Latest news
Cayman Islands CRS update: Participating and Reportable Jurisdictions lists, reporting timelines and the PPoC deadline extension
on 30 march 2026, the cayman islands department for international tax cooperation (ditc) gazetted updated common reporting standard (crs) participating jurisdictions and crs reportable jurisdictions lists. the updates are issued pursuant to the crs regulations (2021 revision), as amended by the crs (amendment) regulations, 2025.
this post summarises the key developments arising from the ditc's industry advisories of 31 march 2026 and 21 january 2026.
additions to the crs jurisdictions lists
participating jurisdictions: rwanda and uganda added.
reportable jurisdictions (2026 onwards):
reportable jurisdictions (2027 onwards): mongolia, papua new guinea, paraguay.
reportable jurisdictions (2028 onwards): fiji, tunisia, zambia.
cayman financial institutions (fis) should update due diligence and self-certification procedures to capture account holders tax-resident in these newly reportable jurisdictions.
2026 reporting deadlines (2025 calendar year)
crs/fatca reporting: 31 july 2026
crs compliance form: 15 september 2026
ppoc deadline extension under the amended crs
the tax information authority has extended the deadline for submission of (i) the appointment of a ppoc and (ii) the date on which the fi became an fi, to 31 january 2027.
this extension applies to all cayman fis, not solely newly registered entities. all other registration obligations for fis that became an fi in 2025 were due by 30 april 2026.
ppoc: key eligibility criteria
the ppoc must be located in the cayman islands, meaning a natural person with a physical address in the cayman islands, or a legal person incorporated/registered/established in the cayman islands maintaining a physical (not merely mailing) address.
practical takeaways
the ppoc local-nexus obligation represents a new substantive compliance requirement under the amended crs; fis should ensure operational readiness well ahead of the 31 january 2027 deadline.
updated self-certification forms (effective 1 january 2026) and the crs guidelines (2026 amendment edition) remain forthcoming and fis should monitor the ditc portal.
ditc’s press release can be found here. the crs participating jurisdictions and crs reportable jurisdictions can be accessed here (pages 71 – 74).
our blog post on the deadline extension for ppoc can be found here.
EU Court partially annuls Meta's “gatekeeper” designations under the Digital Markets Act
on 3 june 2026, the general court of the european union delivered its judgment in case t-1078/23 (meta platforms v commission), partially annulling the european commission's decision of 5 september 2023, which designated meta as a gatekeeper under the digital markets act (dma). background messenger: designation upheld key takeaways on 3 june 2026, the general court of the european union delivered its judgment in case t-1078/23, partially annulling the european commission's decision of 5 september 2023, which designated meta as a gatekeeper under the digital markets act. eu court partially annuls meta's “gatekeeper” designations under the digital markets act on 3 june 2026, the general court of the european union delivered its judgment in case t-1078/23 (meta platforms v commission), partially annulling the european commission's decision of 5 september 2023, which designated meta as a gatekeeper under the digital markets act (dma). background messenger: designation upheld key takeaways
EU Court partially annuls Meta's “gatekeeper” designations under the Digital Markets Act
on 3 june 2026, the general court of the european union delivered its judgment in case t-1078/23 (meta platforms v commission), partially annulling the european commission's decision of 5 september 2023, which designated meta as a gatekeeper under the digital markets act (dma).
the ruling is notable as the first successful challenge to a dma gatekeeper designation and carries significant implications on how the european commission should apply the dma's quantitative thresholds and classification criteria going forward.
background
the european commission's designation decision found that several of meta's services constituted distinct core platform services (cps) within the meaning of the dma, including:
facebook as an online social network,
messenger as a number-independent interpersonal communications service (ni-ics), and
marketplace as an online intermediation service.
meta was deemed to meet the quantitative thresholds set out in article 3(2) dma, giving rise to a presumption that the relevant services qualified as important gateways for business users to reach end users. subsequently, meta brought an action for annulment in part, targeting the classification of messenger and marketplace as important gateways.
messenger: designation upheld
in contrast, the court dismissed meta's challenge to messenger's designation:
standalone cps classification confirmed. the court held that messenger constitutes a standalone ni-ics distinct from the facebook social network, given its standalone applications, independent usability, and business-specific tools. integration arguments did not displace this finding.
no de-duplication of user bases required. the dma does not require the commission to exclude overlapping facebook users when calculating whether messenger meets the quantitative thresholds for a given cps.
no market investigation obligation and no infringement of the rights of defence. absent sufficiently substantiated arguments manifestly calling into question the dma presumptions, the commission was not required to open a market investigation under article 17 dma. no infringement of meta's procedural rights was found.
key takeaways
the ruling sets a precedent for designated undertakings seeking to rebut gatekeeper presumptions by demonstrating substantive changes to product functionality that affect the applicable cps category definition.
an appeal limited exclusively to points of law against a decision of the general court before the court of justice remains available within two months and ten days of notification.
the press release can be accessed here, and the full text of the opinion is published on the curia website here.
CIMA enforces the removal of struck and dissolved entities
the cayman islands monetary authority (cima) announced the removal of several entities from its register as of 17 april 2026. these entities failed to meet the termination requirements set by cima and have either been struck from the general registry or hold a dissolved status. the list includes various mutual funds and private funds across different registration types.
this measure highlights the critical need for adherence to regulatory standards to sustain active registration.
for more information, the general notice can be found here.
Streamlining corporate sustainability: Key updates from EU Directive 2026/470
the directive (eu) 2026/470, adopted on 24 february 2026, introduces amendments to existing eu laws to enhance corporate sustainability reporting and due diligence requirements. the directive (eu) 2026/470, adopted on 24 february 2026, introduces amendments to existing eu laws to enhance corporate sustainability reporting and due diligence requirements. as organisations prepare for the new framework, we revisit the key highlights below: streamlining corporate sustainability: key updates from eu directive 2026/470 the directive (eu) 2026/470, adopted on 24 february 2026, introduces amendments to existing eu laws to enhance corporate sustainability reporting and due diligence requirements.
Streamlining corporate sustainability: Key updates from EU Directive 2026/470
the directive (eu) 2026/470, adopted on 24 february 2026, introduces amendments to existing eu laws to enhance corporate sustainability reporting and due diligence requirements. as organisations prepare for the new framework, we revisit the key highlights below:
streamlined reporting: the directive reduces the scope of mandatory sustainability reporting to large companies with over €450 million in turnover and 1,000 employees, ensuring smaller businesses are not overburdened.
simplified assurance standards: new standards for sustainability reporting assurance will be developed by july 2027, with a focus on flexibility and proportionality.
voluntary reporting standards: small and medium-sized enterprises (smes) can adopt voluntary sustainability reporting standards, promoting inclusivity without mandatory obligations.
value chain protections: protected undertakings which are companies in the value chain with fewer than 1,000 employees are protected from excessive data requests and have the right to decline to provide information exceeding the information specified in the voluntary standards, ensuring proportionality in reporting requirements.
due diligence obligations: apply to companies with more than 5,000 employees and over 1.5 billion in turnover.
digitalisation and support: a dedicated eu portal will provide guidance, templates, information and support for sustainability reporting standards.
extended deadlines: companies are granted additional time to comply, with the application of new rules postponed to 2029 for due diligence.
the directive (eu) 2026/470 can be found here.
JFSC updates AML/CFT/CPF handbook appendices following June 2026 FATF plenary
on 23 june 2026, the jersey financial services commission (jfsc) announced updates to appendix d1 and appendix d2 of the aml/cft/cpf handbook, reflecting the latest financial action task force (fatf) statements issued on 19 june 2026. what has changed? appendix d1 - fatf call for action (blacklist) appendix d2 - countries and territories presenting higher risks why does this matter? what should supervised persons do? on 23 june 2026, the jersey financial services commission announced updates to appendix d1 and appendix d2 of the aml/cft/cpf handbook, reflecting the latest financial action task force statements issued on 19 june 2026. these changes take effect immediately and carry practical implications for all supervised persons in jersey. jfsc updates aml/cft/cpf handbook appendices following june 2026 fatf plenary on 23 june 2026, the jersey financial services commission (jfsc) announced updates to appendix d1 and appendix d2 of the aml/cft/cpf handbook, reflecting the latest financial action task force (fatf) statements issued on 19 june 2026. what has changed? appendix d1 - fatf call for action (blacklist) appendix d2 - countries and territories presenting higher risks why does this matter? what should supervised persons do?
JFSC updates AML/CFT/CPF handbook appendices following June 2026 FATF plenary
on 23 june 2026, the jersey financial services commission (jfsc) announced updates to appendix d1 and appendix d2 of the aml/cft/cpf handbook, reflecting the latest financial action task force (fatf) statements issued on 19 june 2026. these changes take effect immediately and carry practical implications for all supervised persons in jersey.
what has changed?
the updates follow the outcomes of the fatf plenary held in paris from 17–19 june 2026. the key developments are as follows.
appendix d1 - fatf call for action (blacklist)
appendix d1 lists countries and territories for which the fatf has issued a call for action. the following jurisdictions remain on this list:
iran and the democratic people's republic of korea (dprk) - both continue to be subject to a call to apply countermeasures, owing to ongoing and substantial money laundering, terrorist financing, and proliferation financing (ml/tf/pf) risks.
myanmar - remains subject to a call to apply enhanced due diligence measures proportionate to the risks arising from the jurisdiction. the fatf noted that myanmar has taken some steps to improve its regime but warned that if no further progress is made by october 2026, countermeasures may be considered.
appendix d2 - countries and territories presenting higher risks
appendix d2 draws on multiple independent sources to identify countries and territories presenting ml/tf/pf risks. the fatf "grey list", known as "jurisdictions under increased monitoring", is one of the principal inputs to this appendix.
at the june 2026 plenary, two notable changes were made to the grey list:
added: bosnia and herzegovina and iraq have been newly identified as jurisdictions under increased monitoring.
removed: algeria and namibia were removed following successful on-site visits confirming that both had completed their action plans and made positive progress in addressing strategic aml/cft/cpf deficiencies.
additionally, the fatf made initial determinations that bulgaria, côte d’ivoire, the democratic republic of congo, and monaco have substantially completed their respective action plans and warrant on-site assessments.
why does this matter?
countries and territories listed under sources 1 and 2 of appendix d2 should be treated as not compliant with fatf recommendations for the purposes of article 17a of the money laundering (jersey) order 2008. this means that enhanced customer due diligence must be applied to any relationship with a relevant connection to such jurisdictions.
what should supervised persons do?
the jfsc expects supervised persons to take the following steps:
review policies, procedures, and existing customer relationships to assess the impact of these updates on their business.
take particular care when considering placing reliance on an obliged person based in one of the listed countries or territories.
discuss any concerns with their jfsc supervisor.
supervised persons are also expected to exercise judgement in how they interpret and use the sources listed in appendix d2, and to reach and document their own consideration and conclusions on risk.
jfsc industry update can be found here
appendix d1 can be accessed here and appendix d2 here
Luxembourg Bill 8761: practical refinements to the securitisation regime
luxembourg bill of law no. 8761 proposes targeted amendments to the luxembourg securitisation law.
the bill is focussed on removing practical constraints that have emerged since the 2022 reform, while preserving the existing investor-protection framework. for market participants, the key theme is flexibility: broader funding tools, more usable active management, clearer compartment structuring and targeted clarifications on insolvency segregation, security and ranking.
broader funding tools
the bill would allow securitisation undertakings to finance transactions not only through financial instruments or borrowings, but also through other forms of financing and financial commitments.
this is particularly relevant for structures that do not fit neatly into conventional debt concepts. the explanatory notes expressly link the change to market demand, including islamic finance structures where conventional loans or instruments may be unsuitable.
the flexibility is not unlimited. public offers would remain limited to financing through financial instruments, preserving an important boundary within the securitisation framework.
clearer insolvency segregation for funds
the bill would also clarify the segregation of assets of securitisation funds managed by a management company.
it would confirm that the assets of a securitisation fund do not fall into the insolvency estate of the management company. this is an important clarification for fund structures, reinforcing the separation between the fund’s assets and the position of the entity managing it.
the bill also updates references to collective proceedings to reflect newer luxembourg restructuring and dissolution procedures.
intra-vehicle compartment investment
new article 59-1 would expressly permit a compartment of a securitisation undertaking to invest, directly or indirectly, in another compartment of the same undertaking.
this would be subject to the constitutional documents and the relevant issue documentation. circular investments would be excluded.
where the investment is made through debt-type instruments, the investing compartment would retain creditor rights, including voting rights and rights to financial proceeds. this should give luxembourg securitisation vehicles more structuring flexibility while preserving compartment-level discipline.
active management becomes more usable
the proposed article 61-1 would broaden the existing active-management permission.
under the current framework, active management is focussed on portfolios of debt securities, loans, debt financial instruments or receivables. the bill would remove that limitation and extend the possibility of active management to any basket of securitised risks.
that change could open the door to equity and private equity-style securitisation strategies. however, the public-offer limitation remains central: the instruments financing the actively managed basket must not be offered to the public.
clearer line between active management and portfolio maintenance
the bill would also draw a clearer line between active management and ordinary portfolio maintenance.
the following actions would not, by themselves, constitute active management:
replacing defaulted assets;
replacing assets that fail eligibility criteria;
building the initial portfolio within prescribed limits;
adding assets during continuous issuances;
replacing assets at maturity; and
making marginal allocation adjustments.
this is a useful clarification for transactions where portfolios need to be maintained or adjusted without necessarily moving into an actively managed strategy.
security and ranking clarifications
the bill would also clarify when securitisation undertakings may grant guarantees or security.
securitisation undertakings could grant security for:
their own obligations;
obligations of third parties linked to the securitisation; and
obligations of third parties investing in the transaction.
the ranking rules would also be clarified. instruments referencing a benchmark or reference rate plus margin would rank with fixed-return debt, rather than being treated as non-fixed-return debt. non-fixed-return debt would remain subordinated.
key takeaway
if adopted in its current form, bill 8761 should make luxembourg securitisation vehicles more adaptable for complex private transactions, without turning the 2004 securitisation law into a new regime.
the bill’s direction is one of targeted flexibility: broader financing mechanics, clearer compartment structuring, more practical active-management rules and technical clarifications on insolvency segregation, security and ranking. at the same time, the public-offer limitations remain an important boundary, particularly for actively managed structures.
bill of law no. 8761 can be found here.
Fintech on the Seas 2026: Shaping the future of digital finance in the BVI
the british virgin islands has once again proven itself a natural home for the global fintech conversation. this week, regulators, investors, legal professionals and digital asset pioneers converged on oil nut bay and necker island for fintech on the seas 2026. three days of high-calibre discussion, meaningful connection and forward-looking strategy, set against one of the most extraordinary backdrops in the world.
for harneys, this year's summit holds particular significance. as a proud gold sponsor, we were delighted to have a strong team on the ground throughout the week, including george weston, david mathews, aki corsoni-husain, charlotte allery, ian chambers, la toya james and alexandra holden. their presence across panels, roundtables and informal discussions underscored the depth of harneys' commitment to the digital assets space, and to the bvi as a jurisdiction at the forefront of responsible innovation.
day one: the regulatory and policy summit
the week opened with unmistakable momentum. the regulatory and policy summit at oil nut bay drew a capacity audience and a clear sense of purpose. delegates arrived ready to engage, and the programme did not disappoint.
george weston, in his capacity as bvi finance chairman, delivered the welcome address, setting out a clear vision: the bvi intends not merely to keep pace with the global evolution of digital finance, but to play a leading role in directing it. it was an energising start to a day whose agenda read like a roadmap for the industry's next chapter, spanning supervisory frameworks, compliance architecture, the governance of digital assets, and the practical realities of operating responsibly in a fast-moving market.
much of the day's discussion centred on the relationship between onshore and offshore regulatory approaches, and how those frameworks can evolve in a manner that supports innovation without compromising integrity. speakers and panellists examined the increasingly central role of compliance within digital asset businesses. it is no longer a back-office function, but a strategic discipline woven into risk management at every level. the conversation around stablecoins and tokenised assets was particularly rich, with participants exploring how these instruments are reshaping financial infrastructure, enabling cross-border capital flows and demanding new thinking from both regulators and market participants.
the setting itself deserves mention. oil nut bay, with its sweeping views across the caribbean sea and the kind of effortless elegance that defines the bvi at its best, lent a particular atmosphere to the day's proceedings. there is something about discussing the future of global finance with the trade winds and turquoise waters on the horizon that encourages both clarity of thought and generosity of spirit.
day two: building the new digital finance market
the voyage moved to necker island for day two, and any suggestion that the opening day would be a hard act to follow was swiftly dispelled. sir richard branson welcomed delegates with characteristic warmth, setting a tone of ambition and optimism that carried through the entire day. few settings could be more unexpected: stepping off a boat onto necker and being greeted not only by one of the world's most recognisable entrepreneurs but also by the island's resident kangaroos rolling contentedly in the sand, and the gentle, unhurried progress of giant tortoises across the paths between sessions. it is a setting that encourages a different perspective.
the morning brought two landmark announcements. bvi finance ceo elise donovan launched ‘destination digital: an on-chain future’, a report that makes the case for the bvi's standing in digital assets with hard data. the territory now commands a significant share of the global market for us tokenised treasuries and a substantial volume in stablecoins. those are not aspirational figures. they confirm a jurisdiction whose presence in this space is now firmly established. then came the news that payward, parent company of kraken, has secured vasp registrations from the bvi financial services commission. for one of the world's largest digital asset platforms to choose the bvi as a regulated base is a powerful validation of the jurisdiction's legal infrastructure and the professional ecosystem that supports it.
the day's programme was expansive in scope. keynotes and panels explored tokenisation across an impressively broad canvas, from culture, music and sport to real-world assets, governance and prediction markets. sessions examined how digital asset investment products are maturing, how businesses scale in this space, and the evolving interplay between capital, code and jurisdiction. mark mariampillai's presentation on tokenising culture, music and sport as investable assets was a particular highlight, weaving together the bvi's natural beauty, innovative spirit and economic ambition under the memorable banner of "virgin islands nice."
the political dimension was also well represented. premier dr. the honourable natalio d. wheatley and the honourable lorna smith obe, minister responsible for financial services, both addressed delegates, a clear signal of governmental commitment to the territory's digital finance strategy. an exclusive seaside conversation with jackson hinkle from the street crypto added a media perspective, while ethan wang of ltp, a bvi-licensed virtual asset service provider offered a compelling forward view from 2030: a future in which digital finance simply becomes finance.
for harneys, day two was a proud moment. david mathews featured on a panel, bringing his deep expertise in web3 structuring to discussions that demanded precisely that combination of technical depth and cross-jurisdictional awareness. david, a partner in our digital assets and blockchain practice in the cayman islands, is recognised as one of the leading advisers in the dao and defi space, and his contributions here reinforced why clients turn to harneys when navigating the evolving architecture of decentralised finance.
the day closed with conversations on community engagement, purpose-driven partnerships and the role of educational institutions like h. lavity stoutt community college in building local capacity. for all the global ambition on display, the bvi's fintech story is also, fundamentally, a local one.
day three: the road ahead
the final day brought the conversation full circle, from regulatory foundations on day one, through market-building on day two, to the forces that will shape the next decade of financial services: artificial intelligence, digital trust and the reinvention of payments infrastructure. under brilliant caribbean sunshine, the focus shifted decisively from experimentation to execution. asking not merely what digital finance can do, but what it needs next and how jurisdictions like the bvi can help shape that future.
an opening keynote helped frame the shift from pilots and proof-of-concepts toward trusted infrastructure that institutions, regulators and markets can rely on. panels then wrestled with questions that matter deeply to our clients. how is ai transforming asset management and compliance, and how can decision-making remain responsible as these tools proliferate? how can firms defend against increasingly sophisticated cyber threats and fraud? what does the future of global settlement look like in a world of programmable money, stablecoins and tokenised assets? a seaside discussion unpacked tokenisation in practical terms, separating real-world opportunity from market hype whilst highlighting the risks that must be managed as the sector matures. there were also candid examinations of lessons learned from exchange failures and token disputes, the kind of forensic, experience-driven analysis that elevates an event from thought leadership to genuine practical value.throughout, one message was unmistakable: digital finance is no longer only about possibility. it is about delivery and building systems that can earn trust, withstand scrutiny and create real-world value.
aki corsoni-husain, our global head of regulatory and tax, featured on a panel during the day's programme, offering the measured, cross-jurisdictional perspective on licensing and supervisory frameworks that clients and regulators alike have come to expect from harneys. his contribution brought into sharp focus the practical steps needed to move digital finance forward with confidence, credibility and responsible growth. his presence on the final day's line-up was a fitting reflection of the firm's breadth across both transactional and regulatory dimensions of digital assets, and of the bvi’s important role, as a globally recognised international finance centre, in the continuing evolution of this space.
the final wave: harneys' inaugural recovery breakfast
to close out the week, harneys hosted ‘the final wave’, our inaugural recovery breakfast at our bvi offices, designed to give delegates a chance to decompress and reconnect before heading home. after three days of island-hopping between oil nut bay and necker, a more relaxed gathering felt like the right way to bring things full circle. good coffee, good company and the chance to thank the colleagues, clients and collaborators who made the week so memorable.
trust as currency
beyond the panels and presentations, one theme seemed to emerge in almost every conversation throughout the week: trust. the digital asset industry has matured considerably in recent years. early debates centred on whether blockchain and digital assets would ever achieve meaningful adoption, but that question now feels largely settled. the conversations at fintech on the seas 2026 reflected this evolution, moving beyond foundational scepticism towards more practical and, in many respects, more substantive territory. the focus has shifted decisively towards implementation, infrastructure and execution: responsible approaches to asset tokenisation, the development of investment products that inspire confidence, and the design of regulatory frameworks capable of encouraging innovation while safeguarding market integrity.
in many ways, trust has become the thread connecting each of these practical questions. the digital asset industry has spent the last decade proving what is technologically possible. the next chapter will be about proving what is sustainable. technology alone is not enough. investors need confidence, institutions need legal certainty and regulators need assurance that innovation can develop responsibly.
this is where jurisdictions such as the british virgin islands have a real opportunity. the bvi's success as an international financial centre has always been built on sophisticated legal structures, commercial pragmatism and a commitment to providing certainty in an increasingly complex world. those same attributes are becoming increasingly valuable in digital assets. the recent growth of stablecoins and tokenised treasury products connected to the jurisdiction demonstrates that the bvi is no longer simply participating in the digital asset industry. it is helping shape it.
perhaps the most encouraging aspect of the week was seeing regulators, entrepreneurs, investors and advisers engaging in these conversations together. in an industry that often prides itself on disruption, there was a clear recognition that long-term success will depend not only on innovation, but also on trust, collaboration and robust legal infrastructure.
if fintech on the seas 2026 is any indication, the future of digital finance will be built not by those who move fastest, but by those who build most thoughtfully.
ESMA confirms 1 July 2026 as a firm deadline for unauthorised crypto-asset service providers
on 23 june 2026, esma published a public statement clarifying how unauthorised crypto-asset service providers (casps) must conduct themselves once the transitional period under the markets in crypto-assets regulation (mica) ends on 1 july 2026. the statement builds on esma's earlier 17 april 2026 statement on the end of mica transitional periods.
the practical trigger is significant: while many casps will hold authorisation by 1 july 2026, others, including sizeable providers currently servicing eu clients under national regimes, may not. esma's expectations apply regardless of whether a member state aligned its national law with mica, removing any argument that an unadjusted national regime preserves a basis to continue operating.
what unauthorised casps must do
esma expects immediate, orderly wind-down of eu activities, with client protection and market integrity at the centre. specifically, unauthorised casps must:
stop onboarding new eu clients, decline new client relationships or accounts, and cease all marketing and solicitation.
limit services to those necessary to sell or transfer crypto-assets, reallocate assets, or close positions, with custody continuing only for the period strictly necessary to complete an orderly exit.
communicate clearly and repeatedly with retail and institutional clients about safeguarding measures and wind-down timelines, including a deadline after which residual positions would be closed automatically.
the compliance perimeter does not relax during exit
notably, esma insists that aml/cft obligations continue in full throughout the wind-down. casps must maintain customer due diligence, transaction monitoring, sanctions and restrictive-measures screening, suspicious activity reporting, record-keeping, and travel-rule traceability obligations apply until exit is complete. wind-down must also comply with all relevant eu and national conduct laws.
client-side action and supervisory coordination
esma invites clients to verify their provider's status on the esma register and to act promptly where a provider is unauthorised, including by moving holdings to an authorised casp or to a self-hosted wallet. the express endorsement of self-hosted wallets as an exit route is a noteworthy practical signal.
on enforcement, esma and national competent authorities (ncas) are directly engaged with the entities concerned and will coordinate, alongside the eba and amla, to monitor whether significant cross-border unauthorised casps wind down without delay. ncas may take coordinated action against unauthorised casps after the transitional period.
takeaway
the statement signals that esma views the 1 july 2026 cut-off as a hard perimeter rather than a soft transition, with cross-border providers a particular supervisory focus and full aml/cft compliance expected right up to the point of exit.
esma’s public statement can be found here
our blog post on esma's 17 april 2026 statement can be accessed here.
BMA's framework for responsible AI in financial services
the bermuda monetary authority (bma) has released a summary of stakeholder feedback on its discussion paper regarding the responsible use of artificial intelligence (ai) in bermuda’s financial services sector. key highlights the bermuda monetary authority has released a summary of stakeholder feedback on its discussion paper regarding the responsible use of artificial intelligence in bermuda’s financial services sector. the paper outlines key themes and the bma’s approach to ai governance, emphasising a principles-led, outcomes-focussed framework integrated within existing regulatory structures. bma's framework for responsible ai in financial services the bermuda monetary authority (bma) has released a summary of stakeholder feedback on its discussion paper regarding the responsible use of artificial intelligence (ai) in bermuda’s financial services sector. key highlights
BMA's framework for responsible AI in financial services
the bermuda monetary authority (bma) has released a summary of stakeholder feedback on its discussion paper regarding the responsible use of artificial intelligence (ai) in bermuda’s financial services sector. the paper outlines key themes and the bma’s approach to ai governance, emphasising a principles-led, outcomes-focussed framework integrated within existing regulatory structures.
key highlights:
principles-led approach: stakeholders support a flexible, technology-neutral framework to manage ai risks, avoiding rigid, prescriptive rules.
integration with existing frameworks: ai-related risks should be addressed within current governance, risk management, operational resilience structures and third-party oversight requirements, rather than creating standalone ai-specific regulations.
proportionality: governance measures should align with the risk profile of ai use cases, balancing innovation with risk mitigation.
bermuda’s market context: regulatory approaches will reflect bermuda’s predominantly institutional and cross-border market, avoiding retail-focussed models.
governance and accountability: boards remain accountable for ai outcomes, with an emphasis on proportionate ai literacy and oversight mechanisms.
market integrity: ai’s use in trading and market surveillance raises concerns about systemic risks, requiring potential sector-specific guidance or supervisory clarification for higher-risk use cases.
international alignment: the bma will align with global regulatory standards to support firms operating across jurisdictions.
third-party risks: the authority is considering whether existing third-party risk management frameworks sufficiently address ai-related dependencies on external providers, particularly regarding transparency, auditability, and vendor concentration.
implementation challenges: phased adoption and supervisory engagement will support effective ai governance, particularly for smaller institutions.
the bma will monitor ai adoption within existing frameworks, engage with stakeholders, and assess the need for incremental regulatory enhancements. the goal is to foster responsible innovation while safeguarding financial stability and market integrity.
for further details, refer to the full discussion paper here.
European Commission’s Tax Omnibus Directive
on 24 june 2026, the european commission adopted a tax simplification package comprising two legislative proposals: a direct taxation omnibus directive and a recast of the directive on administrative cooperation (dac). together, these are estimated to reduce compliance costs for businesses by approximately eur 7.9 billion annually. the omnibus directive proposes amendments to six existing eu directives: the interest and royalty directive, the parent-subsidiary directive, the tax merger directive, the anti-tax avoidance directive (atad), the dispute resolution mechanism, and the faster directive. both proposals will now be submitted to the european parliament for consultation and to the eu council for unanimous adoption.
direct taxation omnibus directive
the omnibus introduces several notable measures to modernise the eu's direct tax framework:
removal of minimum holding requirements for cross-border intra-eu payments - the omnibus directive proposes to remove the minimum holding requirement under both the interest and royalty directive (ird) and the parent-subsidiary directive (psd). consequently, withholding taxes on dividends, interest and royalties between eu companies would be removed regardless of the level of participation, extending the exemption beyond group payments to those between unrelated parties. the scope of the psd would also be extended to pension funds. notably, eu member states would no longer be able to require prior authorisation to verify exemption conditions; instead, taxpayers would self-assess their eligibility, subject to ex post controls and anti-abuse rules.
new eu-wide r&d allowance - the omnibus directive proposes the introduction of a new eu-wide r&d allowance as a minimum standard to ensure the deductibility of qualifying r&d expenditure. this allowance would equal the amount of qualifying expenditure and could be deducted from the taxable base.
mandatory cfc model under atad. the omnibus directive would remove the current choice between model a (targeting specific categories of passive income) and model b (based on whether the cfc engages in genuine economic activity). model b would be abolished, making model a the sole mandatory approach across all member states. this eliminates an option rooted in the cjeu’s landmark cadbury schweppes judgment (c-196/04), which held that cfc rules cannot apply to subsidiaries with genuine economic substance.
modernised atad interest limitation rules. the omnibus directive would require eu member states to allow the deduction of exceeding borrowing costs up to 30 per cent of a company’s ebitda, removing the current freedom to set a lower threshold. third-party loans would be excluded from the scope of the interest limitation rule where funds are used to finance the borrower’s own activities. a mandatory safe harbour of eur 3 million would be introduced and automatically indexed for inflation.
elimination of the imported hybrid mismatch rule. the omnibus directive proposes to eliminate the imported hybrid mismatch rule under atad 2. this rule currently applies where a deductible payment in an eu jurisdiction indirectly funds expenses giving rise to a hybrid mismatch outcome between two other jurisdictions, where the mismatch has not been neutralised by local rules. the removal has been broadly welcomed, as this provision has proven particularly challenging for both taxpayers and tax administrations.
strengthened tax dispute resolution. procedural shortcomings that have previously delayed or prevented the settlement of cross-border disputes will be addressed.
expanded tax merger directive. tax neutrality will be extended to new forms of cross-border reorganisation not currently covered, specifically the “simplified merger” and the “division by separation”, aligning the directive’s scope with directive (eu) 2017/1132 (as amended by the mobility directive).
recast of the dac
the dac recast focusses on reducing reporting burdens and improving administrative cooperation:
removal of dac6 reporting for pillar two groups. approximately 3,000 multinational enterprise groups already subject to the 15 per cent global minimum tax will no longer be required to report cross-border tax arrangements, generating estimated annual savings of eur 300 million.
elimination of low-value reporting for all companies. reporting requirements relating to certain cross-border arrangements that have demonstrated limited added value to tax administrations will be removed, reducing overall reporting volumes by 35 per cent and saving eur 40 million annually.
raised threshold for online sales reporting. the reporting threshold for online sales of goods will be increased, removing reporting obligations for over 10 million sellers, predominantly private sellers of second-hand goods, with estimated savings of eur 678 million.
single notification obligation. a consolidated notification will replace separate filings for country-by-country reporting and top-up tax information returns, saving businesses over eur 260 million annually.
new taxpayer identification verification tool. a verification mechanism will be introduced to improve taxpayer identification across member states.
mandatory exchange of all income and capital categories. the recast makes it obligatory to exchange information on all categories of income and capital, extending the framework's coverage.
next steps
the package forms part of the european commission's broader simplification agenda, which targets a reduction in administrative burdens of at least 25 per cent (35 per cent for smes) by 2029. however, since the omnibus directive requires unanimous adoption by all eu member states, its prospects in its current form remain uncertain. the directive restricts flexibility for member states wishing to maintain higher taxation by imposing mandatory rules, while simultaneously eliminating the flexibility that enabled more business-friendly approaches in other member states. given these tensions, significant negotiations or amendments are likely before any consensus can be reached.
european commission’s news article can be found here.
Playing by the rules: How the European Court changed the landscape for cross-border online gambling
on 16 april 2026, the court of justice of the european union (cjeu) delivered a landmark judgment in case c-440/23, clarifying how national gambling prohibitions interact with the freedom to provide services in the eu.
background: the german prohibition
the case originated from a dispute involving two maltese-licensed operators offering online virtual slot machines and lottery betting to a player residing in germany. between june 2019 and july 2021, the player used these services and incurred losses. at that time, german law prohibited online games of chance.
the player sought restitution before a maltese court for the lost stakes, prompting the maltese court to ask the cjeu if germany’s strict national ban was compatible with eu law, especially considering the operators held valid licences in another member state. the court also questioned whether germany's subsequent shift to a licensing regime in july 2021 altered the legal standing of the previous ban.
key findings from the cjeu
the cjeu upheld the rights of individual member states to regulate their own gambling markets. without eu-level harmonisation, countries retain broad discretion to establish consumer protection standards that align with their specific moral, cultural and social values.
the court established several vital precedents:
valid national prohibitions: eu law does not prevent a member state from prohibiting online casino games, slot machines, and certain betting activities to channel gambling into supervised environments and combat parallel markets.
cross-border licences: the fact that an operator holds a valid licence in one member state does not make another member state's prohibition or consequences associated with such prohibition disproportionate.
civil-law consequences: eu law permits national courts to declare contracts for prohibited gambling services void. consequently, consumers can pursue civil claims for the restitution of lost stakes.
subsequent licensing regimes: germany's transition to a licensing system in july 2021 does not retroactively invalidate the prior prohibition. the legal consequences of the old regime apply fully to the period it was active.
practical implications
if you provide cross-border online gambling services, you must assess compliance strictly on a jurisdiction-by-jurisdiction basis. implementing the strongest possible geographic controls is essential to prevent access from prohibited markets. the cjeu has effectively confirmed that consumers can act as private enforcers, using contractual nullity to reclaim lost funds.
the cjeu press release can be accessed here and the cjeu judgment here
CySEC adopts ESMA Guidelines on Liquidity Management Tools for fund managers
on 6 may 2026, the cyprus securities and exchange commission (cysec) issued circular c776, confirming its adoption of the esma guidelines on liquidity management tools (lmts) of ucits and open-ended aifs (esma34-671404336-1364) (the guidelines). the guidelines, published by esma on 12 march 2026, are directed at ucits management companies (including self-managed ucits) and alternative investment fund managers (aifms) (including internally managed aifs).
cysec has incorporated these guidelines into its supervisory practices and regulatory approach, signalling a clear expectation of compliance by cyprus investment fund managers (cyifms).
legislative basis
the guidelines stem from mandates under directive (eu) 2024/927 (the aifmd ii), which amends both the aifmd and the ucits directive. specifically, article 18a(4) of the ucits directive and article 16(2h) of the aifmd require esma to develop guidelines on the selection and calibration of lmts for the purposes of liquidity risk management and the mitigation of financial stability risks. the aifmd ii is expected to be transposed into cypriot national law in due course.
key obligations for fund managers
a central feature of the new regime is the mandatory minimum selection requirement. each ucits management company or aifm must select at least two appropriate lmts, following an assessment of the suitability of such tools considering the fund's investment strategy, liquidity profile and redemption policy.
the available toolkit under the framework includes:
quantitative-based lmts: temporary suspensions of subscriptions, repurchases and redemptions of units of shares. as well as the selection of redemption gates, extensions on notice periods and redemptions in kind (the latter restricted to professional investors only).
anti-dilution tools (adts): to mitigate investor dilution and potential first mover advantage. redemption fees, swing pricing, dual pricing and anti-dilution levies can be used in a fair manner and reasonable manner.
side pockets: which may be activated in the interest of investors on an exceptional basis.
notably, temporary suspension of subscriptions and redemptions, as well as the activation of side pockets, may be deployed without prior inclusion in the fund's constitutional documents, provided this is justified by investor protection considerations.
cysec expectations
the circular outlines specific expectations for cyifms, as highlighted below:
review and, where necessary, bolster their liquidity risk management frameworks to ensure that appropriate lmts are effectively embedded into fund structures.
ensure that the selection, calibration and activation of lmts are consistent with the investment strategy, liquidity profile and redemption policy of each fund under management.
establish comprehensive and robust governance arrangements as well as internal procedures governing the use of lmts, including clear decision-making processes and escalation mechanisms.
apply lmts in a fair, transparent and consistent manner, with due regard to the interests of all investors.
adequately disclose the availability and potential use of lmts in offering documentation and investor disclosures, in accordance with applicable transparency requirements.
ensure that relevant staff possess the necessary expertise and that appropriate systems and controls are in place to support effective implementation and monitoring.
timeline
the guidelines apply as of 16 april 2026, which aligns with the date of application of the rts (commission delegated regulations (eu) 2026/465 and 2026/466) specifying the characteristics of lmts. for ucis existing prior to that date, a twelve-month transitional period applies, with full compliance required by 16 april 2027.
wider eu context
cysec is not alone in adopting the guidelines. the cssf in luxembourg issued its own circular 26/910 on 15 april 2026 applying the same esma guidelines, and the amf in france has confirmed its intention to comply once the national transposition of directive (eu) 2024/927 is complete. this cross-jurisdictional convergence underscores esma's aim of ensuring the common, uniform and consistent application of the lmt framework across the single market.
our blog post of luxemburg’s cssf’s circular 26/910 on esma’s lmt guidelines can be accessed here.
practical takeaway
cyifms should treat the circular as requiring immediate action. the combination of a mandatory minimum lmt selection, enhanced governance and disclosure obligations, and defined timelines leaves limited room for delay, particularly for newly established funds, for which the guidelines are already in force.
the cysec circular c776 can be found here and the esma guidelines on lmts of ucits and open-ended aifs can be accessed here
Bermuda’s asset tokenisation consultation: Evolution, not a new regime
on 9 april 2026, the bermuda monetary authority (bma) issued a consultation paper on asset tokenisation. the consultation paper aims to promote responsible innovation in tokenised assets while maintaining robust investor protections, market integrity, and alignment with international standards, by enhancing regulatory clarity and addressing tokenisation-specific risks within bermuda's existing legislative frameworks. notably, the paper does not propose an entirely new regulatory regime. rather, it advances targeted clarifications and amendments within existing legislative frameworks, including the investment business act 2003, the investment funds act 2006, the digital asset business act 2018, the digital asset issuance act 2020, and related statutes.
key points for market participants include:
a “substance over form” model.the bma proposes to regulate tokenised assets according to their economic and functional characteristics, rather than the fact that distributed ledger technology is used. this is important for structures that may sit across the investment business act, investment funds act, digital asset business act and digital asset issuance act.
a harmonised definition of “tokenised investment”.the bma proposes a single definition, introduced through the investment business act and cross-referenced across other regimes. the proposed definition covers an investment represented in digital form using dlt, whether as a “digital twin” of an existing off-chain asset or as a “native token” existing solely on a distributed ledger.
digital twins and native tokens are treated differently, but within one framework.the bma uses this distinction for operational and supervisory purposes, not to create separate regimes. digital twins require attention to the link between the off-chain asset and the on-chain token, including title, asset verification, reconciliation and enforceability. native tokens, by contrast, do not require the same off-chain asset verification or reconciliation because the token ledger is intended to be the definitive ownership record.
three functional roles drive the proposed obligations.the framework distinguishes between primary tokenisers, secondary offerors and custodians. primary tokenisers are responsible for issuance, legal structuring, technical implementation and maintaining the integrity of the tokenised asset. secondary offerors facilitate access to, or trading in, already-created tokenised assets, including through broker-dealer, asset management or trading venue models. custodians safeguard tokens and, for digital twins, may also safeguard the underlying assets.
cross-regime relief is paired with cross-regime controls.the bma proposes tailored exemptions to reduce duplicative licensing where risks are already addressed under one framework. at the same time, it proposes extending the digital asset business (dab) operational cyber risk management code of practice to all entities involved in tokenisation and applying the dab custody code of practice to all entities providing custody for tokenised assets.
tokenised funds receive bespoke treatment.the bma recognises that tokenised fund units may look like native tokens where the register is on-chain, but the fund’s nav is still derived from off-chain portfolio assets. the consultation therefore proposes a tailored approach that preserves the existing investor protection framework for funds while addressing tokenisation-specific operational risks. the bma is also considering amendments to allow fund registers to exist purely on-chain and to require disclosures on smart contract functionality, upgrade mechanisms, technology risks and service provider responsibilities.
fractionalisation is not intended to dilute eligibility rules.the bma states that tokenisation should not be used to make restricted fund products available to investors who would not otherwise meet the applicable eligibility criteria.
stakeholders are invited to submit comments to the bma by the close of business on 30 june 2026. responses received will inform any subsequent legislative amendments, guidance notes, or further regulatory action.
the consultation paper can be found here.
for additional context on the proposed regulatory framework for asset tokenisation, refer to the stakeholder letter, available here
New Sheriff in Road Town: BVI gets its first Information Commissioner
the bvi has taken a significant step forward in its data protection journey. effective as of 11 may 2026, the bvi government officially appointed melissa brewley as the bvi’s first information commissioner under the data protection act 2021 (the dpa). the public announcement was issued on 9 june 2026.
this is more than a routine public appointment as it marks the activation of a dedicated competent authority and oversight function for data protection across the bvi, with real implications for businesses, public authorities and anyone handling personal data in or from the bvi.
what does the information commissioner do?
in short, the information commissioner is responsible for making the dpa work in practice in the bvi. key roles include:
enforcement and complaints handling: the information commissioner will monitor compliance with the dpa, receive complaints and investigate alleged breaches of data protection principles;
public and private sector reach: the role covers both public bodies and private organisations, reflecting the dpa’s broad application to the collection, processing, storage and sharing of personal data in the bvi;
advising on reform: beyond enforcement, the information commissioner is expected to recommend legislative, administrative and procedural improvements to strengthen the bvi’s data protection framework;
education and awareness: the information commissioner’s remit includes developing programmes to help the public better understand the privacy rights and responsibilities.
about the information commissioner
the information commissioner has, until recently, acted in senior legal and regulatory roles at the bvi international tax authority, supporting intergovernmental agreements, confidentiality and data protection obligations, and legislative developments aligned with the oecd’s international standards. we at harneys are very pleased and excited about ms brewley’s appointment to this important function and we wish her all the very best in this new role.
why does this matter?
the bvi government has framed this appointment as an important step in enforcing the dpa and raising standards for the handling of personal data in the bvi. for regulated entities, public authorities and businesses in or from within the bvi, the message is clear i.e. data protection is not subject to active, dedicated oversight. should you have any immediate concerns and in need of any legal advice or looking to implement any data protection policies and procedures into your business operations, please do feel free to get in touch with us.
for further details, the official press release can be found here.
EU acts against war crimes and human rights violations: Further sanctions on Russia, Iran and cyber actors
the european union announced a series of restrictive measures targeting individuals and entities involved in significant violations of international law, human rights, and cybersecurity. these measures were adopted on 16 march 2026, reflect the eu's commitment to safeguard global security, human rights, and the rule of law. these measures form a distinct package of measures from the 20th package on russia, which was released on 23 april 2026.
sanctions related to russia's actions in ukraine: nine (9) individuals responsible for the atrocities committed during the bucha massacre in 2022 have been sanctioned. the designations include high-ranking military officials implicated in crimes against humanity, war crimes, and actions undermining ukraine's sovereignty. measures include asset freezes and travel bans, adding to the eu's extensive sanctions against russia.
countering russian hybrid threats: four (4) individuals have been sanctioned for their roles in spreading disinformation and propaganda supporting russia's aggression against ukraine. these actions undermine democracy and stability within the eu and its partners. the sanctions include asset freezes and travel bans, bringing the total under this regime to sixty-nine (69) individuals and seventeen (17) entities.
human rights violations in iran: sixteen (16) individuals and three entities have been sanctioned for their involvement in suppressing protests and violating human rights in iran. those targeted include members of the judiciary, security officials, and entities linked to surveillance and repression. sanctions include asset freezes, travel bans, and restrictions on exports of monitoring equipment.
cybersecurity measures: entities and individuals have been sanctioned for cyberattacks targeting eu member states and partners. these include chinese and iranian entities involved in hacking critical infrastructure and spreading disinformation. the sanctions aim to deter malicious cyber activities and promote a secure cyberspace.
the press release for the sanctions related to russia's actions in ukraine can be found here
the press release for the russian hybrid threats can be accessed here
the press release for the human rights violations in iran here
the press release for the cybersecurity measures here
E4 leaders issue joint statement on US–Iran peace deal: Key regulatory takeaways
on 14 june 2026, a broad coalition of states, including the united kingdom and european union member states, issued a joint statement responding to the announcement of a memorandum of understanding (mou) between the united states and iran, calling for the detailed negotiations to be concluded and the agreement to be implemented rapidly and comprehensively, indicating their readiness to support that effort.
the statement, first published on gov.uk on 15 june 2026, has since been updated on several occasions to add further signatories, most recently on 17 june 2026. it addresses several matters of potential interest from a regulatory and compliance perspective, summarised below.
freedom of navigation in the strait of hormuz. the leaders describe the urgent re-opening of the strait of hormuz, with unconditional and unrestricted freedom of navigation, as essential. they commit to playing their part in achieving this, in accordance with their respective constitutional requirements, including through a strictly defensive and independent mission intended to reassure commercial shipping and to conduct mine clearance operations.
sanctions relief and nuclear non-proliferation. the statement reiterates that iran must never acquire a nuclear weapon and expresses a readiness to work with the united states, iran and the international atomic energy agency (iaea) to that end. of relevance to sanctions practitioners, the e4 leaders state that they are prepared to lift relevant sanctions in response to clear, verifiable steps by iran on its nuclear programme. the statement does not identify which specific sanctions measures would be affected, nor the timing or sequencing of any such relief.
as negotiations advance, affected parties should monitor developments closely, particularly the prospect of phased sanctions relief contingent on verifiable compliance, and any consequent adjustments to navigation and maritime security arrangements. the provisional nature of the mou means that compliance obligations, licensing positions, and applicable restrictions may evolve as detailed terms are finalised and implemented across the participating jurisdictions.
regional stability. the signatories reaffirmed their support for the stability, sovereignty, and territorial integrity of lebanon and underscored the importance of a robust ceasefire.
the statement concluded with a commitment to work intensively with the united states, iran, and regional partners to maintain momentum and pursue a long-term diplomatic settlement.
the press release can be found here
Showing 21 to 40 of 93 entries