The Travel Rule Skips Tokenized Securities, AML Law Does Not, and the Rules Change on 10 July 2027
The EU Travel Rule does not cover a token that is a financial instrument, but AML duties do, and they change on 10 July 2027. Here is who owes what.

Executive Summary
Two sets of rules get mixed up in tokenization projects, and their reach differs. The Travel Rule in Regulation (EU) 2023/1113 applies to transfers of “crypto-assets”, and that regulation defines the term so that anything MiCA excludes under Article 2(4) falls outside it, financial instruments included. By our reading, a token that is a MiFID II share or bond is therefore outside the Travel Rule. The wider anti-money laundering framework is not: the firms that sell, trade, hold, settle and bank that token are obliged entities, and they owe identity checks, monitoring and five years of records.
The stake is sequencing. On 10 July 2027, Regulation (EU) 2024/1624 (the AMLR) starts to apply and the 2015 directive is repealed, 274 days after this article’s date. An issuer that launches this autumn builds investor files under one regime and runs them under another. On 30 September 2026 the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) published final reports on its draft technical standards for customer due diligence and for thresholds, to be submitted to the Commission for adoption.
The Travel Rule exclusion is only as good as the classification behind it. If the token is a crypto-asset, the provider handling it needs MiCA authorization and the Travel Rule applies. On 24 September 2026 the EBA said the line is still unclear (see MiCA or MiFID: Your Token’s Rights Decide). This is general information, not legal advice. Where we draw a conclusion, we say “by our reading”.
Key Takeaways
- The Travel Rule covers transfers of crypto-assets and funds. A token that is a financial instrument is not a crypto-asset under the regulation. The cash payment for it is still a transfer of funds.
- AML duties attach to what an entity does. Issuing is not a listed activity. Placing, trading, settling and holding the cash are.
- From 10 July 2027 the AMLR applies directly in every Member State. Supervision stays national for most firms.
- For instrument tokens, the issuer’s choice of who may hold the token does the work that wallet rules do for crypto-asset service providers.
- Investor KYC status is a fact with a source and an expiry. The AMLR sets outer limits: one year for higher-risk customers, five for the rest.
Who Is an Obliged Entity When a Token Moves
The AMLR defines obliged entities by activity, not technology. Article 3 lists the categories. The words “tokenised” and “distributed ledger” do not appear in the regulation (we searched the full text), so a share on a chain is treated like any other share. What counts is who performs which function.
| Party in the structure | Obliged entity? | Basis |
|---|---|---|
| Issuer of shares or bonds, as issuer | No category for issuing | AMLR Art. 3 |
| Fund or fund manager making units available (UCITS, alternative investment fund) | Yes | Art. 2(1)(6)(e) |
| Investment firm: placing, order execution, reception and transmission, operating an MTF or OTF | Yes | Art. 2(1)(6)(d); MiFID II Annex I A |
| Central securities depository | Yes | Art. 2(1)(6)(f) |
| Crypto-asset service provider, for tokens that are not financial instruments | Yes | Art. 2(1)(6)(i), (7) |
| Credit institution holding the cash leg | Yes | Art. 2(1)(5) |
| Crowdfunding service provider; lawyers and company-service providers for listed activities | Yes | Art. 3(3)(h), (b), (c) |
| Registrar or transfer agent as such; KYC vendor; wallet software | Not named; a vendor doing checks is an outsourcee | Art. 18 |
By our reading, an issuer is not an obliged entity merely because it issued. It becomes one if it also sits in a listed category, and a fund does. The AMLR’s definition of crypto-asset excludes the categories in MiCA Article 2(4) (Art. 2(1)(7)), so a crypto-asset service provider’s duties attach to tokens that are not financial instruments. One gap deserves a check. Recital 13 of the DLT Pilot Regulation says a DLT multilateral trading facility should be operated by an investment firm or a market operator. The AMLR list names the first and not the second, so a market operator that is not also an investment firm is not obviously covered. National law may fill the gap; we have not checked it.
What the Travel Rule Covers, and What It Skips
The Travel Rule requires information on the originator and beneficiary to accompany a transfer. Regulation (EU) 2023/1113, applicable to crypto-assets since 30 December 2024, covers “transfers of crypto-assets” where the service provider of either side has its registered office in the Union (Article 2(1)). Article 14 sets no minimum amount.
The scope turns on one definition. Article 3(14) says a crypto-asset is a MiCA crypto-asset “except where falling within the categories listed in Article 2(2), (3) and (4)” of MiCA, or otherwise qualifying as funds. MiCA Article 2(4)(a) lists financial instruments. Recital 10 says the definitions match MiCA’s so that they track the FATF’s. The FATF glossary agrees from the other end: virtual assets do not include securities and other financial assets already covered elsewhere in the Recommendations.
| Transfer | Travel Rule under Regulation (EU) 2023/1113? | Basis |
|---|---|---|
| Euro payment for the subscription, between payment service providers | Yes, as a transfer of funds | Art. 2(1) |
| Token that is a MiFID financial instrument, wallet to wallet or through a venue | No, not a “crypto-asset” | Art. 3(14); MiCA Art. 2(4)(a) |
| E-money token as the cash leg, with a service provider on either side | Yes, e-money tokens are treated as crypto-assets | Art. 2(4), last subparagraph; Art. 14 |
| Token that is not a financial instrument, transferred by a service provider | Yes | Art. 3(10), Art. 14 |
| Between two providers on their own behalf, or person to person with no provider | No | Art. 2(4) |
| Unique, non-fungible token | Out of scope unless classified as a crypto-asset or funds | Art. 3(14); recital 24 |
By our reading, the exclusion is clear on the text and fragile in practice, because it rests on a classification. If a structure planned as a MiFID token is later treated as a crypto-asset, every transfer through a service provider needs Travel Rule data from the first day. Plan the Travel Rule answer from the classification file, not from the whitepaper.
The EBA’s Travel Rule Guidelines (EBA/GL/2024/11, 4 July 2024) tell providers what to do about missing information; AMLA’s instruments page, updated 30 September 2026, lists them as continuing to apply until AMLA’s own instruments replace them. Outside the EU, the FATF’s seventh targeted update on Recommendation 15 (16 July 2026) reports that 83% of surveyed jurisdictions have passed Travel Rule legislation, up from 73% in 2025, and the revised Recommendation 16 on payment transparency is due in effect by the end of 2030. An investor in a third country may meet these rules where the EU does not apply them to your token.
Know Your Investor: Due Diligence at Issuance and on Transfer
This is where tokenized securities meet AML law. The duties sit on whichever obliged entity has the customer.
At onboarding. Customer due diligence applies when a business relationship is established (Article 19(1)(a)). Article 20(1) lists the measures: identify and verify the customer and beneficial owners, understand the purpose of the relationship, screen for sanctions and political exposure, identify anyone on whose behalf the customer acts, and monitor. Verification means an identity document with independent sources, or electronic identification at assurance level “substantial” or “high” (Article 22(6)).
Before anything moves. Verification comes before the relationship starts (Article 23(1)). Article 23(3) addresses our case directly: an institution may open an account, “including accounts that permit transactions in transferable securities”, if safeguards ensure nothing is carried out until the identification and beneficial-owner checks are complete. By our reading, a wallet that can be bound but cannot yet receive is the on-chain form of that safeguard.
On transfer. The AMLR creates no separate check for each transfer between holders. It requires ongoing monitoring of the relationship and its transactions (Article 26(1)), so the question is whose customer each holder is. A venue or custodian monitors its own customers. An issuer register that admits only verified holders is a useful control, and by our reading not a substitute for the obliged entity’s own duties.
Over time. Customer information must be kept current: at most one year between updates for higher-risk customers, five years for the rest, and on any change of circumstances (Article 26(2)–(3)). If due diligence cannot be completed, the entity refrains from the transaction or relationship (Article 21(1)). Records are kept for five years after the relationship ends, not redacted, and personal data is then deleted unless other law requires otherwise (Article 77).
Using a provider. A KYC vendor doing checks for an obliged entity is an outsourcee. The entity notifies its supervisor, stays fully liable, and cannot outsource the decision to enter a business relationship or the decision on the customer’s risk profile (Article 18). Reliance is a different route: an obliged entity may rely on another obliged entity for identification, beneficial-owner and purpose checks, under a written agreement and with responsibility staying with the relying entity (Articles 48 and 49). A vendor that is not itself an obliged entity does not fit it.
Wallets You Do Not Control
A self-hosted address is a ledger address not linked to a service provider or an equivalent outside the Union (Article 3(20)). For a transfer to or from one, the provider must hold the originator and beneficiary information and, above EUR 1,000, assess whether its own customer owns or controls the address (Articles 14(5), 16(2)). The AMLR adds a mitigation duty in Article 40, with AMLA guidelines due by 10 July 2027. The EBA Guidelines list accepted proofs of control (paragraph 83): remote verification, a small transfer from and to the address, or a message signed with its key.
For instrument tokens, these duties do not fall on the issuer by the text of either regulation. By our reading, the list is still the best public template for the question every permissioned register must answer: how does the register know this wallet belongs to this verified person? The AMLR also bans credit institutions, financial institutions and service providers from keeping accounts that allow anonymisation of the account holder (Article 79(1)). A pseudonymous register is not an anonymous one when the obliged entity holds the link to the verified person off chain.
Article 79(3) also bans bearer shares, with conversion, immobilisation or deposit due by 10 July 2029 and exceptions for listed companies and for intermediated or dematerialised issuance. The text does not mention tokens. By our reading, a share token held by whoever controls a key, with no register tying the key to a person, is the case to take to a lawyer.
What Changes on 10 July 2027
| Date | Change | Source |
|---|---|---|
| 30 December 2024 | Travel Rule for crypto-assets applies; crypto-asset service providers join the obliged entities of Directive (EU) 2015/849 | Regulation (EU) 2023/1113, Arts. 38, 40 |
| 30 September 2026 | AMLA final reports on draft technical standards for customer due diligence (Art. 28(1)) and thresholds (Art. 19(9)), to be submitted to the Commission for adoption | AMLA |
| 1 July 2027 | AMLA starts its first selection of entities for direct supervision | Regulation (EU) 2024/1620, Art. 13(4) |
| 10 July 2027 | AMLR applies; Directive (EU) 2015/849 repealed; Member States must transpose Directive (EU) 2024/1640; AMLA guidelines due on self-hosted addresses and outsourcing | AMLR Arts. 90, 40, 18; Directive (EU) 2024/1640, Arts. 77, 78 |
| 2028 | AMLA’s direct supervision of selected entities begins | Regulation (EU) 2024/1620, recital 86 |
| 10 July 2029 | Bearer-share conversion deadline | AMLR Art. 79(3) |
First, the AMLR is a regulation: the same text applies in every Member State, but supervision stays national for most firms. AMLA directly supervises only selected institutions that operate in at least six Member States and are classed high risk, with no more than 40 in the first round (Regulation (EU) 2024/1620, Articles 12, 13, 106(2)). A venue active in one Member State deals with its national authority. For the MiCA side, see significant CASPs and ESMA supervision.
Second, the technical standards are drafts until adopted. In the thresholds report, AMLA says it added no further lower thresholds, so the AMLR’s own figures stand: EUR 10,000 for occasional transactions, and EUR 1,000 for crypto-asset service providers and for transfers of funds by other financial institutions (Article 19(1)(b), (2), (3)). In the due diligence draft, a collective investment undertaking distributing through another regulated institution acting in its own name may, on strict conditions, rely on it to identify the final investors. We read only these passages of the two reports.
Third, what carries over matters more than the date. We have not compared the 2015 and 2027 data sets article by article, so we do not claim that a file that passes today passes in July 2027. Investor facts held as dated records with a named source give a gap list when a standard changes, not a re-onboarding.
The Record View
A spreadsheet line saying “KYC done” cannot say by whom, against what, when, and good until when. In Stobox Intelligence, the same fact is built to be held as a record: status, verifier, method, date, expiry, and a reference to where the evidence sits. The record has no name, birth date or document image; those stay with the party that checked them, in line with Article 77.
| Field | Illustrative content |
|---|---|
| Subject | A pseudonymous reference, never a name |
| Fact and verifier | Identity verified to the level the obliged entity applies, by a named obliged entity or its outsourcee |
| Method | Identity document, or electronic identification at “substantial” or “high” (Art. 22(6)) |
| Date and review due | A calendar date; review inside the one-year or five-year limit (Art. 26(2)) |
| Source and evidence level | A reference to the verifier’s file, and how far the record was checked against it |
Nothing is averaged. The risk profile is the obliged entity’s own decision and cannot be outsourced (Article 18), so it is not a platform score. When a review changes the status, the old record stays and a dated one sits beside it.
Design Note: Stobox Orbit
Stobox Orbit, a permissioned tokenization protocol, is in development and running on testnet. It makes no claim about AML compliance, and it does not decide who is an obliged entity or whether the Travel Rule applies to a token.
A verification result is designed to become claims in a registry. A claim states a yes-or-no fact a rule needs, names the issuer that wrote it, carries an expiry, and holds only a salted hash of a reference to evidence kept off chain by the party that checked. The register is pseudonymous: a subject is a hash, not a name, and no identifying data or document content is on chain, hashed or otherwise. Wallets are bound to the person with the wallet’s own signature; Orbit holds no private keys. Every transfer checks that sender and recipient are active in the registry. A revoked claim takes effect on the next transfer; an expired one stops a new purchase or receipt and never forces a holder out.
By design, the party named on an identity claim signs it: the KYC provider, or the issuer’s own key. A Stobox key signs identity claims only for Stobox’s own issuances and otherwise relays, so Stobox does not sign a client’s KYC claims. For a client’s token the issuer is the controller of its investors’ KYC, and Stobox may run the flow as a service provider, as technology only.
What Orbit does not do yet: it does not carry Travel Rule data. Its catalogue lists the Travel Rule as an off-chain item, planned, and no Travel Rule check exists in code today.
What to Do on Monday
In the Stobox Tokenization Framework, this question sits in Legal Documentation and in the investor onboarding that follows it.
- Map each party against the AMLR list. Issuer, placing agent, venue, custodian or depository, registrar, the bank holding the cash, the law firm, the KYC vendor. Mark who is an obliged entity and who is an outsourcee. Note unclear cases as open.
- Write the Travel Rule answer for each token and cash leg. State whether the token is a financial instrument or a crypto-asset, cite the classification file, and say whether an e-money token carries the cash leg. Date it.
- Hold investor KYC status as a dated record, not a copy of the file. Name who verified, the method, the date and the review date inside the one-year and five-year limits. Keep personal data with the verifier.
- Choose your wallet-control proof. Decide which of the EBA’s methods your register or venue requires for an investor’s own wallet, and what happens on a wallet change.
- Re-read your KYC vendor and venue contracts for July 2027. Check the written agreement, who decides on acceptance, five-year non-redacted retention, and who answers a supervisor. Watch for the Commission’s adoption of AMLA’s draft standards.
FAQ
Does the Travel Rule apply to transfers of tokenized shares or bonds? By our reading, no. Regulation (EU) 2023/1113 defines a crypto-asset so that anything excluded from MiCA by Article 2(4), financial instruments included, is outside it. The payment leg and e-money token transfers through a crypto-asset service provider are still covered, and a wrong classification reverses the answer.
Is the issuer of a token an obliged entity under the AMLR? Not because it issues. Article 3 of Regulation (EU) 2024/1624 lists categories of entity, and issuing is not one. An issuer is covered if it also falls into a listed category, such as a fund that makes units available. The firms hired to place, trade, hold or settle the token usually are.
When does the AMLR apply? From 10 July 2027 (Article 90), when Directive (EU) 2015/849 is repealed. Until then the current rules continue, including the Travel Rule for crypto-assets, applicable since 30 December 2024.
Can an issuer rely on a KYC provider’s result? Only within limits. A provider doing checks for an obliged entity is an outsourcee, and the entity stays fully liable. The decision to enter into a business relationship cannot be outsourced (Article 18). Reliance on another obliged entity covers identification, beneficial owner and purpose checks, and responsibility stays with the relying entity (Article 48).
To see how an investor’s verification status looks as a record, look at Stobox Intelligence; Stobox Orbit’s documentation will follow when it is public. For the jurisdiction overview, see our EU guide; for identity without exposing people, on-chain KYC without doxxing.
Related reading in this series
- MiCA or MiFID: Your Token’s Rights Decide
- Significant CASPs and ESMA supervision from 2027
- The DLT Pilot cap: what EU ministers decide on 9 October
- Next in the series: GDPR and onchain registers for EU issuers, and the 2027 scenarios.
Sources
Accessed 1 October 2026.
- Regulation (EU) 2024/1624 (AMLR), OJ L, 19.6.2024, Articles 2, 3, 9, 18, 19, 20, 21, 22, 23, 26, 40, 48, 49, 77, 79, 90 and recitals: EU Publications Office
- Regulation (EU) 2024/1620 (AMLA), OJ L, 19.6.2024, Articles 12, 13, 106, 108 and recital 86: EU Publications Office
- Directive (EU) 2024/1640, OJ L, 19.6.2024, Articles 77 and 78: EU Publications Office
- Regulation (EU) 2023/1113 (Transfer of Funds Regulation), OJ L 150, 9.6.2023, Articles 2, 3, 14, 16, 38, 40 and recitals 10 and 24: EU Publications Office
- Regulation (EU) 2023/1114 (MiCA), OJ L 150, 9.6.2023, Articles 2(3), 2(4) and 3(1): EU Publications Office
- Directive 2014/65/EU (MiFID II), Article 4(1)(1) and Annex I: EU Publications Office
- Regulation (EU) 2022/858 (DLT Pilot Regulation), recital 13: EU Publications Office
- EBA, Guidelines on information requirements in relation to transfers of funds and certain crypto-assets transfers under Regulation (EU) 2023/1113 (Travel Rule Guidelines), EBA/GL/2024/11, 4 July 2024: EBA
- AMLA, Regulatory instruments, last update 30 September 2026: AMLA
- AMLA, Final Report, draft RTS under Article 19(9) of Regulation (EU) 2024/1624, 30 September 2026: AMLA
- AMLA, Final Report, draft RTS under Article 28(1) of Regulation (EU) 2024/1624, 30 September 2026: AMLA
- FATF Glossary, “Virtual asset” and “Virtual asset service provider”: FATF
- FATF, “FATF calls for closing of regulatory gaps as virtual asset illicit finance risks become more complex”, 16 July 2026: FATF
- FATF, “FATF updates Standards on Recommendation 16 on Payment Transparency”, 18 June 2025: FATF
- EBA, Response to the EC targeted consultation on the review of MiCA, 24 September 2026, as summarized in our MiCA or MiFID article
This article is general information, not legal advice. It does not assess any specific token, structure or firm. We did not read national law, and we read the two AMLA final reports only in the passages cited. Check your structure with qualified counsel in the relevant Member State.







