The EU has adopted an anti-money laundering package that consolidates anti-money laundering rules into a single regulation, establishes a single supervisory authority, and expands the scope of application to include more businesses dealing with crypto-assets. The package builds on the Commission’s initiatives on digital finance from September 2020, which also included the proposal for the MiCA Regulation and a recast of the Money Transfer Regulation so that the requirement for information on the sender and recipient (the “travel rule”) also applies to transfers of crypto-assets. This article reviews the anti-money laundering package with a focus on crypto-assets.
The article was published on December 30, 2022, and was updated in September 2026 to reflect the adopted legislative acts and their effective dates.
On July 20, 2021, the Commission presented a proposal for an anti-money laundering package. The package aims to harmonize EU rules on anti-money laundering, establish a common EU supervisory authority, and strengthen cooperation and the exchange of information between the Member States’ financial intelligence units (“FIUs”). The Danish FIU is the Money Laundering Secretariat at the National Unit for Serious Crime, pursuant to Section 29 of the Money Laundering Act. The Money Transfer Regulation was adopted in May 2023, and the three other legal acts were adopted on May 31, 2024, and published in the Official Journal of the European Union on June 19, 2024.
The package is intended to address three problems that the Commission had identified in the previous regulations.
The Anti-Money Laundering Regulation establishes common rules for policies, procedures, and controls in the area of anti-money laundering in all member states. As of July 10, 2027, the same requirements will apply to all obligated entities, regardless of the Member State in which they are licensed or registered. The requirements will become more detailed, which may make it more difficult for smaller businesses to comply with them.
One of the key measures is the establishment of the EU’s anti-money laundering supervisory authority, the Authority for Combating Money Laundering and Terrorist Financing (“AMLA”). AMLA has been operational since July 1, 2025, and is headquartered in Frankfurt. Starting in 2028, the Authority will directly supervise selected credit institutions and financial institutions, coordinate cooperation among national supervisory authorities, and support the FIUs, including by operating FIU.net.
Providers of crypto-asset services must collect and include information about the sender and recipient when transferring crypto-assets, in accordance with Articles 14–16 of the Money Transfer Regulation. This requirement has been in effect since December 30, 2024. The information is similar to that which payment service providers include with electronic money transfers.
Until the Anti-Money Laundering Regulation takes effect, anti-money laundering in Denmark is governed by the Anti-Money Laundering Act, see Consolidated Act No. 433 of April 17, 2026. The Act implements the Fourth Anti-Money Laundering Directive, Directive (EU) 2015/849, as amended by the Fifth Anti-Money Laundering Directive, Directive (EU) 2018/843. The Directive sets out minimum requirements, and Member States may adopt stricter rules. This has led to inconsistent regulation across Member States.
It is up to the national authorities to establish standards and guidelines regarding the procedures prescribed by the directive. According to the Commission, this has led to excessive differences between the laws of the member states and has made it more difficult for companies to offer services in multiple member states while complying with national regulations.
Before the AMLA was established, there was no EU authority with direct supervisory powers in the area of money laundering, and, according to the Commission, coordination between national supervisory authorities and FIUs in cross-border cases was inadequate.
The Anti-Money Laundering Package is intended to address these issues. It changes the form of the regulation from a directive to a regulation and shifts parts of the oversight from the national level to the EU level.
The anti-money laundering package consists of four legislative acts.
FIUs, supervisory authorities, and beneficial ownership registries continue to be regulated by a directive, now AMLD6. The obligations imposed on obligated entities, including the rules on customer due diligence procedures, reporting, and thresholds, are, however, consolidated in the Anti-Money Laundering Regulation, which is directly applicable in member states without the need for national implementation.
AMLA was established by the AMLA Regulation. The Authority is tasked with harmonizing the working procedures of national supervisory authorities and promoting a common supervisory culture, developing technical standards and guidelines in accordance with the Anti-Money Laundering Regulation and AMLD6, establishing formats for reporting and exchanging information, and supporting the FIUs’ joint analyses.
AMLA is to develop a common template for suspicious transaction reports, in accordance with Article 69(3) of the Anti-Money Laundering Regulation, and submitted a draft for public comment in July 2026. The reports will thus follow the same format throughout the EU.
The national supervisory authorities and FIUs will continue to operate. However, AMLA will assume direct supervision of up to 40 credit institutions, financial institutions, or groups that operate in at least six member states and present the highest residual money laundering risk, in accordance with Articles 12 and 13 of the AMLA Regulation. The selection will take place in the second half of 2027, and direct supervision will begin on January 1, 2028. In addition, AMLA may assume supervision of an entity that has not been selected, at the request of the national supervisory authority. The Commission may also decide that AMLA should assume supervision if the firm systematically violates the rules and the national supervisory authority fails to take action.
The Anti-Money Laundering Regulation consolidates anti-money laundering rules into a single set of rules for all member states (“single rulebook”).
The Regulation expands the scope of application of the anti-money laundering rules and aligns the definitions with those in the MiCA Regulation. Crypto-asset service providers are covered as financial institutions, cf. Article 2(1)(6)(i) and Article 3(2) of the Anti-Money Laundering Regulation. The terms “crypto-asset,” “crypto-asset service,” and “crypto-asset service provider” are defined by reference to Article 3(1)(5), (16), and (15) of the MiCA Regulation, as set forth in Article 2(1)(7)–(9) of the Anti-Money Laundering Regulation.
However, advice on crypto-assets is excluded from the definition of crypto-asset services, see Article 2(1)(8) of the Anti-Money Laundering Regulation. Individuals and entities that solely provide advice on crypto-assets, including consultants, are therefore not considered obligated entities under the Anti-Money Laundering Regulation.
Article 79 of the Anti-Money Laundering Regulation prohibits credit institutions, financial institutions, and crypto-asset service providers from maintaining anonymous crypto-asset accounts. The prohibition also applies to accounts that otherwise enable the anonymization of the account holder’s identity or the concealment of transactions, including through anonymity-enhancing cryptoassets (“anonymity-enhancing coins”) such as Monero and Zcash. The prohibition applies to the obligated entities and does not include providers of hardware or software for self-hosted wallets when they do not have access to or control over the customer’s wallet, see Recital 160. Crypto-assets as such are not prohibited.
Member States may require that crypto-asset service providers headquartered in another Member State and established in the territory of the Member State in question by means other than a branch designate a central contact point, pursuant to Article 8(6) of the Anti-Money Laundering Regulation and Article 41 of AMLD6. This option already applies to electronic money issuers and payment service providers. Under Section 33 of the Anti-Money Laundering Act, the Danish Financial Supervisory Authority has the authority to establish such rules.
The rules in the Anti-Money Laundering Regulation are more detailed than those in the Anti-Money Laundering Act and are supplemented by technical standards and guidelines that the AMLA is developing on an ongoing basis through 2027. Below, we review the changes that have the greatest impact on crypto-asset service providers.
The regulation applies to crypto-asset service providers as defined in MiCA.
The recitals of the Regulation reaffirm the principle of proportionality. The requirements must be proportionate to the nature, size, complexity, and risks of the business, see recitals 28, 29, and 32, and, pursuant to Article 9(4), the AMLA must issue guidelines on proportionate internal policies and controls.
Customer due diligence (CDD) procedures must be performed by individuals with the appropriate qualifications. Employees, agents, and distributors who are directly involved in ensuring the firm’s compliance with the Regulation must be assessed with regard to their professional skills, knowledge, and expertise, as well as their reputation, good character, and integrity, in accordance with Article 13(1). The assessment must be proportionate to the risk associated with the tasks, be conducted prior to employment, and be repeated regularly; its content must be approved by the company’s compliance officer. The Anti-Money Laundering Act currently requires policies for employee screening and employee training, see Section 8(1) and (6) of the Anti-Money Laundering Act. The requirement for an actual assessment now follows directly from the Regulation.
Like the Anti-Money Laundering Act, the Regulation specifies the situations in which CDD must be performed, see Article 19(1). This applies, among other things, when establishing a business relationship, in the case of individual transactions exceeding the threshold amount, in cases of suspicion of money laundering or terrorist financing, and when there is doubt regarding the accuracy or adequacy of previously obtained customer information. The general threshold for individual transactions is reduced from EUR 15,000 to EUR 10,000.
For providers of crypto-asset services, the threshold is EUR 1,000 for all individual transactions. Below this threshold, the customer must, at a minimum, be identified and their identity verified, in accordance with Article 19(3). The Anti-Money Laundering Act currently sets a threshold of EUR 1,000 for the exchange of crypto-assets, the transfer of crypto-assets, and services related to the issuance of crypto-assets, as well as a threshold of EUR 500 for the exchange of crypto-assets for fiat currency, in accordance with Section 10(2)(c) and (d) of the Anti-Money Laundering Act.
AMLA was required to develop draft technical standards by July 10, 2026, specifying which obligated entities, sectors, and transactions are associated with higher risk and for which, therefore, a lower threshold should apply, in accordance with Article 19(9). AMLA issued the draft for public consultation in February 2026, together with the draft standards on CDD information pursuant to Article 28. As of the update to this article in September 2026, the final standards have not yet been published.
The Regulation specifies the measures that CDD encompasses, as set forth in Article 20(1). These include, among other things, customer identification and verification, identification of beneficial owners, clarification of the purpose and intended nature of the business relationship, verification of whether the customer is subject to targeted financial sanctions, and ongoing monitoring. Article 22 lists the identity information that must be obtained, and Article 25 specifies the information regarding the purpose of the business relationship and the source of funds.
The obligation to report to the FIU is set forth in Article 69. All suspicious transactions must be reported, regardless of the amount, including attempted transactions and cases where suspicion arises because customer due diligence (CDD) cannot be performed. Requests for information from the FIU must be answered within five business days; in urgent cases, the response must be provided sooner.
In our assessment, for Danish crypto-asset service providers that are already subject to the Anti-Money Laundering Act, this largely represents a continuation of existing requirements. However, policies and procedures must be reviewed and adapted to the regulation’s more detailed requirements and the AMLA’s technical standards by July 10, 2027.
The Anti-Money Laundering Regulation allows for the verification of a customer’s identity using electronic means of identification that meet the “substantial” or “high” assurance level requirements of the eIDAS Regulation, and using qualified trust services, as provided in Article 22(6)(b). This provision should be viewed in the context of the EU’s framework for a European digital identity.
The purpose is to support secure digital onboarding and make it easier to verify identity without the need for a physical presence. According to Recital 66 of the Anti-Money Laundering Regulation, the use of such identification methods can reduce the risk level to normal or low when appropriate risk-mitigating measures are in place.
The European Digital Identity is established under Regulation (EU) 2024/1183 (“eIDAS 2.0”), which amends the eIDAS Regulation and entered into force on May 20, 2024. Member States must make at least one European Digital Identity Wallet (EUDI Wallet) available to citizens and businesses by the end of 2026 at the latest. The framework is intended to provide cross-border access to reliable electronic identity solutions that can be used by both public and private services. Identity data must be shareable as attributes so that each individual service receives only the information it needs, and qualified trust services must be recognized throughout the EU on an equal footing.
The Agency for Digitization is responsible for the Danish digital wallet, which will be introduced in phases in 2026.
The Money Laundering Regulation’s recognition of electronic identification means that a digital wallet issued in one Member State can be used for onboarding at regulated entities in another. The AMLA must, in technical standards pursuant to Article 28(1)(e), specify which attributes must be included in the identification means and trust services.
In addition to money transfers, the Money Transfer Regulation also covers transfers of crypto-assets, thereby implementing the FATF’s travel rule in the EU. The Regulation has been in effect since December 30, 2024, pursuant to Article 40, the date on which the MiCA Regulation became fully applicable. The EBA has issued guidelines on the rules (EBA/GL/2024/11). They apply from the same date.
The Travel Rule requires crypto-asset service providers involved in transfers of crypto-assets to collect, transmit, and retain information about the sender and recipient, as set forth in Articles 14–16. These requirements apply to transfers of crypto-assets where the sender’s or recipient’s crypto-asset service provider is established in the EU, as provided for in Article 2(1). Transfers made directly between two individuals without the involvement of a crypto-asset service provider are exempt, as provided for in Article 2(4).
For the sender, the name, distributed ledger address, or account number, as well as the address or identification number, must be included. For the recipient, the name and distributed ledger address or account number must be included, see Article 14, paragraphs 1 and 2. Unlike money transfers, there is no de minimis threshold for transfers of crypto-assets. For transfers to or from a self-hosted address, the provider must collect and retain the information, and for transfers exceeding EUR 1,000, the provider must assess whether the address is owned or controlled by the customer, see Article 14(5) and Article 16(2).
The purpose is the same as that of Regulation (EU) 2015/847, namely to identify the sender and recipient in order to combat money laundering and terrorist financing and to detect and stop suspicious transfers.
The legal acts in the package take effect at different times. The Money Transfer Regulation has been in effect since December 30, 2024, and the AMLA Regulation since July 1, 2025. The Anti-Money Laundering Regulation applies as of July 10, 2027; however, for soccer agents and professional soccer clubs, it does not apply until July 10, 2029, pursuant to Article 90. In the second half of 2027, the AMLA will select the entities that the authority will directly supervise as of January 1, 2028.
The three-year period provided for in the Anti-Money Laundering Regulation—from its entry into force to its application—is intended to give AMLA time to develop the technical standards and guidelines required by the Regulation. AMLD6 must be transposed into national law no later than July 10, 2027, at which time the Fourth Anti-Money Laundering Directive will be repealed. The rules on access to information on beneficial owners, see AMLD6 Article 74, were to be implemented no later than July 10, 2025, which in Denmark was done by Act No. 710 of June 20, 2025.
The Money Laundering Act remains in effect until the Money Laundering Regulation takes effect. In 2025, the Ministry of Business and Industry stated that a bill to implement AMLD6 and align the Anti-Money Laundering Act with the regulation would be sent out for public comment in 2026 at the earliest, and that it had not yet been decided whether the Anti-Money Laundering Act would be continued in an amended form or replaced by a new law. As of the update to this article in September 2026, no bill or consultation draft has yet been published. The Danish Financial Supervisory Authority has urged companies to begin preparations and is participating in the development of the technical standards.
The Anti-Money Laundering Regulation takes effect on July 10, 2027, but most of its requirements build upon obligations that already apply under the Anti-Money Laundering Act and the Money Transfer Regulation. Crypto-asset service providers would be well advised to take the following steps now.
In our view, the anti-money laundering package, together with the MiCA Regulation, provides the crypto-asset sector with a harmonized legal framework throughout the EU. This could make it easier for established financial institutions, including banks, to collaborate with crypto-asset service providers.
We expect that a common European digital identity will make it easier to onboard customers from other member states. Our experience with cases involving clients engaged in cross-border activities is that reporting to FIUs in other member states remains difficult because it often must be done in the national language and using national login services. AMLA’s common reporting template and the European digital identity wallets can help address this issue.
Samar Law is monitoring developments leading up to July 10, 2027. If you have any questions about the rules, please feel free to contact us.