The Waiting Is Over: How 2026 Turns the Travel Rule into Enforcement
- Elizabeth Travis

- Aug 7
- 7 min read

When the Financial Action Task Force (FATF) published its sixth targeted update on virtual assets in June 2025, it recorded a fact that should have unsettled every compliance officer in Europe. Of the 85 jurisdictions that had passed travel rule legislation, roughly 59 per cent had issued no findings, no directives and no enforcement action at all. The rule existed on paper across most of the developed world. Almost nowhere had it been tested in anger. For firms that had treated the travel rule as a documentation exercise, that gap was a form of shelter. In 2026, the shelter is being dismantled.
The travel rule, the European application of FATF Recommendation 16 (R16), requires that identifying information about the originator and the beneficiary accompanies a transfer of value. In the European Union it is given force by the recast Transfer of Funds Regulation (TFR), Regulation (EU) 2023/1113, which has applied to crypto-asset transfers since 30 December 2024 with no de minimis threshold. Every transfer between crypto-asset service providers (CASPs) must carry the data, from the first euro. The obligation has been live for eighteen months. What has changed is not the law but the willingness to enforce it.
The enforcement gap was never neutral
The FATF was blunt about why the gap mattered. Weak implementation in any one jurisdiction, it warned, creates systemic vulnerability across a borderless sector. The point is structural rather than moral. A travel rule that is legislated but not supervised does not deter anyone; it simply relocates risk to whichever firm is least likely to be inspected. The rule's entire logic depends on the counterparty on the other side of a transfer being held to the same standard. Where enforcement is absent, the data that is supposed to travel arrives incomplete, unverified or not at all, and the sending firm inherits a counterparty it cannot assess.
This is the context in which the phrase "the regulators are done waiting" needs to be read carefully. The enforcement lag documented by the FATF was partly a function of recency; many travel rule laws were young, and supervisors were still building the frameworks to test them. That explanation is now expiring. The FATF used its June 2025 update to publish a dedicated Best Practices on Travel Rule Supervision paper, a signal that the standard-setter expects members to move from drafting rules to auditing them. The tools for enforcement are being handed out. The expectation that they will be used follows close behind.
Germany moves first, and it moves hard
Nowhere is the shift clearer than in Germany. In its Risiken im Fokus 2026 report, published on 28 January 2026, the Federal Financial Supervisory Authority (BaFin) stated that it will carry out at least 75 anti-money laundering special audits across the banking and non-banking sectors during the year, and it named the implementation of the travel rule by crypto-asset service providers as an explicit examination priority. The number is sector-wide rather than aimed solely at crypto firms, but the travel rule focus is directed squarely at them. These are not licensing reviews. They are Sonderprüfungen, on-site examinations of firms that already hold authorisation, and they target the question that most concerns supervisors: whether a documented control actually functions.
BaFin has been specific about what it expects. Supervisors want a documented travel rule risk analysis embedded in the firm's institution-wide risk assessment under the Money Laundering Act, and they want a technical solution that demonstrably exchanges the required data rather than a policy that merely asserts it will. Examiners are expected to ask which messaging protocol a firm uses and to have its system architecture explained to them. The distinction OpusDatum has long drawn between control existence and control effectiveness has become, in Germany, the explicit test.
The supervisory reach behind these audits has also widened. Germany's law strengthening financial-market integrity, the BRUBEG, took effect on 1 April 2026, expanding BaFin's inspection and search powers. A supervisor that can compel access is a different proposition from one that relies on a firm's cooperation. The combination is deliberate: heightened expectations, a named audit programme and reinforced powers to see behind the paperwork.
France ties enforcement to the licence itself
France has taken a different route to the same destination. Rather than run a separate audit wave, the Autorité des Marchés Financiers (AMF) has folded travel rule capability into the authorisation gate. Under the French transition to MiCA, the AMF has been explicit that a travel rule solution must be live at the point of application, not "in progress", a position confirmed in guidance to firms migrating from the former national regime. The MiCA transitional period closed on 1 July 2026, and firms without authorisation must cease French operations, facing a two-year prison term and a 30,000-euro fine under the Monetary and Financial Code for continuing without it.
The effect is to make travel rule readiness a condition of market access rather than a matter for later inspection. A firm that cannot demonstrate compliant data transmission does not receive a licence, and without a licence it has no business to inspect. France has, in effect, moved the enforcement moment forward to the door.
The Netherlands shows what enforcement already looks like
The Dutch position illustrates both the direction of travel and the importance of precision about it. De Nederlandsche Bank (DNB) has an established record of enforcing anti-money laundering obligations against crypto firms. In December 2025 the Court of Rotterdam upheld a finding that a provider had operated without the registration required under the Dutch Anti-Money Laundering and Anti-Terrorist Financing Act, though it reduced the penalty to 2,277,500 euros; DNB lodged a further appeal on 29 January 2026. In February 2026 DNB imposed an order subject to penalty on a crypto firm for failing to submit a required auditor's report on time.
These cases matter, but they should be characterised accurately. They concern registration and reporting failures rather than travel rule data transmission specifically. The lesson is not that a Dutch supervisor has yet published a headline travel rule penalty; it is that DNB treats crypto firms as gatekeepers and enforces the surrounding obligations without hesitation. A supervisor with that posture does not leave the travel rule permanently untested. It establishes the machinery first.
The EU layer is being assembled above the national one
National enforcement is arriving as a new supervisory architecture settles into place above it. The Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA), seated in Frankfurt, became operational on 1 July 2025, and in January 2026 the anti-money laundering mandates and functions of the European Banking Authority transferred to it. In February 2026 AMLA published its first multi-year plan, the Single Programming Document, setting out its work on the AML single rulebook and supervisory convergence.
It is worth being precise about what AMLA does and does not yet do. Its direct supervision of selected high-risk institutions, expected to include the largest CASPs, does not begin until 2028. Between now and then its influence is indirect but real: it drafts the standards national supervisors will apply, it monitors their compliance, and it will operate a central database into which inspection findings and sanctions are fed. A German or French supervisor examining a CASP in 2026 is increasingly working towards a methodology shaped in Frankfurt. The national and the European are converging, and the direction is uniformly towards demonstrable effectiveness rather than asserted compliance.
The standard itself is about to rise again
Firms treating 2026 as the endpoint of the travel rule's evolution are misreading it. On 18 June 2025 the FATF revised Recommendation 16 itself, extending it beyond wire transfers to all payments and value transfers, creating new obligations to obtain and transmit beneficiary information, and pressing for message data structured to standards such as ISO 20022. Those revisions take effect at the end of 2030 and must be adopted jurisdiction by jurisdiction. They matter to CASPs less through direct application than through direction of travel: the FATF has said it will apply the revised standard to virtual asset service providers indirectly, through the tailored framework overseen by its Virtual Asset Contact Group, rather than binding them to the wording of the payments rule. The signal is nonetheless unambiguous. The standard is moving towards richer data, verified rather than merely transmitted, and used rather than merely stored.
That direction should reframe how firms read the current audit wave. The controls being tested in 2026 are not the finished article; they are the foundation on which a higher standard will be built, in Europe through the anti-money laundering regulation that applies from July 2027 and globally through the FATF's own trajectory. A firm that scrambles to pass this year's examination with a minimum-viable solution is building on ground that will shift beneath it before the decade is out.
What firms should reassess now
The practical implication is that the travel rule can no longer be owned by a policy document. Supervisors in the jurisdictions leading the shift are asking to see architecture, not assurances. Firms should be able to explain which protocol carries their data, how the system handles failed, timed-out or incomplete messages, and how those events are logged and remediated. They should be able to show that self-hosted wallet controls function above the relevant thresholds, and that counterparty due diligence extends to whether a receiving CASP can safeguard the personal data being transmitted to it. Above all, they should treat the travel rule as an early-warning indicator: weakness here usually signals broader deficiency in the wider financial crime framework, and that is precisely what an examiner is trained to pursue.
The firms most exposed are those that read the enforcement gap as tolerance rather than delay. It was always the latter. The FATF said as much when it explained the lag as a function of supervisory frameworks still being built. Those frameworks are now built, funded and, in Germany's case, scheduled.
Conclusion
The travel rule spent its first eighteen months as a rule that travelled only on paper. The data was required to move; the enforcement was not yet ready to follow. That asymmetry gave firms a period of grace they were never promised and should never have banked. In 2026 the asymmetry closes: Germany audits, France gates the licence, the Netherlands enforces the obligations around it, and Frankfurt assembles the machinery that will make the standard consistent across the Union. The rule that once travelled only on paper is about to be tested in practice. The firms that mistook the quiet for permission will discover that the waiting was never absolution; it was only a delay.
Would your firm's travel rule solution survive an examiner asking to see it work, not just to read that it exists?
If that question gives you pause, contact us.
At OpusDatum, we help CASPs and payment firms move from documented travel rule policies to demonstrable travel rule controls, mapping protocol coverage, message-failure handling and counterparty due diligence to the effectiveness standard supervisors now apply. We treat control effectiveness, not control existence, as the measure that matters.


