Kod Yasal Ödeme Aracıdır: CBDC'lerin Gömülü AML/CFT Uyumu ve Tasarımla Belirlenen Politikaların Sınır Ötesi Sınırları
Central Bank Digital Currencies in Legal Perspective, Hamburg, Almanya, 28 Ağustos 2026, (Yayınlanmadı)
- Yayın Türü: Bildiri / Yayınlanmadı
- Basıldığı Şehir: Hamburg
- Basıldığı Ülke: Almanya
- Ankara Üniversitesi Adresli: Evet
Özet
The late twentieth century was shaped by Lawrence Lessig’s paradigm that “code is law” asserting that software architecture regulates conduct as powerfully as legal rules, and often escapes the constraints imposed on law. Central bank digital currency (“CBDC”) escalates the thesis since the code becomes not merely law but the legal tender. Therefore, the CBDCs’ code does not merely regulate digital behaviour; it regulates the economic life. The issuer can write policy directly into the instrument of payment. Such embedded design could serve many ends including monetary, fiscal, or the control of capital purposes. However, this paper takes anti-money-laundering and counter-terrorist-financing (AML/CFT) compliance as its sharpest case, because that is where the most consequential rules are coded into the money itself. Although augmentation of AML/CFT compliance is one of the perceived benefits of the CBDCS, this paper argues that enforcing policy through architecture rather than legal process is both legally deficient and self-defeating. The deficit deepens once the currency crosses borders.
The first loss is the standard itself. The risk-based, case-by-case approach that the Financial Action Task Force (FATF) has made the global benchmark cannot survive encoding. Deterministic logic replaces proportionate judgment, and compliance ceases to be a set of rules that must be obeyed and becomes a set of rules that cannot be breached. The standard is not implemented but displaced.
Secondly, to screen every transaction against embedded rules, the code must see every transaction through automated compliance and total transactional visibility. It places the design in standing tension with the foundational principles of data-protection law, particularly with the constraints on solely automated decisions. Since “code is legal tender”, the law may come to define its own horizons within the technical limits permitted by design rules. The same determinism makes the system over-block since the code lacks the judgment the risk-based approach assumes. It might refuse a legitimate transaction a human compliance officer would clear. Embedding that caution in the money hard-codes, at the ledger scale, the over-compliance that the FATF’s own unintended-consequences would work now treats as a systemic threat to financial inclusion; and therefore, it might drive the excluded toward the opaque channels. The instrument, which aims to increase inclusivity, undermines the very goal it encodes.
The third loss is authority, and it is where the cross-border dimension becomes acute. When code is the law, a freeze executes autonomously, leaving no obvious respondent, no forum, and so no effective remedy. The problem changes character once the embedded rule is a foreign state’s sanctions or compliance screen executing on another state’s territory. The issuer’s monetary rule becomes self-executing abroad. The question of extraterritorial jurisdiction and monetary sovereignty prevails over consumer protection. Exploring the design and technical options, the paper asks how domestic and international law can reclaim authority over the code: how liability is allocated across central banks, intermediaries, and code providers, and additionally what remedy and privacy architecture a cross-border CBDC must aim at for embedded AML/CFT compliance to be lawful rather than merely automatic or, in other words, to reflect policy by design.