CCamoCrypt
Regulation

How crypto is regulated, by jurisdiction

There is no global crypto regulator. This is a principles-level map of the US, EU MiCA, UK, and others, plus the FATF baseline that ties them together.

Quick answer

Crypto regulation is a patchwork because each country applies its own securities, commodities, payments, and anti-money-laundering laws, and sometimes adds new ones. The US turns on asset classification and the Howey test split between the SEC and CFTC; the EU has the dedicated MiCA framework; the UK is building a bespoke FCA regime; and FATF sets a near-universal anti-money-laundering baseline. This is education, not legal advice.

Key points

  • There is no single global crypto regulator; rules vary by country and change often.
  • The US applies existing securities and commodities law, centred on the Howey test.
  • The EU's MiCA is a dedicated, harmonised framework licensing service providers.
  • The UK is expanding from AML registration and promotions rules to a full FCA regime.
  • FATF standards create a near-universal anti-money-laundering baseline across borders.

This article explains regulatory principles for general education. It is not legal advice, it is not exhaustive, and rules differ by jurisdiction and change frequently. Anyone making decisions with legal consequences should consult a qualified professional in the relevant country.

Why there is no single answer

There is no global crypto regulator. Each country decides how its existing laws on securities, commodities, payments, consumer protection, and money laundering apply to crypto-assets, and whether to write new law on top. The result is a patchwork: an activity that is lightly regulated in one place may require authorisation in another, and the same token can be classified differently depending on the jurisdiction. What follows is a principles-level map of a few major approaches, not a compliance guide.

United States: activity and classification driven

The US approach has historically been built on applying existing federal law rather than a single dedicated statute. The central question is often whether a given transaction involves an investment contract, and therefore a security, under the Supreme Court’s Howey test. That test asks whether there is an investment of money in a common enterprise with an expectation of profit derived from the efforts of others. If a transaction meets it, securities law and the Securities and Exchange Commission’s jurisdiction are engaged.

Assets treated as commodities fall under a different regime associated with the Commodity Futures Trading Commission, which has long overseen derivatives markets. This split between securities and commodities regulators is a defining feature of the US landscape, and the boundary between the two has been the subject of extensive litigation and evolving guidance. Congress has also considered market-structure legislation intended to clarify which regulator oversees which activity. Because this area is actively changing, the durable takeaway is the framework, not any single rule: in the US, the classification of the asset and the nature of the transaction determine which body of law applies, and separate federal and state money-transmission and anti-money-laundering rules apply on top.

European Union: a dedicated harmonised framework (MiCA)

The EU took a different path with the Markets in Crypto-Assets Regulation (MiCA), the first comprehensive, EU-wide framework specifically for crypto-assets not already covered by existing financial law. Rather than leaving each member state to improvise, MiCA sets uniform rules across the bloc. Its principles include:

  • Authorisation of service providers. Crypto-asset service providers (CASPs), such as exchanges and custodians, must be authorised and supervised, and an authorisation can be passported across member states.
  • Rules for token issuers, including specific regimes for asset-referenced tokens and e-money tokens (categories that include many stablecoins), with disclosure and reserve requirements.
  • Market-integrity provisions prohibiting insider dealing, unlawful disclosure of inside information, and market manipulation, mirroring long-standing securities-market norms.
  • Consumer disclosure, including obligations around clear information and marketing.

The European Securities and Markets Authority (ESMA) works with national regulators to apply MiCA consistently. MiCA became applicable in stages, with transitional arrangements for firms already operating, so the exact obligations on a given firm depend on timing and category.

United Kingdom: building a bespoke regime

The UK has been moving from a narrower starting point toward a broader, bespoke framework. Historically the binding requirements for many firms were two: registration under the money-laundering regulations for anti-money-laundering supervision, and compliance with the financial-promotions regime, which restricts how crypto can be marketed to UK consumers and requires risk warnings. The Financial Conduct Authority (FCA) supervises these.

The UK is expanding this into a fuller regulatory regime under its financial-services legislation, bringing activities such as trading, custody, and issuance within FCA authorisation. Because the regime is being phased in, the practical obligations on a firm depend on the transition timetable. The stable principle is that the UK treats crypto activity as something to be brought inside its existing financial-regulation architecture, with the FCA as supervisor and consumer protection as a stated priority.

Other jurisdictions: a wide spectrum

Beyond these three, national approaches span a broad range:

  • Some jurisdictions have created dedicated licensing regimes and position themselves as hubs, with clear rules for exchanges, custodians, and stablecoin issuers.
  • Some regulate crypto primarily through existing securities, payments, or commodities law without a bespoke statute.
  • Some restrict or prohibit certain activities, such as trading or mining, outright.
  • Some have limited or developing frameworks, leaving significant legal uncertainty.

The point is not to catalogue every country but to recognise that classification, licensing, and permitted activities vary enormously, and that operating or using services across borders can engage multiple regimes at once.

Stablecoins: a regulatory focus everywhere

One category draws heightened attention across almost every jurisdiction: stablecoins, tokens designed to hold a steady value relative to a reference such as a national currency. Because they touch payments and can reach large scale, regulators tend to treat them more strictly than other crypto-assets. MiCA, for example, sets specific regimes for asset-referenced and e-money tokens, including reserve and disclosure requirements, and other jurisdictions have pursued dedicated stablecoin rules focused on backing, redemption rights, and issuer supervision. The recurring regulatory worry is that a widely used stablecoin which fails to hold its value could transmit stress into the broader payment system, so the principles cluster around ensuring the token is genuinely backed and reliably redeemable. As always, the specifics differ by jurisdiction and are still developing.

The global baseline: FATF

Cutting across all of this is the Financial Action Task Force (FATF), an intergovernmental body that sets anti-money-laundering and counter-terrorist-financing standards. FATF is not a regulator and cannot make law, but its recommendations are highly influential: member countries are expected to implement them, and its extension of standards to virtual-asset service providers has shaped national anti-money-laundering rules worldwide. This is why customer-identification and transaction-information requirements look broadly similar across very different jurisdictions even when the surrounding regimes diverge.

Cross-border reach and why it matters

A feature that catches many people out is that regulation frequently follows the customer, not the server. Several regimes apply based on where users are located rather than where a business is incorporated, so a platform can fall under a country’s rules by serving that country’s residents even without a local office. This is why services sometimes restrict access by geography, decline users from particular jurisdictions, or require region-specific onboarding. It is also why the map above cannot be read as a menu from which a business simply picks the friendliest option: offering services internationally can engage several regimes simultaneously, each with its own authorisation, disclosure, and anti-money-laundering demands. For an individual, the corollary is that the rules that bind a service you use may be those of your own country, regardless of where the service is based.

Common themes to hold onto

Despite the fragmentation, a few principles recur almost everywhere:

  • Function over form. Regulators increasingly look at what an arrangement does economically, not merely what it is called, when deciding which rules apply.
  • Intermediaries are the primary point of regulation. Exchanges, custodians, and other service providers bear most of the licensing, disclosure, and anti-money-laundering burden.
  • Anti-money-laundering obligations are near-universal, shaped by FATF standards.
  • Consumer protection and market integrity are consistent stated goals, even where the mechanisms differ.

Use this as orientation, not as a checklist. The specifics change, definitions differ across borders, and only a qualified professional in the relevant jurisdiction can tell you how the rules apply to a particular situation.

Sources

Frequently asked questions

Is there a single global crypto regulator?
No. Each jurisdiction applies its own laws and may add dedicated rules. Bodies like FATF set influential standards that countries implement, but FATF is not a regulator and cannot make law itself.
What is the Howey test?
It is a US Supreme Court standard for whether a transaction is an investment contract, and therefore a security. It asks whether there is an investment of money in a common enterprise with an expectation of profit from the efforts of others.
What does MiCA do?
MiCA is the EU's dedicated, bloc-wide framework for crypto-assets not covered by existing financial law. It requires authorisation of service providers, sets rules for token issuers including many stablecoins, and prohibits market abuse.
Does this article count as legal advice?
No. It is general education about regulatory principles. Rules differ by jurisdiction and change frequently, so anyone with a specific legal question should consult a qualified professional in the relevant country.
Why do anti-money-laundering rules look similar across countries?
Because most follow FATF recommendations. FATF's extension of its standards to virtual-asset service providers has shaped national rules worldwide, producing broadly similar customer-identification and transaction-information requirements even where other rules diverge.

Note: CamoCrypt is security & education only — no prices, no predictions, no investment advice. Verify every address and contract yourself; we cannot recover lost funds and neither can anyone who contacts you claiming they can.