For years, much of the crypto policy debate focused on the asset itself. Regulators asked whether a token was a security, a commodity, a payment instrument or another type of digital asset. That question still matters. But a second regulatory story is now becoming harder to miss.
Regulators are paying more attention to the infrastructure that allows crypto assets to move, trade, settle and remain under control.
That includes crypto custodians, wallet services, trading platforms, stablecoin issuers, payment systems, transaction data, sanctions controls and systems that allow firms to identify customers and counterparties.
This does not mean that tokens are no longer the main regulatory concern. Rather, the regulatory perimeter is becoming wider. Authorities are increasingly looking at the firms and systems that sit around a crypto asset, not only at the asset itself.
Recent developments from the Financial Action Task Force (FATF), the Financial Stability Board (FSB), the UK Financial Conduct Authority (FCA) and the Bank of England show this change clearly. The exact rules differ by jurisdiction, but the direction is similar: access to crypto markets can depend on the controls and infrastructure that support the activity.
The compliance question is changing
The older crypto compliance question was often simple: Is this coin or token allowed?
The newer question is more detailed: Who holds the asset? Who can move it? Who knows the parties to a transaction? What records exist? Where are reserve assets held? What happens if a provider fails? Can the regulator obtain the relevant information?
These questions move attention away from the token alone.
A crypto business can use a lawful asset but still face serious compliance duties because of the service it provides. A custodian, for example, may have duties because it controls client assets. A trading platform may face rules because it provides a market. A stablecoin issuer may face requirements because its product can affect payments and financial stability.
The UK provides a useful example. Under its future cryptoasset regime, the FCA identifies activities such as safeguarding cryptoassets, operating a trading platform, dealing and arranging deals, and arranging cryptoasset staking as activities that may require authorisation. The regime is due to come into force on 25 October 2027, while applications for authorisation open on 30 September 2026.
This is important because the regulatory focus is not limited to the legal status of a coin. The service around that coin can itself bring a firm within the regulatory perimeter.
Custody is now a central issue
Custody sits close to the centre of this shift.
In traditional finance, regulators have long paid attention to who holds client money and securities. Crypto creates a similar issue, but with a different technical structure. Control of a private key can determine who has practical control over an asset.
That creates a set of questions that go beyond the token itself.
A regulator may want to know whether client assets are separate from firm assets, who can approve transfers, how access keys are protected, what controls exist over withdrawals and what happens if the firm becomes insolvent.
The UK’s FCA has placed safeguarding within the future cryptoasset regulatory perimeter. Its final framework covers cryptoasset custodians as well as trading platforms, dealing services and other crypto businesses.
This means that custody can no longer be treated simply as a technical function. For regulated firms, it can become a core legal and operational responsibility.
| Area | Traditional compliance question | Crypto infrastructure question |
|---|---|---|
| Custody | Who holds client assets? | Who controls the private keys? |
| Transactions | Who sent the payment? | Can the firm identify the wallet and counterparty? |
| Records | What transaction record exists? | Can on-chain and customer data be linked? |
| Payments | Who operates the payment service? | Who controls the stablecoin or settlement layer? |
| Risk | Can the firm stop a risky transaction? | Can the system screen and block a wallet or transfer? |
| Failure | What happens if the institution fails? | Can clients recover or transfer crypto assets safely? |
Stablecoins make infrastructure even more important
Stablecoins show why the infrastructure story matters.
A stablecoin may look like a digital token, but its wider system can include reserve assets, redemption rights, custody arrangements, payment functions and technology that supports transfers.
Once a stablecoin becomes widely used for payments, its risks may extend beyond the issuer and its users. This is one reason authorities are paying attention to the full structure around the asset.
The UK has created a framework that reflects this distinction. The FCA will regulate UK-issued qualifying stablecoins. Where a stablecoin becomes widely used in payments and is recognised as systemic by HM Treasury, the Bank of England and FCA will regulate the issuer together.
The Bank of England has also stated that systemic stablecoins can raise financial stability concerns because of their role in payments. Its framework covers matters such as backing assets, capital, reserves, redemption and safeguarding.
The practical result is clear. A stablecoin compliance programme cannot rely only on a review of the token’s code or legal structure. It may also need to address reserves, custody, redemption, operational controls and the payment system around the asset.
The Travel Rule shows the rise of data infrastructure
Perhaps the clearest example of this shift is the FATF Travel Rule.
The Travel Rule requires relevant information about the originator and beneficiary of certain virtual asset transfers to move between covered service providers. This makes compliance partly a data problem.
A firm needs systems that can identify the relevant counterparty, collect the required information, transmit it securely and retain the necessary records.
FATF’s 2026 update shows how far this area has developed. As of its July 2026 report, 83% of surveyed jurisdictions had passed legislation to implement the Travel Rule, compared with 73% in 2025. A further 11 jurisdictions reported that implementation was under way.
FATF also said that jurisdictions representing approximately 97% of the global virtual asset market have materially important VASP activity.
These figures do not mean that the global system is fully harmonised. FATF itself continues to identify gaps in implementation, supervision and enforcement.
That distinction matters. A law can exist on paper while firms still face practical problems with data quality, counterparty identification and cross-border transfers.
The compliance infrastructure therefore becomes part of the regulatory solution.
Wallets are becoming part of the compliance debate
Wallets add another layer.
A hosted wallet may sit under the control of a regulated provider. An unhosted wallet may be controlled directly by an individual or another entity. The compliance risks can differ substantially between the two.
FATF’s July 2026 update specifically identifies unhosted wallets, offshore VASPs, stablecoins and DeFi arrangements as areas that require further attention.
This does not mean that every unhosted wallet is illegal or that every transaction with such a wallet is prohibited. The legal position depends on the relevant jurisdiction, the type of transaction and the applicable rules.
The broader point is that regulators need ways to understand transactions that cross the boundary between regulated firms and external blockchain addresses.
That can create demand for better wallet screening, blockchain analytics, customer verification and transaction monitoring.
Compliance now depends on better systems
This is where technology becomes important.
A crypto firm may have a strong compliance policy on paper but still face problems if its systems cannot apply that policy to real transactions.
Consider a simple transfer. A customer sends crypto to an external address. The firm may need to assess the customer, identify the transaction, screen the destination, check sanctions risks, collect required information and preserve an audit trail.
Each step can involve a different data source.
The blockchain may provide transaction data. The customer system may provide identity data. A blockchain analytics provider may provide risk information. A Travel Rule system may handle counterparty information. Internal systems may hold the firm’s decisions and records.
The legal obligation may therefore sit with the firm, but the practical ability to meet that obligation may depend on several connected systems.
This creates a less visible part of the crypto compliance market.
| Infrastructure area | Main compliance purpose |
|---|---|
| Blockchain analytics | Assess transaction and wallet risk |
| Travel Rule systems | Exchange required transfer information |
| Custody controls | Protect client assets and control access |
| Identity systems | Establish customer and counterparty information |
| Sanctions screening | Identify restricted parties and addresses |
| Transaction monitoring | Detect unusual or potentially suspicious activity |
| Reserve systems | Support stablecoin backing and reporting |
| Audit systems | Preserve evidence of decisions and controls |
| Operational resilience | Support continuity after system failures |
The regulator also needs infrastructure
There is another side to this story.
Regulation is not only about what firms must build. Supervisors also need data and tools that allow them to understand the market.
The FSB’s 2025 thematic review found significant gaps and inconsistencies in the implementation of its global framework for crypto assets and stablecoins. The review covered areas such as crypto service providers, stablecoins, data reporting, risk monitoring and cross-border cooperation.
The FSB said that progress had occurred, but implementation remained incomplete and uneven. It also noted that global stablecoin regulation was less advanced than regulation of many other crypto activities.
This matters because crypto markets do not stop at national borders.
A customer may live in one country, use a platform based in another country, hold assets through a third-party custodian and transact with a wallet whose controller is not immediately known.
A regulator that sees only one part of this chain may not have enough information to assess the full risk.
That makes data sharing and cross-border cooperation a central part of the infrastructure story.
The global picture is still uneven
It would be too broad to say that every regulator is following one common model.
Countries have taken different approaches to crypto assets. Some have built licensing regimes. Some have applied existing financial laws. Some have restricted particular activities. Others have created special rules for stablecoins or crypto service providers.
The FSB’s findings support this more careful view. Its October 2025 review said that jurisdictions had made progress but that important gaps and inconsistencies remained. It also warned that differences between national regimes could create opportunities for regulatory arbitrage.
FATF has made a similar point from an AML/CFT perspective. Its 2026 update says that many jurisdictions still face difficulty in identifying VASPs and turning legal rules into effective supervision and enforcement.
Therefore, the shift toward infrastructure should not be read as a single worldwide rulebook.
It is better understood as a common direction across several regulatory and supervisory efforts.
What this means for crypto businesses
For crypto businesses, the practical lesson is that compliance cannot sit apart from product design.
A new wallet product may raise custody questions. A new payment product may raise stablecoin and payment questions. A new trading service may raise market conduct and reporting questions. A new cross-border feature may raise licensing, sanctions and Travel Rule questions.
This can affect firms before a product reaches customers.
The UK approach illustrates the point. The FCA says firms must understand whether their activities fall within the future regulatory perimeter and whether they need authorisation or a variation of permission. Existing registrations and permissions will not automatically convert into the new permissions.
For businesses, this suggests that legal analysis should take place at the level of the complete service.
The question is not only what asset is offered. It is also what the firm does with that asset.
The compliance cost may move into the plumbing
This shift may also change where crypto companies spend money.
Earlier compliance programmes often focused on registration, customer checks and financial promotions. Those remain relevant, but firms may now need stronger technology and controls behind them.
A mature crypto compliance function may need legal specialists, compliance officers, engineers, data teams, security staff, risk specialists and external technology providers.
The exact mix will depend on the firm’s business model and jurisdiction.
The important point is that infrastructure can become a compliance control.
A system that cannot produce reliable transaction records may create a compliance problem. A custody system that cannot show who approved a transfer may create a control problem. A stablecoin system that cannot provide clear information about reserves may create a regulatory problem.
The technology is therefore not separate from compliance. In many cases, it is part of the evidence that a firm has complied.
A new regulatory map for crypto
The crypto market can now be viewed through several connected layers.
| Layer | Regulatory concern |
|---|---|
| Asset | Classification, disclosure and market conduct |
| Issuer | Governance, reserves and disclosures |
| Custody | Asset protection and access controls |
| Platform | Trading, execution and market integrity |
| Payments | Settlement and payment-system risk |
| Data | Identity, transaction records and reporting |
| Network | Wallets, counterparties and blockchain activity |
| Operations | Resilience, security and business continuity |
| Cross-border activity | Licensing and supervisory cooperation |
This wider map helps explain why infrastructure may become one of the most important parts of the crypto compliance story.
The token remains relevant. But the legal risk can arise from the system around the token.
The next phase of crypto compliance
The next phase of regulation is therefore less about asking whether crypto will be regulated. In many major markets, some form of regulation already exists or is under development.
The more useful question is where regulation will attach.
The evidence suggests that it is attaching to the services that make crypto usable at scale.
Custody matters because someone must control the assets. Stablecoin reserves matter because a digital payment instrument needs a credible redemption and backing structure. The Travel Rule matters because cross-border transfers require information. Transaction monitoring matters because regulators need firms to detect and report risk. Operational resilience matters because a financial service must continue to function even when technology fails.
None of this means that regulation will remove risk from crypto markets. It also does not mean that every regulatory model will produce the same result.
It does mean that the compliance discussion is becoming more detailed.
The industry’s future regulatory burden may not be visible in the name of a token. It may sit inside the wallet, the custody arrangement, the payment rail, the data pipeline, the reserve account or the software that decides whether a transaction can proceed.
That is the overlooked story.
Crypto regulation is moving from the coin toward the infrastructure that makes the coin useful.
For businesses, that means compliance is becoming less of a final legal check and more of a feature of the underlying system. For regulators, it means effective oversight may depend not only on new rules, but also on reliable data, cross-border cooperation and the ability to see how digital assets move through the financial system.
The precise legal obligations will remain jurisdiction-specific. But the direction is increasingly visible: the regulatory perimeter is expanding from the asset itself toward the infrastructure that supports its custody, transfer, exchange and use.
ALSO READ: Should Exporters Hedge More When the Rupee Is Stable?