Andrzej Wieckowski
Partner

Andrzej has a broad experience of financial services regulation – from asset/wealth management, banking to digital assets and fintechs. He has worked on large cross border transactions and worked on setting up banks and financial institutions in the UK and EU. Andrzej supported industry bodies, regulators and governments on developing existing regulation and policy. He frequently advises clients on responding to regulatory change and navigating the regulatory perimeter to maximise their commercial goals.

Aligned with technological advancements, Andrzej is advising firms on the new UK cryptoasset regime – including on thought leadership, strategy, regulatory perimeter, authorisation and compliance with the new rules as they apply to digital assets and cryptoassets in the UK. He is working actively with industry groups to help shape the new regime and improve regulatory guidance available to market participants.

Meghan Millward
Associate

Meghan Millward is a financial services regulatory lawyer specialising in cryptoassets, payments, and financial crime. She has spent several years advising banks, fintechs, and digital asset businesses on navigating the evolving UK and international regulatory landscape. Her experience spans the full lifecycle of crypto projects, from token launch structuring and financial promotions compliance to designing and implementing regulatory frameworks across multiple jurisdictions.

Meghan works at the intersection of crypto and payments, advising on innovative products. More recently, she has focused on cryptoasset authorisation planning under the UK’s FSMA regime, helping firms prepare for transition and meet regulatory expectations. She is actively engaged in industry groups and contributes to thought leadership on emerging regulatory trends in cryptoassets.

Regulating the Future: The UK’s Evolving Cryptoasset Regime

Cryptoasset regulation is coming to the UK with full force in 2027 – we explore what that means, what the path to regulation looks like and who is best placed to make the most of the new regime.

Path to regulation

Until now, UK crypto regulation resembled a building project with very visible scaffolding and very little construction behind it. The FCA held the front entrance, policing financial promotions and running AML registration – most firms just got on with it outside this perimeter, using UK intermediaries for marketing to UK customers where necessary.

That has now changed, not with a single dramatic announcement, but with something more reliable: plumbing. In February 2026, HM Treasury made the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 (Cryptoasset Regulations), the foundational instrument that brings cryptoasset activities inside FSMA, the same legal architecture that governs banks, investment managers, and payment institutions. Then, in April 2026, Treasury published a draft amending statutory instrument (SI) and policy note that recalibrated parts of the regime before it had even fully commenced. This is what active regulatory construction looks like.

For banks, investment firms, payment service providers (PSPs), exchanges, custodians, and financial market infrastructure firms, the regime that is emerging carries a striking feature: it is not designed for the crypto-native market. It is based on bricks and mortar and designed for institutions that already know how to be regulated.

The existing perimeter

Before turning to where the regime is going, it is worth understanding where it already is, because the current framework is more substantive than it is sometimes given credit for.

The FCA’s most visible intervention has been in financial promotions. Since October 2023, cryptoasset communications to UK consumers have been subject to a dedicated regime, with risk warnings, cooling-off periods for first-time investors, and a clear, fair, and not misleading standard that mirrors what applies to investment products more broadly. The FCA has shown it is prepared to enforce this seriously. In early 2026, it began legal proceedings against HTX (formerly Huobi) for allegedly promoting cryptoasset services illegally to UK consumers. The message was pointed: being physically offshore does not insulate a firm from the UK promotions perimeter. For banks and PSPs thinking about distribution arrangements, white-label partnerships, or customer-facing on/off ramp journeys, that should already be shaping product design – not just compliance sign-off.

The AML registration gateway tells a similar story about supervisory intent. Since becoming cryptoasset AML supervisor in January 2020, the FCA has notably had an alarmingly low pass rate for AML applications for cryptoasset service providers. For institutions conducting counterparty due diligence, this matters: “FCA registered” in the crypto context means passing an AML gatekeeping exercise, not FSMA authorisation. The two are not the same thing, and the gap between them is precisely what the new regime is designed to close.

The Travel Rule, which since September 2023 has required UK cryptoasset businesses to collect, verify, and transmit information about cryptoasset transfers, has quietly embedded a more substantive compliance infrastructure than its low-profile introduction suggested. Firms serious about Travel Rule compliance are already building sanctions screening, transaction monitoring, data standards, and correspondent relationship management that will be table stakes under the full FSMA regime. Those that are not will face a steeper hill in 2026 and 2027.

FSMA regime: a significant uplift from AML registration

The Cryptoassets Regulations are built around a simple but significant idea: cryptoasset activities should be regulated on the same basis as other financial services activities, not through a bespoke crypto licence, but through Part 4A FSMA permissions.

Beyond the authorisation requirement (and its related on-going compliance requirements), the Cryptoasset Regulations establish two substantive legal frameworks. The first is a disclosure and liability regime for public offers and admissions to trading of qualifying cryptoassets, bringing cryptoasset capital markets activity into something recognisably close to the prospectus framework that applies to traditional securities, including liability for misleading statements and investor withdrawal rights. The second is a market abuse framework: prohibitions on insider dealing, unlawful disclosure, and market manipulation, with systems and controls obligations and FCA investigatory and enforcement powers. For any compliance team that has spent time working on UK or EU MAR, the concepts will feel familiar. The practical challenge is that crypto market structure (fragmented, pseudonymous, virtual and cross-border) makes surveillance genuinely much more difficult to build than in equities or fixed income. Firms that develop that capability early will be ahead of those that wait for further guidance that may not arrive.

The difference from the current UK AML registration regime is not one of degree; it is one of kind. AML registration asks whether a firm’s financial crime controls are sufficient that it will not become a conduit for criminal activity. FSMA authorisation asks whether the firm’s governance, customer outcomes framework, conduct standards, market integrity controls, and operational resilience are fit for sustained regulatory supervision – through growth, stress, and the full cycle of a regulated firm’s life. That is the standard banks and investment firms already must meet for their existing businesses. For crypto-native firms, it is a substantially higher bar.

Timings

Here FCA has been unusually precise. Pre-application meetings via the PASS service will open in July 2026, though firms were able to apply from 11 May 2026. The application window is expected to run from 30 September 2026 to 28 February 2027, with full commencement on 25 October 2027.

HM Treasury’s letter of 29 May 2026 confirmed the FCA intends to finalise its rules by mid-2026 – a large chunk of which was published on 30 June. That timetable sounds comfortable until you consider what FSMA authorisation readiness actually requires. It is not a form-filling exercise; it is a demonstration that operating models, governance, controls, customer journeys, and risk frameworks will support a business fit for regulatory scrutiny. For firms starting from scratch on any of those dimensions, fifteen months is a short runway.

At an international level, it has always been clear that the UK is not trying to win a speed contest. The EU’s MiCA framework delivered earlier certainty and EU-wide passporting. The US GENIUS Act, signed into law in July 2025, has given USD stablecoin issuers a federal framework that will accelerate dollar-denominated stablecoin adoption globally. Other jurisdictions have moved faster in specific respects. The UK’s wager is different: that absorbing crypto into FSMA produces something those alternatives do not quite deliver – a digital assets market operating inside the full accountability framework of a G7 financial centre. Whether that bet pays off depends heavily on whether firms of real scale – the banks, custodians, and market infrastructure providers – choose to build within it.

The design principles for the new regime try to strike a balance between the desire for the UK to be seen as open to cryptoasset businesses and the consumer protections that the regulators are there to police. Parliament has not provided additional cover to the regulators to lessen the latter in order to achieve the former.

The stablecoin question

The draft amending SI discussed above identified and addressed a structural problem with the Cryptoasset Regulations. The problem is specific. As the Regulations were originally drafted, a firm providing stablecoin payment services, routing value from A to B using a GBP-denominated stablecoin, risked being captured within the regulatory perimeter for “dealing in” or “arranging deals in” qualifying cryptoassets. In practice, that would mean a payments firm needing the same category of authorisation as a crypto trading platform. Treasury’s conclusion, stated plainly in the policy note, was that this was not the right outcome and needed to be resolved before the regime went live.

The draft amending SI introduces a concept of “relevant qualifying stablecoin transactions” and carves certain activities (dealing as principal, dealing as agent, and arranging deals) out of the regulated activities perimeter for those transactions. Critically, the carve-out is not for stablecoins generally. It applies to a “relevant qualifying stablecoin”, defined as one issued by a firm with Part 4A permission for the regulated activity of issuing qualifying stablecoins. In other words: an authorised, UK-issued stablecoin.

The policy dimension is deliberate. By tying the carve-out to UK-issued, FCA-authorised stablecoins, Treasury is making it structurally easier to build payment services around a domestically authorised stablecoin than around an imported one. This is not a ban on foreign stablecoins, nor a restriction on consumer access. But it is a meaningful regulatory preference expressed through perimeter design, and in a market where dollar-denominated stablecoins already represent the majority of the global stablecoin supply, the geopolitical driver for creating that preference now is not hard to follow. As a result, exchanges, investment firms and other intermediaries looking to offer non-UK issued stablecoins to UK consumers will face a significantly larger regulatory burden than their UK counterparts.

Treasury acknowledged the trade-offs. Removing payment-focused stablecoin activity from the dealing/arranging perimeter creates interim consumer risk. The compensating control is the requirement for cryptoasset safeguarding permissions, which firms holding stablecoin assets on behalf of customers will still need. The draft SI also tightens the “temporary settlement” exclusion from safeguarding, rewriting it so it applies only where settlement is ancillary to dealing or arranging, not to stablecoin payment flows.

Equally significant, though less discussed, is the draft SI’s early commencement of provisions that carve out stablecoin backing assets from the collective investment scheme and alternative investment fund frameworks, ahead of October 2027. Without this change, the reserves held to back an authorised stablecoin could inadvertently be characterised as a fund. Resolving this early matters enormously to any bank or custodian thinking about providing reserve asset custody services for a stablecoin issuer, and it signals that Treasury is thinking seriously about making the commercial ecosystem around stablecoin issuance workable, not just the issuance activity itself.

The consultation period on the draft SI closed on 22 May 2026. As of early July 2026, the instrument has not yet been made. Firms should plan on this architecture arriving, while recognising that the final mechanics have not yet settled into law.

The incumbent advantage

There is a version of the UK digital assets landscape in which the winners are crypto-native firms that navigate the FSMA gateway successfully: the exchanges, niche custodians, and specialist intermediaries that have been operating in this market for years. That version exists. But for traditional financial institutions, it is not the most interesting version of the story.

The more compelling case is that the UK’s FSMA-shaped regime has created a genuine structural advantage for regulated incumbents, provided they recognise it and move on it before the window narrows.

Custody is the most obvious starting point. The Cryptoasset Regulations make cryptoasset safeguarding a regulated activity. As the crypto market matures, “who holds your assets, under what regulatory framework, and what happens if they fail?” becomes a live question for institutional counterparties and clients. This was a key lesson from the FTX saga as well as the US bank failures and the demise of Credit Suisse in 2023. Banks and established custodians already answer that question for equities, bonds, and alternative assets. The control environment they bring (segregation, independent key management, incident response, third-party risk frameworks, regulatory audit trails) is exactly what the FCA will be looking for in authorised digital asset custodians. It is not something a crypto-native firm with a few years of operating history can easily replicate. And Treasury’s early commencement of the backing asset carve-out means that reserve custody for stablecoin issuers is a service banks can now begin structuring without the risk of inadvertently triggering fund regulation. There is also a commercially significant opportunity for banks to serve as custodians of the fiat-denominated reserve assets that back qualifying stablecoins – something within existing banking capabilities and that will become increasingly central to the institutional credibility of any UK-authorised stablecoin issuance.

For PSPs and banks with payments infrastructure, the UK qualifying stablecoin carve-out creates a commercial lane that rewards authorised, UK-established entities. A firm that secures Part 4A permission for stablecoin issuance, or that works alongside a firm that has, can provide stablecoin payment services without being treated as a crypto dealer. For firms that prefer not to be issuers, the intermediary model is a credible alternative: providing on/off ramps, GBP conversion, compliance infrastructure, and distribution for an authorised stablecoin, occupying a significant position in the payment chain without taking on issuer risk or the direct regulatory overhead of issuance.

The FCA has already run a stablecoins sandbox cohort and publicly identified firms testing issuance use cases in a controlled environment, signalling that early engagement with the new regime is the path the regulator is trying to encourage. Firms that have had those conversations are better placed to shape the rules than those who arrive at the gateway in late 2026 with a cold application.

The broader strategic point is this: every activity in scope under the new regime (issuance, dealing, custody, intermediation, staking, lending, operating a platform) will need to map to a permission, a governance structure, a set of conduct obligations, and a supervisory relationship with the FCA. That is an environment that should feel familiar to any institution already operating under FSMA, but not to currently unregulated market participants. The compliance overhead for an incumbent adding digital assets permissions to an existing regulatory relationship is meaningful, but it is significantly lower than building that relationship from scratch.

The invitation

The UK’s digital assets regulatory regime is not finished and is unlikely to be complete on 25 October 2027. The experience of the April 2026 draft amending SI, identifying and addressing a structural drafting problem before it became a live commercial failure, shows that Treasury, the PRA and the FCA are actively tuning the perimeter and will continue to do so. This is further reinforced by the pivot on applying the new CASS rules for cryptoassets to tokenised versions of existing financial instruments – which the FCA is no longer proposing and is seeking industry feedback on what rules to apply to safeguarding tokenised securities.

For legal and compliance teams at banks and PSPs, the immediate task isn’t simply to achieve full FSMA readiness this calendar year. It is to understand which of your firm’s activities, products, and client journeys fall within the new perimeter, and to begin building (in governance, controls, and operating model) the foundations that a credible authorisation application will require. New entrants face a bigger challenge.

The deeper point is simpler than the legislation makes it look. The UK has built a digital assets regime that is demanding, deliberate, and constructed in the image of the broader financial services framework that traditional institutions already inhabit. That is not a coincidence. It is an invitation, and it will not stay open indefinitely.