Financial regulation works by attaching obligations to a legal person. Autonomous contracts running on a public chain frustrate that approach at its foundation, and the responses have been uneven.
Enforcement needs someone to enforce against
Licensing, supervision and penalties all presuppose an entity that can hold a licence, receive an order and be sanctioned for ignoring it.
A deployed contract has none of these properties. It executes when called, and there is no account to freeze or office to inspect.
So the question becomes who else can be reached, and every answer involves someone further from the code than the code itself.
Developers, interfaces and governance are the available targets
Authorities have looked to the people who wrote and deployed the software, to the websites that make it usable, and to token holders who vote on its parameters.
Each target raises its own difficulty. Publishing code is ordinarily protected expression, an interface is only one of many possible front ends, and governance participants may be numerous and anonymous.
The effect has been to push interfaces toward geographic restrictions and address screening, since the interface is the most reachable point in the stack.
Decentralisation is a spectrum, not a status
Many protocols described as decentralised retain upgrade keys, treasury control or the ability to pause contracts, held by a small group.
Where such control exists, the holders look very much like operators, and claims of autonomy tend not to survive scrutiny.
Assessment therefore focuses on who can change what, rather than on how a project describes itself, and the presence of an emergency switch is often decisive.
Sanctions raised the sharpest version
Applying address-based restrictions to contract addresses meant restricting interaction with software rather than with a person.
That created questions about users whose funds were already inside, about developers, and about whether an unstoppable contract can be complied with at all.
Downstream services responded by screening addresses more aggressively, which pushed the compliance burden onto intermediaries who could actually implement it.
The likely settlement is at the edges
Where value enters and leaves through exchanges, custodians and payment providers, obligations can be applied conventionally because identifiable firms exist.
The protocol layer in between is harder to reach, and the practical approach has been to regulate the perimeter and accept that the middle is different.
How far that holds differs by jurisdiction, and the boundaries are still being drawn through cases rather than settled by rules.