




Sep 9, 2026 - 40min
EPISODE 119
How Institutions Can Use Permissionless Rails with Rebecca Rettig and Michael Mosier
With Rebecca Rettig, and Michael Mosier, and and
In this episode of TRM Talks, Ari Redbord is joined by close friends and two of the most important voices in our space: Rebecca Rettig, Chief Operating Officer and Chief Legal Officer at Jito Labs, and Michael Mosier, founding partner of Arktouros and former acting director of FinCEN.
Rebecca developed deep subject matter expertise as a financial-services litigator working with the earliest DeFi protocols, including an early pitch to Uniswap when the team numbered four people in a Williamsburg loft. Michael came through DOJ, OFAC, and FinCEN, and traces a through-line from protective orders for domestic-violence survivors to cryptography as a tool for people living under authoritarian control.
The focus is on the future of DeFi. In a brand new paper, the dynamic duo lay out a framework institutions can implement under current law, and explains why OFAC and BSA enforcement has never targeted SWIFT, telecoms, or RPC nodes the way critics fear it will target crypto infrastructure. They cover the GENIUS Act's focus on issuers rather than networks, US DOJ’s prosecution of a Tornado Cash developer and the Blockchain Regulatory Certainty Act. Mosier also addresses the panic around AI, arguing these systems function as motion sensors rather than a person standing in front of the car with a red flag.
Click here to listen to the full episode: How Institutions Can Use Permissionless Rails with Rebecca Rettig and Michael Mosier. Follow TRM Talks on Spotify for new episodes.
Ari Redbord (00:02):
I'm Ari Redbord and this is TRM Talks. I'm Global Head of Policy at TRM Labs, we provide blockchain intelligence software to support law enforcement investigations and to help financial institutions and cryptocurrency businesses mitigate financial crime risk within the emerging digital asset economy. Prior to joining TRM I spent 15 years in the US federal government, first as a prosecutor at the Department of Justice, and then as a Treasury Department official where I worked to safeguard the financial system against terrorist financiers, weapons of mass destruction proliferators, drug kingpins, and other rogue actors. On TRM Talks, I sit down with business leaders, policymakers, investigators, and friends from across the crypto ecosystem who are working to build a safer financial system.
(00:53):
On today's TRM Talks, I sit down with legal legends, Michael Mosier and Rebecca Rettig. But first, Inside the Lab, where I share data-driven insights from our blockchain intelligence team. On today's Inside the Lab, we're digging into the stablecoin data because stablecoins are no longer a crypto subcategory, they're global financial infrastructure. In 2025, stablecoins processed approximately four trillion in onchain activity. That number reflects not speculative trading alone, but settlement rails for exchanges, cross-border Treasury operations, remittance corridors, and institutional liquidity provisioning. Stablecoins now represent a substantial portion of total crypto transaction volume and are increasingly embedded in payment flows outside traditional banking system. But here's the critical data point. Illicit use is not proportional to that volume. It is concentrated. Sanctions related activity in 2025 was overwhelmingly driven by Russian-linked flows. The ruble pegged stablecoin A7A5 processed more than 70 billion in total volume. That 70 billion was not just the driver of sanctions activity in 2025, it was a driver of overall activity.
(02:14):
Meanwhile, overall illicit crypto volume reached 158 billion in 2025, according to TRM's 2026 crypto crime report, up nearly 145% from the prior year, yet illicit activity as a share of total crypto volume declined from 1.3% to 1.2%. That tells us the ecosystem is expanding rapidly, but specific high risk corridors are scaling aggressively with it. The strategic lesson is this. When trillions move across stablecoin rails, risk management must focus on liquidity concentration and network architecture. Stablecoins power lawful global adoption, but they also power industrialized sanctions evasion and high risk flows like A7A5. Visibility into structured clusters, not isolated transactions is what separates the noise from the real exposure. And now the dynamic duo, Michael Mosier and Rebecca Rettig. Today we have the most special of episodes, two great friends, Michael Mosier and Rebecca Rettig. Michael is the founding partner of Arktouros and the former acting director of FinCEN and so many other amazing things in this space for so long.
(03:34):
Rebecca is currently the chief operating officer and chief legal officer of Jito Labs. But again, we're going to get into her rich storied history in this space. Let's start with your journeys before we get really deep into your collaborations, which I'm really excited to do. Rebecca, why don't we start with you? I think people look to you really oftentimes as this bridge between how we should think about regulatory and policy, but then sort of deep tech expertise, particularly on the legal issues. How are you? How did you get to this place where you are a go-to person in that way?
Rebecca Rettig (04:06):
Where I started does not actually portend like where I am now. I was just a traditional financial services lawyer at a big New York firm for a long time. I did litigation, regulatory enforcement work. I'll say the one thing that we were taught as young lawyers, because we were all generalist litigators, was you can learn all the skills of law, but you actually need to become a subject matter expert every time you're giving advice or litigating a case. So you could do an IP case on peer-to-peer music or file sharing software, which I worked on a long time ago just to date myself, but you could also do some environmental case or an accounting case with fraud during the JP Morgan or Bear Sterns stuff, which I also worked on. And so I think that skillset of becoming a subject matter expert has informed how I tackle everything in the law.
(04:56):
So I worked at a big law firm for a long time and then I decided, I had this revelation one day like, "Oh, I want to be an entrepreneurial lawyer." And I had gotten interested in Bitcoin in about 2013, and it was 2017 and things started heating up, and I took myself to a small conference in the basement of a hotel on 44th Street and 8th Avenue or something like that. And Andrew Keys was there back when he was at Consensus, so it was a big thing. And so I just started doing more and more in the space, meeting more lawyers, meeting more builders, and started pretty early just trying to figure out and become a subject matter expert on what the technology was, what was happening, as I did one of the very early trading arbitrations between one of the large exchanges and a bunch of whales.
(05:44):
They were paying maker-taker fees way back in the day, the exchanges were, to get more trading and more liquidity. It's something that hasn't changed a lot fully in crypto. It has on the centralized exchange side, but not necessarily on others. And that I think was my first big case and had to really learn about bots because part of the dispute was over the fact that these whales were using bots and the exchanges didn't anticipate that. And so that was my first entry big time into the space.
Ari Redbord (06:13):
Can I double click on two things before I ask you to keep going with your journey? Because I think that sometimes this show is instructive for folks. Young lawyers reach out all the time, I know they do to you guys too, and say, "Hey, I want to be a crypto lawyer. What should I be doing?" Used to hear about sports law and entertainment law and all these things. And oftentimes what I say is you need to become an expert on whatever the area is that you're going to need to know in this area. So you're a financial services lawyer by training, you leaned into the technology to understand the space, but it's like you want to be a crypto lawyer, really understand the regulation, really understand financial services. It's not necessarily like there's this thing that is a crypto lawyer. It's understanding all of that.
(06:51):
But the other piece to this is what caused you to go down the rabbit hole the way you did? I think what differentiates you in so many respects between other lawyers in our space is that deep technology. Is it just intellectual curiosity? Is it more than that? Yeah.
Rebecca Rettig (07:05):
No, I mean it's not much more than that. I think I'm just a very curious person. I do have a lot of creative parts of my background and I thought this was a really creative part of the law. I think all of us got in and started working on this so early in so many different ways, and I think that was really exciting too. I think when we look back, we're going to be shocked at how much we were able to influence thought and how our financial system continues to be built out. I keep saying to people 10 years from now, we're going to look back and be like, "Whoa, we lived through that." But right now this is very much our day-to-day. So I think it was just curiosity. I think the reason that Mike and I write so many papers is we see things happening and then we're like, "Wait, we have all these ideas." So I mean, I think this is a very creative practice of law, and that's why I still like it.
(07:53):
It's not stopped being interesting or creative.
Ari Redbord (07:55):
Michael, I would love to hear your story and your journey. How did you go down this rabbit hole? I mean, you're such a obviously DOJ, money laundering, FinCEN. You were the first lawyer, I believe, at Chainalysis, just incredible journey at that kind of intersection, but yet you're such a voice for the decentralized space and the developers and the builders here. How did you become you?
Michael Mosier (08:18):
Yeah, thanks. I mean, that's a big question, but I think also like Rebecca, but a junior version, I didn't make it in big law for long, but I started there briefly really during e-commerce and internet heyday when things were really getting big enough that suddenly what is jurisdiction and what do you do with IP theft when suddenly it's pets.com, it's not just the pet store and people are being defrauded or they're being ripped off. And what is jurisdiction in a global commerce world? And thinking through some of that, and I was in the tech and litigation space there really briefly because while I was there, even as a summer associate, I started working with victims of domestic violence in pro bono cases to get protective orders and going to court just as a very junior person just to get these protective orders. And just that being in court and helping people be empowered to protect themselves and pursue that was just so compelling that I left pretty quickly, clerked for a federal judge and then went to the DA's office in Manhattan full-time into public service to do that sort of work, feeling like the protective orders is a great start, but that's not really doing it and wanting to do more full-time.
(09:42):
And that sense of empowering people has been the through line through all of it. At OFAC, worked a lot on the Global Magnitsky Program, which you did a lot of work at Maine Treasury on as well, and thinking through autocrats and justice in the intersection helped stand up the kleptocracy program and seeing these autocrats around the world just denying people their rights while taking all their money and times working with them through human rights groups to find witnesses, to find where did these assets go.
Ari Redbord (10:18):
It's extraordinary. I didn't know a bit of that to include your focus on domestic violence. I spent about my first four years at the US Attorney's office in DC doing domestic violence, child abuse. It was the most extraordinary experience of my life and I think went on to inform someone of what I do. Rebecca, let's dig into this paper a little bit. Literally this week, you dropped a paper together on compatibility of financial integrity with permissionless networks. Tell me a little bit about why you did it, ultimately what it's about and why it's important in this moment.
Rebecca Rettig (10:54):
Well, thank you for the opportunity to talk about it. We also had a third co-author, Omid Malekan, who's an adjunct professor over at Columbia and too and a huge proponent of the benefits of permissionless networks. I would make one tweak to this, which is I don't think the network layer counts as DeFi. Actually, just speaking of Jake, he and I just had a whole discussion about this. I think the network layer is very, very different than the app layer, and I would put DeFi, CeFi, onchain finance, whatever we're calling all these things, much more up at the app layer and think about the network layer as permissioned or permissionless, and that's really it. I think in this current era that we're in of crypto, there's a lot of blockchain, not Bitcoin and a lot more of the gated networks or enterprise blockchain. And we've seen this happen a number of times in the space, but it never really took hold.
(11:44):
But now that the cost of doing business in the blockchain crypto world is not getting a subpoena or otherwise being worried about the viability of their business, we've seen a lot of institutions push in and they, I think, have really embraced blockchain, but through an enterprise lens or through a gated lens because what I've heard a lot of both directly and indirectly through the press, through all sorts of different venues is that, "Oh, well, we can't possibly be on permissionless networks because what if we pay gas fees to a validator that's run by North Korea? Or what if a North Korean pays gas fees to us? Or what if we transact with somebody from a sanctioned country on a permissionless network?" I think that institutions are so tied to how they think of the implementation of the BSA and all attendant amendments and how they think of implementation of the sanctions laws and penalties for violations of those are very high and very severe on a regular basis that people keep thinking about these attenuated contacts as somehow being fatal to their business.
(12:48):
And we really wanted to put out a paper that says, "No, this is not. You guys withstand all sorts of things in your business." And so we wanted to put out something that was really practical. I think we felt that we've seen a lot both from clients, both from the inside, and so we put this together.
Ari Redbord (13:04):
Let's just dig in a little more. The paper does a whole bunch of different things. I think one thing I really like is the conversation/distinction between permission and permissionless, because I think that oftentimes that's even blurry for a lot of people as they're trying to understand the ecosystem. But then you do get into BSA sanctions compliance within permissionless systems. I think that's probably the meat here, especially when you're trying to, which I think in part this is trying to do, is give confidence to financial institutions that are embracing blockchain at least to engage with permissionless networks. So tell me maybe about that part, how you see that piece.
Michael Mosier (13:44):
And we grappled with it at FinCEN and OFAC both. In fact, OFAC was one of the first folks in the government to bring in IBM, early IBM poach from IBM because they're like, "We need to understand this technology and when do you hold someone accountable for using this global infrastructure?" I mean, starting with telecoms all the way through processing of wires, wire transfers, ACH. SWIFT obviously is a huge global player that has shown up in countless wire stripping and SWIFT message manipulation enforcement cases around the world. SWIFT's never been the subject of an enforcement action. There hasn't even really been a very credible discussion of that. Same with Verizon, Comcast, Cisco, routers. All of this is not new. RPC, we say this all the time, but RPC knows, go back to the 70s, it's how networks talk to each other. Nobody was out there saying we need to be getting the RPC node providers because North Korea had a saw data packet go through for them in some way.
(14:48):
And so what we tried to do was really break down what does the law say? What is dealing with a customer? What was the BSA trying to get at when OFAC does enforcement? Yes, they have an authority to have strict liability, but how is it actually implemented? And this is very clearly laid out in the enforcement guidelines. And by the way, every enforcement case that OFAC has done, including both on the designation side and the enforcement side, where it's really about dealing with and controlling transactions and the ability to stop it and who is your customer and who's your user, you can even ignore our whole paper and just go back and scroll through the OFAC enforcement actions page and read them, and you just aren't going to see infrastructure being targeted like this. And so what we tried to do is actually lay it out and say, this is what's out there.
(15:39):
If you don't believe us, go check it out, but make sure that it's all stacked up in a way that you can go through it.
Ari Redbord (15:45):
The next obvious question is, all right, what does a regime look like?
Rebecca Rettig (15:48):
We didn't want to put something out there and say you could do it and then leave it to compliance folks or institutions to figure this out. And to your point about round tables, Treasury held a couple round tables maybe three or four months ago in New York and in DC. And for me, the one in New York was heavily TradFi. It was maybe two or three crypto players total. And what we heard a lot from the TradFi players in the room, banks, asset managers, card issuers, payment issuers, they said things like, "We need to actually have a framework that we can hand to our legal and compliance teams because not that they don't believe the business side, but a little bit that they don't believe the business side." And no aspersions at all. I kind of understand that because this is the way the BSA has been implemented fine and it has variations around the edges within institutions, but they're sort of known and accepted EDD, CDD, things like that.
(16:45):
We did this in our prior paper too where we sort of said, "We're identifying the problem and here are ways to fix it."That's I think just what lawyers and policy people are meant to do, which is here's an actual solution. And I think I will give Mike credit for always saying people in crypto can't just keep saying no. They have to say no, but here's a path forward. And so for me, I think that's actually what inspired a lot of the ideas about writing papers together is that we actually have ideas of what solutions may be. So this is not a, just to restate it, this is not a, we're changing the law or we think there need to be changes in law to allow people to do it. It's like, here's how you do it under the law as it's written today.
Ari Redbord (17:23):
The thing I love about this is not only are you saying, Hey, you don't need to change the law, this is a framework within the law today, you're using the language that regulators use to frame all of these issues. If you look at OFAC, that's what they're looking for. They're looking for screening, they're looking for geolocation. You're saying, hey, no, we're building exactly what you're asking for over the years, whether it's in guidance or enforcement. I kind of have a hairier question for you, if you will. And that is you're writing about these issues obviously because we really still haven't ever seen not only regulation or policymaking really line up with DeFi. And I think that's the reality is Clarity goes deep on how you deal with mostly centralized crypto. Obviously GENIUS is for stablecoin issuers, but I know what you guys are doing feels like, hey, how do we finally get to a place where policymakers understand decentralized systems and what a regulatory framework can look like?
(18:22):
What has been the problem or the gap there over the years, if you will, if you agree with my premise?
Michael Mosier (18:29):
I do, and I would take it back to something Rebecca said earlier, which was that distinction of the infrastructure layer as well. Part of it is historical and it's everyone moving fast because the world's moving so, so fast, which we're seeing in the AI agent space hourly it feels like. And as Rebecca said, there's the infrastructure layer, there's the application layer, you have genuine DeFi, you have CDFi, and you have CeFi and you have TradFi. And I think part of what we've been trying to grapple with in both papers is that there's multiple, multiple layers to this and that it's important that even though in the DeFi space, it's like those early Apple computers where it was transparent and you could see all the workings. It didn't suddenly make a certain RPC connection in there into a money transmitter or a separate data transmitter. Yeah, you can see a lot more and a lot more is transparent, but we don't want to suddenly treat them drastically differently than we ever have before.
(19:31):
And so some of what we always anchor it in historical because thinking some of these are really new issues and some of these are actually not new issues around liability. At what point do you have consumer liability because something you created does a thing? That's not brand new. That goes back to Falsegraph and Dynamite on the train platform. That's not new at all. And we're seeing it in different permutations, but likewise, the infrastructure's been there in different ways. There's been different ways about thinking about really liability, but whether that's financial integrity or consumer liability in a space where someone put something out there. And I think what's complicated it, but also really empowered people is there are a lot of public goods being produced, which again, we also had with Linux. There was a point in Linux where everybody was like, "Oh my God, what do you do?" It's like people can just contribute to open source software.
(20:26):
Open source software itself is not new. But I think part of this is grappling with the fact that there's also more and more financial value happening through these systems and how do we think about managing risk in a way that is also helping protect people.
Rebecca Rettig (20:42):
To go to your point and to what Mike was saying, understanding DeFi, I was with somebody from a huge Tradfi institution yesterday and they kept saying DeFi over and over. And I said, "Oh, what DeFi apps have you used?" And they said, "Coinbase." So I think that the term has been thrown around so much, it's partly why Mike and I worked on the last paper together to try to be really precise in our definitions. And I don't know if we're going to be successful because the term has gotten away from us. And one of the terms that you didn't use was onchain finance, which is also something that's coming now into the vernacular, and that I don't think has been defined either. Probably see DeFi, but who knows? I think the other part on what are we going to do about regulation in DeFi is, and I've said this a number of times, Clarity is the only piece of legislation anywhere in the world that takes on DeFi or CDFi at all.
(21:30):
And it would be the only piece of enacted legislation that has any DeFi provisions in it. And I think that's just important to take away and know. And whatever you want to say about whether Congress understands or doesn't or certain offices understands or doesn't, I think everybody who's worked on this, and there have been a ton of people both on the industry side and on the Hill side of things who've worked really hard to think through these provisions, whether we like them or not or whether we like some of them or not, but there's a provision in there even that enables or allows for institutions to be able to put it together a risk management framework for how they engage with DeFi apps. On that note and to tie it back to the paper, I think as we were ideating around it, Mike made two really important points which are in the paper too, and they're not the front points, but they're in there and I think they're really powerful.
(22:20):
One of which is that Genius and the implementing regulations that are going to be put around Genius actually support the way we put together the compliance framework or the risk management framework, which is that we are not going to be mediating at the network layer. We're going to be mediating issuers who are the apps. Stablecoins are apps too in many ways. So I think that's really important. I think the other thing is we talk a lot about some of the benefits that institutions may gain from using permissionless networks. And one of those is that you will get a lot of regulatory insight into the financial services perimeter in a way. It's a very important takeaway, which is this is going to allow better regulation, better view into the financial services sector.
Ari Redbord (23:07):
I love it. And to just double click on that point, literally the audience for this are exactly these people. They're compliance professionals, many at traditional financial institutions. People ask me all the time, what should I read? Read this if you're listening. I think it's really, really important. You both have mentioned AI, and I think there's probably a huge, which has moved faster than anything in our lifetime as much as we wish it was crypto, I know. But I think the reality is that AI will play a huge role in the framework that you've developed. And I talk a lot about, well, we should have sandboxes and we should have opportunities to use these without being potentially sanctioned for it. Not sanctioned in that way, but sanctioned by your regulator. How do you think about AI when you think about a framework like that or even take it beyond that?
Rebecca Rettig (23:52):
Well, I was going to say I've had the same experience both with financial institutions and with law firms, but especially on the financial, I literally had a discussion about this yesterday with somebody who works at a bank and they were like, oh, regulations say we can't just drop XYZ into AI. We have to hand input certain things. I'm like, "What regulations?" And they're like, "Well, that's what the compliance department is telling us that we can't drop a term sheet into Claude or we can't do this into whatever LLM they are using." And I was just like, "I don't think there are any regulations that say that yet, but I think it's the same type of fear as using permissionless networks."
Michael Mosier (24:32):
Going back to the other themes of we've seen some of this before, it's thinking through how do we assess risk and safety and how do we assess liability around it? And I think what we're seeing even more, and I think faster in the AI space, which we went through a period in the crypto space with chain audits, is the security audits piece. Is this going to do what we think it's going to do? And there was a period where, remember being in-house and having this experience with a lot of people of the hardest thing to do was get an audit of your smart contract because everybody suddenly realized this is a huge risk. And I think the sooner. There was just a study, I think it was Anthropic or one of these agents, they asked it to hack itself and it immediately got out of the sandbox and then came up with 20 more vulnerabilities on itself.
(25:23):
And I think if we approach this even as a regulator as well in terms of obviously just like the internet, obviously we're not going to not use the internet. Obviously we're not going to use these trains like the telegraph. So let's think of rationally, what are the real risks here? We don't need another red flag where there is to walk in front of a car with a red flag waving it so that it's going slowly enough so everyone can handle it. It's actually what we need are motion sensors that detect that you're going out of a lane or you're going too close to another car. That's what we need to develop. So I think it's how do we develop the risk detection tools that can operate at the speed of these new tools, whether it's decentralized finance or CFI even by the way, and just twenty four seven settlement, or is it these agents that suddenly can move at exponential speed and we're just so far past. I mean, I will say this does make me realize as much as we denigrate the bank working hours when the world is moving at twenty four seven, it sounds actually awesome now and then to stop work at five.
(26:32):
And so having the risk management in place that we can be detecting that stuff that's not reliant on Ari sitting at the switchboard ready to pull a cord out if someone's making a call that they shouldn't be.
Ari Redbord (26:45):
Really well said. I mean, we talk all the time about guardrails. I think the scariest part is these open models where it's going to be very, very hard to ever implement those types of controls.
Rebecca Rettig (26:53):
We're just going to have to grapple with a lot of the same issues. A lot of what digital asset lawyers went through over the last decade is what the AI lawyers need to grapple with now. How do we deal with open versus closed networks? It goes exactly to what you were saying about how do I become a crypto lawyer? It's like you need to know every set of financial services regulations out there because of the things it touches on. So a lot of the lessons that, as Mike said, we've learned over the last few years, we're going to have to learn here now. And I think that one of the things that came out this week is that closed models are building on top of offshore open models and what does that look like and what does that mean? And we've been grappling with that even now in crypto. So I think that's really important to think about as well as we go forward.
Ari Redbord (27:36):
Whether it's this sort of how financial institutions can engage with permissionless networks, whether it's the AI issues we discussed today, you guys are literally, I mean, you are the two people who are in the conversations at the highest levels, whether it's policymakers on Capitol Hill, whether it's regulators. What are the big issues that you guys are hearing or the issues that you see most important in this space today?
Michael Mosier (27:57):
I'll give a short one. To me, it's actually, and I mentioned this before, it's the confusion around what's left of the FinCEN guidance after the SDNY storm case. And I think the Blockchain Regulatory Certainty Act is to me one of the biggest issues because you've got the key regulator FinCEN with the 2019 guidance saying we draw a line about what is independent control that we're going to hold you liable for, going back to false graph and decades and decades and being consistent with that. And the issue, which goes to even the people that are developing the risk tooling around this is at what point can I build a thing and contribute to Linux and I might be held liable? We put out the 2019 guidance. FinCEN, I think actually you were at Maine Treasury and probably approved it, Ari, so you have some authority on this as well.
(28:52):
The 2018 guidance on virtual currency, and again, to draw these lines and provide clarity so that people would build and empower people to do things. And one of them was we said, sure, an open source software, which people have been contributing to for decades, we draw the line if you're maintaining independent control over the transmission of value of when you would be held liable, that you should have registered as a money transmitter. And in the storm case with Tornado Cash, SDNY sort of rejected FinCEN's own interpretation of its own statute of whether he should have registered as a money transmitter and prosecuted him for failure to register as a money transmitter with FinCEN who had interpreted their own statutes and regulations, and he's being held criminally liable for that. He's up for the retrial. It was just pushed out to April. And I think that level of confusion that people felt like this was interpreted by the regulator and now not only would I possibly have be fined civilly like a FinCEN would do, you actually could be facing jail for it.
(29:56):
And I think that level of confusion is an anxiety that need to clarify because you have two authorities saying basically two different things.
Ari Redbord (30:05):
We've got developer protections, we've got how banks can engage with permissionless systems, AI, guardrails. Rebecca, what else is really the biggest, hairiest issues that you're seeing out there right now?
Rebecca Rettig (30:19):
So what I would say about the developer protections piece goes back to peer-to-peer file sharing in the music industry. But one of the things that came out of that that I think applies to crypto and I think really applies to AI in the same place is where does secondary liability attach for somebody who has built software and then there is a violation of law, whether civil or criminal, that comes along with it. And in the old music cases, even if they were open, they were being maintained and had other sort of controls around them. And so secondary liability attached where the developers knew or had reason to know that these would be used to violate the laws, where I'm talking about Napster, Grockster, these old, old cases. And I think that we've thought about it a lot with respect to secondary liability as it applies in the crypto space as well.
(31:14):
And I think it's going to apply with equal effect and ways we have to think about it with these AI cases because we're even seeing now, and the social media stuff as well is you have all these new types of technologies, new ways to use the internet, new apps, which I think is the important point when it comes to social media. And this is an AI agent question, which is if your agent goes rogue and does something, who's liable? The thing I always have struggled with in thinking about this is where is the causation element here? And there's not a reasonable person standard as you have when you're really looking at negligence when you do software development. Fine, if you did it and you put it out and maybe you didn't QA it or maybe you didn't do certain things, but we don't have a reasonable person standard under negligence for software development.
(32:02):
And I'm not saying we need to have that, but it is a very hard thing to contemplate when you think about can we even hold software developers liable based on what happens with software they've put out into the world?
Ari Redbord (32:14):
Let me kind of finish with this because I always do, and you two are the most interesting people I know as well. Michael, what do you do when you are not advising the government at the highest levels, advising clients on key issues? Talk me through what do you do for fun?
Michael Mosier (32:27):
The thing I'm doing right now is actually reading old Tibetan Buddhist writings. I studied it in college as a philosophy and religion major, but we've spent so much time debating and talking through emergent issues around the dynamic, what is the person, what is the self? And some of the conversations we've been having, including in policy convenings, it's so much about, well, actually we should be doing activity-based dynamic people are a collection of attributes. I mean, you know from TRM, what is a wallet risk score? It's a collection of attributes and experience that isn't static. And it just kept bringing me back to these old writings. And so I unearthed a bunch of old Tibetan Buddhist books on what is the self as a collection of attributiom. And again, to the theme that we've talked about, none of these are new issues. People have been grappling with lots of these issues, some for decades, but in this case centuries.
(33:21):
So I felt like maybe I ought to read a thing instead of just pretending it from new.
Ari Redbord (33:26):
Would you mind just digging into that a little bit more, less around the comparison piece and just more about what the writings are saying or saying to you and affecting you personally as you're reading them?
Michael Mosier (33:35):
Yeah, actually that's really interesting. That would take more reflection than I think I can gin up right now in this piece. But I think to answer that really well, because it's such a good question and is the spirit of the readings for itself. I think a lot of it is that it's like, again, you think back to what people have been grappling with for centuries and a lot of what the writings are about is, guys, don't be distracted of this. You have this idea of a static person that is a thing. It's all a collection of attributes and experiences. And in the Buddhist thinking this is the cycle of suffering is that you get attached to you're a thing as opposed to a collection of experiences and not thinking in those ways, including how you interact with other people, but also how you assess others and yourself.
(34:28):
What is it? Is it a constant evolution? I mean, everything we've talked about on this whole podcast is the constant evolution of whether it's infrastructure or interpersonal financial communications. And so I think part of this is that sense of even with all these papers, we have to think about things in a new way/none of this is new in some form and we should be thinking about and putting those two together. And I think that's the piece that comes out of these writings of a lot of this is not new issues. It's just loosening up and rolling with it, but also thinking back to how people have grappled with it in the past.
Ari Redbord (35:04):
That's amazing. In the spirit of being significantly less zen, Rebecca, what do you do for fun?
Rebecca Rettig (35:10):
So the fun things that I actually do are pretty zen, actually. I love to fly fish, really love to fly fish. And I do a lot of hiking in the mountains out west day to day. I do a lot of running and just am active, but that's really when my brain is juiciest. And look, in the same vein, I recently reread, I read Meditations by Marcus Arelius a long, long time ago and we all had to, but I just reread it at the beginning of the summer, maybe in May, and I've been doing a lot of thinking about personal choice and autonomy. And so I do feel like it's important to contribute to these writings and putting out your thoughts because it allows people to really have autonomy around the choices that they make. And I think it's really important as you talk about to be in private rooms and to be at round tables and things like that, but sharing thoughts with the world is a very, very important, empowering experience both for the people who write, but also for the people who can receive the information and figure out a new way of doing things.
(36:10):
And so I do a lot of creative writing myself on the side.
Ari Redbord (36:14):
Amazing. Just doubling on the fly fishing piece, I feel like there's probably two ways people approach it and that is what are you catching and then the experience of being out there for hours either by yourself or I think in your case, maybe with people you love. Tell me about that. Which is it for you?
Rebecca Rettig (36:30):
Well, I would say I like the feeling of being in the water. I'm a water sign. I don't know if people care about astrology who listen to you, but I find the water extremely calming. And if you really center your body and you just sit there for a long time, it is a pretty zen or experience, if you said. I don't mind catching big fish. I caught my biggest fish ever this summer, which was a two pound white fish. So I do get a kick out of it, but I have both sides of myself and I bring this to my fly fishing endeavors.
Ari Redbord (36:59):
Amazing. Michael, Rebecca, thank you so much for joining TRM Talks. This was as amazing as I knew it would be. I said this on the show, but for me, so much of this space and the experience that I've had over the last six years are the people. And Michael and Rebecca are folks I've known even before my time at TRM and just so meaningful to be able to have a conversation like this. And it's just so cool to see how they've grown, but also sort of how the issues have grown. I love Michael's through line for him as a domestic violence prosecutor at the Manhattan DA's office and then ultimately to FinCEN, but sort of inclusion and privacy and people having an opportunity to access to their funds as such an important piece of his journey. So that was something that was a huge takeaway for me.
(37:48):
And then in terms of their paper, I mean, I think they've been singularly focused and focused together, which has been so cool on how do we really ensure the promise of permissionless systems, whether that means as critical infrastructure, which is the first paper they wrote or how financial institutions could adopt or engage with permissionless systems. So I think obviously so, so critical. Look, these are two of the people or the two people in my mind in many ways who are having the most important conversations and are really looked to somehow Michael with his experience as acting director of FinCEN at the money laundering section within the Department of Justice as a DA has obviously that deep government regulator prosecutor experience, but yet I think his focus on DeFi and on financial inclusion has really made him a bridge between regulators, policymakers and the decentralized space people who are building developers.
(38:50):
And then Rebecca, the same. She's kind of gone the opposite way almost where she has become really a voice for developers. But I think because of some of the positions she's taken, the reasonableness, the approach, the fact that she makes the right arguments, "Hey, we understand the BSA is going to need to exist. How can we fit permissionless systems within the current framework?" I think has really made her a go-to for regulators and policymakers. Honored to be their friend, honored to be involved in a conversation like this today. On the next TRM Talks, I sit down with Amy Oldenberg, the head of digital assets for Morgan Stanley. If you love the show, leave a review wherever you're listening to it and follow us on LinkedIn to get the latest news on crypto regulation, compliance, and investigations.
TRM Labs (39:40):
TRM Talks is brought to you by TRM Labs, the leading provider of blockchain intelligence and anti-money laundering software. This episode was produced in partnership with Voltage Productions. The music for this show was provided by iKOLIKS.
Ari Redbord (39:57):
Now let's get back to building.
About the guests

Rebecca Rettig is the Chief Operating Officer and Chief Legal Officer at Jito Labs, the team behind the most widely adopted software and applications in the Solana ecosystem and one of the most important infrastructure companies in crypto today.
As COO, Rebecca builds the organizational infrastructure that allows a lean, technically elite team to scale and execute; as CLO, she charts the company's course through the most complex regulatory terrain at the crossover between technology and finance. Together, these roles place her at the intersection of operational excellence and legal vision in one of the most dynamic sectors in technology.
A recognized pioneer in blockchain law and policy, Rebecca has spent the better part of a decade shaping legal and regulatory frameworks for decentralized systems. Few attorneys have shaped crypto policy as visibly or consistently: she has been invited to address the Financial Action Task Force, the SEC's Crypto Task Force, as well as the European Commission and the European Banking Authority, among others; has been invited to testify before Congress; and has published widely on DeFi policy, including in the Journal of Financial Regulation.
Rebecca serves on the boards of the Texas Stock Exchange, the DeFi Education Fund, and the Blockchain Association, as well as NYDFS's Virtual Currency Advisory Board; she previously sat on the CFTC's GMAC Digital Assets Subcommittee. She began her legal career at Cravath, Swaine & Moore LLP and remains Of Counsel at Arktouros PLLC, a boutique firm focused on cutting-edge technology companies.

Michael Mosier co-founded Arktouros, a boutique law firm of former senior officials and in-house counsel dedicated to emergent technology and civil society. He twice has been the first in-house counsel at tech companies: Chainalysis (blockchain analytics) and EspressoSystems (configurable privacy & cross-chain composability). In public service, Michael served as Acting Director of FinCEN (the U.S. Financial Intelligence Unit & administrator of the Bank Secrecy Act); head of Sanctions Compliance & Enforcement at Treasury's Office of Foreign Assets Control (OFAC); Deputy Chief in the Department of Justice's Money Laundering & Asset Recovery Section; and a Director at the White House National Security Council.
More TRM Talks
Subscribe to TRM Talks
Subscribe to be the first to hear about new episodes, and to stay in the know about all things blockchain technology and crypto policy.