Crypto regulation by jurisdiction: the complete guide
A principles-level map of how the major jurisdictions regulate crypto-assets — the US multi-agency patchwork, the EU's MiCA, the UK's promotions regime, Asia-Pacific licensing, and the FATF travel rule. General information, not legal advice.
Last reviewed: September 2026 — security guidance re-reviewed on a six-month cycle.
Quick answer
Crypto regulation is national, not global, so the first question is always which jurisdiction applies. This guide maps the principles: the US multi-agency patchwork (SEC, CFTC, FinCEN, state licensing), the EU's single MiCA framework, the UK's AML registration and financial-promotions regime, Asia-Pacific licensing in Singapore and Japan, and the cross-cutting FATF travel rule. It is general information, not legal advice, and rules vary and change constantly.
Key points
- There is no global crypto law; obligations depend on where an activity happens and where its customers are, and regulators judge substance over labels.
- The US applies existing law through several agencies (SEC via the Howey test, CFTC for commodities and derivatives, FinCEN for AML) plus state money-transmission licences.
- The EU's MiCA (Regulation 2023/1114) is a single harmonised regime with categories for ARTs, EMTs and general crypto-assets; stablecoin rules applied 30 June 2024 and CASP rules 30 December 2024.
- The UK requires FCA money-laundering registration and, since 8 October 2023, compliance with a strict cryptoasset financial-promotions regime with criminal penalties for breaches.
- Asia-Pacific regimes diverge sharply; Singapore (Payment Services Act) and Japan (Payment Services Act, FSA) license exchanges, while other jurisdictions range to prohibition.
- The FATF travel rule (Recommendation 16) requires VASPs to transmit originator and beneficiary information for transfers at or above USD/EUR 1,000, implemented into national law worldwide.
Why jurisdiction is the first question
There is no global law for crypto-assets. What is permitted, how a token is classified, who must be licensed, and what a business must disclose all depend on where an activity takes place and where its customers are. Two people doing what looks like the same thing can face entirely different rules because one is in the European Union and the other in the United States. This guide sets out the principles that shape the major regimes so that the landscape is legible. It is not legal advice, it does not tell you whether any activity is lawful for you, and the details it describes change frequently. Anyone with a concrete question needs advice from a qualified professional in the relevant jurisdiction.
A few structural ideas recur everywhere and are worth stating up front. Regulators generally take a functional or substance-over-form approach: they ask what an asset or service actually does, not what it is called, so labelling a token a “utility token” or a service “decentralised” does not by itself change its treatment. Regulation typically attaches to intermediaries — exchanges, custodians, issuers, brokers — because they are identifiable entities that can be licensed and held accountable, which is why purely peer-to-peer or genuinely autonomous software is harder to regulate directly. And most regimes pursue a small set of consistent objectives: protecting consumers, preserving market integrity, ensuring financial stability, and preventing money laundering and terrorist financing.
How regulators classify crypto-assets
Almost every downstream rule depends on classification, and the categories differ by jurisdiction but rhyme. A token that represents an investment in a common enterprise with an expectation of profit from others’ efforts tends to be treated as a security and pulled into existing securities law. A token used primarily as a means of exchange or a store of value may be treated as a commodity, a payment token, or fall outside securities law. Tokens designed to hold a stable value against a currency or basket are increasingly carved out as their own category — stablecoins — with bespoke rules. And tokens that give access to a product or service are sometimes called utility tokens, though regulators scrutinise that label closely because many purported utility tokens function as investments.
The practical point is that classification is not a formality. It determines whether an offering needs a prospectus or whitepaper, whether a trading venue needs an exchange or securities licence, whether marketing is restricted, and which regulator has jurisdiction. Because the tests are fact-specific and applied case by case, the same token can be treated differently in different countries, and a token’s status can change as a project evolves from a fundraising phase to a functioning network.
United States: a fragmented, multi-agency landscape
The United States has no single crypto statute. Instead, several federal agencies apply existing law to crypto according to how they classify the asset or activity, and fifty states add their own money-transmission regimes on top. This fragmentation is the defining feature of the US approach.
Securities regulation
The Securities and Exchange Commission (SEC) asserts jurisdiction over crypto-assets it considers securities, applying the long-standing Howey test, which asks whether there is an investment of money in a common enterprise with an expectation of profit derived from the efforts of others. If a token meets that test, offering or trading it can trigger registration and disclosure obligations designed for securities, and platforms that list it may need to register as securities exchanges or broker-dealers. The application of Howey to specific tokens has been contested and litigated, which is one reason US treatment can feel unsettled.
Commodities and derivatives
The Commodity Futures Trading Commission (CFTC) treats certain crypto-assets as commodities and has authority over crypto derivatives markets and over fraud and manipulation in spot markets. The boundary between the SEC’s and CFTC’s remits is one of the central unresolved questions of US crypto policy, and legislative proposals to divide it have been debated repeatedly.
Anti-money-laundering and state licensing
The Financial Crimes Enforcement Network (FinCEN) applies the Bank Secrecy Act to many crypto businesses, which it treats as money services businesses subject to registration, recordkeeping, and suspicious-activity reporting. Separately, most states require a money transmitter licence to serve their residents, so a business often needs a patchwork of state approvals in addition to federal compliance. New York’s BitLicense is the best-known state-specific regime.
European Union: MiCA as a single harmonised framework
The EU has taken the opposite path to the US: a single, comprehensive regulation. The Markets in Crypto-Assets Regulation, Regulation (EU) 2023/1114 (MiCA), creates uniform rules across all member states for crypto-assets that are not already covered by existing financial-services law. Because it is a regulation rather than a directive, it applies directly and largely identically across the bloc, and authorisation in one member state can be passported to operate across the others.
What MiCA covers
MiCA divides crypto-assets into categories with tailored rules. Asset-referenced tokens (ARTs) purport to hold a stable value by reference to a basket of currencies, commodities, or other crypto-assets. E-money tokens (EMTs) reference a single official currency. Everything else that is a crypto-asset but not already a financial instrument falls into a general category. Issuers face disclosure obligations, including publishing a crypto-asset whitepaper, and issuers of the stablecoin categories face additional prudential and reserve requirements reflecting financial-stability concerns.
Service providers and timing
Crypto-Asset Service Providers (CASPs) — exchanges, custodians, brokers, and similar — must be authorised and meet organisational, prudential, and conduct requirements, and a market-abuse regime applies to crypto trading. MiCA came into force in phases: the stablecoin provisions (covering ARTs and EMTs) became applicable on 30 June 2024, and the CASP authorisation regime and the remainder became applicable on 30 December 2024, subject to transitional arrangements that member states could apply to existing firms. The direction of travel is a mature, licence-based single market, which is a marked contrast to the US patchwork.
United Kingdom: AML registration and a promotions crackdown
The United Kingdom left the EU before MiCA and has built its own approach incrementally, with a broader regime under construction. Two elements are already firmly in place.
Money-laundering registration
Cryptoasset businesses operating in or into the UK must register with the Financial Conduct Authority (FCA) under the Money Laundering Regulations and meet anti-money-laundering and counter-terrorist-financing obligations. This registration is an AML gateway, not a stamp of consumer protection — the FCA is explicit that registration does not mean deposits are protected by the Financial Services Compensation Scheme.
The financial-promotions regime
Since 8 October 2023, the UK has applied a financial-promotions regime to qualifying cryptoassets. Marketing crypto to UK consumers must be done through one of a limited set of permitted routes, must be fair, clear and not misleading, and must carry prominent risk warnings and, in many cases, a cooling-off period for first-time investors. Making a non-compliant promotion can be a criminal offence under the Financial Services and Markets Act. Notably, unlike some other financial promotions, there is no blanket exemption for high-net-worth or sophisticated investors. The UK has signalled that a fuller regulatory framework bringing more crypto activities within the regulatory perimeter is being developed, so this area is actively evolving.
Asia-Pacific: licensing regimes that diverge sharply
Asia-Pacific is not a single market but a set of national regimes that range from structured licensing to outright prohibition. Two of the most developed illustrate the spread.
Singapore
Singapore regulates crypto principally through the Payment Services Act, administered by the Monetary Authority of Singapore (MAS), which came into force in January 2020. Firms providing digital payment token services must be licensed, and licensing tests governance, capital, custody, technology-risk, and AML/CFT controls. MAS has combined a relatively clear licensing pathway with public caution about the suitability of crypto for retail consumers and restrictions on how it may be marketed to the public.
Japan
Japan was an early mover and regulates crypto exchanges under its Payment Services Act, supervised by the Financial Services Agency (FSA). Exchanges must register as crypto-asset exchange service providers and meet requirements on custody, segregation of customer assets, and AML. Japan has also developed a specific framework treating certain stablecoins as electronic payment instruments. Other jurisdictions in the region vary widely, from active licensing to bans, which is why the regional picture cannot be generalised and each market must be assessed on its own terms.
The cross-cutting layer: AML, CFT and the FATF travel rule
Sitting above every national regime is a set of global anti-money-laundering standards set by the Financial Action Task Force (FATF). FATF’s recommendations are not binding law, but member countries implement them into national law, which is why AML obligations look broadly similar across otherwise different regimes.
In 2019 FATF extended its standards to virtual assets and virtual asset service providers (VASPs) — broadly, exchanges, custodians, and similar intermediaries. The most consequential element is the travel rule under Recommendation 16. It requires that when a VASP sends a virtual-asset transfer at or above a threshold (FATF’s designated de minimis is USD/EUR 1,000), it must collect and transmit identifying information about both the originator and the beneficiary to the receiving institution, mirroring the rule that has long applied to bank wires. The aim is to remove the anonymity of intermediated transfers so that illicit flows can be traced.
The travel rule is a compliance obligation on intermediaries, not on individuals, but it shapes the user experience: it is why regulated platforms increasingly ask about the counterparty when you withdraw, and why transfers between regulated venues carry identifying data. Implementation details — the exact threshold, the treatment of self-hosted wallets, and technical standards for transmitting the data — vary by country, which is a recurring source of friction between platforms in different jurisdictions.
Stablecoins and DeFi under regulation
Two areas deserve separate mention because they test the edges of every framework. Stablecoins have moved to the centre of regulatory attention because a widely used token that promises redemption at par raises the same financial-stability and consumer-protection questions as money and payments. MiCA’s dedicated ART and EMT regimes, Japan’s electronic-payment-instrument framework, and active legislative work in other jurisdictions all reflect a common instinct: a token that behaves like money should be backed by real reserves, be redeemable, and be issued by an accountable, supervised entity.
DeFi is harder still, because the premise of much regulation — an identifiable intermediary to license — is precisely what a genuinely decentralised protocol lacks. Regulators are grappling with where responsibility lies when there is no company: with the developers, the governance-token holders, the front-end operator, or no one. The practical reality is that most “DeFi” users still touch a regulated on- or off-ramp somewhere, and that many nominally decentralised systems have identifiable operators. The regulatory perimeter around DeFi is unsettled and is one of the most actively debated questions in the field; nothing in this guide should be read as a claim about how any specific protocol will be treated.
What most regimes are actually trying to protect
Beneath the differences, the major frameworks pursue a recognisable set of protections, and understanding them makes any specific rule easier to predict. Custody and asset segregation rules aim to ensure that when a platform holds customer assets, those assets are kept separate from the firm’s own and are returnable if the firm fails; this is a direct response to failures in which customer funds were commingled and lost. Prudential requirements — minimum capital, governance, and risk controls — are meant to make regulated firms resilient enough not to collapse in the first place. Disclosure rules, such as MiCA’s whitepaper obligation, aim to give buyers a baseline of accurate information rather than marketing claims. Market-abuse rules target insider dealing and manipulation on trading venues. And conduct and marketing rules, exemplified by the UK promotions regime, aim to ensure ordinary consumers are not misled about risk.
Two activities attract particular scrutiny under these headings because they blur the line between a service and a regulated financial product. Custodial staking-as-a-service and yield or lending programmes offered by platforms — where a firm takes customer assets and offers a return — have repeatedly drawn regulatory attention, because to a regulator they can resemble taking deposits or offering an investment product, triggering licensing and disclosure obligations regardless of the crypto-native framing. This is a clear instance of the functional approach in action, and a reminder that how an activity is described matters far less than what it does.
Where the perimeter is still being drawn: NFTs, tokenised securities and enforcement
Two token types sit awkwardly across the classifications above and illustrate why substance-over-form matters. Non-fungible tokens (NFTs) are often assumed to be outside financial regulation because they represent unique items such as art or collectibles. But regulators look at function, not the technical standard: an NFT marketed as a fractional interest in an asset, or sold with promises of returns, can be treated as a security or a regulated financial product regardless of the “NFT” label. Conversely, a genuine one-of-a-kind collectible may fall outside financial regulation while still attracting consumer-protection, anti-fraud, and tax rules. The label carries no protection.
Tokenised securities — traditional instruments such as shares or bonds issued or recorded on a blockchain — are the mirror image. Here the strong default is that existing securities law applies in full: putting a security on a distributed ledger changes the plumbing, not the legal character. Frameworks such as MiCA explicitly carve out crypto-assets that already qualify as financial instruments, precisely because those remain governed by the pre-existing securities regime rather than the new crypto rules.
It is also worth understanding how these regimes are enforced, in principle. Enforcement typically targets intermediaries and issuers rather than individual users, and the tools range from registration refusals and public warnings to fines, disgorgement, trading bans, and, for the most serious breaches such as unlawful financial promotions in the UK, criminal liability. The general lesson is that “the rules were unclear” is rarely a complete defence: regulators expect firms to assess in good faith whether existing law applies to what they are doing, and to seek authorisation or advice where it might.
Determining which jurisdiction’s rules apply
Because obligations follow both the operator and the customer, working out which regimes are in scope is itself a discipline. Several connecting factors commonly pull an activity into a jurisdiction: the location of the business and its staff; the location of its customers; whether it markets or solicits into a country, even from abroad; where servers or key operations sit; and sometimes the currency or market being served. The UK financial-promotions regime, for instance, reaches businesses anywhere in the world whose promotions are capable of having an effect in the UK, and MiCA’s provisions bite when services are provided within the EU. The practical result is that a single business can be simultaneously in scope in multiple jurisdictions, and that “we are based offshore” does not remove obligations toward customers located in a regulated market. Untangling this is a core reason professional advice is needed for anything operational.
How tax and regulation interact
Regulatory classification and tax treatment are separate questions decided by different authorities, and they do not always line up. A token that a securities regulator treats as a security may still be taxed under general property or capital-gains rules; a token outside financial regulation entirely may still be fully taxable on disposal. It is a common error to assume that because an asset “is not regulated” it is somehow also outside tax, or that a favourable tax characterisation implies anything about regulatory status. They are independent, and both must be considered — which is a further reason this guide, focused on regulatory principles, is not a substitute for tax advice.
How to think about compliance without treating this as advice
The useful posture is to reason from principles rather than to look for a universal answer. Identify the jurisdictions that matter — where the activity happens and where its customers are — because obligations follow customers as much as operators. Establish how the relevant assets are likely to be classified there, since classification drives everything else. Assume that any intermediary function (exchanging, custody, brokerage, issuance) is the thing most likely to require a licence. Expect AML and travel-rule obligations to apply wherever an intermediary is involved. And treat the whole area as fast-moving: MiCA is bedding in, the UK is expanding its perimeter, the US is debating how to divide its agencies’ remits, and Asia-Pacific regimes are being revised. None of this is a substitute for advice from a qualified professional in the relevant jurisdiction, and this guide does not provide legal, tax, or investment advice.
Sources
- EUR-Lex — Regulation (EU) 2023/1114 (MiCA), official text
- ESMA — Markets in Crypto-Assets Regulation (MiCA)
- FCA — Cryptoasset firms marketing to UK consumers
- FCA Policy Statement PS23/6 — Financial promotion rules for cryptoassets
- FATF — Virtual assets and VASPs (Recommendation 16 / travel rule)
- U.S. Securities and Exchange Commission — Crypto assets
- U.S. Commodity Futures Trading Commission — Digital assets
- Monetary Authority of Singapore — Payment services regulation
- Financial Services Agency of Japan
Frequently asked questions
Is there a single global set of crypto regulations?
What is the Howey test?
What does MiCA regulate?
Does FCA registration mean a UK crypto firm is safe or protected?
What is the FATF travel rule and does it apply to me?
How is DeFi regulated?
Is this guide legal advice?
Note: CamoCrypt is security & education only — no prices, no predictions, no investment advice. Verify every address and contract yourself; we cannot recover lost funds and neither can anyone who contacts you claiming they can.