Global

BCBS discusses regulatory and supervisory initiatives

The Basel Committee on Banking Supervision (BCBS) met in Indonesia on 28 and 29 September 2026, to discuss a range of analytical, supervisory and regulatory initiatives, including:

  • Digitalisation: The BCBS agreed to review the sufficiency and adequacy of existing ‘event type’ loss categories set out in the operational risk framework, with a focus on cyber risk and AI developments; it will continue to monitor AI developments. It approved a final standard to provide for an innovative and efficient channel of bank disclosures.
  • Cryptoassets: The BCBS is reviewing targeted elements of its prudential standard for banks’ exposures to cryptoassets and expects to provide an update by the end of 2026. [1 Oct 2026]  #Digitalisation #Crypto #AI #DigitalAsset

UK

FCA gateway opens for crypto authorisation applications

The FCA has announced that the gateway for crypto firms to apply for authorisation formally opened on 30 September 2026. Cryptoasset firms that intend to continue operating in the UK should apply by 28 February 2027, ahead of the new regime coming into force on 25 October 2027.

The FCA has a dedicated page which provides an overview of the new cryptoassets regime policy statements. [30 Sep 2026]   #Crypto #DigitalAsset

FCA: Non-Handbook Guidance on COREPRU 7 and CRYPTOPRU 7

The FCA has published non-Handbook guidance to the Core Prudential Sourcebook (COREPRU) and the Prudential Sourcebook for CRYPTOPRU Firms (CRYPTOPRU).

Finalised Guidance 26/9 (FG26/9) and FG26/10 are intended to help firms complete the overall risk assessment required under COREPRU 7 or, for cryptoasset firms, the assessment under CRYPTOPRU 7. The guidance explains how firms should identify risks, run stress tests, plan recovery actions and prepare for wind-down.

This non-Handbook guidance comes into force 25 October 2027. [30 Sep 2026] #Crypto #DigitalAsset

BoE Governor on frontier AI and the question of governance

The BoE has published an Insights article, Frontier AI and the question of governance, written by Governor Andrew Bailey. Mr Bailey argues that before turning to questions of regulatory approach, policymakers must first establish precisely what problem they are seeking to solve. He identifies the novel defining feature of frontier AI as its capacity for recursive self-improvement; there is a feedback loop in which systems increasingly draw on their own outputs to refine their performance. This risks becoming self-referential.

Although acknowledging that there are challenges posed by frontier AI, the Governor says that this should not imply there is a need to prohibit the technology which promises potential benefits that are immense.  

He argues for the need to retain the ability to intervene and set the boundaries within which these systems operate. Rather than beginning with a formal regulatory framework, he advocates for rigorous model testing as the appropriate starting point, and expresses support for the work of the UK's AI Security Institute, calling for its pace to accelerate. [30 Sep 2026]   #AI

FRC consults on CASS assurance standards – payments and e-money firms

The FRC has launched a consultation on a new appendix to its Client Assets Sourcebook (CASS) Assurance Standard: Safeguarding Assurance for Payment and E-Money Institutions to support the implementation of the FCA’s safeguarding regime.

In its PS25/12: Changes to the safeguarding regime for payments and e-money firms, the FCA introduced a new safeguarding audit requirement for certain payment services and e-money institutions. In response, the FRC has developed a new Appendix to the CASS Assurance Standard to provide a framework for practitioners undertaking those safeguarding assurance engagements. This Appendix will replace the FRC’s Interim Guidance on Payment and E-money Safeguarding Assurance Engagements issued in March 2026.

Responses are requested by 26 November 2026. The FRC will host a roundtable for stakeholders on 3 November 2026. [30 Sep 2026]  #Payments #e-Money

FCA Smart Data Accelerator-commissioned research: Open finance infrastructure

The FCA has published a note: Powering open finance infrastructure, which summarises research commissioned by the FCA's Smart Data Accelerator to examine three possible approaches to building the infrastructure to scale from open banking to a future proof open finance ecosystem: a fully centralised model, a fully decentralised model, and a hybrid of the two. Drawing on evidence from other jurisdictions, the research compares the models’ trade-offs, and considers whether their identity, permission, monitoring, and revocation arrangements could support AI-enabled services acting on behalf of consumers or firms.

The research concludes that a combination of approaches provides a credible proposition for further testing in the UK context. This could mean centrally coordinating the functions where consistency matters most, such as accreditation and trust, while giving firms and sectors flexibility over how they build and deliver services.

A further phase of work will test the reference architecture through practical use cases, including participant verification, permission journeys, trust metadata, monitoring, revocation, and interoperability.

This paper is provided for general information only. The FCA does not guarantee the accuracy, completeness, or reliability of this paper. The FCA accepts no responsibility for any errors or omissions in this paper, any loss or damage arising from reliance on this paper, or for any action taken based on the information provided. [29 Sep 2026]  #SmartData #OpenFinance

FCA secures money back for victims of crypto fraud

The FCA has announced that victims of a £1.5m crypto investment fraud will recover lost funds after confiscation orders were secured against two individuals. At a hearing at Southwark Crown Court, the individuals were ordered to pay £603,404.28 and £247,997.99.

Between February 2017 and June 2019, they operated a fraudulent investment scheme, cold-calling consumers and persuading them to invest in fake cryptoasset opportunities. At least 65 investors were defrauded and lost £1,541,799. In July 2025, both individuals were sentenced to  imprisonment for their part in the fraud.

The FCA has identified and contacted victims of the fraud and will ensure that funds recovered through the confiscation process are returned. [28 Sep 2026]  #Crypto #DigitalAsset

FSCP responses to BoE’s and HM Treasury’s consultations

The FCA has published the responses from the (FSCP) to the following consultations:

  • The BoE’s Retail Payments Infrastructure Board’s (RPIB) Consultation on the Design of the Future Retail Payments Infrastructure - The Panel supports the National Payments Vision. It concurs with the principles for the core infrastructure and the conceptual architecture that the RPIB has set out and offers no further feedback on possible future payment journeys at this time. The FSCP moves on to comment on the cross-cutting issues set out in the consultation including: interoperability between different forms of money; settlement frequency and liquidity implications; consumer protection, fraud and wider financial crime; and the default safeguards for new and emerging payment journeys. The Panel states that it is vital that these issues are considered on a standalone basis and that consumers are consulted before design choices are finalised.
  • HM Treasury’s Consultation on Modernising Payment Services Regulation – The Panel stresses the importance of ensuring that in opening the path to greater levels of innovation and competition, consumer needs and protections are not put at risk. It notes that consumer trust is foundational to the success of any payments instrument or system, and offers the following guiding principles: accessibility; fairness and affordability; reliability and resilience; safety, security and consumer protection; and transparency. [28 Sep 2026]   #Payments

Europe

ESMA responds to EC consultation on review of MiCAR, recommends changes to make MiCAR clearer, safer and ready for emerging services

The European Securities and Markets Authority (ESMA) has published its response to the European Commission’s (EC’s) consultation on the review of Markets in Cryptoassets Regulation (MiCAR). ESMA’s recommendations aim to simplify the framework while improving investor protection and addressing innovative business models, such as decentralised finance (DeFi), staking, lending and borrowing.

On enhancing investor protection, ESMA proposes new safeguards in areas where investors face risks that are not fully covered under the current framework, including: stricter rules for the marketing of cryptoassets (particularly when they are promoted by influencers and third parties); improving cost transparency; and proportionate requirements for staking, lending and borrowing, including through disclosure obligations.

On supervision, ESMA recommends enhancing capacity to detect, block and deactivate fraudulent websites and freeze cryptoassets where market abuse or terrorist financing are suspected. It also notes the need to reinforce supervisory powers to deal with third-country firms which solicit EU investors without being authorised under MiCAR; and to make explicit that regulated crypto firms are prevented from offering services linked to non-compliant stablecoins.

On De-Fi and improving cryptoasset classification, ESMA advocates for clearer criteria for determining which activities can be considered genuinely decentralised. It also recommends creating a new regulated cryptoasset service for firms that provide users with access to DeFi protocols. To reduce uncertainty and support harmonised supervision, ESMA suggests adopting rules on classification, including as regards new products, and enabling ESMA to issue binding opinions on token classification to ensure products are treated consistently.

On simplification, ESMA’s proposals include simplifying cryptoasset white paper notification procedures, reducing duplicative authorisation requirements for some regulated firms, and improving the consistency of prudential requirements.

Lastly, ESMA highlights the need for a framework for tokenised securities and on-chain settlement that can support the development of an integrated European tokenised capital market and facilitate future cross-border activity. [1 Oct 2026] #MiCAR #Crypto #DigitalAsset

ESRB responds to the EC’s targeted consultation on the review of MiCAR

The European Systemic Risk Board (ESRB) has responded to the EC’s targeted consultation on the review of MiCAR, focusing on the multi-issuer model of global stablecoins. The ESRB identified as ‘significant’ risks all items on the list in the consultation: run risk and reserve depletion in the EU; unbalanced reserve distribution across jurisdictions; cross-border reserve transfer restrictions; regulatory arbitrage arising from the fungibility of tokens; supervisory monitoring and data-tracking challenges; and issuer home jurisdiction prudential and/or conduct standards which are not equivalent to those in the EU.

In addition, the ESRB commented on: contagion and liquidity risks; legal uncertainty regarding liability and reserve backing; challenges for effectiveness of key MiCAR safeguards; and resolvability challenges for credit institutions. It does not support allowing multi-issuer model for stablecoins, and recommends that, to prevent divergent approaches within the EU, the EC interpret MiCAR as not permitting such schemes.

Should multi-issuer schemes be permitted to continue, the ESRB called for a dedicated framework comprising nine safeguards, including:

  • a framework for assessing third country equivalence;
  • enhanced cooperation with third countries;
  • addressing barriers to the mobility of reserve assets relating to crossborder run risks;
  • amending the criteria for classification as significant;
  • enhanced prudential requirements;
  • supervisory convergence for cryptoasset service providers (CASPs);
  • assessment of cross-border transaction readiness;
  • competent authorities access to relevant data; and
  • increased transparency through disclosure.

The ESRB also responded to questions on: determining or estimating reserves of e-money tokens (EMTs) and asset-referenced tokens (ARTs) with sufficient accuracy and frequency; un-hosted wallets; redemption rights being explicitly limited to EU holders only; and the location of reserve assets. [1 Oct 2026]  #MiCAR #Crypto #DigitalAsset

ECB President calls for macroprudential approach to AI risks in financial services

European Central Bank (ECB) President Christine Lagarde delivered the welcome address at the tenth annual conference of the ESRB. The ECB President focused her remarks on the systemic implications of AI in finance, identifying three areas for particular supervisory attention: financial-market trading; cyber resilience; and geopolitics. Ms Lagarde noted risks including: correlated AI-driven trading strategies; model misalignment; cyberattacks affecting multiple firms simultaneously; dependence on a small number of frontier-model providers; and interruptions to access to critical AI tools. She called for macroprudential monitoring of AI use in finance, enhanced coordination among supervisory authorities, updated cyber defences and timely sector-wide responses where an AI-related incident could spread across financial institutions. [1 Oct 2026]  #AI

EBA: 2027 Work Programme

The European Banking Authority (EBA) has published its Work Programme outlining the key areas of focus and deliverables for 2027. The EBA will focus on: completing the implementation of the 2024 banking package; preparing for the new payment services framework; supporting crisis management and deposit insurance (CMDI) reforms; strengthening supervisory convergence and stress testing; advancing integrated reporting and data sharing; and continuing work under the Digital Operational Resilience Act (DORA), MiCAR and the European Market Infrastructure Regulation (EMIR). [30 Sep 2026]  #Payments #MiCAR #DORA

ESMA sets out 2027 priorities 

ESMA has published its annual Work Programme for 2027. Guided by ESMA’s multi-annual strategy for 2023–2028, the programme characterised by a shift from preparation to the delivery. Among the technology focus areas, ESMA will work to promote innovation in supervision, including developing its Data Platform and deploying AI-based tools. It will also: strengthen cybersecurity capabilities; advance work on cryptoassets; and examine the impact of AI on financial markets. Additionally, tokenisation will remain as a priority for ESMA. [28 Sep 2026]  #Crypto #DigitalAsset #AI #Cybersecurity

ECB: Call for expressions of interest – digital euro innovation platform activities

The ECB has announced that it is launching a call for expression of interest in digital euro innovation platform activities. Participation in this new wave is open to a broad range of stakeholders. Activity will be organised around two main workstreams:

  • Experimentation: supporting the private sector in developing new practical features and additional services to improve the digital euro user experience for consumers and merchants. Focus areas include: electronic integrated receipts; multi-payer and multi-payee transactions; conditional payments; and app features. Experimentation activities are expected to run from January 2027 to June 2027.
  • Exploration: exploring technological developments that could enhance the digital euro in future releases. Focus areas include AI in payments and public uses of a digital euro. Exploration activities will take place via workshops on-site at the ECB premises in the first half of 2027.

Applications are requested by 9 November 2026.

The ECB notes that the final decision on whether to issue a digital euro will only be taken once the relevant EU legislation has been adopted. [28 Sep 2026]  #DigitalEuro #CBDC #AI #Payments


Hong Kong

SFC shares updates with securities industry on scam prevention and cybersecurity at Brokers' Forum

The SFC has held its Brokers’ Forum themed 'Defend Your Business, Outsmart the Scammers', which was attended by over 600 industry participants (see our previous update).  The forum was aimed at enabling participants to familiarise themselves with the latest supervisory observations and regulatory updates on cybersecurity and anti-scam measures.

The forum featured a panel discussion in which representatives from the SFC, the Commercial Crime Bureau of the Hong Kong Police Force, the Investor and Financial Education Council and the securities industry shared their perspectives on joint actions against financial scams, including emerging scam typologies and approaches to prevention and regulatory focuses.

The forum also included (among others) a presentation by the Cyber Security and Technology Crime Bureau of the Hong Kong Police Force on strengthening cyber resilience and preventing scams in the brokerage sector, as well as a briefing by the SFC on its anti-scam outreach initiatives.  The SFC launched its first anti-scam investor education initiative in a local restaurant on 25 September 2026, bringing practical fraud prevention messages into one of Hong Kong's most familiar everyday settings.  [28 Sep 2026]  #Cybersecurity

HKMA publishes presentation slides used in Deputy Chief Executive's HKIB Annual Banking Conference keynote speech

The HKMA has published the presentation slides used by its Deputy Chief Executive, Mr Arthur Yuen, in his keynote speech at the HKIB Annual Banking Conference.

Mr Yuen discussed the HKMA's regulatory progress in various areas over the past year:

  • Artificial intelligence (AI) – Mr Yuen highlighted the progress with the GenA.I. Sandbox++, and emphasised that Boards and senior management of banks must remain accountable for the outcomes generated using AI.
  • Technology resilience – Topics including operational resilience, AI-driven cyber risk, and preparing for post-quantum transition were discussed.
  • Tokenisation – Mr Yuen covered the supervisory incubator for distributed ledger technology, and the potential interactions between tokenisation and agentic AI.
  • Data excellence – Mr Yuen discussed the tech maturity stock-take, agenda for data excellence (including granular data reporting 3.0), and redefining the business model.  [25 Sep 2026]  #AI #Tokenisation #Cyber

US

CFTC secures $31 million+ court order against defendants in digital assets and precious metals fraud

The CFTC has announced that the U.S. District Court for the Middle District of Florida entered a default judgment against two individuals for their participation in a digital assets and precious metals fraud operated through an unincorporated entity, resolving all remaining claims in the CFTC's action. The court found that the individuals, who were board members of the unincorporated entity and social media moderators, made material misrepresentations concerning expected profits, risk of loss, and historical trading performance. The CFTC also found they had falsely represented that participants' funds would be traded by a proprietary algorithm and could be withdrawn in 180 days with interest.

When they learned of the CFTC's investigation, the individuals attempted to walk back profitability claims and eliminate the scheme's social media presence. The court has ordered the individuals to pay $15,732,455 in restitution and a $15,752,455 civil monetary penalty, and permanently enjoined them from further violations of the Commodity Exchange Act, with permanent registration and trading bans imposed.

Separately, two related consent orders were entered regarding other individuals.  [Sep 30, 2026]  #DigitalAsset

SEC charges multiple entities in online platform investment fraud schemes

The SEC has filed charges against four entities, which it believes may be operated by individuals located overseas, for defrauding hundreds of retail investors, including many in the U.S., through so-called "investment confidence scams" on online platforms.  Two of the entities are alleged to have used online platforms to impersonate investment professionals, issue fictitious AI-generated trading signals, and direct victims to a fake trading platform, misappropriating more than $12.5 million in crypto assets; investors who attempted to withdraw funds were told their accounts were frozen pending fraudulent advance fee payments. The other two entities are alleged to have similarly used online platforms and their own website to market a fraudulent AI trading bot programme, falsely claiming full SEC regulation and misappropriating approximately $2.8 million; investors were also encouraged to recruit others into the scheme.  [Sep 29, 2026]  #AI #Crypto #DigitalAsset

CFTC staff update FAQs on crypto and blockchain technologies for registered entities

CFTC staff from the Market Participants Division, Division of Market Oversight, and Division of Clearing and Risk have published updated FAQs on registrant and registered entity activities relating to cryptoassets and blockchain technologies, addressing two new areas: investments of customer funds in tokenised forms of permitted investments; and the use of blockchain technologies to satisfy CFTC registrant recordkeeping requirements.  [Sep 24, 2026]  #Crypto #DigitalAsset #Tokenisation


Key contacts

Cat Dankos photo

Cat Dankos

Senior Regulatory Consultant, London

Michael Tan photo

Michael Tan

Senior Associate, London

Chris Ninan Jon Ford Cat Dankos Michael Tan