For several years, the digital-asset industry treated regulatory progress as a question of perimeter: which stablecoins, issuers, exchanges and wallet providers would be brought inside a licensing regime? That question is now largely settled across the leading financial centres. The more consequential issue is whether regulated firms can demonstrate that their controls work continuously, across products, blockchains and borders.
Recent developments in the United Kingdom, United States, European Union and Australia point in the same direction. Regulators are moving beyond high-level commitments and defining the operational evidence they expect from stablecoin issuers and virtual asset service providers.
Stablecoin Regulation Becomes Balance-Sheet Regulation
On 22 June, the Bank of England published its policy statement and draft Code of Practice for sterling-denominated systemic stablecoins. The proposed model would allow as much as 70% of reserve assets to be held in short-term UK government debt, with the remainder deposited at the central bank. Each systemic stablecoin would initially face a £40 billion issuance guardrail rather than individual user holding limits. Subject to consultation, the Bank intends to finalise the code by the end of 2026, allowing regulated systemic stablecoins to operate from 2027.
The significance extends beyond those numbers. Stablecoin supervision is becoming recognisably prudential: reserve liquidity, redemption capacity, concentration, operational resilience and confidence under stress are being treated as parts of one system. An issuer may have adequate assets on paper yet remain vulnerable if it cannot liquidate them promptly, reconcile circulating supply or process redemptions during market disruption.
The strategic lesson is straightforward. Stablecoin operators need an integrated control architecture connecting treasury data, token issuance and burning, custody records, customer liabilities and stress-testing results. Periodic reserve attestations alone will not establish operational resilience.
KYC Moves Closer to the Point of Issuance
In the United States, FinCEN and four federal banking agencies proposed customer-identification requirements for permitted payment stablecoin issuers under the GENIUS Act. The proposal would place these issuers within the Bank Secrecy Act framework and require effective customer identification programs comparable to those maintained by banks and credit unions.
This development sharpens a difficult design question: who is the customer in a token capable of circulating through secondary markets and self-hosted wallets?
A credible answer cannot rely on onboarding alone. Issuers and intermediaries will need to distinguish direct customers, distribution partners, custodial users and external wallet holders. They must then define what information is collected at each relationship boundary, when enhanced due diligence is triggered and how identity findings affect transaction monitoring.
The strongest KYC systems will therefore be event-driven. Material changes in wallet behaviour, geography, ownership, sanctions exposure or source-of-funds indicators should prompt reassessment instead of waiting for a fixed review date.
VASP Transition Deadlines Are Becoming Enforcement Boundaries
The EU's MiCA transition reached its decisive point on 1 July. In a 23 June statement, ESMA instructed unauthorised crypto-asset service providers to stop taking new EU clients, cease marketing and restrict activity to what is necessary for an orderly exit. It also made clear that customer due diligence, sanctions screening, transaction monitoring, suspicious-activity reporting and record retention must continue throughout the wind-down process.
This matters for counterparties as much as for firms seeking authorisation. Banks, payment companies and licensed CASPs should not assume that a provider's historical VASP registration remains sufficient. Counterparty due diligence must verify current authorisation, permitted services, geographic scope and any restrictions or wind-down status.
Australia reached a parallel operational milestone on 1 July, when its revised AML/CTF obligations — including Travel Rule requirements for virtual-asset transfers — began applying to relevant services. AUSTRAC has explicitly told firms to prepare their systems, policies, training and recordkeeping for the change.
Travel Rule compliance is therefore becoming an infrastructure requirement rather than a policy statement. Firms need reliable counterparty identification, secure exchange of originator and beneficiary data, transaction-level linkage to blockchain records, exception handling for incomplete information and auditable decisions concerning self-hosted wallets.
Risk Evaluation Must Become Continuous
FATF's 2026 work on stablecoins and unhosted wallets reinforces the same principle. Its targeted report highlights the illicit-finance exposure created by scalable stablecoins and peer-to-peer transfers, while its VA/VASP risk-assessment guidance says assessments should directly inform the frequency and focus of supervision.
For industry leaders, this means replacing static annual risk assessments with a living model. Product risk, customer risk, geographic exposure, blockchain typology, counterparty quality and control performance should be measured together. Risk scores should change when the evidence changes — and material changes should produce an observable control response.
The Observation That Matters
The next generation of digital-asset leaders will not be distinguished simply by holding the right licence. They will be distinguished by their ability to prove — quickly, accurately and repeatedly — that reserves are sound, customers are understood, transfers are traceable and risk decisions remain defensible as the market evolves.
That requires treating compliance not as a detachable reporting layer, but as an integrated system that connects identity, transaction, counterparty and blockchain signals into decisions that are consistent, explainable and reviewable.
The perimeter question is settled. The evidence question is just beginning.
UWAY provides compliance infrastructure for FinTech, Web3, and digital asset businesses across Hong Kong, Singapore, and the EU.
