Elliptic Publishes First Standard for Agentic On-Chain Risk
Blockchain analytics firm Elliptic published its Elliptic Standard on 10 September 2026, setting out eight principles for managing on-chain risk in a world where autonomous agents transact at machine speed and illicit actors are already deploying AI. With stablecoin volumes reaching $33 trillion in 2025, a 72% increase year on year, the document is a direct challenge to the forensics-first compliance models that most firms still rely on. For teams responsible for AML programmes, digital asset accounting software strategy, and board-level risk accountability, the implications run deeper than a vendor white paper.
Why Elliptic Published This Now
The timing is deliberate. Stablecoin settlement volume did not just grow in 2025, it accelerated into territory that legacy review workflows were never designed to handle. Autonomous agents, software programmes that can authorise and settle on-chain transactions without human sign-off at each step, are now contributing a measurable and growing share of that volume every quarter.
The gap between old tooling and new risk
Legacy blockchain analytics products were engineered around a specific assumption: a human initiates a transaction, the transaction settles, and a compliance analyst reviews it after the fact. That forensics-first design made sense when transaction volumes were manageable and the counterparty was always a person. Neither condition holds reliably today.
Elliptic frames the current environment not as a bigger version of the same problem but as a categorically different one. Autonomous agents compress the window between initiation and settlement to milliseconds. After-the-fact review arrives too late to prevent exposure. Simultaneously, illicit actors are embedding AI into their attack methods, meaning the sophistication of the threat is rising at the same time as the speed of the underlying activity.
Stablecoins as the critical infrastructure layer
The $33 trillion figure matters specifically because stablecoins have become the settlement rail of choice for both legitimate on-chain finance and a disproportionate share of illicit flows. Any standard that addresses agentic on-chain risk must therefore treat stablecoin transaction screening as a core, not peripheral, function. Elliptic's positioning reflects that: the standard is written for the people who will be accountable for these systems, and the teams who will run them, not for retrospective audit.
The Eight Principles: What the Standard Covers
Elliptic has not published the full text of each principle in the excerpt available, but the framing of the standard makes clear what the eight principles collectively address. They are designed for agentic, real-time on-chain risk rather than for human-paced, sequential review. The firm states explicitly that it builds to these principles and answers for them, positioning the standard as an accountability framework as much as a technical one.
Real-time versus post-hoc assessment
The most structurally significant shift the standard proposes is moving risk assessment upstream, into or before the transaction rather than after it. For accounting firms advising clients on crypto bookkeeping software selection, this distinction matters operationally. A tool that only produces a risk score after settlement can satisfy a record-keeping obligation but cannot prevent a sanctioned-counterparty transaction from completing. The standard implicitly asks whether the tooling in use is fit for a pre-settlement, agentic environment.
Accountability for autonomous systems
Regulators globally are increasingly asking who is responsible when an autonomous system causes a compliance failure. The Elliptic Standard addresses this directly by targeting the document at the people who will be accountable, meaning senior management and compliance officers, rather than solely at technical operators. That framing aligns with the direction of travel in regulatory guidance across multiple jurisdictions, where the compliance officer or MLRO remains personally responsible for the adequacy of automated systems.
AI as both tool and threat vector
The standard acknowledges a duality that compliance teams are only beginning to grapple with. AI can improve the speed and accuracy of risk detection. The same category of technology is already being used by illicit actors to evade detection, generate synthetic identity documents, automate structuring, and probe for gaps in screening logic. A principles-based framework that addresses both sides of that equation is more durable than a checklist tied to specific attack patterns that will evolve.
AML and Compliance Implications for Accounting Firms and CFOs
The Elliptic Standard does not carry regulatory force. It is a published industry framework from a blockchain analytics provider. That distinction matters, and it does not diminish the document's relevance to compliance teams. Industry standards frequently precede regulatory requirements and are later cited in supervisory expectations. Firms that wait for a regulator to mandate equivalent principles before reviewing their tooling are accepting a lag that could prove costly.
Assessing your current crypto accounting software stack
For accounting firms and CFOs managing digital assets, the standard raises a practical audit question: does the crypto accounting software and AML tooling in the current stack perform screening at transaction initiation or only at settlement? For clients holding stablecoins in any volume, or operating with treasury automation that instructs on-chain transfers, the answer to that question defines whether real-time risk assessment is even possible.
Firms should also examine whether their digital asset accounting software integrates with on-chain risk data in a way that timestamps the risk assessment relative to the transaction, not just at month-end reconciliation. This is relevant both for internal controls and for evidencing to auditors that screening occurred at the appropriate point in the payment lifecycle.
Board and senior management accountability
The standard's emphasis on accountability for automated systems echoes the personal liability framing that financial regulators in the UK, EU, Singapore, and elsewhere have been developing for crypto-specific AML obligations. Where an autonomous agent or treasury automation tool executes on-chain transfers, the MLRO or Chief Compliance Officer needs a clear documented basis for asserting that the system operated within defined risk parameters. A principles framework like the Elliptic Standard, even if adopted voluntarily, can provide part of that documented basis.
CFOs at digital asset businesses should consider whether the risk appetite statement and AML policy documentation currently in place addresses agentic transaction scenarios, including what happens when an autonomous agent attempts a transaction that would breach a counterparty risk threshold.
Vendor due diligence and procurement
When evaluating or renewing contracts for crypto bookkeeping software and on-chain risk tooling, the principles in this standard provide a useful evaluation lens. Key questions include: does the vendor provide real-time screening rather than batch review? Does the vendor's risk methodology account for AI-driven evasion tactics, not just static typology lists? Is there a clear audit trail that maps each risk assessment to the specific transaction and the specific point in time at which it was assessed?
This last point has direct accounting relevance. For firms applying IFRS 9 or US GAAP expected credit loss models to crypto receivables, or for those subject to sanctions compliance obligations, the timeliness and traceability of risk assessments forms part of the audit evidence base. Understanding sanctions screening obligations for crypto transfers as they are evolving at the regulatory level reinforces why tooling decisions made today carry longer-term compliance weight.
The Broader Context: Why Agentic Risk Is Not a Future Problem
It would be convenient to treat agentic on-chain risk as an emerging concern that only affects cutting-edge DeFi protocols or large centralised exchanges. The evidence does not support that framing. Treasury automation tools that execute stablecoin payments, crypto payroll systems, and on-chain settlement layers used by mid-market firms are all forms of agentic activity. The agent may be a scheduled script rather than a sophisticated AI model, but the compliance gap is the same: no human reviews the specific transaction before it settles.
Illicit actors are not waiting for the standard to mature
Elliptic's observation that illicit actors are already embedding AI into their operations is consistent with findings from other supervisory and law enforcement bodies. The NCA in the UK, for example, has documented how laundering methodologies are becoming more technologically sophisticated. Understanding how AI-driven laundering tactics are reshaping UK AML requirements gives compliance teams a useful parallel frame of reference alongside the Elliptic Standard.
The convergence of rising stablecoin volumes, increasing automation of legitimate treasury activity, and AI-assisted illicit activity creates a compliance environment where the principles in this standard are likely to be absorbed into regulatory expectations faster than comparable industry frameworks have been in the past. Firms that engage with the framework now, map it against their current tooling, and identify gaps are better placed than those who defer until a regulator mandates equivalent controls.
What Accounting and Compliance Teams Should Do Next
The Elliptic Standard is a published framework, not a regulatory requirement, so the response does not need to be a crisis mobilisation. It does warrant a structured review.
Practical steps for compliance and finance teams
First, map the agentic touchpoints in your current operations. Any automated process that initiates or settles an on-chain transaction without human authorisation at the point of execution qualifies. That includes treasury automation, crypto payroll, DeFi yield strategies run by automated vaults, and any API-driven exchange settlement.
Second, assess whether the risk screening associated with each touchpoint happens pre-settlement or post-settlement. Where it is post-settlement, document the residual risk and the compensating controls, such as position limits, counterparty whitelisting, or manual batch review cadence.
Third, review whether your crypto accounting software and AML tooling contracts include any commitments to real-time screening capability, and check the vendor's published methodology against the direction of the Elliptic Standard's eight principles once the full text becomes available.
Fourth, ensure that the policy documentation covering autonomous transaction systems is captured in the AML risk assessment and that the MLRO or equivalent has formally signed off on the residual risk. This is the accountability trail that regulators and auditors will look for if a compliance failure occurs.
Frequently Asked Questions
What is the Elliptic Standard?
It is a set of eight principles published by Elliptic in September 2026 for managing on-chain risk in environments where autonomous agents are transacting and AI is being used by both legitimate operators and illicit actors. Elliptic describes it as the first published standard specifically designed for agentic on-chain risk.
Does the Elliptic Standard have regulatory force?
No. It is an industry framework published by a blockchain analytics firm. It does not carry the authority of a regulatory rule or supervisory guidance. However, industry standards of this kind frequently shape regulatory expectations over time and can be cited in supervisory reviews as evidence of what reasonable practice looks like in a given period.
Why does the $33 trillion stablecoin figure matter for compliance teams?
Volume at that scale, growing 72% year on year, means that legacy batch-review workflows are increasingly inadequate for managing counterparty and sanctions risk. At $33 trillion in annual settlement, the average daily volume exceeds $90 billion. A post-hoc review cadence that catches a sanctioned-party transaction days after settlement creates both regulatory exposure and potential asset recovery complications.
How does agentic risk differ from standard automated transaction risk?
Standard automation, such as a scheduled payment batch, typically operates within a narrow, pre-defined parameter set and is reviewed by a human before or shortly after execution. Agentic systems can make context-dependent decisions, modify execution parameters in response to on-chain conditions, and settle transactions at a speed and frequency that makes individual human review impractical. The compliance gap is qualitatively different, not just larger.
What should CFOs prioritise when reviewing their digital asset accounting software in light of this standard?
The most urgent question is whether the tooling provides risk assessment at transaction initiation rather than only at settlement or month-end reconciliation. Beyond that, CFOs should verify that the audit trail produced by the software is granular enough to evidence, for both internal audit and external regulators, that screening occurred at the correct point in the transaction lifecycle and that the risk methodology in use accounts for AI-assisted evasion techniques.
Source: Elliptic
