
This Week in Compliance: UK Cryptoasset Authorisation Rules Land
Three regulators and one breach spent the week of 27 June to 3 July 2026 making the same point from different directions. The UK published its final UK cryptoasset authorisation rules, the EU let the MiCA transitional window shut for good, and an insurer disclosed an intrusion that exposed personal and bank-account data for 4.38 million people. Read separately, the four events look unrelated. Read together, they describe one operating reality: market access now turns on compliance evidence a firm can produce on demand, and the raw personal data historically warehoused to produce that evidence has become the liability rather than the asset.
Four items carried the week — the FCA's final rules, the MiCA cliff and its fallout, the Aflac breach, and a quieter note on whether compliance evidence can be independently checked. This is not four stories. It is one: evidence you can produce, data you shouldn't store.
The FCA's final UK cryptoasset authorisation rules move firms from policy to proof
On 30 June 2026 the FCA published its package of final policy statements for the UK cryptoasset regime — covering stablecoin capital, backing assets, redemption, AML/KYC and market integrity — alongside a joint Bank of England and FCA approach to regulating systemic stablecoin issuers (1)(2). "Firms supporting people to buy, trade and hold crypto will need to meet clear standards," the FCA said (1). The authorisation gateway is expected to open on 30 September 2026, with the joint FCA/BoE systemic-stablecoin consultation closing 28 February 2027, PASS pre-application support meetings running from July 2026, and the new regime coming into force on 25 October 2027 (1)(10).
The change these rules make is not the standard itself but the burden of demonstrating it. Final rules move crypto firms from having a policy to producing the evidence. The FCA sets standards across five control areas, and four of them — capital, backing assets, redemption and market integrity — are the firm's own balance-sheet and market-conduct obligations. No identity provider answers those; they belong to the issuer and the venue. The fifth control area, anti-money laundering and KYC, is where the question of producing evidence turns into a question of architecture — where the data lives, and who ends up holding a copy. When the timeline first firmed up, we set out the gateway's date-versus-architecture split: the dates are fixed, but the harder work is the control architecture a firm has to stand up behind them.
For the AML/KYC control area specifically, this is the case for verifier-private attestations. At Verifyo, a firm can prove the identity check and AML screening were done — sanctions, PEP, adverse-media, barred, criminal and military screening captured at verification time, plus document-country and age attestation — without handing the regulator, or the next platform, a copy of the customer's documents. The other four control areas stay the firm's to evidence; capital, backing assets, redemption and market integrity are not something an identity layer touches.
The joint Bank of England and FCA approach to systemic stablecoin issuers is the part of the package least covered elsewhere (2). It sits at the regulatory-framework level rather than the identity layer, but it marks where UK supervision is heading: the larger a stablecoin's role in payments, the more its issuer answers to two regulators at once. For consumer protection, that dual line of sight is the point — the systemic issuers move to a tighter regulatory framework precisely because their failure would be felt widely.

MiCA CASP authorisation after 1 July: the window shut, and the biggest name walked
In last week's recap we covered the approaching MiCA deadline; this is what happened when it passed. The MiCA transitional period ended across the EEA on 1 July 2026, closing the window that had let pre-existing crypto-asset service providers keep operating while they pursued authorisation (4). ESMA's public statement of 23 June 2026 told unauthorised CASPs to implement wind-down plans by that date, and national competent authorities are now enforcing. "By 1 July 2026, any service provider not authorised to provide services under the European MiCA Regulation must have implemented its wind-down plan," ESMA set out (3).
The biggest name in the market did not get an exemption. On 26 June 2026 Binance told EU users it would suspend most services from 1 July — new orders, deposits, sign-ups and staking — after withdrawing its Greek MiCA application on 24 June, though user funds remain withdrawable. "Your assets remain safe and secure, and will remain accessible at all times," Binance told users (5). Authorisation, not scale, now gates EU market access, and the largest exchange stepping back from most EU services is the clearest evidence of it.
The consolidation behind that headline is stark. CoinDesk reported on 29 June 2026 that only 244 firms held MiCA CASP authorisation against more than 3,000 pre-MiCA registrations across EU member states; Poland alone had over 1,400 registrations but a single licensed firm (6). The transitional period and its national grandfathering are gone, and EU crypto volume is concentrating into a small authorised cohort whose compliance stack is now the moat. One point the guides tend to omit: a UK firm serving EU clients still needs an EU CASP authorisation. The UK and MiCA regimes stack; they do not substitute for one another.
For that surviving cohort, evidencing MiCA-grade onboarding at scale has become a survival-tier decision, and the choice between storing raw PII on every platform or producing a reusable proof is where onboarding cost and breach exposure both sit. This is the problem verifier-private attestations are built for: a natural person verifies once, and each platform receives proof of identity and AML screening rather than another copy of the documents.
The Aflac breach re-prices the cost of storing KYC data
On 30 June 2026 Aflac disclosed, via an SEC Form 8-K, that an intrusion into its Japan subsidiary between 15 and 25 June 2026 exposed policy details, personal information and bank-account data for approximately 4.38 million customers and agents (7)(8). "Certain impacted files contain policy and coverage details, personal information, and bank account information," the filing stated (7).
Stored policyholder identity and bank data is a honeypot, and this is the week's clearest illustration that centralised PII is a liability rather than an asset. Aflac joins a pattern of identity and KYC data breaches where the damage scales with how much personal data sat in one place. The mechanism is not exotic: a central store of identity data is worth stealing precisely because it is central. It lands in the same week the FCA asked firms to evidence their checks and MiCA raised the onboarding bar — two pressures that, handled the usual way, push firms to collect and retain still more identity data.
This is the strongest argument of the week for a different default. Zero-knowledge proofs and selective disclosure let a platform confirm that a person passed identity verification and AML screening without receiving, or storing, the underlying documents. A Zero-Knowledge KYC attestation keeps that class of personal data out of a breachable central store rather than concentrating it for exfiltration. It does not prevent an intrusion — no architecture does — but it changes what an intruder finds after they get in. This is a data-minimisation argument about where identity data lives at verification and reuse, and it is the case we build Verifyo around.

A closing note: compliance evidence should be checkable
On 29 June 2026 Chainalysis published a proposed ontology for crypto-tracing analytics, arguing that providers should show their methodology and submit to independent testing rather than deliver opaque results (9). "When people start stepping away from independent scrutiny about their methodologies, like independent testing, that's a clear danger sign," the firm's chief scientist said (9).
The principle travels beyond blockchain analytics. Compliance evidence — whether it is a transaction trace or an identity check — should be independently verifiable and methodology-transparent. Chainalysis occupies transaction tracing, not identity: Verifyo handles the identity-verification side, and transaction-monitoring tools like Chainalysis handle the transaction side. Different parts of the compliance stack, held to the same standard — an assertion is only as good as a third party's ability to test it. Verifiable, privacy-preserving attestations meet that standard for identity, because they prove a check happened without exposing the personal data behind it.
What to watch
The week's four events converge on a single instruction to anyone building in a regulated market: build so you can produce the evidence, and stop storing the data whose only job was to prove it. The FCA made producible evidence the price of a licence, MiCA made it the price of survival, and Aflac made the cost of the old way legible in 4.38 million records. Evidence you can produce, data you shouldn't store — two halves of the same design decision.
The dated markers ahead are worth holding in view. The UK cryptoasset authorisation gateway is expected to open on 30 September 2026, with PASS pre-application meetings from July 2026 and the regime in force on 25 October 2027 (10). In the EU, AMLA is due to finalise its regulatory technical standards — including the Article 28(1) AMLR customer due diligence RTS — by July 2026, and FATF opened its revised Recommendation 16 cross-border payment consultation in the week of 22 June 2026. These are regulatory-landscape markers rather than our remit; the AMLA due-diligence standards and the FATF work in particular sit outside what any single identity provider does. We are watching them because they set the baseline that the evidence — whoever produces it — will have to meet.
Sources
- FCA. FCA sets landmark crypto rules to cement UK's place as a global hub. 30 June 2026. https://www.fca.org.uk/news/press-releases/fca-sets-landmark-crypto-rules-cement-uks-place-global-hub
- Bank of England & FCA. The Bank of England's and FCA's approach to joint regulation of systemic stablecoin issuers. 30 June 2026. https://www.bankofengland.co.uk/paper/2026/boe-and-fcas-approach-to-joint-regulation-of-systemic-stablecoin-issuers
- AMF France (relaying ESMA). End of the MiCA transitional period: ESMA sets out its expectations for professionals and warns retail investors. 23 June 2026. https://www.amf-france.org/en/news-publications/news/end-mica-transitional-period-esma-sets-out-its-expectations-professionals-and-warns-retail-investors
- ESMA. Markets in Crypto-Assets Regulation (MiCA). https://www.esma.europa.eu/esmas-activities/digital-finance-and-innovation/markets-crypto-assets-regulation-mica
- CoinDesk. Binance Tells EU Users It Will No Longer Provide Services After Failing to Secure MiCA License. 26 June 2026. https://www.coindesk.com/policy/2026/06/26/binance-tells-eu-users-it-will-no-longer-provide-services-after-failing-to-secure-mica-license
- CoinDesk. Europe's Unlicensed Crypto Firms Face Wipeout as Final Regulatory Deadline Falls. 29 June 2026. https://www.coindesk.com/policy/2026/06/29/europe-s-unlicensed-crypto-firms-face-wipeout-as-final-regulatory-deadline-falls
- Aflac Inc. Form 8-K (Item 1.05 — material cybersecurity incident, Aflac Japan). 30 June 2026. https://www.sec.gov/Archives/edgar/data/0000004977/000162828026046124/afl-20260630.htm
- BleepingComputer. Insurance giant Aflac discloses data breach after subsidiary hack. 30 June 2026. https://www.bleepingcomputer.com/news/security/insurance-giant-aflac-discloses-data-breach-after-subsidiary-hack/
- CoinDesk. Crypto Analytics Firm Chainalysis Proposes Standards for Blockchain Tracing. 29 June 2026. https://www.coindesk.com/policy/2026/06/29/crypto-analytics-firm-chainalysis-proposes-standards-for-blockchain-tracing
- FCA. Cryptoasset regulation: a new regime for cryptoasset activities. https://www.fca.org.uk/firms/new-regime-cryptoasset-regulation
Want to learn more?
Explore our other articles and stay up to date with the latest in zero-knowledge KYC and identity verification.
Browse all articles