AMLA ¦ AMLA's Response to the EC's Targeted Consultation on the Review of MiCA

AMLA ¦ AMLA's Response to the EC's Targeted Consultation on the Review of MiCA

AMLA asks the Commission to close the AML/CFT gaps in MiCA

The Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) has submitted its contribution to the European Commission’s targeted consultation on the review of Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA). The paper is dated 30 September 2026 and looks at MiCA only from the anti-money laundering and counter-terrorist financing side. AMLA does not answer the Commission’s questions one by one. It groups its points around five weaknesses: staking, lending and borrowing, decentralised finance (DeFi), stablecoins issued without MiCA authorisation, issuers of asset-referenced tokens (ARTs) that fall outside the AML/CFT perimeter, and the passporting regime for crypto-asset service providers (CASPs). In each of them, criminal proceeds can move through the EU crypto market without meeting an obliged entity that applies customer due diligence (CDD).

Staking, lending and borrowing sit outside MiCA

MiCA does not regulate crypto-asset staking, lending or borrowing as activities in their own right, although all three have become a significant part of the market. Staking reaches the regulation only indirectly, through the authorisation requirement for custody and administration of crypto-assets on behalf of clients under Article 75. That covers safekeeping. It does not cover what makes these products risky: pooling of client assets, yield generation, temporary transfers of control and periods in which clients cannot access their assets. The same applies where a CASP routes its clients into DeFi lending, borrowing or staking protocols.

AMLA, following the EBA and ESMA joint report on recent developments in crypto-asset markets, sees three consequences. CASPs have a structural incentive to push transactions through unregulated lending wrappers. Customers, transactions and funds can be linked to high-risk jurisdictions or to jurisdictions with deficient AML/CFT frameworks. And customers may remain anonymous, because there is no obligation to disclose their true identity and activity is monitored little or not at all.

A lending or staking wrapper suits a money launderer because it breaks the transaction trail: assets go into a pool, earn yield and come back out as apparently legitimate returns, often after passing through protocols where nobody performs CDD. AMLA therefore asks the Commission to consider dedicated requirements for staking, lending and borrowing that reflect their own risk profile. The ancillary coverage through the custody provisions is, in its view, not enough. These requirements could sit within the existing CASP framework. Echoing the EBA, AMLA also suggests additional management requirements for CASPs that act as gatekeepers by giving their customers access to DeFi services.

Bastian Schwind-Wagner
Bastian Schwind-Wagner

"AMLA has read MiCA the way a money launderer would and found the doors: yield products that pool and return assets without any CDD, protocols that call themselves decentralised while someone still holds the keys, and token issuers that can sell and redeem without ever identifying a customer. None of this is new to practitioners, but it is now on record as the view of the authority that will set EU supervisory standards.

I would not wait for the Commission. CASPs should assess staking, lending and DeFi access as separate ML/TF risks, know exactly which stablecoins they touch and who issued them, and be able to show where CDD happens when an ART is issued or redeemed. Banks serving CASPs should ask the same questions in their own due diligence."

DeFi arrangements and the question of effective control

Recital 22 of MiCA excludes crypto-asset services provided in a fully decentralised manner without any intermediary. In practice, the persons behind an arrangement largely decide for themselves whether it qualifies. Supervisors then struggle to establish whether someone nevertheless performs, provides or exercises effective control over the services carried out through the arrangement.

Control can take forms that are easy to overlook: a concentration of governance tokens, or the ability to pause or modify smart contracts. If such control goes unnoticed, activities that should be subject to MiCA and to AML/CFT obligations stay outside both. Without common criteria for measuring decentralisation, national supervisors are also likely to reach different conclusions on the same arrangement, which invites regulatory arbitrage.

AMLA recommends that the legal framework define the term “DeFi arrangement” and set common criteria for determining when a person or entity exercises effective control over crypto-asset services through it. Those criteria should allow supervisors to identify, consistently, arrangements that are not genuinely decentralised and therefore fall within MiCA and the AML/CFT framework. Where a person holds significant influence over key functions or a significant share of governance power without providing a crypto-asset service itself, AMLA suggests that CASPs facilitating access to the arrangement should apply appropriate risk-mitigation measures. That puts the obligation on the regulated firm through which customers reach the protocol, which supervisors can actually reach.

Unauthorised stablecoins remain a laundering tool

Despite the authorisation regimes for ART and e-money token (EMT) issuers in Titles III and IV of MiCA, tokens from issuers that have not obtained, or are not eligible for, MiCA authorisation continue to circulate in EEA markets. Under Articles 16(1) and 48(1) MiCA, a CASP service involving a non-compliant ART or EMT also constitutes an offer to the public or an admission to trading. The Commission clarified this in a Q&A, and ESMA followed with a statement that Member States are expected to apply it.

AMLA supports the clear position of the EBA and ESMA on non-compliant tokens and places it in a financial crime context. The FATF’s 2026 targeted report on stablecoins and unhosted wallets identifies stablecoins as a common component of money laundering, terrorist financing and proliferation financing, particularly where transactions involve unhosted wallets or no obliged intermediary at all. AMLA points to the US Treasury’s 2024 action against the TGR Group, a network that used US dollar-backed stablecoins to launder money and evade sanctions, and to the typologies documented by the ICIJ, from scams and hacks to human trafficking.

The predicate offences behind these cases are familiar ones such as fraud, cybercrime, trafficking and sanctions circumvention. The proceeds are increasingly settled in dollar-pegged tokens, which hold their value and move across borders within minutes, and that makes them a convenient vehicle for layering. AMLA asks the Commission to clarify and enforce the treatment of non-MiCA-authorised ARTs and EMTs consistently across the EEA, including where such tokens continue to circulate or are intermediated by CASPs, and to consider legislative measures that remove the remaining legal uncertainty.

ART issuers outside the AMLR perimeter

Under MiCA, ARTs can be issued either by credit institutions or by issuers holding a specific ART authorisation. A credit institution is an obliged entity. The Anti-Money Laundering Regulation (AMLR), however, does not list ART issuers as such. They only become obliged entities if they also provide services in relation to their tokens and therefore hold a CASP licence.

Article 16(1) MiCA allows an issuer to offer an ART to the public itself, so a pure-play issuer that places its token without involving another obliged entity performs no CDD at issuance. Article 39 gives holders a permanent right of redemption against the issuer, whatever its legal status, so the same gap opens again when the token is converted back into funds. Issuance and redemption are exactly the points where illicit funds enter and leave the token, and both may happen without any customer identification. Several jurisdictions have already extended AML/CFT obligations to ART issuers, or are considering it, in line with the FATF Recommendations.

AMLA asks the Commission to review the interaction between MiCA and the AML/CFT framework and to assess whether the current perimeter captures the risks of ART issuance and redemption. The assessment should map the roles of CASPs, custodians and credit institutions along the token’s life cycle and check whether CDD and transaction monitoring are applied at each stage. On that basis, the Commission should consider amending the AMLR to include ART issuers that issue or redeem tokens directly without another obliged entity, or apply equivalent AML/CFT requirements to them.

Passporting leaves host supervisors without the facts

Crypto-asset activity is cross-border by design, and AML/CFT supervisors need timely and granular information on how CASPs operate across the Union. Under the current MiCA passporting regime, a CASP notifying activities in another Member State does not have to say whether it will serve that market through an establishment or under the freedom to provide services. National competent authorities report that the nature of the cross-border activity therefore cannot always be determined.

This matters for the central contact point regime under Article 45(9) of Directive (EU) 2015/849, as amended by Regulation (EU) 2023/1113. A host Member State can only require a central contact point if it knows which foreign providers are present and how they operate. Without a clear picture of a CASP’s operational footprint, host authorities have difficulty identifying the activities within their remit and using their host-state powers.

AMLA recommends additional information requirements at Level 1, so that competent authorities can distinguish establishment-based from free-provision business models and, for free provision, see whether services rely on infrastructure located in the host Member State. That information is the precondition for exercising the supervisory powers under Article 38 of Directive (EU) 2024/1640.

Multi-issuance stablecoins and wallet attribution

AMLA adds three further observations. Third-country multi-issuance stablecoin arrangements, in which identical and fully fungible tokens are issued inside and outside the EU, raise particular concerns at redemption, because the issuer has limited visibility on a token’s transactional history and the origin of the funds behind it. If such arrangements are permitted, AMLA suggests enhanced transparency, cooperation and information exchange across jurisdictions, in line with the recommendations of the European Systemic Risk Board (ESRB).

AMLA acknowledges that the new AML/CFT package already addresses some concerns. Article 16 of the new AML Directive requires the attribution and identification of crypto-asset accounts, which should help with the broader problem of linking wallet activity to persons. It still needs to be clarified whether the required unique identifier of a crypto-asset account will reveal the relevant wallet addresses. Blockchain analytics tools work on addresses, so an identifier without them would name the account holder but leave the funds untraceable.

Fitness and propriety need the full picture

Finally, AMLA supports the EBA’s observation that MiCA’s Level 1 mandates on authorisation and on the assessment of qualifying holdings are not fully aligned with other sectoral EU legislation. This may limit supervisors’ ability to consider all information relevant to good repute, including ML/TF information about shareholders and managers. AMLA asks the Commission to align the relevant provisions and mandates, so that the fit and proper assessment of a CASP owner is no less thorough than that of a bank shareholder.

What the contribution means for CASPs and their banks

None of these recommendations changes the law today, and the Commission is free to take them up or not. They do, however, show where AMLA, which will directly supervise a selection of the largest cross-border obliged entities and coordinate national supervisors, sees the weaknesses of the crypto framework. Staking and lending products, DeFi access, the handling of unauthorised stablecoins and the treatment of ART issuance and redemption are likely to attract supervisory attention well before any amendment is adopted.

CASPs and the banks that provide them with accounts and services can prepare. A reasonable first step is a risk assessment that covers staking, lending and DeFi access as ML/TF exposures of their own, separate from custody. Exposure to stablecoins from unauthorised issuers should be identified and justified, or removed. Firms that sit at the issuance or redemption point of an ART should be able to show where CDD takes place along the chain. And passporting notifications should describe the actual cross-border footprint, because host supervisors will increasingly ask for it.

The information in this article is of a general nature and is provided for informational purposes only. If you need legal advice for your individual situation, you should seek the advice of a qualified lawyer.
Did you find any mistakes? Would you like to provide feedback? If so, please contact us!
Dive deeper
  • AMLA ¦ AMLA’s Response to the EC’s Targeted Consultation on the Review of MiCA (pdf) ¦ Link
Bastian Schwind-Wagner
Bastian Schwind-Wagner Bastian is a recognized expert in anti-money laundering (AML), countering the financing of terrorism (CFT), compliance, data protection, risk management, and whistleblowing. He has worked for fund management companies for more than 24 years, where he has held senior positions in these areas.