Updated researchStable reference

EU Crypto AML Rules in 2026: MiCA and the Travel Rule

A dated guide to EU crypto AML duties, MiCA authorization, the travel rule, self-hosted wallets, and the 2027 AML rulebook.

Topic first covered Current edition By CryptoDigest Research Desk
Plain-English answer

The short answer

As of August 27, 2026, EU crypto-asset service providers generally operate under MiCA authorization and the existing EU AML/CFT framework. Regulation (EU) 2023/1113 has applied since December 30, 2024 and extends the travel rule to covered crypto-asset transfers. The maximum MiCA grandfathering period ended across the EU on July 1, 2026; ESMA says an entity providing MiCA crypto services to EU clients after that date needs the appropriate authorization unless a specific legal route applies.286

The rules do not ban self-hosted wallets. When a crypto-asset service provider is involved, it must collect required originator and beneficiary information and apply risk-based controls. For a transfer above €1,000 between its customer and that customer's self-hosted address, the provider must verify that the customer owns or controls the address. A person-to-person transfer with no service provider involved falls outside the transfer regulation's scope.8106

At a glance

Key findings

  1. 01

    MiCA and AML are different layers

    MiCA governs authorization, conduct, organization, and market rules; AML laws and the transfer regulation govern financial-crime controls and traceability.

  2. 02

    The transition period is over

    July 1, 2026 was the EU-wide final date for MiCA grandfathering; some Member States ended their periods earlier.

  3. 03

    Self-hosted does not mean prohibited

    The framework regulates provider involvement and risk; it expressly contemplates transfers to and from self-hosted addresses.

Dated 27 August 2026

The current position in one page

MiCA has applied in full since December 30, 2024, following the earlier June 30, 2024 start for its asset-referenced-token and e-money-token titles. It establishes EU-wide rules for in-scope crypto-asset issuers and service providers, including authorization, governance, custody, conflicts, complaints, prudential safeguards, and market abuse. MiCA is not itself the complete AML rulebook.23

The recast Transfer of Funds Regulation—Regulation (EU) 2023/1113, often called the travel-rule regulation or TFR—also applies from December 30, 2024. It requires information about originators and beneficiaries to accompany covered crypto-asset transfers and amended Directive (EU) 2015/849 so the broader MiCA CASP category entered the AML/CFT framework.89

The EBA's crypto-specific ML/TF risk-factor and travel-rule guidelines have applied from the same date. National competent authorities and financial intelligence units continue to perform core authorization, AML supervision, and suspicious-activity functions. The EU Anti-Money Laundering Authority (AMLA) is building a more centralized supervisory system, with direct supervision of selected high-risk cross-border financial entities scheduled to begin in 2028.121016

A new directly applicable AML Regulation, Regulation (EU) 2024/1624, is already in force as legislation but generally applies from July 10, 2027. Directive (EU) 2024/1640 will replace Directive (EU) 2015/849 from that date as Member States complete transposition. The result is a current 2026 layer plus a known 2027 changeover—not one timeless checklist.1415

Do not merge the laws

Which EU instrument does what

Other regimes may apply at the same time: sanctions and restrictive measures, payment services, e-money, securities, data protection, tax reporting, consumer law, cyber resilience, and national criminal law. A MiCA licence is not a declaration that every product or transaction complies with all of them.

InstrumentCurrent role on 27 Aug 2026Main crypto relevance
MiCA — Regulation (EU) 2023/1114Fully applicableCASP authorization and passporting; issuer, conduct, custody, governance, prudential, and market rules24
TFR — Regulation (EU) 2023/1113Applicable since 30 Dec 2024Originator and beneficiary information for covered crypto transfers; self-hosted-address controls810
Directive (EU) 2015/849 as amendedCurrent AML/CFT framework until replacementRisk-based CDD, monitoring, reporting, records, governance, and supervision for obliged entities including CASPs138
EBA risk-factor guidelinesApplicable to CASPs since 30 Dec 2024Customer, product, channel, geography, self-hosted-address, and enhanced-due-diligence factors12
EBA travel-rule guidelinesApplicable since 30 Dec 2024Missing information, messaging, self-hosted verification, risk controls, and transfer handling10
AMLR — Regulation (EU) 2024/1624Published and in force; generally applies 10 Jul 2027Harmonized directly applicable AML/CFT obligations across the EU14
AMLD6 — Directive (EU) 2024/1640Transposition underway; replaces 2015/849 from 10 Jul 2027National supervision, FIUs, registers, sanctions, and institutional mechanisms15
AMLA — Regulation (EU) 2024/1620Authority operational and preparing the harmonized systemRulemaking, supervisory convergence, FIU coordination, and selected direct supervision from 202816
From the 2018 article to now

The European crypto AML timeline

DateChangeWhy it matters
2018 / national implementation by 10 Jan 2020The Fifth Anti-Money Laundering Directive added fiat-to-crypto exchange providers and custodial wallet providersThis was the narrower framework the original CryptoDigest article discussed1
29 Jun 2023MiCA and the TFR entered into forceEU legislation created a broader CASP and crypto-transfer framework with staged application28
30 Jun 2024MiCA Titles III and IV began applyingRules for asset-referenced and e-money tokens started before full MiCA application3
30 Dec 2024Full MiCA, crypto TFR, and key EBA guidelines began applyingCASP authorization, AML scope, transfer information, and risk guidance aligned391210
1 Jul 2026Maximum MiCA CASP grandfathering period endedESMA says unauthorized providers serving EU clients must cease unless another lawful route applies6
10 Jul 2027AMLR generally applies and AMLD6 replaces the existing directive frameworkThe EU moves to a more harmonized AML single rulebook and revised national mechanisms1415
2028AMLA plans to begin direct supervision of selected high-risk cross-border financial entitiesMost entities remain nationally supervised, while a selected group moves to EU-level supervision16
Roles and activities

Who is a crypto-asset service provider

MiCA defines a CASP through the professional provision of named crypto-asset services to clients. The list includes custody and administration, operating a trading platform, exchanging crypto-assets for funds or other crypto-assets, executing orders, placing crypto-assets, receiving and transmitting orders, advice, portfolio management, and transfer services. Authorization is granted for specified services, not for an unlimited category called crypto business.24

The TFR amended the AML directive to align the obliged-entity category with MiCA services, subject to wording and exclusions in the applicable instrument. A bank, investment firm, e-money institution, or other regulated financial entity can also provide permitted crypto services through MiCA's notification route rather than the ordinary CASP authorization route, but its exact permissions still matter.84

Software publication, self-custody, protocol development, token issuance, mining or validation, decentralized interfaces, and professional client services raise different scope questions. A label such as DeFi, non-custodial, DAO, or offshore does not decide the legal analysis. Control, intermediation, service facts, solicitation, establishment, clients, asset classification, and exemptions all matter.

  • Identify the legal entity

    The consumer-facing brand may include several companies. ESMA tells users to verify the specific authorized EU legal entity, not assume authorization extends to every group company.67

  • Identify each service

    Custody, exchange, order execution, transfer, advice, and platform operation carry different permissions and risks.4

  • Identify the client and geography

    EU establishment, solicitation, cross-border service, outsourcing, and the narrow reverse-solicitation concept can change the result.6

  • Identify the asset

    MiCA crypto-assets, financial instruments, deposits, funds, e-money tokens, NFTs, and other rights can fall under different or overlapping regimes.2

AML programme

What a risk-based CASP framework generally contains

EU AML/CFT rules use a risk-based approach. A CASP must understand its business, customers, products, transaction types, delivery channels, counterparties, and geographies; apply controls proportionate to those risks; and document why the controls are effective. The EBA's crypto amendments provide sector-specific risk factors rather than declaring every crypto customer or self-hosted transfer high risk.1213

Blockchain analytics can help identify exposure patterns, typologies, and address risk, but it does not replace customer identification, beneficial-owner analysis, source-of-funds work, sanctions screening, context, or human review. A chain score can be wrong, incomplete, vendor-specific, or unable to identify the person controlling an address.12

  • Enterprise-wide risk assessment

    Map inherent ML/TF and sanctions-evasion risks, control effectiveness, residual risk, new products, chains, assets, geographies, channels, and outsourcing.12

  • Customer due diligence

    Identify and verify customers and, where relevant, beneficial owners; understand purpose and intended nature; and resolve identity or control concerns before or during the relationship as law permits.13

  • Risk classification and enhanced measures

    Use customer, product, transaction, delivery-channel, and geographic factors to apply proportionate enhanced or simplified measures where legally available.12

  • Ongoing monitoring

    Compare activity with the customer's profile and source of funds, investigate unusual or complex behavior, refresh information, and retain the reasoning behind alerts and closures.1312

  • Suspicious transaction reporting

    Escalate and report suspicions to the relevant financial intelligence unit under applicable national procedures, while respecting confidentiality and anti-tipping-off rules.13

  • Restrictive-measures controls

    Screen relevant customers, owners, counterparties, and transactions and maintain procedures for freezes, rejections, false positives, and reporting under applicable EU and national sanctions law.

  • Records and audit trail

    Retain required CDD, transfer information, transaction, alert, decision, and reporting records in a form supervisors and investigators can reconstruct.138

  • Governance, staff, and independent testing

    Assign accountable management, maintain policies and training, control agents and outsourcing, protect personal data, test systems, and correct identified weaknesses.

Crypto transfers

How the EU travel rule works

For a covered transfer, the originator's CASP must ensure required originator and beneficiary information is submitted before, simultaneously with, or concurrently with the crypto transfer. The beneficiary's CASP must have procedures to detect missing or incomplete information. Personal travel-rule data can travel through a secure provider messaging channel; it does not need to be written publicly into the blockchain transaction.810

The required data depends on the transaction and legal provisions, but it is designed to make the originator and beneficiary traceable. Providers need data-quality checks, secure transmission, matching to the on-chain transfer, sanctions and AML screening, handling of technical failure, and rules for retention and personal-data protection.810

The crypto travel rule is not generally switched off below €1,000. The €1,000 figure is especially relevant to the additional requirement for a CASP to verify ownership or control when its customer sends to or receives from that customer's self-hosted address. Treating €999 as a no-information threshold misreads the structure of the regulation.8

Transfer pathCore treatmentImportant operational question
CASP → CASPRequired originator and beneficiary information accompanies the transferCan the providers exchange, validate, screen, and match the data before releasing funds?810
Customer self-hosted address → CASPReceiving CASP collects required information from its customer and applies risk-based controlsWho is the external originator, and is the address or transaction consistent with the customer profile?810
CASP → customer's self-hosted addressSending CASP collects required beneficiary information and applies risk-based controlsDoes the customer own or control the destination, and what evidence is proportionate?810
Customer ↔ own self-hosted address above €1,000CASP verifies that its customer owns or controls the self-hosted addressWhich reliable method—such as signed message, small transfer, or supervised verification—fits the wallet?811
Person → person, no CASP involvedOutside the TFR's person-to-person no-provider scopeOther laws and later provider interactions can still apply8
What the rules actually say

Self-hosted wallets are regulated at the provider boundary, not banned

A self-hosted address is one for which no crypto-asset service provider controls the transfer. The TFR expressly contemplates transfers to and from those addresses whenever a CASP is involved. ESMA's April 2026 transition statement even identifies transfer to a self-hosted wallet as one possible way to offboard a client from an unauthorized provider.86

For transfers above €1,000 made between a CASP customer and a self-hosted address that the customer says is their own, the CASP must verify ownership or control. EBA guidance lists possible methods including an attended or unattended display, a small predefined transfer, or signing a message with the key corresponding to the address. The provider must choose reliable and secure evidence, not blindly apply one method to every chain or wallet.811

When the external address belongs to another person, the CASP generally obtains the required counterparty information from its own customer and assesses risk. Risk factors can include transaction pattern, geography, exposure, use of privacy-enhancing features, and the quality of available information, but self-hosting alone is not proof of money laundering.1012

  • Do not publish personal data on-chain

    Match secure travel-rule information to the public transaction while applying data-minimization, access, security, and retention controls.810

  • Support multiple proof methods

    Message signing may not be available on every chain, account, multisig, or smart-contract wallet; design fallbacks that still provide reliable verification.11

  • Separate ownership from risk

    Proof that a customer controls an address does not establish source of funds, transaction purpose, or the legitimacy of prior counterparties.

  • Explain decisions to customers

    A risk-based restriction should have a documented legal and policy basis, review path, and communication that does not reveal protected suspicious-activity information.

Post-transition market

The July 2026 deadline changed the provider question

MiCA's ordinary rule is that a person may not provide crypto-asset services in the EU unless it is an authorized CASP or an eligible regulated financial entity providing permitted services through Article 60. An authorized CASP has a registered office in a Member State, effective management in the EU, and an authorization specifying its services.4

Existing national providers could use Member State grandfathering only until the relevant national end date, authorization or refusal, and never later than July 1, 2026. ESMA's April 2026 statement says that after the EU-wide expiry, an entity providing MiCA services to EU clients without a licence is in breach and must cease. It also warns that a non-EU group company cannot rely on an affiliated EU company's licence.65

Consumers and counterparties should check ESMA's register and the national authority, then match the named legal entity and authorized services to their contract. A familiar brand, application localization, or statement that an application is MiCA-ready is not authorization evidence.76

CheckEvidenceWhy it matters
Legal entityContract, terms, corporate identifier, registered officeAuthorization applies to a legal person, not a brand in the abstract
Authorization statusESMA MiCA register and home national authorityThe old transitional status ended no later than 1 Jul 202676
Authorized servicesLicence or register service fieldsCustody, exchange, transfer, advice, and platform permissions differ4
Client-facing entityAccount agreement, statements, payment details, and support noticesA non-EU affiliate may operate under the same brand without sharing the EU licence6
AML supervisor and FIU routeHome-state authority, provider disclosures, and national reporting processAML supervision and suspicious-report handling remain tied to competent institutions
Known changes ahead

What changes in July 2027 and 2028

The AMLR will replace much of the directive-based private-sector rule set with directly applicable EU requirements from July 10, 2027. Its purpose is greater consistency across Member States. Firms should map its requirements early but avoid describing a future-applying provision as the controlling 2026 rule.14

AMLD6 addresses the national mechanisms surrounding that single rulebook, including supervisors, financial intelligence units, registers, cooperation, and sanctions. It repeals Directive (EU) 2015/849 from July 10, 2027, subject to the directive's phased transposition details.15

AMLA is developing regulatory standards, common methods, FIU coordination, and supervisory convergence. It plans to select directly supervised entities in 2027 and begin direct supervision in 2028 for a limited group meeting cross-border and high-risk criteria. Most CASPs will still interact directly with national authorities, even as AMLA shapes the common framework.16

Operational checklist

A defensible implementation sequence for a CASP

  • 1. Scope the business

    Map entity, establishment, clients, assets, chains, MiCA services, payment services, custody, outsourcing, agents, and every country served.

  • 2. Confirm authorization and accountability

    Match permissions to services; identify home and host authorities, AML management, compliance leadership, FIU processes, and board reporting.46

  • 3. Build the risk assessment from evidence

    Use customer, product, chain, delivery, counterparty, and geographic data; document methodology, data gaps, residual risk, and approval.12

  • 4. Join identity and transaction controls

    Link verified customer and beneficial-owner records to accounts, addresses, deposits, withdrawals, trades, devices, counterparties, alerts, and case decisions.

  • 5. Implement travel-rule orchestration

    Select secure messaging and counterparty-discovery processes; validate data; match it to transfers; handle self-hosted addresses, failures, and missing information.810

  • 6. Test adverse scenarios

    Cover chain reorganization, replacement transactions, bridge hops, mixers, privacy assets, smart-contract wallets, account abstraction, failed proof of control, provider outage, and false sanctions matches.

  • 7. Protect the evidence

    Apply data minimization, encryption, role-based access, retention, quality controls, model governance, vendor oversight, and reproducible audit logs.

  • 8. Prepare for 2027

    Maintain a gap analysis for AMLR, AMLD6, and AMLA standards with named owners and dates, while keeping the current programme compliant today.141516

Frequent errors

Five claims the legal texts do not support

  • 'MiCA replaced AML law.'

    MiCA and AML/TFR requirements operate together. Authorization does not remove CDD, monitoring, travel-rule, reporting, or sanctions duties.28

  • 'The EU banned self-custody.'

    The TFR regulates transfers involving CASPs and expressly addresses self-hosted addresses; person-to-person transfers without a provider are outside its scope.86

  • 'Travel-rule data is required only above €1,000.'

    The regulation's transfer-information duties are broader. The €1,000 threshold triggers a particular control-verification duty for a customer's self-hosted address.8

  • 'A blockchain-analytics score proves criminal activity.'

    Analytics is one risk input. Attribution, customer context, false positives, source reliability, legal standards, and investigation remain necessary.12

  • 'Our old national registration still lets us serve the EU.'

    The maximum MiCA grandfathering period ended July 1, 2026, and some national periods ended earlier. Current authorization and service scope must be verified.65

Reader questions

Frequently asked questions

Concise answers to the questions readers most often ask about this topic.

Did the EU ban self-hosted crypto wallets?

No. EU law expressly contemplates transfers to and from self-hosted addresses. When a CASP is involved, it must collect information and apply risk controls; above €1,000, it must verify control when its customer transfers to or from that customer's own address. Person-to-person transfers without a CASP are outside the TFR's scope.8106

Does the EU crypto travel rule apply below €1,000?

Yes, the information requirements for covered CASP transfers are not generally limited to amounts above €1,000. That threshold is tied to an additional ownership-or-control verification when a CASP customer uses their own self-hosted address.8

Is MiCA the EU anti-money-laundering law?

MiCA is primarily the crypto-asset market and service-provider regime. CASPs also follow the AML/CFT framework and the crypto transfer regulation. The instruments interact, but a MiCA authorization does not replace AML obligations.28

Can an old national VASP registration still be used in 2026?

Not as an EU-wide continuation after the applicable transition. The maximum MiCA grandfathering period ended on July 1, 2026, and several Member States chose shorter periods. Verify current authorization in ESMA's register and with the national authority.657

What information travels with a crypto transfer?

Covered transfers carry prescribed information identifying the originator and beneficiary plus account, address, or transaction identifiers required by the regulation. CASPs validate and securely exchange that information and match it to the on-chain transfer; it need not be published on the public blockchain.810

What happens if travel-rule information is missing?

The receiving or intermediary provider must detect missing or incomplete information and apply documented, risk-based procedures. Depending on the facts, it may request information and decide whether to execute, reject, return, or suspend the transfer and whether further AML escalation is required.810

When does the new EU AML Regulation apply?

Regulation (EU) 2024/1624 generally applies from July 10, 2027. Until the changeover, the current framework remains relevant. Firms should prepare for AMLR without describing its future-applying provisions as the law already controlling every 2026 obligation.1415

Method 2.0

Methodology

This edition is dated to August 27, 2026 and prioritizes EUR-Lex legislation, ESMA authorization statements and registers, EBA guidelines, and AMLA's official implementation timeline. It distinguishes entry into force, application, transposition, transitional end dates, and planned future supervision.2861012141516

CryptoDigest first covered European crypto AML changes in 2018, when the Fifth Anti-Money Laundering Directive had a much narrower provider scope. This new guide does not preserve that framework as current law; it uses the historical date only to explain how the rules evolved.1

Limitations

  • This guide is general information, not legal advice, and cannot determine the rules for a particular entity, asset, transfer, customer, or Member State.
  • EU regulations interact with national competent-authority practice, criminal law, FIU procedures, sanctions, data protection, payments, tax, and other sector rules.
  • EBA, ESMA, AMLA, the Commission, courts, and national authorities can issue or revise binding measures, guidance, Q&As, and interpretations after the displayed date.
  • The 2027 framework is described as a scheduled future change and should not be applied as though it already replaced the current 2026 rules.
  • Technical controls such as blockchain analytics or proof of address control do not by themselves establish compliance or criminal conduct.
16 references

Sources and evidence

Claims are linked to the technical documentation, standards, law, research, and enforcement records that support them.

  1. 1
    Directive (EU) 2018/843 — Fifth Anti-Money Laundering Directive

    EUR-Lex · Historical EU legislation

    Supports: 2018 virtual-currency, fiat-exchange, and custodian-wallet framework
  2. 2
    Regulation (EU) 2023/1114 on Markets in Crypto-assets

    EUR-Lex · EU regulation

    Supports: MiCA scope, issuers, CASPs, conduct, governance, and market rules
  3. 3
    MiCA Article 149: application dates

    European Securities and Markets Authority · Official rulebook

    Supports: 30 June and 30 December 2024 application dates
  4. 4
    MiCA Title V: CASP authorization and operating conditions

    EUR-Lex · EU regulation

    Supports: CASP services, authorization, legal presence, and regulated-entity route
  5. 5
    MiCA Article 143: transitional measures

    European Securities and Markets Authority · Official rulebook

    Supports: Grandfathering, shorter national periods, and July 1, 2026 maximum
  6. 6
    Statement on the End of Transitional Periods under MiCA

    European Securities and Markets Authority · Supervisory statement

    Supports: Post-July 2026 authorization, wind-down, group entities, and consumer checks
  7. 7
    MiCA registers and implementation page

    European Securities and Markets Authority · Official register

    Supports: Authorized CASPs, issuers, white papers, and non-compliant entities
  8. 8
    Regulation (EU) 2023/1113 on information accompanying transfers

    EUR-Lex · EU regulation

    Supports: Crypto travel rule, scope, data, self-hosted addresses, and AMLD amendments
  9. 9
    Information accompanying transfers of funds and certain crypto-assets

    EUR-Lex · Official legal summary

    Supports: Purpose, application date, traceability, and self-hosted transfers
  10. 10
    EBA travel-rule guidance

    European Banking Authority · Regulatory guidance

    Supports: Missing information, CASP procedures, traceability, and self-hosted controls
  11. 11
    Final EBA Travel Rule Guidelines

    European Banking Authority · Regulatory guidelines

    Supports: Proof-of-control methods, self-hosted risk assessment, and implementation detail
  12. 12
    EBA ML/TF risk-factor guidance for CASPs

    European Banking Authority · Regulatory guidance

    Supports: Risk factors, mitigating measures, blockchain analytics, and 2024 application
  13. 13
    Directive (EU) 2015/849 consolidated AML/CFT framework

    EUR-Lex · EU directive

    Supports: CDD, ongoing monitoring, reporting, records, controls, and supervision
  14. 14
    Regulation (EU) 2024/1624 — AML Regulation

    EUR-Lex · Future-applying EU regulation

    Supports: Harmonized rulebook and July 10, 2027 general application date
  15. 15
    Directive (EU) 2024/1640 — AMLD6

    EUR-Lex · EU directive

    Supports: National mechanisms, transposition, and 2027 replacement of Directive 2015/849
  16. 16
    AMLA frequently asked questions and implementation timeline

    EU Anti-Money Laundering Authority · Authority guidance

    Supports: AMLA functions, 2027 selection, and direct supervision from 2028

Cite this resource

Stable edition 2026.08.27

Version history

  1. 2026.08.27

    Full editorial rebuild with claim-level citations, current primary sources, tables, and reader FAQs.

  2. 2026.08.26

    Initial source-backed guide edition published.

  3. Earlier coverage

    CryptoDigest previously covered this topic; the original article text is unavailable.