Maëlle Vautrin
Paris, France
Oct 5, 2026

Verification note: The supplied reference to FCA Policy Statement PS26/18, dated 16 September 2026, could not be independently verified. This article therefore explains the relevant perimeter issues without treating that publication, its stated conclusions or any implementation timetable as confirmed.

The UK’s move towards a broader cryptoasset authorisation regime presents businesses with a question more demanding than whether they qualify as a “crypto company”: which legal entity performs which service, for which customers, and with what degree of control?

Five activity groups sit at the centre of that assessment: stablecoin issuance, trading-platform operation, safeguarding, dealing and arranging transactions, and arranging staking. For businesses combining several of these functions in one product, the authorisation analysis cannot stop at the customer-facing brand.

The distinction is material. Registration with the Financial Conduct Authority under the Money Laundering Regulations is not equivalent to authorisation under the Financial Services and Markets Act 2000. Nor does an EU licence establish permission to conduct regulated business in the UK.

The starting point must be the applicable legislation, its commencement provisions and any exclusions. FCA guidance can explain the regulator’s interpretation; it cannot replace the statutory test.

1. Stablecoin issuance: identify the issuer, not just the token

A stablecoin assessment begins with the legal definition of the asset. A token marketed as “stable” does not necessarily belong to the same regulatory category as every other token designed to maintain a reference value.

The next question is which entity performs the issuance activity. Businesses should distinguish token creation from the responsibilities surrounding reserves, redemption, distribution and governance. Those functions may be divided between several companies, but that division does not make their legal significance disappear.

A useful assessment therefore follows the token through its lifecycle: who issues it, who owes any redemption obligation, who manages backing assets and who contracts with holders?

These functions are not automatically one regulated activity. They are facts that help establish which activities and obligations may apply. Territorial scope also needs separate examination, particularly where an issuer is outside the UK but its tokens circulate among UK customers.

2. Trading platforms: examine how transactions come together

For a trading venue, the important issue is what the service organises—not whether its operator describes it as an exchange, marketplace or software interface.

Relevant facts include how trading interests interact, who sets admission and trading rules, and what role the operator plays in execution. Firms should distinguish operating a platform from dealing on their own account or arranging transactions. One business model may require more than one perimeter assessment.

A decentralised architecture does not, by itself, answer these questions. Neither does a centralised interface prove that its provider operates a regulated venue. The analysis depends on the legal definition and the responsibilities exercised in practice.

3. Safeguarding: trace control and responsibility

Custody assessments should follow both the assets and the authority to move them.

Who holds or controls private keys? Who can approve transfers? Can a provider recover access, change signing arrangements or restrict withdrawals? What responsibility has it accepted for protecting customer assets?

The answers may be distributed across a wallet provider, an exchange and a specialist custodian. Outsourcing is therefore a reason to examine the contractual chain, not a substitute for doing so.

Likewise, “non-custodial” is a product description rather than a legal conclusion. Firms need to substantiate it through their technical design, customer terms and operational permissions. Key possession is important evidence, but should not be treated as the only relevant fact.

4. Dealing and arranging: map the transaction chain

Businesses that buy or sell cryptoassets, execute customer orders, route transactions or connect counterparties need to examine their precise role.

Trading as principal differs from acting as an agent. Introducing customers differs from operating an execution service. Whether a particular function falls within a dealing or arranging category depends on the applicable definition and any exclusion—not simply on its commercial label.

This is especially important for products marketed as execution-only or technology-enabled. Removing investment advice does not necessarily remove every other regulated function.

A transaction map should show who receives the instruction, selects the route, contracts with the customer, executes the trade and receives payment. That provides a stronger basis for analysis than a general statement that the business merely facilitates access.

5. Staking: separate infrastructure from the customer service

Staking requires a similar distinction between technical participation and arranging a service for customers.

Running validator infrastructure is not necessarily the same activity as organising customer participation in staking. Firms should examine who selects validators, places or delegates assets, determines withdrawal arrangements and allocates rewards and losses.

Contracts should also make clear who bears slashing risk and what happens if assets cannot be withdrawn when expected. Those issues affect customer protection, but they do not alone determine the regulatory classification.

The perimeter analysis must remain specific to the service. A staking label cannot establish that every participant requires authorisation—or that every participant is outside the regime.

Software exclusions need evidence

The boundary between providing technology and performing a financial service is particularly consequential for infrastructure businesses.

Supplying software should not be equated automatically with operating the activity it supports. Equally, describing a business as a software provider does not settle the issue if it also controls assets, directs execution or exercises substantive authority over a customer service.

Any reliance on a statutory exclusion should be tested against its actual wording. Firms should retain supporting evidence: contracts, system permissions, key-management arrangements, decision-making records and clear allocations of responsibility.

This is where proportionate regulation matters. A workable perimeter should distinguish genuine infrastructure provision from regulated intermediation without requiring firms to infer the boundary primarily from enforcement cases.

Registration, transition and cross-border access are separate questions

The FCA’s existing cryptoasset anti-money-laundering regime should not be confused with broader financial-services authorisation. Existing registration does not establish that a firm holds every permission a new regime may require.

Businesses must separately check commencement dates, application requirements and any transitional provisions. Until verified, a claimed transition should not be treated as permission to continue operating unchanged.

Overseas firms also need a UK-specific assessment. An authorisation under the EU’s Markets in Crypto-Assets Regulation does not passport into the UK. Whether UK authorisation is required depends on the relevant territorial rules and the firm’s activities—not merely its place of incorporation.

The practical priority is therefore a service-by-service, entity-by-entity review. Identify the asset, classify the activity, establish who performs it, test territorial scope and exclusions, and document the conclusion. Only then can a business determine what permissions it may need—and whether its operating model must change.