EU Crypto AML Rules in 2026: MiCA and the Travel Rule
A dated guide to EU crypto AML duties, MiCA authorization, the travel rule, self-hosted wallets, and the 2027 AML rulebook.
The short answer
As of August 27, 2026, EU crypto-asset service providers generally operate under MiCA authorization and the existing EU AML/CFT framework. Regulation (EU) 2023/1113 has applied since December 30, 2024 and extends the travel rule to covered crypto-asset transfers. The maximum MiCA grandfathering period ended across the EU on July 1, 2026; ESMA says an entity providing MiCA crypto services to EU clients after that date needs the appropriate authorization unless a specific legal route applies.286
The rules do not ban self-hosted wallets. When a crypto-asset service provider is involved, it must collect required originator and beneficiary information and apply risk-based controls. For a transfer above €1,000 between its customer and that customer's self-hosted address, the provider must verify that the customer owns or controls the address. A person-to-person transfer with no service provider involved falls outside the transfer regulation's scope.8106
Key findings
- 01
MiCA and AML are different layers
MiCA governs authorization, conduct, organization, and market rules; AML laws and the transfer regulation govern financial-crime controls and traceability.
- 02
The transition period is over
July 1, 2026 was the EU-wide final date for MiCA grandfathering; some Member States ended their periods earlier.
- 03
Self-hosted does not mean prohibited
The framework regulates provider involvement and risk; it expressly contemplates transfers to and from self-hosted addresses.
The current position in one page
MiCA has applied in full since December 30, 2024, following the earlier June 30, 2024 start for its asset-referenced-token and e-money-token titles. It establishes EU-wide rules for in-scope crypto-asset issuers and service providers, including authorization, governance, custody, conflicts, complaints, prudential safeguards, and market abuse. MiCA is not itself the complete AML rulebook.23
The recast Transfer of Funds Regulation—Regulation (EU) 2023/1113, often called the travel-rule regulation or TFR—also applies from December 30, 2024. It requires information about originators and beneficiaries to accompany covered crypto-asset transfers and amended Directive (EU) 2015/849 so the broader MiCA CASP category entered the AML/CFT framework.89
The EBA's crypto-specific ML/TF risk-factor and travel-rule guidelines have applied from the same date. National competent authorities and financial intelligence units continue to perform core authorization, AML supervision, and suspicious-activity functions. The EU Anti-Money Laundering Authority (AMLA) is building a more centralized supervisory system, with direct supervision of selected high-risk cross-border financial entities scheduled to begin in 2028.121016
A new directly applicable AML Regulation, Regulation (EU) 2024/1624, is already in force as legislation but generally applies from July 10, 2027. Directive (EU) 2024/1640 will replace Directive (EU) 2015/849 from that date as Member States complete transposition. The result is a current 2026 layer plus a known 2027 changeover—not one timeless checklist.1415
Which EU instrument does what
Other regimes may apply at the same time: sanctions and restrictive measures, payment services, e-money, securities, data protection, tax reporting, consumer law, cyber resilience, and national criminal law. A MiCA licence is not a declaration that every product or transaction complies with all of them.
| Instrument | Current role on 27 Aug 2026 | Main crypto relevance |
|---|---|---|
| MiCA — Regulation (EU) 2023/1114 | Fully applicable | CASP authorization and passporting; issuer, conduct, custody, governance, prudential, and market rules24 |
| TFR — Regulation (EU) 2023/1113 | Applicable since 30 Dec 2024 | Originator and beneficiary information for covered crypto transfers; self-hosted-address controls810 |
| Directive (EU) 2015/849 as amended | Current AML/CFT framework until replacement | Risk-based CDD, monitoring, reporting, records, governance, and supervision for obliged entities including CASPs138 |
| EBA risk-factor guidelines | Applicable to CASPs since 30 Dec 2024 | Customer, product, channel, geography, self-hosted-address, and enhanced-due-diligence factors12 |
| EBA travel-rule guidelines | Applicable since 30 Dec 2024 | Missing information, messaging, self-hosted verification, risk controls, and transfer handling10 |
| AMLR — Regulation (EU) 2024/1624 | Published and in force; generally applies 10 Jul 2027 | Harmonized directly applicable AML/CFT obligations across the EU14 |
| AMLD6 — Directive (EU) 2024/1640 | Transposition underway; replaces 2015/849 from 10 Jul 2027 | National supervision, FIUs, registers, sanctions, and institutional mechanisms15 |
| AMLA — Regulation (EU) 2024/1620 | Authority operational and preparing the harmonized system | Rulemaking, supervisory convergence, FIU coordination, and selected direct supervision from 202816 |
The European crypto AML timeline
| Date | Change | Why it matters |
|---|---|---|
| 2018 / national implementation by 10 Jan 2020 | The Fifth Anti-Money Laundering Directive added fiat-to-crypto exchange providers and custodial wallet providers | This was the narrower framework the original CryptoDigest article discussed1 |
| 29 Jun 2023 | MiCA and the TFR entered into force | EU legislation created a broader CASP and crypto-transfer framework with staged application28 |
| 30 Jun 2024 | MiCA Titles III and IV began applying | Rules for asset-referenced and e-money tokens started before full MiCA application3 |
| 30 Dec 2024 | Full MiCA, crypto TFR, and key EBA guidelines began applying | CASP authorization, AML scope, transfer information, and risk guidance aligned391210 |
| 1 Jul 2026 | Maximum MiCA CASP grandfathering period ended | ESMA says unauthorized providers serving EU clients must cease unless another lawful route applies6 |
| 10 Jul 2027 | AMLR generally applies and AMLD6 replaces the existing directive framework | The EU moves to a more harmonized AML single rulebook and revised national mechanisms1415 |
| 2028 | AMLA plans to begin direct supervision of selected high-risk cross-border financial entities | Most entities remain nationally supervised, while a selected group moves to EU-level supervision16 |
Who is a crypto-asset service provider
MiCA defines a CASP through the professional provision of named crypto-asset services to clients. The list includes custody and administration, operating a trading platform, exchanging crypto-assets for funds or other crypto-assets, executing orders, placing crypto-assets, receiving and transmitting orders, advice, portfolio management, and transfer services. Authorization is granted for specified services, not for an unlimited category called crypto business.24
The TFR amended the AML directive to align the obliged-entity category with MiCA services, subject to wording and exclusions in the applicable instrument. A bank, investment firm, e-money institution, or other regulated financial entity can also provide permitted crypto services through MiCA's notification route rather than the ordinary CASP authorization route, but its exact permissions still matter.84
Software publication, self-custody, protocol development, token issuance, mining or validation, decentralized interfaces, and professional client services raise different scope questions. A label such as DeFi, non-custodial, DAO, or offshore does not decide the legal analysis. Control, intermediation, service facts, solicitation, establishment, clients, asset classification, and exemptions all matter.
Identify the legal entity
The consumer-facing brand may include several companies. ESMA tells users to verify the specific authorized EU legal entity, not assume authorization extends to every group company.67
Identify each service
Custody, exchange, order execution, transfer, advice, and platform operation carry different permissions and risks.4
Identify the client and geography
EU establishment, solicitation, cross-border service, outsourcing, and the narrow reverse-solicitation concept can change the result.6
Identify the asset
MiCA crypto-assets, financial instruments, deposits, funds, e-money tokens, NFTs, and other rights can fall under different or overlapping regimes.2
What a risk-based CASP framework generally contains
EU AML/CFT rules use a risk-based approach. A CASP must understand its business, customers, products, transaction types, delivery channels, counterparties, and geographies; apply controls proportionate to those risks; and document why the controls are effective. The EBA's crypto amendments provide sector-specific risk factors rather than declaring every crypto customer or self-hosted transfer high risk.1213
Blockchain analytics can help identify exposure patterns, typologies, and address risk, but it does not replace customer identification, beneficial-owner analysis, source-of-funds work, sanctions screening, context, or human review. A chain score can be wrong, incomplete, vendor-specific, or unable to identify the person controlling an address.12
Enterprise-wide risk assessment
Map inherent ML/TF and sanctions-evasion risks, control effectiveness, residual risk, new products, chains, assets, geographies, channels, and outsourcing.12
Customer due diligence
Identify and verify customers and, where relevant, beneficial owners; understand purpose and intended nature; and resolve identity or control concerns before or during the relationship as law permits.13
Risk classification and enhanced measures
Use customer, product, transaction, delivery-channel, and geographic factors to apply proportionate enhanced or simplified measures where legally available.12
Ongoing monitoring
Compare activity with the customer's profile and source of funds, investigate unusual or complex behavior, refresh information, and retain the reasoning behind alerts and closures.1312
Suspicious transaction reporting
Escalate and report suspicions to the relevant financial intelligence unit under applicable national procedures, while respecting confidentiality and anti-tipping-off rules.13
Restrictive-measures controls
Screen relevant customers, owners, counterparties, and transactions and maintain procedures for freezes, rejections, false positives, and reporting under applicable EU and national sanctions law.
Records and audit trail
Retain required CDD, transfer information, transaction, alert, decision, and reporting records in a form supervisors and investigators can reconstruct.138
Governance, staff, and independent testing
Assign accountable management, maintain policies and training, control agents and outsourcing, protect personal data, test systems, and correct identified weaknesses.
How the EU travel rule works
For a covered transfer, the originator's CASP must ensure required originator and beneficiary information is submitted before, simultaneously with, or concurrently with the crypto transfer. The beneficiary's CASP must have procedures to detect missing or incomplete information. Personal travel-rule data can travel through a secure provider messaging channel; it does not need to be written publicly into the blockchain transaction.810
The required data depends on the transaction and legal provisions, but it is designed to make the originator and beneficiary traceable. Providers need data-quality checks, secure transmission, matching to the on-chain transfer, sanctions and AML screening, handling of technical failure, and rules for retention and personal-data protection.810
The crypto travel rule is not generally switched off below €1,000. The €1,000 figure is especially relevant to the additional requirement for a CASP to verify ownership or control when its customer sends to or receives from that customer's self-hosted address. Treating €999 as a no-information threshold misreads the structure of the regulation.8
| Transfer path | Core treatment | Important operational question |
|---|---|---|
| CASP → CASP | Required originator and beneficiary information accompanies the transfer | Can the providers exchange, validate, screen, and match the data before releasing funds?810 |
| Customer self-hosted address → CASP | Receiving CASP collects required information from its customer and applies risk-based controls | Who is the external originator, and is the address or transaction consistent with the customer profile?810 |
| CASP → customer's self-hosted address | Sending CASP collects required beneficiary information and applies risk-based controls | Does the customer own or control the destination, and what evidence is proportionate?810 |
| Customer ↔ own self-hosted address above €1,000 | CASP verifies that its customer owns or controls the self-hosted address | Which reliable method—such as signed message, small transfer, or supervised verification—fits the wallet?811 |
| Person → person, no CASP involved | Outside the TFR's person-to-person no-provider scope | Other laws and later provider interactions can still apply8 |
Self-hosted wallets are regulated at the provider boundary, not banned
A self-hosted address is one for which no crypto-asset service provider controls the transfer. The TFR expressly contemplates transfers to and from those addresses whenever a CASP is involved. ESMA's April 2026 transition statement even identifies transfer to a self-hosted wallet as one possible way to offboard a client from an unauthorized provider.86
For transfers above €1,000 made between a CASP customer and a self-hosted address that the customer says is their own, the CASP must verify ownership or control. EBA guidance lists possible methods including an attended or unattended display, a small predefined transfer, or signing a message with the key corresponding to the address. The provider must choose reliable and secure evidence, not blindly apply one method to every chain or wallet.811
When the external address belongs to another person, the CASP generally obtains the required counterparty information from its own customer and assesses risk. Risk factors can include transaction pattern, geography, exposure, use of privacy-enhancing features, and the quality of available information, but self-hosting alone is not proof of money laundering.1012
Do not publish personal data on-chain
Match secure travel-rule information to the public transaction while applying data-minimization, access, security, and retention controls.810
Support multiple proof methods
Message signing may not be available on every chain, account, multisig, or smart-contract wallet; design fallbacks that still provide reliable verification.11
Separate ownership from risk
Proof that a customer controls an address does not establish source of funds, transaction purpose, or the legitimacy of prior counterparties.
Explain decisions to customers
A risk-based restriction should have a documented legal and policy basis, review path, and communication that does not reveal protected suspicious-activity information.
The July 2026 deadline changed the provider question
MiCA's ordinary rule is that a person may not provide crypto-asset services in the EU unless it is an authorized CASP or an eligible regulated financial entity providing permitted services through Article 60. An authorized CASP has a registered office in a Member State, effective management in the EU, and an authorization specifying its services.4
Existing national providers could use Member State grandfathering only until the relevant national end date, authorization or refusal, and never later than July 1, 2026. ESMA's April 2026 statement says that after the EU-wide expiry, an entity providing MiCA services to EU clients without a licence is in breach and must cease. It also warns that a non-EU group company cannot rely on an affiliated EU company's licence.65
Consumers and counterparties should check ESMA's register and the national authority, then match the named legal entity and authorized services to their contract. A familiar brand, application localization, or statement that an application is MiCA-ready is not authorization evidence.76
| Check | Evidence | Why it matters |
|---|---|---|
| Legal entity | Contract, terms, corporate identifier, registered office | Authorization applies to a legal person, not a brand in the abstract |
| Authorization status | ESMA MiCA register and home national authority | The old transitional status ended no later than 1 Jul 202676 |
| Authorized services | Licence or register service fields | Custody, exchange, transfer, advice, and platform permissions differ4 |
| Client-facing entity | Account agreement, statements, payment details, and support notices | A non-EU affiliate may operate under the same brand without sharing the EU licence6 |
| AML supervisor and FIU route | Home-state authority, provider disclosures, and national reporting process | AML supervision and suspicious-report handling remain tied to competent institutions |
What changes in July 2027 and 2028
The AMLR will replace much of the directive-based private-sector rule set with directly applicable EU requirements from July 10, 2027. Its purpose is greater consistency across Member States. Firms should map its requirements early but avoid describing a future-applying provision as the controlling 2026 rule.14
AMLD6 addresses the national mechanisms surrounding that single rulebook, including supervisors, financial intelligence units, registers, cooperation, and sanctions. It repeals Directive (EU) 2015/849 from July 10, 2027, subject to the directive's phased transposition details.15
AMLA is developing regulatory standards, common methods, FIU coordination, and supervisory convergence. It plans to select directly supervised entities in 2027 and begin direct supervision in 2028 for a limited group meeting cross-border and high-risk criteria. Most CASPs will still interact directly with national authorities, even as AMLA shapes the common framework.16
A defensible implementation sequence for a CASP
1. Scope the business
Map entity, establishment, clients, assets, chains, MiCA services, payment services, custody, outsourcing, agents, and every country served.
2. Confirm authorization and accountability
Match permissions to services; identify home and host authorities, AML management, compliance leadership, FIU processes, and board reporting.46
3. Build the risk assessment from evidence
Use customer, product, chain, delivery, counterparty, and geographic data; document methodology, data gaps, residual risk, and approval.12
4. Join identity and transaction controls
Link verified customer and beneficial-owner records to accounts, addresses, deposits, withdrawals, trades, devices, counterparties, alerts, and case decisions.
5. Implement travel-rule orchestration
Select secure messaging and counterparty-discovery processes; validate data; match it to transfers; handle self-hosted addresses, failures, and missing information.810
6. Test adverse scenarios
Cover chain reorganization, replacement transactions, bridge hops, mixers, privacy assets, smart-contract wallets, account abstraction, failed proof of control, provider outage, and false sanctions matches.
7. Protect the evidence
Apply data minimization, encryption, role-based access, retention, quality controls, model governance, vendor oversight, and reproducible audit logs.
8. Prepare for 2027
Maintain a gap analysis for AMLR, AMLD6, and AMLA standards with named owners and dates, while keeping the current programme compliant today.141516
Five claims the legal texts do not support
'MiCA replaced AML law.'
MiCA and AML/TFR requirements operate together. Authorization does not remove CDD, monitoring, travel-rule, reporting, or sanctions duties.28
'The EU banned self-custody.'
The TFR regulates transfers involving CASPs and expressly addresses self-hosted addresses; person-to-person transfers without a provider are outside its scope.86
'Travel-rule data is required only above €1,000.'
The regulation's transfer-information duties are broader. The €1,000 threshold triggers a particular control-verification duty for a customer's self-hosted address.8
'A blockchain-analytics score proves criminal activity.'
Analytics is one risk input. Attribution, customer context, false positives, source reliability, legal standards, and investigation remain necessary.12
'Our old national registration still lets us serve the EU.'
The maximum MiCA grandfathering period ended July 1, 2026, and some national periods ended earlier. Current authorization and service scope must be verified.65
Frequently asked questions
Concise answers to the questions readers most often ask about this topic.
Did the EU ban self-hosted crypto wallets?
No. EU law expressly contemplates transfers to and from self-hosted addresses. When a CASP is involved, it must collect information and apply risk controls; above €1,000, it must verify control when its customer transfers to or from that customer's own address. Person-to-person transfers without a CASP are outside the TFR's scope.8106
Does the EU crypto travel rule apply below €1,000?
Yes, the information requirements for covered CASP transfers are not generally limited to amounts above €1,000. That threshold is tied to an additional ownership-or-control verification when a CASP customer uses their own self-hosted address.8
Is MiCA the EU anti-money-laundering law?
Can an old national VASP registration still be used in 2026?
What information travels with a crypto transfer?
Covered transfers carry prescribed information identifying the originator and beneficiary plus account, address, or transaction identifiers required by the regulation. CASPs validate and securely exchange that information and match it to the on-chain transfer; it need not be published on the public blockchain.810
What happens if travel-rule information is missing?
The receiving or intermediary provider must detect missing or incomplete information and apply documented, risk-based procedures. Depending on the facts, it may request information and decide whether to execute, reject, return, or suspend the transfer and whether further AML escalation is required.810
When does the new EU AML Regulation apply?
Methodology
This edition is dated to August 27, 2026 and prioritizes EUR-Lex legislation, ESMA authorization statements and registers, EBA guidelines, and AMLA's official implementation timeline. It distinguishes entry into force, application, transposition, transitional end dates, and planned future supervision.2861012141516
CryptoDigest first covered European crypto AML changes in 2018, when the Fifth Anti-Money Laundering Directive had a much narrower provider scope. This new guide does not preserve that framework as current law; it uses the historical date only to explain how the rules evolved.1
Limitations
- This guide is general information, not legal advice, and cannot determine the rules for a particular entity, asset, transfer, customer, or Member State.
- EU regulations interact with national competent-authority practice, criminal law, FIU procedures, sanctions, data protection, payments, tax, and other sector rules.
- EBA, ESMA, AMLA, the Commission, courts, and national authorities can issue or revise binding measures, guidance, Q&As, and interpretations after the displayed date.
- The 2027 framework is described as a scheduled future change and should not be applied as though it already replaced the current 2026 rules.
- Technical controls such as blockchain analytics or proof of address control do not by themselves establish compliance or criminal conduct.
Sources and evidence
Claims are linked to the technical documentation, standards, law, research, and enforcement records that support them.
- 1Directive (EU) 2018/843 — Fifth Anti-Money Laundering Directive ↗
EUR-Lex · Historical EU legislation
Supports: 2018 virtual-currency, fiat-exchange, and custodian-wallet framework - 2Regulation (EU) 2023/1114 on Markets in Crypto-assets ↗
EUR-Lex · EU regulation
Supports: MiCA scope, issuers, CASPs, conduct, governance, and market rules - 3MiCA Article 149: application dates ↗
European Securities and Markets Authority · Official rulebook
Supports: 30 June and 30 December 2024 application dates - 4MiCA Title V: CASP authorization and operating conditions ↗
EUR-Lex · EU regulation
Supports: CASP services, authorization, legal presence, and regulated-entity route - 5MiCA Article 143: transitional measures ↗
European Securities and Markets Authority · Official rulebook
Supports: Grandfathering, shorter national periods, and July 1, 2026 maximum - 6Statement on the End of Transitional Periods under MiCA ↗
European Securities and Markets Authority · Supervisory statement
Supports: Post-July 2026 authorization, wind-down, group entities, and consumer checks - 7MiCA registers and implementation page ↗
European Securities and Markets Authority · Official register
Supports: Authorized CASPs, issuers, white papers, and non-compliant entities - 8Regulation (EU) 2023/1113 on information accompanying transfers ↗
EUR-Lex · EU regulation
Supports: Crypto travel rule, scope, data, self-hosted addresses, and AMLD amendments - 9Information accompanying transfers of funds and certain crypto-assets ↗
EUR-Lex · Official legal summary
Supports: Purpose, application date, traceability, and self-hosted transfers - 10EBA travel-rule guidance ↗
European Banking Authority · Regulatory guidance
Supports: Missing information, CASP procedures, traceability, and self-hosted controls - 11Final EBA Travel Rule Guidelines ↗
European Banking Authority · Regulatory guidelines
Supports: Proof-of-control methods, self-hosted risk assessment, and implementation detail - 12EBA ML/TF risk-factor guidance for CASPs ↗
European Banking Authority · Regulatory guidance
Supports: Risk factors, mitigating measures, blockchain analytics, and 2024 application - 13Directive (EU) 2015/849 consolidated AML/CFT framework ↗
EUR-Lex · EU directive
Supports: CDD, ongoing monitoring, reporting, records, controls, and supervision - 14Regulation (EU) 2024/1624 — AML Regulation ↗
EUR-Lex · Future-applying EU regulation
Supports: Harmonized rulebook and July 10, 2027 general application date - 15Directive (EU) 2024/1640 — AMLD6 ↗
EUR-Lex · EU directive
Supports: National mechanisms, transposition, and 2027 replacement of Directive 2015/849 - 16AMLA frequently asked questions and implementation timeline ↗
EU Anti-Money Laundering Authority · Authority guidance
Supports: AMLA functions, 2027 selection, and direct supervision from 2028
Cite this resource
Stable edition 2026.08.27
Version history
- 2026.08.27
Full editorial rebuild with claim-level citations, current primary sources, tables, and reader FAQs.
- 2026.08.26
Initial source-backed guide edition published.
- Earlier coverage
CryptoDigest previously covered this topic; the original article text is unavailable.