July 10, 2026: AMLA's First Major Deadline, and What It Means for Crypto Compliance Teams
This week, AMLA and the European Commission must deliver a wave of technical standards and guidelines under the AML Regulation — a year before AMLR formally applies. Here's what's due on July 10, why the timing matters more than it looks, and what it means specifically for CASPs.
Most compliance teams have filed the EU AML Regulation under "2027 problem" — it doesn't formally apply until July 10, 2027, so there's a year of runway left. This week, that assumption gets tested.
On July 10, 2026 — this Friday — the Anti-Money Laundering Authority (AMLA) and the European Commission are required to deliver one of the largest batches of technical standards and guidelines since the AML Package entered into force in 2024. It isn't one document. It's close to a dozen, covering everything from customer due diligence to how sanctions on obliged entities get calculated.
For obliged entities generally, and crypto-asset service providers specifically, this is worth reading now — not in twelve months.
What's actually due on July 10
Under Regulation (EU) 2024/1624 (the AMLR) and Directive (EU) 2024/1640 (AMLD6), a specific set of deliverables carries a 10 July 2026 deadline:
| Deliverable | Owner | What it covers |
|---|---|---|
| Guidelines on CDD risk factors | AMLA | Which risk variables obliged entities must weigh when onboarding or assessing customers |
| RTS on information required for CDD | AMLA → Commission | The specific data points a due diligence file must contain |
| Guidelines on ongoing monitoring | AMLA | Standards for monitoring business relationships and transactions after onboarding |
| Guidelines on sizing internal controls | AMLA | How compliance staffing and internal policy scope should match an entity's size and risk |
| RTS on group-wide AML policies | AMLA → Commission | Minimum standards for information-sharing and control across corporate groups |
| RTS on high-risk third-country measures | AMLA → Commission | Additional safeguards for groups with branches or subsidiaries in high-risk jurisdictions |
| ITS on a common SAR template | AMLA | A standardised format for suspicious activity reports across the EU |
| Delegated acts on sanctions requirements | European Commission | Further detail on the "effective, proportionate, dissuasive" sanctions standard Member States must apply |
Separately, AMLA is also working on regulatory technical standards for how it will procedurally apply supervisory measures and pecuniary sanctions — rights of defence, limitation periods, collection — expected around the same window as part of its first-half 2026 work programme, though not tied to the same fixed date as the deliverables above.
Running on its own legal track, but landing the same day: Articles 11, 12, 13, and 15 of AMLD6, covering beneficial ownership registers, must be transposed into national law by 10 July 2026 as well. That deadline belongs to Member States, not AMLA, but it affects the same UBO data compliance teams rely on for entity screening.
One piece of this package is already visibly in motion. On July 2, AMLA held a public hearing on its draft guidelines for ongoing monitoring of business relationships — the last formal step before the guidelines are finalized. It's a useful signal for how the rest of the July 10 batch is likely to land: as final or near-final text, not early drafts.
Why a 2026 deadline matters for a 2027 regulation
It's tempting to treat this as an internal EU institutional milestone with no immediate bearing on obliged entities. That undersells it, for three reasons.
The numbers in the AMLR are not preliminary. The Regulation already fixes several thresholds that don't move regardless of how the technical standards read: the general customer due diligence threshold for occasional transactions drops to €10,000, and for crypto-asset service providers specifically, the threshold is €1,000 — with mandatory identification and verification required below that figure. The RTS due this week specify how CDD data is collected and documented; they don't change when it's triggered.
Supervisors calibrate against draft standards well before formal application. Since January 1, 2026, AMLA has held full responsibility for AML/CFT mandates previously carried by the European Banking Authority, and national regulators — BaFin, the AMF, DNB, and others — are already treating AMLA's technical standards and guidelines as the direction of travel, not waiting for the 2027 application date before asking questions about them.
The sanctions regime is getting sharper, not softer. AMLD6 already raised the ceiling for pecuniary sanctions on serious or systematic breaches from €5 million or 5% of annual turnover to €10 million or 10% of annual turnover. The procedural technical standards AMLA is developing won't change that ceiling, but they will specify exactly how it gets applied. A clearer procedure tends to mean a supervisor more willing to use it.
What this means specifically for CASPs
Two of the deliverables in this week's package are directly relevant to crypto-asset service providers, beyond the general obligations shared with every obliged entity.
Group-wide policy standards. Many CASPs operate across several EU jurisdictions under MiCA passporting, with a parent entity in one Member State and branches or subsidiaries in others. The RTS on group-wide AML policies sets the baseline for how compliance controls — and crucially, information-sharing — must work across that structure. It's directly relevant to any CASP group that isn't already running a single, centralized compliance function.
Ongoing monitoring standards. The guidelines that just cleared their public hearing cover exactly the activity a wallet screening and transaction monitoring program performs: continuous assessment of a business relationship, not a one-time check at onboarding. For CASPs already screening transactions in real time to meet the Instant Payments Regulation's 10-second window, this is the standard their existing monitoring workflow will eventually be measured against.
Neither of these changes the €1,000 / €10,000 CDD thresholds already in force in the AMLR text. But both narrow the room for interpretation in how a CASP demonstrates compliance — exactly the kind of detail that shows up in a supervisory review.
What to do this week, not next year
- Don't file this under "2027." The application date for AMLR is 10 July 2027. The standards that will define what "compliant" looks like on that date are being finalized now, and early alignment costs less than a retrofit later.
- Check your CDD workflow against the €1,000 / €10,000 thresholds. These are already fixed in the Regulation, independent of anything published this week. If your onboarding or transaction monitoring logic isn't built around them yet, that gap exists regardless of the RTS timeline.
- Revisit your group compliance structure if you operate across more than one EU jurisdiction. The group-wide RTS is aimed precisely at multi-entity structures with fragmented information-sharing.
- Read the published texts directly. AMLA publishes finalized guidelines and RTS on its regulatory instruments page as they clear adoption — this week's batch is worth reading in full rather than relying on secondary summaries.
AML Radar's Regulatory Tracker follows AMLA and Commission publications as they land, so MLROs and compliance officers don't have to monitor the Official Journal manually. Combined with the MLRO Audit Trail, it gives you a record of both what the rules said at a given moment and what your screening program actually did about it — the two things a supervisor tends to ask for together.
Conclusion
AMLA's July 10 package doesn't change the 2027 application date, and it doesn't move the CDD thresholds already written into the AMLR. What it does is remove the ambiguity around how those thresholds get documented, monitored, and enforced — a year earlier than most compliance calendars assume. For CASPs operating across EU borders under MiCA passporting, the group-wide and ongoing monitoring standards in this batch are worth reading this week, not filed away for 2027.
This article is for informational purposes only and does not constitute legal advice. Always consult a qualified compliance professional for guidance specific to your jurisdiction and business.
Ready to screen a wallet address?
Use AMLRadar's free screener to check any crypto address against OFAC, EU, and UK sanctions lists instantly.
Try the Screener