Search This Blog

Monday, 10 August 2026

AI Transparency Obligations Now Apply

The transparency obligations under article 50 of the EU's AI Act are now live. Basically, the aim is to identify AI-generated or manipulated content. Subject to certain exceptions, users must be informed when they are interacting with an interactive AI system, such as a chatbot; deepfakes must be clearly labelled, as must AI-generated or manipulated text that is published on matters of public interest. There is 4 month transitional period for machine-readable marking by AI systems first made available in the EU market before 2 August 2026. This post is for information purposes only. If you need advice, please let me know.

Meaning of 'Provider' and 'Deployer' etc

A ‘provider’ is:
a natural or legal person, public authority, agency or other body that: 
develops an AI system or a general-purpose AI model or 
has an AI system or a general-purpose AI model developed 
and 
places it on the market or  
puts the AI system into service under its own name or trademark, 
whether for payment or free of charge; 

A 'deployer' is: 

"a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity;"

‘AI system’ means: 

"a machine-based system that is 
designed to operate with varying levels of autonomy and
that may exhibit adaptiveness after deployment, and 
that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments;"

'general-purpose AI model’ means: 

an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that 

displays significant generality and 

is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and 

that can be integrated into a variety of downstream systems or applications,

except AI models that are used for research, development or prototyping activities before they are placed on the market

What Must Providers and Deployers Do? 

There are certain useful carve-outs or exceptions, but generally:

Providers must:

design AI systems that interact directly with individuals (including chatbots) to disclose that users are engaging with an AI system. 

mark AI-generated or manipulated audio, image, video or text in a machine-readable format, using effective, interoperable, robust and reliable technical solutions for detection. 

Deployers must:

inform individuals when they are subject to emotion recognition or biometric categorisation. 

disclose when some content (deep fakes or text on matters of public interest) has been artificially generated or manipulated.

'deep fake’ means AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful;

EU Voluntary Code

Provides and deployers can sign up to an EU voluntary code that has more guidance on achieving and assessing AI transparency here

This post is for information purposes only. If you need advice, please let me know.

Registration-only Firms Face Closer FCA Scrutiny For AML Compliance

It takes more than a bank to launder money, so a wide range of businesses are required to comply with the UK's anti-money laundering (AML) regime. The scrutiny of these businesses has been increasing, particularly since Russia's invasion of Ukraine and the sanctions (and sanctions evasion) that followed. Various misadventures in crypto and Iran have also raised the stakes. The Financial Conduct Authority is the latest regulator to up the ante for the firms it supervises. This post is for information purposes only. If you would like advice on whether you need to register or other aspects of AML, please let me know.

What's involved in AML compliance?

Basically, AML compliance involves the relevant service provider registering with a supervisory authority; conducting certain 'customer due diligence' on clients; and monitoring the business relationship with clients in order to detect and report any suspicious activity to the National Crime Agency. There are also related laws that require a firm to screen clients against sanctions lists, avoid handling proceeds of crime or 'tipping off' those under investigation, provide information on transactions, establish client's source of funds/wealth and so on. 

To meet these regulatory obligations, each 'relevant person' that is covered by the regime must maintain policies and procedures that also involve appointing a 'money laundering reporting officer', assessing the risk of money laundering and terrorist financing for the business as a whole, as well as each product and client; and taking a risk-based approach to deploying resources in their compliance efforts. 

The consequences of getting any of this wrong can be very serious indeed, including jail time, fines and the firm having to cease doing business unless/until the right policies, procedures and controls are in place.

Non-financial businesses that must register and comply

The types of business activities that trigger registration when carried out in the UK are listed in Chapter 1 of the UK's money laundering regulations (MLRs).

The Gambling Commission is obviously the supervisory authority for gambling operators, while HMRC is the supervisory authority for the other non-financial business covered by the regime:

  • money service businesses not supervised by the Financial Conduct Authority (FCA) 
  • high value dealers handling cash payments for goods totalling 10,000 euros or more on a single transaction or linked transactions
  • trust or company service providers not supervised by the FCA or a professional body 
  • accountancy service providers not supervised by a professional body 
  • estate agency businesses 
  • bill payment service providers not supervised by the FCA 
  • telecommunications, digital and IT payment service providers not supervised by the FCA 
  • art market participants buying or selling of works of art where the transaction value (or a series of linked transactions) is 10,000 euros or more 
  • letting agency businesses renting property or land valued at the equivalent of 10,000 euros or more a month

It is typically quite straightforward for these firms to register with HMRC. Money service businesses and trust or company service providers must be registered first before they do any business. The others can trade while their application is being assessed, but run the risk of their application being unsuccessful and having to cease the relevant activity. Otherwise, it's basically a crime not to be registered where you should be, and the sanctions are explained here.

Financial services businesses that must register, even if not FCA authorised.

Certain financial services providers are covered by the AML regime if they carry out financial activities listed in Annex 1 of the MLRs as a business in the UK, even if those activities don't require the firm to be otherwise 'authorised' by the FCA (e.g. under the Financial Services and Markets Act 2000). Such firms must still register with the Financial Conduct Authority (FCA) and otherwise comply with the AML regime. It used to be quick to register, but the FCA has just announced that it will increase its scrutiny of these firms and take longer to register them.

Cryptoasset service providers are not mentioned in Annex 1 of the MLRs, but have their own listing and detailed qualifying criteria set out in Chapter 1 - basically, they are caught by the regime where they undertake cryptoasset exchange or custodian wallet activity (separately from the new cryptoasset regulations).  The FCA already takes considerably longer to register cryptoasset service providers than other businesses.

Are there any exclusions?

Yes, there is a range of exclusions under the MLRs (as well as the initial 'gating' factors of whether an activity is 'carried out as a business' in its own right and 'in the UK', which should not be overlooked).

One area of potential confusion is whether an entity is acting as a 'special purpose vehicle' (SPV). An SPV is a company or other legal entity which is established exclusively for the purpose of simply holding the legal or beneficial (equitable) title or interest in an asset of some kind -  typically a loan, lease or other type of funding agreement. They are common in securitisation (asset-backed bond issuance), but there are also more private arrangements. The financial asset is agreed or 'originated' and funded by some other entity before the legal or beneficial ownership (and the right to receive payments or 'receivables') are transferred (sometimes automatically or almost immediately) to the SPV to be simply held pending expiry or transfer elsewhere. Accordingly, the SPV has no operations, staff or systems of its own because a range of related agreements provide for the 'servicing' of the assets and collection of receivables by either the originator or a third party servicer. The point is that AML compliance obligations should already have been carried out by the entity which originated or created the instrument so it would be 'overkill' to require the SPV to gear up just to carry out AML compliance obligations. Sometimes, people confuse the role of the originator (which must comply with AML requirements) with the role of the SPV (which does not), especially where the originator transfers the asset to the SPV straight away and itself plays no further role in relation to the asset. 

This post is for information purposes only. If you would like advice on whether you need to register or other aspects of AML, please let me know.

Monday, 20 July 2026

UK Payments Regulation: Divergence And The End Of Open Banking?

The UK government is consulting on proposed changes to e-money and payment services regulation, with submissions invited until 6 October. There isn't much substantive detail here, so much as broad 'world leading' aspiration and calls for input, apart from eroding support for 'open' banking. Given the pace of evolution in payments and the conclusion of the EU's reform of the directives that underpin UK regulation - not to mention cryptoasset regulation - one would expect far more detail at this stage. 

This post is for information purposes only. If you would like advice, please let me know.

AI fan fiction

There are of course many signs that UK policy makers have been seduced by the AI lobby, so it's no surprise that the consultation touts the imagined 'potential' of agentic payments to "complete payments safely and seamlessly". Readers will know that a healthy dose of scepticism is in order, if not outright alarm. There's a very short section on "managing sector risks" but no suggestion that the government understands what these are. Surely, we should be into the detail on this front, rather than apparently inviting education.

Brexit and Divergence from EU Regulatory Framework

There is a nod to the fact that the EU is making substantial changes to the directives that underpinned the UK's Payment Services Regulations (PSRs) and E-money Regulations (EMRs), while committing to "ensuring that the UK’s regulatory framework remains world leading and responsive to developments across international jurisdictions".  

The fact is that most of Europe's payment service providers used to be based in the UK, and Brexit meant having to go to significant trouble and expense to replicate their offerings in the EEA. Personally, I've been advising clients via both UK and Irish firms since 2018 for this very reason. 

Any significant divergence in regulation will increase the cost and complexity of spanning the English Channel, further stressing the business case for maintaining a foothold in both UK and Single Market, so the UK has little choice but to follow the EU's approach here and should make it as easy as possible for groups to map the changes. That doesn't mean it will, of course, and the proposal to replace some sections in the EMRs and PSRs with more flexible FCA rules threatens making that read-across more difficult and less trustworthy over time. 

Cryptoassets, Tokenised Deposits and E-money Tokens

The government wishes to use this reform process to "regulate the use of tokenised payments, including stablecoins and tokenised deposits, for their use in payments." 

Worryingly, however, the consultation paper is silent on 'e-money tokens' and merely invites 'views' on whether payments regulation contains any barriers to the use of tokenised payments, notwithstanding that the UK has only just introduced its own cryptoasset regulation. You would expect these issues to have been ventilated and understood in that process. The EU's draft PSD3 and related Regulation (PSR) already address certain areas of overlap, including in relation to e-money tokens

As with AI, there seems to be both naivety and the suggestion of seduction from the blockchain lobby, including the supposed innovation in the idea of "programmable payments" and that "a smart contract could be set up to allow a business owner to pay a supplier immediately on signed receipt of goods, rather than having to wait for an invoice to be issued and then paid." 

Again, the section on risks is very short.

The End of Open Banking in the UK? 

Consistent with the first E-money Directive and then the Payment Services Directive carving out payment services from the traditional banking monopoly, "Open Banking" requirements were introduced under PSD2 (finalised in 2015 and implemented in 2017). These have been bolstered in the proposed PSD3/PSR

Open Banking consists of two services: 'payment initiation services' (which sought to regulate Dutch and German methods for initiating bank transfers from online checkouts) and 'account information services' (which sought to replace the (consensual) practice of 'screen-scraping' customers' bank account information with secure, direct API access). PSD2 requires banks and other 'account service payment service providers' to allow API access to a customer's regulated open banking service provider free of charge and without the need to negotiate a contract. Access requirements have been intensified under PSD3, including availability and performance requirements.

The larger UK banks' resistance to these innovations (not to mention faster payments) eventually led to a Competition and Markets Authority’s Retail Banking Market Investigation Order in 2017, quickly followed/expanded by the implementation of PSD2 under the PSRs. 

Now, the UK government wants to facilitate account access under the Data (Use and Access) Act 2025 (DUAA), rehearsing the 'mydata/midata' initiatives of 2011-2014, as well as reforming the PSRs with a new right of access for variable recurring payments. 

But all is not what it seems.

Notwithstanding the vast, expensive regulatory processes designed to drag them kicking and screaming into the 21st century, the UK government now wants the very banks who dragged their feet in allowing access to their payment accounts to be able to charge for API/account access and require open banking service providers to enter into contracts to gain access as well as dispensing with other requirements in the hard won CMA Order and allowing the formation of (exclusive) 'commercial open banking schemes' and requiring open banking service providers to fund the FCA's supervisory costs.

The government's rationale for reversing measures responding to 30 years of consumer and payment industry complaint is that, somehow, the banks have managed to convince the government of their age old claim that "there is currently little incentive for them to invest to enable new products and services". As if this were not evidence enough of the triumph of hope over experience:

It is the Government’s expectation that by establishing a new right of access for variable recurring payments and supporting fair commercial arrangements for new products, ASPSPs will be incentivised to participate in Open Banking schemes on a voluntary basis. Therefore, the Government does not propose providing the FCA with a new power to mandate ASPSP participation in commercial Open Banking schemes. However, it will monitor adoption of these schemes as the market continues to develop.

You could not make it up.

Conclusion

The ongoing theatrical pretence of 'making Brexit work' lack of certainty in many areas and revisions to open banking in particular, mean that the UK regulatory approach to e-money and payment services is already diverging significantly from the regulatory framework in the Single Market. Firms which operate in both markets will need to be alert to the differences, which will likely affect service architecture, contracts, liability, fraud risks, costs and pricing.

This post is for information purposes only. If you would like advice, please let me know.




Friday, 19 June 2026

Some Changes To UK Money Laundering Regs...

There are noteworthy changes to the UK's money laundering regulations (MLRs) some of which are summarised in this post for information purposes. Unusually, these include obligations on customers with accounts in which money is pooled (in addition to the regulated firm providing the 'pooled' or 'segregated' account). Let me know if you need advice.

  • Monetary amounts are now in GBP on a 1:1 basis, so those thresholds/limits increase (since €10k is about £8,600 at time of posting), except where that would risk failing to meet the Financial Action Task Force (“FATF”) recommendations.
  • The practice of selling “off-the-shelf" companies is now specified among the activities that render the provider of such a service a “trust or company service provider”; and it is considered to be an act that establishes a 'business relationship', thereby triggering the need for KYC etc.
  • Any firm subject to the MLRs who provides a customer with a "pooled account" must undertake additional customer due diligence measures to understand the purpose and determine/address the risk of money laundering/terrorist financing. Unusually, a customer who receives a pooled account must maintain written records for 5 years, and provide information to the account provider and the authorities on request, in respect of the pooled account. Such an obligation obviously assists the account provider and authorities; and a breach of these obligation by the customer would provide a basis for the suspension or closure of the account. However, these obligations do not seem to be 'relevant requirements' for the purpose of determining offences under the MLRs.
  • The customer due diligence (CDD) transaction-based triggers for 'letting agents' and 'art market participants' are now the same as those for 'high value dealers' (£10k).
  • Banks who take on customers from an insolvent bank can allow those customers to open an account and transact from it prior to completing CDD measures (including enhanced due diligence (EDD), where relevant) other than identifying the customer or person purporting to act on the customer’s behalf (and verifying that such person is authorised to act); while the need to verify the identity and report discrepancies in the registers related to such customers are disapplied. 
  • The definition of “high-risk third country” has been replaced by “FATF call for action country”. 
  • Cryptoasset businesses must conduct EDD in relation to their "correspondent relationships" (specifically defined for this purpose, as opposed to the existing "correspondent relationship" for credit/financial institutions), consistent with FATF recommendations.
  • Trusts which acquired an interest in UK land before 6th October 2020 and continue to hold that interest on 30 June 2026 must register with HMRC (other than 22 excluded trusts), but a liability to pay Stamp Duty Reserve Tax (SDRT) will not result in a trust becoming a 'taxable trust' that must be registered.
  • The MLRs are now aligned with the new FCA regime for cryptoassets, so that a cryptoasset exchange or custodian wallet provider that is registered under the MLRs before 25th October 2027 must also give notice of a change of control within the meaning of Financial Services and Markets Act 2000 (FSMA). 

This post is for information purposes. If you need advice, please let me know.

Sunday, 24 May 2026

UK Presses On With Consumer Credit Reform

The Treasury has published its policy statement on the next steps in reforming Britain's complex consumer credit framework, following the consultation in May 2025. The Financial Conduct Authority has also announced that it will consult on its rules in due course (it seems likely there will be a fairly generous transition period with so much work to do). I have described the overall approach in more detail below based on the Treasury's executive summary. Broadly, however, the industry will still need to navigate between the Consumer Credit Act ("CCA") and related sets of rules, albeit the FCA rules are more accessible than the various CCA regulations. It is not clear whether and to what extent this will address some areas that had been left behind by interim regulatory evolutions (e.g. consumer hire). Please let me know if you require legal advice on the detail of the changes in due course.

FCA rules will replace various information disclosure requirements under Consumer Credit Act ("CCA") regulations relating to the three phases of consumer credit: pre-contract (e.g. Pre-Contract Credit Information, Agreement, etc.), post-contract (e.g. statements, copies, etc.) and collections (e.g. arrears and default notices, etc.). Security and guarantees (surety) will also be addressed in FCA rules.

Restrictions on enforcing defective agreements without a court order and other sanctions will be replaced by the FCA compliance/enforcement regime, but criminal offences will be retained. 

Other CCA requirements will also be replaced by FCA rules as follows (subject to FCA consultation): 

  • Withdrawal rights (some parts retained); 
  • Cancellation rights (some parts retained); 
  • Early settlement and rebate rights; 
  • Termination of agreements (including voluntary termination) (some parts retained); 
  • Securities and sureties (some parts will be retained); 
  • Credit-token agreements, acceptance and liability for misuse of credit tokens; 
  • Agreement to enter future agreement void; 
  • Liability for misuse of credit facilities; 
  • Interest not to be increased on default; and 
  • Statements by creditor or owner to be binding.

The following CCA concepts/provisions would be retained (with necessary amendments): 

  • Consumer credit agreements, meaning of credit, running account credit, fixed sum credit, restricted used and unrestricted use credit, debtor-creditor-supplier agreements, and debtor-credit agreements; 
  • Consumer hire agreements; 
  • Linked transactions; 
  • Cancellation: recovery of money paid by debtor or hirer, return of goods and goods given in part exchange; 
  • Withdrawal from prospective agreement 
  • Death of debtor or hirer; 
  • Protected goods, recovery of possession of goods or land, summary diligence not competent in Scotland; 
  • Ineffective securities; 
  • Pawnbroking; 
  • Negotiable instruments; 
  • Land mortgages; and 
  • Provisions under Judicial Control (including Time Orders, interest, etc.), 
  • Ancillary Credit Businesses (including credit reference agencies), 
  • Enforcement of Act and 
  • Supplemental (including interpretation, definitions, etc.)


Thursday, 30 April 2026

It's... PSD3 Time! Well, Almost...

Another year and another update on the third Payment Services Directive (PSD3) and its sister Payment Services Regulation (PSR). For evolutionary fans, I last summarised the content in detail in 2023, with an update last June. I'm working through a fresh update here, calling out any differences that I see as significant versus PSD2. I'm through the PSD3 directive and the main exclusions in the PSR. Timing wise, of course PSD3 will need to be implemented in each EEA member state (as with PSD2/EMD2) while the PSR will have direct effect. Both will apply together from some time in 2027/28 (18 months from publication in the Official Journal). There are various additional transition periods for existing payment/e-money institutions and those benefitting from exclusions/exemptions. This post is for information purposes. If you'd like legal advice, please let me know (via Crowley Millar in Ireland, as this would be EU-related work).

In very broad terms, PSD3/PSR merges the e-money and payment services frameworks and:

  • improves non-bank payment service providers' access to payment systems and bank accounts
  • better facilitates 'open-banking' and consumer control
  • enhances enforcement powers
  • improves consumer information, rights and access to cash via retail shops and ATMs

There are really no newly regulated payment services, although "issuance of electronic money" is now called out and consolidated under the PSD (though I'm not yet clear on whether that includes directly related payment services, as opposed to those you might operate separately from your e-money features).

Changes introduced by PSD3

Annoyingly, the definitions are split between PSD/PSR with some tweaks. Most definitions are in the PSR, so the PSD cross-refers to those and so will all the national implementing regulations. However, the PSD does have a few definitions of its own, including:

  • "execution of a payment transaction" is now a thing in the PSD, apparently to differentiate it from a 'payment initiation service':
'execution of a payment transaction’ means the process starting once the initiation of a payment transaction is completed and ending once the funds placed, withdrawn, or transferred are available to the payee;

  • the concept of ‘agent’  seems to be a source of potential regulatory creep, because you might argue that a 'technical service provider' is directly involved in the payment institution's provision of payment services - but perhaps that is now a (fuzzy?) line of demarcation: 

'agent' means a natural or legal person who acts in the name and on behalf of a payment institution in providing payment services, and who either enters into possession of funds on behalf of the payment institution or is directly involved in the payment institution's provision of payment services;

currently, an “agent” is a natural or legal person who acts on behalf of a payment institution in providing payment services; as distinct from, say, a 'distributor' in the e-money world, who does not carry on any payment services activity... wither that distinction?

  • anti-forum shopping: There's a requirement to explain where your firm or related firms have sought authorisation in other EU jurisdictions, and the reason for refusal; and certain information on any prior cryptoasset service provider authorisation.
  • initial capital: increases to €150k (from €125k) for most payment services, but reduces to €250k (from €350k) for e-money issuers, but is cumulative where you offer both e-money issuance and (unrelated?) payment services. There seem to be clues to the demarcation in the ongoing capital requirements at least.
  • e-money tokens: there are some provisions to try to dovetail and not overlap with MiCAR, particularly on safeguarding.

Changes introduced by the PSR

Here's where the differences start to get tricky. There are four categories of activity: (a) out of scope entirely (often a matter of interpreting the 'perimeter'); (b) in-scope but benefiting from an exclusion (often with conditions, including registration); and (c) in-scope but carried out by people or entities who are not required to be authorised or registered; and (d) in-scope and requiring the service provider to be authorised/registered or appointed/registered as the agent of a firm with the right authorisation. 

In this post, I'll skip what would be out of scope.

Activities in-scope but benefiting from an exclusion (often with conditions).

  • Commercial agents: The exclusion for commercial agents in Article 2(2)(b) appears to be narrower, in that the agreement authorising the agent to negotiate or conclude the sale or purchase of goods on behalf of either the payer or payee must also "give the commercial agent a real scope to negotiate with the payer or payee or conclude the sale or purchase of goods or services". That's consistent with how the FCA, for example, has always interpreted the existing exclusion, anyway. But the new language begs the question whether there are any specific e-commerce platforms the authorities believe are unfairly outside scope. Recital 11/Article 2(7) requires the EBA to develop guidelines to pre-empt differing interpretations, so it will be interesting to see where these end up and who has to reconfigure their offering.
  • Technical service providers: the definition of ‘technical service provider’ has shortened but is effectively the same or potentially broader than being purely about technology or data processing ("a provider of services which, although not being payment services, support the provision of payment services, without entering at any time into possession of the funds to be transferred"), but, among other conditions, they will have liability for direct financial damage up to the value of each affected transaction for any failure to support the application of 'strong customer authentication' (multi-factor authentication) and any PSP of the payer who relies on a technical service provider to 'provide and verify' the elements of SCA will need to have an outsourcing agreement in place (which triggers other provisions and the EBA outsourcing guidelines). The competent regulator will be in the Member State in which the technical service is provided. Technical services offered jointly with payment services must also be subject to the restrictions on termination fees for the related payment services.
  • Limited networks: there are still 4 classes of potential limited network, but the preamble no longer mentions 'used in a limited way' and the first two limbs in PSD2 are blended into one. The reference to 'payment instruments' is clarified to include 'electronic money-based instruments', which is apt to confuse; those limited to 'premises' include both physical and online stores (some regulators interpreted premises to mean physical only); and those that can only be used for a very limited range of goods or services can include payment service users who are not consumers. It is also clarified that public sector instruments cannot be redeemable for cash. The reference to e-money-based instruments yet the exclusion of redemption for cash is very confusing!
  • Several new exclusions: highlight scenarios that perhaps some have realised are currently considered to constitute regulated 'payment services' - namely:
  • retail stores dispensing cash where the customer is not obliged to buy any goods or services; and
    • a crypto-asset service provider intermediating between a buyer and a seller where electronic money tokens are exchanged for other electronic money tokens or for crypto-assets, as well as the exchange of electronic money tokens for funds, including electronic money tokens, or crypto-assets carried out by a crypto-asset service provider acting in its own name as buyer or seller of those electronic money tokens

The latter takes some un-picking, but even absent this exclusion (which the recital at 29a says is intended to avoid the need for dual MiCAR/PSD authorisations) some authorities might well conclude that a cryptoasset service provider doing the above is not offering a 'payment service' by way of a distinct regular occupation or business activity, but is merely facilitating the exchange as an ancillary aspect of operating a cryptoasset exchange service, for example. The difference might be that a retailer accepting e-money payments can't actually do that, even technologically speaking, without the involvement of a regulated payment service provider. At any rate, a transitional provision also exempts this activity from PSD2.

Activities in-scope but carried out by people not required to be authorised or registered 

  • Operators of payment systems and payment schemes: a 'payment system' means "a funds transfer system with formal and standardised arrangements and common rules for the processing, clearing or settlement of payment transactions", while a 'payment scheme' is not otherwise defined but a recital clarifies this to 'typically include four-party card schemes' (or what the Americans refer to as 'networks'), e.g. Visa and Mastercard - and 'payment card scheme' (along with 'processing entity') is defined by reference to the Interchange Fee Regulation. There is wording in the PSR to suggest that the term 'payment system' may be intended to cover 'payment scheme' in certain respects, but without duplicating the regulation of systemically important payment schemes. A 'payment system operator' is of course the legal entity legally responsible for operating the payment system. Essentially, regulated PSPs must have fair access to payment systems; and payment systems, payment schemes and processing entities are given specific rights to process personal data. Payment card schemes and processing entities must be transparent on fees 'imposed on' PSPs providing acquiring services.
  • original manufacturers of mobile devices and electronic communication service providers: must grant fair access to PSPs and technical service providers acting on their behalf. 
  • Providers of electronic communication services and very large online platforms/search engines: must establish anti-fraud communication channels, educational measures and alerts. This also includes exchanging information with 'providers of hosting services' who may be subject to direct obligations in due course, if the Commission determines that is necessary.
  • Currency conversion: the PSRs continue the requirement that payment transactions must occur in the currency agreed between the "parties" (conflating the contract of sale/supply of goods/services with the payment transaction itself). This covers scenarios where, for instance, a cardholder is offered a choice to pay for an item in a different currency to that of their card ('dynamic currency conversion') or the merchant quotes a price on its website in one or more different currencies to the normal currency in which prices are quoted ('price conversion'). In such cases, all charges and the exchange rate to be used for converting the payment transaction must be disclosed to the payer as both a monetary amount and as a percentage mark-up over an "aggregated mid-market exchange rate" provided by "a trusted administrator who meets applicable governance and control requirements, such as the IOSCO Principles for Financial Benchmarks". Some foreign exchange operators offer the merchant a 'spread' on these FX transactions.

Activities in-scope and requiring authorisation etc

  • 'electronic money': this no longer includes "as represented by a claim on the issuer"
‘electronic money’ means electronically, including magnetically, stored monetary value as represented by a claim on the issuer which is issued on the receipt of funds for the purpose of making payment transactions and which is accepted by other natural or legal persons than the issuer;

There is no mention of the misunderstanding as to the meaning of "and which is accepted by other natural or legal persons than the issuer" that was sparked by an ECJ's preliminary ruling in February 2024, picked up in an EBA Q&A in January 2025 (and since then by the Central Bank of Ireland). As explained at length, the better interpretation is that e-money is stored monetary value issued for the purpose of enabling the e-money holder to pay an intended third party (such as a merchant), as the 'payee' - rather than the payee actually having to receive the actual stored monetary value directly.

The definition of 'funds' continues to include e-money and will extend to 'e-money tokens'. 

  • 'initiation of a payment transaction': there appears to be some attempt to more clearly demarcate payment initiation and payment execution (see above), but this phrase does not appear in the definition of 'payment initiation service' (which still says 'place a payment order'). This phrase replaces 'payment order' in the definition of a 'payment instrument' (although 'remote initiation..." involves a payment order placed 'via the internet' (to differentiate from a blockchain? what about a mobile network, is the assumption that even in that case the internet is involved at some point or is the use-case intended to be covered by provisions relating to 'electronic communication services'?)
  • 'account information service' (AIS): this definition is different to PSD2 and now seems to catch both an interim service provider as well as the service provider who deals with the customer:
‘account information service’ means an online service where a provider, accesses one or several payment accounts held by the payment service user with one or several account servicing payment service providers that are accessible online in order to provide a service of aggregation or consolidation of payment account data to the payment service user or to transmit the data to another entity that will provide that service to the payment service user;
Recitals 26 and 54 refer to scenarios where the data is being provided to an entity providing 'another service' (e.g. lending, accounting) but the definition is not clear on that distinction - merely referring to 'another entity' and 'that service' (the only one mentioned being an 'account information service'). In a chain scenario, this would seem to mean that both entities in the chain will need to be authorised to provide an AIS - the entity that accesses the payment account(s) to transmit the data, and the other entity that actually provides the data to the payment service user. Under PSD2, there have been several ways for the intermediate entity to avoid the need for authorisation.

Where this leaves the situation where the AISP is being asked to send the data to, say, a lender with the payment service user's permission is not clear. Under Article 43, it is up to the account servicing PSP to maintain a dashboard showing the names of AISPs and PISPs who have been granted access to your payment account and the 'purpose of the consent' to use their service (based on data provided by the AISP/PISP), so it seems that purpose should also reveal any third party service provider to which payment account data is flowing via the relevant AISP.

Operational issues

  • Strong customer authentication: definitions of "merchant initiated transactions" and "mail order, telephone order" transactions have been introduced for the purpose of clarifying how and when SCA should be applied. 
  • Currency conversionthe currency conversion charges for credit transfers and remittances will need to be expressed consistently as both a monetary amount in the currency of the payer’s account and as a percentage mark-up over an "aggregated mid-market exchange rate" provided by "a trusted administrator who meets applicable governance and control requirements, such as the IOSCO Principles for Financial Benchmarks" using the "same reference benchmark consistently and for exchanges made in both directions." References to ‘charges’ should also be read to cover currency conversion charges. 
  • Periodic penalty payments: regulators may impose a daily fine to be paid until compliance is restored for up to 6 months of at least 3% of the average daily turnover (annual divided by 365) for a legal entity and €30k for a natural person, though member states can increase these amounts.
  • derogation for low value instruments: the threshold has doubled to €300 for these instruments generally, but remains at €500 for prepaid.
  • where the payee's payment service provider is located outside the EEA, the estimated time for the funds of credit transfers and money remittance transactions to be received by the payee's payment service provider.
  • as now, after receiving a payment order, a payer's PSP must provide/make available certain information, but information on the payee has been strengthened to include "the information needed for the payer to unambiguously identify the payee,  including the payee’s commercial trade name and, where available to the payment service provider and if different from the commercial trade name, the payee’s legal name".
  • among the information to be included in the framework contract (service agreement) in relation to payment instruments is "the length of a delay for any resulting increase in spending limits to come into effect and description of how the payment service user can modify the spending limits and adjust or opt out of the application of a delay period."
Other changes too numerous to mention, but including:
  • the period in which a consumer can terminate without charge is reduced from 6 to 3 months;
  • the notice period for the PSP to terminate an open-ended framework contract is increased from 2 to 3 months;
  • the 'corporate opt-out' remains, but of course the regulatory references will change for contracts that include that opt-out now;
  • there are extensive transparency requirements relating to charges by payment card schemes, processing entities and acquirers (as customers of payment schemes);
  • the PSRs incorporate provisions dealing with 'open banking' interfaces for account information and payment initiation service providers, including availability and performance requirements;
  • there are tighter rules concerning PSPs' access to bank accounts, including the reasons for refusal;
  • the PSRs provide that:
A payment transaction shall not be deemed to be authorised where the transaction was initiated or modified by a third party who is acting without the consent of the payment service user, including by using the personalised security credentials of the payment service user fraudulently obtained

  • there are requirements to enable users to set transaction limits and modify them on a delayed or immediate basis as they wish;
  • the time for notifying a PSP of unauthorised or incorrect transactions increases from 13 to 18 months after the date of debit, with greater clarity around burden of proof and evidence that can be expected;
  • there are various anti-fraud measures, including APP fraud reimbursement on certain conditions;
  • there are advertising restrictions for very large online platforms; and
  • there are more detailed transaction processing times, including for e-money tokens.

This post is for information purposes. If you'd like legal advice, please let me know (via Crowley Millar in Ireland, as this would be EU-related work).
 

Friday, 24 April 2026

It's... The Moment of Truth For The UK Crypto Sector

Just like "the It's man" who introduced Monty Python's Flying Circus, the UK regulation of cryptoassets has been a long time arriving but is very suddenly upon us. For existing activities to be 'grandfathered' into the regime you must apply to the Financial Conduct Authority between 30 September 2026 and 28 February 2027. Working backward, it usually takes at least 3 months to prepare an application, so you'll need to be in a position to start that process in June. Yet the FCA has only just begun consulting on its "Perimeter Guidance" on where the boundary of the new regulatory regime lies. Comments are invited by 3 June 2026 with a view to the FCA finalising its interpretation "in September"... Below's a brief summary of the consultation for information purposes. If you need advice, please get in touch via Keystone.  Of course, this follows a similar though transitional issue throughout the EU/EEA under the Markets in Cryptoassets Regulation (MiCAR) for which the application window closes on 1 July 2026. For advice on that, please get in touch via Crowley Millar.

A key challenge for everyone in the crypto space is that 'bare' cryptoassets themselves have been largely unregulated since being popularised by the launch of bitcoin in 2009 (often referred to as 'exchange tokens' or 'utility tokens'). 

But some cryptoassets might have characteristics that also make them some kind of 'traditional' regulated instrument (usually referred to as 'security tokens' and 'e-money tokens').

So any firm which is already active in the crypto sector has to be careful in approaching the FCA for authorisation to carry on a new regulated cryptoasset activity in relation to a newly defined "qualifying cryptoasset" or "qualifying stablecoin" (or in the case of safeguarding, a “relevant specified investment cryptoasset”) that it has not already been carrying on an existing regulated activity for which it should already have obtained FCA authorisation. 

The FCA even sounds a clear warning about this, as well as getting the analysis right in relation to newly regulated activities:

2.8 Persons should consider the perimeter in relation to every activity they perform and should carry out an analysis on a case-by-case basis. Whether an activity is regulated will depend on the specifics of what a person is doing and their role in the relevant arrangements, whether the activity is carried on in the UK, whether it is carried on by way of business, and whether any exclusion or exemption applies. 
2.9 Anyone carrying on activities in relation to cryptoassets must consider the legislation and guidance carefully, and ensure that they have the appropriate permission for any regulated activities they carry on, or an exclusion or exemption... 
2.10 In cryptoasset markets, some terminology is used differently and business models do not necessarily map onto traditional financial services concepts. It might not be clear whether an arrangement is inside or outside the perimeter just from its name – what is important is the substance of the activity and the role performed by the person in question, not the terminology the market participants adopt. 
2.11 Persons should also consider this proposed guidance carefully where a service includes automated, blockchain-based or decentralised features. The fact that an arrangement involves smart contracts, public blockchains or some elements of decentralisation does not determine the perimeter position or place the arrangement outside of regulation. The question remains whether there is an identifiable person whose business includes carrying on the relevant activity in the UK. In that context, depending on the activity, considerations should include whether a person operates or maintains the service, sets key parameters, controls important aspects of how it functions, and/or receives fees or some other commercial benefit from the activity. As with any perimeter question, the analysis will depend on the facts. 
2.12 Carrying on a regulated activity in breach of the general prohibition has significant consequences. Contravention of section 19 of FSMA is a criminal offence that carries a term of imprisonment of up to 2 years, an unlimited fine, or both. A breach of the general prohibition means that agreements entered into by the unauthorised person carrying on regulated activity are unenforceable. There are also consequences for anyone who’s already authorised but who does not have the correct permission for the regulated activities they intend to carry on.

The consultation paper then goes on to explain the FCA's proposed interpretation of what constitutes the regulated instruments as well as the new types of regulated activity, including when they would be considered to be conducted 'by way of business' and 'in the UK' and how the exclusions might apply, as well as how all this relates to the existing registration regime for some types of cryptoasset service provider under the money laundering regulations and the financial promotions regime.

If you need advice on such things for the UK, please get in touch via Keystone.

Of course, this follows a similar though transitional issue throughout the EU/EEA under the Markets in Cryptoassets Regulation (MiCAR) for which the application window closes on 1 July 2026. For advice on that, please get in touch via Crowley Millar.