AML
Crypto
Regulation
MiCA
FATF

MiCA and the New Crypto AML Landscape: What 2026 Compliance Looks Like

The EU's Markets in Crypto Assets regulation is now fully in force, and its ripple effects are reshaping AML compliance globally. Here's a practitioner's guide to what has changed and what your program needs to address.

RiskLex EditorialJune 20, 2026
MiCA and the New Crypto AML Landscape: What 2026 Compliance Looks Like

A Regulatory Sea Change

On 30 December 2024, the Markets in Crypto Assets Regulation (MiCA) became fully applicable across all 27 EU member states, marking the first time a major jurisdiction implemented a comprehensive, harmonised legal framework for crypto asset service providers (CASPs). For AML practitioners, MiCA represents both a compliance milestone and an operational challenge — it mandates controls that were previously aspirational for much of the industry.

Combined with the EU Transfer of Funds Regulation (TFR) — the crypto version of the FATF Travel Rule — the regulatory stack now demands institutional-grade AML programmes from entities that, until recently, operated with the informality of early fintech startups.

The Travel Rule: Operationalised at Scale

The FATF Travel Rule requires that identifying information about the originator and beneficiary of a virtual asset transfer travel with that transfer. In the EU, TFR went live in December 2024 with no minimum threshold — every crypto transfer, regardless of amount, must carry VASP-to-VASP originator and beneficiary data.

This sounds straightforward. In practice, it has exposed profound data quality and interoperability problems:

  • No universal messaging standard. VASPs have adopted competing Travel Rule protocols (IVMS 101, OpenVASP, Notabene, Sygna Bridge), creating translation friction at every cross-VASP hop.
  • Sunrise issue. Transfers to VASPs in jurisdictions that haven't yet implemented the Travel Rule create compliance gaps. EU VASPs must now assess whether counterparty jurisdictions are FATF-compliant and apply enhanced due diligence where they are not.
  • Unhosted wallet interactions. Transfers to self-custodied wallets require additional customer verification for amounts above 1,000 EUR and ongoing risk assessment. This has forced VASPs to implement blockchain analytics workflows that didn't previously exist in their compliance stack.

MiCA's AML Expectations Beyond the Travel Rule

MiCA's AML obligations extend well beyond fund-transfer tagging. Key requirements that are reshaping compliance programmes in 2026:

Mandatory Crypto-Asset Risk Assessments CASPs must conduct documented risk assessments of the crypto assets they list or custody — evaluating their susceptibility to money laundering based on transaction anonymity, mixer compatibility, smart contract risk, and the jurisdiction of the issuing entity. This has created a new subspecialty: **asset-level AML due diligence**, akin to the counterparty assessments banks conduct for correspondent relationships.

On-Chain Transaction Monitoring Blockchain analytics is no longer optional. MiCA-supervised entities are expected to screen transactions against sanctions lists in real time, monitor for patterns consistent with layering (e.g. rapid chain-hopping, mixer interactions, peel chains), and file SARs/STRs based on on-chain indicators — not just off-chain behavioral signals.

Regulators are now examining whether analytics tools cover the full asset universe an institution trades, not just Bitcoin and Ethereum. Firms with significant exposure to DeFi protocols or layer-2 networks face particular scrutiny.

Beneficial Ownership for Institutional Clients For institutional CASP clients, MiCA aligns with the EU's 6th Anti-Money Laundering Directive (6AMLD) expectations: full beneficial ownership transparency to the natural person level, with ongoing monitoring. This is particularly demanding for DAO-structured counterparties and investment vehicles holding crypto assets, where ownership chains are novel and frequently contested.

The US Contrast: A Fragmented but Tightening Picture

While the EU moved to harmonisation, the US regulatory landscape in 2025-2026 has been characterised by tension between deregulatory impulses and enforcement continuity.

The SEC's shift under the new administration significantly reduced novel enforcement actions against crypto exchanges. However, FinCEN's Bank Secrecy Act obligations for money services businesses — which cover most centralised exchanges — remain intact. FinCEN's proposed rule to extend BSA requirements to DeFi protocol developers and front-end operators, first floated in 2023, remains unresolved but has not been formally withdrawn.

State-level regulation has accelerated to fill the perceived federal gap. New York's BitLicense remains the gold standard, and several states have introduced equivalent frameworks. Institutions serving US customers while based offshore face a patchwork of state registration obligations that rivals MiCA's complexity without its coherence.

FATF's 2025 Mutual Evaluation Cycle: Crypto as a Priority

FATF's current mutual evaluation round has placed virtual asset regulation at the centre of assessments. Countries with weak VASP oversight — or those that have not yet brought Travel Rule obligations into domestic law — risk FATF grey-listing, which carries significant correspondent banking consequences.

This creates a practical risk management obligation for global CASPs: they must continuously monitor FATF evaluation outcomes and adjust their counterparty risk ratings accordingly. A VASP in a newly grey-listed jurisdiction should trigger enhanced due diligence, regardless of the prior relationship.

What Effective Crypto AML Looks Like in 2026

Programme architecture: Treat blockchain analytics as a first-class compliance tool, not a back-office add-on. Integration with transaction monitoring systems should enable automated alert generation based on on-chain risk indicators.

Travel Rule operations: Implement a VASP discovery and verification workflow. Before transacting, confirm the counterparty VASP's licensing status, Travel Rule protocol, and sanctions screening practices. This is now a due diligence obligation, not a trust assumption.

Asset listing governance: Establish a documented asset onboarding committee with AML representation. Privacy coins (Monero, Zcash shielded transactions) and tokens with built-in mixer functionality require explicit policy decisions — most EU-regulated CASPs have delisted them entirely.

Regulatory horizon scanning: MiCA's technical standards (RTS/ITS) are still being finalised by ESMA and EBA. The next 18 months will see significant secondary legislation on market manipulation surveillance, white paper disclosures, and custody requirements. Compliance teams need dedicated regulatory intelligence capacity to track this output.

The era of crypto operating at the margins of AML regulation is definitively over. The institutions that treat this as an opportunity to build genuinely robust programmes — rather than minimally compliant ones — will be better positioned as regulatory expectations continue to converge globally.