
THE DIGITAL COMMONWEALTH (DCW)
DCW GLOBAL REGULATORY CHANGES
COMPLIANCE & RISK EDITION | SEPTEMBER 2026 | EDITION 5
Digital Assets • Crypto • Stablecoin • RWA • Tokenisation • Quantum Computing • AI • VASP • Financial Markets
This edition of the DCW Global Regulatory Changes, Compliance & Risk Edition updates material regulatory developments, enforcement activity, compliance notices and risk factor alerts from 1 July 2026 to 30 September 2026, across digital assets, cryptocurrency, stablecoins, real-world asset tokenisation, quantum computing, artificial intelligence, virtual asset service providers, and global financial markets. Each section includes a dedicated Risk Factors panel and a Compliance Notice to assist practitioners in assessing obligations and prioritising actions. Where a position reported in the June 2026 edition has since been superseded or corrected, the relevant section says so.
Headline developments this quarter: the FCA published its final cryptoasset policy statements on 30 June, issued final perimeter guidance (PS26/18) on 16 September and opened the authorisation gateway on 30 September; MiCA's transitional period closed on 1 July and Binance remains unauthorised in the EU; the Digital Omnibus on AI entered into force on 27 July; the Senate's CLARITY Act cloture vote failed on 15 September; US agencies missed the GENIUS Act's 18 July rulemaking deadline; Japan's Diet enacted the FIEA reclassification on 15 July; the SEC issued its innovation exemption for tokenised securities venues on 17 September; and the Bank of England and FCA finalised the UK systemic stablecoin approach.
Reporting period: 1 July 2026 – 30 September 2026 | Update frequency: Quarterly cycle
1. UNITED KINGDOM
1.1 FCA FSMA Cryptoasset Regime: Final Rules Published and Authorisation Gateway Open
The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 remain the statutory foundation for the UK's comprehensive cryptoasset regime, which commences on 25 October 2027. On 30 June 2026 the FCA published its five principal final policy statements: PS26/9 (admissions and disclosures and the market abuse regime for cryptoassets), PS26/10 (stablecoin issuance), PS26/11 (regulated cryptoasset activities), PS26/12 (a prudential regime for cryptoasset firms) and PS26/13 (application of the FCA Handbook, including Consumer Duty, SM&CR, operational resilience and financial crime requirements, to regulated cryptoasset activities). The June 2026 edition recorded these statements as outstanding at the reporting cut-off; they were in fact published on the final day of that period.
On 16 September 2026 the FCA published PS26/18, its final perimeter guidance, following 78 responses to CP26/13. The guidance confirms five regulated activities: issuing qualifying stablecoins, operating a cryptoasset trading platform, dealing in and arranging deals in cryptoassets, safeguarding cryptoassets, and arranging cryptoasset staking. Government amendments have introduced targeted exclusions that give greater certainty to technical service providers, and a proposed statutory instrument would exclude UK-issued qualifying stablecoins from certain arranging and dealing activities, directing them towards a modernised payments framework. Existing registrations under the Money Laundering Regulations do not convert automatically: registered firms must assess for themselves whether their activities fall within the new perimeter and apply accordingly. The FCA will consult in October 2026 on further PERG amendments (stablecoin exclusions, proprietary trading, technology providers and decentralised protocols), with final guidance targeted for early 2027.
The FCA opened the authorisations gateway on 30 September 2026. The application window runs to 28 February 2027. Firms that apply within the window may rely on savings and transitional provisions and continue business while their applications are determined; firms that apply later cannot, and may need to suspend activity until authorised. Pre-application support meetings and on-demand webinars have been available through FCA Connect since July 2026 for both UK and overseas firms. Further FCA work is expected later in 2026 on DeFi guidance, operational resilience for firms using distributed ledger technology, firm failure management and updates to the Financial Crime Guide.
⚠ RISK FACTORS |
The gateway is now open and the window to 28 February 2027 is a hard horizon: firms applying after that date lose the savings and transitional provisions and may be required to suspend regulated activity until authorised. |
The perimeter is still moving. The October 2026 PERG consultation and early 2027 final guidance on stablecoin exclusions, proprietary trading, technology providers and decentralised protocols mean firms relying on a provisional reading of scope risk later reclassification. |
Existing Money Laundering Regulations registrations do not carry across to the FSMA regime. Firms that assume continuity without a fresh perimeter analysis and application risk operating outside the regime from 25 October 2027. |
Authorisation is not guaranteed. Applicants must evidence compliance with PS26/9 to PS26/13 across governance, SM&CR, safeguarding, capital and stress testing, and market abuse controls; incomplete or poorly evidenced applications will extend timelines. |
Section 21 approver run-off: firms relying on third-party financial promotion approvers who do not seek direct authorisation must complete an orderly wind-down of UK cryptoasset business before the regime commences. |
✔ COMPLIANCE NOTICE |
Complete and submit authorisation applications within the 30 September 2026 to 28 February 2027 window, mapping each application element to PS26/9 to PS26/13 and PS26/18, and avoid leaving submission to the final weeks of the window. |
Use the FCA's pre-application support meetings and webinars through FCA Connect to test the application approach before submission. |
Respond to the October 2026 PERG consultation where relevant, and track forthcoming DeFi guidance, DLT operational resilience proposals and Financial Crime Guide updates. |
Complete a fresh perimeter analysis for every existing MLR-registered activity, and document the conclusion and the evidence relied upon. |
Where a firm will not seek authorisation, put in place a documented wind-down plan and client communications ahead of 25 October 2027. |
1.2 UK Stablecoin Regulation: Bank of England Finalises Systemic Stablecoin Policy
The dual-track FCA and Bank of England framework has moved from proposal to settled policy. On 22 June 2026 the Bank of England published its policy statement on sterling-denominated systemic stablecoins, followed on 30 June 2026 by a joint document with the FCA on the allocation of supervisory responsibilities. The Bank has reduced the proportion of backing assets required to be held as unremunerated central bank deposits from 40% to 30%, with the remaining 70% permitted in short-term UK government debt of up to six months' maturity. The proposed holding limits (GBP 20,000 per individual and GBP 10 million per business) have been dropped in favour of a temporary GBP 40 billion issuance guardrail per stablecoin. The Bank is responsible for prudential regulation, backing assets, capital, safeguarding and failure arrangements; the FCA for conduct, Consumer Duty, financial crime and complaints; with operational resilience, governance, redemption and reporting shared. The June 2026 edition recorded no material change to this framework; these publications immediately preceded that edition's cut-off and are recorded here.
The consultation on the Bank's Code of Practice closed on 22 September 2026 and the joint document consultation closed on 30 September 2026; the Bank expects to finalise the Code by the end of 2026. Alongside the FCA's PS26/10 on stablecoin issuance, the FSMA stablecoin regime remains on course to commence with the broader cryptoasset regime on 25 October 2027. FCA authorisation will remain mandatory for GBP rail integration by any stablecoin issuer irrespective of its status in other jurisdictions.
⚠ RISK FACTORS |
Issuers approaching systemic scale must model the 30% central bank deposit and 70% government debt backing structure and the GBP 40 billion issuance guardrail; the economics differ materially from the earlier proposals. |
Dual supervision by the Bank of England and the FCA creates coordination and interpretation risk, particularly on the shared areas of operational resilience, governance and redemption. |
Non-qualifying stablecoins risk listing restrictions on UK-regulated platforms once the regime commences; ongoing review of token eligibility is required. |
✔ COMPLIANCE NOTICE |
Stablecoin issuers should assess whether issuance constitutes activity 'from a UK establishment', test reserve-asset design against the Bank's final backing requirements, and map operational resilience and redemption arrangements to both regulators' expectations. |
Consider whether to respond to the Bank's Code of Practice and joint document consultations, now closed, through trade association channels, and prepare for the final Code expected by the end of 2026. |
UK platforms should continue reviewing listing policies for non-qualifying stablecoins ahead of regime commencement. |
1.3 OECD CARF: UK Implementation, Ongoing Obligations
UK CARF obligations, in force since 1 January 2026, remain a live operational requirement. We have not identified a material change in the reporting period. Crypto-asset service providers must continue collecting full transaction records and tax-residency self-certifications from UK customers ahead of the first data exchange with partner jurisdictions, scheduled for 2027. HMRC continues to build data-matching infrastructure ahead of that exchange.
⚠ RISK FACTORS |
CASPs not collecting CARF-compliant data from 1 January 2026 remain in breach; HMRC enforcement risk increases as the 2027 exchange date approaches. |
Accounts without valid tax-residency self-certifications must be frozen; failure to enforce this is both a regulatory and a potential criminal liability exposure. |
✔ COMPLIANCE NOTICE |
Verify that enhanced KYC workflows, including tax-residency self-certification capture, remain fully operational for all new and existing users. |
Map all reportable transaction categories against internal reporting infrastructure ahead of the first HMRC submission window in 2027. |
1.4 UK Sustainability Reporting: FCA Adopts Comply-or-Explain Approach (PS26/19)
The FCA's consultation on aligning listed issuers' sustainability disclosures with UK Sustainability Reporting Standards (UK SRS), based on IFRS S1 and S2, closed on 20 March 2026. The FCA has now published PS26/19, reported on 30 September 2026. Rather than imposing mandatory UK SRS reporting on all listed companies, the FCA has adopted a comply-or-explain approach against UK SRS S1 and S2, citing feedback that mandatory requirements would place a disproportionate burden on smaller companies. The requirements apply to accounting periods beginning on or after 1 January 2027, with initial reporting in 2028, and the FCA has retained relief periods for UK SRS S1 and for Scope 3 reporting. Firms should confirm the detailed rules against the policy statement itself.
⚠ RISK FACTORS |
Comply-or-explain does not remove the need for underlying data: issuers choosing to explain non-compliance will face investor and supervisory scrutiny of the quality of the explanation. |
Listed issuers with EU subsidiaries continue to face dual reporting under UK SRS and the revised ESRS (section 2.4); the two frameworks differ in timing, scope and content and must be mapped carefully. |
✔ COMPLIANCE NOTICE |
Confirm which accounting periods and entities fall within PS26/19, and brief the board and audit committee on the 1 January 2027 start date and 2028 first reporting. |
Continue mapping UK SRS S1 and S2 requirements against internal sustainability data, and reconcile UK SRS and ESRS requirements for UK groups with EU subsidiaries. |
2. EUROPEAN UNION
2.1 MiCA: Transitional Period Closed on 1 July 2026
The Markets in Crypto-Assets Regulation reached its defining milestone on 1 July 2026, when the final national transitional (grandfathering) arrangements under Article 143 expired across the EEA. ESMA confirmed that there would be no extension and issued a public statement calling on unauthorised crypto-asset service providers to wind down in an orderly manner while safeguarding clients' interests. Any entity offering crypto-asset services to EU clients without MiCA authorisation is now operating in breach of EU law. Industry reporting indicates that only around 210 of more than 3,000 firms previously operating in Europe secured full authorisation. Tether's USDT remains without MiCA authorisation and has been delisted from major regulated venues; Circle's USDC and EURC, alongside a small number of other authorised e-money tokens, remain the principal MiCA-compliant alternatives.
Binance withdrew its Greek application on 24 June 2026 and holds no MiCA authorisation in any member state. From 1 July 2026 it reportedly suspended new EU services, including new spot orders, deposits, sign-ups and earn and staking products, while leaving withdrawals open, and closed its French entity. It is reported to be pursuing authorisation in France. Later reporting suggests that ESMA has questioned whether the exchange's EU business is being wound down properly rather than relabelled, that the French ACPR has identified deficiencies in anti-money laundering safeguards, and that the exchange has continued to serve some EU customers through reverse solicitation and third-country routing, which MiCA does not permit as a general route to the EU market. These points are drawn from secondary reporting and should be verified against regulator statements before reliance.
Electronic money token custody and transfer services have faced a dual MiCA and PSD2 licensing requirement since March 2026, increasing compliance costs for stablecoin service providers. The EU Anti-Money Laundering Authority (AMLA) is operational and is expected to supervise the largest cross-border CASPs directly.
⚠ RISK FACTORS |
Any firm continuing to serve EU clients without MiCA authorisation is in direct breach of EU law, and national competent authorities, including those in France and the Netherlands, have signalled active enforcement. |
Reverse solicitation is a narrow exemption. Firms relying on it, or on routing EU customers through third-country entities, face supervisory challenge where the activity resembles active marketing or a relabelled continuation of an unauthorised EU business. |
Non-compliant stablecoins, including USDT, cannot lawfully be offered on EU-regulated venues; firms with exposure to non-compliant tokens must complete migration or wind-down without delay. |
Dual MiCA and PSD2 licensing for EMT custody and transfer services creates ongoing cost and complexity for stablecoin service providers. |
AMLA direct supervision: firms meeting the large cross-border CASP threshold must demonstrate AML/CFT governance to a standard commensurate with direct AMLA oversight, not merely national-authority expectations. |
✔ COMPLIANCE NOTICE |
Confirm MiCA authorisation status; any firm without a granted authorisation must have ceased providing crypto-asset services to EU clients or have an orderly wind-down plan in execution, with client asset return arrangements documented. |
Review any reliance on reverse solicitation, with evidence that each client relationship was initiated at the client's own exclusive initiative and without marketing in the EU. |
Review all listed stablecoin tokens against the ESMA MiCA register; remove or restrict non-compliant ARTs and EMTs. |
EMT issuers should confirm PSD2 overlap positioning and ensure any required separate payment services licence is in place. |
Document AML/CFT policies, governance structures and cross-border transaction monitoring to a standard appropriate for direct AMLA oversight, and keep marketing materials and white papers aligned with MiCA disclosure requirements. |
My Thoughts: The first quarter after the MiCA cut-off confirms that a hard-edged deadline reshapes a market quickly, and that the regulatory challenge then shifts from authorisation to perimeter integrity. With only around 210 of more than 3,000 firms securing authorisation, the consolidation has been severe. Reported reliance by a major unauthorised platform on reverse solicitation and third-country routing shows that supervisors must now police the boundary of the regime as actively as its entrance, and ESMA's reported question of whether an EU business has been wound down or merely relabelled is the right line of enquiry. For UK firms, the contrast with the FCA's approach is instructive. The gateway opened on 30 September 2026 with savings and transitional provisions for firms that apply by 28 February 2027, a managed on-ramp that MiCA did not offer, but the same perimeter questions will arise once the UK regime commences on 25 October 2027.
2.2 EU AI Act: Digital Omnibus in Force, High-Risk Deadlines Deferred
The most material EU AI development of the reporting period is the entry into force of the Digital Omnibus on AI. Following provisional political agreement on 7 May 2026, Parliament's endorsement on 16 June 2026 and Council adoption, the Omnibus was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744 and entered into force on 27 July 2026. The uncertainty recorded in the June 2026 edition, under which the original 2 August 2026 high-risk deadline remained the law until publication, has therefore been resolved.
The Omnibus defers high-risk obligations for standalone Annex III AI systems from 2 August 2026 to 2 December 2027, and for AI embedded in regulated Annex I products from 2 August 2027 to 2 August 2028. General-purpose AI model obligations remain on their original schedule. Article 50 transparency obligations, including disclosure of AI interaction, deepfake labelling and biometric system notifications, apply from 2 August 2026, save that the marking obligation for generative systems already on the market before that date is deferred to 2 December 2026. The Commission finalised its Code of Practice on marking and labelling AI-generated content on 20 July 2026; approximately 190 organisations had signed by 31 July 2026. The Code expects providers to mark outputs with at least two machine-readable techniques, to offer detection mechanisms, and to make watermark detection interoperable by 2 February 2027. Adherence is voluntary, but non-signatories must be able to justify alternative measures to authorities.
The Omnibus introduces a new Article 5 prohibition on AI systems that generate non-consensual intimate imagery or child sexual abuse material, including so-called nudifier tools, with effect from 2 December 2026. It also extends certain SME regulatory privileges to small mid-cap companies and strengthens the supervisory role of the European AI Office over general-purpose AI models and AI systems integrated into very large online platforms, with national authorities retaining competence for law enforcement, border management and financial institutions.
The deferral does not alter the AI Act's core architecture. Its risk-based classification, prohibited practices and general-purpose AI rules remain unchanged, and the European Commission has stressed that the deferral reflects standards and conformity-assessment infrastructure not being ready, not a reduction in regulatory ambition.
⚠ RISK FACTORS |
The deferral changes timing, not exposure. Financial AI systems used in credit scoring, fraud detection, risk assessment, AML surveillance and insurance pricing remain classified as high-risk under Annex III; non-compliance after 2 December 2027 carries fines of up to EUR 15 million or 3% of global annual turnover. |
Agentic AI systems deployed in financial services remain subject to heightened supervisory attention under Articles 9, 13 and 14 irrespective of the Omnibus deferral; auditability, human oversight and interruption capability expectations have not been relaxed. |
Article 50 applies from 2 August 2026. The marking carve-out to 2 December 2026 applies only to generative systems already on the market before that date; any new generative feature shipped into the EU after 2 August 2026 must meet labelling and disclosure obligations from day one. |
The new Article 5 prohibition applies where non-consensual intimate content generation is a reasonably foreseeable outcome absent adequate safeguards, not only to systems designed for that purpose; providers of general-purpose image and video generation tools face a design-stage obligation ahead of 2 December 2026. |
Firms that do not follow the Article 50 Code of Practice must be able to evidence alternative measures to supervisors, which increases documentation burden. |
✔ COMPLIANCE NOTICE |
Continue AI system inventory and Annex III classification work; the deferral provides additional time but does not reduce the underlying scope of the obligation, and internal compliance calendars should now be updated to the 2 December 2027 and 2 August 2028 dates. |
Implement Article 50 marking and labelling for any generative feature shipped into the EU market, assess whether to adhere to the Code of Practice, and plan for watermark detection interoperability by 2 February 2027. |
Assess Article 5 exposure for any image or video generation capability and document safe-harbour design measures ahead of 2 December 2026. |
Continue agentic AI governance work, including identity registers, decision logging, human oversight and interruption procedures, irrespective of the high-risk deadline deferral. |
Confirm which of the firm's systems fall within the 'already on the market' carve-out and record the evidence. |
2.3 EU DAC8: Ongoing Data Collection Obligations
DAC8 data collection obligations for EU member-state CASPs, in effect since 1 January 2026, remain a live operational requirement, and we have not identified a material change in the reporting period. The first reports remain due to member-state tax authorities between 1 January and 30 September 2027.
⚠ RISK FACTORS |
CASPs not collecting DAC8-compliant transaction data remain in breach; enforcement risk increases as the 2027 submission deadline approaches. |
DeFi platforms with identifiable operators may be classified as Reporting CASPs; DeFi branding does not confer exemption. |
✔ COMPLIANCE NOTICE |
Confirm DAC8 transaction data collection systems remain fully operational for all reportable EU-resident user transactions. |
Continue testing account-freeze protocols for users failing to provide valid self-certifications. |
2.4 EU Sustainability Reporting: Revised ESRS Adopted
The European Commission adopted the revised European Sustainability Reporting Standards (ESRS) by delegated act on 3 July 2026, giving effect to the Omnibus I simplification. The revision reduces mandatory data points by more than 60%, with the Commission estimating a saving of around 30% in reporting costs per company, introduces a fair presentation requirement, and restricts the reporting of non-material information other than where legally required. A value chain cap protects entities with 1,000 or fewer employees from information requests beyond voluntary reporting standards. The revised standards are reported to enter into force on 20 November 2026 following a two-month scrutiny period for the Council and Parliament, and to apply to financial years beginning on or after 1 January 2027. Reporting for earlier financial years continues under the existing ESRS Set 1.
⚠ RISK FACTORS |
Reporters must not apply the simplified standards to earlier financial years; full ESRS Set 1 compliance remains mandatory until the revised standards apply from 1 January 2027. |
UK groups with EU subsidiaries must manage dual sustainability reporting under UK SRS (section 1.4) and the revised ESRS, which differ in timing, content and the basis of materiality assessment. |
✔ COMPLIANCE NOTICE |
Plan the transition from ESRS Set 1 to the revised standards for financial years beginning on or after 1 January 2027, including the data-point reduction and the fair presentation requirement. |
Monitor completion of the scrutiny period and entry into force expected on 20 November 2026. |
3. UNITED STATES OF AMERICA
3.1 SEC-CFTC Coordination: CLARITY Act Fails Senate Cloture
The SEC and CFTC continue to implement their 11 March 2026 Memorandum of Understanding and Joint Harmonisation Initiative, and the 17 March 2026 joint interpretation establishing a crypto-asset taxonomy (digital commodities, digital collectables, digital tools, stablecoins and digital securities) continues to anchor industry compliance reviews. On 17 September 2026 the agencies took coordinated interim action, described in section 11.3, including the SEC's innovation exemption for tokenised securities venues and CFTC Staff Letter 26-25.
The Digital Asset Market Clarity Act (CLARITY Act) did not reach a floor vote before the Senate's August recess. The Senate then held a cloture vote on H.R. 3633 on 15 September 2026, which failed by 49 votes to 50, well short of the 60 required. The ethics provision addressing officials' crypto industry ties was reported to be the deciding issue rather than the SEC and CFTC jurisdictional settlement, and stablecoin yield treatment also remained unresolved. Seven Democratic senators, including Senators Gallego, Gillibrand and Warner, described the result as a setback rather than the end and recommitted to bipartisan negotiations. The Senate's next session runs from 5 October to 6 November 2026, directly into midterm campaigning; a post-election lame-duck session is regarded as the most realistic remaining window, and prediction markets were reported to price passage in 2026 in single digits.
⚠ RISK FACTORS |
Comprehensive federal market structure legislation will not arrive in the near term. Firms must continue reassessing the classification of all assets traded, custodied or issued against the 17 March 2026 taxonomy; this remains an active compliance exercise, not a one-off review. |
Interim agency relief is conditional and revocable. Exemptions and no-action positions can be narrowed or withdrawn, and do not bind a future Commission or provide the durability of statute. |
State-level enforcement (NYDFS, California DFPI and others) continues to assert jurisdiction independently of the federal coordination agenda; state compliance exposure is not reduced by SEC-CFTC harmonisation. |
Private class actions are expected to fill any gap left by a lighter federal enforcement posture; firm practices must withstand both regulatory and private litigation scrutiny. |
✔ COMPLIANCE NOTICE |
Continue legal review of all assets traded, custodied or issued against the SEC-CFTC taxonomy; update custody agreements, trading terms and marketing materials as the taxonomy is applied in practice. |
Plan on the basis that the CLARITY Act is unlikely to be enacted before 2027; monitor the Senate's session from 5 October and any lame-duck scheduling, and maintain contingency plans for both outcomes. |
Audit all digital asset product and service offerings for state securities and licensing law compliance, independently of federal developments. |
Maintain robust internal controls for financial reporting, insider trading prevention and offering compliance, which remain active SEC enforcement priorities. |
My Thoughts: The failure of the 15 September cloture vote moves the centre of gravity from Congress to the agencies. The same week produced the SEC's innovation exemption and the CFTC's no-action relief, which illustrates the near-term path: interim, revocable administrative relief in place of durable statute. That is workable for firms willing to operate within the conditions, but it carries reversal risk with any change in agency leadership or political direction, and it does not settle the boundary between the two agencies or the treatment of stablecoin yield. With the Senate returning on 5 October and the midterms close, firms should plan on the basis that comprehensive legislation is unlikely before 2027, and should treat exemptive relief as an opportunity to be used with the exit conditions in mind.
3.2 GENIUS Act: Statutory Rulemaking Deadline Missed
The GENIUS Act's one-year statutory deadline for final implementing regulations passed on 18 July 2026 with no final rules issued by the OCC, FDIC, NCUA, Federal Reserve or Treasury. The principal rule packages remained at proposal stage: the FDIC's AML compliance proposal was open for comment until 4 August 2026, and a joint customer identification proposal involving the Federal Reserve was open until 21 August 2026. Congress did not prescribe a penalty or alternative timetable for missing the deadline. The FinCEN and OFAC AML/CFT and sanctions proposal (comments closed 9 June 2026) and the Treasury state-similarity proposal (comments closed 2 June 2026) have not been finalised.
On 18 August 2026 Treasury published a further notice of proposed rulemaking implementing the Act's provisions on who may issue, offer or sell payment stablecoins in the United States. As reported, the proposal applies to any entity offering payment stablecoins to a person located in the United States regardless of where it is incorporated, and refers to criminal penalties of up to USD 1 million and five years' imprisonment per violation. Comments are due approximately 17 October 2026. The OCC has stated that it is aiming to finalise its rule in November 2026 so that it can begin processing applications in the new year.
My Thoughts: The missed 18 July deadline carries no statutory penalty and does not delay the Act's effective date. The effective date is the earlier of 18 January 2027 and 120 days after final regulations are issued; 120 days before 18 January 2027 fell on 20 September 2026, so, with no final rules by that date, 18 January 2027 is now in practice the operative date. An OCC final rule in November would therefore leave issuers with weeks rather than months between final text and effectiveness. Foreign issuers, including Tether, still require a Treasury reciprocity determination to continue serving US businesses, and we have not identified one as at 30 September 2026. The statute also contemplates a later restriction, from 18 July 2028, on US platforms offering non-reciprocal foreign stablecoins.
⚠ RISK FACTORS |
Final AML/CFT, sanctions and prudential rules are not yet in force; firms must build to the proposed standards now while final text remains subject to change, with an effective date that is, in practice, 18 January 2027. |
The staggered finalisation across the OCC, FDIC, NCUA, FinCEN and Treasury may produce a two-track outcome in which licensing proceeds before AML requirements are final, creating sequencing risk for applicants. |
The Treasury proposal's extraterritorial reach and criminal penalties materially raise the stakes for offshore issuers and intermediaries that offer stablecoins to US persons. |
Foreign issuers without a Treasury reciprocity determination, including Tether, face continued uncertainty over their ability to serve US businesses; counterparties should assess concentration risk accordingly. |
The state and federal 'substantially similar' determination remains undefined in final form; state-qualified issuers face a live design gap pending Treasury's final principles. |
✔ COMPLIANCE NOTICE |
Review and, where relevant, submit comments on the August 2026 Treasury proposal before the October deadline; continue AML/CFT programme build-out against the proposed FinCEN and OFAC standard. |
Engage early with the OCC on national trust bank or federal qualified issuer applications, given the OCC's November 2026 target and the volume of applications expected. |
Assess whether any offering could be characterised as made to a person located in the United States and, if so, how the extraterritorial proposal would apply. |
Firms with exposure to non-reciprocal foreign stablecoins should model contingency redemption and counterparty arrangements, and plan for 18 January 2027 as the effective date. |
3.3 US AI Regulation: Colorado Act Replaced and Delayed to 2027
The June 2026 edition recorded that Colorado's AI Act reached its effective date on 30 June 2026. That position has been overtaken. Colorado enacted SB 26-189, which replaces the original Act (SB 24-205) with narrower obligations and moves the effective date to 1 January 2027. The new law requires notice to consumers when automated decision-making technology materially influences consequential decisions in employment, housing, financial services, insurance, healthcare or education; a plain-language explanation of the system's role within 30 days of an adverse decision; three years' record retention; and a right to request human review. It removes mandatory risk management programmes, annual impact assessments, self-reporting to the Attorney General and the freestanding duty to prevent algorithmic discrimination. It is also reported to remove several exemptions that protected federally regulated entities, so financial services firms should not assume they are outside scope. Reporting indicates the law remains subject to a court-ordered enforcement stay pending xAI's constitutional challenge and to state rulemaking on terms such as 'materially influence'. California's AI Safety Act has remained in effect since 1 January 2026. The federal Executive Order on AI continues to direct agencies to challenge state AI laws deemed incompatible with national policy; we have not identified a court ruling on the preemption argument, leaving firms with multi-state exposure to navigate continuing legal uncertainty.
⚠ RISK FACTORS |
Multi-state exposure: financial firms must track live obligations in California and the Colorado requirements taking effect on 1 January 2027, alongside a growing number of other state AI statutes, with no resolved federal preemption position. |
The Colorado law's litigation and rulemaking status is unsettled; firms should not assume either that the 1 January 2027 date will hold or that it will be displaced. |
Algorithmic pricing and credit decisioning systems face increasing scrutiny under both state AI statutes and existing consumer protection and antitrust frameworks. |
✔ COMPLIANCE NOTICE |
Map all AI systems used in financial decision-making against California, Colorado (as amended) and other enacted state AI laws, and build the notice, adverse-decision explanation, human review and record retention processes that Colorado will require from 1 January 2027. |
Implement whistleblower protection and AI safety reporting protocols required under California's AI Safety Act. |
Continue monitoring Colorado rulemaking, the xAI litigation and federal preemption developments before assuming any reduction in state-level obligations. |
4. ASIA-PACIFIC
4.1 Hong Kong: Stablecoin Licensing and Regime Relaxations
The HKMA announced on 10 April 2026 that it had granted its first stablecoin issuer licences, to two entities (reported to be HSBC and Anchorpoint) from a field of 36 applicants. The June 2026 edition described the first cohort as including a wider group of applicants and dated it to March 2026; readers should rely on the HKMA's 10 April announcement and register. On 27 May 2026 the HKMA and SFC relaxed requirements for licensed stablecoin-related activity, including dispensing with virtual asset knowledge assessments for firms offering only Relevant Stablecoin services, removing the high-liquidity and exposure-limit requirements for Relevant Stablecoins, and permitting licensed corporations to custody and transfer clients' Relevant Stablecoins through segregated accounts with issuers. Hong Kong requires stablecoin reserves to be backed by High Quality Liquid Assets, with par redemption, client asset segregation and public reserve disclosure. The SFC continues to expand its Virtual Asset Trading Platform (VATP) regime, and legislation to bring virtual asset dealing and custody (and, in time, advisory and management) within licensing is progressing; commentary indicates that the dealing and custody regime may carry no transitional period. We have not identified a further stablecoin licensing round within the reporting period.
⚠ RISK FACTORS |
Hong Kong's regime remains among the strictest globally; with only two licences granted from 36 applications, firms with incomplete governance structures continue to face rejection at the licensing stage. |
Stablecoin issuers targeting Hong Kong without a completed HKMA application operate at a competitive disadvantage against the licensed cohort. |
The pending virtual asset dealing and custody legislation may commence without a transitional period, leaving unlicensed OTC dealers and custodians exposed on commencement. |
✔ COMPLIANCE NOTICE |
Firms seeking SFC VATP or HKMA stablecoin licences should engage early, given the demonstrated rigour of the first licensing cohort, and should review the May 2026 relaxations for service model implications. |
Monitor the Legislative Council progress of the virtual asset dealing and custody legislation and prepare for licensing without transitional relief. |
4.2 China: PBOC Ban Enforcement and e-CNY Expansion
The PBOC's February 2026 directive banning unapproved Yuan-pegged stablecoins, unregulated tokenised real-world assets, and crypto transactions through banks and payment institutions remains in force and actively enforced; we have not identified a material change in the reporting period. The e-CNY continues its strategic expansion, with the most recently reported figures showing cumulative transactions above 16 trillion yuan (approximately USD 2.3 trillion) and pilots covering 26 cities, positioning the e-CNY as the state's preferred alternative to private stablecoins. These e-CNY figures are carried forward from the previous edition and have not been refreshed.
⚠ RISK FACTORS |
Firms with any PRC nexus or Chinese-user-facing services must maintain ongoing compliance with the directive; enforcement remains active. |
Offshore RWA tokenisation platforms serving Chinese users continue to face extraterritorial application risk of Chinese law. |
✔ COMPLIANCE NOTICE |
Maintain ongoing review of all services for any China/PRC nexus; continue to restrict Yuan-pegged stablecoin, RWA token or crypto payment processing for Chinese users. |
Direct RWA and stablecoin innovation toward Hong Kong, Singapore, UAE or EU jurisdictions with established regulatory clarity. |
4.3 Japan: FIEA Reclassification Enacted by the Diet
Japan's National Diet enacted the amendment to the Financial Instruments and Exchange Act (FIEA) on 15 July 2026, when the House of Councillors approved the bill, following approval by the House of Representatives on 11 June 2026 and Cabinet approval in April. The law reclassifies approximately 105 cryptoassets, including Bitcoin, Ethereum and XRP, as financial instruments on a par with stocks and bonds, introduces insider trading restrictions, annual disclosure obligations for token issuers and market manipulation enforcement, and carries penalties of up to ten years' imprisonment and fines of up to JPY 10 million for operating without registration. Stablecoins and NFTs are excluded and continue to be regulated under the Payment Services Act. The FIEA framework takes effect in fiscal year 2027, allowing 12 to 18 months for secondary rulemaking. The flat 20% tax rate, replacing progressive rates of up to approximately 55%, is reported to apply from January 2028. The Japan Exchange Group is targeting spot crypto ETF listings from around 2027, subject to Investment Trust Act amendments, custody standards and individual fund reviews.
⚠ RISK FACTORS |
Reclassification under FIEA will impose financial product compliance obligations on crypto exchanges; significant systems and reporting uplift will be required ahead of the fiscal year 2027 effective date, and secondary rules are yet to be written. |
The gap between the FIEA effective date and the January 2028 tax change creates client communication and reporting risk during the transition. |
Bank entry into crypto custody and investment creates new counterparty risk dynamics; institutional frameworks must be updated to account for bank-custodied digital assets. |
✔ COMPLIANCE NOTICE |
Exchanges handling reclassified assets should begin compliance planning for financial product obligations and track the FSA's secondary rulemaking over the next 12 to 18 months. |
Prepare client reporting tools for the 20% flat tax regime from January 2028 and the transition from progressive treatment. |
4.4 Brazil: BCB VASP Application Deadline of 30 October 2026
Brazil's mandatory BCB VASP authorisation regime reaches its deadline on 30 October 2026, by which existing VASPs must file authorisation applications, including independent assurance reports. Industry commentary describes it as the hardest deadline in Brazil's history, estimates that most of the roughly 120 providers in the market remain unlicensed, and reports that further restrictions are under consideration, including a proposed 24-hour hold on transfers above approximately USD 10,000 to offshore or self-custodied destinations. We have not identified an extension. Capital requirements remain BRL 10.8 million to BRL 37.2 million, and stablecoin transactions or cross-border transfers exceeding approximately USD 100,000 require enhanced reporting.
⚠ RISK FACTORS |
VASPs that have not filed by 30 October 2026 will be non-compliant; the application, including independent assurance, is complex and commonly underestimated, so late-stage starters face material execution risk. |
Foreign exchange classification of stablecoins creates FX compliance obligations; dual licensing may be required. |
Proposed transfer holds on movements to offshore or self-custodied destinations would affect operational design for on and off-ramp providers. |
✔ COMPLIANCE NOTICE |
File BCB applications, with independent assurance reports, well ahead of 30 October 2026, and confirm minimum capital is met. |
Implement enhanced reporting for cross-border stablecoin transfers above USD 100,000 and track the proposed transfer hold. |
4.5 Singapore: MAS Consults on Legislating the Stablecoin Framework
On 1 September 2026 MAS opened a consultation on legislative amendments to implement its stablecoin regulatory framework under payments legislation; the consultation closes on 16 October 2026. The proposals set out three pathways: MAS-regulated stablecoins, including those jointly issued by a Singapore issuer and foreign issuers; designated systemic stablecoins; and MAS-recognised stablecoins, an avenue for stablecoins issued outside Singapore by foreign issuers. Stablecoins outside these frameworks remain digital payment tokens requiring Payment Services Act licensing, and the consultation addresses enhanced safeguards for retail customers using non-MAS-regulated stablecoins and the requirements for banks entering the stablecoin market. MAS also continues to engage institutions on its Tokenisation of Capital Markets Products Guide. The June 2026 edition referred to a SGD 10 million supply cap for non-bank issuers; we have not been able to verify that figure against the consultation and recommend confirming it with MAS before reliance.
⚠ RISK FACTORS |
The legislative proposals are not yet final; the treatment of foreign and jointly issued stablecoins, and the criteria for designation as systemic, may change after consultation. |
Issuers and distributors relying on a non-MAS-regulated stablecoin position face enhanced retail safeguard requirements and the risk of reclassification. |
FATF mutual evaluation outcomes may trigger enhanced monitoring or increased AML/CFT obligations for Singapore-based VASPs. |
✔ COMPLIANCE NOTICE |
Consider responding to the MAS consultation before 16 October 2026, particularly where the firm issues, distributes or banks stablecoins. |
Implement MAS tokenisation guidance for all capital markets product tokenisation activities. |
4.6 Dubai / UAE: VARA Compliance Obligations Ongoing
VARA-regulated VASPs continue implementing remediation measures arising from the November 2025 AML/CFT gap assessment circular. We have not identified a material new VARA rulebook or enforcement publication within the reporting period. The UAE's CBDC regime continues to advance as a core element of national digital finance infrastructure.
⚠ RISK FACTORS |
All VARA-regulated VASPs must have completed AML/CFT gap assessments and submitted compliance reports; non-submission constitutes a regulatory breach. |
Delay in remediating identified AML/CFT gaps risks licence suspension. |
✔ COMPLIANCE NOTICE |
Complete the AML/CFT gap assessment against VARA's Compliance and Risk Management Rulebook and submit the report without further delay. |
Confirm a dedicated AML Compliance Officer owns the remediation programme and that all remediation measures meet VARA timelines. |
5. GLOBAL BODIES & INTERNATIONAL STANDARDS
5.1 OECD CARF: Live Across 48+ Jurisdictions
CARF remains live across 48 jurisdictions from 1 January 2026, and we have not identified a material change in the reporting period. Reporting CASPs must continue collecting transaction data and tax-residency self-certifications. The first data exchanges between tax authorities (EU, Channel Islands, Brazil, Cayman Islands, South Africa) remain scheduled for 2027; second-wave jurisdictions, including Australia, Canada, Hong Kong, Kenya, Nigeria, Singapore, Switzerland, Thailand and the UAE, follow in 2028, with US participation from 2029. The jurisdiction count is carried forward from the previous edition and should be confirmed against the OECD's current list of commitments.
⚠ RISK FACTORS |
RCASPs in active CARF jurisdictions that have not begun data collection remain in breach. |
CARF's definition of 'Reporting CASP' is broader than the FATF VASP definition; NFT platforms and DeFi protocols with control may be in scope. |
✔ COMPLIANCE NOTICE |
Verify CARF compliance status in all operating jurisdictions across the active jurisdiction list. |
Continue self-certification collection and account-freeze protocols, and prepare reporting infrastructure ahead of the 2027 first exchange. |
5.2 G7 Cyber Expert Group and US Treasury: Financial Sector PQC
The G7 Cyber Expert Group's 13 January 2026 financial sector post-quantum cryptography (PQC) roadmap, co-chaired by the US Treasury and the Bank of England, remains the principal supervisory benchmark, targeting critical financial infrastructure systems for PQC migration completion by 2030 to 2032, with full transition by 2035. On 24 August 2026 the US Treasury launched a Quantum-Readiness Task Force, a public-private body to coordinate the financial sector's migration, with workstreams on sector alignment and PQC transition, third-party and vendor readiness, and digital assets and emerging technology risk. The vendor readiness workstream signals that the PQC posture of technology suppliers is becoming part of institutional compliance expectations. Cyber insurance underwriters continue to incorporate quantum readiness assessments into policy renewal questionnaires.
⚠ RISK FACTORS |
Financial institutions unable to demonstrate a credible PQC transition plan by 2027 face mounting supervisory scrutiny, now extending to the readiness of their technology vendors. |
'Harvest Now, Decrypt Later' attacks remain active; adversaries may already be collecting encrypted financial data for future decryption. |
✔ COMPLIANCE NOTICE |
Adopt the G7 PQC roadmap as the benchmark for internal migration planning, with board-level visibility of the 2030 to 2032 critical systems target, and add PQC readiness to third-party due diligence. |
Conduct a comprehensive cryptographic inventory identifying RSA/ECC dependencies and adopt NIST PQC standards (FIPS 203, 204, 205) as the migration baseline. |
5.3 Basel Committee: Crypto Capital Rules Review Continues
The Basel Committee on Banking Supervision met on 24 to 25 February 2026 and again on 19 to 20 May 2026, on both occasions confirming continued progress on its expedited targeted review of the prudential standard for banks' cryptoasset exposures, with a further update promised later this year. We have not identified publication of a revised standard in the reporting period. The original framework requiring full capital deductions for most crypto assets remains deferred following the US and UK's declination to adopt it on the original 1 January 2026 timetable.
⚠ RISK FACTORS |
Banks engaged in digital asset activities still cannot rely on a finalised Basel framework; capital planning uncertainty for treasury and risk functions remains material. |
A revised framework, when published, could impose significant capital charges with limited transitional notice; scenario planning for multiple outcomes must be maintained. |
✔ COMPLIANCE NOTICE |
Continue monitoring Basel Committee review progress and engage with BIS consultation processes as the targeted review advances. |
Maintain conservative internal capital buffers for crypto exposures pending the finalised framework, and engage the PRA, OCC/FRB or ECB for jurisdiction-specific interim guidance. |
5.4 FATF: Virtual Assets Targeted Update, Travel Rule and Stablecoins
On 16 July 2026 the FATF published its targeted update on implementation of the FATF Standards on virtual assets and VASPs. It found that nearly half of the jurisdictions with Travel Rule legislation have not yet taken Travel Rule-related supervisory or enforcement action; that significant gaps remain in operationalising regimes and translating risk assessments into enforcement; that jurisdictions using prohibition approaches have yet to take meaningful action against illegal VASPs; that more than one-third of jurisdictions now require licensing of offshore VASPs; that determining control or influence over DeFi arrangements remains difficult; and that illicit activity involving virtual assets has become more sophisticated, including through organised crime-linked operations. FATF figures cited in earlier editions indicated that 85 of 117 assessed jurisdictions had passed or were passing Travel Rule legislation.
The June 2026 edition recorded a dedicated FATF stablecoin analysis as unpublished. The FATF in fact published a targeted report on stablecoins and unhosted wallets in March 2026, addressing illicit finance risks and secondary-market monitoring. Firms should treat that report as the current FATF reference point for stablecoin AML/CFT expectations.
⚠ RISK FACTORS |
VASPs in FATF-compliant jurisdictions unable to transmit originator and beneficiary Travel Rule data continue to face direct regulatory sanctions, and supervisory action is expected to increase as jurisdictions close the enforcement gap the FATF has identified. |
Stablecoin secondary-market monitoring expectations from the FATF's March 2026 report will shape supervisory examinations; systems must be able to adapt rapidly. |
Offshore VASPs serving customers in jurisdictions that require offshore licensing face growing enforcement exposure. |
✔ COMPLIANCE NOTICE |
Implement IVMS 101-compliant Travel Rule data transmission for all qualifying transfers and maintain a documented unhosted wallet risk-assessment framework. |
Review stablecoin transaction monitoring against the FATF's March 2026 report on stablecoins and unhosted wallets, and confirm licensing status for any offshore activity in jurisdictions that require it. |
6. REAL-WORLD ASSET (RWA) TOKENISATION
6.1 Market Expansion and Institutional Adoption, Q3 2026
The tokenised real-world asset market continued to expand through the reporting period. One industry tracker put distributed value at approximately USD 38 billion on public blockchains by late August 2026, against USD 33 to 34 billion cited in the June 2026 edition for mid-May; measurement methodologies differ between trackers and the figures should be treated as indicative. Growth has extended beyond tokenised US Treasuries and money market funds into private credit, commodities, corporate bonds, equities and ETFs. The same report observed that roughly 56% of measured tokenised value recorded no weekly on-chain transfers, indicating that many assets remain passively held rather than deployed as collateral or settlement instruments.
Market infrastructure and regulatory engagement advanced. The DTCC was reported to have conducted live production trades in July 2026, settling tokenised representations of equities and Treasury instruments with around 40 participating institutions; this is drawn from secondary reporting and should be verified. On 17 September 2026 the SEC granted a five-year innovation exemption for tokenised securities venues (section 11.3), the most significant US regulatory step on tokenised securities trading to date. The ECB continued to advance Project Pontes (section 10.1).
The failure of the CLARITY Act cloture vote on 15 September 2026 (section 3.1) means that legislation confirming tokenisation as a delivery method rather than a new asset class, with tokenised securities and RWAs following the same registration, reporting and transfer rules as their traditional equivalents, remains unenacted. Interim agency relief now fills part of that gap.
⚠ RISK FACTORS |
Legal and regulatory uncertainty remains the primary institutional adoption barrier; firms must not deploy tokenised assets in jurisdictions without explicit legal clarity on settlement finality and insolvency treatment. |
The SEC innovation exemption is temporary, conditional and subject to volume caps; reliance on it carries revocation and scope risk, and does not extend to firms outside its conditions. |
Custody and transfer-agent reconciliation between on-chain tokens and off-chain legal records remains unresolved at the market-structure level; firms should not assume regulatory consensus exists on this point. |
China's prohibition on unapproved RWA tokenisation (section 4.2) continues to require firms with any Chinese nexus to exclude Chinese users and RMB-denominated assets from tokenisation activity. |
Concentration risk: a small number of issuers account for the substantial majority of distributed value, and low on-chain transfer activity suggests liquidity may be thinner than headline values imply; counterparty and liquidity risk should be assessed accordingly. |
✔ COMPLIANCE NOTICE |
Continue updating capital treatment models for tokenised instruments to reflect the technology-neutral standard confirmed by US banking regulators. |
Assess eligibility for, and the conditions attached to, the SEC innovation exemption before committing to tokenised trading models, including issuer notification and market data requirements. |
Conduct jurisdiction-by-jurisdiction legal analysis of DLT settlement finality and insolvency treatment before deploying tokenised assets at scale. |
Monitor CLARITY Act progress through the lame-duck period; passage would materially affect the legal certainty available to tokenised commodity and RWA assets in the US market. |
7. QUANTUM COMPUTING & POST-QUANTUM CRYPTOGRAPHY
7.1 G7 Roadmap, Regulatory Mandates and Accelerating Threat Timeline
The G7 Cyber Expert Group's January 2026 financial sector PQC roadmap remains the principal supervisory reference point, targeting critical financial systems for PQC migration by 2030 to 2032, with full transition by 2035. NIST's three principal PQC standards (FIPS 203: ML-KEM, FIPS 204: ML-DSA, FIPS 205: SLH-DSA) remain the baseline for migration planning, and the US NSA's CNSA 2.0 continues to mandate quantum-safe algorithms for national security systems, with a first compliance deadline of January 2027 for new systems. Reporting on the US Treasury's Quantum-Readiness Task Force (section 5.2) also cites federal migration deadlines of 31 December 2030 for key establishment and 31 December 2031 for digital signatures, and the move of remaining FIPS 140-2 validated certificates to historical status on 21 September 2026; these figures are drawn from secondary reporting and should be verified against NIST and Treasury publications.
The Basel Committee's ongoing engagement on cryptoasset and operational risk standards (section 5.3) continues to intersect with quantum-readiness expectations, and cyber insurance underwriters continue incorporating quantum readiness into renewal questionnaires, with explicit exclusions emerging for firms without documented transition plans.
⚠ RISK FACTORS |
'Harvest Now, Decrypt Later' attacks remain active; adversaries are collecting encrypted financial data now for future quantum decryption, with long-term confidentiality records at particular risk. |
Vendor opacity: an institution can complete its own migration and remain exposed if third-party providers have not; the Treasury task force's vendor workstream makes supplier readiness a compliance expectation. |
Blockchain private key vulnerability: assets secured by ECC remain theoretically vulnerable to a sufficiently powerful quantum computer; migration on major blockchains will require coordinated protocol-level changes over a multi-year horizon. |
Cyber insurance exclusions for quantum-related exposure are becoming more common for firms without documented PQC plans, creating an immediate financial risk independent of regulatory mandates. |
✔ COMPLIANCE NOTICE |
Conduct a comprehensive cryptographic inventory across IT systems, financial messaging and digital asset infrastructure, identifying all RSA/ECC dependencies, including those embedded in vendor products. |
Add PQC migration status and crypto-agility commitments to vendor due diligence and contracts. |
Adopt NIST PQC standards as the migration baseline and implement crypto-agility in all new systems for rapid algorithm replacement. |
Review cyber insurance policies at next renewal to ensure PQC transition plan documentation is included in renewal submissions. |
8. ARTIFICIAL INTELLIGENCE: GOVERNANCE & REGULATION
8.1 EU AI Act: Omnibus in Force and the Post-August 2026 Position
As detailed in section 2.2, the Digital Omnibus on AI entered into force on 27 July 2026 (Regulation (EU) 2026/1744), deferring standalone high-risk obligations to 2 December 2027 and embedded high-risk obligations to 2 August 2028, while leaving general-purpose AI obligations and Article 50 transparency obligations on their schedule from 2 August 2026, subject to the 2 December 2026 marking carve-out for generative systems already on the market. Financial institutions should treat the deferral as a reprieve on documentation and conformity-assessment timing, not a reduction in the underlying classification or governance obligations for high-risk financial AI systems such as credit scoring, fraud detection, AML surveillance and insurance pricing.
Agentic AI governance remains an active supervisory focus independent of the Omnibus deferral. Under Articles 9, 13 and 14, agentic AI systems used in high-risk financial contexts must maintain an identity registry for every agent, log every decision with full reconstruction capability, implement policy-based access controls, support immediate interruption, and provide interpretable outputs.
⚠ RISK FACTORS |
The deferral changes timing, not exposure: high-risk financial AI systems remain subject to fines of up to EUR 15 million or 3% of global annual turnover once the 2 December 2027 deadline arrives. |
Article 50 obligations are already live from 2 August 2026; firms that treated the Omnibus as a wholesale delay of the AI Act may be in breach of transparency and labelling requirements. |
Agentic AI audit trail requirements for multi-agent financial workflows remain unaffected by the Omnibus and continue to demand a logged reconstruction capability for every reasoning step and tool call. |
✔ COMPLIANCE NOTICE |
Continue building the AI system register and risk classification exercise against Annex III categories, with particular attention to agentic systems, and update internal calendars to the new deadlines. |
Implement agent identity registers, decision logs, policy-based access controls and documented interruption procedures, independent of the deferred high-risk compliance date. |
Confirm Article 50 transparency and marking implementation status, distinguishing pre-existing systems (2 December 2026 marking grace period) from new systems (2 August 2026 obligation). |
8.2 UK AI Regulation: Data (Use and Access) Act and the ICO Code of Practice
The Data (Use and Access) Act received Royal Assent on 19 June 2025 and is cited in the June 2026 edition as the 2026 Act; that reference is corrected here. Its Section 80 reforms replace the old UK GDPR Article 22 near-prohibition on solely automated decision-making with a new framework (Articles 22A to 22D) permitting such decisions subject to safeguards, meaningful information about the underlying logic, the right to human review and the right to contest.
The Data Protection Act 2018 Code of Practice on Artificial Intelligence and Automated Decision-Making Regulations 2026 (SI 2026/425) came into force on 12 May 2026 and places the Information Commissioner under a duty to prepare a statutory Code of Practice on AI and automated decision-making; it binds the Commissioner and does not itself impose obligations on controllers, whose duties derive from the UK GDPR and the Data Protection Act 2018. The Code is to address automated decision-making, foundation model development and, through a separate regime, police live facial recognition. The ICO's consultation on updated automated decision-making and profiling guidance closed on 29 May 2026; final guidance is now expected in winter 2026, and the statutory Code, which must follow that guidance and complete parliamentary procedure, is realistically a 2027 publication. The ICO has confirmed that its 2026/27 AI work programme includes the Code, dedicated agentic AI guidance and further consumer-facing support.
The UK continues to rely on sectoral, principles-based AI governance rather than a horizontal AI statute: the FCA applies Consumer Duty, SYSC 8 outsourcing rules and SS1/23 model risk principles to AI in financial services, while the ICO, MHRA, Ofcom and other sector regulators apply AI-specific expectations within their own remits.
⚠ RISK FACTORS |
Firms relying on automated decision-making in financial services must review their frameworks against the Articles 22A to 22D regime now in force, particularly around documented human review and contestability. |
The ICO's final ADM guidance has slipped from the summer to winter 2026 and the statutory AI Code remains a 2027 prospect; firms cannot yet rely on final guidance and should treat the draft ADM consultation outcomes as the clearest available signal of regulatory direction. |
UK firms with EU market exposure remain in scope of the EU AI Act irrespective of UK domestic regulatory architecture; the test is EU market impact, not corporate domicile. |
✔ COMPLIANCE NOTICE |
Review automated decision-making systems against the Articles 22A to 22D framework, updating disclosure notices, human review routes and contestation processes where required. |
Monitor publication of the ICO's final ADM guidance (expected winter 2026) and the statutory AI Code of Practice (expected 2027), and engage early with the ICO's forthcoming agentic AI guidance. |
Map AI systems against the FCA, MHRA, Ofcom and other applicable sector-regulator AI expectations in addition to data protection obligations. |
8.3 AI in Financial Services: Specific Risk Factors
The convergence of EU AI Act obligations (now with settled Omnibus timing), UK data protection reform, sector-specific guidance, state-level US AI laws (section 3.3) and reputational risk from AI failures continues to create a complex, multi-layered compliance environment for financial institutions. Supervisors continue to raise expectations regarding model risk governance, explainability and auditability as supervisory requirements rather than aspirations.
⚠ RISK FACTORS |
Model risk: AI models in credit, insurance and investment decisions must be explainable and auditable; supervisory expectations continue to harden through 2026. |
Third-party AI risk: financial institutions using third-party AI providers inherit compliance obligations; vendor AI governance must be assessed and contractually captured. |
Bias and discrimination: algorithmic bias testing remains mandatory under several frameworks; consumer protection and equality law exposure applies to AI systems in credit, insurance and employment decisions. |
✔ COMPLIANCE NOTICE |
Implement model risk governance frameworks for all AI models used in credit, insurance, investment and compliance functions. |
Conduct AI governance due diligence on all AI vendors, including AI-specific contractual representations on compliance, explainability and data security. |
Implement regular algorithmic bias audits for all consumer-facing AI decision systems. |
9. VASP, AML/CFT & FINANCIAL CRIME COMPLIANCE
9.1 Travel Rule: Implementation and Enforcement
FATF's updated Recommendation 16 remains in effect globally. The FATF's 16 July 2026 targeted update (section 5.4) found that nearly half of jurisdictions with Travel Rule legislation have not yet taken Travel Rule-related supervisory or enforcement action, which points to a likely increase in enforcement as supervisors close that gap. Implementation challenges persist: fragmented national adoption, limited VASP-to-VASP technical interoperability, unhosted wallet identification requirements and continuing DeFi scope ambiguity.
⚠ RISK FACTORS |
VASPs in FATF-compliant jurisdictions unable to transmit originator and beneficiary Travel Rule data continue to face direct regulatory sanctions; the current enforcement gap is unlikely to persist. |
DeFi and cross-chain bridges remain increasingly used for illicit finance; firms providing on/off-ramp services for DeFi protocols must implement enhanced monitoring. |
✔ COMPLIANCE NOTICE |
Implement IVMS 101-compliant Travel Rule data transmission for all qualifying transfers. |
Ensure real-time blockchain analytics are integrated into transaction monitoring, particularly for cross-chain bridge and DEX activity. |
9.2 Global Compliance Convergence: Crypto Approaching Banking Standards
The convergence of crypto compliance expectations with banking standards continues. OECD CARF, EU DAC8, AMLA direct supervision under MiCA and intensifying enforcement continue to drive higher compliance costs across the sector. During this reporting period the MiCA cut-off and its aftermath (section 2.1), the FCA's final rules and open gateway (section 1.1), the missed GENIUS Act deadline and Treasury's extraterritorial proposal (section 3.2), and the FATF's July 2026 update (section 5.4) each reinforced the trend.
⚠ RISK FACTORS |
Firms investing insufficiently in compliance infrastructure face existential regulatory risk; the era of light-touch crypto regulation is definitively over across the UK, EU, US and major Asian markets. |
Regulatory arbitrage is closing rapidly as CARF, FATF, AMLA and extraterritorial approaches such as the Treasury GENIUS proposal create an increasingly coordinated global framework. |
✔ COMPLIANCE NOTICE |
Conduct a compliance function capability assessment, ensuring staffing, systems and processes are scaled to meet 2026 and 2027 regulatory obligations. |
Treat compliance risk as a standing board and senior management agenda item; regulators expect demonstrable tone-from-the-top on compliance culture. |
9.3 Switzerland: New Digital Asset Licence Types
Switzerland's proposed amendments to the Financial Institutions Act, introducing a Payment Instrument Institution licence for stablecoin issuers and a Crypto Institution licence for crypto service providers, completed public consultation on 6 February 2026. We have not identified a Federal Council dispatch to Parliament or final legislation within the reporting period, and the new licence types therefore remain proposals.
⚠ RISK FACTORS |
Firms operating under the existing Swiss fintech licence must assess whether transition to the new licence types will be required once final legislation is adopted. |
Switzerland's CARF implementation (2028 exchange tranche) requires CASPs to be collecting required transaction data and self-certifications from 2026. |
✔ COMPLIANCE NOTICE |
Monitor for the Federal Council dispatch and final Swiss Financial Institutions Act amendment, and assess re-licensing requirements once published. |
Continue CARF transaction data collection for Swiss operations and engage with FINMA on transitional arrangements for existing fintech licence holders. |
10. CENTRAL BANK DIGITAL CURRENCIES (CBDC)
10.1 Global CBDC Tracker: Key Developments July to September 2026
EU: the European Parliament's Economic and Monetary Affairs Committee approved the digital euro Regulation on 23 June 2026, and on 9 July 2026 the plenary approved a negotiating mandate by 416 votes to 169, with 22 abstentions. Trilogue negotiations with the Council were expected to begin by the end of July, with an institutional aim of completing the legislative process by the end of 2026. The ECB continues to plan a 12-month pilot starting in the second half of 2027 and aims to be ready for a potential first issuance during 2029, contingent on adoption of the Regulation. Separately, the ECB's wholesale settlement initiative, Project Pontes, is expected to go live in the second half of 2026, allowing commercial banks to settle tokenised assets directly in central bank money.
China: the e-CNY continues its expansion, with the most recently reported figures (carried forward from the previous edition) showing cumulative transactions above 16 trillion yuan and pilots covering 26 cities, reinforcing the PBOC's positioning of the e-CNY as the sanctioned alternative to private stablecoins following the February 2026 ban (section 4.2).
UK: digital pound design work continues at the Bank of England and we have not identified a decision to build; the Bank's approach to systemic stablecoins (section 1.2) is the more active policy track. US: the Federal Reserve remains statutorily barred from issuing a retail CBDC under the GENIUS Act.
⚠ RISK FACTORS |
US/EU CBDC divergence continues: the US prohibition on retail CBDC alongside EU and Chinese acceleration creates ongoing dollar, euro and renminbi digital payment competitiveness dynamics relevant to global stablecoin market structure. |
Programmable money risk: wholesale CBDC initiatives such as Project Pontes introduce counterparty compliance obligations that institutions must understand before integrating settlement infrastructure. |
Interoperability risk: the proliferation of non-interoperable CBDCs continues to create a fragmented cross-border payment infrastructure for firms operating across multiple jurisdictions. |
✔ COMPLIANCE NOTICE |
Monitor the digital euro trilogue negotiations and assess implications of Project Pontes for securities settlement and interbank payment operations. |
Wholesale CBDC participants should ensure programmable payment conditions and smart contract obligations are reviewed for compliance with existing regulatory frameworks. |
Continue monitoring Bank of England digital pound progress and US federal CBDC policy developments. |
11. FINANCIAL MARKETS & REPORTING REQUIREMENTS
11.1 AIFMD II: Transposition Deadline Passed
EU member states were required to transpose AIFMD II by 16 April 2026, a deadline that has passed. We have not verified member-state by member-state transposition status as at 30 September 2026, and firms should check the specific position in each member state where they manage or market funds, given continuing variation in national implementation. Key changes remain: expanded pre-investment and periodic disclosures (Article 23); expanded Annex IV reporting (Article 24), including delegation arrangements; a new loan origination regime; enhanced liquidity management; and more permissive depositary arrangements.
⚠ RISK FACTORS |
Fund managers operating in member states with incomplete transposition risk regulatory uncertainty and potential supervisory action. |
Loan origination funds must have completed compliance review against the new origination, risk retention, diversification and leverage limit requirements. |
✔ COMPLIANCE NOTICE |
Confirm AIFMD II transposition status in all EU member states where funds are managed or marketed. |
Ensure Annex IV reporting systems reflect expanded delegation arrangement disclosure requirements. |
11.2 ESMA Active Account Requirement and OTC Derivative Reporting
EMIR 3's Active Account Requirement (AAR) provisions required transposition by member states by 25 June 2026, a deadline that has passed. ESMA's reporting templates and instructions were published in April 2026, and first AAR reports were due by 31 July 2026, including backlog data demonstrating compliance from the original 25 June 2025 start date alongside 2026 data. Firms that missed the first submission should confirm their position with their national competent authority. ESMA's reporting obligations continue to evolve across MiFID II, EMIR and MiCA transaction reporting frameworks.
⚠ RISK FACTORS |
Firms that did not complete the first AAR submission by 31 July 2026, or submitted incomplete backlog data, face supervisory follow-up and remediation costs. |
Dual reporting burden: EU firms subject to both EMIR and MiCA transaction reporting face overlapping data requirements requiring system integration and reconciliation. |
✔ COMPLIANCE NOTICE |
Confirm that the first AAR submission, including backlog data from 25 June 2025, was completed accurately, and put in place the process for ongoing reporting. |
Conduct a comprehensive data lineage and reporting obligations mapping exercise covering MiFID II, EMIR, MiCA and DAC8 obligations. |
11.3 US SEC/CFTC: Innovation Exemption and Coordinated Interim Relief
The SEC-CFTC Joint Harmonization Initiative, launched under the 11 March 2026 MOU, produced its most significant practical output of the quarter on 17 September 2026. The SEC issued an innovation exemption (Release No. 34-106402) granting five-year temporary exemptive relief, to 17 September 2031, for Tokenized Securities Venues and liquidity providers trading tokenised National Market System stocks through automated market makers on blockchain networks. Qualifying venues are exempted from exchange registration and covered liquidity providers from dealer status, subject to conditions: volume and symbol caps (Tier 1 stocks, being S&P 500 and Russell 1000 constituents, limited to 75 symbols and 0.25% of monthly average daily volume per stock; Tier 2 stocks to 250 symbols and 2.5%); publication of transaction data within ten minutes; halting trading when primary exchanges halt; auditable smart contracts; and disclosure filings with the SEC. Third-party tokenisers must give issuers 30 days' notice before trading begins, with objection rights, and tokenised shares must carry identical economic and voting rights to the underlying stock. On the same day the CFTC issued Staff Letter 26-25, a no-action position for qualifying passive software providers in respect of introducing broker registration, and submitted a prerule filing titled 'Regulation Crypto Asset Transactions and Regulation Crypto Asset Markets'. These actions were taken two days after the failure of the CLARITY Act cloture vote (section 3.1) and are described as interim measures pending legislation.
⚠ RISK FACTORS |
The exemption and no-action relief are temporary and conditional. They do not create binding obligations on the agencies for the future and can be narrowed, so firms should not assume relief beyond the stated terms. |
Operating outside the volume caps, data publication and halt-alignment conditions forfeits the exemption; operational controls must be capable of demonstrating continuous compliance. |
Reduced SEC headcount continues to create delays in regulatory guidance issuance; firms cannot rely on prompt informal guidance on how conditions will be applied. |
✔ COMPLIANCE NOTICE |
Assess whether any tokenised securities trading, liquidity provision or software activity falls within the 17 September 2026 relief, and document the conditions relied upon. |
Maintain robust internal controls for financial reporting, insider trading prevention and offering compliance, which remain active enforcement priorities for both agencies. |
Monitor the SEC's and CFTC's follow-on rulemaking, including the CFTC's prerule filing, for opportunities to streamline dual SEC/CFTC compliance architecture. |
12. CYBERSECURITY & OPERATIONAL RESILIENCE
12.1 UK Cyber Bill, DORA and Evolving Threat Landscape
The UK Cyber Security and Resilience Bill continues through Parliament. It entered the House of Lords on 25 June 2026, completed Second Reading on 14 July 2026 and reached Committee Stage on 1 September 2026, with Royal Assent expected in late 2026 and substantive implementation anticipated around 2028 through secondary legislation. As reported, the Bill extends regulation to relevant managed service providers and data centre operators, brings designated critical suppliers within scope, requires an initial notification within 24 hours of becoming aware of a significant incident and a fuller report within 72 hours, and carries fines of up to GBP 17 million or 4% of global annual turnover. DORA (EU) has applied to financial entities and their critical ICT third-party providers since January 2025; compliance and testing obligations remain ongoing. The January 2026 Memorandum of Understanding between the European Supervisory Authorities and the Bank of England, PRA and FCA on cross-border cooperation on the oversight of critical ICT third-party providers under DORA remains the reference point for cross-border oversight.
⚠ RISK FACTORS |
Ransomware and nation-state attacks on financial infrastructure continue to escalate; operational resilience plans must be tested regularly against severe and disruptive scenarios. |
Third-party cyber risk: supply chain attacks and technology provider compromises remain a growing systemic risk; the Bill's extension to managed service providers and data centres, and the ESA and UK cooperation arrangement under DORA, reinforce third-party due diligence as a regulatory expectation. |
The Bill's 24-hour initial incident notification would materially tighten current timelines; incident response processes should be assessed against it now, even though commencement is expected around 2028. |
DORA (EU): ICT risk management frameworks, third-party registers and incident reporting workflows must remain fully operational for EU financial entities. |
✔ COMPLIANCE NOTICE |
Maintain an ICT third-party risk register and conduct regular penetration testing and security assessments of critical providers, including managed service and data centre suppliers. |
Test incident response against 24-hour and 72-hour reporting timelines and track the Bill's Lords amendments. |
EU and UK firms with cross-border ICT third-party arrangements should review the implications of the ESA, Bank of England, PRA and FCA DORA cooperation MoU for their oversight obligations. |
Integrate post-quantum cryptography migration planning into the broader cybersecurity roadmap rather than treating it as a separate workstream. |
13. KEY REGULATORY DATES & FORWARD-LOOKING INTELLIGENCE
13.1 Critical Compliance Calendar: October 2026 and Beyond, with Quarter Milestones
DATE | JURISDICTION | REQUIREMENT / DEADLINE | RISK LEVEL |
30 Jun 2026 | UK | FCA publishes five final cryptoasset policy statements (PS26/9 to PS26/13) | HIGH |
1 Jul 2026 | EU | MiCA: all national transitional periods expired; no extension | CRITICAL |
1 Jul 2026 | California, US | California DFAL operative; completed applications required for safe harbour | HIGH |
15 Jul 2026 | Japan | Diet enacts FIEA amendment reclassifying 105 cryptoassets as financial instruments | HIGH |
18 Jul 2026 | US | GENIUS Act statutory rulemaking deadline passed without final rules | CRITICAL |
27 Jul 2026 | EU | Digital Omnibus on AI (Regulation (EU) 2026/1744) enters into force | CRITICAL |
2 Aug 2026 | EU | EU AI Act Article 50 transparency obligations apply (marking deferred for existing systems) | HIGH |
15 Sep 2026 | US | CLARITY Act cloture vote fails 49 to 50 in the Senate | HIGH |
16 Sep 2026 | UK | FCA publishes final perimeter guidance (PS26/18) | HIGH |
17 Sep 2026 | US | SEC innovation exemption for tokenised securities venues takes effect (to 17 Sep 2031) | HIGH |
30 Sep 2026 | UK | FCA FSMA cryptoasset authorisation gateway opens (window to 28 Feb 2027); PS26/19 comply-or-explain on UK SRS reported | CRITICAL |
5 Oct 2026 | US | Senate returns (session to 6 Nov); CLARITY Act path to lame-duck session | MEDIUM |
Oct 2026 | UK | FCA consultation on further PERG amendments (stablecoins, proprietary trading, technology providers, DeFi) | HIGH |
16 Oct 2026 | Singapore | MAS stablecoin legislative consultation closes | MEDIUM |
~17 Oct 2026 | US | Treasury GENIUS Act NPRM (who may issue, offer or sell payment stablecoins): comment deadline | HIGH |
30 Oct 2026 | Brazil | BCB VASP deadline: authorisation applications and assurance reports to be filed | HIGH |
Nov 2026 | US | OCC target for final GENIUS Act rule | HIGH |
20 Nov 2026 | EU | Revised ESRS expected to enter into force (apply from financial years starting 1 Jan 2027) | MEDIUM |
2 Dec 2026 | EU | AI Act Article 5 prohibition on non-consensual intimate imagery tools; Article 50 marking grace ends for existing systems | HIGH |
End 2026 | EU / UK | Digital euro trilogue target; Bank of England final systemic stablecoin Code expected | MEDIUM |
1 Jan 2027 | Colorado, US | Colorado SB 26-189 effective date (subject to litigation and rulemaking) | MEDIUM |
1 Jan 2027 | UK | UK SRS comply-or-explain applies to accounting periods beginning on or after this date (PS26/19) | MEDIUM |
18 Jan 2027 | US | GENIUS Act statutory effective date (or 120 days after final rules, if earlier) | CRITICAL |
2 Feb 2027 | EU | AI Act Article 50 watermark detection interoperability target under the Code of Practice | MEDIUM |
28 Feb 2027 | UK | FCA FSMA cryptoasset authorisation application window closes | CRITICAL |
~2027 | Global | CARF first cross-border tax authority data exchanges | HIGH |
FY2027 | Japan | FIEA crypto framework takes effect (12 to 18 months of secondary rulemaking) | HIGH |
25 Oct 2027 | UK | FCA FSMA cryptoasset regime commences: all firms must be authorised | CRITICAL |
2 Dec 2027 | EU | EU AI Act high-risk obligations apply: standalone Annex III systems | CRITICAL |
Jan 2028 | Japan | Flat 20% crypto tax rate reported to apply | MEDIUM |
18 Jul 2028 | US | GENIUS Act: US platforms restricted from offering non-reciprocal foreign stablecoins | HIGH |
2 Aug 2028 | EU | EU AI Act high-risk obligations apply: Annex I embedded systems | HIGH |
~2028 | AU/CA/HK/SG/CH/UAE | CARF data exchange tranche 2 | MEDIUM |
2029 | EU | Potential first issuance of the digital euro (subject to legislative adoption) | MEDIUM |
~2029 | US | CARF US data exchange begins | LOW |
2030 to 2032 | G7 Financial Sector | G7 PQC roadmap: critical financial systems migration target | HIGH |
ABOUT THIS PUBLICATION
The DCW Global Regulatory Changes, Compliance & Risk Edition is produced by The Digital Commonwealth Limited (DCW), an independent industry organisation representing the AI, Blockchain, DePIN, Digital Assets, ScienceTech, and Web3 sectors. This publication is updated quarterly to capture material regulatory and compliance developments. This edition covers 1 July 2026 to 30 September 2026. Certain items are drawn from secondary reporting and are identified in the text as such; readers should verify them against primary sources before reliance.
Document Prepared by: Eric Williamson, Director of Compliance and Risk
The Digital Commonwealth Limited | Classification: Industry Analysis Public
EAJW © 2026 DCW Research. All rights reserved.
DISCLAIMER: The information in this publication is for general intelligence purposes only and does not constitute legal, financial, regulatory or compliance advice. Readers should seek independent professional advice regarding specific obligations. DCW accepts no liability for decisions taken in reliance on this publication without independent professional verification.

