In November 2025 a major US bank began settling a deposit token on a public Layer 2 network, according to reporting at the time. The technical achievement was modest by the standards of the institution. The operating implication was not. A regulated deposit liability now moves on infrastructure the bank does not control, does not pause and cannot roll back.
What a deposit token on a public network requires
Issuance and redemption logic with transfer restrictions, so that tokens move only between permitted parties, and so that the restriction survives contract upgrades. Reconciliation to the core banking ledger, continuous rather than end of day, because the token supply is publicly observable and any divergence from the deposit record is visible to third parties before it is visible internally. Governance of privileged roles, with the addresses holding administrative authority inventoried, held under bank key management standards and monitored for every action. Continuous monitoring of the contract and of counterparty addresses, including the bridges and Layer 2 components in the settlement path. Sanctions screening at the boundary, applied where the bank has control, with a documented approach to the addresses it cannot pre-approve.
Operations is the constraint, not technology
None of the above is a research problem. Deposit token contracts are simple relative to the rest of a bank's technology estate. The difficulty is that a public network runs continuously and produces obligations at hours when the issuing bank has historically been closed. A supervisor asking who was accountable at 03:00 on a Sunday expects a name, not a rota with best-effort coverage. Meeting that expectation means staffing, published clocks and evidence produced as the work happens.
How separation of duties satisfies supervisors
Banks are accustomed to independence between the function that builds a system and the function that assures it. The same expectation is arriving for on-chain services. Where a supervisor requires it, the engineering teams that build issuance and settlement components and the security operations teams that monitor them should operate under independent reporting lines, with separate access, separate change authority and audit-ready attestation of the separation, documented in the service agreement. That structure lets a bank use one partner for delivery speed without conceding the independence its examiners expect.
The strategic read is straightforward. Public networks have moved from pilot to production for institutions of the largest size. What follows is not more experimentation. It is the extension of ordinary banking operations discipline, with its clocks and its named owners, to infrastructure that never closes.