
The European Union is preparing to bring large cross-border crypto firms under direct anti-money-laundering supervision even when they serve customers remotely without maintaining a branch or local office. The framework gives the EU Anti-Money Laundering Authority, or AMLA, a route to supervise high-risk financial institutions operating across at least six member states, including crypto-asset service providers.
AMLA’s finalized draft selection rules treat remote activity as material in a member state when a firm has more than 20,000 resident customers there or processes more than €50 million in annual incoming and outgoing transactions for those customers. The thresholds are alternatives, and activity carried out directly, through branches, agents or distributors can count toward the test.
The model adds an AML layer to MiCA’s cross-border passporting system. MiCA allows an authorized crypto-asset service provider to operate across the bloc without a physical presence in each host member state, while AMLA can still count sufficiently large remote markets toward its geographic test. That follows the EU’s earlier move requiring unauthorized crypto firms to wind down activity once the MiCA transition expired.
The selection methodology is not operational yet. AMLA finalized the draft regulatory technical standards in December 2025, but the rules still require European Commission approval before applying directly across member states. AMLA will start its first selection process in July 2027, with direct supervision scheduled to begin in 2028.
Crossing the customer or transaction threshold alone does not place a firm under AMLA. An eligible institution must operate in at least six member states and receive a high residual money-laundering or terrorist-financing risk classification under the authority’s methodology. The first selection is expected to cover up to 40 high-risk financial institutions or groups.
Crypto firms are explicitly inside the financial-sector AML regime. The EU’s AML Regulation includes crypto-asset service providers within its financial-institution definition and introduces enhanced requirements covering customer due diligence, cross-border crypto relationships and transfers involving self-hosted addresses. Those requirements form part of the broader 2027 crypto KYC framework.
AMLA will gain direct enforcement powers over selected firms. For serious, repeated or systematic breaches involving customer due diligence, internal controls or reporting obligations, the statutory penalty framework allows sanctions to rise as high as 10% of annual turnover after aggravating and mitigating adjustments are applied.
The 10% level is a ceiling rather than an automatic fine. Lower basic penalty ranges apply first, with AMLA required to consider the seriousness and circumstances of each breach before setting the final sanction.
AMLA’s first selection cycle will run from July through December 2027, with the chosen institutions moving into direct EU-level AML supervision six months after the final list is published in 2028.
The post EU AMLA Rules Put Remote Crypto Exchanges in Scope for Direct Supervision appeared first on Crypto Adventure.