senior executives. The company gets billed. The individual accountability that is supposed to travel alongside it, in this domain’s own historical pattern, more often than not does not follow.

This report compares five very different mechanisms against the same three questions.

  • Getting Established (F1) asks whether a mechanism was ever formally, legally constituted in the first place.

  • Making It Stick (F2) asks whether that formal authority actually produces a concrete consequence for the party it targets.

  • Standing Up to Resistance (F3) asks whether that consequence survives once the target pushes back — appeals it, refuses to recognize it, or simply declines to cooperate.

Five phenomena carry these comparisons:

  • The Paper Verdict — the treaty and court system deciding whether a sovereign or state-linked party can be held to an arbitration ruling

  • The Untested Fine — the European Commission’s platform-governance enforcement under the Digital Services Act

  • The Missing Defendant — US institutional financial-crime enforcement succeeding at the company level while lagging at the individual level

  • The Governance Trapdoor — the liability question hanging over decentralized crypto governance since a landmark US regulatory ruling

  • The Waiting Room — brand-new EU institutions and mandates, each formally created, each still short of its full power

Compare the five side by side. Every one of them clears Getting Established — no mechanism in this report, across five domains and four jurisdictions, lacked valid formal authority. None fully clears Making It Stick: some concrete consequence exists in every case, but always partially. And on Standing Up to Resistance, three of the five — The Paper Verdict, The Missing Defendant, and The Governance Trapdoor — sit at the bottom of the scale: the moment a target genuinely resists, the mechanism has no further evidenced lever to pull.

In this domain's own map, that puts The Untested Fine and The Waiting Room in the Margins — close to, but not at, the center — while The Paper Verdict, The Missing Defendant, and The Governance Trapdoor sit further out, in what this framework calls Outside. That gap — an empty space at the center of this domain’s map — is not occupied by anything.

Every mechanism in this domain can compel a formal, unilateral act of enforcement — a fine, a judgment, a designation — but none of them, on this evidence, can make that act durable against a target’s own resistance without depending on a separate legal or structural chokepoint the enforcing party does not itself control.

Three courts, working independently in three different countries, reached the same structural conclusion within about a year of each other:

  • In March 2026, the UK Supreme Court ruled that Spain and Zimbabwe could not use sovereign immunity to block recognition of arbitration awards against them under the ICSID treaty.

  • On July 24, 2025, England’s Court of Appeal ruled that the New York Convention works only as a shield, not a sword.

  • On July 25, 2025, Singapore’s International Commercial Court held that Russia could not relitigate a sovereign-immunity argument in the long-running Yukos case that an earlier English ruling had already settled.

All three rulings make it easier to get a claim formally recognized. None touch a separate, harder question: whether that creditor can actually collect.

The same UK Supreme Court ruling was explicit that execution immunity — over actual assets — survives untouched. A creditor here can win the argument in one room, only to find the vault is in a different room, with a different combination, that the winning argument does not open.

The European Commission has now fined three of the world’s largest online platforms under the Digital Services Act:

  • X, for €120 million

  • Temu, for €200 million, the largest DSA fine to date

  • TikTok, in a preliminary — not yet final — finding

Every one of these actions is, on paper, a working enforcement mechanism. None has yet survived a full test.

In February 2026, X did something no platform had done before: it appealed its DSA fine to the EU’s General Court. Whichever way that appeal goes, it will be the first genuine judicial test of this mechanism’s own durability, not just its target’s compliance.

TD Bank’s $3.09 billion settlement is one of the cleanest examples in this report of a formal accountability mechanism doing exactly what it was designed to do. What the same evidence base does not show — in this case specifically, or as a broader historical pattern — is a comparable rate of accountability at the individual level. This report’s evidence does not identify or accuse any specific person at TD Bank; the point is a documented pattern across many comparable settlements.

Independent research found that only about a third of comparable federal settlements between 2001 and 2014 were accompanied by any individual prosecution at all.

Both the SEC and the CFTC now describe individual accountability as a stated priority in recent policy language — but neither agency’s evidence in this report shows that language producing a changed pattern yet.

In 2022, the CFTC won a default judgment against Ooki DAO — a decentralized crypto-lending protocol — establishing that a DAO can be treated as an unincorporated association under US commodities law. The ruling didn't just fine the protocol; it ordered its website taken offline and held that the people who vote with its governance tokens can be held personally liable for what the DAO does. It was the first ruling of its kind.

Wyoming responded directly. Its DUNA Act, in effect since mid-2024, gives a DAO that registers under it legal personhood and limited liability for its participants — a specific, purpose-built answer to the exposure Ooki DAO created. Uniswap, one of the largest and most established DAOs in the industry, proposed adopting exactly this structure in 2025, putting real scale behind the question. But independent legal analysis written at the time the Wyoming law passed raise a question this report's evidence does not resolve either way:

Does the shield actually hold up against a regulatory claim like the one that hit Ooki DAO — or only against ordinary contract and tort claims?

No regulator has yet tested a DUNA-registered DAO to find out. The trapdoor Ooki DAO opened is still there; whether Wyoming's law actually covers it is, as of this report's evidence, an open question rather than a settled one.

Several of this domain’s newest institutions have already opened for business. None is running at full power yet. The EU’s new Anti-Money-Laundering Authority has been operational since mid-2025 — but its power to directly supervise the roughly 40 highest-risk financial entities in Europe doesn’t activate until 2028. The EU’s digital-identity wallet, mandated for every member state by the end of 2026, was still showing distinctly uneven rollout as of July. New EU rules meant to speed up cross-border privacy investigations carry a strict 15-month deadline — but missing it does not by itself invalidate the eventual decision. And nineteen major cloud and technology providers, including AWS, Google Cloud, and Microsoft, were newly placed under direct EU financial-oversight rules in late 2025 — a real and unprecedented reach, but one not yet tested against an actual disruption.

Taken together, these cases point to a recurring pattern: institutions that formally exist, but whose real authority, capacity, and consequences remain deferred, uneven, or untested.

This report’s definitive finding is Coexistence: five structurally different accountability mechanisms, each occupying its own separate position, none converging toward or displacing another. Readers of this series will recognize the label — two prior reports reached the same finding in different domains — but this report’s version has a specific shape the others didn’t share.

Every mechanism studied here clears formal authority cleanly. Every one of them encounters its principal constraint somewhere downstream of formal authority.

Two things are worth watching:

  • First, whether the EU General Court’s eventual ruling on X’s appeal becomes the first real judicial test of the DSA’s own enforcement power, not just a platform’s compliance.

  • Second, whether any regulator brings an individual, not merely corporate, charging action tied to a resolution on the scale of TD Bank’s — reversing a pattern that has held for at least the last two decades.

What this report does not claim is also worth stating plainly:

It does not claim any of these five mechanisms is fixable, or unfixable, in principle — the evidence supports observing the pattern, not prescribing a cure. It does not claim formal accountability in this domain is merely symbolic — several of these mechanisms produce real, severe, immediately-felt consequences, and TD Bank’s asset cap is exactly that. And it does not claim this pattern is unique to the five mechanisms studied here; it flags, rather than resolves, whether the same split between making something happen and making it stick would reproduce in decentralized crypto governance specifically — an area this report could only examine at limited depth, reserved for closer treatment elsewhere.

This report maps five phenomena across cross-border finance, technology governance, and DAO liability against three functional requirements — Getting Established, Making It Stick, and Standing Up to Resistance (F1–F3) — derived from this domain’s own evidence.

Bridge: evidence and claim are connected through a formal structural model and pattern register before any interpretive lens is applied, so findings trace back to cited sources rather than general knowledge.

This report is a structural and interpretive analysis, not investment, legal, or policy advice, and does not recommend action by any actor.

Epistemic Boundary Statement: findings are bounded by evidence gathered as of the analytical date; where evidence was thin (rating-agency/auditor accountability literature, whistleblower-mechanism effectiveness, MLAT case law, self-regulatory/ audit mechanisms specifically) or unverified from prior background material, this report says so rather than filling the gap with general knowledge.

Geographic scope: United States, European Union, United Kingdom, and Singapore are treated in direct comparative detail.

Zone assignments: The Untested Fine and The Waiting Room sit in the Margins; The Paper Verdict, The Missing Defendant, and The Governance Trapdoor sit Outside. No phenomenon reaches the Center.

Zone migration: none is predicted with better than Moderate probability; The Untested Fine shows genuinely opposite predicted trajectories rather than one direction.

Method: Phenomena were constituted through a nine-lens framework spanning six perspectives — Competing Powers, Temporal Dynamics, Mutual Autonomy, Ledgered Values, Mediated Markets, and Technical Architectonics. Polycentric Plurality identifies the domain’s extreme structural fragmentation; Compliance Architecture and Regulatory Inscription, coupled, jointly explain the recurring gap between formal constitution and enforcement follow-through.

F1/F2/F3 shorthand is used throughout; full definitions appear in [the Vocabulary section] above.

Understanding Key Metrics:

Distance measures how close a phenomenon is to performing all applicable requirements at Full.

Zone(Center/Margins/Outside) is the category Distance maps into; transition probabilities are qualitative ordinals, not numbers, each with a stated prerequisite and obstacle.

This report combines work from a human research team and multiple AI models.

The research team’s own early work helped shape the questions this report set out to answer. From that starting point, the AI carried out searches, verified every source cited here, built the comparisons across the cases this report covers, and wrote the narrative — but did so under a human researcher’s ongoing direction. Every stage was reviewed before the next began, and the report was not published without the researcher’s explicit approval.

Along the way, the AI also caught and corrected at least one of its own mistakes — including a citation carried forward from an earlier report under a label that turned out to be wrong once the original source became available.

This process isn’t perfect, and it isn’t presented as such. If something here looks off, we’d genuinely like to hear about it.

References are grouped by analytical lens to show evidential logic.

  1. Baker Botts — UK Supreme Court Confirms Sovereign Immunity Is No Defence To ICSID Award Enforcement (2026)
    https://www.bakerbotts.com/thought-leadership/publications/2026/march/uk-supreme-court-confirms-sovereign-immunity-is-no-defence-to-icsid-award-enforcement
    [accessed 2026-07-29]
    Grounds The Paper Verdict’s central adjudicative/execution-immunity distinction via the UK Supreme Court’s own March 2026 ruling.

  2. Preston Byrne — The Wyoming DUNA Act, Section-by-Section (2024)
    https://prestonbyrne.com/2024/03/08/dunaa/
    [accessed 2026-07-29]
    Grounds The Governance Trapdoor’s central unresolved question — whether DUNA registration shields against a regulatory, not merely contract/tort, claim.

  1. England and Wales Court of Appeal — Star Hydro Power v National Transmission and Despatch Company Limited [2025] EWCA Civ 928 (2025) https://www.bailii.org/ew/cases/EWCA/Civ/2025/928.html
    [accessed 2026-07-29]
    Grounds the “shield not sword” doctrine central to The Paper Verdict.

  2. Singapore International Commercial Court — Hulley Enterprises Ltd v The Russian Federation [2025] SGHC(I) 19 (2025)
    https://jusmundi.com/en/document/decision/en-hulley-enterprises-ltd-v-russian-federation-judgment-of-the-singapore-international-commercial-court-2025-sghc-i-19-friday-25th-july-2025
    [accessed 2026-07-29]
    Grounds the transnational-issue-estoppel finding, a third independent instance of The Paper Verdict’s recognition/execution pattern.

  3. Alliance Defending Freedom International — X challenges €120m fine under EU censorship law at top European court (2026)
    https://adfinternational.org/news/x-challenges-e120m-fine-under-eu-censorship-law/
    [accessed 2026-07-29]
    Grounds the documented fact of X’s General Court appeal, central to The Untested Fine’s open judicial-test question.

  1. TD Bank Group — TD Bank Group Announces Resolution of AML Investigations (2024)
    https://stories.td.com/us/en/article/td-bank-group-announces-resolution-of-aml-investigations
    [accessed 2026-07-29]
    Grounds The Missing Defendant’s institutional-success finding via TD Bank’s own primary confirmation.

  2. Gibson Dunn — Waived Through: UK Supreme Court Confirms No State Immunity Defence Against ICSID Award Recognition in the UK (2026)
    https://www.gibsondunn.com/waived-through-uk-supreme-court-confirms-no-state-immunity-defence-against-icsid-award-enforcement/
    [accessed 2026-07-29]
    Independent corroboration of the UKSC ruling underlying The Paper Verdict.

  1. European Commission — Commission fines X €120 million under the Digital Services Act (2025)
    https://digital-strategy.ec.europa.eu/en/news/commission-fines-x-eu120-million-under-digital-services-act
    [accessed 2026-07-29]
    Grounds the first DSA non-compliance decision underlying The Untested Fine.

  2. Lewis Silkin — European Commission fines Temu €200 million for breaching the Digital Services Act (2026)
    https://www.lewissilkin.com/insights/2026/06/02/european-commission-fines-temu-200-million-for-breaching-the-digital-services-ac-102n0sa
    [accessed 2026-07-29]
    Grounds the second, largest-to-date DSA fine.

  3. European Commission — Commission preliminarily finds TikTok’s addictive design in breach of the Digital Services Act (2026)
    https://digital-strategy.ec.europa.eu/en/news/commission-preliminarily-finds-tiktoks-addictive-design-breach-digital-services-act
    [accessed 2026-07-29]
    Grounds the third, still-preliminary DSA finding.

  1. UK Financial Conduct Authority — FCA Enforcement Data 2025/26 (2026) https://www.fca.org.uk/data/fca-operating-service-metrics-2025-26/enforcement-data [Live — accessed 2026-07-29]
    Grounds the domain’s structural fragmentation finding via the FCA’s own zero-cross-connectivity enforcement record.

  2. eIDEasy — EU Digital Identity Wallet Rollout Status by Member State (2026) https://www.eideasy.com/blog/eu-digital-identity-wallets-july-2026
    [Live — accessed 2026-07-29] Grounds The Waiting Room’s uneven-rollout finding.

  1. U.S. Department of Justice — Individual Accountability for Corporate Wrongdoing (the “Yates Memo”) (2015)
    https://www.justice.gov/archives/dag/individual-accountability
    [accessed 2026-07-29] Grounds the policy framework The Missing Defendant’s historical pattern is tested against.

  2. Brandon L. Garrett — Declining Corporate Prosecutions (2019)
    https://corpgov.law.harvard.edu/2019/05/13/declining-corporate-prosecutions/ [accessed 2026-07-29]
    Grounds the empirical ~34% individual-prosecution-rate figure central to The Missing Defendant.

  3. Sullivan & Cromwell — CFTC Division of Enforcement Issues New Cooperation Policy Advisory (2026)
    https://www.sullcrom.com/insights/memo/2026/May/CFTC-Issues-New-Cooperation-Self-Reporting-Policy
    [accessed 2026-07-29]
    Grounds the CFTC’s own 2026 individual-accountability-adjacent policy language.

  1. Council of the European Union — Council adopts new EU law to speed-up handling of cross-border data protection complaints (2025)
    https://www.consilium.europa.eu/en/press/press-releases/2025/11/17/council-adopts-new-eu-law-to-speed-up-handling-of-cross-border-data-protection-complaints/
    [accessed 2026-07-29]
    Grounds The Waiting Room’s GDPR Procedural Regulation instance.

  2. Council of the European Union — Frankfurt to host the EU’s new anti-money laundering authority (AMLA) (2024)
    https://www.consilium.europa.eu/en/press/press-releases/2024/02/22/frankfurt-to-host-the-eus-new-anti-money-laundering-authority-amla/
    [accessed 2026-07-29]
    Grounds The Waiting Room’s AMLA instance.

  1. U.S. District Court, N.D. California — CFTC v. Ooki DAO, Order (2023)
    https://www.cftc.gov/media/8736/enfookidaoorder060923/download
    [accessed 2026-07-29]
    Grounds the default judgment establishing the liability theory The Governance Trapdoor documents.

  2. a16z crypto — The DUNA: An Oasis For DAOs (2024) https://a16zcrypto.com/posts/article/duna-for-daos/
    [accessed 2026-07-29]
    Grounds the DUNA Act’s own legislative facts.

  1. Amazon Web Services — AWS designated as a critical third-party provider under EU’s DORA regulation (2025)
    https://aws.amazon.com/blogs/security/aws-designated-as-a-critical-third-party-provider-under-eus-dora-regulation/
    [accessed 2026-07-29]
    Grounds The Waiting Room’s DORA/CTPP instance via a designated provider’s own primary confirmation.

Four corrections/updates below, identified through source verification after publication. None affect the report’s Coexistence finding, the F1–F3 scoring, or any zone assignment. Three concern factual precision within The Governance Trapdoor and The Missing Defendant; two concern reference quality.

Original text:

In 2022, the CFTC won a default judgment against Ooki DAO — a decentralized crypto-lending protocol — establishing that a DAO can be treated as an unincorporated association under US commodities law.

Corrected text:

In 2023, the CFTC won a default judgment against Ooki DAO — a decentralized crypto-lending protocol it had charged the year before — establishing that a DAO can be treated as an unincorporated association under US commodities law.

Why: The CFTC filed its enforcement action against Ooki DAO in September 2022, but the default judgment itself — the ruling that actually established DAO liability, ordered the website taken offline, and exposed governance-token voters to personal liability — was entered by Judge William Orrick on June 8, 2023. Reference #18 in the original report already dated the order to “(2023)”; the narrative text should match its own citation.

Source: CFTC v. Ooki DAO, Order Granting Default Judgment, No. 3:22-cv-05416-WHO (N.D. Cal. June 8, 2023). https://www.cftc.gov/media/8736/enfookidaoorder060923/download

Original text:

TD Bank’s $3.09 billion settlement is one of the cleanest examples in this report of a formal accountability mechanism doing exactly what it was designed to do. What the same evidence base does not show — in this case specifically, or as a broader historical pattern — is a comparable rate of accountability at the individual level. This report’s evidence does not identify or accuse any specific person at TD Bank; the point is a documented pattern across many comparable settlements.

Update (August 2026): Since original publication, DOJ has brought — and in several instances already resolved — individual prosecutions tied specifically to the TD Bank matter:

  • Wilfredo Aquino, TD Bank employee — pleaded guilty January 2026; sentenced to 46 months

  • Edward Low, former TD Bank retail employee — pleaded guilty February 2026

  • Leonardo Ayala, former TD Bank retail banker — sentenced to 2 years

  • Jhonnatan Steven Rodriguez, TD Bank branch employee — pleaded guilty June 2025

DOJ’s Bank Integrity Unit has stated publicly that the investigation extends to staff “at every level” of the bank, and the underlying charging documents allege that senior executives — including members of the TD Bank U.S. Holding Company audit committee — knew of the AML deficiencies.

Suggested revised framing: individual accountability in the TD Bank matter specifically has begun, but so far only reaches branch- and mid-level employees, not the senior-executive tier that Getting Established/Making It Stick/Standing Up to Resistance is really probing. The open question the original report posed — whether individual accountability follows corporate accountability — is now sharper rather than resolved: DOJ’s own November 2024 statement (”we would expect future cases against individuals”) has partly borne out, but only at the level furthest from the boardroom so far.

Sources:

Original ref 5: Alliance Defending Freedom International — “X challenges €120m fine under EU censorship law at top European court” (2026)

Issue: ADF International is, by its own account, providing legal support to X in this litigation and is not a neutral party to the fact being cited. Its own headline characterizes the DSA as “an EU censorship law,” which is advocacy framing, not reporting. The underlying fact (X filed at the General Court on 16 February 2026) is well-established and doesn’t need an interested source.

Suggested replacement:

Either is a non-party news source reporting the identical fact; no change to the narrative text is needed, only the citation.

Original ref 19: a16z crypto — “The DUNA: An Oasis For DAOs” (2024)

Issue: a16z is a venture firm with a direct financial interest in DAOs having a workable liability shield; it’s a reasonable secondary/explanatory source but shouldn’t be the sole anchor for “the DUNA Act’s own legislative facts.”

Suggested addition (primary source, cited alongside the existing a16z reference rather than replacing it):

These four items surfaced through source-by-source verification requested after publication, not through the report’s own drafting or review process. Two are outright corrections (items 1 and 3); two are updates reflecting events that postdate the original research window (item 2) or sourcing choices worth tightening even though the underlying facts were never in dispute (item 4). None change the report’s central finding. If anything, item 2 sharpens it: the TD Bank case has moved from “no individual accountability yet” to “individual accountability at the bottom of the org chart, senior accountability still untested” — which is arguably a cleaner illustration of Standing Up to Resistance than the original framing.

Read the original on netzmoney.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.