Most people assume anti-money laundering rules in Europe are basically settled — a patchwork of national regulators quietly checking boxes in the background. That assumption is about to be wrong in a fairly dramatic way because the EU has spent the last two years building something it’s never had before: a single, centralized authority with the power to directly supervise the riskiest financial institutions across the entire bloc, crypto firms very much included.

From National Patchwork to a Single Authority

For decades, AML enforcement in Europe ran through national financial intelligence units — one per member state, each reading the same EU directives a bit differently depending on local habits and priorities. The result was predictably uneven. Two banks doing the exact same thing in two different countries could face totally different levels of scrutiny, just because one national regulator happened to be paying closer attention than the other. That inconsistency didn’t go unnoticed either — it became a known workaround, a way for bad actors to route activity through whichever country was watching least closely.

The EU’s answer was the Anti-Money Laundering Authority, or AMLA, born in June 2024 and headquartered in Frankfurt. It picked up its actual powers in July 2025, and by January 1, 2026, it was financially independent and had absorbed every AML mandate the European Banking Authority used to carry. So far, though, nobody’s being directly supervised. AMLA is still in setup mode — building risk models, writing technical standards, working out coordination with national regulators. That changes once AMLA names its first batch of roughly 40 high-risk entities in 2027. Direct oversight actually kicks in on January 1, 2028.

That’s not replacing national FIUs entirely — those still exist and will keep handling the bulk of day-to-day supervision for everyone outside the directly supervised group. But once 2028 arrives, AMLA sits above them with direct supervisory power over a specific list of the highest-risk financial entities operating across multiple member states, selected specifically for their cross-border footprint and risk profile. That’s a genuinely new model for the EU, closer to how the European Central Bank supervises major banks directly rather than leaving it entirely to national central banks.

What makes this more than a bureaucratic reshuffle is who’s expected to end up on that list. AMLA has explicitly flagged crypto and «novel payment channels» as emerging risk areas it intends to focus on as it finalizes its selection methodology through 2026 and 2027. For an industry that just spent two years getting comfortable with MiCA licensing, that’s a strong signal that a second, parallel layer of EU-level AML scrutiny is coming for the largest cross-border crypto firms — even if it’s not live yet.

Why the Runway Matters More Than the Deadline

Here’s the part that’s genuinely underappreciated: the gap between now and 2028 isn’t dead time, it’s the window during which AMLA is actively shaping the rules that firms will eventually be judged against. Throughout 2026 and 2027, AMLA is testing and calibrating its risk-based selection model, issuing binding regulatory technical standards, and running supervisory convergence guidance that shapes how national regulators handle AML enforcement even before AMLA takes over anything directly. Firms that wait until 2028 to start caring about this are, in effect, choosing to build their compliance programs against a moving target rather than getting ahead of a target that’s still being finalized.

That matters more for crypto firms than for traditional banks, honestly. A bank that’s operated for decades has generations of AML compliance infrastructure, well-worn relationships with regulators, and staff who’ve lived through multiple supervisory cycles. A CASP that only became fully MiCA-licensed in the past year or two is, by comparison, still building that muscle from scratch — right at the moment when a second, more demanding layer of EU-level oversight is actively being designed with crypto specifically in mind.

There’s also a real timing problem worth pointing out. MiCA’s transitional period just wrapped up in mid-2026, so most CASPs are barely settled into life as fully licensed entities under a brand-new framework. Now imagine a second EU-level supervisory relationship landing on top of that in 2028, right when firms have only just gotten their MiCA compliance stabilized. That’s an awkward sequence by any measure, and it’s exactly why sharper compliance teams aren’t waiting until it’s urgent — they’re already thinking it through now.

 

The €10,000 Cash Limit Nobody Talks About

If AMLA is the slow-building structural story, the €10,000 cash limit is the reform people will actually notice. It’s oddly under-discussed given how big a change it is. Article 80 of the EU’s new Anti-Money Laundering Regulation sets a hard EU-wide cap on cash payments at €10,000, and it takes effect on 10 July 2027. Past that line, cash won’t cut it anymore for goods or services — not between a business and a private buyer, not between two businesses — no matter what any individual country’s rules used to allow.

That might sound minor. It isn’t, once you see how differently countries used to treat this. Some had no limit at all. Others already had thresholds well below €10,000, and those stricter local rules stick around even after the EU cap kicks in — countries can go tighter, just not looser. What that really kills off is a loophole that’s existed for years: structuring big transactions to run through whichever country had the weakest cash rules. Once everyone shares the same floor, that trick gets a lot harder to pull off.

Worth noting: the cap doesn’t touch purely private transactions between individuals who aren’t acting professionally, and it exempts payments or deposits made directly at banks, e-money issuers, or payment institutions — though those still get reported to national FIUs. For everyday consumers, the practical effect will be fairly limited, since most people rarely move that much cash in a single transaction anyway. But for sectors that have historically leaned on large cash transactions — real estate, luxury goods, parts of the art market — 10 July 2027 represents a genuine structural shift in how business gets done, and it’s one that’s still more than a year away, meaning affected sectors have real time to adapt if they start now.

 

Crypto’s Awkward Middle Ground

Crypto occupies a weird position in all of this. It’s the sector AML rules were obviously built to target, and also the sector where actually enforcing anything has proven hardest. There’s a real irony buried in there too — blockchain transactions sit permanently on a public ledger, which in theory makes them more traceable than cash ever was. But wallet addresses are pseudonymous, funds move across borders in seconds, and that combination has kept crypto squarely in regulators’ crosshairs regardless of how traceable the underlying tech actually is.

MiCA already folded crypto firms into a formal licensing system with AML rules attached. AMLA’s direct supervision, once it starts in 2028, is expected to push further — especially on the Travel Rule, which requires crypto transfers to carry sender and recipient details the same way traditional wire transfers have for years. Simple in theory. Much harder in an industry built on decentralized infrastructure that wasn’t really designed with that kind of data-sharing in mind. It’s also exactly the kind of thing AMLA has already said it’s watching as it figures out how to handle «novel payment channels.»

What’s interesting is how this changes the competitive landscape within crypto itself, even before 2028 arrives. Firms building robust Travel Rule infrastructure and genuine AML programs now, well ahead of AMLA’s actual supervisory launch, are positioning themselves for a real structural advantage over competitors still treating it as a problem for later. As AMLA finalizes its selection criteria through 2027, the gap between firms with genuinely mature AML systems and those with bolted-on, minimal-effort compliance is going to become far more visible — and far more consequential — once direct EU-level supervision actually begins.

 

The Enforcement Question Everyone’s Watching

Nobody knows the answer to the obvious question here — does direct supervision starting in 2028 actually toughen things up, or is it just the same light-touch approach dressed up as something bigger? Reasonable people are skeptical. Look at Europe’s worst laundering scandals: plenty happened at institutions that were, technically, already under serious oversight. The rules were there. What was missing was the follow-through — either the will to enforce, or the resources to do it properly.

Supporters of AMLA push back on that read. Centralizing supervision, they argue, takes away something specific: a national regulator’s ability to quietly protect a bank or firm that happens to matter a lot locally. Put a cross-border crypto firm under an EU-level supervisor instead of a national one with its own local incentives, and the dynamic changes — at least on paper. Whether that actually plays out once AMLA runs its first real supervisory cycle is anyone’s guess right now.

What This Actually Means for Businesses Today

For any firm operating across multiple EU jurisdictions — crypto or otherwise — the practical takeaway is that AML compliance can no longer be treated purely as a jurisdiction-specific exercise, even though AMLA’s direct supervision is still roughly two years out. A compliance program built to satisfy one national FIU’s particular preferences and priorities isn’t necessarily going to hold up under AMLA’s more centralized, EU-wide standards once they’re finalized, especially for firms large enough or cross-border enough to eventually land on the direct supervision list.

That has real implications for how compliance budgets and priorities should be structured right now, well before 2028. Firms that have historically treated AML as a localized cost center, handled slightly differently in each market they operate in, will need a more unified, EU-wide approach that can withstand scrutiny from a single centralized authority rather than several loosely coordinated national ones. For crypto businesses specifically, that means Travel Rule implementation, beneficial ownership transparency, and cross-border transaction monitoring should be treated as core infrastructure investments now, rather than compliance afterthoughts layered on top of an already-built business once AMLA’s deadline actually arrives.

The €10,000 cash limit, meanwhile, is a useful reminder that AML reform in Europe isn’t only about crypto or banking — it’s a genuinely broad restructuring of how value can move through the European economy at all, in whatever form it takes, and it lands on a fixed date just three years from now. Businesses in real estate, luxury retail, and other cash-intensive sectors that haven’t historically thought of themselves as AML-adjacent have real, usable time between now and July 2027 to adjust — but that window is exactly the kind of runway that tends to get wasted if it isn’t treated as urgent early on.

None of this is settled yet, and much of it genuinely won’t be for another year or two. AMLA is still building out its actual supervisory operations, the final list of directly supervised entities won’t exist until the 2027 selection process runs its course, and how aggressively the authority chooses to enforce against the firms under its direct watch remains to be seen in practice rather than in policy documents. What is clear is that Europe is building genuinely new AML infrastructure, not just an updated rulebook — and the businesses that treat the next two years as preparation time, rather than waiting for the deadline to force their hand, are the ones that will actually be ready when 2028 arrives.

Hiring an Outsourced AML Officer / MLRO

Protegra logo, white wordmark of the European crypto accounting and AML compliance law firm


Sources:

The AMLA Regulation

AMLA’s Own Direct-Supervision Explainer