The FATF Travel Rule highlights compliance gaps in 2026
The FATF Travel Rule faces compliance gaps in 2026, exposing challenges in cross-border crypto transactions despite progress in several major markets.
The Travel Rule is the single compliance obligation that most reliably shapes how a crypto transfer between two exchanges actually works. It requires that identifying information travels alongside the money. Seven years after the Financial Action Task Force extended the concept to virtual assets, the picture in August 2026 is one of serious progress in a handful of large markets and continuing unevenness everywhere else.
What the Travel Rule actually requires
At its core, the Travel Rule requires that when a virtual asset service provider sends a transfer on behalf of a customer to another virtual asset service provider, it must transmit specific identifying information alongside the transaction, typically the originator’s name, account number and, depending on the jurisdiction, address or other identifying details, along with equivalent information about the beneficiary. The rule takes its name from an older piece of traditional banking regulation requiring that identifying information “travel” with a wire transfer between financial institutions, and FATF’s 2019 guidance extended the same underlying logic to crypto transfers between exchanges, custodians and other regulated intermediaries. The purpose is to close a gap that made crypto transfers, unlike traditional wire transfers, largely anonymous from the receiving institution’s perspective, which anti-money laundering regulators viewed as a significant vulnerability given how quickly and cheaply value can move across borders on a blockchain compared with the traditional banking system.
Implementing the rule in practice has proven more difficult than writing it, because unlike the banking system, where a relatively small number of correspondent banks already had established channels for exchanging this kind of data, the crypto industry had no equivalent shared infrastructure when the rule was introduced. That gap has been filled unevenly by a mix of competing commercial messaging protocols that different exchanges and custodians have adopted, meaning two compliant firms in different jurisdictions do not automatically have a working technical channel to exchange the required data even when both are legally obligated to do so.
The United States: an old rule stretched to cover crypto
The United States did not invent a crypto rule so much as extend an existing one. Travel Rule requirements have been part of the Bank Secrecy Act since 1996, long before anyone was moving value on a blockchain. In 2019, FinCEN extended those requirements to virtual asset service providers, applying a $3,000 threshold to both domestic and international transfers.
That threshold has become the point of friction. FATF’s own standard sits lower, and there has been sustained pressure from FinCEN and the Treasury to bring the international threshold down to $1,000 to align with it. For firms operating across borders, the practical consequence is that a US-calibrated compliance system can be under-collecting relative to what a foreign counterparty’s regulator expects.
The United Kingdom: reasonable steps in an unreasonable world
The Financial Conduct Authority has required crypto firms to comply with Travel Rule obligations since September 2023. The more interesting development came in late 2025, when the UK Parliament passed Financial Services and Markets Act regulations addressing the awkward case that every compliance officer already knew about: what a firm is supposed to do when the counterparty is in a jurisdiction that has no Travel Rule at all.
The answer Parliament settled on is that firms must “take reasonable steps” to obtain counterparty information even when dealing with unregulated jurisdictions. It is a duty of effort rather than a duty of result, which is a fair reflection of what is actually achievable.
The European Union: the most harmonized block
The EU has gone furthest toward a single, consistent regime. The Transfer of Funds Regulation and MiCA both became fully applicable on December 30, 2024, giving crypto firms across the bloc one rulebook rather than twenty-seven interpretations. The European Banking Authority followed with final 2025 guidelines on “central contact points” for virtual asset service providers, establishing where regulators and counterparties should direct compliance queries. Taken together, this makes the EU one of the more harmonized regions for Travel Rule compliance anywhere.
Singapore: early mover, widening scope
Singapore moved early. The Monetary Authority of Singapore’s Notice PSN02 has been in effect since 2020, well ahead of most peer jurisdictions. The scope has since widened: Singapore’s Financial Institutions Act 2024 became fully effective in January 2025, expanding oversight of cross-border digital payment token transmissions.
What FATF changed in June 2025
A June 2025 FATF update introduced three changes that matter operationally. It standardized peer-to-peer data requirements for cross-border transfers exceeding $1,000, an area previously left largely to national interpretation. It clarified the “chain of responsibility,” specifying that it begins with the first institution that receives a customer’s instructions, which removes a long-running ambiguity about who owns the obligation when multiple intermediaries are involved. And it made fraud-prevention tools mandatory, specifically address verification and name-matching, moving those from good practice to requirement.
The sunrise issue is still the hard part
None of this solves the structural problem. FATF itself acknowledged in 2024 that global implementation of the Travel Rule “was lagging,” and the consequence has a name: the sunrise issue. Firms in compliant jurisdictions are obliged to send required data to counterparties in jurisdictions that have not implemented the rule, where there may be no legal framework to receive it, no infrastructure to process it, and no obligation to reciprocate. The gap is not a failure of the compliant firm. It is a gap created by the fact that not every country has implemented the rule at the same pace, and it will close only as the slower jurisdictions catch up.
Why the gap persists
The unevenness is not simply a matter of some countries being slow bureaucracies. Implementing Travel Rule obligations requires domestic legislation, a supervisory body with the resources and mandate to enforce it, and a licensed or registered population of virtual asset service providers large enough to make enforcement meaningful. In jurisdictions where crypto activity is dominated by offshore exchanges with no local licensing requirement, or where domestic financial regulators have limited crypto-specific expertise, building that infrastructure takes years even where there is political will to do so. FATF conducts periodic mutual evaluations of member jurisdictions’ compliance, and those evaluations have consistently found a wide spread between the most advanced implementers, generally large, well-resourced financial centres, and jurisdictions still in the early stages of building a supervisory regime at all.
What this means in practice for a transaction
For an ordinary user, the sunrise issue mostly shows up as friction rather than as a visible compliance failure. A transfer from a Canadian or US exchange to a counterparty in a jurisdiction without equivalent Travel Rule infrastructure may face additional verification steps, delayed processing, or in some cases an outright refusal to process the transfer, since the sending institution cannot fulfil its own legal obligation to transmit the required data to a counterparty not equipped to receive it. This is one of the underlying reasons why moving funds between exchanges in different countries can, in 2026, still take longer or face more friction than moving funds domestically, even though the underlying blockchain transaction itself would settle in minutes regardless of where the counterparties are located.