Can privacy infrastructure protect criminals?
Yes.
At least sometimes.
If we build infrastructure that protects people from surveillance, administrative seizure, forced disclosure, and centralized control, those protections will not be reserved for people we approve of.
The same architecture that hides a company’s payroll can make illicit flows harder to trace. The same exit rights that protect an innocent user from a hostile intermediary can also prevent an operator from freezing a criminal’s funds on command.
Freedom cuts both ways.
But the mirror image matters just as much.
A system designed to exclude criminals can become infrastructure for excluding everyone who fails to satisfy the dominant credential regime.
Privacy architecture needs to confront that tradeoff.
The previous article set out six architectural safeguards and asked what social pressure could still make unavoidable. This final piece confronts the risks of both strong privacy and pervasive permissioning.
The criminal-to-criminal case is the hardest
Imagine two malicious parties.
They control their own wallets. Neither asks the other for KYC, sanctions screening, source-of-funds evidence, or an auditor.
If the settlement layer is private and permissionless, the base protocol cannot magically discover that their commercial purpose is criminal.
Cryptography can prove:
“This transaction is valid.”
It cannot prove:
“This transaction is morally legitimate.”
ZKC can prove eligibility predicates when a counterparty asks for them. But if neither party asks, there is no counterparty-imposed compliance requirement to satisfy.
ZKM can prove that an agent acted within a principal’s mandate. But a criminal principal can authorize criminal activity.
AFP can authenticate cryptographic principals. Cryptographic identity still does not make their intentions lawful.
This is a fundamental boundary of the architecture, and we should not pretend otherwise.
Why not require compliance everywhere?
There is an obvious response.
Require KYC before value can move. Require a global sanctions predicate. Give regulators or protocol operators a key that can freeze suspicious assets.
That would make some enforcement easier.
It would also destroy much of what the Freedom Safeguards are trying to protect.
The moment every valid transaction requires Predicate X from Provider Y, Predicate Pluralism is gone.
The moment credential status determines whether a holder can withdraw their own value, compliance has crossed from the interaction layer into custody.
The moment an administrator can freeze valid notes, the infrastructure has reintroduced a master key.
And once that capability exists, it exists for everyone.
A system designed for a benevolent regulator still contains the same control surface when the regulator is not benevolent.
Privacy is not the same thing as impunity
The mistake is assuming only two models are possible:
total transparency
or
total secrecy.
There is another possibility:
private infrastructure with accountable interaction boundaries.
A regulated institution can require stronger predicates before entering a relationship.
A principal can revoke an agent’s authority.
A counterparty can retain evidence.
A legitimate investigation can use records held by the parties involved.
What the architecture tries to avoid is a universal observer that sees every relationship, payment, identity, and compliance event by default.
That is different from impunity.
Legitimate commerce can create a perimeter
A criminal may be able to transact privately with another criminal.
But eventually, many criminals want something in the legitimate economy: a bank account, regulated exchange, supplier, marketplace, real estate, professional service, cloud provider, or corporate counterparty.
At those boundaries, legitimate institutions can require evidence.
If the actor cannot produce acceptable KYC, sanctions, source-of-funds, provenance, or other required proofs, the institution can refuse the interaction.
The underlying private asset does not disappear.
But privacy alone is not enough to enter the relationship.
The goal is not:
“Make illicit value impossible to possess.”
It is closer to:
“Make opacity insufficient for admission into participating legitimate commerce.”
That is isolation by interoperability requirements rather than confiscation.
It is not magic. Criminals can use mules, stolen identities, sham companies, corrupted issuers, weak institutions, or remain outside the compliant perimeter entirely.
Privacy-preserving compliance does not “solve money laundering.”
At best, it changes where accountability lives.
The layering problem remains serious
Settlement privacy can make the layering phase of money laundering harder to observe.
If illicit value moves through shielded transactions, observers may have a much harder time reconstructing the flow. Coordination privacy can make the relationship graph harder to map as well.
Those properties are valuable for legitimate enterprises.
They are also useful to criminals.
One possible response is privacy-preserving provenance proofs. A regulated institution might require proof that value satisfies a defined provenance rule without demanding the holder’s entire transaction graph.
But that immediately creates governance questions.
Who defines the acceptable set?
Who decides what provenance is prohibited?
Can innocent users be wrongly excluded?
Can network effects turn one blacklist into the de facto global standard?
Can provenance proof itself become another form of economic permissioning?
Those are political questions expressed through technical infrastructure.
The mirror-image danger
Now turn the problem around.
Imagine a future where every meaningful transaction requires proof of approved identity, jurisdiction, source of funds, reputation, employment status, insurance, or AI-agent policy.
Technically, nobody seized your money.
Technically, the proofs were “voluntary.”
Technically, multiple predicate providers still exist.
But if every major counterparty requires the same proofs, refusal becomes economically meaningless.
That is another kind of dystopia.
The criminal-use problem and the over-compliance problem are mirror images.
One asks:
What happens when privacy is too strong?
The other asks:
What happens when permissioning becomes too strong?
A serious architecture has to think about both.
Freedom Safeguards help, but they do not solve the social problem
The Freedom Safeguards constrain protocol power through ideas such as minimal disclosure, Predicate Pluralism, open predicate logic, unconditional exit, no administrative asset revocation, and accountability for whoever demands a proof.
Those constraints matter.
But they are not enough by themselves.
Predicate Pluralism can exist formally while markets converge on one dominant issuer.
A disclosure can be technically voluntary while employment or commerce makes refusal impractical.
A scoped pseudonym can reduce global linkage while becoming a durable tracking identifier inside an important relationship.
A verifier can authenticate a coercive demand.
And private decision systems can make discrimination harder for outsiders to observe because exclusion happens one encrypted interaction at a time.
These are reasons to describe the safeguards accurately, not to abandon them.
They are necessary architectural constraints, not a complete constitution for society.
Autonomous agents raise the stakes
Autonomous agents can industrialize whatever policy we give them.
An agent does not get tired of checking credentials.
It does not hesitate before enforcing the rule against the millionth applicant.
If machine-verifiable eligibility becomes embedded into autonomous commerce, exclusion can happen instantly, consistently, privately, and at enormous scale.
The machine economy may create two kinds of opacity at once:
privacy for the subject, because unnecessary data is hidden,
and
privacy for the decision system, because outsiders may struggle to observe who is being excluded and why.
That second form deserves more attention.
The line I do not want to cross
I do not want to design systems that optimize for evasion or make criminal investigation impossible as a product goal.
But I also do not want to solve those problems by creating:
- a universal identity layer,
- a global financial surveillance graph,
- an administrator freeze key,
- compulsory disclosure to every counterparty,
- or a protocol-level authority that decides who is allowed to own or move value.
And I do not want to pretend that moving control from the protocol to counterparties eliminates coercion.
If every counterparty makes the same demand, decentralization at the protocol layer can coexist with centralization at the social layer.
The architecture therefore has to minimize the powers it creates and remain honest about the powers it cannot prevent others from accumulating.
Freedom has a shadow. So does control.
Strong privacy can protect people we wish it did not protect.
Strong exit rights can benefit people we wish we could stop.
Strong metadata protection can frustrate investigations we wish were easier.
The alternative has costs too.
A surveillance system designed to catch criminals watches everyone.
A master key designed to freeze illicit assets can freeze legitimate ones.
A universal compliance layer designed for good governments still exists when the government changes.
And a supposedly voluntary credential economy can become a permission system without ever placing a freeze key in the protocol.
So the question is not whether one side of the tradeoff is harmless.
Neither is.
The question is:
Where should power live, and what capabilities should we refuse to create even when creating them would make enforcement easier?
I do not have a perfectly comfortable answer.
I am increasingly convinced that good architecture should make legitimate accountability possible while making universal control difficult.
And cryptography cannot guarantee freedom if every institution around the protocol chooses coercion.
That is not a reason to stop building safeguards.
It is a reason to stop mistaking safeguards for the end of the argument.
Disclosure: I am an active contributor to the ZKA/ZKC/ZKM/AFP protocol family discussed here. This article is a reflection on the dual-use and governance risks of the architecture I am helping develop, not a claim that the current specifications eliminate money laundering, illicit finance, coercive credential regimes, discrimination, or other abuse.
The series began by asking whether enterprises could transact on public rails without exposing their business. It closes with the question that privacy alone cannot settle: where should power live?