Three Deadlines, One Reckoning: RegTech's Week of Living Dangerously

AMLA opens a consultation that will define what "monitoring" means in Europe. DORA's grace period is officially over. MiCA's authorisation deadline is days away. RegTech just stopped being a category and started being a survival strategy.
If compliance officers were hoping for a quiet European summer, the regulators had other ideas. As of this week, three of the most consequential rule sets in European financial supervision, the EU's Anti-Money Laundering framework, the Digital Operational Resilience Act, and the Markets in Crypto-Assets Regulation, moved into their next phase simultaneously. Each one carries its own deadline, its own teeth, and its own implication for the technology stack that sits between a regulated institution and a regulator's audit trail.
Welcome to RegTech in the middle of 2026, where the question is no longer "what do we need to build?" but "what did we miss?"
AMLA's monitoring consultation: the next definition fight
The newest item on the desk: the Authority for Anti-Money Laundering and Countering the Financing of Terrorism, better known as AMLA, has launched a public consultation in June 2026 on draft Guidelines for the ongoing monitoring of business relationships. The consultation closes on 3 September 2026, with final detailed guidelines on ongoing monitoring and transactions due by 10 July 2026, per AMLA's published programming document.
This is not housekeeping. The guidelines will define what "effective monitoring" looks like in practice across all 27 member states, covering transaction monitoring, customer activity reviews, and the cadence at which obliged entities must re-screen relationships. Industry analysis from KPMG and Norton Rose Fulbright has highlighted that AMLA's Single Programming Document schedules 26 RTS, ITS, and guidelines for release through 2026 and Q1 2027, with around 18 Level 2 measures landing directly on financial institutions' technology stacks.
From point-in-time to perpetual KYC
The biggest change in language is the regulator's shift from periodic refresh cycles to continuous monitoring. As RegTech Analyst flagged this month, 2026 marks a "decisive shift in how regulators evaluate AML programmes", from confirming that controls exist to confirming, with data, that those controls work.
For the vendors that have spent the past three years positioning around perpetual KYC, Fenergo, ComplyAdvantage, Hawk, SymphonyAI, Quantexa, and others, this is the moment the architecture they sold becomes the architecture regulators expect. Event-driven refresh triggers, integrated case management, network-based risk scoring, and explainable AI move from differentiator to baseline.
AMLA also held its first conference
On 9 June 2026, AMLA convened its first public conference at the Alte Oper in Frankfurt am Main. Coupled with the 10 June webinar on the identification of obliged entities eligible for direct supervision, the message from AMLA is that the institutional plumbing for direct EU-level supervision is no longer aspirational, it's operational. Selected institutions will sit under AMLA's direct oversight from 2028, but the preparation has started now.
DORA's grace period is over, and the first compulsion payments have landed
The Digital Operational Resilience Act stopped being a planning exercise this year. As reported by industry guides including Regulation DORA and IBM, 2026 marks the transition from "documentation review" to "active enforcement". National competent authorities are now cross-checking Register of Information data automatically and issuing the first compulsion payments, the regulator's polite term for fines that escalate until you comply.
Register deadlines vary, expectations don't
The 2026 Register of Information (ROI) covers ICT third-party arrangements as of 31 December 2025, with national submission deadlines that have already passed: the Dutch AFM demanded submission by 31 March 2026; the Luxembourg CSSF portal opened 11 February 2026; and the European Supervisory Authorities consolidated deadline was 30 April 2026. Institutions that missed those windows are now in the regulator's line of sight.
But the bigger shift this year is conceptual. Regulators are no longer asking, "Do you have a third-party risk policy?" They are asking, "Show us the live evidence that your critical functions can withstand a disruption right now." That demand is unmistakably a RegTech demand. Real-time control monitoring, automated incident classification, board-ready resilience dashboards, these were nice-to-haves in 2024. In 2026, they are the audit deliverable.
The vendor consolidation has begun
Industry trackers like FinTech Global have catalogued the resulting M&A wave through the first half of the year. RegTech buyers want the full stack, ICT risk, third-party risk, business continuity, and reporting, under one pane of glass. Expect more roll-ups before year-end as private equity reads the same enforcement memo as the regulated firms.
MiCA's authorisation deadline arrives in days
The week's third deadline is the loudest. As of this writing, ESMA has held firm on a 1 July 2026 authorisation deadline for all crypto-asset service providers operating in the EU under MiCA. According to Elliptic and ESMA's published guidance, any firm continuing to provide crypto services to EU clients without a MiCA licence after that date is in breach of EU law and is expected to cease operations.
Stablecoin issuers face the same cliff. Circle, whose USDC and EURC are compliant, has the floor mostly to itself in regulated venues. Tether's USDT remains non-compliant and has been delisted from multiple EU exchanges as a result. The asymmetry has already reshaped European crypto liquidity.
MiCA is the largest RegTech onboarding event in a decade
For RegTech vendors, MiCA is a once-in-a-decade demand spike. The authorisation file alone requires governance documentation, custody attestations, conflict-of-interest controls, market-abuse surveillance, white-papers for token issuers, and AML programmes, every one of which has a software counterpart that vendors like Chainalysis, Elliptic, Sumsub, Hacken, and Sanction Scanner have spent the last 18 months selling into. With ESMA also moving its interim MiCA register into a permanent supervisory system mid-2026, the data flowing out of authorised CASPs will become a structured supervisory feed in its own right.
AI in AML: the year explainability stops being optional
Behind all three regulatory frameworks sits the same uncomfortable question for compliance teams: what role can AI realistically play, and how do you defend it to a supervisor?
Industry research published this quarter, including coverage from FinTech Magazine and King's Research, shows AI-enabled KYC and AML adoption among regulated firms climbing from 42% in 2024 to 82% in 2025, with more than half of financial services firms running active AI initiatives by early this year. The global RegTech market for financial crime compliance is projected to reach USD 17.4 billion by 2032, up from USD 4.5 billion in 2025, a 21% CAGR that reflects exactly the kind of demand pull that AMLA, DORA, and MiCA are now creating in parallel.
But adoption is only half the story. AMLA's guidance is expected to put explainability and model-fairness obligations on the same footing as monitoring effectiveness, meaning every AI decision needs an audit trail a human can defend. The vendors who can ship that capability win the next procurement cycle. The vendors who can't will be acquired or quietly displaced.
What to do this week if you sit on the regulated side
Three concrete actions. First, file your AMLA consultation response before 3 September 2026, the guidelines that emerge will determine your next three years of monitoring architecture. Second, run a self-assessment against your DORA Register of Information and verify that your critical third-party arrangements have automated control evidence behind them, not just policy text. Third, if you touch crypto in any way — including through partner banking or settlement rails, confirm your counterparties' MiCA authorisation status before 1 July 2026.
The reckoning isn't theoretical. It's on the calendar. RegTech is no longer the budget line item nobody fought for. It's the line item that's keeping institutions inside the perimeter.



