Back to all articles
SCALESUCCESSCOMPLIANCE

2026: Regulatory overhang as the new normal.

·
9 min
2026: Regulatory overhang as the new normal.

Payments · Crypto · Digital investments

Publication date: March 2026 | Author: Nexora Regulatory Team | Jurisdiction: Austria / EU

This article is for informational purposes only and does not constitute legal, tax, or investment advice. Regulatory requirements, deadlines, and sanctions may change; for your specific case, please contact Nexora or a qualified legal adviser.

Executive Summary – Key takeaways 2026–2028

  • Regulatory overhang: MiCA, DORA, the AI Act, PSD3/PSR, and capital markets reforms will be phased in through at least 2028; many details will only be clarified through technical standards, national transitional rules, and supervisory practice.
  • Affected business models: Banks, payment service providers, crypto-asset service providers (CASPs), digital investment platforms, and data- and API-driven fintech models.
  • Risks & opportunities: Rising compliance costs and operational complexity, but also higher barriers to entry and therefore consolidation and M&A opportunities for “regulation-ready” players.
  • DORA & AI Act: DORA has applied since 17 January 2025; the AI Act will be fully rolled out between 2025 and 2027 according to a clearly defined phased plan – many sector-specific guidelines are still being developed.
  • MiCA: MiCA is in force; key parts already apply, while transitional provisions under Article 143 MiCA allow Member States to let CASPs continue operating under national regimes until no later than 1 July 2026.
  • Strategic imperative: Actively integrate regulatory overhang into strategy, technology roadmap, and M&A planning (invest, partner, divest), rather than pursuing only minimal, piecemeal compliance.
1. MiCA: From the legal framework to supervisory practice

1.1 MiCA: Start of application and transitional regime

The Markets in Crypto-Assets Regulation (MiCA – Regulation (EU) 2023/1114) is in force; most of its provisions have applied since late 2024 and mid-2025 and form the uniform EU framework for crypto-assets and crypto services. At the same time, Article 143 MiCA allows Member States to provide transitional arrangements for crypto service providers already operating.

Specifically:

  • CASPs that were already lawfully providing their services before 30 December 2024 may – depending on national law – continue operating until 1 July 2026 or for a shorter period without immediately holding a MiCA authorisation.
  • In a statement, ESMA explicitly pointed out that this creates a fragmented landscape of transitional deadlines and that investors under these transitional regimes do not fully benefit from MiCA protections.
For crypto service providers, this means: MiCA is effectively the binding reference, but until 1 July 2026, MiCA licensing regimes and national transitional solutions will coexist.

1.2 Supervisory priorities and practical examples

ESMA and the EBA have published a number of technical standards and guidelines on MiCA; further items are under consultation or in preparation. Key areas include, among others:

  • Requirements for authorisation applications and ongoing supervision of CASPs,
  • Reporting obligations and data requirements,
  • Interaction with existing AML/CFT and sanctions regimes.
National measures illustrate the seriousness of the situation: In Austria, the FMA prohibited KuCoin EU Exchange GmbH from concluding new business and onboarding new customers because key functions in AML/CFT and sanctions were not adequately staffed. This shows: A MiCA licence is necessary, but without robust governance, staffing, and risk culture, it is no guarantee of sustained market presence.

2. PSD3/PSR: Reshaping payments

2.1 From political agreement to technical implementation

A political agreement has been reached for the Payment Services Regulation (PSR) and the Payment Services Directive (PSD3); formal adoption and publication of the texts are expected in 2026. In parallel, the EBA is preparing to implement an extensive set of mandates – currently estimated at just under 20 technical mandates under PSD3 and slightly more than 20 mandates under PSR.

Key content areas:

  • Fraud prevention & liability: Enhanced SCA rules, strengthened “verification of payee” mechanisms, expanded refund and liability rules, including potential responsibility for certain online platforms.
  • Transparency & fees: More precise information obligations and requirements on price transparency.
  • Access to accounts & data: Removing remaining obstacles for third-party providers, higher requirements for interface quality, and preparation for a broader open-finance framework.
For payment service providers, 2026 is therefore primarily a design and planning year, in which fraud frameworks, authentication processes, price communication, and the API landscape must be adapted to the forthcoming detailed framework.

2.2 Open Finance and the financial data framework

In parallel, the EU is working on a financial data framework (FIDA or a similar legal act) intended to anchor Open Finance beyond PSD2. The goal is a regulated data ecosystem with clear rules on:

  • Data types and access rights,
  • Governance, consent, and withdrawal,
  • Security and liability.
Trilogue negotiations are ongoing; progress is expected in 2026, without any guaranteed final completion date. Nevertheless, market participants should assume that API-based open-finance models will become the standard and must already be factored into architecture and product decisions today.

3. Capital markets reforms and the “Savings & Investments Union”

3.1 Master Regulation and Master Directive

At the end of 2025, the Commission presented a package to strengthen the Capital Markets Union and a “Savings & Investments Union”. This includes, among other things:

  • a Master Regulation amending MiFIR, transparency, data, and market infrastructure rules,
  • a Master Directive adjusting, among other things, MiFID II, prospectus law, and listing rules.
In 2026, the proposals are in the legislative process; specific application dates depend on the trilogue negotiations.

Important for digital business models:

  • Expansion of a consolidated tape for selected instruments as a central data access point,
  • Easier access to capital markets for SMEs,
  • Discussion about a stronger role for ESMA in certain supervisory areas.
3.2 Implications for digital investment platforms

Neo-brokers, robo-advisers, and tokenisation providers should expect that, in the coming years:

  • Transparency and market data obligations (including ESG) will continue to intensify,
  • Product classification and suitability requirements will change in certain areas,
  • Additional requirements will arise for AI-supported strategies and advisory systems (interface with the AI Act).
As the detailed design is still evolving, a flexible, modular, and data-centric architecture is crucial to integrate new obligations step by step.

4. DORA and the AI Act: Resilience and AI as a dual lever

4.1 DORA: Applies since 17 January 2025 – implementation in focus

The Digital Operational Resilience Regulation (DORA – Regulation (EU) 2022/2554) has applied since 17 January 2025 to the in-scope financial entities. No statutory transitional periods beyond this date are предусмотр; instead, supervisors rely on proportionality when assessing how quickly and to what extent institutions implement the requirements.

In 2026, the supervisory reality is therefore at the forefront:

  • Institutions must identify and document critical functions, assets, and ICT third-party service providers;
  • Outsourcing contracts with cloud, SaaS, data, and infrastructure providers must be structured and monitored in a DORA-compliant manner;
  • Processes for ICT incident reporting and – depending on size/risk – resilience testing (e.g., advanced penetration testing) are being actively reviewed by supervisors.
Smaller fintechs and CASPs in particular are experiencing the shift from “best practice” to a supervisory minimum standard: Without demonstrable ICT resilience frameworks, maintaining a stable supervisory relationship is becoming increasingly difficult.

4.2 AI Act: Clear timeline, sector-specific clarification underway

The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024; its application follows a phased timeline through 2 August 2027.

  • From 2 February 2025, the prohibitions for AI systems with “unacceptable risk” (e.g., social scoring by public authorities, certain manipulative practices) apply, as well as general provisions, including AI literacy requirements.
  • From 2 August 2025, key requirements for general-purpose AI models (GPAI) and the governance structure (AI Office, AI Board, codes of practice) apply.
  • From 2 August 2026, the AI Act is generally applicable in principle; in particular, most obligations for high-risk AI systems will apply, including many applications in credit granting, employment, critical infrastructure, and certain financial services.
  • By 2 August 2027, GPAI models that were already on the market before August 2025 must be fully compliant; extended deadlines apply for certain embedded systems.
The sectoral financial frameworks (CRR/CRD, MiFID/MiFIR, Solvency II, etc.) remain unchanged. ESMA, the EBA, and EIOPA are working to align AI Act obligations with existing governance, risk, and disclosure requirements in the financial sector; detailed guidance on AI-supported creditworthiness assessment, robo-advice, algorithmic trading, or AML monitoring is expected to be issued gradually over the coming years.

For financial institutions, this makes it clear: The legal framework and timelines are set; the actual overhang arises from sector-specific interpretation and supervisory practice that are not yet fully harmonised.

5. Regulatory overhang as a driver of consolidation & M&A

5.1 Cost drivers and complexity

In the interplay of MiCA, PSD3/PSR, DORA, the AI Act, and capital markets reforms, structural compliance effort is increasing:

  • Technical infrastructure: Adapting core systems, interfaces, logging, and monitoring to DORA, MiCA/PSD reporting, and future open-finance requirements.
  • Organisation & governance: Expanding compliance, risk, ICT, and data governance functions; higher requirements for key function holders, especially in crypto and payments.
  • Data & reporting: Increasingly granular, more frequent, and standardised reporting to ESMA/EBA/EIOPA, including new crypto data and payment statistics.
  • Contract landscape: Restructuring contracts with third-party providers, platforms, and distributors in line with DORA, PSD3/PSR, the AI Act, and AML/sanctions regimes.
5.2 Consolidation and M&A opportunities

Regulatory overhang thus acts as a filter and catalyst:

  • “Regulation-ready” companies gain value because they enable buyers to access regulated markets faster with less retrofitting required.
  • Undercapitalised players come under pressure and will be more likely to sell licences, platforms, or customer portfolios.
  • Banks and large brokers can acquire regulated crypto and payments infrastructures instead of building them from scratch.
  • Embedded finance models are likely to rely more heavily on white-label partnerships with regulated institutions.
For M&A transactions, this means: Regulatory implementation status, data quality, ICT resilience, and governance become central value drivers and risk indicators and must be explicitly addressed in due diligence, valuation, and contractual clauses (including regulatory MAC, warranties, and transitional services).

6. Strategic recommendations from Nexora’s perspective

  • Create a regulatory roadmap through 2028.
Map all relevant regimes (MiCA, PSD3/PSR, DORA, the AI Act, capital markets reforms, financial data framework) with their known milestones and supervisory mandates from ESMA/EBA.
  • Conduct business-model-specific gap analyses.
Assess payments (fraud, SCA, liability), crypto (MiCA licence, governance, custody, AML/CFT), and digital investments (AI use, market data, ESG disclosure) separately.
  • Clearly separate core vs. non-core segments.
Consistently align core segments with full regulatory requirements; define peripheral activities early as cooperation or exit candidates before the overhang leads to a forced exit.
  • Treat data and ICT functions as a core resource.
DORA, MiCA/PSD reporting, and the AI Act make data governance, logging, monitoring, and model governance central assets, not merely cost blocks.
  • Think about M&A strategies through a regulatory lens.
Select targets based on “regulation readiness”, realistically price remaining remediation effort into valuation, and address it contractually.
  • Proactively engage with supervisors and industry associations.
Participate in consultations, working groups, and, where applicable, sandboxes – especially for AI- and data-intensive business models – to gain early insight into sector-specific guidance.

Nexora Unternehmensberatung GmbH – Your partner for regulatory transformation MiCA · DORA · AML/KYC · PSD3 · AI Act · M&A · Market Entry Austria www.nexora-consulting.at | office@nexora-consulting.at

#MiCA, #MarketsInCryptoAssets, #DORA, #DigitalOperationalResilience, #EUAIAct, #PSD3, #PSR, #OpenFinance, #SavingsAndInvestmentsUnion, #EURegulation, #RegulatoryOverhang, #FinancialServices, #Payments, #CryptoAssets, #CASP, #FinTech, #RegTech, #DigitalInvestments, #ESMA, #EBA, #EIOPA, #ECB, #FMA, #BaFin, #FINMA, #Compliance, #AML, #KYC, #RiskManagement, #OperationalResilience, #DataGovernance, #APIEconomy

Need a consultation?

Book a free initial consultation with the NEXORA team.

Free Consultation
2026: Regulatory overhang as the new normal. | NEXORA