Project Pigeon Takes Flight: Inside the New APAC Rulebook for Public Blockchains

We have spent years watching financial institutions circle public blockchains with a mix of curiosity and caution, drawn to the efficiency of open networks but wary of the legal fog surrounding them. That fog got noticeably thinner on August 13, 2026, when a consortium led by Baker McKenzie, Elliptic, the Digital Asset Association, and the Responsible Fintech Institute launched Project Pigeon, a working group built to establish legal certainty, settlement finality protocols, and risk management guidelines for permissionless blockchain operations across the Asia Pacific financial sector.

A Name Chosen With Intent

There is something quietly poetic about the name itself. The initiative takes its name from carrier pigeons, reflecting the consortium’s goal of developing trusted governance frameworks that enable secure communication and value transfer across open, decentralized blockchain networks. We appreciate when an institutional project chooses a metaphor that actually earns its place, and this one does. Carrier pigeons once carried messages across distances with a kind of resilient, decentralized reliability that predates any modern network, and the image maps neatly onto what this consortium is trying to build, a trusted way to move value across open rails that nobody centrally controls.

What Project Pigeon Actually Is

The Project Pigeon consortium, jointly convened by Elliptic, the Digital Asset Association, the Responsible Fintech Institute and Baker McKenzie, announced the formation of Project Pigeon, a working group for permissionless blockchain governance in APAC. The regional initiative is dedicated to advancing safe, compliant innovation on public blockchain networks, providing financial institutions with the frameworks necessary to operate securely within rapidly evolving regulatory landscapes. For anyone who has tried to explain to a compliance officer why a public, permissionless network might still be safe enough for institutional settlement, that sentence captures the entire tension this project is trying to resolve.

The timing is not incidental. The launch of the working group follows the Monetary Authority of Singapore’s April 2026 Consultation Paper regarding the prudential treatment of crypto assets on permissionless blockchains. Regulators across the region have been signaling, cautiously, that they are open to permissionless infrastructure playing a role in mainstream finance, provided the industry can show it has thought through the risks with the same rigor applied to traditional settlement systems. Project Pigeon reads like the industry’s direct response to that signal, an attempt to hand regulators a ready made framework rather than wait for one to be imposed.

Four Workstreams, One Shared Goal

The consortium has organized its work around distinct risk categories, each led by a different partner organization drawing on its particular expertise. The Technology Risk workstream, led by the Digital Asset Association, focuses on mitigating threats such as majority attacks, protocol vulnerabilities, smart contract exploits, and broader infrastructure risks. A second workstream, led by Baker McKenzie, tackles what may be the thorniest question of all for lawyers and regulators alike. The Settlement Finality Risk workstream evaluates consensus mechanisms, reconciles probabilistic versus deterministic finality, and works to establish legal certainty around when a transaction on a public blockchain can actually be considered final.

That distinction between probabilistic and deterministic finality might sound like an academic footnote, but we think it sits at the emotional core of why institutions have hesitated to embrace permissionless networks in the first place. Traditional settlement systems give a bank or a clearinghouse a clean, legally defined moment when a transaction is done, final, irreversible. Public blockchains, by contrast, often settle probabilistically, meaning the confidence that a transaction will not be reversed grows over time rather than snapping into certainty at a single instant. For a compliance officer signing off on a multimillion dollar transfer, that difference is not academic at all. It is the difference between sleeping soundly and staring at a ledger at two in the morning wondering if a reorganization somewhere on the network just undid a settled trade.

Compliance Built Into the Bloodstream, Not Bolted On

Financial crime compliance sits at the center of the consortium’s mission as well. June Lau, APAC Head of Policy and Regulatory Affairs at Elliptic, framed the stakes plainly, noting that as adoption of permissionless chains accelerates, the industry’s approach to financial crime compliance must keep pace, and that embedding advanced onchain analytics and Travel Rule compliance directly into the operational lifecycle ensures transparency and security move forward together rather than one trailing behind the other.

We find that framing important because it pushes back against a tendency, common in both crypto skepticism and crypto enthusiasm, to treat compliance as something applied after the fact, a patch on top of a technology that was never designed with regulators in mind. Project Pigeon appears to be arguing for the opposite approach, building compliance logic into the operational lifecycle of permissionless activity from the very first design decision.

Governance With Regulators Watching Closely

Underscoring the systemic importance of this initiative, Project Pigeon has established observer and consulting roles for leading regulatory bodies. Baker McKenzie serves as the official secretariat to the consortium, providing comprehensive editorial oversight, supporting engagement with regulators, and managing the consortium’s governance processes. This structured approach includes twice weekly plenary sessions, focused meetings for the four workstream sub groups, quarterly regulatory checkpoints, and monthly reviews conducted by the central Steering Committee comprising the Digital Asset Association, the Responsible Fintech Institute, Elliptic, and Baker McKenzie.

Stephanie Magnus, Principal in Financial Services Regulatory and FinTech at Baker McKenzie Wong and Leow, described the initiative as a platform to examine these issues and contribute to the development of practical approaches for the industry, language that signals the consortium sees itself as a working laboratory rather than a body issuing final pronouncements from on high.

Where This Leads: The Pigeon Guide

The culmination of the consortium’s efforts will be an authoritative industry guide, titled Pigeon Permissionless Blockchains, which will set out a practical, comprehensive risk management lifecycle framework and executable guidelines for risk and compliance managers, referencing existing industry standards and regulatory guidance. This comprehensive publication will feature a detailed risk taxonomy, catalogues of risk events, preventive and detective controls, governance mechanisms, methodologies for controls testing, and protocols for issues management and reporting. Alongside the guide, the consortium will release a dedicated regulatory briefing paper tailored for supervisors across the APAC region.

We think that dual output, one document written for risk and compliance practitioners inside financial institutions and another written directly for the supervisors overseeing them, is a smart structural choice. It acknowledges that these two audiences read documents differently and need different things from them. A compliance manager needs an operational playbook. A regulator needs enough technical grounding to feel confident approving something they cannot fully control the way they control traditional infrastructure.

An Open Door for Participation

Interested financial institutions, technology providers and regulatory bodies are invited to participate in the working groups or contribute to the public consultation phase, with those wanting to express interest, contribute expertise or receive official updates encouraged to contact the Project Pigeon secretariat. That openness matters to us, because frameworks built behind closed doors by a handful of insiders tend to struggle for legitimacy once they meet the messy reality of live markets. A framework shaped through public consultation, with regulators sitting in observer seats from the start, has a far better chance of surviving contact with actual deployment.

Organizations like Elliptic have spent years building the analytics infrastructure that makes onchain monitoring possible at institutional scale, and pairing that technical capability with Baker McKenzie’s legal and regulatory reach gives Project Pigeon a credibility that few purely academic or purely industry led efforts manage to achieve. We will be watching closely as the working groups begin their sessions and the public consultation phase opens, because the outcome here could shape whether permissionless blockchains become a normal part of institutional finance across Asia Pacific or remain, for a while longer, a technology regulators admire from a cautious distance.

Related Posts

Leave a Reply

Your email address will not be published. Required fields are marked *

We use cookies to improve experience and analyze traffic. Privacy Policy