How crypto regulation actually works, and why it varies so much
Why the same asset is treated differently in different countries, what a licence does and does not mean, and how rules reach you as a user.
Crypto is not regulated by one framework but by several existing ones applied by analogy — securities, money transmission, anti-money-laundering and consumer protection — each administered by a different body. That is why treatment varies so much by country, and why a licence in one place tells you very little about protection in another.
This is an explanation of how crypto regulation is structured and how it reaches you. It deliberately describes no specific rule, case, deadline or country’s current position, because those change constantly and a confidently wrong regulatory claim is worse than none. For your own situation, get advice from someone qualified in your jurisdiction.
There is no single crypto regulator
The foundational thing to understand is that crypto was not born into a regulatory framework built for it. Existing frameworks were applied by analogy, and different bodies reached for different analogies.
A securities regulator may treat some tokens as investment contracts. A financial-conduct or money-transmission authority may treat an exchange as a payments business. An anti-money-laundering body imposes identity and reporting obligations regardless of either. A tax authority takes its own independent view. A consumer-protection or advertising body governs how products may be marketed.
These bodies have different mandates and can reach different conclusions about the same asset at the same time. That is not incoherence; it is what happens when several existing regimes each cover part of something new.
The classification question underneath everything
Most regulatory disagreement reduces to one question: is a given token a security, a commodity, a payment instrument, or something else?
The distinction matters enormously because each classification carries a different rulebook — registration and disclosure obligations, who may sell it, who may hold it, and what happens if those obligations were not met. Different jurisdictions apply different tests, and some assets are treated one way in one country and another way elsewhere.
What follows for a user is subtle but practical: the availability of an asset on a platform in your country is partly a legal judgement rather than a commercial one, and it can change without the asset changing at all.
What AML obligations actually require
The most visible regulation to ordinary users is anti-money-laundering, because it is why you are asked for documents.
Broadly, regulated platforms must verify who their customers are, monitor transactions for patterns, screen against sanctions lists, keep records, and report activity meeting defined thresholds — often without being permitted to tell the customer. That last point explains a great deal of otherwise baffling behaviour: an account frozen with no explanation is frequently a platform that is legally barred from giving one.
Related obligations require identifying information to travel with transfers between institutions, which is why sending to some destinations triggers extra questions. And requirements are typically tiered, so higher limits demand more documentation. Understanding what will be asked and when is genuinely useful; content that helps people evade these checks is something we do not publish under any framing, as set out in our Editorial Guidelines.
What a licence does and does not mean
“Licensed and regulated” appears in a great deal of crypto marketing and is among the most over-read phrases in the sector.
A licence is granted by a specific authority, for specific activities, in a specific jurisdiction. It may cover money transmission but not custody. It may permit serving local customers only. It may come from a jurisdiction whose regime is considerably lighter than the one you live in. And crucially, it usually says nothing about whether your funds are protected if the company fails — deposit-guarantee schemes generally do not extend to crypto holdings.
The useful questions are which authority, for what activities, covering which customers, and what it says about client-asset segregation. A registration number in a footer answers none of those.
Why your jurisdiction decides your experience
Two people using the same platform can have genuinely different rights, available features, tax treatment and recourse, purely by location. Platforms geo-restrict features to comply with local rules, and the restrictions are not always visible before signing up.
This is also why terms of service matter more than they appear to. They usually specify which jurisdiction’s law governs the relationship and where disputes are heard — which may be nowhere near you, and which determines what happens in an insolvency.
How rules reach a user in practice
Regulation rarely arrives as a rule addressed to you. It arrives as friction: a verification request, a delisted asset, a feature unavailable in your country, a withdrawal held for review, a platform exiting a market, or a marketing claim that quietly disappears.
Interpreting that friction correctly is most of the practical value of understanding the structure. A platform demanding more documentation is usually complying, not obstructing. A delisting is often a classification judgement rather than a verdict on the asset’s quality.
Why the picture keeps moving
It is worth understanding why this area is unusually unstable rather than treating each change as news. Regulators are applying frameworks written before the technology existed, which means much of the position is established through enforcement and litigation rather than through rules published in advance. That produces long periods of genuine uncertainty followed by abrupt clarification.
At the same time, jurisdictions are competing: some position themselves as welcoming to attract businesses, others prioritise consumer protection, and firms relocate in response. The practical effect for a user is that a platform’s regulatory posture is not a fixed attribute. It can change because the platform moved, because the rules moved, or because an enforcement action clarified something that had been ambiguous for years — which is why any regulatory statement worth reading carries a date.
What is generally NOT protected
One asymmetry is worth stating plainly, because marketing frequently blurs it. The protections most people associate with regulated finance — deposit guarantees, compensation schemes, a statutory ombudsman — generally do not extend to crypto holdings, even on a licensed platform. Regulation in this sector predominantly governs how a business must behave, not what happens to your money if it fails.
The practical implication is that “regulated” and “protected” are different claims, and only one of them is usually being made. A platform can be fully compliant with every applicable obligation and still leave customers as unsecured creditors in an insolvency. That is not a loophole; it is the ordinary position, and assuming otherwise is one of the more expensive misreadings available.
How we cover this
As compliance journalism: explaining what rules require and what the risks of breaking them are, never how to route around them. We do not publish legal advice, we do not assert the current status of any specific rule without a source, and where a regulatory position is contested we say that rather than picking the tidier answer. Regulatory posture is one dimension in our published rubric precisely because it determines whether a platform is usable by a given reader at all.
- Several existing regimes apply by analogy, administered by bodies with different mandates.
- Most disagreement reduces to classification, which decides the entire applicable rulebook.
- A licence is jurisdiction- and activity-specific and rarely protects funds in an insolvency.
- Regulation reaches users as friction — verification requests, delistings, geo-restrictions.