Financial Integrity Monitor

European Economic Area EEA

Domains (D1–D6)
6
Sources
11
Role actions
8
Horizon <90d
5
Jurisdiction profile
CleanTier ARisk: IncreasingMixed

EU AML architecture is mid-transition: AMLR (Reg 2024/1624) becomes the directly-applicable single rulebook from 10 July 2027, 6AMLD (Dir 2024/1640) is under national transposition, and AMLA (Reg 2024/1620) began operations mid-2025 in Frankfurt, building toward direct CASP/bank supervision from 2028.

MoreSanctions architecture (19th/20th Russia packages) is aggressive but BO transparency was rolled back by the 2022 Sovim ruling and CASP supervision remains nationally fragmented pending AMLR application.

Key deficiencies
  • Beneficial ownership register public access remains restricted EU-wide since the CJEU Sovim/WM ruling (Nov 2022); BORIS interconnection cannot provide public access, undermining D2 transparency
  • Bulgaria, an EU/EEA member state, remains on the FATF Jurisdictions Under Increased Monitoring ('grey') list pending on-site verification as of the June 2026 Plenary
  • No formal operational information-exchange interface exists between Europol and AMLA, fragmenting the EU financial intelligence landscape
  • Divergent national implementation of MiCA/CASP AML supervision creates 'jurisdiction shopping' risk flagged by France's AMF, Austria's FMA and Italy's CONSOB
  • AMLA direct supervision of high-risk obliged entities (including crypto) does not begin until 2028, leaving a multi-year gap during which national supervisors retain primary responsibility despite acknowledged inconsistency
Recent developments (18m)
  • AMLA began operations mid-2025 in Frankfurt; Bruna Szego appointed first Chair; staff reached ~120 by end-2025
  • European Commission added Russia to the EU list of high-risk third countries for AML/CFT (Delegated Regulation (EU) 2026/46, 3 Dec 2025)
  • EU 19th sanctions package (23 Oct 2025) sanctioned the A7A5 ruble-backed stablecoin ecosystem, its developer, Kyrgyz issuer and trading platform, plus five additional Russian banks and third-country banks/oil traders
  • EU 20th sanctions package (23 Apr 2026, crypto provisions effective 24 May 2026) imposed a sector-wide transaction ban on Russian- and Belarusian-established crypto-asset service providers and activated the anti-circumvention tool against an entire jurisdiction for the first time
  • EBA's fifth biennial ML/TF risk assessment flagged a 2.5-fold increase in authorised CASPs in the EU between 2022 and 2024 alongside persistent AML/CFT control weaknesses
  • FATF June 2026 Plenary made an initial determination that Bulgaria has substantially completed its action plan, pending an on-site verification visit before delisting
Weekly brief

Lead signal

Lead Signal

Read full brief

Lead Signal

The financial-integrity picture for the EEA this cycle is defined by an escalation in the external architecture of enforcement running alongside a deepening internal-architecture gap. The Council of the European Union twentieth sanctions package, adopted 23 April 2026 with crypto provisions effective 24 May 2026, activated a sector-wide, jurisdiction-level anti-circumvention tool against Russian and Belarusian crypto-asset service providers, the first time the EU has moved from entity-level designation to a blanket transaction ban against an entire national CASP sector. That structural innovation, however, arrives against a persistent evasion architecture it is designed to counter: the ruble-backed A7A5 stablecoin ecosystem, launched via a Kyrgyz issuer after the March 2025 seizure of Garantex and settled through the successor exchange Grinex, crossed one hundred billion dollars in cumulative on-chain transaction volume by January 2026 before layered EU, US and UK sanctions compressed daily volumes from one point five billion dollars to approximately five hundred million dollars.

This is architecture-over-incident in its purest form: individual designations trail a persistent successor-platform pattern rather than closing it. The same cycle that hardens the external sanctions perimeter of the EU leaves internal supervisory architecture mid-transition. The Anti-Money Laundering Authority continues its Frankfurt build-out under Chair Bruna Szego, having taken administration of the EuReCA database and finalised cross-border reporting-format technical standards, yet the bloc beneficial-ownership transparency regime remains structurally rolled back more than three years after the CJEU Sovim and WM judgment invalidated indiscriminate public register access, with no legislative fix identified. Meanwhile, three national competent authorities, in France, Austria and Italy, have publicly flagged a jurisdiction-shopping vulnerability under the MiCA single-passport model that persists until AMLA assumes direct CASP supervision no earlier than 2028. Sanctions architecture is advancing faster than the transparency and supervisory architecture meant to support it.

Other Developments

Russia formal addition to the EU list of high-risk third countries for AML and CFT purposes, via Commission Delegated Regulation (EU) 2026/46 effective 3 December 2025, triggers enhanced due diligence obligations for EU obliged entities EU-wide, a listing distinct from and additional to the CFSP restrictive-measures regime that has targeted Russia since 2014 and 2022.

Beneficial-ownership transparency remains structurally opaque. The EU BORIS interconnection system continues to operate on a restricted, legitimate-interest basis rather than providing public access, a condition that disproportionately benefits enabler jurisdictions inside the bloc, including Luxembourg, Cyprus and Malta, previously flagged for patchy beneficial-ownership implementation.

Bulgaria remains the sole EU or EEA member state on the FATF grey list, though the June 2026 Plenary made an initial determination that its AML and CFT action plan has been substantially completed, with an on-site verification visit expected ahead of the October 2026 Plenary before any delisting decision.

The EU high-risk third country list itself shows volatility. Commission Delegated Regulation (EU) 2026/83 added Bolivia and the British Virgin Islands while delisting six African jurisdictions, meaning the British Virgin Islands, a well-known offshore and enabler jurisdiction, re-entered the list only months after being delisted in June 2025.

National regulators are converging on a jurisdiction-shopping warning. The AMF, FMA and CONSOB have called for stronger EU-level oversight of CASP authorisation under MiCA passporting, a vulnerability compounded by the European Banking Authority finding, in its fifth biennial ML/TF risk assessment, that authorised EU CASPs grew two and a half times between 2022 and 2024 alongside persistent AML and CFT control weaknesses.

A DPRK IT-worker proliferation-financing network used Spain as an EEA transit node. OFAC March 2026 designations identified a Vietnam-based facilitator converting approximately two point five million dollars into cryptocurrency between mid-2023 and mid-2025 for operatives linked to the Amnokgang Technology Development Company, illustrating EU exposure as an unwitting transit point in a wider multi-chain DPRK laundering playbook.

Shadow-fleet vessel sanctions listings continued expanding, reaching six hundred forty vessels by June 2026, alongside a full transaction ban on Rosneft and Gazprom Neft and a Russian LNG import ban from 2027 under the nineteenth sanctions package, targeting core Russian war-economy revenue streams.

A structural gap persists between AMLA and Europol. A June 2026 Council document confirms the absence of a reciprocal operational information-exchange interface between the two bodies, fragmenting the ability to cross-match AMLA supervisory findings with Europol criminal intelligence.

Sanctions-regime divergence across the Atlantic continues. OFSI issued a one hundred sixty thousand pound penalty against Bank of Scotland for Russia sanctions breaches in January 2026, while OFAC and OFSI convened an Enhanced Partnership Exchange in January and mid-2026 to align shadow-fleet typologies, even as the core EU Russia sanctions regime requires unanimous six-monthly renewal, a recurring political veto point absent from the non-sunsetting US and UK designation models. The United Kingdom assumed the FATF Presidency effective 1 July 2026, with Giles Thomson prioritising fraud and scam-compound risk globally.

Cross-Monitor Connections

Three connections to adjacent monitors stand out this cycle. The persistence of the A7A5 and Grinex evasion architecture, tied to Ilan Shor-linked infrastructure, warrants a WDM assessment of whether this financial network reflects state direction or is more accurately read as a criminally-captured architecture operating with state tolerance. The EU full transaction ban on Rosneft and Gazprom Neft constrains a core Russian war-economy revenue stream in a manner that the conflict-finance framework of SCEM can sharpen from source through channel to deployment, particularly given the parallel expansion of shadow-fleet vessel listings to six hundred forty by June 2026, a commodity-flow evasion signal of direct relevance to ERM tracking of Russian oil-revenue circumvention routes. Taken together, these flags illustrate how a single sanctions-architecture development radiates across the state-capture, conflict-finance and commodity-flow analytical lenses simultaneously.

Outlook

The next several quarters carry a dense regulatory-horizon calendar. AMLA is expected to publish its first work programme and supervisory methodology by December 2026, while the Bulgaria on-site FATF verification visit, expected ahead of the October 2026 Plenary, will determine whether the sole grey-listed bloc member exits enhanced monitoring. The structural centre of gravity, however, sits further out: the AMLR becomes directly applicable EU-wide from 10 July 2027, folding crypto-asset service providers into the same obliged-entity framework as banks, while sixth Directive transposition completes nationally on a divergent two to three year timetable from mid-2024. AMLA first harmonised selection of up to forty high-risk cross-border obliged entities for direct supervision follows in 2027, with direct supervision itself commencing in 2028. Until that hybrid EU-level supervisory perimeter is operative, the jurisdiction-shopping vulnerability documented this cycle, and the beneficial-ownership opacity that has persisted since 2022, are likely to remain the load-bearing structural weaknesses beneath an increasingly aggressive external sanctions posture. These are scenario-oriented observations, not predictions.

weekly_brief_draft · JID EEA
Domain intelligence (D1–D6)

D1 Sanctions Architecture and Evasion

Sanctions Architecture and Evasion

Continue reading

The defining sanctions-architecture development this cycle is the shift from entity-level to jurisdiction-level enforcement. The Council of the European Union adopted its twentieth sanctions package on 23 April 2026, with crypto provisions taking effect 24 May 2026, imposing a complete transaction ban between EU persons and any crypto-asset service provider or platform established in Russia, alongside an equivalent sectoral ban for Belarus. This activates, for the first time, an anti-circumvention tool at the level of an entire national CASP sector rather than against individually named platforms, closing precisely the gap that allowed a successor exchange to emerge each time a predecessor was designated. Neither OFAC nor OFSI has mirrored this jurisdiction-wide approach, making the EU regime the most structurally advanced of the three in this specific respect, even as it remains the most exposed to the unanimity-renewal constraint described below.

The persistence problem this measure is meant to solve is illustrated starkly by the ruble-backed A7A5 stablecoin ecosystem. Following the March 2025 seizure of Garantex, a network linked to Ilan Shor launched A7A5 through a Kyrgyz issuer, routing settlement through Promsvyazbank and the successor exchange Grinex. Cumulative on-chain transaction volume crossed one hundred billion dollars by January 2026, less than a year after launch, before layered United States, United Kingdom and EU sanctions constrained daily volumes from approximately one point five billion dollars to roughly five hundred million dollars. The pattern is architecture, not incident: designation of one node in the chain reliably produces a successor node rather than a cessation of activity, and the sanctions response this cycle is notable precisely because it attempts to target the sector rather than the node.

Compounding this is the addition of Russia to the EU list of high-risk third countries for AML and CFT purposes, via Commission Delegated Regulation (EU) 2026/46, effective 3 December 2025. This listing operates on a distinct legal track from the CFSP restrictive-measures regime that has applied to Russia since 2014 and again since 2022, and it obliges enhanced due diligence across the EU obliged-entity population regardless of whether a given counterparty or transaction is separately subject to a CFSP asset freeze or transaction ban. The layering of an AML high-risk designation atop an existing sanctions regime is itself a structural signal: it extends the compliance perimeter from designated entities and transactions to an entire jurisdiction-of-counterparty risk factor.

The EU is not the only jurisdiction exposed to Democratic Peoples Republic of Korea proliferation-financing infrastructure operating through crypto rails. OFAC March 2026 designations identified a Vietnam-based facilitator who converted approximately two point five million dollars into cryptocurrency between mid-2023 and mid-2025 on behalf of an IT-worker network linked to the Amnokgang Technology Development Company, with operations spanning Vietnam, Laos and Spain. Spain functioned here as an unwitting European transit and enabler node in a wider multi-chain, multi-jurisdiction laundering playbook, even though the EU was not the primary designated target of the underlying scheme. This illustrates a recurring pattern in DPRK-linked proliferation finance: exposure arrives through transit-node status rather than through direct sanctions-evasion intent by the exposed jurisdiction itself.

Divergence between the three principal Western sanctions regimes remains a standing architectural feature rather than a transitional one. OFSI imposed a one hundred sixty thousand pound penalty on Bank of Scotland, part of Lloyds Banking Group, for Russia sanctions breaches in January 2026, illustrating the continued UK reliance on an administrative, pecuniary-penalty enforcement posture distinct from the EU AMLA-centred supervisory model. Separately, OFAC and OFSI convened an Enhanced Partnership Exchange across January and mid-2026 specifically targeting shadow-fleet typologies, a bilateral alignment mechanism operating outside the EU framework entirely, evidence of a parallel United States and United Kingdom enforcement-convergence track that the EU does not currently participate in. Underlying all of this is a structural asymmetry the EU regime alone carries: its core Russia sanctions architecture requires unanimous six-monthly renewal, with the core regime renewed to 31 July 2026 and the Crimea and Sevastopol regime to 23 June 2026, creating a recurring political veto point that the non-sunsetting United States and United Kingdom designation models do not share. This is a standing structural vulnerability in the EU sanctions architecture, independent of any single enforcement outcome, and it is the analytical counterweight to the jurisdiction-wide anti-circumvention innovation described above.

Read together, these developments indicate an EU sanctions architecture that is simultaneously innovating at the enforcement frontier, through sector-wide CASP bans, and structurally fragile at its foundation, through the unanimity-renewal mechanism, while transatlantic partners pursue a differently structured but converging enforcement track. The red-flag indicators associated with this evasion architecture are themselves instructive for obliged entities operating correspondent or virtual-asset-service-provider relationships: rapid migration of user volume to a successor exchange or stablecoin issuer following designation of a predecessor platform, and ruble-pegged stablecoin settlement routed through a single domestic bank acting as a fiat gateway, are both observable at the payment-data and on-chain level and both featured directly in the A7A5 and Grinex pattern this cycle.

Outlook

The near-term calendar carries two Russia-sanctions renewal dates that will test the EU unanimity mechanism directly: the Crimea and Sevastopol regime falls due 23 June 2026 and the core regime 31 July 2026, and any single Member State veto at either juncture would represent a structural discontinuity in an otherwise hardening EU sanctions posture. Separately, the EU AML high-risk-country listing of Russia, layered atop the CFSP regime, is not itself time-limited and will continue to shape enhanced due diligence obligations for EU obliged entities regardless of the outcome of the sanctions-renewal votes. Whether the sector-wide CASP transaction ban activated in the twentieth package materially reduces A7A5 or Grinex-linked volumes, or whether a further successor platform emerges, is the key architecture-level question for the coming cycles, and would be the clearest test yet of whether jurisdiction-wide anti-circumvention tools outperform entity-level designation in an evasion ecosystem defined by its capacity to reconstitute itself. This is offered as analytical orientation on the observed trajectory, not as a forecast of any specific outcome.

Cumulative analysis

Sanctions Architecture and Evasion — Cumulative Analysis

Through this baseline cycle, the EEA sanctions-architecture picture integrates into a single structural story: an EU regime that is innovating at the enforcement frontier while carrying a standing procedural vulnerability at its foundation, set against a Russian evasion ecosystem defined by its capacity to reconstitute itself faster than entity-level designation can suppress it. The Council of the European Union twentieth sanctions package, adopted 23 April 2026 with crypto provisions effective 24 May 2026, marks the first activation of a jurisdiction-wide anti-circumvention tool against an entire national CASP sector, imposing a complete transaction ban between EU persons and any crypto-asset service provider established in Russia, with an equivalent sectoral measure for Belarus. Neither OFAC nor OFSI has mirrored this jurisdiction-level approach, positioning the EU as the most structurally advanced of the three principal Western sanctions regimes on this specific enforcement dimension.

The evasion architecture this measure targets has a documented history across this baseline: following the March 2025 seizure of Garantex, a network linked to Ilan Shor launched the ruble-backed A7A5 stablecoin through a Kyrgyz issuer, settling through Promsvyazbank and the successor exchange Grinex. Cumulative on-chain transaction volume crossed one hundred billion dollars within less than a year of launch, before layered United States, United Kingdom and EU sanctions compressed daily volumes from approximately one point five billion dollars to roughly five hundred million dollars. Read cumulatively, this is the clearest demonstrated case in the current baseline of a persistent, self-reconstituting evasion architecture: each individual platform designation to date has produced a successor node rather than a cessation of underlying activity, and the twentieth package sector-wide ban is significant precisely because it is the first EU attempt to target the sector rather than any single node within it.

The compliance perimeter around this evasion architecture widened further with the addition of Russia to the EU list of high-risk third countries for AML and CFT purposes, via Commission Delegated Regulation (EU) 2026/46, effective 3 December 2025, a designation operating on a distinct legal track from the CFSP restrictive-measures regime applied to Russia since 2014 and 2022. This layering, an AML high-risk-country designation atop an existing sanctions regime, extends enhanced due diligence obligations across the EU obliged-entity population regardless of whether a specific counterparty or transaction separately triggers a CFSP asset freeze, and it is best read as a structural widening of the compliance perimeter rather than as an incremental listing update.

The cumulative picture also includes exposure that arrives through transit rather than direct targeting. OFAC March 2026 designations identified a Vietnam-based facilitator who converted approximately two point five million dollars into cryptocurrency between mid-2023 and mid-2025 for an IT-worker network linked to the Amnokgang Technology Development Company, with operations spanning Vietnam, Laos and Spain. Spain functioned as an unwitting European transit and enabler node in this wider multi-chain, multi-jurisdiction Democratic Peoples Republic of Korea laundering playbook, even though the EU was not the primary designated target. Integrated across the baseline, this is a recurring structural feature of DPRK-linked proliferation finance rather than an isolated incident: European exposure most often arrives through transit-node status, not through direct evasion intent by the exposed jurisdiction.

Divergence among the three principal Western sanctions regimes is a standing, rather than transitional, architectural feature across this baseline. OFSI imposed a one hundred sixty thousand pound penalty on Bank of Scotland for Russia sanctions breaches in January 2026, consistent with the continued UK reliance on an administrative, pecuniary-penalty enforcement posture distinct from the EU AMLA-centred supervisory model, while OFAC and OFSI convened an Enhanced Partnership Exchange across January and mid-2026 targeting shadow-fleet typologies specifically, a bilateral alignment track that operates entirely outside the EU framework. Underlying this divergence, and standing as the single most consequential structural vulnerability identified in the EU sanctions architecture across this baseline, is the requirement for unanimous six-monthly renewal of the core Russia regime, renewed to 31 July 2026, and of the Crimea and Sevastopol regime, renewed to 23 June 2026, a recurring political veto point absent from the non-sunsetting United States and United Kingdom designation models.

Integrated across this baseline, the state of the D1 domain is one of accelerating enforcement innovation, evidenced by the sector-wide CASP ban and the AML high-risk listing, running directly against a persistent, self-reconstituting evasion architecture and a standing unanimity-renewal vulnerability that together define the durable structural tension in EU sanctions policy toward Russia.

Outlook

The near-term calendar carries two Russia-sanctions renewal dates, 23 June 2026 for the Crimea and Sevastopol regime and 31 July 2026 for the core regime, either of which would test the unanimity mechanism directly and represent a structural discontinuity if a single Member State exercised a veto. The EU AML high-risk-country listing of Russia is not itself time-limited and will continue shaping enhanced due diligence obligations independent of the renewal votes. Across subsequent cycles, the central architecture-level question remains whether the sector-wide CASP ban activated this cycle measurably suppresses A7A5 or Grinex-linked volumes or whether the evasion ecosystem again reconstitutes around a new successor platform, a question that this cumulative record is well positioned to track going forward. This is offered as analytical orientation on an observed trajectory, not as a forecast of any specific outcome.

domain_sub_briefs · D1 · Cumulative analysis

D2 Beneficial Ownership and Corporate Transparency

Beneficial Ownership and Corporate Transparency

Continue reading

Beneficial-ownership transparency in the EEA this cycle is best read as a story of persistent structural rollback rather than incremental repair. More than three years after the November 2022 Court of Justice of the European Union judgment in WM and Sovim invalidated mandatory public access to beneficial-ownership registers as disproportionate under Charter Articles 7 and 8, the BORIS interconnection system continues to operate on a restricted, legitimate-interest basis, and no legislative fix has been identified in this baseline window. The consequence falls unevenly: opacity persists most acutely in jurisdictions previously flagged for patchy beneficial-ownership implementation inside the bloc itself, including Luxembourg, Cyprus and Malta, meaning the current transparency regime disproportionately protects exactly the enabler jurisdictions the framework was designed to constrain.

Bulgaria remains the sole EU or EEA member state on the FATF grey list, though the June 2026 Plenary made an initial determination that its AML and CFT action plan, including beneficial-ownership register accuracy and market-entry controls for virtual-asset service providers and postal operators, has been substantially completed. An on-site verification visit is expected ahead of the October 2026 Plenary, and a successful outcome would remove the last EU or EEA member state from increased monitoring, closing an internal reputational and enhanced-due-diligence gap that has applied bloc-wide enhanced scrutiny to Bulgaria-linked relationships in the interim.

Separately, the United Kingdom assumed the FATF Presidency effective 1 July 2026, with Giles Thomson appointed FATF President and prioritising fraud, scam-compound risk and risk-based supervision globally, including a grey-listing methodology review intended to relieve pressure on least-developed countries. A UK-led FATF term may in turn influence how grey-listing criteria are applied to future EEA-relevant determinations, including any subsequent Bulgaria-style pending delisting case.

The durable structural backdrop against which this cycle should be read is the EU AML Package, which comprises three distinct legal instruments proceeding on separate tracks. The AML Regulation, or AMLR, Regulation (EU) 2024/1624, is directly applicable EU-wide without national transposition and becomes applicable from 10 July 2027, harmonising customer due diligence, beneficial-ownership and cash-payment rules, including a ten thousand euro cash-payment cap, and folding crypto-asset service providers into the same obliged-entity framework as banks. The sixth Anti-Money Laundering Directive, or 6AMLD, Directive (EU) 2024/1640, by contrast, must be transposed by each Member State individually, on divergent deadlines of two to three years from its June 2024 Official Journal publication, with full bloc-wide transposition expected by approximately mid-2027, though this baseline does not establish per-Member-State transposition vehicles or status. The third instrument, the AMLA Regulation, Regulation (EU) 2024/1620, establishes the Anti-Money Laundering Authority itself, which began operations in Frankfurt on 1 July 2025 and is building toward a direct and indirect supervision perimeter that will, from 2028, shift a portion of AML supervision from purely national authorities toward a hybrid EU-level regime. This three-instrument, multi-track architecture, rather than any single beneficial-ownership development this cycle, is the structural frame within which the BORIS rollback, the Bulgaria grey-list process and future EEA beneficial-ownership signals should all be read.

Read together, the AMLR direct-applicability track and 6AMLD per-Member-State transposition track will, in principle, eventually restore a harmonised customer due diligence and beneficial-ownership baseline across the bloc, but that harmonisation date, 10 July 2027 for the AMLR and approximately mid-2027 for full 6AMLD transposition, sits roughly four and a half years after the Sovim and WM judgment first opened the current transparency gap. The multi-year interval between judicial rollback and legislative repair is itself the material beneficial-ownership finding of this cycle.

Outlook

The most immediate beneficial-ownership-adjacent milestone is the FATF on-site verification visit to Bulgaria, expected ahead of the October 2026 Plenary, which will determine whether the sole remaining EU or EEA grey-listed state exits increased monitoring. On a longer horizon, the AMLR becomes directly applicable EU-wide from 10 July 2027 and 6AMLD transposition is expected to complete across the bloc on a similar timetable, jointly restoring a harmonised legal baseline for beneficial-ownership record-keeping even though public access itself remains constrained absent a distinct legislative fix to the Sovim and WM gap. AMLA supervisory build-out, including its first work programme expected by December 2026 and its first harmonised selection of up to forty high-risk cross-border obliged entities in 2027, will progressively determine how much of the beneficial-ownership and customer due diligence architecture is enforced at EU level rather than nationally. This is offered as orientation on a known regulatory calendar, not as a prediction of outcomes.

Cumulative analysis

Beneficial Ownership and Corporate Transparency — Cumulative Analysis

Across this baseline, the state of beneficial-ownership and corporate-transparency practice in the EEA integrates into a picture of judicial rollback that has not yet been legislatively repaired, layered against a slow-moving but structurally significant AML Package build-out. More than three years after the November 2022 Court of Justice of the European Union ruling in WM and Sovim invalidated mandatory public access to beneficial-ownership registers as disproportionate under Charter Articles 7 and 8, the BORIS interconnection system continues, through this cycle, to operate on a restricted, legitimate-interest-only basis, with no legislative fix identified across the baseline window. The consequence of this multi-year rollback is not evenly distributed: opacity persists most acutely in jurisdictions previously documented for patchy beneficial-ownership implementation inside the bloc itself, notably Luxembourg, Cyprus and Malta, meaning the current transparency regime continues, cumulatively, to shelter precisely the enabler jurisdictions the original public-access framework was designed to constrain.

Bulgaria remains, through this baseline, the sole EU or EEA member state on the FATF grey list, though the June 2026 Plenary produced the first material forward movement in this record, an initial determination that Bulgaria substantially completed its AML and CFT action plan, including beneficial-ownership register accuracy and virtual-asset-service-provider and postal-operator market-entry controls. An on-site verification visit is scheduled ahead of the October 2026 Plenary, and this baseline will track whether that visit produces the delisting decision that would remove the final EU or EEA member from increased monitoring. Set against this specific national process, the United Kingdom assumed the FATF Presidency effective 1 July 2026 under Giles Thomson, prioritising fraud, scam-compound risk and a grey-listing methodology review intended to relieve pressure on least-developed countries, a presidency-level development that this cumulative record will continue to test against future EEA-relevant grey-listing determinations.

The standing structural backdrop against which every beneficial-ownership signal in this baseline should be read, and will continue to be read in subsequent cycles, is the EU AML Package, comprising three distinct legal instruments on three separate tracks. The AML Regulation, the AMLR, Regulation (EU) 2024/1624, is directly applicable EU-wide without national transposition and becomes applicable from 10 July 2027, harmonising customer due diligence, beneficial-ownership and cash-payment rules, including a ten thousand euro cash-payment cap, and bringing crypto-asset service providers into the same obliged-entity framework as banks. The sixth Anti-Money Laundering Directive, the 6AMLD, Directive (EU) 2024/1640, requires per-Member-State transposition on divergent two to three year deadlines from its June 2024 Official Journal publication, with full bloc-wide transposition expected by approximately mid-2027, though individual Member State transposition vehicles and status remain unestablished in this baseline and are flagged as a research gap for subsequent cycles. The third instrument, the AMLA Regulation, Regulation (EU) 2024/1620, established the Anti-Money Laundering Authority, which began Frankfurt operations on 1 July 2025 and is building toward a direct and indirect supervision perimeter that will, from 2028, shift a portion of AML supervision from purely national authorities toward a hybrid EU-level regime.

Integrated across the baseline, the interval between the Sovim and WM judgment and the AMLR harmonisation date of 10 July 2027, roughly four and a half years, remains the single most consequential beneficial-ownership finding: a judicially imposed transparency rollback has persisted for years longer than any legislative repair has yet materialised, and the durable AMLA architecture described above is the frame, not the fix, for that specific gap.

Outlook

The nearest beneficial-ownership-adjacent milestone remains the FATF on-site verification visit to Bulgaria ahead of the October 2026 Plenary, a determination this cumulative record will update directly upon outcome. Further out, the AMLR direct-applicability date of 10 July 2027 and the expected mid-2027 completion of 6AMLD transposition will jointly restore a harmonised legal baseline for beneficial-ownership record-keeping, even though public register access itself remains constrained absent a distinct legislative response to the Sovim and WM ruling. AMLA milestones, including a first work programme expected by December 2026 and a first harmonised selection of up to forty high-risk cross-border obliged entities in 2027, will progressively clarify how much of this architecture is enforced at EU rather than national level. This is offered as orientation on a known regulatory calendar, not as a prediction of specific outcomes.

domain_sub_briefs · D2 · Cumulative analysis

D3 Enabler Jurisdictions and Professional Facilitators

Enabler Jurisdictions and Professional Facilitators

Continue reading

The defining enabler-jurisdiction finding this cycle is the volatility of the EU high-risk third country list itself. Commission Delegated Regulation (EU) 2026/83 added Bolivia and the British Virgin Islands to the EU high-risk third country AML and CFT list while simultaneously delisting Burkina Faso, Mali, Mozambique, Nigeria, South Africa and Tanzania. The British Virgin Islands, a jurisdiction with a long-documented offshore and enabler function, re-entered the EU list only months after being delisted in June 2025, a pattern of churn that sits awkwardly alongside the more predictable, twice-yearly FATF Plenary cycle and raises a methodological question about how the EU list-update process weighs enabler-jurisdiction risk relative to FATF determinations.

A second, arguably more structurally significant enabler-jurisdiction finding concerns facilitators operating inside the EEA bloc itself rather than in an external offshore centre. Three national competent authorities, the AMF in France, the FMA in Austria and CONSOB in Italy, have publicly called for stronger EU-level oversight and tighter supervision of cross-border activity to prevent jurisdiction shopping under the MiCA single-passport model. Because a crypto-asset service provider authorised in any one Member State can passport its licence bloc-wide, the national competent authority applying the least rigorous AML and CFT scrutiny at the point of initial authorisation effectively sets the AML floor for the entire bloc. This is a structural enabler condition, not an isolated incident, and it persists as a live vulnerability until the Anti-Money Laundering Authority assumes direct supervision of a first cohort of cross-border high-risk obliged entities, a milestone that will not arrive before 2028.

Beneficial-ownership opacity compounds the enabler-jurisdiction picture from a different angle. The restricted, legitimate-interest-only access regime that has applied since the November 2022 Sovim and WM ruling disproportionately benefits enabler jurisdictions inside the EU itself, particularly Luxembourg, Cyprus and Malta, each previously documented for patchy beneficial-ownership register implementation. An enabler-jurisdiction assessment of the EEA therefore cannot rest solely on the external high-risk list; it must also account for the internal capacity of certain Member States to continue functioning as opacity centres under a framework that, for now, does not compel public disclosure.

A further capacity gap reinforces the enabler dynamic at the level of institutional cooperation rather than legal framework. A June 2026 Council document confirms that Europol and the Anti-Money Laundering Authority currently lack a reciprocal operational information-exchange interface, meaning AMLA supervisory findings, which might otherwise surface professional-facilitator networks operating across jurisdictions, cannot be systematically cross-matched against Europol criminal intelligence. In an enabler-jurisdiction analysis, this is a structural fragmentation of the EU financial-intelligence architecture rather than a single agency shortfall, and it degrades the practical value of the more aggressive external sanctions and high-risk-listing measures described elsewhere this cycle, since intelligence generated by one arm of the architecture cannot readily inform enforcement action by another.

Applying the enabler-jurisdiction filter methodology to the British Virgin Islands re-listing specifically requires separating legal framework, enforcement capacity and jurisdictional choice. A jurisdiction re-entering a high-risk list within months of exiting it may reflect a genuine deterioration in underlying AML and CFT controls, a change in EU risk-assessment methodology, or simply volatility in how episodic findings are weighed against structural indicators; this baseline does not have sufficient longitudinal EU list-history data to distinguish between these explanations with confidence, and that itself is a research gap worth flagging for subsequent cycles.

Taken together, external list volatility, internal beneficial-ownership opacity in specific Member States, MiCA passporting arbitrage and the Europol-AMLA intelligence gap describe an enabler-jurisdiction landscape in which the EEA functions simultaneously as a rule-setter externally and as a residual permissive space internally, a duality that architecture-over-incident analysis is specifically designed to surface.

Outlook

The MiCA jurisdiction-shopping vulnerability is structurally time-bound to the AMLA direct-supervision calendar: a first harmonised selection of up to forty high-risk cross-border obliged entities is expected in 2027, with direct supervision commencing in 2028, and until that date the least rigorous national CASP authorisation regime will continue to set the bloc-wide AML floor for the crypto sector under MiCA passporting. Whether the EU high-risk third country list stabilises or continues to show volatility relative to the FATF Plenary cycle is also worth monitoring, particularly for jurisdictions, like the British Virgin Islands, that combine offshore-centre characteristics with recent delisting and relisting history. This is offered as an orientation toward a known institutional calendar and a documented pattern, not as a prediction of the future listing status of any specific jurisdiction.

Cumulative analysis

Enabler Jurisdictions and Professional Facilitators — Cumulative Analysis

Integrated across this baseline, the enabler-jurisdiction landscape of the EEA presents a persistent duality: the bloc functions externally as an increasingly assertive rule-setter, while internally certain Member States and structural gaps continue to function as residual permissive space. The most visible external signal this cycle is the volatility of the EU own high-risk third country list. Commission Delegated Regulation (EU) 2026/83 added Bolivia and the British Virgin Islands while delisting Burkina Faso, Mali, Mozambique, Nigeria, South Africa and Tanzania, and the re-entry of the British Virgin Islands, a jurisdiction with a long-documented offshore and enabler function, only months after its June 2025 delisting is a pattern of churn that this cumulative record flags as methodologically unresolved: it is not yet possible, on the available longitudinal data, to distinguish genuine control deterioration from methodology change or from ordinary volatility in how episodic findings are weighed against structural indicators.

The more structurally significant enabler dynamic this baseline documents, however, sits inside the bloc itself. Three national competent authorities, the AMF in France, the FMA in Austria and CONSOB in Italy, have called publicly for stronger EU-level oversight of cross-border activity to prevent jurisdiction shopping under the MiCA single-passport model. Because a crypto-asset service provider authorised in any one Member State can passport its licence bloc-wide, the least rigorous national AML and CFT scrutiny at authorisation effectively sets the bloc-wide floor, a structural enabler condition that this baseline finds will persist as a live vulnerability until the Anti-Money Laundering Authority assumes direct supervision of a first cohort of cross-border high-risk obliged entities, a milestone not expected before 2028.

Beneficial-ownership opacity is the third integrated strand of this enabler picture. The restricted, legitimate-interest-only access regime applied since the November 2022 Sovim and WM ruling disproportionately benefits enabler jurisdictions inside the EU itself, particularly Luxembourg, Cyprus and Malta, each previously documented for patchy beneficial-ownership register implementation. Read cumulatively, this means an enabler-jurisdiction assessment of the EEA cannot rest on the external high-risk list alone; it must account for the continuing internal capacity of specific Member States to function as opacity centres under a framework that does not, at this baseline point, compel public disclosure.

A fourth, institutional-cooperation strand compounds the other three. A June 2026 Council document confirms that Europol and the Anti-Money Laundering Authority currently lack a reciprocal operational information-exchange interface, meaning AMLA supervisory findings, which might otherwise surface professional-facilitator networks operating across jurisdictions, cannot be systematically cross-matched against Europol criminal intelligence. Integrated across the baseline, this structural fragmentation of the EU financial-intelligence architecture degrades the practical value of the more aggressive external sanctions and high-risk-listing measures documented in the D1 record, since intelligence generated in one arm of the architecture cannot readily inform enforcement action in another.

Taken as a whole, this cumulative account establishes that the EEA enabler-jurisdiction profile through this baseline is defined less by any single episodic finding than by four interlocking structural conditions, external list volatility, internal beneficial-ownership opacity, MiCA passporting arbitrage, and the Europol-AMLA intelligence gap, each of which is independently durable and none of which resolves before 2027 or 2028 at the earliest.

Outlook

The MiCA jurisdiction-shopping vulnerability remains structurally bound to the AMLA direct-supervision calendar, with a first harmonised selection of up to forty high-risk cross-border obliged entities expected in 2027 and direct supervision commencing in 2028; until then the least rigorous national CASP authorisation regime will continue setting the bloc-wide AML floor. Whether the EU high-risk third country list stabilises relative to the FATF Plenary cycle, and whether the Europol-AMLA interface gap is addressed through a legislative proposal, are the two structural items this cumulative record will specifically track in subsequent cycles. This is offered as orientation toward a documented institutional calendar and pattern, not as a prediction of the future status of any specific jurisdiction or institutional gap.

domain_sub_briefs · D3 · Cumulative analysis

D4 Conflict Finance and Extractive-Industry Integrity

Conflict Finance and Extractive-Industry Integrity

Continue reading

Conflict-finance signal this cycle centres overwhelmingly on the Russian war economy rather than on extractive-industry corruption more broadly, a concentration that is itself worth naming explicitly given the FIM mandate to correct for regional and sectoral coverage imbalance. The EU nineteenth sanctions package, adopted 23 October 2025, imposed a full transaction ban on Rosneft and Gazprom Neft and a Russian LNG import ban effective from 1 January 2027, directly constraining two of the core revenue streams that fund the Russian war economy rather than merely designating discrete entities within it. Read through a conflict-finance lens, this action traces a source, namely Russian state-linked energy revenue, through a channel, namely EU import and transaction relationships, toward deployment in a continuing armed conflict, satisfying the three-stage conflict-finance filter methodology directly.

Alongside the energy-sector transaction bans, the EU shadow-fleet vessel listing architecture continued its expansion this cycle, reaching six hundred forty vessels by June 2026, up from five hundred fifty seven after the nineteenth package, with forty one additional vessels listed via Council Regulation 2025/2618 in December 2025 and forty three more added in the twentieth package. This is an architecture-level enforcement pattern rather than a single incident: successive listing rounds target the physical transport infrastructure that allows sanctioned Russian oil to reach market despite the price-cap and import-ban measures targeting the underlying commodity and its principal corporate sellers. The persistence of this vessel-listing expansion pattern across three successive sanctions instruments, the nineteenth package, the December 2025 regulation, and the twentieth package, indicates sustained EU institutional attention to shadow-fleet logistics specifically, even as broader extractive-industry due-diligence enforcement receives comparatively less sustained institutional attention within the same period.

Notwithstanding this substantial Russia-focused signal, this baseline explicitly identifies EU-bloc conflict-finance and extractive-industry-integrity coverage outside the Russian war economy as comparatively thin. No dedicated EU conflict-minerals due-diligence enforcement outcomes under Regulation 2017/821 were identified within the eighteen-month baseline window. This is a self-identified sourcing gap rather than a finding that no such enforcement activity has occurred, and it should be read as a research-coverage limitation rather than as evidence of an absence of extractive-industry-integrity risk within the EEA supply-chain footprint. Applying the three-pillar balance principle, this gap is itself analytically significant: a financial-integrity assessment of conflict finance that is structurally weighted toward the Russian war economy, simply because that is where enforcement volume and sanctions-list activity concentrate, risks under-representing extractive-industry corruption and conflict-mineral flows that generate less enforcement volume but may carry comparable conflict-finance significance.

The concentration of this cycle signal in the Russian war economy also reflects a broader pattern in how conflict-finance evidence becomes available to a research process of this kind: sanctions designations, transaction bans and vessel listings generate a steady stream of primary-source regulatory documentation, whereas conflict-minerals due-diligence enforcement, where it exists, is less likely to be centrally catalogued in the same regulatory-press-release format. This is a structural feature of the evidence base rather than a substantive judgment about the relative severity of Russian war-economy financing versus extractive-industry corruption, and future research cycles should specifically target primary sources for Regulation 2017/821 enforcement outcomes and Sahel or Democratic Republic of Congo extractive-sector financial flows to correct the current imbalance.

Outlook

The Russian LNG import ban takes effect from 1 January 2027, and its actual implementation, together with any further expansion of the shadow-fleet vessel listing beyond the six hundred forty vessels recorded by June 2026, are the clearest near-term conflict-finance developments to track within the current baseline scope. The more significant outlook item, however, is a coverage gap rather than a forward-looking regulatory event: closing the identified thinness in EU conflict-minerals and extractive-industry-integrity sourcing under Regulation 2017/821, and in Sahel and Democratic Republic of Congo-linked extractive flows, is a research priority for subsequent cycles rather than a described regulatory milestone. This is offered as an honest account of current coverage limits rather than as a prediction of enforcement outcomes.

Cumulative analysis

Conflict Finance and Extractive-Industry Integrity — Cumulative Analysis

Across this baseline, the conflict-finance and extractive-industry-integrity picture for the EEA integrates two very different threads: a well-evidenced, rapidly hardening Russian war-economy enforcement track, and a self-identified thin evidence base for conflict-minerals and extractive-industry corruption more broadly. On the first thread, the EU nineteenth sanctions package, adopted 23 October 2025, imposed a full transaction ban on Rosneft and Gazprom Neft and a Russian LNG import ban effective from 1 January 2027, directly constraining core revenue streams funding the Russian war economy rather than designating discrete entities in isolation. Read cumulatively through the conflict-finance filter methodology, this action traces a source, Russian state-linked energy revenue, through a channel, EU import and transaction relationships, toward deployment in a continuing armed conflict, and it sits alongside the parallel, sustained expansion of the EU shadow-fleet vessel listing architecture, which reached six hundred forty vessels by June 2026, up from five hundred fifty seven after the nineteenth package, with forty one additional vessels listed in December 2025 and forty three more in the twentieth package.

Integrated across three successive sanctions instruments, the nineteenth package, the December 2025 vessel regulation, and the twentieth package, this vessel-listing expansion demonstrates sustained EU institutional attention to shadow-fleet logistics specifically, a genuinely architecture-level enforcement pattern rather than a single incident, targeting the physical transport infrastructure that allows sanctioned Russian oil to reach market despite price-cap and import-ban measures aimed at the underlying commodity and its principal corporate sellers.

The second, and analytically distinct, thread in this cumulative record is a self-identified evidence gap. This baseline has not identified dedicated EU conflict-minerals due-diligence enforcement outcomes under Regulation 2017/821 within the eighteen-month baseline window, and this absence is best read as a research-coverage limitation rather than as evidence that extractive-industry-integrity risk within the EEA supply-chain footprint does not exist. Applying the three-pillar balance principle across this cumulative record, the concentration of available signal in the Russian war economy, driven by the fact that sanctions designations, transaction bans and vessel listings generate a steady stream of primary-source regulatory documentation while conflict-minerals due-diligence enforcement is less likely to be centrally catalogued in the same format, risks under-representing extractive-industry corruption and conflict-mineral flows of comparable conflict-finance significance but lower enforcement visibility.

Held together, the cumulative D4 record through this baseline documents a genuinely deteriorating and architecturally significant Russian war-economy financing constraint, alongside an honestly flagged and as-yet unaddressed gap in EU conflict-minerals and extractive-industry-corruption sourcing, specifically for Sahel and Democratic Republic of Congo-linked extractive flows, that future research cycles are directed to close.

Outlook

The Russian LNG import ban takes effect from 1 January 2027, and its implementation, together with any further expansion of the shadow-fleet vessel listing beyond the six hundred forty vessels recorded by June 2026, remain the clearest near-term conflict-finance developments this cumulative record will track. The more consequential outlook item, however, continues to be a coverage gap rather than a forward regulatory event: closing the identified thinness in EU conflict-minerals and extractive-industry-integrity sourcing under Regulation 2017/821, and in Sahel and Democratic Republic of Congo-linked extractive flows, remains a standing research priority rather than a described regulatory milestone. This is offered as an honest account of current coverage limits, integrated across this baseline, rather than as a prediction of enforcement outcomes.

domain_sub_briefs · D4 · Cumulative analysis

D5 Crypto, Digital Assets, and Financial Innovation

Crypto, Digital Assets, and Financial Innovation

Continue reading

The central digital-asset finding this cycle is a structural mismatch between the pace of crypto-asset service provider sector growth and the maturity of the AML and CFT controls applied to that sector. The European Banking Authority fifth biennial ML/TF risk assessment documents a two and a half times increase in authorised CASPs across the EU between 2022 and 2024, a period spanning the phased entry into force of the Markets in Crypto-Assets Regulation, alongside persistent AML and CFT control weaknesses that have not kept pace with that growth. Read through a digital-asset lens rather than a sanctions-architecture lens, this is the same underlying MiCA passporting dynamic that produces the jurisdiction-shopping vulnerability described elsewhere this cycle: the AMF, FMA and CONSOB have called publicly for stronger EU-level oversight specifically because divergent national AML and CFT scrutiny at CASP authorisation persists until the Anti-Money Laundering Authority assumes direct supervision of cross-border obliged entities no earlier than 2028, leaving rapid sector expansion to outpace its supervisory architecture for a multi-year window.

The ruble-backed A7A5 stablecoin ecosystem is, from a digital-asset-integrity perspective, a case study in how quickly illicit-finance infrastructure can be rebuilt on-chain following a prior enforcement action. Following the March 2025 seizure of the Garantex exchange, a successor ecosystem launched a stablecoin through a Kyrgyz issuer and routed settlement through the exchange Grinex, reaching one hundred billion dollars in cumulative on-chain transaction volume by January 2026, a scale that rivals many licensed CASP operations, before layered sanctions compressed daily volumes from approximately one point five billion dollars to roughly five hundred million dollars. The EU response, a sector-wide transaction ban on Russian and Belarusian CASPs activated via the twentieth sanctions package with crypto provisions effective 24 May 2026, represents the first EU attempt to address this kind of on-chain reconstitution problem at the level of jurisdiction and sector rather than individual platform, a structurally significant innovation for digital-asset sanctions enforcement specifically, though it remains untested against the next successor platform that this evasion architecture may produce.

Digital-asset exposure to Democratic Peoples Republic of Korea proliferation financing also persists this cycle through the same on-chain and multi-chain layering techniques that have characterised DPRK crypto activity for several years. OFAC March 2026 designations identified a facilitator converting approximately two point five million dollars into cryptocurrency for an IT-worker network linked to Amnokgang Technology Development Company, operating across Vietnam, Laos and Spain between mid-2023 and mid-2025. From a digital-asset-architecture perspective, this scheme depends on the same underlying vulnerability as the A7A5 case, namely the capacity of crypto-conversion facilitators and virtual-asset-service-provider counterparties to move value across jurisdictions faster than compliance and law-enforcement responses can track it, even where, as here, the exposed European jurisdiction was an unwitting transit node rather than a designated target.

The red-flag indicators associated with the A7A5 and Grinex pattern are directly applicable to digital-asset compliance programmes: rapid migration of user volume to a successor exchange or stablecoin issuer following designation of a predecessor platform is observable on-chain, while ruble-pegged stablecoin settlement routed through a single domestic bank acting as a fiat gateway is observable in payment data, and both indicators are specifically relevant to virtual-asset-service-provider counterparty due diligence programmes operating correspondent relationships with EEA-domiciled crypto platforms.

Taken as a whole, the digital-asset picture this cycle is one of structural tension between rapid, MiCA-enabled sector growth, a persistent capacity of sanctioned or proliferation-financing networks to reconstitute infrastructure on-chain, and a supervisory architecture, AMLA direct CASP supervision, that will not be operative before 2028. Each of these three elements independently would warrant close monitoring; together, they describe a digital-asset compliance environment in which growth, evasion architecture, and supervisory capacity are moving on materially different timelines.

Outlook

The AMLR becomes directly applicable EU-wide from 10 July 2027, bringing crypto-asset service providers into the same obliged-entity framework as banks for customer due diligence, beneficial-ownership and cash-payment purposes, a harmonisation event that will apply uniformly regardless of the authorising Member State. The Anti-Money Laundering Authority is expected to complete its first harmonised selection of up to forty high-risk cross-border obliged entities, plausibly including significant CASPs, in 2027, with direct supervision commencing in 2028. Until that date, whether the sector-wide crypto sanctions activated this cycle measurably reduce successor-platform reconstitution of the kind observed with A7A5 and Grinex, or whether a further successor emerges, remains the key open digital-asset-integrity question. This is offered as orientation on a documented trajectory, not as a prediction of platform-level outcomes.

Cumulative analysis

Crypto, Digital Assets, and Financial Innovation — Cumulative Analysis

Across this baseline, the digital-asset picture for the EEA integrates into a single, structurally significant tension: rapid MiCA-enabled sector growth, a persistent capacity of sanctioned and proliferation-financing networks to reconstitute infrastructure on-chain, and a supervisory architecture that will not be operative until at least 2028. The European Banking Authority fifth biennial ML/TF risk assessment documents a two and a half times increase in authorised CASPs across the EU between 2022 and 2024, a period spanning the phased entry into force of the Markets in Crypto-Assets Regulation, alongside persistent AML and CFT control weaknesses that have not kept pace with that growth. Integrated with the enabler-jurisdiction record, this same MiCA passporting dynamic underlies the jurisdiction-shopping vulnerability documented by the AMF, FMA and CONSOB, which have called publicly for stronger EU-level oversight because divergent national AML and CFT scrutiny at CASP authorisation persists until the Anti-Money Laundering Authority assumes direct supervision of cross-border obliged entities no earlier than 2028.

The cumulative record of on-chain evasion architecture is anchored by the ruble-backed A7A5 stablecoin ecosystem, a case study, integrated across this baseline, in how quickly illicit-finance infrastructure can be rebuilt following a prior enforcement action. Following the March 2025 seizure of the Garantex exchange, a successor ecosystem launched a stablecoin through a Kyrgyz issuer and routed settlement through the exchange Grinex, reaching one hundred billion dollars in cumulative on-chain transaction volume by January 2026, a scale rivalling many licensed CASP operations, before layered sanctions compressed daily volumes from approximately one point five billion dollars to roughly five hundred million dollars. The EU response, a sector-wide transaction ban on Russian and Belarusian CASPs activated via the twentieth sanctions package with crypto provisions effective 24 May 2026, is the first EU attempt within this cumulative record to address on-chain reconstitution at the level of jurisdiction and sector rather than individual platform, a structurally significant innovation that this record will continue to test against any future successor platform.

Digital-asset exposure to Democratic Peoples Republic of Korea proliferation financing persists across the same on-chain and multi-chain layering techniques documented throughout this baseline. OFAC March 2026 designations identified a facilitator converting approximately two point five million dollars into cryptocurrency for an IT-worker network linked to Amnokgang Technology Development Company, operating across Vietnam, Laos and Spain between mid-2023 and mid-2025, with the exposed European jurisdiction functioning as an unwitting transit node rather than a designated target. Integrated with the A7A5 case, this scheme depends on the same underlying structural vulnerability, the capacity of crypto-conversion facilitators and virtual-asset-service-provider counterparties to move value across jurisdictions faster than compliance and law-enforcement responses can track it.

The red-flag indicators surfaced across this baseline, rapid migration of user volume to a successor exchange or stablecoin issuer following a predecessor designation, and ruble-pegged stablecoin settlement routed through a single domestic bank acting as a fiat gateway, remain directly applicable to virtual-asset-service-provider counterparty due diligence programmes and are the clearest operational takeaway from the cumulative digital-asset record to date.

Outlook

The AMLR becomes directly applicable EU-wide from 10 July 2027, bringing crypto-asset service providers into the same obliged-entity framework as banks, a harmonisation event this cumulative record will track for uniform application regardless of authorising Member State. The Anti-Money Laundering Authority first harmonised selection of up to forty high-risk cross-border obliged entities, plausibly including significant CASPs, is expected in 2027, with direct supervision commencing in 2028. Whether the sector-wide crypto sanctions activated this cycle measurably reduce successor-platform reconstitution of the kind observed with A7A5 and Grinex, or whether the evasion ecosystem again reconstitutes, remains the central open question this cumulative record will continue to test. This is offered as orientation on a documented trajectory, not as a prediction of platform-level outcomes.

domain_sub_briefs · D5 · Cumulative analysis

D6 Compliance Technology and Active Defence

Compliance Technology and Active Defence

Continue reading

The compliance-technology and active-defence picture this cycle is one of steady institutional build-out running alongside a persistent capacity gap in inter-agency intelligence sharing. The Anti-Money Laundering Authority continues to stand up its Frankfurt operations, having commenced activity on 1 July 2025 under Chair Bruna Szego, taken over administration of the EuReCA database by the end of 2025, and finalised three sets of reporting-format technical standards intended to speed cross-border financial-intelligence flow between national financial intelligence units and obliged entities. A public hearing held 2 July 2026 on guidelines for the ongoing monitoring of business relationships signals a supervisory direction of travel toward a perpetual-KYC-adjacent expectation, in which customer due diligence is treated as a continuous rather than point-in-time obligation, a meaningful active-defence and compliance-technology development in its own right regardless of its eventual final form.

A note of caution belongs alongside this build-out narrative. Baseline research initially described the AMLA operational start as occurring in mid-2025 with end-2025 staffing of approximately one hundred twenty, while challenge-stage verification against the AMLA official site produced a more precise 1 July 2025 start date and an alternative staffing estimate of approximately eighty. This active precision discrepancy, on what is fundamentally a RegTech and SupTech capacity-build-out signal, is a reminder that institutional stand-up claims of this kind warrant continued verification rather than being treated as settled once reported, and confidence in the underlying claim has accordingly been assessed rather than treated as high pending resolution of the staffing figure.

The most consequential compliance-technology gap identified this cycle, however, sits not within the AMLA build-out itself but at its institutional boundary. A June 2026 Council document confirms that Europol and AMLA currently lack a reciprocal operational information-exchange interface, meaning AMLA supervisory findings cannot be systematically cross-matched against Europol criminal intelligence. This is a structural fragmentation of the EU financial-intelligence architecture rather than an isolated administrative oversight: it means that a supervisory finding generated by AMLA about, for example, a beneficial-ownership or CASP-authorisation weakness in a given Member State cannot automatically inform a parallel Europol criminal investigation into professional-facilitator networks exploiting that same weakness, and vice versa. Applying an active-defence lens specifically, this gap degrades the practical value of every other compliance-technology investment described this cycle, since intelligence generated on one side of the institutional boundary cannot readily reach the other.

Looking ahead to the supervisory perimeter itself, AMLA is set to select up to forty high-risk cross-border obliged entities for direct EU-level supervision in 2027, with direct supervision commencing in 2028. This marks the durable structural shift of the supervisory perimeter from purely national authorities toward a hybrid EU-level regime, and it is the anchor fact against which all near-term AMLA compliance-technology and active-defence developments, including the reporting-format standards and ongoing-monitoring guidelines described above, should ultimately be read: they are the technical and procedural infrastructure being built in advance of a supervisory transition that itself remains roughly two years away.

Taken together, the EuReCA database transfer, the finalised reporting-format standards, and the ongoing-monitoring guidelines under consultation describe a genuine and improving compliance-technology trajectory at EU level, even as the confirmed absence of a Europol interface and the unresolved AMLA staffing-figure discrepancy indicate that this trajectory remains incomplete both externally, in its connection to criminal-intelligence functions, and internally, in the verifiability of its own operational metrics.

Outlook

AMLA is expected to publish its first work programme and supervisory methodology by December 2026, a milestone that should clarify how the ongoing-monitoring guidelines under public hearing this cycle will be finalised and applied. Full staffing toward a projected cruising capacity of approximately four hundred thirty by the end of 2027, alongside a transition from EU-funded start-up financing to a predominantly fee-funded model from 2028, represents a structural test of institutional independence and capacity that will only become assessable over the next eighteen months. Whether the confirmed Europol-AMLA information-exchange gap is addressed through a legislative proposal, and on what timetable, is not established in this baseline and is a specific item to track in subsequent cycles. This is offered as orientation on a documented institutional-build-out calendar, not as a prediction of the eventual operational capacity or effectiveness of AMLA.

Cumulative analysis

Compliance Technology and Active Defence — Cumulative Analysis

Across this baseline, the compliance-technology and active-defence picture for the EEA integrates into a story of steady, genuine institutional build-out at the Anti-Money Laundering Authority, running against a persistent and unresolved capacity gap at the boundary between that Authority and Europol. The Authority commenced Frankfurt operations on 1 July 2025 under Chair Bruna Szego, has since taken over administration of the EuReCA database, finalised three sets of reporting-format technical standards intended to speed cross-border financial-intelligence flow, and held a 2 July 2026 public hearing on guidelines for the ongoing monitoring of business relationships, signalling a supervisory direction of travel toward a perpetual-KYC-adjacent expectation in which customer due diligence is treated as continuous rather than point-in-time. Integrated across the baseline, this is a genuinely improving trajectory, even though a note of caution belongs alongside it: baseline research initially described the operational start as occurring in mid-2025 with end-2025 staffing of approximately one hundred twenty, while challenge-stage verification against the official site produced a more precise 1 July 2025 start date and an alternative staffing estimate of approximately eighty. This active precision discrepancy, on a fundamentally RegTech and SupTech capacity-build-out signal, has been carried through this record as a reminder that institutional stand-up claims warrant continued verification, and confidence in the underlying claim remains assessed rather than high pending resolution of the staffing figure.

The most consequential compliance-technology finding integrated across this baseline sits not within the build-out itself but at its institutional boundary. A June 2026 Council document confirms that Europol and the Anti-Money Laundering Authority currently lack a reciprocal operational information-exchange interface, meaning supervisory findings generated by the Authority cannot be systematically cross-matched against Europol criminal intelligence, and vice versa. Read cumulatively, this is a structural fragmentation of the EU financial-intelligence architecture, not an isolated administrative oversight, and it degrades the practical value of every other compliance-technology investment documented in this record, since intelligence generated on one side of the institutional boundary cannot readily reach the other. This gap has now persisted across the full baseline window without an identified remediation timeline or legislative proposal.

Looking to the supervisory perimeter itself, the Authority is set to select up to forty high-risk cross-border obliged entities for direct EU-level supervision in 2027, with direct supervision commencing in 2028, a durable structural shift of the supervisory perimeter from purely national authorities toward a hybrid EU-level regime. Integrated across this baseline, this milestone is the anchor fact against which every near-term compliance-technology development, the reporting-format standards, the EuReCA transfer, and the ongoing-monitoring guidelines, should be read: they constitute the technical and procedural infrastructure being built in advance of a supervisory transition that remains roughly two years away at this baseline point.

Taken as a whole, the cumulative record through this baseline documents a compliance-technology trajectory that is genuinely improving at the level of EU institutional capability, while remaining incomplete both externally, in its connection to criminal-intelligence functions via Europol, and internally, in the verifiability of its own operational metrics such as staffing.

Outlook

The Authority is expected to publish its first work programme and supervisory methodology by December 2026, a milestone that should clarify how the ongoing-monitoring guidelines under public hearing this cycle will be finalised. Full staffing toward a projected cruising capacity of approximately four hundred thirty by the end of 2027, alongside a transition from EU-funded start-up financing to a predominantly fee-funded model from 2028, represents a structural test of institutional independence that this cumulative record will continue to assess over subsequent cycles. Whether the confirmed Europol-AMLA information-exchange gap is addressed through a legislative proposal, and on what timetable, remains unestablished and is a specific item this record will track going forward. This is offered as orientation on a documented institutional-build-out calendar, not as a prediction of the eventual operational capacity or effectiveness of the Authority.

domain_sub_briefs · D6 · Cumulative analysis
Regulatory horizon
In Force Pending2026-12 · ±half_year

AMLA Work Programme and Supervisory Methodology Build-Out

AMLA consolidates its Frankfurt headquarters operations, publishes its first work programme and supervisory methodology, and finalises reporting-format technical standards and guidelines intended to harmonise EU-level AML supervisory practice ahead of direct supervision.
In Force Pending2027 · ±year

AMLA First Harmonised Selection of Directly-Supervised High-Risk Obliged Entities

AMLA selects up to forty high-risk cross-border obliged entities for future direct EU-level supervision, using its harmonised risk-categorisation methodology, as a precursor step to full direct supervision beginning 2028.
Adopted10 Jul 2027 · ±year

AMLR Direct Applicability and 6AMLD Member State Transposition Deadlines

The single AML rulebook, AMLR Regulation 2024/1624, becomes directly applicable EU-wide, bringing CASPs into the same obliged-entity framework as banks; 6AMLD, Directive 2024/1640, transposition deadlines complete across Member States on a divergent two to three year timetable from the June 2024 Official Journal publication.
In Force Pending2027-12 · ±half_year

AMLA Full Staffing and Transition to Fee-Based Funding Model

AMLA is projected to reach cruising-capacity staffing of approximately four hundred thirty by end-2027 and to transition from an EU-funded startup model, approximately one hundred nineteen million euro through 2027, to a predominantly fee-funded model from 2028, a structural test of institutional independence and capacity.
Adopted2028 · ±multi_year

AMLA Direct Supervision of Selected High-Risk Cross-Border Obliged Entities

AMLA begins direct supervision of a first cohort of high-risk cross-border obliged entities, shifting supervisory perimeter from purely national authorities to a hybrid EU-level regime.
5 dated · 5 pending date · baseline fim-2026-07-05
Role action cards
MLROHigh

Russia AML high-risk listing, DPRK crypto transit exposure via Spain, and a Bank of Scotland Russia sanctions penalty together raise SAR-relevant enhanced due diligence and screening exposure this cycle.

The addition of Russia to the EU AML high-risk third country list obliges enhanced due diligence across the EU obliged-entity population independent of any separate CFSP sanctions trigger. Combined with the confirmed use of Spain as a transit node for DPRK crypto-converted proliferation-financing proceeds and the OFSI penalty against Bank of Scotland for Russia sanctions breaches, MLRO functions face an expanded set of reportable-activity risk factors spanning jurisdiction-based AML risk, proliferation financing, and sanctions-screening adequacy.

4 evidence refs
ComplianceHigh

CASP jurisdiction shopping under MiCA passporting, EBA-documented sector growth outpacing controls, and the EU AMLR and 6AMLD legislative tracks define this cycle policy-gap landscape.

Three national regulators have publicly flagged that divergent AML and CFT scrutiny at CASP authorisation, combined with MiCA passporting, allows the weakest national licensing regime to set a bloc-wide floor, a control-framework adequacy issue that persists until AMLA direct supervision from 2028. This sits alongside a two and a half times increase in authorised CASPs documented by the EBA and the ongoing, separately-tracked AMLR and 6AMLD legislative timelines that will eventually harmonise obligations.

5 evidence refs
LegalHigh

The EU twentieth sanctions package sector-wide CASP ban, the unanimity-renewal exposure in the core Russia sanctions regime, and the Bank of Scotland penalty define this cycle liability landscape.

The activation of a jurisdiction-wide anti-circumvention tool against Russian and Belarusian CASPs raises client-instruction and transaction-structuring liability questions distinct from prior entity-level designation regimes. The EU core Russia sanctions regime requirement of unanimous six-monthly renewal introduces a standing legal-continuity risk absent from the US and UK designation models, while the OFSI penalty against Bank of Scotland and the OFAC-OFSI Enhanced Partnership Exchange together illustrate the current enforcement-trajectory divergence across the three regimes.

4 evidence refs
BoardHigh

AMLA institutional build-out, the future direct-supervision perimeter, the Russia AML high-risk listing, and Bulgaria pending FATF delisting are the strategic-level regulatory developments this cycle.

AMLA continued Frankfurt build-out and its planned selection of up to forty high-risk cross-border obliged entities for direct supervision from 2028 represent a durable shift of supervisory perimeter from national to EU level, a material strategic development for any institution operating cross-border in the EEA. The Russia AML high-risk listing and Bulgaria pending FATF delisting are both bloc-level reputational and regulatory-posture signals relevant to board-level risk oversight.

4 evidence refs
CTOHigh

The A7A5 stablecoin evasion architecture, the EU sector-wide CASP sanctions ban, EBA-documented CASP growth, and CASP jurisdiction shopping define this cycle digital-asset architecture risk.

The persistence of the A7A5 and Grinex on-chain evasion architecture at one hundred billion dollars cumulative volume, set against the EU first-ever sector-wide crypto sanctions and a two and a half times rise in authorised CASPs alongside persistent control weaknesses, together describe a digital-asset infrastructure and platform-risk environment moving faster than current AML supervisory capacity. DPRK IT-worker crypto conversion via an EEA transit node adds a proliferation-financing dimension to this same technical-architecture risk picture.

5 evidence refs
RiskHigh

Shadow-fleet vessel listing expansion, the Rosneft and Gazprom Neft transaction ban, thin EU conflict-minerals sourcing, and EU sanctions-renewal unanimity risk are this cycle emerging exposure-concentration signals.

The expansion of shadow-fleet vessel listings to six hundred forty by June 2026 and the full transaction ban on Rosneft and Gazprom Neft concentrate conflict-finance and energy-sector exposure in a specific, trackable set of counterparties and routes, while the self-identified thinness of EU conflict-minerals enforcement sourcing is a model and coverage-risk signal in its own right. The EU unanimity-renewal requirement for core Russia sanctions introduces a distinct regime-continuity risk not present in the US or UK models.

4 evidence refs
OperationsHigh

Russia AML high-risk listing, EU high-risk list update adding Bolivia and the British Virgin Islands, and the Bank of Scotland penalty require operational screening and threshold updates this cycle.

Enhanced due diligence obligations triggered by the Russia AML high-risk listing and the addition of Bolivia and the British Virgin Islands to the EU high-risk third country list require transaction-monitoring rule and customer-risk-scoring updates across affected obliged entities. The Bank of Scotland penalty for Russia sanctions breaches is an operational screening-adequacy data point relevant to correspondent-banking workflow review.

3 evidence refs
AuditHigh

The confirmed Europol-AMLA information-exchange gap, unestablished per-Member-State 6AMLD transposition status, and the BORIS beneficial-ownership access restriction are this cycle control-testing and evidence-gap signals.

The confirmed absence of a reciprocal operational information-exchange interface between Europol and AMLA is a documented control gap in the EU financial-intelligence architecture with no established remediation timeline. Per-Member-State 6AMLD transposition status remains unestablished at this baseline, and the continued restriction of BORIS to legitimate-interest access more than three years after the Sovim and WM ruling represents an unresolved audit-trail and evidentiary-access limitation for beneficial-ownership verification work.

3 evidence refs
Decision lens
MLRO

Russia AML high-risk listing, DPRK crypto transit exposure via Spain, and a Bank of Scotland Russia sanctions penalty together raise SAR-relevant enhanced due diligence and screening exposure this cycle.

Compliance

CASP jurisdiction shopping under MiCA passporting, EBA-documented sector growth outpacing controls, and the EU AMLR and 6AMLD legislative tracks define this cycle policy-gap landscape.

Legal

The EU twentieth sanctions package sector-wide CASP ban, the unanimity-renewal exposure in the core Russia sanctions regime, and the Bank of Scotland penalty define this cycle liability landscape.

Board

AMLA institutional build-out, the future direct-supervision perimeter, the Russia AML high-risk listing, and Bulgaria pending FATF delisting are the strategic-level regulatory developments this cycle.

CTO

The A7A5 stablecoin evasion architecture, the EU sector-wide CASP sanctions ban, EBA-documented CASP growth, and CASP jurisdiction shopping define this cycle digital-asset architecture risk.

Risk

Shadow-fleet vessel listing expansion, the Rosneft and Gazprom Neft transaction ban, thin EU conflict-minerals sourcing, and EU sanctions-renewal unanimity risk are this cycle emerging exposure-concentration signals.

Operations

Russia AML high-risk listing, EU high-risk list update adding Bolivia and the British Virgin Islands, and the Bank of Scotland penalty require operational screening and threshold updates this cycle.

Audit

The confirmed Europol-AMLA information-exchange gap, unestablished per-Member-State 6AMLD transposition status, and the BORIS beneficial-ownership access restriction are this cycle control-testing and evidence-gap signals.

Shared evidence: 10 refs
Typology observations
Exposure: {'total_matched_typologies': 0, 'by_typology': {}, 'top_indicators': [], 'exposure_note': None}
Scenario sketches

AMLA Direct-Supervision Transition and the Evasion Landscape

As the EU AML architecture moves from a purely national supervisory model toward AMLA direct and indirect supervision of cross-border obliged entities under the AMLA Regulation, alongside the directly-applicable AMLR and per-state 6AMLD transposition, the supervisory perimeter facing cross-border groups could shift materially. One illustrative structural possibility is that entities currently able to select the most permissive national CASP or bank supervisor under passporting rules face a narrowing of that option as AMLA harmonised risk-categorisation methodology selects a first cohort for direct supervision from 2028 onward, potentially compressing the jurisdiction-shopping window described this cycle. An alternative illustrative possibility is that evasion architecture adapts by concentrating activity among obliged entities just below the direct-supervision threshold, preserving a residual national-supervision arbitrage space beneath the AMLA perimeter. Neither possibility is observed fact; both are offered purely as orientation on how a supervisory-architecture transition of this kind could plausibly interact with existing evasion incentives.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Sector-Wide Crypto Sanctions and Successor-Platform Reconstitution

The EU twentieth sanctions package activation of a jurisdiction-wide anti-circumvention tool against Russian and Belarusian crypto-asset service providers illustrates a structural enforcement approach distinct from prior entity-level designation. One illustrative forward scenario is that this sector-wide approach meaningfully raises the cost of reconstituting a successor platform inside the targeted jurisdictions, given the additional friction of a blanket transaction ban rather than a single designation to route around. An alternative illustrative scenario is that evasion architecture of the kind observed with A7A5 and Grinex relocates settlement and issuance functions to a third jurisdiction outside the sanctioned sector entirely, preserving on-chain volume while formally exiting the newly restricted perimeter. Neither scenario reflects an observed outcome at this stage; both are offered solely as architecture-over-incident orientation for how jurisdiction-wide crypto sanctions tools might interact with a historically adaptive evasion ecosystem.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Registers

Enforcement actions

  • The Commission adopted Delegated Regulation (EU) 2026/46, formally listing Russia as a high-risk third country with strategic AML/CFT deficiencies, following a technical assessment triggered by Russia's suspended FATF membership. 3 Dec 2025
  • The 19th sanctions package designated the developer and Kyrgyz issuer of the ruble-backed stablecoin A7A5, the operator of a platform trading it, five additional Russian banks (Istina, Zemsky Bank, Absolut Bank, MTS Bank, Alfa-Bank), and eight banks/oil traders in Tajikistan, Kyrgyzstan, UAE and Hong Kong, alongside a full transaction ban on Rosneft and Gazprom Neft. 23 Oct 2025
  • The 20th sanctions package, adopted 23 April 2026 with crypto measures effective 24 May 2026, imposed a complete ban on transactions between EU persons and any CASP or platform established in Russia, and an equivalent sectoral ban for Belarus, activating the EU's anti-circumvention tool against an entire jurisdiction for the first time. 23 Apr 2026
  • At its June 2026 Plenary, FATF made an initial determination that Bulgaria has substantially completed its AML/CFT action plan, including securing BO register accuracy and VASP/postal money operator market-entry controls, and now warrants an on-site assessment before removal from the increased monitoring list. 19 Jun 2026
  • Commission Delegated Regulation (EU) 2026/83 added Bolivia and the British Virgin Islands to the EU high-risk third country AML/CFT list while delisting six African jurisdictions following FATF's June/October 2025 Plenary decisions. 4 Dec 2025

Sanctions changes

  • Russia added to the EU list of high-risk third countries for AML/CFT via Commission Delegated Regulation (EU) 2026/46, following a technical assessment of countries with suspended FATF membership. 3 Dec 2025
  • The EU's 19th Russia sanctions package (23 Oct 2025) imposed a full transaction ban on Rosneft and Gazprom Neft, a Russian LNG import ban from 1 Jan 2027, transaction bans on 5 additional Russian banks and 8 third-country financial operators, and first-ever crypto-sector sanctions (A7A5 stablecoin ecosystem). 23 Oct 2025
  • The EU's 20th sanctions package (23 Apr 2026) introduced a full maritime services ban for Russian crude oil, listed 43 additional shadow-fleet vessels (reaching 640 total), and imposed a sector-wide transaction ban on Russian/Belarusian CASPs, effective 24 May 2026. 23 Apr 2026
  • Council Regulation (EU) 2025/2618 (18 Dec 2025) sanctioned 41 further shadow-fleet vessels; the Council separately renewed the core territorial-integrity sanctions regime for six months to 31 July 2026 and the Crimea/Sevastopol regime to 23 June 2026, requiring periodic re-authorisation votes that create renewal-cliff risk. 18 Dec 2025

Regulatory horizon (register)

  • AMLR (Reg 2024/1624) becomes directly applicable EU-wide
  • AMLA's first harmonised selection of 40 directly-supervised entities
  • 6AMLD Member State transposition deadlines complete
  • FATF October 2026 Plenary: Bulgaria on-site verification outcome
  • AMLA full staffing and fee-based funding model matures

Active schemes

  • [CRITICAL] Ruble-backed stablecoin (A7A5/Grinex) sanctions-evasion architecture
  • [HIGH] EU beneficial-ownership register opacity post-Sovim rollback
  • [CRITICAL] DPRK IT-worker crypto proliferation-financing network (EU node)
  • Divergent CASP/MiCA supervision enabling jurisdiction shopping
Sources
  1. European Commission / AMLA
  2. Council of the European Union
  3. European Commission
  4. Council of the European Union
  5. FATF
  6. European e-Justice Portal (European Commission)
  7. OCCRP
  8. Chainalysis
  9. Council of the European Union
  10. TRM Labs
  11. HM Treasury (UK)
Coverage gaps
Since the November 2022 CJEU Sovim/WM ruling, the EU's BORIS…
Since the November 2022 CJEU Sovim/WM ruling, the EU's BORIS beneficial-ownership interconnection system cannot provide public access to national BO registers, reversing a core 5AMLD transparency tool relied on by investigators and civil society across the bloc.
A June 2026 Council document confirms that reciprocal exchan…
A June 2026 Council document confirms that reciprocal exchange of operational information between Europol and AMLA is currently not foreseen, despite both bodies sitting at the centre of the EU's financial-crime and money-laundering response architecture.
MiCA's single-passport model combined with divergent nationa…
MiCA's single-passport model combined with divergent national AML/CFT scrutiny at CASP authorisation has produced 'jurisdiction shopping' concerns publicly raised by France's AMF, Austria's FMA and Italy's CONSOB, while the EBA documented a 2.5-fold rise in authorised CASPs (2022-2024) alongside persistent AML control weaknesses.
Conflict-finance/extractive-industry integrity (D4) coverage…
Conflict-finance/extractive-industry integrity (D4) coverage specific to EEA/EU-bloc architecture is comparatively thin in this baseline relative to sanctions (D1) and crypto (D5) coverage; available sourcing centred on Russia-energy sanctions (oil price cap, LNG ban) rather than dedicated EU conflict-minerals or extractive-corruption enforcement actions within the 18-month window.

Evidence

Confidence-tiered claims

No structured claims published for this jurisdiction yet.