Sato Hub
← Back to blogA7 sanctions and the sub-agent payment ban: what a stablecoin-moving agent should read

A7 sanctions and the sub-agent payment ban: what a stablecoin-moving agent should read

FinCEN's proposed rule targets front companies called "sub-agents." They are not AI agents, but the compliance lesson lands squarely on anyone building agents that move money.

2026-10-04 · 4 min read

On October 1, 2026, the US Treasury sanctioned the A7 Network, a Russia-linked cross-border payments system, and FinCEN proposed a rule that would bar covered US financial institutions from sending or receiving funds, crypto included, involving A7's "sub-agents." FinCEN says those sub-agents processed more than $17 billion in dollar-denominated transactions from January 2025 through June 2026 (The Defiant).

First, a clarification the headline invites: a "sub-agent" here is a front company, not an AI agent. Nobody is proposing to ban autonomous software from paying for things. But if you are building agents that hold wallets and move stablecoins, this is the clearest recent example of where the compliance line sits, and it is worth ten minutes of your attention.

What was actually announced

Per the reporting, OFAC designated A7 as a significant transnational criminal organization, and FinCEN issued a finding plus a notice of proposed rulemaking. Treasury Secretary Scott Bessent said facilitators could "lose access to the U.S. financial system" (crypto.news).

The details, as described by TRM Labs and crypto.news:

  • ▸Sub-agents are entities outside the US that FinCEN says A7 controls and uses to make and receive payments for its clients. They are registered in places such as the UAE, Hong Kong, Kyrgyzstan, Turkey, Indonesia and the Seychelles.
  • ▸As of June 2026, FinCEN says A7 controlled hundreds of sub-agents with accounts at roughly 435 financial institutions in at least 83 countries.
  • ▸Treasury says A7 personnel controlled sub-agent websites and bank accounts and used custom VPNs to mask where staff were logging in from.
  • ▸The proposed rule (31 CFR 1010.668, per TRM) would cover every covered US financial institution. FinCEN would share the full sub-agent list only with those institutions, through a secure portal, because publishing it would let A7 spin up replacements faster.
  • ▸A 30-day comment period starts once the proposal is published in the Federal Register.

These are regulatory allegations and a proposal. The rule is not final, and the list of sub-agents is not public.

The stablecoin angle

The crypto part is A7A5, a ruble-backed token that crypto.news says is issued by Old Vector LLC, which was sanctioned in August 2025. FinCEN identified more than 180 entities that processed at least $179.1 billion in A7A5 transactions between February 2025 and June 2026 (TRM's summary of the finding).

TRM reports that FinCEN chose a prohibition on transmitting funds specifically because recordkeeping rules and correspondent-account restrictions would leave A7A5 flows untouched: those transactions move outside the correspondent banking system. In FinCEN's description, A7 used the token as a bridge toward USDT and then fiat. TRM adds its own on-chain figures, which are TRM's analysis and not FinCEN's, and it flags an unsanctioned Kyrgyz exchange it says shares infrastructure with a sanctioned one. Treat that as a vendor claim until a regulator says it.

Why a builder should care

The sass-free version: the rule's target is a network of companies, but the mechanism is counterparty exposure. The thing that gets an institution in trouble is who is on the other side of the transfer.

An onchain agent that pays, swaps or settles is a counterparty-picking machine. It will happily route to whatever address its prompt or its tools hand it. "The model decided" is not a compliance program. If your agent can move funds, you need to be able to answer:

  • ▸Who can it pay? An allowlist or a screening step before signing, not after.
  • ▸Where does the money touch fiat? Off-ramps and OTC desks are where regulated institutions apply these rules, and where your users' funds can get frozen.
  • ▸What does it log? When someone asks why a transfer happened, a transcript of the reasoning is not a record of the decision.

None of this is legal advice, and a proposed US rule does not tell you what applies to your product. Get actual counsel for that. It is a reminder that wallet controls and payment rails are part of the stack, not an afterthought bolted on after the demo.

What to watch

  • ▸The final rule. Whether the proposal survives the comment period unchanged, and how "covered institution" is applied to crypto-native firms.
  • ▸The undisclosed list. Institutions get it, builders do not. Expect screening vendors to productize the gap.
  • ▸Exchange designations. TRM argues one exchange sits on identical infrastructure to a sanctioned one. Whether regulators agree is a claim to track, not a fact to repeat.
  • ▸Agent-specific guidance. Nothing in this action targets autonomous software. If that changes, it will be a separate story with its own sources.

Building an agent that moves money? Map the wallet, payment rail and screening pieces before you write the prompt: satohub.ai/build.

Sources

Join the Sato Hub Briefing

One email a week — the agents, tools, and infrastructure that actually shipped, and why they matter.