How Do You Sue Something That Doesn't Legally Exist?
A regulator sued a decentralized organization that had no office, no CEO, and no address to send a summons to. They served the lawsuit through the DAO's own chat box, and it was held up in court. Here's what that means for anyone running, funding, or doing business with a DAO that touches Canada.

A DAO got sued last year. The lawsuit was served through its own chat box, because nobody could find a person to hand the papers to.
That's the whole test DAO AML compliance is about to fail. The structure was built so there's no one to serve, no one to register, and no one to call when a regulator has questions.
A regulator found someone anyway.
What changed: a U.S. regulator successfully sued a DAO as a real legal entity, which means "no company, no liability" stopped being a safe assumption.
Who it hits: any DAO with Canadian token holders, developers, or users, and any Canadian business that transacts with one.
When: the precedent already exists. The case was filed in 2022 and a default judgment landed in 2023.
Why now: FATF has said it will regulate whoever actually controls a project, whatever the project calls itself. FINTRAC has never ruled DAOs out of scope. Nobody has tested that in Canada yet, which is exactly the kind of gap that gets tested by surprise.
Wait, Can You Even Sue a DAO?
Yes, and it's already been done.
In September 2022, the CFTC sued the Ooki DAO directly, alongside settling separate charges against the founders of its predecessor project. The regulator argued the DAO met the legal definition of an unincorporated association: a voluntary group, without a charter, formed by mutual consent, working toward a shared goal.
Then CFTC couldn't find a person to serve with the lawsuit, so a court let it serve the DAO through its own website's help chat box and by posting the summons on the DAO's public forum. A judge later ruled that was constitutionally sufficient, because the forum was where the DAO actually talked to itself about its own business. In June 2023, the CFTC won a default judgment.
So Who Actually Answers When a Regulator Has Questions?
Whoever the law can identify as controlling or benefiting from the activity, even if that's never been written down anywhere.
The Ooki DAO theory went further than just suing the DAO as a whole. The CFTC argued token holders who vote on governance proposals could, in principle, be personally liable as members of that unincorporated association.
In the judgment it actually won, the CFTC said it wasn't pursuing individual members on a joint-and-several basis this time.
Does FATF Actually Say DAOs Are VASPs?

Not by name, but functionally, yes.
FATF's guidance doesn't exempt a project just because it calls itself decentralized. It takes an activity-based approach: if there's a party that exchanges, transfers, or safeguards virtual assets, or provides services related to their sale, that party is a VASP, whatever label it uses.
For a DAO specifically, FATF has pointed to the people who actually hold the keys and control the protocol, its "owners or operators," as the ones who can be classified as the VASP, even when governance is nominally spread across thousands of token holders.
Has FINTRAC Said Anything About DAOs?
No. There's no FINTRAC guidance that mentions DAOs by name.
What does exist is the same activity-based logic Canada already applies everywhere else.
Businesses dealing in virtual currency have had to register as money services businesses since June 2020, and that requirement was never written to depend on the legal form of the business doing the dealing.
A DAO that exchanges, transfers, or manages virtual assets through identifiable Canadian participants is doing the activity FINTRAC regulates. The absence of a named policy for DAOs isn't the same as an exemption from the underlying Proceeds of Crime (Money Laundering) and Terrorist Financing Act, any more than it was for crypto platforms generally before FINTRAC caught up with specific guidance on those too.
FINTRAC has already shown it's willing to act on crypto activity it never named in advance; the 2026 crackdown that revoked around 50 MSB registrations didn't wait for a DAO-specific rulebook either.

What Should a DAO, or Anyone Doing Business With One, Do This Quarter?
-
Figure out if the DAO is performing a virtual-asset activity, not just building software. Voting on a proposal isn't the trigger. Managing a treasury, running swaps, or handling withdrawals for other people is. Run it against the same red flags an examiner would check for any other counterparty.
-
Get a legal wrapper if there isn't one already. Wyoming now offers two: the DAO LLC structure it introduced in 2021, and the DUNA framework signed into law in March 2024, built specifically so a DAO can contract, sue, be sued, and hold liability without dissolving its governance model.
-
Name someone. Even an unincorporated group can designate a person or entity to handle regulatory correspondence, the same way Canadian reporting entities can already use an agent to handle parts of their obligations while staying responsible themselves.
-
If you're a Canadian MSB, exchange, or platform transacting with a DAO's treasury or token, treat it like any other counterparty. Know who actually controls it before "it's decentralized" becomes your answer to a bank's question, since it's exactly the kind of gap that decides who gets banked and funded and who doesn't. And know what's actually at stake: operating as an unregistered virtual currency dealer carries the same exposure whether the business behind it is a company or a DAO.
Picture a DAO Run Partly Out of Toronto
Five of the twelve wallets with proposal-execution rights are controlled by people who all know each other from the same Toronto meetup scene. Nobody incorporated anything. The DAO has a treasury worth eight figures, a Discord server, and a governance forum where decisions get made in public.
A Canadian bank starts asking one of those five why large, structured transfers keep moving through an account linked to their name. "I'm just a signer on a DAO" is the sentence that starts a longer conversation, the same way it did for the people the CFTC eventually found.
Nobody built this DAO to launder anything. That's rarely the point where these situations start.
FAQ
What is a DAO, in plain terms?
A group that makes decisions through token-holder votes and code instead of a company structure. No board, often no legal entity at all.
Can a DAO actually be sued if it has no legal structure?
Yes. A U.S. court accepted the theory that an unincorporated group acting toward a common goal can be treated as a legal entity for the purpose of being sued, served, and held liable.
Does that mean every DAO member is personally liable?
Not automatically, and in the one case that's gone this far, the regulator chose not to pursue individual token holders. The legal theory that could reach them still exists and hasn't been fully tested.
Are DAOs virtual asset service providers under FATF?
Not by name, but FATF's activity-based approach means a DAO's key signers or operators can be classified that way if the DAO exchanges, transfers, or safeguards virtual assets.
Has FINTRAC ever regulated a DAO in Canada?
Not that's been made public. There's no FINTRAC guidance naming DAOs specifically, which isn't the same as DAOs being outside the existing rules for virtual currency activity.
What's a legal wrapper, and do we actually need one?
It's a real entity, like a Wyoming DAO LLC or DUNA, that gives a DAO something to register, sign contracts as, and be held liable through, instead of leaving that question to whichever court gets there first.
We're just token holders, not developers. Are we exposed?
Possibly, depending on what governance rights you hold and how actively you use them. The Ooki DAO theory reached token holders in principle, even if this particular case didn't pursue them individually.
Does incorporating remove all the risk?
No, but it replaces an open question with a defined one. A named entity with a defined structure is something a compliance program can actually be built around. An anonymous forum isn't.
Get In Touch
If your business touches a DAO's treasury, token, or governance process, or you're building one yourself, "we're decentralized" isn't a position that holds up against the questions a bank or a regulator will actually ask.
AML Effectiveness Review: an independent review of your program, including how you evaluate decentralized counterparties that don't come with a standard corporate structure.
CAMLO and MLRO Services: a qualified compliance officer who can actually make the call on who your counterparty is, and defend it later.
FINTRAC MSB Registration: for platforms and projects that need to register as a virtual currency dealer, or need help deciding whether they have to.
Book a discovery call and we'll walk through where your program actually stands.




