
Payments · Crypto · Digital investments
Publication date: March 2026 | Author: Nexora Regulatory Team | Jurisdiction: Austria / EU
This article is for informational purposes only and does not constitute legal, tax, or investment advice. Regulatory requirements, deadlines, and sanctions may change; for your specific case, please contact Nexora or a qualified legal adviser.
Executive Summary – Key takeaways 2026–2028
- Regulatory overhang: MiCA, DORA, the AI Act, PSD3/PSR, and capital markets reforms will be phased in through at least 2028; many details will only be clarified through technical standards, national transitional rules, and supervisory practice.
- Affected business models: Banks, payment service providers, crypto-asset service providers (CASPs), digital investment platforms, and data- and API-driven fintech models.
- Risks & opportunities: Rising compliance costs and operational complexity, but also higher barriers to entry and therefore consolidation and M&A opportunities for “regulation-ready” players.
- DORA & AI Act: DORA has applied since 17 January 2025; the AI Act will be fully rolled out between 2025 and 2027 according to a clearly defined phased plan – many sector-specific guidelines are still being developed.
- MiCA: MiCA is in force; key parts already apply, while transitional provisions under Article 143 MiCA allow Member States to let CASPs continue operating under national regimes until no later than 1 July 2026.
- Strategic imperative: Actively integrate regulatory overhang into strategy, technology roadmap, and M&A planning (invest, partner, divest), rather than pursuing only minimal, piecemeal compliance.
1.1 MiCA: Start of application and transitional regime
The Markets in Crypto-Assets Regulation (MiCA – Regulation (EU) 2023/1114) is in force; most of its provisions have applied since late 2024 and mid-2025 and form the uniform EU framework for crypto-assets and crypto services. At the same time, Article 143 MiCA allows Member States to provide transitional arrangements for crypto service providers already operating.
Specifically:
- CASPs that were already lawfully providing their services before 30 December 2024 may – depending on national law – continue operating until 1 July 2026 or for a shorter period without immediately holding a MiCA authorisation.
- In a statement, ESMA explicitly pointed out that this creates a fragmented landscape of transitional deadlines and that investors under these transitional regimes do not fully benefit from MiCA protections.
1.2 Supervisory priorities and practical examples
ESMA and the EBA have published a number of technical standards and guidelines on MiCA; further items are under consultation or in preparation. Key areas include, among others:
- Requirements for authorisation applications and ongoing supervision of CASPs,
- Reporting obligations and data requirements,
- Interaction with existing AML/CFT and sanctions regimes.
2. PSD3/PSR: Reshaping payments
2.1 From political agreement to technical implementation
A political agreement has been reached for the Payment Services Regulation (PSR) and the Payment Services Directive (PSD3); formal adoption and publication of the texts are expected in 2026. In parallel, the EBA is preparing to implement an extensive set of mandates – currently estimated at just under 20 technical mandates under PSD3 and slightly more than 20 mandates under PSR.
Key content areas:
- Fraud prevention & liability: Enhanced SCA rules, strengthened “verification of payee” mechanisms, expanded refund and liability rules, including potential responsibility for certain online platforms.
- Transparency & fees: More precise information obligations and requirements on price transparency.
- Access to accounts & data: Removing remaining obstacles for third-party providers, higher requirements for interface quality, and preparation for a broader open-finance framework.
2.2 Open Finance and the financial data framework
In parallel, the EU is working on a financial data framework (FIDA or a similar legal act) intended to anchor Open Finance beyond PSD2. The goal is a regulated data ecosystem with clear rules on:
- Data types and access rights,
- Governance, consent, and withdrawal,
- Security and liability.
3. Capital markets reforms and the “Savings & Investments Union”
3.1 Master Regulation and Master Directive
At the end of 2025, the Commission presented a package to strengthen the Capital Markets Union and a “Savings & Investments Union”. This includes, among other things:
- a Master Regulation amending MiFIR, transparency, data, and market infrastructure rules,
- a Master Directive adjusting, among other things, MiFID II, prospectus law, and listing rules.
Important for digital business models:
- Expansion of a consolidated tape for selected instruments as a central data access point,
- Easier access to capital markets for SMEs,
- Discussion about a stronger role for ESMA in certain supervisory areas.
Neo-brokers, robo-advisers, and tokenisation providers should expect that, in the coming years:
- Transparency and market data obligations (including ESG) will continue to intensify,
- Product classification and suitability requirements will change in certain areas,
- Additional requirements will arise for AI-supported strategies and advisory systems (interface with the AI Act).
4. DORA and the AI Act: Resilience and AI as a dual lever
4.1 DORA: Applies since 17 January 2025 – implementation in focus
The Digital Operational Resilience Regulation (DORA – Regulation (EU) 2022/2554) has applied since 17 January 2025 to the in-scope financial entities. No statutory transitional periods beyond this date are предусмотр; instead, supervisors rely on proportionality when assessing how quickly and to what extent institutions implement the requirements.
In 2026, the supervisory reality is therefore at the forefront:
- Institutions must identify and document critical functions, assets, and ICT third-party service providers;
- Outsourcing contracts with cloud, SaaS, data, and infrastructure providers must be structured and monitored in a DORA-compliant manner;
- Processes for ICT incident reporting and – depending on size/risk – resilience testing (e.g., advanced penetration testing) are being actively reviewed by supervisors.
4.2 AI Act: Clear timeline, sector-specific clarification underway
The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024; its application follows a phased timeline through 2 August 2027.
- From 2 February 2025, the prohibitions for AI systems with “unacceptable risk” (e.g., social scoring by public authorities, certain manipulative practices) apply, as well as general provisions, including AI literacy requirements.
- From 2 August 2025, key requirements for general-purpose AI models (GPAI) and the governance structure (AI Office, AI Board, codes of practice) apply.
- From 2 August 2026, the AI Act is generally applicable in principle; in particular, most obligations for high-risk AI systems will apply, including many applications in credit granting, employment, critical infrastructure, and certain financial services.
- By 2 August 2027, GPAI models that were already on the market before August 2025 must be fully compliant; extended deadlines apply for certain embedded systems.
For financial institutions, this makes it clear: The legal framework and timelines are set; the actual overhang arises from sector-specific interpretation and supervisory practice that are not yet fully harmonised.
5. Regulatory overhang as a driver of consolidation & M&A
5.1 Cost drivers and complexity
In the interplay of MiCA, PSD3/PSR, DORA, the AI Act, and capital markets reforms, structural compliance effort is increasing:
- Technical infrastructure: Adapting core systems, interfaces, logging, and monitoring to DORA, MiCA/PSD reporting, and future open-finance requirements.
- Organisation & governance: Expanding compliance, risk, ICT, and data governance functions; higher requirements for key function holders, especially in crypto and payments.
- Data & reporting: Increasingly granular, more frequent, and standardised reporting to ESMA/EBA/EIOPA, including new crypto data and payment statistics.
- Contract landscape: Restructuring contracts with third-party providers, platforms, and distributors in line with DORA, PSD3/PSR, the AI Act, and AML/sanctions regimes.
Regulatory overhang thus acts as a filter and catalyst:
- “Regulation-ready” companies gain value because they enable buyers to access regulated markets faster with less retrofitting required.
- Undercapitalised players come under pressure and will be more likely to sell licences, platforms, or customer portfolios.
- Banks and large brokers can acquire regulated crypto and payments infrastructures instead of building them from scratch.
- Embedded finance models are likely to rely more heavily on white-label partnerships with regulated institutions.
6. Strategic recommendations from Nexora’s perspective
- Create a regulatory roadmap through 2028.
- Conduct business-model-specific gap analyses.
- Clearly separate core vs. non-core segments.
- Treat data and ICT functions as a core resource.
- Think about M&A strategies through a regulatory lens.
- Proactively engage with supervisors and industry associations.
Nexora Unternehmensberatung GmbH – Your partner for regulatory transformation MiCA · DORA · AML/KYC · PSD3 · AI Act · M&A · Market Entry Austria www.nexora-consulting.at | office@nexora-consulting.at
#MiCA, #MarketsInCryptoAssets, #DORA, #DigitalOperationalResilience, #EUAIAct, #PSD3, #PSR, #OpenFinance, #SavingsAndInvestmentsUnion, #EURegulation, #RegulatoryOverhang, #FinancialServices, #Payments, #CryptoAssets, #CASP, #FinTech, #RegTech, #DigitalInvestments, #ESMA, #EBA, #EIOPA, #ECB, #FMA, #BaFin, #FINMA, #Compliance, #AML, #KYC, #RiskManagement, #OperationalResilience, #DataGovernance, #APIEconomy
Need a consultation?
Book a free initial consultation with the NEXORA team.