Anonymity is not the same thing as confidentiality
Why two privacy designs get treated differently
What Anonymity is not the same thing as confidentiality actually says
Regulators keep drawing a line that the debate tends to flatten. What the instruments actually turn on is who holds the disclosure lever, not how strong the cryptography is. A protocol with mandatory, protocol-level anonymity leaves a regulated intermediary with no compliant posture at all, because it cannot produce records it has no mechanism to obtain. A design with encrypted state and a disclosure path leaves that intermediary roughly where it sits in conventional finance: data confidential from the public, available to the authorised party. Two caveats we would rather state ourselves. This is our reading of the drafting, not a position any regulator has published. And issuer-retained control is a real centralisation risk, not a free win. The EU's key phrase, increased obfuscation of transactions, is undefined, and AMLA guidance will decide how far it reaches.
The instruments that matter
- AMLR Article 79 turns on the account
- it prohibits obliged entities from keeping accounts allowing anonymisation of the holder, or anonymisation or increased obfuscation of transactions
- The lever, not the cryptography
- protocol-level mandatory anonymity leaves an intermediary with no compliant posture; optional shielding with disclosure keys leaves a workable one
- This cuts both ways
- issuer-retained disclosure control is itself a centralisation and abuse surface, and encrypted personal data is still personal data
What this means for confidential transactions
Bubble is built for exactly this shape of obligation: amounts and balances live on chain as ciphertexts, computation happens without decryption, and the only disclosure path is an on-chain access list through which an authorized party - an auditor, a supervisor, a counterparty - can request scoped decryption. That is confidentiality from the public, not from the regulator.
Related entries
- Central banks are building confidentiality themselvesGlobal · What the people writing the rules do when they design money
- Erasure against an append-only ledgerGlobal · The one collision with no clean answer yet
- Proving where funds did not come fromGlobal · Association sets, and the Tornado Cash aftermath
- Sanctions screening on a confidential ledgerGlobal · The genuinely open problem
- Selective disclosure as a compliance primitiveGlobal · Bilateral disclosure versus publishing to everyone
- The travel rule binds institutions, not ledgersGlobal · The rule everyone assumes ends on-chain confidentiality
Compliant by default.
See how selective disclosure satisfies a supervisor without publishing your book to the world.