Crypto Compliance in 2026: The Regulator Moved. The Bank Did Not.
US regulators stepped back from crypto in 2025 while EU rules tightened. A crypto business's bank reads the same file either way. What it asks, and why.
ComplianceSince early 2025, a crypto business has been getting two opposite signals. In the United States, the Securities and Exchange Commission dropped its cases against Coinbase, Kraken and Binance between February and May 2025, dismissed with prejudice and without penalties. In the European Union the direction was the reverse: the last transitional periods under MiCA ended on 1 July 2026, and from July 2027 the new Anti-Money Laundering Regulation bans anonymous accounts across the regulated sector, crypto-asset service providers included.
Either headline is easy to read as the signal. Neither is the one that decides whether a crypto business can pay its suppliers next month. That decision sits with its bank.
Securities enforcement is not what a bank works under
The SEC's retreat changed which cases get brought against crypto companies. It did not change the law a bank's compliance officer applies to a crypto client. That law is anti-money-laundering law, and it has only moved in one direction. In the US, the GENIUS Act, signed in July 2025, treats payment stablecoin issuers as financial institutions under the Bank Secrecy Act. In the EU, the new regulation applies from 2027.
A bank also carries a risk that no change in a regulator's priorities removes. If a client's flows turn out to include money the bank should not have touched, the consequences land on the bank - with its own supervisor, with its correspondent banks, and on its reputation. That is why a bank reads a crypto business's file the way it does, and why the file matters more than the headlines.
From where we sit, between crypto businesses and the banks that serve them, the questions have not become any softer since the SEC changed course.
What a bank actually reads
The file a bank builds on a crypto business comes down to a handful of questions. None of them is new, and each is answered with documents rather than assurances.
- Who regulates you, and for what. A licence or registration, the jurisdiction that issued it, and whether it covers the activity the bank will actually see on the account.
- Who runs compliance. A named compliance officer and an anti-money-laundering policy that describes what the business really does, not a template written for a different model.
- How transactions are monitored. Which blockchain analytics and screening tools are used, and what happens when one of them returns a hit.
- Whether the Travel Rule is applied. Originator and beneficiary information travelling with transfers, as FATF standards require.
- Where your clients' money comes from. A bank treats its client's customers as its own exposure. A business that cannot show the origin of its customers' funds passes that risk to the bank, and the bank knows it.
A business can hold a licence and still fail this file, because the licence answers the first question and none of the others.
Why the file costs more than the licence
Building that file is ongoing work, not a one-off. Policies have to follow the product as it changes, monitoring has to run on every transaction, and the questions do not come once, at onboarding. They come again when volumes grow, when a new corridor opens, when a payment looks different from the last hundred.
For a crypto business whose product is not compliance, this means a team, tools, and a steady stream of correspondence with the bank. Every hour spent on it is an hour not spent on the product, and a gap anywhere in it shows up in the same place: a payment that stalls while someone assembles an answer.
How we work with crypto businesses
This is the layer Stablegate works in.
Some of the businesses we work with do not build this function themselves. They plug into our compliance process instead, with client verification, screening and monitoring running through our platform. When a bank has questions about a flow, our compliance team answers them, working with the bank's compliance team directly rather than through the client.
The documents come first. What a bank is likely to ask for is collected before a transaction is executed, and if we see a risk - in the documents, in the origin of the funds or in the route - the client hears about it before anything moves. A transfer is not sent until the file is complete.
None of this is lighter compliance. It is the same compliance, done by a team whose job it is, in the order a bank expects. The team behind it is the team behind EURS, a euro stablecoin launched in 2018, and Stablegate operates under the Swiss AML framework through VQF, a FINMA-recognised self-regulatory organisation.
The signal worth following
Regulatory direction can change with an election, as 2025 showed. The questions a bank asks a crypto business change far more slowly, and they are the ones that decide, every month, whether the money moves.
Watching the regulators is worth doing. Being able to answer the bank is what keeps a crypto business running.
Published for general information and education only. Not investment, financial, legal, or tax advice, and not an offer or solicitation in any jurisdiction. This is not marketing - Stablegate does not market its services to persons in the EU/EEA, the UK or the US (Restricted Persons).
The views expressed are current as of the publication date and may change. Third-party quotes are attributed and used under applicable quotation exceptions. Sourced and first-party data has not been independently verified and is provided without warranty. Any forward-looking statements are illustrative only. Past performance is not indicative of future results.
STGG AG is not a MiCA crypto-asset service provider (CASP) and does not offer or onboard services to Restricted Persons via this hub. Any service relationship arises only away from this hub, at the client's own exclusive initiative.



