Overseas crypto providers could fall under the UK’s incoming authorisation regime if they serve British consumers, even when their businesses are based abroad, the Financial Conduct Authority (FCA) has said.
The regulator published its final cryptoasset perimeter guidance on Sept. 16, setting out when firms carrying out newly regulated cryptoasset activities may require FCA authorisation from Oct. 25, 2027.
Applications for transitional arrangements open on Sept. 30, meaning overseas platforms, custodians and staking providers have less than two weeks to assess how UK consumers access their services.
For the purposes of the guidance, a “UK consumer” is an individual in the UK acting outside a trade, business or profession. The FCA said this is a statutory territorial definition, which may differ from client classifications used elsewhere in its Handbook.
Consumer access determines whether firms are inside the regime
The FCA’s territorial guidance says firms must first apply ordinary territorial principles. Section 418 deeming provisions can then bring certain activities carried out by an overseas provider within the UK regulatory perimeter when they involve a UK consumer.
The regulator gives the example of an overseas qualifying cryptoasset trading platform. If UK consumers cannot access the platform and an authorised UK firm trades on it as principal under the relevant permission, the overseas platform remains outside the platform activity perimeter.
The position changes if the authorised UK firm uses the platform as an agent for UK consumers. In that case, the overseas operator falls inside the perimeter and requires authorisation, according to the platform guidance.
The FCA said the outcome in this example depends on both whether consumers can access the service and the capacity in which the UK firm trades.
Other crypto services are subject to activity-specific conditions. An overseas provider safeguarding cryptoassets or arranging staking for a UK consumer may be deemed to be operating in the UK when it acts independently of a person authorised for that activity.
However, that deeming provision does not apply where the provider acts at the direction of the authorised person.
DeFi services require individual assessment
Automated-protocol interfaces will not be treated under a single blanket rule. The FCA said each case must be assessed on its facts, with attention focused on whether an identifiable person carries out the elements of a regulated activity by way of business in the UK.
The transitional application period runs from Sept. 30, 2026 through Feb. 28, 2027. The new activities will enter the regulatory perimeter on Oct. 25, 2027.
Existing registrations and permissions will not be converted automatically. A firm that is already authorised may therefore need to vary its permission if its current scope does not cover the new activities.
The FCA said the regulatory boundary depends on the functions and structure of each service. Its PERG guidance explains the regulator’s interpretation of the legislation but is not legally binding in court, leaving exchanges, custodians, staking providers and DeFi platforms to apply it to their own circumstances.
