Regulatory Updates on AML and MiCA in 2026
Financial crime continues to evolve alongside technological developments, digitalization, and the increasing use of crypto-assets. Money launderers and other financial criminals may seek to exploit new technologies, payment methods and cross-border structures to conceal the origin or movement of illicit funds. This reinforces the importance of regularly reviewing and updating the applicable legal and regulatory framework to ensure that it remains responsive to emerging risks and evolving financial crime typologies.
In 2026, Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) requirements continue to develop alongside the regulatory framework governing crypto-assets. For regulated entities, this means understanding not only the traditional AML/CFT framework, but also how financial crime risks may arise from fiat currencies, digital assets and crypto-assets and how those risks should be identified, assessed and mitigated.
At the same time, the European Regulation on Markets in Crypto-Assets (MiCA) establishes a harmonized regulatory framework for crypto-assets across the European Union. The framework addresses, among other matters, the authorization, operation, organisation and governance of Crypto-Asset Service Providers (CASPs) and issuers of crypto-assets.
In this article, the SALVUS Regulatory Compliance team takes a closer look at the significant applicable regulatory updates for regulated entities. We break down the key updates and share the most relevant insights below.
1. Key Regulatory Updates in 2026
2. Specific Regulatory Updates for CASPs under MiCA in 20256
We regularly share bite-sized insights on LinkedIn such as those found in this article
1. Key Regulatory Updates in 2026
- AMLA Takes Over the EU AML/CFT Mandate
- Development of the EU AML/CFT Single Rulebook
- Preparations for AMLA Direct Supervision
AMLA Takes Over the EU AML/CFT Mandate
A major regulatory development in 2026 is the transfer of responsibility for EU-level AML/CFT functions from the European Banking Authority (EBA) to the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA).
On 1 January 2026, AMLA and the EBA completed the transfer of all AML/CFT mandates and functions. Existing EBA AML/CFT Guidelines and standards remain applicable until they are replaced by AMLA instruments. AMLA is now responsible for completing the EU AML/CFT Single Rulebook, promoting supervisory convergence and coordinating cooperation between Financial Intelligence Units.
Development of the EU AML/CFT Single Rulebook
During 2026, AMLA significantly progressed the technical standards and guidelines needed to implement the new EU AML/CFT framework. Several instruments underwent public consultation during the year, while AMLA also published final reports on certain draft technical standards.
Among the main areas addressed are:
- Customer Due Diligence, including customer identification, verification and ongoing monitoring;
- criteria for identifying business relationships, occasional transactions and linked transactions;
- business-wide ML/TF risk assessments;
- group-wide AML/CFT requirements;
- formats for reporting suspicious activity and transaction records;
- methodologies for assessing the inherent and residual ML/TF risk of obliged entities; and
- sanctions, administrative measures and periodic penalty payments.
These measures represent an important step towards a more harmonised application of AML/CFT requirements across the European Union.
Preparations for AMLA Direct Supervision
Another important 2026 development is AMLA’s preparation for the future direct supervision of selected high-risk financial institutions and groups.
In May 2026, AMLA published a reporting package to help identify entities that may qualify for its first selection exercise. The selection process is scheduled for 2027, with AMLA’s direct supervision of selected institutions expected to begin in 2028.
2. Specific Regulatory Updates for CASPs under MiCA in 2025
- End of the MiCA Transitional Period
- ML/TF Risks Following the End of the MiCA Transitional Period
- Supervisory Focus on CASPs’ Digital Operational Resilience
End of the MiCA Transitional Period
One of the most important MiCA developments in 2026 is the end of the EU-wide transitional period on 1 July 2026.
ESMA clarified that, following this date, an entity providing crypto-asset services to EU clients without the required MiCA authorization is in breach of EU law and must cease providing those services. CASPs that had not obtained authorization were expected to implement their wind-down arrangements, while authorized CASPs were expected to appropriately manage the migration and onboarding of existing clients.
ML/TF Risks Following the End of the MiCA Transitional Period
Following the end of the transitional period, CySEC issued Circular C790 on 7 July 2026, drawing regulated entities’ attention to the ML/TF risks associated with the transition to the fully authorized MiCA environment.
Particular attention is required where unauthorized VASPs exit the market, and their customers or activities migrate to authorized CASPs. This may result in changes to CASPs’ customer populations, business models, and overall ML/TF risk exposure. Regulated entities therefore need to continue applying an appropriate risk-based approach when dealing with customer migrations and relationships or transactions involving unauthorized or offshore VASPs.
Supervisory Focus on CASPs’ Digital Operational Resilience
In July 2026, ESMA launched a Common Supervisory Action (CSA) on the digital operational resilience of CASPs, with particular focus on crypto-asset custody.
The supervisory exercise examines areas including:
- governance arrangements;
- cryptographic key and storage management;
- transaction controls;
- incident detection and response;
- smart-contract risks; and
- dependencies on ICT third-party providers.
The exercise runs from the second half of 2026 through the first half of 2027 and involves a risk-based sample of authorized CASPs.
SALVUS Funds, in collaboration with the Institute for Professional Excellence (IforPE), presents a self-study course titled “Regulatory Updates on AML and MiCA in 2026”. This course serves as a comprehensive guide through the dynamic landscape of crypto assets and the ever-evolving regulatory environment.
The SALVUS Regulatory Compliance team can support CIFs, CASPs and other CySEC and CBC regulated entities, with their regulatory requirements and reporting obligations.
Contact us at compliance@salvusfunds.com if you require further guidance or if you have enquiries about our Regulatory Updates course with IforPE.
#StayAhead
The information provided in this article is for general information purposes only. You should always seek professional advice suitable to your needs.