AMLA MiCA Review Response: Five AML/CFT Gaps It Asks the EC to Review
On 7 October 2026 the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) published its response to the European Commission’s targeted consultation on the review of Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA). The AMLA MiCA review paper is dated 30 September 2026, the day the consultation closed, and reads MiCA from an anti-money laundering and countering the financing of terrorism (AML/CFT) angle. It asks the Commission to look again at five areas: staking, lending and borrowing; DeFi arrangements; unauthorised stablecoins; issuers of asset-referenced tokens (ARTs) that are not obliged entities; and the passport regime for crypto-asset service providers (CASPs).
Nothing in the paper changes a CASP’s obligations today. Member States had to apply the amendments that Regulation (EU) 2023/1113 (the transfer of funds Regulation, TFR) made to Directive (EU) 2015/849, which list CASPs as financial institutions, from 30 December 2024, and Regulation (EU) 2024/1624 (the AMLR) applies from 10 July 2027. AMLA’s asks reach the rulebook only if an amending act takes them up, for example a legislative proposal accompanying the report that Article 140(1) MiCA requires “where appropriate”, once the co-legislators adopt it.
What the paper offers a compliance team is a map of where the EU’s AML authority thinks MiCA leaves money laundering and terrorist financing (ML/TF) risk uncovered. Two of its themes, unauthorised stablecoins and CASP access to DeFi, line up with the EBA and ESMA responses filed in the last week of the consultation. Two others come from AMLA’s own remit: the ART issuer that is not itself an obliged entity under the AMLR, and the passport notification that does not tell a host supervisor how a CASP actually operates in its territory.
Related reading: MiCA Review: The EBA’s Priorities for Token Issuers and CASPs
AMLA MiCA review: the dates that frame it
The response sits between dates already fixed in Level 1 texts and the review’s own milestones:
- 30 December 2024: the TFR applies, and Member States apply its amendments to Directive (EU) 2015/849, including the extension of the Article 45(9) central contact point option to CASPs.
- 17 January 2025: the Commission’s answer in ESMA Q&A 2404 and ESMA’s public statement on non-MiCA-compliant ARTs and e-money tokens (EMTs) are published.
- 20 May 2026: the Commission opens its targeted consultation on the MiCA review.
- 1 July 2026: the outer limit of the Article 143(3) MiCA transitional period for CASPs that provided services under national law before 30 December 2024 (Member States could disapply or shorten it).
- 10 July 2026: the deadline in Article 41(2) of Directive (EU) 2024/1640 (AMLD6) for AMLA’s draft regulatory technical standards (RTS) on central contact points.
- 24 September 2026: the EBA’s response to the consultation.
- 30 September 2026: ESMA’s response and the date on AMLA’s paper; the consultation closes at 23:59 CEST.
- 7 October 2026: AMLA publishes its response.
- 30 June 2027: the Commission’s Article 140(1) report is due.
- 1 July 2027: the date by which AMLA must commence its first selection of directly supervised entities under Article 13(4) of Regulation (EU) 2024/1620.
- 10 July 2027: the AMLR applies, and the general AMLD6 transposition deadline in Article 78(1) falls.
The last three dates are set in Level 1 text. None of them depends on the outcome of the MiCA review.
What AMLA sent, and how firmly it is worded
AMLA’s paper is organised around AML/CFT issues that, it says, cut across several parts of the consultation, so the Commission’s numbered questions get no individual answers. Each of the five sections closes with a recommendation addressed to the Commission. Most are phrased as “should consider” or “consideration could also be given”; the firmest are the DeFi ask that the legal framework “should define” a DeFi arrangement, the stablecoin ask that the Commission “should ensure” consistent treatment, and the ART-issuer ask that the Commission “should review” the interaction between MiCA and the AML/CFT framework. No sentence is addressed to supervised firms, and the paper sets no supervisory expectation. It is neither a guideline nor a draft technical standard.
The press release compresses that modality. Its staking bullet says AMLA suggests the Commission “consider bringing these activities within the regulatory framework”. The paper itself asks the Commission to consider whether dedicated regulatory requirements “would be appropriate”, and adds that such requirements could sit inside the existing CASP framework. The paper’s wording is the one to quote in an internal impact note.
AMLA’s formal position in the review is narrower than its profile might suggest. Article 140(1) MiCA names two authorities the Commission must consult before it reports: the EBA and ESMA. AMLA, established by Regulation (EU) 2024/1620, is not named there, and its paper is a response to the targeted consultation. The Commission’s consultation page states that responses feed the reports required under Articles 140 and 142 MiCA, which “may, if warranted, be accompanied by a new legislative proposal”.
Staking, lending and borrowing: beyond the custody hook in Article 75
Article 3(1), point (16), MiCA lists ten crypto-asset services, points (a) to (j). Lending, borrowing and staking are not among them. AMLA’s paper starts from that gap. Staking can fall within MiCA indirectly, through the authorisation for custody and administration of crypto-assets on behalf of clients, but that route covers the custody element only. In AMLA’s account it misses the risks specific to asset pooling, yield generation, temporary transfers of control and limited client access to assets during staking periods. The same concern applies where CASPs give clients access to DeFi lending, borrowing or staking arrangements.
AMLA names three ML/TF risks. The current framework could give CASPs a structural incentive to route transactions through unregulated lending wrappers. Customers, transactions and funds can be linked to high-risk jurisdictions or to jurisdictions with deficient AML/CFT frameworks. And, in AMLA’s words, there is no obligation on customers to disclose their true identity and no or limited monitoring of activity, risks it attributes to the EBA and ESMA.
The recommendation asks the Commission to consider whether dedicated requirements for staking, lending and borrowing would be appropriate, given their specific risk profile, instead of relying solely on the ancillary coverage that the custody provisions of Article 75 provide. AMLA adds two refinements. Such requirements could be built into the existing CASP framework, where appropriate. And additional management requirements could apply to CASPs acting as gatekeepers when they give customers access to DeFi services, a point AMLA credits to the EBA’s answer to question 67 of the consultation.
The paper stops short of three things a reader might expect from it: it names no new crypto-asset service, sets no customer due diligence measure for staking, and gives no timing. The EBA-ESMA joint report it cites as recognising the gap, EBA/Rep/2025/01 of January 2025 prepared under Article 142 MiCA, describes itself as analytical and sets out no policy recommendations.
My reading for a CASP running a staking or lending product today: its AML/CFT file is built around the client relationship and the transfers it executes, both already within national AML law and the TFR. AMLA’s concern is the leg beyond the CASP, where client assets go into a pool, a lending wrapper or a protocol after they leave custody. That leg is where the paper places the unregulated wrappers and the limited monitoring.
DeFi arrangements: what “effective control” would turn on
MiCA’s scope language on decentralisation sits in Recital 22. The Regulation applies to services performed, provided or controlled, directly or indirectly, by natural and legal persons, including where part of the activity is performed in a decentralised manner, while services provided in a fully decentralised manner without any intermediary fall outside it. Outside the review clauses in Articles 140 and 142, MiCA’s articles do not mention decentralisation at all.
AMLA’s diagnosis is about evidence. An arrangement that claims to be decentralised may rely heavily on the self-assessment of the persons concerned, which makes it hard for supervisors to see whether someone performs, provides or exercises effective control over crypto-asset services carried out through it. The paper gives two examples of where control can arise: a concentration of governance tokens, and the ability to pause or modify smart contracts. Where control goes unidentified, activities that would otherwise be subject to MiCA and AML/CFT requirements may remain outside both. Without clear criteria, supervisors may also reach different conclusions on whether the same arrangement is genuinely decentralised.
The recommendation has two limbs. First, the legal framework should define “DeFi arrangement” and set common criteria for deciding whether a person performs, provides or exercises effective control through it, so that supervisors consistently identify arrangements that are not genuinely decentralised and therefore fall within MiCA and AML/CFT obligations. Second, where a person exercises significant influence over key functionalities, or holds a significant concentration of governance power, without itself providing a crypto-asset service, consideration could be given to requiring CASPs that give access to the arrangement to apply appropriate risk-mitigation measures. AMLA does not list what those measures would be.
ESMA’s response of 30 September 2026 covers adjacent ground from a market angle. It asks for a DeFi definition in the legal text, with the exemption “as narrow as possible”, warns of “decentralisation washing”, and proposes a new regulated service for CASPs that give clients access to DeFi, with duties covering risk disclosure, transparency on protocol selection and routing, conflicts of interest, due diligence on the protocols offered and operational safeguards. AMLA’s second limb points at the same intermediary for an AML/CFT purpose.
FATF’s approach to control over DeFi arrangements is covered in our FATF DeFi report explainer; AMLA’s paper does not cite FATF on this point. For CASPs that route clients to protocols, AMLA’s two examples of where control can arise are recordable facts: who can pause or modify the contracts, and how concentrated governance-token holdings are. The paper proposes no duty to record them.
Unauthorised stablecoins: AMLA backs the EBA and ESMA line
The legal anchor is short. Under Articles 16(1) and 48(1) MiCA, an ART or EMT may be offered to the public or admitted to trading in the Union only by an issuer that meets MiCA’s authorisation conditions, or by another person with that issuer’s written consent, subject to the exemptions those Articles allow. The Commission’s answer to ESMA Q&A 2404, published on 17 January 2025, applied that to CASPs: an operator listing such a token on its trading platform is seeking admission to trading, and exchange, reception and transmission or execution services may amount to an offer where the provider promotes or advertises the token, assessed case by case.
ESMA’s public statement of the same day expected trading platforms to stop making non-compliant ARTs and EMTs available, and the other three services to cease where they amount to an offer, with restrictions completed by the end of January 2025 and “sell only” service allowed until the end of Q1 2025. It added that “mere custody and transfer of these crypto-assets should remain possible”, and that neither ESMA nor national competent authorities have any formal power to disapply a directly applicable EU legal text.
AMLA’s paper supports the EBA and ESMA positions and adds the AML/CFT evidence. It cites the FATF’s 2026 targeted report on stablecoins and unhosted wallets, which in AMLA’s summary identifies stablecoins as a common component of money laundering, terrorist financing and proliferation financing, particularly where transactions involve unhosted wallets or no AML/CFT-obliged intermediary; our FATF on Stablecoins and Unhosted Wallets article covers that report. AMLA also points to the US Treasury’s action of 4 December 2024 against the TGR Group, a network the Treasury said served Russian elites who sought to use US dollar-backed stablecoins to evade sanctions, and to illicit-finance typologies reported by the International Consortium of Investigative Journalists.
The recommendation asks the Commission to ensure that the treatment of non-MiCA-authorised ARTs and EMTs is clarified and applied consistently across the EEA, “including where such tokens continue to circulate or are intermediated by CASPs”, and to consider legislative measures that remove legal uncertainty about how MiCA applies to services involving non-authorised stablecoins.
One sentence in the paper needs care. AMLA’s summary of current law states that, under Articles 16(1) and 48(1), CASP services involving non-compliant ARTs or EMTs “also constitute an offer to the public or admission to trading”. That is wider than the texts it relies on. The Commission’s Q&A ties the result to listing on a trading platform and, for other services, to a case-by-case test, and ESMA’s statement left custody and transfer open. Until MiCA is amended, those two January 2025 texts remain the reference points for what a CASP may do with such tokens.
ESMA’s own response goes further than AMLA’s. It asks for an express provision that a CASP cannot provide “any licensable service” under MiCA in relation to non-compliant ARTs or EMTs, which it calls a “binary supervisory test”. Custody and administration, and transfer services, are both crypto-asset services under Article 3(1), point (16)(a) and (j). AMLA’s phrase about tokens that “continue to circulate or are intermediated by CASPs” covers the same residual activity from the AML/CFT side, without specifying the rule.
ART issuers outside the AMLR’s list of obliged entities
Article 16(1) MiCA allows two kinds of ART issuer: a legal person or other undertaking established in the Union and authorised under Article 21, or a credit institution that complies with Article 17. Article 3 AMLR lists the obliged entities, starting with credit institutions and financial institutions, and the AMLR’s definition of financial institution includes CASPs (Article 2(1), point (6)(i)). The AMLR does not name ART issuers, and the term “asset-referenced token” does not appear in its text. AMLA’s paper says that an ART issuer authorised with an ad hoc licence, as opposed to a credit institution, is classified as an obliged entity only if it also provides services in relation to its ARTs, that is, if it obtains a CASP licence.
The consequence AMLA draws is specific. A pure-play ART issuer, with no other obliged entity placing the token, is not directly subject to AML/CFT requirements, so customer due diligence (CDD) is not performed when a token is issued or redeemed. Two MiCA provisions make that path workable. Article 16(1) lets the issuer offer the ART to the public itself, and Article 39(1) gives holders a right of redemption at all times against the issuer. AMLA also notes that several jurisdictions have extended, or are considering extending, AML/CFT obligations to ART issuers in line with FATF recommendations. The paper does not name them.
The recommendation is staged. The Commission should first review the interaction between MiCA and the AML/CFT framework, assessing the roles of CASPs, custodians and credit institutions across issuance, distribution and redemption, and whether CDD and transaction monitoring are applied at each stage. On that basis it should consider whether the AMLR should be amended to include ART issuers that are not otherwise obliged entities and that issue or redeem directly without another obliged entity applying AML/CFT measures, or whether equivalent AML/CFT requirements should apply to them.
AMLA’s ART-issuer section does not discuss e-money token issuers, and the ART point has no direct counterpart for them. Article 48(1)(a) MiCA requires an EMT issuer to be authorised as a credit institution or an electronic money institution, subject to the exemptions in Article 48(4) and (5) for issuers exempted under Article 9(1) of Directive 2009/110/EC and for e-money tokens exempt under Article 1(4) and (5) of that Directive. Credit institutions are obliged entities in their own right, and the AMLR’s definition of financial institution covers undertakings carrying out the activities in points (2) to (12), (14) and (15) of Annex I to Directive 2013/36/EU, where point (15) is issuing electronic money. The press release’s reference to “certain” ART issuers is precise for the same reason: an ART issuer that is a credit institution sits inside the perimeter already.
For CASPs the point lands at distribution. Under the second subparagraph of Article 16(1), other persons may offer or seek admission to trading of an ART with the issuer’s written consent, and must then comply with Articles 27, 29 and 40. A CASP doing so is an obliged entity and applies CDD to its own clients. The issuance and redemption legs between holder and issuer are what AMLA’s staged review would test.
CASP passports: what an Article 65 notification leaves out
Article 65(1) MiCA requires a CASP that intends to provide services in more than one Member State to give its home competent authority four pieces of information: the list of Member States, the crypto-asset services it intends to provide cross-border, the starting date, and a list of its other activities not covered by MiCA. The home authority passes that information within 10 working days to the single points of contact of the host Member States, to ESMA and to the EBA, and informs the CASP of that communication without delay. The CASP may start from the date it receives the home authority’s notice or, at the latest, from the 15th calendar day after submitting the information.
None of the four items says whether the CASP will serve a host Member State through an establishment or under the freedom to provide services (FPS), or whether it will rely on infrastructure located there. AMLA reports feedback from competent authorities that, as a result, the nature of cross-border activity cannot always be reliably ascertained.
The AML/CFT rules turn on exactly that distinction. Article 45(9) of Directive (EU) 2015/849, as amended by the TFR, lets Member States require e-money issuers, payment service providers and CASPs established on their territory in forms other than a branch, with their head office in another Member State, to appoint a central contact point (CCP). Under AMLD6, Article 38(1) makes host supervisors responsible for activities carried out in their territory under FPS through agents, distributors or other types of infrastructure, with CASPs named in point (c), and Article 38(2) moves that supervision to the home supervisor only where the RTS criteria under Article 41(2) are not met and the host supervisor notifies the home supervisor. Article 38(5) disapplies the Article when AMLA acts as supervisor. Article 41(1) lets Member States require a CCP from CASPs operating establishments other than a subsidiary or branch, or operating under FPS through agents, distributors or other infrastructure.
AMLA’s recommendation is that the Commission consider adding information requirements at Level 1 so that competent authorities can distinguish establishment-based from FPS-based business models and, for FPS, see whether the services rely on infrastructure in the host Member State, for the effective exercise of their powers under Article 38 AMLD6. The paper links the gap to the CCP regime directly: that regime presupposes reliable information on the presence and operations of foreign providers in a host Member State.
AMLA’s own CCP workstream shows the sequencing. Its survey launched on 6 August 2026 as preparatory work for the Article 41(2) RTS was addressed to electronic money institutions and payment service providers, and left CASPs out because, in AMLA’s words, the previous CCP framework did not apply to them. Our AMLA central contact point survey article covers that exercise.
AMLA’s founding Regulation uses the same distinction for a different purpose. For the periodic assessment that feeds selection for direct supervision, Article 12(1) of Regulation (EU) 2024/1620 counts the Member States in which an entity operates “whether through establishments or under the freedom to provide services”, regardless of whether the activities use infrastructure in the territory or are carried out remotely. Under Article 12(7), however, the minimum activities an entity must carry out under FPS for it to be considered as operating in a Member State other than its home state are to be specified in regulatory technical standards that AMLA drafts and the Commission adopts, so a CASP’s six-Member-State count can depend on whether it serves a host state through an establishment or under FPS.
Three further observations: multi-issuance, account registers, good repute
Third-country multi-issuance stablecoin arrangements, where identical and fully fungible tokens circulate globally, raise an AML/CFT concern for AMLA about ultimate redemption, given limited visibility on a token’s transaction history and the origin of funds. Should such arrangements be permitted, AMLA suggests measures on transparency, cooperation and information exchange across jurisdictions, in line with the ESRB’s recommendations. ESRB Recommendation ESRB/2025/9, published on 20 October 2025, recommends that the Commission not consider third-country multi-issuer schemes as permitted under the current MiCA framework. If the Commission does not clarify this, the ESRB urges authorities to mitigate the risks through appropriate safeguards, including enhanced supervisory measures, closer international cooperation and necessary legal reforms.
The second observation concerns AMLD6. Article 16 requires Member States to run centralised automated mechanisms that identify the persons holding or controlling payment, bank, securities and crypto-asset accounts held by a credit or financial institution, and Article 16(3)(f) makes searchable, for crypto-asset accounts, the unique identifier of the account and its opening and closing dates. AMLA asks for clarification on whether that unique identifier will enable identification of the relevant wallet address or addresses, which it describes as the information blockchain analytics tools need. Article 16 is not among the provisions with an earlier or later deadline in Article 78(1), so it falls under the general transposition date. For a CASP’s account data model, which identifier ends up in the national register is an open question.
The third supports the EBA’s answer to the final open question of the consultation. The EBA recommends amending Article 18(5)(a) and (c) MiCA, which governs the information in an ART authorisation application, to remove limits on the scope of the good repute assessment, arguing that good repute is a horizontal concept. AMLA agrees with the EBA that MiCA’s Level 1 mandates are not fully aligned with other sectoral law, for example on authorisations and the assessment of qualifying holdings, which may limit the information that can be taken into account in assessing good repute, including from an ML/TF perspective, and asks the Commission to consider aligning them.
AMLA, the EBA and ESMA on the overlapping topics
On four topics the three responses can be compared directly. The cells summarise each paper’s ask; none of it is law.
| Topic | AMLA (30 Sep 2026) | EBA (24 Sep 2026) | ESMA (30 Sep 2026) |
|---|---|---|---|
| Unauthorised ARTs and EMTs | Consistent EEA treatment, including tokens still circulating or intermediated by CASPs; consider legislative measures | CASPs could be barred from intermediating or giving access to lending and borrowing involving them (Q67) | Express rule: no licensable CASP service for non-compliant ARTs or EMTs |
| DeFi | Define “DeFi arrangement”; common effective-control criteria; possible risk-mitigation duty for CASPs giving access | Cost-benefit analysis of requirements for CASPs giving clients access to DeFi lending protocols (Q67) | Definition in the legal text with a narrow exemption; new regulated service for CASPs giving access |
| Staking | Consider dedicated requirements beyond Article 75 custody coverage | No staking-specific proposal; answers Q67 on lending and borrowing | Targeted conduct, disclosure and safeguarding rules for CASP staking; no heavy authorisation regime |
| Lending and borrowing | Same dedicated-requirements question; could sit in the existing CASP framework | Cost-benefit analysis of adding intermediation of lending and borrowing to the CASP service list | Lending: rules including client express written consent and disclosure. Borrowing: targeted conduct, disclosure and risk-management requirements |
The open design question is the vehicle. The EBA asks the Commission to weigh a new CASP service for lending intermediation, ESMA says its lending proposal is “not to create a newly regulated service requiring authorisation”, and AMLA leaves the choice open. On unauthorised stablecoins the three papers point the same way, with ESMA’s the most specific about the rule.
What a CASP can map before the Commission reports
None of AMLA’s asks requires a policy change today. What a CASP can do is assemble the facts each proposal would test, so that a legislative proposal, if one follows the Article 140 report, lands on an inventory that already exists. A CASP that wants that evidence base could record:
- Staking, lending and borrowing products: for each, whether it relies on the custody and administration authorisation, where client assets go once they leave custody, and who the counterparty or protocol is.
- DeFi access points: the protocols clients reach through the CASP’s interface, with the control facts AMLA names for each.
- Tokens that may meet the ART or EMT definition without an authorised issuer: which are still held in custody or moved for clients, tested against the Q&A 2404 criteria.
- ART distribution: any ART the CASP offers with an issuer’s written consent, and whether the CASP is the only obliged entity between the issuer and the holder.
- Host Member States: for each Article 65 notification, whether services run through an establishment or under FPS, and any agents, distributors or other infrastructure located there.
- Crypto-asset account identifiers: what the CASP would supply as the “unique identifier of the account” for the AMLD6 Article 16 registers, and how that maps to wallet addresses.
The host Member State record has value before any MiCA change. Article 45(9) of Directive (EU) 2015/849 already turns on the form of a CASP’s presence in a host state, and Articles 38 and 41 AMLD6 follow on the AMLD6 timetable, not on the review’s. For the wider package those provisions belong to, see our EU AML package guide.
Frequently Asked Questions
Does AMLA’s ART-issuer point cover an issuer exempt from authorisation under Article 16(2) MiCA?
Article 16(2) disapplies the authorisation requirement where, over 12 months, the average outstanding value of the ART never exceeds EUR 5 000 000 and the issuer is not linked to a network of other exempt issuers, or where the offer is addressed solely to qualified investors and the ART can only be held by them. AMLA’s paper describes ART issuers as either credit institutions or issuers authorised with an ad hoc licence and does not address exempt issuers. The AMLR does not name ART issuers of either kind, authorised or exempt, as obliged entities.
Would AMLA’s passport proposal require CASPs to refile Article 65 notifications already made?
AMLA asks the Commission only to consider additional information requirements at Level 1. Transition, supplementation of existing notifications and any template are left open, and would depend on the drafting of an amending act.
Can AMLA supervise a CASP directly without any MiCA amendment?
Yes, through its own Regulation. CASPs are financial institutions, and Article 12(4)(j) of Regulation (EU) 2024/1620 lists them as a separate category for the risk-classification methodology used in the periodic assessment, which covers entities operating in at least six Member States including the home Member State. Selection depends on a high residual risk profile, the first selection must commence by 1 July 2027, and direct supervision starts six months after the list is published. Where AMLA supervises, Article 38 AMLD6 does not apply (Article 38(5)).
Does the response propose changes to the TFR or the travel rule?
AMLA’s asks are directed at MiCA, at the AMLR for ART issuers and, through a request for clarification, at the crypto-asset account identifier in Article 16 AMLD6. The TFR appears in the paper only as the Regulation that amended Article 45(9) of Directive (EU) 2015/849 to bring CASPs into the central contact point option.
Is a CASP still allowed to hold a non-authorised EMT in custody for an existing client?
The January 2025 ESMA statement expected mere custody and transfer of such tokens to remain possible, while the Commission’s Q&A focuses on services that amount to an offer or a seeking of admission to trading. ESMA’s 30 September 2026 response describes uncertainty about how far authorised CASPs may continue to support such tokens and asks for an express ban covering any licensable service. AMLA asks for clarity on tokens that continue to circulate or are intermediated by CASPs. Until legislation changes, the January 2025 texts are the reference, read with any guidance from the CASP’s own competent authority.
Would AMLA’s DeFi proposal make a CASP responsible for a protocol’s AML/CFT compliance?
AMLA’s proposal is narrower. Where a person has significant influence or governance power over an arrangement without providing a crypto-asset service, CASPs that give access could be required to apply appropriate risk-mitigation measures. The paper specifies neither the measures nor any liability for the protocol itself.
Related Articles
- MiCA Review: The EBA’s Priorities for Token Issuers and CASPs: the EBA’s 24 September 2026 response, including its Q67 lending and DeFi recommendations.
- ESMA MiCA Review Response: What CASPs and Token Issuers Should Map: ESMA’s asks on classification, the DeFi gateway service, unauthorised stablecoins and CASP capital.
- EC MiCAR Review Consultation: the structure and scope of the Commission’s targeted consultation that AMLA responded to.
- FATF on Stablecoins and Unhosted Wallets: the FATF report AMLA cites on stablecoin misuse and peer-to-peer transfers.
- AMLA Central Contact Point Survey for PSPs and EMIs: AMLA’s preparatory work for the AMLD6 Article 41(2) central contact point RTS.
Key Takeaways
- None of AMLA’s five asks has legal effect unless an amending act takes it up; the AMLR’s start date does not wait for the review.
- AMLA identifies a gap for ART issuers that are not otherwise obliged entities and that issue or redeem tokens directly without another obliged entity involved; credit institutions that issue ARTs are already obliged entities, and the paper does not address whether EMT issuers are obliged entities.
- For services involving non-authorised ARTs or EMTs, Articles 16(1) and 48(1) MiCA govern, and Q&A 2404 and ESMA’s 17 January 2025 statement remain the reference points for reading them until MiCA is amended.
- MiCA’s articles hold no DeFi definition; AMLA gives governance-token concentration and the ability to pause or modify smart contracts as examples of where effective control can arise, and asks for common criteria to be set.
- An Article 65 notification has four statutory items, and establishment versus FPS, the fact Article 38 AMLD6 host supervision depends on, is not one of them.
- AMLA’s direct-supervision assessment counts a host state served under FPS only where the minimum activities to be specified under Article 12(7) of Regulation (EU) 2024/1620 are met, so establishment versus FPS can matter for the six-Member-State test as well.
Sources and References
- AMLA, “AMLA identifies AML/CFT priorities for the review of MiCA”, 7 October 2026: amla.europa.eu
- AMLA, “AMLA’s Response to the EC’s Targeted Consultation on the Review of Regulation on the Markets in Crypto-Assets (MICA)”, 30 September 2026: AMLA response (PDF)
- Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA), Recital 22 and Articles 3, 16, 18, 39, 48, 65, 75, 140, 142 and 143: EUR-Lex
- Regulation (EU) 2024/1624 (AMLR), Articles 2, 3 and 90: EUR-Lex
- Directive (EU) 2024/1640 (AMLD6), Articles 16, 38, 41 and 78: EUR-Lex
- Regulation (EU) 2024/1620 establishing AMLA, Articles 12 and 13: EUR-Lex
- Regulation (EU) 2023/1113 (TFR), Articles 38 and 40: EUR-Lex
- Directive (EU) 2015/849, Article 45(9): EUR-Lex
- Directive 2013/36/EU, Annex I: EUR-Lex
- European Commission, targeted consultation on the review of the MiCA Regulation: finance.ec.europa.eu
- ESMA Q&A 2404 (answer provided by the European Commission), 17 January 2025: esma.europa.eu
- ESMA, Public Statement on the provision of certain crypto-asset services in relation to non-MiCA compliant ARTs and EMTs, ESMA75-223375936-6099, 17 January 2025: ESMA statement (PDF)
- EBA, statement on the application of MiCAR to ARTs and EMTs, 5 July 2024: EBA statement (PDF)
- EBA, response to the EC targeted consultation on the review of MiCA, 24 September 2026: EBA response (PDF)
- ESMA, response to the EC consultation on the MiCA Regulation review, ESMA75-113276571-1721, 30 September 2026: ESMA response (PDF)
- EBA and ESMA, Joint Report on recent developments in crypto-assets (Article 142 MiCAR), EBA/Rep/2025/01: Joint report (PDF)
- ESRB, press release on Recommendation ESRB/2025/9 on third-country multi-issuer stablecoin schemes, 20 October 2025: esrb.europa.eu
- FATF, Targeted Report on Stablecoins and Unhosted Wallets: Peer-to-Peer Transactions: fatf-gafi.org
- US Department of the Treasury, “Treasury Exposes Money Laundering Network Using Digital Assets to Evade Sanctions”, 4 December 2024: home.treasury.gov
- AMLA, “AMLA launches survey on Central Contact Points”, 6 August 2026: amla.europa.eu
Before the Commission’s Article 140 report
AMLA’s paper is now part of the record the Commission draws on for its MiCA report. Host-state supervision under Article 38 AMLD6 and the crypto-asset account registers under Article 16 AMLD6 run on the AMLD6 transposition timetable whatever the review concludes. The staking, DeFi, stablecoin and ART-issuer asks depend on what the Commission puts in the report it prepares under Articles 140 and 142 MiCA and on any amending act that follows. The host Member State record serves both tracks, and it can be compiled, like the DeFi access list, from data a CASP already holds before the report falls due on 30 June 2027.
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.
