Traditional finance had a decade-long head start on this problem. BaFin was writing algorithmic-decision principles in 2018, and by the time the EU AI Act existed in draft form, banks and insurers across the European Union had years of supervisory precedent to work from. Crypto has no equivalent runway. MiCA’s transitional period for crypto-asset service providers closed on 1 July 2026 with no extension anywhere in the Union, and autonomous AI agents that hold wallets, execute trades, and move funds without a human clicking «confirm» arrived on the scene at almost exactly the same moment. Two immature regulatory problems are colliding in real time, and the collision has stopped being theoretical.

Binance made that concrete in September. Having withdrawn its MiCA application in Greece and halted most retail services across the EU from 1 July 2026, the exchange spent the same week pitching «Agent OS» — a system built to let AI agents trade automatically within user-defined limits, framed explicitly as a new class of exchange customer rather than a new class of user interface. A major global exchange, locked out of the EU retail market for lacking MiCA authorization, is simultaneously building the infrastructure for autonomous agents to become account holders in the markets it can still serve. That’s the tension this article is about, playing out in public rather than in the abstract.

The Question MiCA’s Drafters Never Answered

MiCA defines a crypto-asset service provider around a specific structure: a legal entity authorized to provide crypto-asset services to clients. That framing assumes a service is being provided to someone, by an identifiable operator, on a commercial basis. An AI agent that automatically converts tokens or executes trades based on market conditions — the kind of thing Binance is now actively marketing — can functionally resemble an investment or payment service provider without ever being licensed as one, and MiCA’s Title V doesn’t clearly say who — the user, the developer, or the platform hosting the agent — would actually be the regulated party in that scenario.

ESMA has drawn one boundary here. The regulator has confirmed that non-custodial software falls outside the CASP definition, because it doesn’t hold client assets or provide a service «on behalf of» a client — a desktop trading bot executing your own transactions with your own private keys isn’t a CASP, and MiCA doesn’t reach it . That clarity disappears the moment an agent takes custody of assets, executes trades as an intermediary, or manages a pooled position across multiple users. Binance’s Agent OS sits close to that line by design: it operates within a licensed exchange’s own infrastructure, but the trading decisions themselves come from an autonomous system acting inside limits a human set once and then stopped supervising in real time.

Legal scholarship on agentic payments has flagged the same structural problem from a different angle. Agentic transactions pose real challenges for AML and KYC compliance because agents can process enormous volumes of activity while struggling to replicate the judgment a human compliance officer would apply, and when they operate without direct human oversight they can obscure the true origin and destination of funds — undermining the exact objectives MiCA and the EU’s AML framework were designed to protect . One analysis calls MiCA «complementary but equally incomplete» on this point: it has detailed rules for custody, transfer, and consumer protection, but nothing that addresses what happens when the party initiating a transaction is an autonomous agent rather than a company or an employee.

What Already Binds an AI System Working Inside a Licensed CASP

Ambiguity about fully autonomous agents doesn’t mean nothing applies. Where an AI system operates as part of a service a licensed CASP already provides, MiCA’s existing obligations reach it in full, and «the algorithm did it» doesn’t reduce anyone’s liability.

Start with the Travel Rule. MiCA’s Article 82 incorporates the FATF framework, requiring transfers above €1,000 to carry originator and beneficiary information throughout the transfer chain. An AI agent initiating crypto transfers on behalf of a CASP has to enforce that threshold, collect the required data before a transfer executes, and screen against sanctions lists before completion — the same standard a human operations team answers to, applied to code that might make the decision in milliseconds rather than minutes.

A newer obligation adds a human layer on top of that. ESMA’s knowledge and competence rules under Article 81(7) took effect on 28 July 2026, requiring staff who give information or advice about crypto-assets to meet defined competence standards. That matters directly for AI agents fielding customer questions or executing trades on a client’s behalf: if a human employee still has to sign off on, configure, or supervise what the agent does, that employee has to meet the Article 81(7) bar regardless of how much of the actual decision-making has been delegated to the model. A firm can’t route advisory-type functions through an AI system as a way of sidestepping a competence requirement written for people.

Record-keeping carries similar weight. Article 75 requires CASPs to keep records of all services and transactions for at least five years . For an AI-driven operation, that means logging every automated decision — every transfer initiated, every trade executed, every wallet created — in a form a supervisor can reconstruct later. A firm that can’t explain, eighteen months on, why its AI agent moved a particular sum to a particular address hasn’t satisfied Article 75 just because a model made the call instead of a person.

Conflicts of interest work the same way. MiCA requires CASPs to identify and manage them, and that obligation doesn’t care whether a human trader or a trained model made the call. If an AI system consistently routes volume toward the platform’s own liquidity, a connected market maker, or an affiliated token, the firm still owns that conflict. No employee has to have pressed a button for the duty to apply.

When an AI Agent Starts Sounding Like a Market Manipulator

Nobody drafting Article 91 had generative AI in mind. Even so, the provision covers more AI-adjacent behavior than it looks like at first read. It bans entering orders that send false signals about supply or demand, pushing a price to an artificial level, using deceptive devices to create a misleading impression, and spreading information about a token’s price or demand that the person spreading it knew, or should have known, was false .

One clause deserves particular attention for anything built on generative AI. Article 91(3) treats it as market manipulation when a person voices an opinion about a crypto-asset through media — «including the internet» — after taking a position in that asset, then profits from the resulting market impact without disclosing the conflict . Picture an AI-driven content agent posting bullish commentary about a token the operator holds, without disclosing the position. That’s exactly the behavior this clause was written to catch, and it doesn’t matter whether the words came from a person typing or a model prompted to sound like one. MiCA’s market abuse framework closely tracks the EU’s existing rules for securities markets, though legal analysis has flagged one apparent gap — no explicit prohibition on benchmark manipulation — that may still be captured indirectly through the broader «false or misleading signals» language.

Article 66 covers the customer-facing side of the same problem. CASPs have to act honestly, fairly, and professionally in clients’ best interests, and every communication — including marketing — has to be fair, clear, and not misleading, with marketing content clearly labeled as such . A generative AI chatbot answering questions about a token’s prospects is a «communication» for these purposes whether or not a compliance officer read the specific output before a client saw it. A hallucinated claim about guaranteed returns isn’t a technical glitch under MiCA. It’s a breach of Article 66 with the CASP’s name attached to it.

None of this is abstract, and it’s getting less abstract by the month. MiCA’s penalty regime allows fines of up to 12.5% of annual turnover for legal entities, up to €700,000 for natural persons, temporary or permanent bans from providing CASP services, and public disclosure of the sanction . The EBA opened a formal consultation on the methodology for calculating those fines, closing 28 September 2026 — a sign that the penalty framework is moving from statutory text to an actual, applied calculation regulators intend to use rather than a number that exists mainly for deterrence.

 

DORA Puts a Crypto Firm’s AI Infrastructure Under Direct EU Oversight

Operational resilience adds a layer that’s easy to underweight. Every CASP authorized under MiCA Title V counts as a DORA «financial entity» under Article 2(1)(s), covering custody, administration of crypto-assets, and every other MiCA-licensed activity . DORA draws no line between crypto and traditional finance on operational resilience . A CASP running an AI-driven trading engine or fraud-detection system faces the same ICT risk-management obligations a bank does — and unlike MiCA itself, DORA never had a separate transitional period for crypto firms. Several national competent authorities are now assessing ICT and DORA readiness directly as part of the CASP authorization decision, effectively fusing licensing and operational-resilience review into one process rather than treating them as sequential steps.

What changes the calculus for AI specifically is DORA’s third-party oversight regime. The European Supervisory Authorities designated the first cohort of Critical ICT Third-Party Providers under DORA’s Chapter V in late 2025, and the list includes the exact infrastructure most AI-driven crypto operations run on: Amazon Web Services, Google Cloud, and Microsoft, among sixteen other firms spanning cloud, data, and enterprise software . Google Cloud’s designation specifically names «AI/ML» among its primary services under DORA’s criticality assessment . A CASP building AI agents on top of a major cloud provider’s machine learning stack sits downstream of infrastructure the EU directly supervises — subject to threat-led penetration testing, information requests, and on-site inspection by a Lead Overseer . Documenting your own AI governance isn’t enough. You also need to track how your cloud AI/ML dependencies fit into a register of critical providers that Brussels, not your compliance team, ultimately oversees.

 

AMLA Is Already Building the Toolkit This Problem Needs

The EU’s anti-money-laundering apparatus hasn’t ignored the crypto-specific angle either. The EBA’s 2025 report on AML/CFT SupTech tools documents at least one national authority that built a crypto transaction risk monitoring tool using blockchain analytics to refine supervision and risk classification . That’s a direct precedent for the kind of system a CASP would need to build its own AML monitoring around, and it signals something worth sitting with: supervisors are running AI-driven analysis over the same blockchain data crypto firms are obligated to monitor themselves.

That work now sits under the Anti-Money Laundering Authority, AMLA, which is expected to take direct supervisory power over a subset of high-risk financial entities in the coming years, with cross-border crypto firms squarely within its intended remit. For a CASP relying on an AI-driven transaction monitoring system to meet its own AML obligations, the practical effect is a rising bar rather than a falling one — the regulator building comparable tools for itself makes it harder to argue that a lighter-touch AI system on the CASP’s side counts as «adequate.»

 

The AI Act’s Blind Spot for Crypto Just Got Formally Confirmed

Here’s where crypto’s situation genuinely diverges from the rest of financial services, and it’s no longer a matter of interpretation. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and is now settled law rather than a Commission proposal. It confirms that Chapter III’s substantive obligations for standalone Annex III high-risk systems — including creditworthiness assessment and credit scoring under point 5(b), and life and health insurance pricing under point 5(c) — now apply from 2 December 2027, not August 2026. Product-embedded high-risk systems under Annex I get until 2 August 2028. Crypto trading, custody, and portfolio management still appear nowhere in Annex III at all, deferred deadline or not.

That means the AI Act’s heavier machinery — fundamental rights impact assessments, conformity documentation, human-oversight duties tied to a specific risk classification — never attaches to an autonomous crypto trading agent the way it will eventually attach to a credit-scoring model. What did take effect on schedule, unaffected by the Omnibus, are the AI Act’s general-purpose AI provisions under Articles 102 to 110, live since 27 July 2026, along with Article 50’s transparency duties for any system that talks to a customer directly. An AI agent trading crypto through something like Binance’s Agent OS still has to disclose that it’s an AI system if it interacts with a retail user, but the deeper Annex III risk-management regime that lenders and insurers are now building toward has no crypto equivalent on the horizon at all. Whatever protection an EU crypto customer gets from an AI trading agent going wrong has to come from MiCA, DORA, and general consumer protection law, not from the piece of legislation most people assume covers «AI risk» comprehensively.

 

A Grandfather Clause That Expired Right as Agents Multiplied

Timing sharpened this collision further. MiCA’s transitional period — the window letting crypto firms operate under pre-MiCA national licenses without full MiCA authorization — closed on 1 July 2026 under Article 143(3), with no extension available anywhere in the EU. ESMA’s statements through the summer were blunt about the consequence: any entity serving EU crypto clients without a MiCA license is in breach of EU law and has to stop. By September, ESMA’s posture had visibly hardened from a one-time announcement into standing enforcement guidance — a formal statement on wind-down expectations, reissued and reinforced through the following months, covering client onboarding freezes, marketing restrictions, and continued AML controls throughout the exit, including customer due diligence, transaction monitoring, sanctions screening, and transfer traceability.

Binance is the clearest illustration of what that actually costs a firm in practice: a global exchange withdrawing its own MiCA application and shutting down most EU retail activity rather than complete authorization on the current timeline. That happened at the exact moment agent-driven trading products were maturing enough for the same exchange to market them as a new customer category elsewhere. There’s no soft landing available for a platform that bet on transitional cover lasting longer, or on agentic activity sitting outside MiCA’s scope by default. ESMA has also made clear that authorized CASPs onboarding clients migrating from unauthorized platforms have to run full, fresh AML/CFT checks rather than treating the migration as a formality , closing off the obvious workaround of quietly moving users and their AI-managed portfolios from an unlicensed platform onto a licensed one without new diligence.

 

Building an AI Agent Into a Regime That’s Still Being Finished

The overall picture here looks different from the one in traditional finance. Banks and insurers are layering AI oversight onto decades of settled prudential law, inside a supervisory culture that had already been asking algorithmic-governance questions since 2018. Crypto firms are dealing with AI-driven agents that arrived before MiCA finished its own rollout, in a market where the AI Act has now formally confirmed it won’t classify crypto activity as high-risk at all, and where nobody — ESMA, national regulators, or the courts — has settled who answers for it when a fully autonomous agent, rather than a licensed entity’s employee, initiates a transaction that breaks the rules.

That uncertainty isn’t the same thing as safety, and it shouldn’t be read as one. The obligations that clearly do apply attach the moment a licensed CASP puts an AI system into production: the Travel Rule, the new Article 81(7) competence standard for anyone supervising an advisory-type agent, five-year record-keeping, conflicts-of-interest management, the market manipulation and fair-communication provisions, DORA’s ICT risk framework reaching into a CASP’s cloud AI/ML dependencies, and AML monitoring standards a well-resourced supervisor is actively raising. None of that waits for a settled answer on how autonomous an agent has to be before liability shifts, and none of it is paused by the fact that Annex III’s deeper machinery has been pushed out to December 2027. A firm building an AI agent into a crypto product in the EU right now is better off treating the older, settled obligations as the ones that get enforced first — with a live fine methodology now being built around them — and treating the open questions around agent liability as risks to manage conservatively rather than gaps worth exploiting while regulators catch up.

Read more: AI Agents in EU Finance 

 

SOURCES

  1. Regulation (EU) 2023/1114 (MiCA) — full consolidated text

ESMA — Official Publications

  1. ESMA — Final Report on the Guidelines on knowledge and competence (MiCA)

  2. ESMA — Consultation Paper on Guidelines on knowledge and competence (MiCA)

  3. ESMA — Guidelines on suitability and periodic statements (MiCA)

  4. ESMA — Consultation Paper on RTS for market abuse and guidelines on investor protection and operational resilience

EBA — Official Publications

  1. EBA — «Consultation on methodology for setting fines under MiCA» (official consultation page)

  2. EBA — Consultation Paper on a Methodology for setting fines under MiCA (full PDF)

  3. EBA — Public Hearing presentation, «EBA MiCA Fines Methodology» (16 July 2026)

  4. EBA — Press release: «The European Banking Authority consults on a draft methodology for setting fines under MiCA»

  5. EBA — Report on the use of AML/CFT SupTech tools (2025)

Binance — Company’s Own Announcements

  1. Binance — «Introducing Binance Agent OS» (official announcement)

  2. Binance — «Binance Launches Binance Agent OS»

  3. Binance — «Binance Introduces Agent OS for Building and Deploying AI Agents»

Digital Operational Resilience Act (DORA) and Crypto

  1. Regulation (EU) 2022/2554 (DORA) — full consolidated text

AI Act and the Digital Omnibus

  1. Regulation (EU) 2024/1689 (the AI Act) — full consolidated text

  2. Regulation (EU) 2026/1744 (Digital Omnibus on AI) — Official Journal

Academic Sources

  1. Cambridge University Press — «AI Agents in Payments: Applications, Risks and Regulations,» European Journal of Risk Regulation

  2. Cambridge University Press — «Crypto-Asset Market Abuse Under EU MiCA» (M. Barczentewicz), European Journal of Risk Regulation