EU Financial Sector Faces Four Major Regulatory Challenges in 2026
The European financial landscape is undergoing significant changes in 2026, with four key regulatory frameworks reshaping the industry. The Digital Operational Resilience Act (DORA), now in effect since January 2025, focuses on enhancing financial institutions' ability to manage ICT risks, report incidents, and test resilience. In 2026, the emphasis shifts to national authorities' interpretations and enforcement, as seen in Norway's updated guidance on incident reporting and Austria's sanctions for procedural shortcomings.
The Payment Services Directive 3 (PSD3) and the Payment Services Regulation (PSR) are set to overhaul the European payments framework, replacing PSD2/EMD2. These regulations aim to improve transaction security and create a fairer playing field between banks and non-bank providers. The PSR will be directly applicable across member states, while PSD3 requires national transposition, potentially leading to varying implementation timelines.
The Anti-Money Laundering Regulation (AMLR), part of a broader EU reform, seeks to standardize rules for preventing money laundering and terrorist financing. Scheduled to apply from July 2027, the AMLR will be supported by the new Anti-Money Laundering Authority (AMLA) in Frankfurt. In 2026, AMLA is already engaging in public consultations to develop reporting systems and technical standards.
Finally, the Markets in Crypto-Assets Regulation (MiCA) is entering its full compliance phase after its transition period ended on July 1, 2026. MiCA governs crypto-assets and service providers, with particular attention to stablecoins. From July 2027, crypto-asset service providers (CASPs) will also fall under the full AMLR obligations, adding another layer of regulatory complexity.