AMLA Is Watching: EU's New AML Authority
The EU's new Anti-Money Laundering Authority is now actively supervising crypto firms. Here's what CASPs must do before the July 2026 deadline.

A new enforcement body took its seat, quietly, at the table of European financial regulation in July 2025. The EU's centralized AML supervisory agency — the Anti-Money Laundering Authority (AMLA) — became operational. It has been watching ever since.
AMLA's expectations, as of April 2026, are unmistakable. Crypto-asset service providers (CASPs) operating in the EU must meet rigorous AML and KYC standards or face direct enforcement action. The MiCA transitional window closes on July 1, 2026 — exactly 70 days away — and the full AMLR rulebook applies from July 2027. The compliance window is narrowing fast.
What AMLA is, what it demands of CASPs, and what identity verification infrastructure firms need in place before the clock runs out are set out below. The specific Customer Due Diligence technical standards being finalised right now are covered in our analysis of AMLA's CDD RTS and what identity systems must deliver.
AMLA's Mandate and Why It Matters
Established under Regulation 2024/1620, the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) is a decentralized EU agency. EU financial crime enforcement has not seen a structural shift of this scale in a generation.
AML supervision across the EU was fragmented prior to AMLA. National financial intelligence units (FIUs) operated under different interpretations of the same directives. Sophisticated money launderers readily exploited the regulatory arbitrage opportunities that fragmentation created.
That fragmentation ends with AMLA. Its mandate includes:
- Direct supervision of up to 40 of the largest, highest-risk cross-border financial entities by 2027 — including CASPs
- Coordination of national supervisors to ensure consistent application of the AMLR
- Enforcement authority to impose administrative sanctions, including fines of up to 10% of annual turnover or €10 million, whichever is higher
- Guidance publication on high-risk crypto activities, including mixers, privacy coins, and anonymity-enhancing tools
"AMLA expects high standards against financial crime in the crypto sector." That statement, published on the AMLA website, is not a suggestion. It is a declaration of intent from an authority with real teeth.
What Changes on July 1, 2026
Enforceable since December 30, 2024, the Markets in Crypto-Assets Regulation (MiCA) still contained a transitional clause. CASPs that were already legally operating in a member state under national law could continue operating — temporarily — without a MiCA license.
July 1, 2026 is when that transitional period ends.
After that date:
| Status | Consequence |
|---|---|
| MiCA-licensed CASP | Can operate freely across the EU |
| Unlicensed CASP with transitional status | Must cease EU operations |
| Non-EU CASP without registration | Subject to immediate enforcement |
Seventeen EU member states have already closed their transitional windows early. Enforcement in France, Germany, and the Netherlands began well before mid-2026. CASPs that assumed they had until July 1 may already be out of compliance in their primary markets.
AMLA's Requirements for CASPs
Grounded in the AMLR, AMLA's requirements for crypto firms will apply uniformly from July 2027. CASPs should treat those rules as the standard today. Five areas hold the core obligations.
1. Customer Due Diligence (CDD)
Full CDD for all customers is mandated by MiCA and the AMLR. This means:
- Government-issued identity verification (live liveness check, document authentication)
- Proof of address for higher-risk customers
- Source of funds documentation for deposits above €10,000
- Ongoing monitoring for changes in customer risk profile
Simplified, checkbox KYC is over. Firms must demonstrate not just that they collected data, but how they assessed it, what risk conclusions they drew, and how consistently those conclusions apply across customer segments. That is what AMLA expects.
2. The Travel Rule
Originator and beneficiary information must accompany every crypto-asset transfer, with no minimum threshold. Operational since MiCA's enforcement began, this requirement remains one of the most technically challenging elements for smaller CASPs. Exactly what data must travel with each transaction, and how to close the compliance gap before July 1, is covered in our guide on the MiCA Travel Rule and what CASPs must have by July 2026.
Infrastructure to capture, transmit, and store Travel Rule data in a format compatible with receiving VASPs — including those outside the EU operating under FATF standards — must be maintained. Transfers linked to FATF grey-listed jurisdictions require more than account-level flags. Iraq and Bosnia-Herzegovina were both added in the June 2026 FATF plenary. Elevated customer risk scores must translate into tighter transaction-level screening.
3. Anonymous Wallets and Privacy Coins: Prohibited
This is the regulatory line that has generated the most discussion in the industry.
CASPs are prohibited under Article 79 of the AMLR from:
- Maintaining anonymous crypto-asset accounts — any account that does not have a verified, identified owner
- Transacting in anonymity-enhancing cryptocurrencies — including Monero (XMR), Zcash (ZEC) in shielded mode, and any asset designed to obscure transaction trails
Additional guidance specifically targeting crypto mixers, stealth addresses, and other privacy-enhancing techniques used to circumvent monitoring will be published by AMLA in 2026, the authority has signaled.
Delisting or restricting these products is no longer optional for CASPs currently offering privacy coin trading or non-custodial wallet interactions without identity verification. It is a prerequisite for continued operation.
4. Suspicious Transaction Reporting (STR)
Active transaction monitoring systems must be maintained, and suspicious activity must be reported to their national FIU. Monitoring that is automated, risk-calibrated, and documented — not a manual process relying on individual analyst judgment — is AMLA's expectation. Draft guidelines defining precisely what that monitoring framework must include were published by AMLA on 3 June 2026; see AMLA's ongoing monitoring guidelines for the operational requirements.
The gap between legacy compliance systems and modern AI-powered approaches is most visible here. Transaction volumes on major platforms simply cannot be matched by manual STR processes.
5. Direct Access for Authorities
"Direct, immediate, and unfiltered access" to crypto-asset account data must be provided upon request from competent authorities under the AMLR. Data architecture is implicated: firms cannot structure their systems in ways that would delay or complicate regulatory access.
The 40 CASPs Under Direct AMLA Supervision
Up to 40 CASPs will be directly supervised by AMLA by July 2027 — those operating cross-border in at least six EU member states and meeting a threshold for transaction volume or customer base. Selection criteria are still being finalized. The implication is significant.
Direct AMLA supervision, if selected, means:
- Regular inspections and information requests from AMLA itself (not just national authorities)
- Obligation to maintain a dedicated compliance interface with AMLA
- Heightened scrutiny of AML program effectiveness, including KYC processes
Whether they will be selected is not the question for large exchanges and multi-jurisdiction CASPs. Whether their compliance infrastructure will survive the inspection is.
Compliant KYC Infrastructure in 2026
Common characteristics are shared by firms that will meet AMLA's standards in 2026. Those firms have left static, document-only verification behind in favor of dynamic, continuous identity management.
Real-Time Identity Verification
Distinguishing genuine users from deepfake attacks is a baseline requirement for liveness detection — not a premium feature. Passive liveness checks are no longer sufficient, as JINKUSU CAM and similar darknet tools capable of generating real-time synthetic video have demonstrated.
Multi-layer biometric assessment combined with behavioral signals — device fingerprinting, typing patterns, session anomalies — that static deepfakes cannot replicate is what effective KYC in 2026 requires.
Autonomous Risk Assessment
Human-only compliance review is economically unsustainable given the volume and complexity of AMLA's requirements. Compliance at scale is achieved by firms deploying autonomous AI agents for KYC review — processing identity checks, flagging anomalies, and generating documented audit trails automatically.
Replacing compliance officers is not the point. Giving them the tools to manage thousands of customer risk profiles simultaneously rather than hundreds is.
Documented, Auditable Decision Trails
Firms must show their work under AMLA's audit standard. Evidence, reasoning, and timestamps must document every KYC decision — approval, enhanced due diligence trigger, rejection. AMLA inspections will be failed by systems that cannot produce this trail on demand.
Cross-Border Consistency
The same KYC standard applied consistently, regardless of which country the customer onboards in, is what AMLA expects of CASPs operating across multiple EU jurisdictions. Applying stricter KYC in high-scrutiny markets while relaxing standards in newer or lower-volume jurisdictions is a common practice this rules out.
Penalties AMLA Can Impose
There is nothing symbolic about AMLA's enforcement powers. Under the framework:
- Administrative fines of up to 10% of annual group turnover or €10 million (whichever is higher)
- Prohibition orders against senior management
- Public reprimands (reputational damage in a sector where trust is currency)
- Referral to national criminal authorities for serious breaches
A marker event for the industry will be the first significant AMLA enforcement action against a CASP — a signal of what direct EU-level supervision actually means in practice.
AMLA Readiness Before July 2026
The following checklist reflects AMLA's stated expectations for CASPs currently assessing their compliance posture:
| Requirement | Status Check |
|---|---|
| MiCA license or active application filed | Yes / In progress / No |
| Full CDD implemented for all customers | Yes / Partial / No |
| Travel Rule infrastructure operational | Yes / In progress / No |
| Anonymous accounts eliminated | Yes / In progress / No |
| Privacy coin listings reviewed and restricted | Yes / In progress / No |
| Automated STR monitoring deployed | Yes / Partial / No |
| Audit trail for every KYC decision | Yes / Partial / No |
| Direct authority access architecture ready | Yes / In progress / No |
A material compliance gap is represented by any "No" on this checklist — one that national supervisors and eventually AMLA itself will be positioned to identify.
Implications for AI-Powered KYC
What AI-first compliance vendors have been arguing for years is effectively mandated by the AMLA framework: KYC cannot be a one-time check. A continuous, documented, risk-calibrated process that adapts as customer behavior and regulatory expectations evolve is what it must be.
Firms relying on manual workflows or static SaaS KYC tools are structurally less well positioned to meet AMLA's requirements than platforms like Joinble that deploy autonomous AI agents for identity verification and compliance monitoring.
The regulatory direction is clear. The burden of proof for identity verification in the EU is moving toward a model that is continuous — not satisfied by a single onboarding check conducted years ago.
Related Reading
- How autonomous AI agents are replacing manual compliance reviews in agentic KYC
- The state of KYC in crypto 2026, the year identity became autonomous
- What the Dec 2026 EUDI Wallet deadline means for KYC
FAQ
What is AMLA and when did it start operating?
The EU's Anti-Money Laundering Authority — AMLA — became operational in July 2025. Coordinating national AML supervisors and directly supervising high-risk financial entities, including major crypto-asset service providers, is the role of this centralized EU agency.
What happens to crypto firms without a MiCA license after July 1, 2026?
EU operations must cease for CASPs that were operating under national transitional provisions but have not obtained a MiCA license by July 1, 2026. Enforcement action by national regulators and, in major cases, AMLA itself will follow continued operation without authorization.
Will AMLA directly supervise all crypto companies in the EU?
No. Up to 40 CASPs that operate cross-border in at least six EU member states and meet volume or customer base thresholds will be directly supervised by AMLA. National supervisory authority remains in place for other CASPs, who must still comply with the same AMLR standards.
Are privacy coins like Monero now banned in the EU?
Maintaining anonymous crypto accounts or transacting in anonymity-enhancing cryptocurrencies is prohibited for CASPs under Article 79 of the AMLR. Privacy coins are effectively banned from regulated EU CASP platforms as a result. Full enforceability of the prohibition begins in July 2027, but enforcement intent is being signaled by AMLA ahead of that date.
What does AMLA consider adequate KYC?
Documented, consistent, and defensible KYC processes are what AMLA expects. Firms must demonstrate how they assessed each customer's risk, what evidence supported their CDD conclusions, and how consistently those methods apply across customer segments and jurisdictions. This standard will not be satisfied by manual, undocumented processes.
How can AI agents help meet AMLA's compliance requirements?
Identity verification, customer risk-profile assessment, transaction monitoring for suspicious activity, and documented audit-trail generation can all be processed by autonomous AI agents — at the scale and speed that AMLA's requirements demand. Consistent, evidence-based decision-making across the entire customer base can be demonstrated by firms using AI-powered compliance systems, which is precisely what AMLA audits will look for.
Related Articles

DORA and KYC: Identity Vendors Are Now ICT Third Parties
DORA's ICT third-party rules apply to KYC vendors from 2025. Here's what financial firms must audit, contract, and monitor to stay compliant in 2026.

SR 26-2: The Governance Gap in AI-Powered KYC
The Fed's new model risk guidance explicitly excludes generative and agentic AI. For banks using AI in KYC, that gap is now a compliance liability.

KYB Under AMLR: The UBO Threshold Trap of 2027
44% of KYB processes will fail the EU AMLR's new UBO threshold rules from July 2027. Here's how to audit your beneficial ownership verification now.