Half a Stack: What the case for permissionless networks borrows from the internet, and what it leaves behind
.jpg?w=1152&q=85&fit=max&auto=format)
By Miguel Angel Calero, executive director, ISBE.
This week a16z crypto published ๐๐ฎ๐ป๐ธ๐ ๐ฑ๐ผ๐ป'๐ ๐ป๐ฒ๐ฒ๐ฑ ๐ฐ๐น๐ผ๐๐ฒ๐ฑ ๐ฏ๐น๐ผ๐ฐ๐ธ๐ฐ๐ต๐ฎ๐ถ๐ป๐. ๐ฆ๐ผ ๐๐ต๐ ๐ฑ๐ผ ๐๐ต๐ฒ๐ ๐ธ๐ฒ๐ฒ๐ฝ ๐ฐ๐ต๐ผ๐ผ๐๐ถ๐ป๐ด ๐๐ต๐ฒ๐บ?, by Rebecca Rettig, adapted from a paper she wrote with Omid Malekan and Michael Mosier: ๐ง๐ต๐ฒ ๐๐ผ๐บ๐ฝ๐ฎ๐๐ถ๐ฏ๐ถ๐น๐ถ๐๐ ๐ผ๐ณ ๐ฃ๐ฒ๐ฟ๐บ๐ถ๐๐๐ถ๐ผ๐ป๐น๐ฒ๐๐ ๐ก๐ฒ๐๐๐ผ๐ฟ๐ธ๐ ๐ฎ๐ป๐ฑ ๐๐ถ๐ป๐ฎ๐ป๐ฐ๐ถ๐ฎ๐น ๐๐ป๐๐ฒ๐ด๐ฟ๐ถ๐๐: ๐ ๐ฃ๐ฟ๐ฎ๐ฐ๐๐ถ๐ฐ๐ฎ๐น ๐๐๐ถ๐ฑ๐ฒ ๐ณ๐ผ๐ฟ ๐๐ถ๐ป๐ฎ๐ป๐ฐ๐ถ๐ฎ๐น ๐๐ป๐๐๐ถ๐๐๐๐ถ๐ผ๐ป๐. It argues that regulated financial institutions can build on permissionless networks while meeting their financial integrity obligations. It is a serious piece of work, and Mosier's record at FinCEN and OFAC gives it standing. Whether its AML and sanctions analysis holds is not what I want to discuss.
I want to discuss one sentence, because everything else rests on it.
"๐๐ฆ๐ณ๐ฎ๐ช๐ด๐ด๐ช๐ฐ๐ฏ๐ญ๐ฆ๐ด๐ด ๐ฃ๐ญ๐ฐ๐ค๐ฌ๐ค๐ฉ๐ข๐ช๐ฏ ๐ฏ๐ฆ๐ต๐ธ๐ฐ๐ณ๐ฌ๐ด ๐ข๐ณ๐ฆ ๐ฅ๐ช๐ด๐ต๐ณ๐ช๐ฃ๐ถ๐ต๐ฆ๐ฅ ๐ฅ๐ช๐จ๐ช๐ต๐ข๐ญ ๐ฅ๐ข๐ต๐ข๐ฃ๐ข๐ด๐ฆ๐ด ๐ต๐ฉ๐ข๐ต ๐ณ๐ฆ๐ค๐ฐ๐ณ๐ฅ ๐ต๐ณ๐ข๐ฏ๐ด๐ข๐ค๐ต๐ช๐ฐ๐ฏ๐ด ๐ข๐ค๐ณ๐ฐ๐ด๐ด ๐ฎ๐ข๐ฏ๐บ ๐ค๐ฐ๐ฎ๐ฑ๐ถ๐ต๐ฆ๐ณ๐ด ๐ด๐ช๐ฎ๐ถ๐ญ๐ต๐ข๐ฏ๐ฆ๐ฐ๐ถ๐ด๐ญ๐บ ๐ข๐ค๐ค๐ฐ๐ณ๐ฅ๐ช๐ฏ๐จ ๐ต๐ฐ ๐ต๐ฉ๐ฆ ๐ณ๐ถ๐ญ๐ฆ๐ด ๐ฐ๐ง ๐ข ๐ฑ๐ณ๐ฆ๐ด๐ฆ๐ต ๐ด๐ฐ๐ง๐ต๐ธ๐ข๐ณ๐ฆ ๐ฑ๐ณ๐ฐ๐ต๐ฐ๐ค๐ฐ๐ญ. ๐๐ฏ ๐ต๐ฉ๐ช๐ด ๐ณ๐ฆ๐ด๐ฑ๐ฆ๐ค๐ต, ๐ต๐ฉ๐ฆ๐บ ๐ณ๐ฆ๐ด๐ฆ๐ฎ๐ฃ๐ญ๐ฆ ๐ต๐ฉ๐ฆ ๐ค๐ฐ๐ฎ๐ฎ๐ถ๐ฏ๐ช๐ค๐ข๐ต๐ช๐ฐ๐ฏ๐ด ๐ฑ๐ณ๐ฐ๐ต๐ฐ๐ค๐ฐ๐ญ๐ด (๐ฆ.๐จ., ๐๐๐/๐๐) ๐ต๐ฉ๐ข๐ต ๐ถ๐ฏ๐ฅ๐ฆ๐ณ๐ฑ๐ช๐ฏ ๐ต๐ฉ๐ฆ ๐ช๐ฏ๐ต๐ฆ๐ณ๐ฏ๐ฆ๐ต."
If that resemblance holds, the rest follows. Transport layers are not held responsible for what moves across them. The obligations sit with whoever operates above. The paper says so explicitly, and it is the same argument circulating far beyond finance: permissionless networks are the internet of value, and infrastructure regulation does not reach infrastructure this neutral.
The analogy is worth taking seriously. More seriously, in fact, than the paper takes it.
๐ง๐ต๐ฒ ๐ถ๐ป๐๐ฒ๐ฟ๐ป๐ฒ๐ ๐ถ๐ ๐ป๐ผ๐ ๐ง๐๐ฃ/๐๐ฃ
TCP/IP is a transport layer. It carries packets and forgets them. A router does not read the payload, and that is precisely why holding it responsible makes no sense: it neither knows nor determines what it carries.
But nobody does anything consequential on TCP/IP. You do not sign a contract on a transport layer. You do not log into your bank on one.
What makes those things possible is a second layer the analogy skips. Above neutral transport sits a layer of identifiable, accountable authorities: DNS, and above all the public key infrastructure. When you open your bank's website, what protects you is not that IP is indifferent to your packets. It is that a Certification Authority vouched for that identity, is auditable, and can revoke it. In Europe, qualified CAs operate under eIDAS with defined liability. Somebody answers.
That layer is hierarchical, identified, revocable and regulated. It is the structural opposite of permissionlessness. And it is the layer that turned a neutral transport network into infrastructure people could rely on.
The internet solved trust not by being neutral, but by adding accountable authorities on top of neutrality.
๐ช๐ต๐ฎ๐ ๐๐ฎ๐ ๐ฐ๐ผ๐ฝ๐ถ๐ฒ๐ฑ, ๐ฎ๐ป๐ฑ ๐๐ต๐ฎ๐ ๐๐ฎ๐ ๐ฑ๐ฟ๐ผ๐ฝ๐ฝ๐ฒ๐ฑ
Permissionless networks took the first half of that architecture and left the second. Neutral base layer, no trust layer. No issuer of identity who answers for it. No revocation. Nobody to ask.
Which is why the claim "we are like the internet" reads to me as the opposite of what it intends. If the analogy holds, permissionless networks have implemented half a stack, and it is the half that does not make trust enforceable.
There is a second thing the sentence does. It defines the object as a database that records, then compares it to a protocol that transports. Transport forgets; a record keeps. A router that mishandles a packet causes a retransmission. A ledger that accepts a bad entry keeps it, and keeps it authoritative, until somebody with the standing to act corrects it. Where nobody holds that standing, the error is permanent by design. Which brings us to the question the paper never asks.
๐ง๐ต๐ฒ ๐พ๐๐ฒ๐๐๐ถ๐ผ๐ป ๐ป๐ผ๐ฏ๐ผ๐ฑ๐ ๐ฎ๐๐ธ๐ฒ๐ฑ
The paper answers whether an institution can manage financial integrity on a permissionless network. That is one regulatory domain, and it is the one the authors know best. There is another that never appears, and it is the one that decides whether infrastructure can be depended on at all: who is accountable for the security of the infrastructure itself.
The paper analyses transaction integrity: screening, provenance, monitoring. It does not ask who answers for the base layer those transactions settle on. When a failure occurs there rather than in the transaction, a bank's screening program is irrelevant, because the problem is not on its layer. Resilience is not the same as accountability. A network can stay up indefinitely and still have nobody obliged to answer for its integrity.
The clearest case is the supply chain. The paper's own framework requires third-party risk management โ due diligence, contractual protections, monitoring, exit planning โ and applies it to node providers, staking providers, custody technology vendors and analytics firms. Every supplier around the network, that is, except the one that settles the transaction. The validator set is the supplier of settlement, and it is pseudonymous, open to join, and different for every block. The framework does ask for network-level diligence, but what it can measure is shape: client diversity, stake distribution, finality characteristics. Those are statistical properties of a population, not knowledge of a counterparty. You cannot run due diligence on a supplier you cannot identify, you cannot contract with one, and you cannot write an exit plan for one you never onboarded.
The same gap shows up in incident response. A regulated institution has to report a significant incident within hours, to a named authority, and is expected to know whom to call at each of its critical suppliers. On a permissionless base layer nobody is under a duty to notify anyone. When something goes wrong at that layer, an institution finds out the way everyone else does: from the public post-mortem of whoever chooses to write one.
Concentration is the same problem in different clothes. The paper points to the October 2025 AWS outage, during which major base layers kept producing blocks while centralised services went down, and the point is fair โ that day the distributed system was the resilient one. But knowing whether that still holds tomorrow requires knowing how many validators sit in the same region, on the same cloud, behind the same hosting provider. That is precisely what pseudonymity withholds. The concentration risk is not absent. It is unmeasurable.
Europe has written parts of this down โ NIS2 makes supply chain security a direct obligation, and DORA requires a register of critical ICT third-party providers with an exit strategy for each โ but the principle is not regional. An institution that calls something critical infrastructure is expected to be able to name who runs it.
๐ง๐ต๐ฒ ๐ฐ๐ผ๐ป๐ฐ๐ฒ๐๐๐ถ๐ผ๐ป ๐ฎ๐น๐ฟ๐ฒ๐ฎ๐ฑ๐ ๐ถ๐ป ๐๐ต๐ฒ ๐๐ฒ๐ ๐
What that omission asks for is the one thing credible neutrality is designed to exclude: an actor able to intervene and obliged to answer.
The paper's own framework reintroduces exactly that actor where the stakes are highest. Its closing section notes that the GENIUS Act requires stablecoin issuers to hold the technical capability to freeze, to burn, and to execute lawful orders. For money, pure neutrality was not deemed sufficient. Somebody has to be able to act.
The question is only where that somebody sits. Placing them inside each application works for a private issuer. It does not work for the layer beneath every application โ the one carrying identity, public records and sovereign money. You cannot have a kill switch in each app and none in the layer that holds them all up.
Take the internet analogy seriously and it does not describe a network without authorities. It describes one that learned to add them. That is the half of the stack we are building at ISBE.

Redacciรณn ISBE
Redacciรณn @ ISBE