Credibility is the UK's Crypto Advantage

Many advantages: the UK has deep financial markets, legal expertise, supervisory experience and a long history of adapting to changes in global finance. Image: Ruslan Abdullin/Adobe Stock

Many advantages: the UK has deep financial markets, legal expertise, supervisory experience and a long history of adapting to changes in global finance. Image: Ruslan Abdullin/Adobe Stock


The UK’s new crypto regime is a major milestone. But competitive advantage will come from building credibility, not merely regulating today’s visible crypto market.

With the publication last month of the Financial Conduct Authority’s (FCA) cryptoassets regime policy statements, the UK has reached an important milestone in its regulation of the virtual asset industry. After years in which policy debates have oscillated between enthusiasm for innovation and concern about criminal misuse, the question is now whether the UK can ensure effective regulation without stifling responsible innovation or leaving material risks to grow in the shadows.

The package represented by the statements is broad. It covers admissions and disclosures, market abuse, stablecoin issuance, custody, trading platforms, intermediaries, staking, prudential requirements, operational resilience and the application of key parts of the FCA Handbook to regulated crypto activities. In other words, the UK is moving from partial oversight to a much more complete regulatory architecture, through which credibility and reliability (as underlined in a recent FCA webinar) may become its greatest competitive advantage.

However, achieving this is a harder task than it first appears. Crypto is no longer a self-contained market of speculative tokens and specialist exchanges. Stablecoins, tokenised deposits, decentralised finance, privacy-enhancing technologies and emerging forms of automated payments are increasingly interacting with the traditional financial system, presenting co-mingled risks that may accelerate and amplify existing financial system vulnerabilities. Furthermore, as explored at a recent workshop hosted by the Centre for Finance and Security at RUSI in partnership with EY, a further risk is emerging: that the UK may design regulation for the parts of the crypto ecosystem that are most visible, while the most important risks migrate to the boundaries between – and outside – regulatory systems.

That matters for both financial crime policy and the UK’s ambition to remain a leading centre for financial innovation. A regulatory regime that cleans up the most obvious parts of the market but fails to address the less visible infrastructure through which illicit finance moves will not be judged effective for long – and will be open to ongoing exploitation by criminal actors who are known to ‘shop around’ for systemic weaknesses. Equally, a regime that imposes high burdens without offering clarity, predictability and credibility will struggle to attract the responsible firms the UK says it wants.

How Crypto Amplifies Risk

The first point underlined by the roundtable discussion was that crypto does not simply create a set of wholly new crimes. Fraud, money laundering, sanctions evasion, terrorist financing and asset concealment all existed long before the advent of virtual assets. What crypto changes is the speed, scale, geographic dimension and visibility of those risks. It can accelerate payments, compress laundering chains, enable value to move across borders outside traditional correspondent banking channels and allow criminals to exploit gaps between regulatory systems.

In that sense, crypto often amplifies existing risks rather than creating new ones. But amplification can itself become transformation. When a technology enables crime to happen at greater speed, across more jurisdictions and through infrastructure that sits outside established controls, the operational challenge becomes different. The distinction between ‘new crime’ and ‘old crime in new clothes’ begins to matter less than whether the existing regulatory and enforcement architecture can keep pace.

This is particularly clear in the relationship between crypto and traditional finance. For years, banks have built compliance systems around known customers, monitored transactions and established counterparties. Cryptoasset firms have developed their own tools, including blockchain analytics, wallet scoring and on-chain tracing. Both systems can produce useful intelligence. But the most intense risks emerge where these two worlds meet.

A traditional financial institution and a regulated crypto exchange may both have information about their customers, but neither necessarily has a full view of the activity that preceded or follows a transaction, particularly where funds pass through decentralised exchanges, mixers, peer-to-peer markets, self-hosted wallets, privacy chains or offshore providers. This resembles the familiar correspondent banking problem of understanding a customer’s customer, but with added velocity and technical complexity.

quote
The success of UK regulation should therefore be measured not only by the quality of firms that gain authorisation, but also by the extent to which displaced activity that does not meet those standards is captured

The result is a growing visibility gap. Traditional transaction monitoring and blockchain analytics were developed for different environments. When value moves between them, the available data points do not always overlap. Criminals are likely to identify and exploit these seams. The danger is not that regulated banks or exchanges knowingly facilitate illicit finance, it is that visibility is lost at the boundary between regulated and less regulated activity.

The Regulatory Gap

The most straightforward way of plugging this gap is to regulate identifiable firms: exchanges, custodians, issuers and other entities that can be authorised, supervised and sanctioned. This is at the heart of the UK’s latest move to increase standards, improve consumer protection and reduce the number of poorly controlled firms operating in the market.

But this will not be sufficient. A regime focused primarily on firms that are easiest to supervise risks mistaking regulatory tidiness for effectiveness. It may produce a cleaner authorised sector while pushing higher-risk activity into less transparent spaces, just as occurred 15–20 years ago in the traditional financial system.

The FCA has deliberately constructed an activity-based regime rather than one defined solely by institutional type. But decentralised finance still poses the harder question: what happens when economically significant financial activity cannot easily be attributed to an identifiable entity? The success of UK regulation should therefore be measured not only by the quality of firms that gain authorisation, but also by the extent to which displaced activity that does not meet those standards is captured.

This is where decentralised finance (DeFi) remains the hardest unresolved issue. Much financial regulation assumes that there is an identifiable entity providing a service. DeFi challenges that assumption. Protocols, software, governance tokens and dispersed developer communities may provide economically equivalent services without fitting neatly into the categories that regulators are used to supervising.

It is understandable that regulators begin with the parts of the market they can most readily understand and control. But ‘too difficult for now’ cannot become ‘too difficult forever’ – the regulatory journey must continue. If decentralised exchanges, liquidity pools and other DeFi structures perform the functional equivalent of financial intermediation, then the regulatory debate must move beyond whether they look like traditional firms. It must ask where control, economic benefit, governance and accountability actually sit.

That will require different expertise. Regulators do not need to become software developers, but they do need access to people who understand the tech stack, the governance arrangements and the real incentives within these systems. The UK should be exploring models that combine legal accountability with technical supervision, including forms of embedded supervision, protocol-level reporting and clearer tests for when developers, token-holders or governance participants should be treated as exercising meaningful control.

Stablecoins as Infrastructure

Stablecoins make this challenge more urgent as they become an increasingly central element of payments infrastructure. Thus, related risks are no longer limited to money laundering or consumer protection. They extend to operational resilience, concentration, liquidity, monetary sovereignty and dependence on infrastructure that may be controlled or influenced outside the UK.

Subscribe to the CFS Newsletter

Receive a monthly newsletter and emails about upcoming events hosted by the Centre for Finance and Security Research Group

This is why stablecoin regulation cannot be merely bolted onto existing crypto policy. The more stablecoins are used for payments, settlement or cross-border value transfer, the more they matter to the functioning of the wider financial system. That does not mean they should be smothered by bank-like regulation in every respect. But it does mean that policymakers need to treat them as infrastructure, not just products.

There is also a national security dimension. States and sanctioned actors that have been constrained in the traditional financial system will continue to seek alternative routes for moving value. Cryptoassets, and stablecoins in particular, offer speed, liquidity and access to global markets. The UK has already treated crypto-related sanctions evasion as a serious policy concern. The next step is to ensure that the regulatory framework helps identify and disrupt the points of liquidity and convertibility on which those networks depend.

At the same time, the debate should avoid caricature. Crypto is not merely a threat. In some respects, public blockchains have created investigative opportunities that do not exist in traditional finance. Law enforcement agencies can map the movement of assets across a blockchain far faster than they could reconstruct equivalent flows through multiple banks, jurisdictions and mutual legal assistance channels. Crypto investigations have produced notable asset recovery successes precisely because some activity is transparent and permanent.

This is one of the paradoxes at the heart of the debate: crypto can accelerate financial crime while also making some financial flows more visible to investigators. The policy goal should be to preserve and enhance that investigative advantage, not accidentally undermine it.

Responsible Privacy

That is why the growing use of privacy-enhancing technologies by legitimate financial institutions deserves close attention. There are good commercial reasons why banks and market participants may not want all transaction details visible on public ledgers. Privacy is not inherently suspicious. But some of the techniques used to protect privacy may also reduce the visibility that currently supports blockchain investigations. If traditional financial institutions adopt privacy measures that obscure transaction flows, they may inadvertently recreate some of the opacity associated with the tools favoured by criminal actors such as mixers.

This does not mean privacy should be rejected. It means the UK needs to define what responsible privacy looks like in financial infrastructure. The challenge is to allow legitimate confidentiality while ensuring that accountable institutions can provide information to supervisors and law enforcement when required. Thus, the question becomes one of data mobility and the need to rethink what information should ‘travel’ with crypto transactions. Simply pushing more personal data around the system may not be the right answer. In some cases, cryptographic attestations, including proof that customer due diligence has been performed by an accountable institution, may be more useful than replicating traditional payment-message logic in an environment for which it was not designed.

Credibility as Competitiveness

At the heart of this debate is how the UK should think about competitiveness. The standard framing is that the UK must balance innovation and regulation. But that is too simplistic. The more important question is whether high-quality regulation can become part of the UK’s value proposition. If authorisation is demanding but predictable, if supervision is technically informed, and if firms can understand what good looks like, then UK regulation can become a mark of credibility rather than merely a cost of entry.

quote
The UK will need to show that supervision, enforcement, information sharing and international cooperation work in practice

There will inevitably be trade-offs. Higher standards will raise barriers to entry. Some firms may choose more permissive jurisdictions. Smaller innovators may find the process difficult and overwhelming. But a race to the bottom would not serve the UK well. The UK is unlikely to win by being the lightest-touch jurisdiction. It may, however, win by being the jurisdiction where responsible firms can innovate with confidence because the rules are clear, the supervisor understands the technology and the regime is internationally respected.

That credibility will matter as the UK prepares for scrutiny of its anti-money laundering and counter-terrorist financing effectiveness under its fifth-round evaluation of the Financial Action Task Force. It will not be enough to show that rules exist. The UK will need to show that supervision, enforcement, information sharing and international cooperation work in practice. That means looking beyond formal compliance to whether risks are actually being identified and disrupted.

The UK will also face international challenges. The EU and US will continue to shape global markets because of their size. Their approaches may diverge, and full alignment may not be achievable. The UK should not define success as splitting the difference between Brussels and Washington. Instead, it should focus on interoperability: shared outcomes, compatible standards, effective information exchange and a regulatory environment that allows responsible firms to operate across borders without creating avoidable gaps.

The UK has advantages. It has deep financial markets, legal expertise, supervisory experience and a long history of adapting to changes in global finance. But those advantages will only matter if policy keeps pace with the financial system that is emerging.

The core risk for now is that the UK builds a regime for the crypto market it can see: registered firms, centralised exchanges, authorised issuers and visible consumer-facing products. That market needs regulation, but it is not the whole story. The more important question is how value moves across the boundaries between regulated and unregulated activity, between crypto and traditional finance, between public transparency and private infrastructure, and between domestic supervision and global networks.

The UK should therefore judge its virtual asset framework against a simple test: does it regulate the financial system crypto is creating, or merely the crypto market regulators can most easily recognise?

If the UK gets that right, it can support innovation without being naïve about risk. If it gets it wrong, it may achieve the appearance of control while the most important risks may move elsewhere.

An artificial intelligence language model (GenAI) was used to create a summary of the roundtable discussion, on which this article is based.

© RUSI, 2026.

The views expressed in this Commentary are the authors', and do not represent those of RUSI or any other institution.

For terms of use, see Website Terms and Conditions of Use.

Have an idea for a Commentary you'd like to write for us? Send a short pitch to commentaries@rusi.org and we'll get back to you if it fits into our research interests. View full guidelines for contributors.


WRITTEN BY

Tom Keatinge

Director, CFS

Centre for Finance and Security

View profile


Footnotes


Explore our related content