The Crypto Compliance Report Q3 2026
Author:
Andreas Katelari
Senior Compliance Officer
Here’s what you need to know.
In the EU, the MiCA transitional period ended on 1 July 2026, triggering AMLA guidance on the money-laundering risks of customer migration between authorised and unauthorised providers. The Council’s 21st Russia sanctions package extended the crypto platform transaction ban, introduced a third-country restriction tool, and widened ownership and governance restrictions on Russian nationals in EU crypto businesses. AMLA continued technical-standards work under the AML Regulation, and ESMA’s September risk report highlighted roughly USD 1 billion in H1 2026 hack losses and growing links between crypto and traditional finance.
In Switzerland, the revised AMLA and the new beneficial-ownership transparency law (LETA) enter into force on 1 October 2026, alongside FINMA supervisory findings on AML weaknesses, a country-risk communication reflecting June FATF listings, and sanctions notices under the Iran and ISIL/Al-Qaida regimes.
In the US, OFAC issued two further Iran-related digital-asset designations (7 August and 17 September), FinCEN proposed correspondent-banking restrictions on a UAE bank, GENIUS Act implementation proposals advanced, and the CLARITY Act market-structure bill failed a Senate cloture vote on 15 September, leaving its AML provisions at the proposal stage.
In the UK, the FCA’s PS26/18 opened the cryptoasset authorisation gateway (from 30 September 2026) and further joint operations targeted unregistered peer-to-peer trading. Internationally, FATF reported continuing Travel Rule implementation gaps and persistent centralisation risk in DeFi arrangements presented as decentralised. Meanwhile, Australia’s Travel Rule obligations took effect on 1 July.