1. Uruguay: The BCU approves a comprehensive VASP regulatory framework.

On July 2026, the Uruguay’s Central Bank (“BCU”) published the country’s first comprehensive regulatory framework for Virtual Asset Service Providers (“VASPs”). The framework covers crypto-to-fiat and crypto-to-crypto exchange, transfers, custody and administration of virtual assets, and services related to the offering of virtual assets by an issuer, including smart contracts involving a legal entity. Software development, scriptural securities, electronic money, and NFTs that do not function as a means of payment or investment are excluded based on their economic function rather than underlying technology.

The framework introduces prudential requirements including minimum capital thresholds, mandatory guarantees in favor of the BCU, and strict asset segregation rules under which client funds may not remain with the VASP for more than 48 hours and custodied assets may not be used without the client’s express authorization. VASPs must also implement AML/CFT systems covering client due diligence, beneficial ownership identification, transaction monitoring, and suspicious activity reporting, as well as a travel rule for virtual asset transfers. In terms of cybersecurity, the framework requires independent information security functions and annual systems audits. New operators must obtain BCU authorization before commencing operations as of September, 2026. Existing operators may apply for authorization until March 2027, with full compliance required by June 2027.

2. EU: The AI Omnibus Regulation enters into force.

The European Union AI Omnibus Regulation entered into force in July 2026, amending the EU AI Act (Regulation (EU) 2024/1689) to simplify certain compliance requirements and adjust its implementation timeline.

Among the key changes introduced by the Regulation:

  • Extended timeline for high-risk AI: The application of the AI Act’s requirements for certain high-risk AI systems has been postponed to December 2027, while high-risk AI systems embedded in regulated products will become subject to the relevant requirements from August 2028.
  • Simplified compliance requirements: Certain administrative and documentation requirements under the AI Act have been streamlined, reducing compliance burdens for businesses.
  • Broader support for smaller companies: Simplified compliance measures previously available to small and medium companies have been extended to small mid-cap companies in certain areas.
  • Expanded regulatory sandboxes: The Regulation provides for broader access to AI regulatory sandboxes, including the establishment of an EU-level AI regulatory sandbox to facilitate the testing and development of AI systems under regulatory supervision.
  • Strengthened AI governance: The role and supervisory powers of the European AI Office have been expanded, particularly in relation to certain general-purpose AI systems and AI systems integrated into large online platforms and search engines.
  • Transparency obligations remain applicable: The Omnibus does not eliminate the AI Act’s transparency framework. Certain transparency obligations, including those relating to AI-generated or manipulated content and interactions with AI systems, continue to apply from August 2026.
  • The EU AI Omnibus does not replace the EU AI Act. Rather, it adjusts its implementation, timelines and certain compliance requirements, while maintaining the EU’s risk-based regulatory framework for artificial intelligence.

These developments are particularly relevant for companies developing, providing or deploying AI-based solutions in the EU, including businesses operating in regulated sectors such as financial services and fintech.

3.  EU: DAC8 compliance deadline for crypto tax reporting.

July 2026 marked the compliance deadline under the European Union’s Directive on Administrative Cooperation (DAC8) for Crypto-Asset Service Providers (“CASPs”) operating within the European Union. CASPs are now required to have fully operational systems for client due diligence, transaction reporting, and internal controls in connection with the directive’s crypto-asset tax reporting framework. Under DAC8, CASPs must report detailed user and transaction data to their respective national tax authorities, which will then automatically exchange that information across all 27 EU Member States. The first formal reporting submissions are due before September 30, 2027.

4. UK: The FCA publishes final rules for its cryptoasset regulatory regime.

The United Kingdom’s Financial Conduct Authority (“FCA”) published a comprehensive suite of policy statements setting out the final rules for the country’s new cryptoasset regulatory regime. The rules cover admissions and disclosures standards, a dedicated market abuse regime for cryptoassets (PS26/9), stablecoin issuance requirements (PS26/10), regulated cryptoasset activities including trading, custody and staking (PS26/11), and a prudential framework for cryptoasset firms (PS26/12). The regime is established under The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026, enacted by Parliament on February 4, 2026. Firms will be able to apply for FCA authorization starting September 30, 2026, with the authorization window closing on February 2027. The full regime becomes mandatory on October 2027.