Marius Raetz
Counsel/Head of Fintech Germany

Marius advises commercial and investment banks and other financial institutions (including FinTechs/neobrokers) on financial regulatory law, including on major M&A transactions, licensing procedures, relocation and restructuring, litigation and engaging with financial regulators. Marius has experience advising across a wide range of products and business lines, including payment solutions, wealth management and private banking, retail and prime brokerage, custody business and links to market infrastructure.

 

German and EU Fintech Regulation 2025–2026: Key regulatory developments

The German and European fintech landscape is undergoing one of the most demanding regulatory transformations since the introduction of MiFID and PSD2. With MiCA, a landmark framework is reshaping compliance obligations, market access, and competitive dynamics in the market for crypto assets. And the provisions of DORA, the EU’s comprehensive digital operational resilience act, became applicable in 2025, following a two-year implementation period.

Changing regulatory requirements meet a rebounding global fintech industry, with the still unbroken appetite for investments into AI and the continued dynamic in the markets for crypto-assets and tokenisation – fueled by the recent boom in stablecoins – providing core drivers. Despite a challenging 2024, Germany’s fintech market remains Europe’s second-largest market with relatively high adoption rates of fintech services and a recent recovery in venture capital investments.

While EU initiatives aim to simplify and further harmonize the regulatory framework as part of the reforms under the Savings and Investments Union, relatively high regulatory complexity remains a persistent challenge. There is, however, an argument to make that the regulators’ openness to fully engage with new regulatory frameworks underpinning the growth drivers neo-banking and -brokerage, digital lending, embedded finance and AI-powered solutions has increased predictability and contributed to a fairly well-developed discourse, supporting a positive outlook for Germany as the largest Fintech hub in the EU.

I.MiCA: Germany continues to lead on crypto-asset licenses in the EU

On 30 December 2024, Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA) became fully applicable across the EU, representing the first EU legislation that introduces a comprehensive regulatory framework for crypto-assets, covering issues from issuance of crypto-assets, through provision of services in crypto-assets to preventing market abuse in crypto-asset markets. Since then, more than 50 MiCA authorisations have been granted to crypto-asset service providers (CASPs) and stablecoin issuers across the EU. Germany and the Netherlands have emerged as the leading jurisdictions for the issuance of MiCA licenses, with Germany leading in front and accounting for more than a third of all licenses issued, confirming its role as the major EU hub for crypto regulation.

One driver for an overall encouraging MiCA uptake is the rapidly expanding stablecoin market, not least because of its onramp function by serving as the cash leg in cryptocurrency transactions. The market remains overwhelmingly dominated by USD-backed stablecoins accounting for 99% of the global market capitalization in all stablecoins (which, in turn, is dominated by Tether (USDT) and USD Coin by Circle (USDC), not least buttressed by issuers having become noticeable participants in the US Treasury market through investments into T-bills as backing or reserve assets). Nevertheless, EUR pegged stablecoins have started to emerge, with Circle’s EURC leading in terms of market capitalization. Overall, MiCA has seen a healthy uptake with 23 stablecoins (e-money tokens) issued across 14 entities in the EU.

That said, regulatory compliance remains a focus point of regulatory attention in the nascent crypto-asset market:

Early in 2025, ESMA issued a public statement expecting CASPs operating a trading platform for crypto-assets to stop making available for trading all assets qualifying as ARTs and EMTs without the issuer’s authorisation (“non-MiCA compliant ARTs and EMTs”). In response, large CASPs have delisted non-MiCA compliant stablecoins, though their continued use nevertheless remains under scrutiny by EU regulators.

More recently, multi-issuer stablecoins have garnered regulatory attention. These describe arrangements, where identical, interchangeable stablecoins are issued by firms that form part of the same group, but where only part of the issuance is issued as an EMT under MiCA by an EU-established firm, while another part of the issuance is issued by a third-country entity. Reserve assets held in the EU may, in principle, also be used to redeem tokens issued by the third-country issuers (where the relevant token holder would direct his request for redemption against the EU issuer rather than the third-country issuer), the prudential regime. MiCA does not explicitly address multi-issuer schemes. However, the perceived risks have led the European Systemic Risk Board (ESRB), a Union-level body mandated with macro-prudential oversight of the financial system within the Union and consisting of representatives of EU regulators, to recently recommend that the European Commission does not consider third-country multi-issuer stablecoin schemes as permitted under MiCA or, alternatively, subject such stablecoins to a dedicated framework (noting that a respective Q&A posed by the French regulator ACPR to the Commission has not yet been answered).

2025 also saw the question of a potential “dual authorization” requirement for transactions involving stablecoins/EMTs under MiCA receiving a much-awaited response from the EBA. EMTs are ‘deemed to be electronic money’ (Article 48(2) MiCA) and are considered ‘funds’ for the purposes of PSD2. This means that a single CASP activity involving EMTs may fall within both regulatory regimes, potentially subjecting CASPs to requirements and authorisations under PSD2 and MiCA. The EBA advised that the transfer of EMTs on behalf of clients, as well as the custody and administration of EMTs where custodial wallets allow the transfer of EMTs to/from third parties constitute payment services and, consequently, custodial wallets holding EMTs that can be transferred to/from third parties are also regarded as payment accounts under

PSD2. Recognising the administrative burden of requiring dual authorisation, the EBA recommended in its June 2025 no-action letter that, during a transition period up to 2 March 2026, national competent authorities (‘NCAs’) shall not require authorisation under PSD2 for payment services involving EMTs and also not prioritise enforcement of certain obligations under PSD2. As a long-term solution, the EBA is clear that the overlap of multiple regimes (particularly multiple authorisation requirements) for the same activity is undesirable, such that, either, MiCA would be amended to include PSD-requirements, or PSD3/PSR would specify which requirements apply to CASPs in relation to EMTs.

Bigger changes may lie ahead as part of the Commission’s proposal under the Savings and Investments Union. Following the unusual step of ESMA to publish a peer review looking at the authorisation of CASPs in Malta under MiCA and the approach taken by the Malta Financial Services Authority (MFSA) in the authorisation and early supervision of a CASP in which ESMA found that some issues were not fully resolved when CASP authorizations were granted and that some risk areas where not adequately assessed during the licensing process. The legislation is widely expected to include a proposal to transfer direct oversight over most or, perhaps, all significant CASPs in the EU to ESMA.

II.Use of AI: Sector guidance still rules as use cases evolve

After the initial hype surrounding generative AI, the financial sector now shows more realism and pragmatism. Companies are testing capabilities and limitations, with widespread use more modest than expected, also due to the key role of investments required for a larger-scale rollout in the necessary infrastructure (technology, governance, and data).

Agentic AI may prove essential for the widespread AI adoption in business processes by complementing the generative AI content creation with autonomous task execution. We expect the use of agentic AI to multiply the number of AI-supported work processes by 2026, bringing the regulatory framework into sharper focus than ever before.

Many jurisdictions, including EU and Germany, have not pursued legislation that specifically governs the use of AI in financial services. Rather, the financial services industry must navigate AI use within the existing sector-specific general regulatory framework. This means fintechs and financial service providers operate in a familiar regulatory environment, but one that is interpreted in an AI-specific manner by the supervisory authorities and, therefore, remains dynamic. Key issues emerging for regulatory risk management are the same globally: accountability (“Who is in charge?”), data transparency, and explainability (“How do you explain outcomes?”).

With the use of AI models transitioning from pilot to practice, failures in AI governance become increasingly difficult to justify. A dedicated AI governance framework helps companies to promote the responsible use of AI within their own organizations, identify and proactively manage risks, and ensure that AI is used in a manner that is appropriate and commensurate with the risks.

III. Digital Money: Off to the races?

The payment sector is undergoing a profound transformation – and it is not just stablecoins. Traditional payment rails are being complemented, and in some cases challenged, by new forms of digital money.

In 2025, banks and payment service providers implemented the Instant Payments Regulation (IPR), a reform of the SEPA Regulation designed to make real-time euro transfers the standard across the Single Euro Payments Area (SEPA). From 9 January, payment service providers in the eurozone were required to receive instant payments, and by 9 October, they must also enable sending capabilities, including a newly established mandatory verification of payee mechanism.

At the same time, the debate on alternatives to stablecoins increasingly focuses on two emerging forms of digital money: Central Bank Digital Currencies (CBDCs) and tokenized deposits:

  • In the EU, interest in CBDCs has intensified, driven by ECB concerns over monetary sovereignty and financial stability should USD-denominated stablecoins gain dominance, and by its advocacy for the Digital Euro as a countermeasure. In October 2025, the ECB’s Governing Council decided that the Eurosystem will move to the next phase, following a two-year preparation period. However, it has also reaffirmed its earlier stance that a final decision on whether to issue a digital euro will only be taken once the accompanying EU legislation has been adopted. Insofar, the proposed roadmap – relying on the assumption that European co-legislators will adopt the Regulation on the establishment of the digital euro in 2026 – foreseeing a pilot exercise and initial transactions as of mid-2027 and a potential first issuance during 2029 may well prove too optimistic in light of the state of the legislative process. The recently published draft report by the rapporteur for the EP on the Digital Euro, responding to a proposal by the Commission published in 2023, outlines a significantly scaled-back version compared to the ECB’s vision, focusing on only pursuing the “offline” version for the time being while ostensibly sharing industry criticism that the need for an online version has not yet been convincingly established in light of progress in the private sector towards a pan-European payment system.
  • Tokenised deposits are an option presented by the private sector that blends innovation with legal certainty. Tokenised deposits are digital representations of traditional bank deposits issued on a blockchain or DLT. They maintain the legal and regulatory characteristics of regular deposits, meaning they are liabilities of a commercial bank and typically covered by deposit protection schemes, but gain additional functionality through tokenisation. Germany has emerged as a frontrunner in tokenised deposit innovation, e.g. through the Commercial Bank Money Token (CBMT) initiative, and the EBA has contributed to legal certainty by its Report on Tokenised Deposits, confirming that recording a deposit balance on a Distributed Ledger Technology (DLT) does not per se change the fundamental nature of the claim (the deposit) but only the ledger technology for recording such claim, and that the acceptance of tokenised deposits from the public therefore remains regulated in the traditional sphere of banking activities under the CRD/CRR.

Ultimately, different digital money models may coexist, forming a diversified digital money ecosystem supporting a range of applications, from retail transactions using digital cash equivalents, to on-chain liquidity for tokenised or crypto assets, to programmable, digitalised deposits operating within conventional ledgers for institutional use cases.

IV.Tokenisation and Digital Infrastructure

Tokenisation has become a central pillar of Europe’s digital finance agenda, with Germany playing a leading role through initiatives in the fields of tokenised deposits as well as industry pilots for digital securities. Across the EU, the DLT Pilot Regime – introduced in March 2023 as a regulatory sandbox for trading and settlement of tokenised financial instruments – was intended to accelerate innovation in market infrastructure. However, uptake has been modest, with only a handful of authorisations and limited trading activity.

ESMA’s 2025 review of the DLT Pilot Regime identified key shortcomings, including restrictive thresholds on eligible assets, lack of interoperability with traditional systems, and operational bottlenecks such as the absence of trusted mechanisms for cash settlements (in particular in the form of limited access to central bank money). In response, EU legislation as part of the Savings and Investments Union is under way to increase the flexibility of the framework and extend its scope and scale with proposals expected early December. The legislation can be expected to remove the restrictions on eligible assets, significantly raise the activity thresholds that have made it difficult to scale activities under the DLT Pilot, broaden the scope of eligible entities (potentially to also include CASPs) and facilitate the easier use of commercial bank money and EMTs for settlement of DLT transactions (among other changes).

V.DORA: A snapshot

Going from aspirations to current practice, 2025 was also the year of DORA and DORA implementation.

In its most general form, DORA requires in-scope organisations to comply with common rules and standards for the management of information and communication technology (ICT) risk, which relates broadly to risks arising in relation to the use of network and information systems. Key pillars of DORA are:

  • ICT risk management (including cybersecurity governance and asset inventory)
  • third-party ICT risk management (vendors must undergo due diligence and extensive contracting obligations apply)
  • reporting of major ICT-related incidents
  • testing of digital operational resilience (including penetration testing, in some cases).

Third-party ICT risk management requirements present particular challenges for fintech companies. Organisations in scope of DORA are required to ensure their contracts with ICT service providers include a large set of contractual provisions with additional contractual requirements applied to ICT service providers that support a “critical or important” function of the relevant financial entity. BaFin has provided substantive guidance, including the issuance of a Supervisory Notice on the implementation of DORA in ICT risk management and ICT third-party risk management (also including a table summarizing the minimum contractual clauses to be included in in-scope agreements). In addition, BaFin has published guidance on the broader documentation requirements for financial entities according to DORA, focusing on the necessary policies and procedures.

In light of the fact that DORA became applicable to in-scope entities from 17 January 2025, this year will also be the first year where DORA implementation will be a subject of regular audit reports (in addition to any regulatory audits), with results in 2026 allowing for a more robust assessment of the state of implementation in the wider industry and any gaps to remedy. Finally, DORA may also prove to be impactful beyond its original scope of digital resilience: Taking inspiration from DORA and with the specific aim to align the frameworks for ICT- and non-ICT-related third-party risk, the EBA has issued draft guidelines on the sound management of third-party risk in July 2025, updating the EBA Guidelines on outsourcing arrangements issued in 2019 which, so far, have set the standard for outsourcing management, proposing to apply large parts of the fairly detailed DORA framework for the management of ICT third-party risks also to the management of non-ICT related third-party risks.