Breaking

FCA PS26/18 leaves crypto front-ends waiting on Article 9Z2A

FCA PS26/18 leaves crypto front-ends waiting on Article 9Z2A

The Financial Conduct Authority’s (FCA) final cryptoasset perimeter guidance, Policy Statement PS26/18, tells UK trading apps and wallet front-ends that giving users a way to place orders is likely to be regulated arranging, while the technical-services exclusion that would take many of them out of scope sits in a separate HM Treasury statutory instrument that the guidance does not yet cover. With the FCA crypto authorisation window opening on September 30, 2026, firms must now decide on their permissions against a perimeter that is still changing.

The FCA published PS26/18 on September 16, 2026, turning its April consultation (CP26/13) into a new Perimeter Guidance Manual chapter, PERG 18, made under legal instrument FCA 2026/55. The guidance interprets the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 (S.I. 2026/102) as passed on February 4, 2026. One day earlier, on September 15, the Treasury published the draft Cryptoassets (Miscellaneous Amendments) Regulations 2026, which would insert a new Article 9Z2A excluding non-discretionary technical interfaces from the arranging activity. This analysis sets out what PERG 18 actually says, how the UK position compares with the EU, US and Singapore, and what the gap between the two texts means for applicants.

Key facts

  • September 16, 2026: the FCA published PS26/18 and final PERG 18 guidance, after 78 responses to CP26/13 (FCA PS26/18).
  • 63% of respondents on the intermediary topic did not support the guidance on arranging deals, and 59% said it read the activity too broadly (PS26/18, paragraph 4.32).
  • Article 9Z2A: the Treasury’s draft amending SI, published September 15, 2026, would exclude from Article 9Y arranging a person who “merely provides a technical service” giving access to authorised firms or decentralised protocols (Explanatory Memorandum, paragraph 6.10).
  • No overseas persons exclusion (OPE): the Cryptoasset Regulations do not apply the OPE to the new regulated cryptoasset activities (PERG 18.3.6).
  • Application window: September 30, 2026 to February 28, 2027 for firms relying on the savings provisions; the regime starts on October 25, 2027.
  • Next PERG update: the FCA plans to consult in early Q4 2026 on changes for the new SI and to publish final amended guidance in early 2027 (PS26/18, paragraph 1.8).

Methodology: the documents behind this analysis

This analysis rests on four primary documents. The first is PS26/18 and its made instrument FCA 2026/55, including the full PERG 18 text in Annex B. The second is the Treasury’s Explanatory Memorandum to the Cryptoassets (Miscellaneous Amendments) Regulations 2026. The third is the underlying S.I. 2026/102. The fourth is the EU’s Markets in Crypto-Assets Regulation (MiCA), Regulation (EU) 2023/1114. For the US and Singapore comparison we used the Commodity Futures Trading Commission (CFTC) staff position of September 17, 2026 and the Monetary Authority of Singapore (MAS) statement of June 6, 2025. Every quotation was checked against the source text; the window runs from April 2026 to September 21, 2026. The analysis covers the UK arranging and territorial perimeter. It does not cover the prudential, conduct or stablecoin rules in PS26/9 to PS26/13, which the FCA says remain “settled”.

What PERG 18 says about arranging, software and front-ends

PERG 18.8.4 follows the traditional-finance model. Article 9Y of the Regulated Activities Order (RAO) contains two activities: arranging (bringing about) deals in qualifying cryptoassets, and making arrangements with a view to transactions. The second is the broad one. According to the guidance, it can apply where a person provides “only part of the facilities” for a transaction, and it does not need to cause the deal. The FCA also rejected the control-based test that many respondents wanted. Under PERG 18.8.4, being able to influence, direct or exercise discretion over whether a transaction happens is “not a necessary element” of arranging, and neither is control over the cryptoassets.

Most of the guidance is about software. The FCA writes that “Developing software is not a regulated activity as such”, and that the persons who need authorisation are “typically” those who provide access to or use of software that facilitates transactions, “not necessarily the developers of it.” The line that matters most for wallets and trading apps comes next: “where a website host or app provider is providing users with the means by which they can place orders, this is likely to amount to the activity of making arrangements with a view to transactions in qualifying cryptoassets, unless an available exclusion applies.” Where the app also shows users that a trade has been completed, it may carry on both forms of arranging.

The FCA did narrow things in one area. New question PERG 18.8.8 says that providing information, analytics, research, market data or dashboard services “does not, of itself, amount to arranging.” The test is whether the service is part of how the transaction is carried out, for example by routing orders or identifying execution venues, not whether it influences a trading decision.

The FCA’s perimeter guidance for crypto front-ends in the UK can be summarised as follows. Under PERG 18.8.4, published in PS26/18 on September 16, 2026, a website or app that gives users the means to place orders in qualifying cryptoassets is likely to be making arrangements with a view to transactions under Article 9Y of the Regulated Activities Order, unless an exclusion applies. Control over client assets is not required, and discretion over trades is not required either. Writing code is not regulated as such. The obligation falls on whoever gives users access to the software. Pure information, analytics and dashboard services are unlikely to amount to arranging under PERG 18.8.8. The exclusion that would remove many non-discretionary interfaces, the proposed Article 9Z2A, is in a Treasury statutory instrument published in draft on September 15, 2026. PS26/18 does not yet reflect it. The FCA will consult on that change in early Q4 2026.

PS26/18 is also explicit about what PERG can and cannot do. Paragraph 1.15 says: “PERG cannot be used to expand, narrow or otherwise alter the scope of the perimeter established in legislation.” The FCA’s reply to the arranging feedback is that most objections were “directed at the breadth of the regulated activity itself rather than the content of the proposed guidance”. In other words, Parliament drew the arranging perimeter, and the FCA has no power to write in an exclusion that the law does not contain.

Jurisdiction / Regulator Effective date Scope Key requirement Penalty / sanction
UK (FCA, HM Treasury) October 25, 2027 (gateway opens September 30, 2026) Arranging deals in qualifying cryptoassets, Article 9Y RAO; no OPE (PERG 18.3.6) App providers enabling order placement likely arranging (PERG 18.8.4); proposed Article 9Z2A would exclude unregulated, non-discretionary interfaces Breach of the general prohibition in section 19 FSMA is a criminal offence under section 23 FSMA
EU (ESMA, national authorities under MiCA) CASP provisions applied from December 30, 2024 Reception and transmission of orders is a crypto-asset service, Article 3(1)(16)(g); fully decentralised services without an intermediary fall outside scope under Recital 22 Article 59 authorisation; Article 61 exempts services at the client’s exclusive initiative Article 111(3): maximum fines of at least €5 million or 5% of annual turnover for Article 59 breaches
US (CFTC) CFTC Staff Letter 26-25, September 17, 2026 Passive software sending users’ orders to registered futures commission merchants (FCMs), introducing brokers (IBs) and designated contract markets (DCMs) No-action relief from IB registration, subject to specified conditions Uniswap Labs: $175,000 civil monetary penalty, CFTC Docket No. 24-25 (September 4, 2024)
Singapore (MAS) June 30, 2025 Digital token service providers (DTSPs) serving only customers outside Singapore, Financial Services and Markets Act 2022 Must be licensed; MAS “will generally not issue a licence” Unlicensed DTSPs must cease regulated activities

Sources: FCA PS26/18; HM Treasury Explanatory Memorandum; Regulation (EU) 2023/1114; CFTC release 9300-26; CFTC release 8961-24; MAS, June 6, 2025. Last updated: September 21, 2026.

How four jurisdictions draw the line on software intermediaries

The four regimes all have to decide the same thing: when a piece of software that passes an order to someone else counts as an intermediary. They answer it in different ways.

MiCA decides it through its definitions. Reception and transmission of orders is a listed crypto-asset service under Article 3(1)(16)(g). Recital 22 says that services provided “in a fully decentralised manner without any intermediary” should not fall within scope. That gives EU front-ends a way out, although the recital has no fixed test and national regulators apply it differently. The UK has no equivalent recital. PERG 18.7.5, on interfaces connecting users to automated protocols, says the answer turns on whether a regulated activity is carried on “by an identifiable person”, assessed “on a case-by-case basis”.

The US approach is to grant relief through a staff letter. On September 17, 2026, the CFTC’s Market Participants Division made the no-action position it had given Phantom Technologies in Letter 26-09 in March available to passive software providers generally. Staff will not recommend enforcement for failing to register as an introducing broker, provided the software only connects users to registered FCMs, IBs and DCMs. As our analysis of CFTC Letter 26-25 explains, the relief depends on the software staying passive.

Singapore takes the opposite approach on territorial reach. Since June 30, 2025, a Singapore-based DTSP serving only overseas clients has needed a licence, and MAS said it “will generally not issue a licence”.

The UK’s territorial position under PS26/18 works as follows. The Cryptoasset Regulations amend section 418 of the Financial Services and Markets Act 2000 so that some cryptoasset activities involving UK consumers are treated as carried on in the UK even when the provider is established overseas. PERG 18.3.1 describes a two-stage test: first the ordinary territorial analysis, then the section 418 deeming provisions. PERG 18.3.6 confirms that the overseas persons exclusion is not available for the new regulated cryptoasset activities, although it may still apply to specified investment cryptoassets. PERG 18.3.7 says reverse solicitation is “not, in itself, an exemption or exclusion”, which differs from Article 61 of MiCA, where it is an express exemption. According to PS26/18, 13% of respondents challenged Parliament’s decision to leave out the OPE. An overseas dealer selling to a UK authorised intermediary, rather than to consumers, falls outside the deeming rule.

The main arbitrage risk is therefore about timing, not geography. Between now and Article 9Z2A taking effect, a UK front-end faces a stricter written position than an EU front-end relying on Recital 22 or a US wallet relying on Letter 26-25. Some firms may apply for permissions they will not need once the SI is in force.

“This is a significant moment for crypto regulation in the UK. We’ve created a framework that doesn’t force firms to choose between regulatory certainty and room to innovate – this regime means they can have both in a stable, competitive home to build and grow.”

David Geale, executive director of payments and digital finance, Financial Conduct Authority (FCA press release, June 30, 2026)

PS26/18 puts that promise of certainty under strain. The written guidance and the law it describes will differ for at least one full quarter of the application window.

Enforcement context: the Uniswap interface case

The UK regime has no enforcement record yet because the perimeter does not start until October 2027. The clearest precedent on who is responsible for a front-end is American. On September 4, 2024, the CFTC filed and settled charges against Universal Navigation Inc., trading as Uniswap Labs, in CFTC Docket No. 24-25. The order found that leveraged tokens available through the Uniswap protocol were leveraged or margined retail commodity transactions that had to trade on a designated contract market. Uniswap Labs paid a $175,000 civil monetary penalty and agreed to cease and desist.

The facts are directly relevant to PERG 18. According to the CFTC, Uniswap Labs “developed and maintained a web interface that it made available to users”, through which users could trade in hundreds of liquidity pools. The agency held the interface operator responsible, not the anonymous token deployers. PERG 18.8.4 takes the same approach when it says authorisation falls on the person providing access to software, “not necessarily the developers of it.”

For UK firms, the lesson is not the size of the fine, which the CFTC reduced for cooperation. It is the theory of liability. Once a regulator decides a front-end brings buyers and sellers together, the operator is responsible for what flows through it, whatever the protocol underneath looks like. In the UK, carrying on a regulated activity without permission breaches the section 19 general prohibition, which is a criminal offence under section 23 of the Financial Services and Markets Act 2000. Agreements made in breach may also be unenforceable against customers under section 26.

What this means for exchanges, wallets, brokers and compliance teams

Wallet and front-end providers. Any interface that lets users place orders should assume that PERG 18.8.4 applies until Article 9Z2A is in force. Under paragraph 6.10 of the Explanatory Memorandum, the proposed exclusion covers only a person who is “neither an authorised person nor a payment service provider”. Firms that are already authorised, or that are applying for other crypto permissions, may therefore not be able to use it. Paragraph 5.10 adds that the financial promotions regime will not copy the exclusion, so interface providers “remain subject to the regime” for their marketing even if they fall outside the arranging perimeter.

Exchanges and dealers. Overseas liquidity providers that sell only to UK-authorised dealers acting as intermediaries fall outside the section 418(6C) deeming rule (PERG 18.3.6). Direct sales to UK consumers from offshore are inside it. The same draft SI would also add an exclusion from dealing as principal for proprietary trading and market making (Article 9UA), which affects how firms structure groups. The FCA’s parallel reform of principal firms points the same way: permissions will be granted and checked, not assumed.

Legal and compliance teams. Existing Money Laundering Regulations (MLR) registrations and FSMA permissions “will not convert automatically” (PS26/18, paragraph 1.25). An RAO exclusion does not exempt a firm from MLR registration either. For the anti-money laundering gate, see how Annex 1 registration became an FCA gate. Application files should include a written perimeter memo that assesses each business line under both the current S.I. 2026/102 and the draft SI, and records which permissions would lapse if Article 9Z2A is made.

“This case has all the hallmarks of what we have come to know as regulation through enforcement: A settlement with a de minimis penalty that bears little relationship to the conduct alleged, sweeping statements about the broader industry that are not germane to the case at hand, and legal theories that have not been tested in court.”

Summer K. Mersinger, then Commissioner, Commodity Futures Trading Commission, dissenting on Uniswap Labs (CFTC, September 4, 2024)

Mersinger’s criticism is the strongest version of the industry’s case. Perimeter rules for software are better written in advance, through legislation or rulemaking, than inferred from enforcement orders. The UK is doing that through the draft SI, but it is not finished yet.

What’s next: the forward view

The next dates are fixed. The authorisation gateway opens on September 30, 2026. The FCA will consult in early Q4 2026 on further PERG amendments covering the new SI, including Article 9Z2A, the UK qualifying stablecoin exclusions and the temporary settlement exclusion from safeguarding, and it aims to finalise that guidance in early 2027. The savings-provision window closes on February 28, 2027, and the regime starts on October 25, 2027.

Several issues are still open. The draft SI has to complete its parliamentary process, and the final wording of the “substantively involved” condition in Article 9Z2A will decide how much an interface can do, for example routing, fee-setting or token curation, before it counts as arranging. The FCA’s June 30 press release also promised a separate consultation on decentralised finance (DeFi) guidance later this year. That paper will need to deal with the “identifiable person” question left open in PERG 18.7.5. The FCA also says it intends to consult on guidance distinguishing e-money from qualifying stablecoins.

In the US, Letter 26-25 remains a staff position that runs until the effective date of a Commission rulemaking or guidance on whether software developers must register as introducing brokers, and staff can modify or terminate it at any time. In the EU, ESMA and national regulators still interpret “fully decentralised” case by case. The industry body CryptoUK has already flagged the timing problem, warning that some firms may submit applications before the guidance reflects the legislative changes that decide whether they are in scope. For the wider timetable, see how the FCA’s final crypto rules set up the October 2027 gateway, why the UK refused to copy MiCA, and our earlier comparison of CP26/13 against MiCA, which predicted that the non-custodial wallet question would be settled only when the perimeter guidance was finalised.

TL;DR

The FCA’s PS26/18, published September 16, 2026, finalises PERG 18, the guidance on which UK crypto activities need authorisation from October 25, 2027. It says app and website providers that let users place orders are likely arranging deals under Article 9Y, whether or not they control assets or exercise discretion. It also confirms there is no overseas persons exclusion and that reverse solicitation is not an exemption. The FCA refused to narrow the arranging perimeter by guidance, even though 63% of respondents on the topic opposed it. The fix is a Treasury SI published in draft on September 15, 2026, whose Article 9Z2A would exclude unregulated, non-discretionary interfaces. PERG will not reflect it until early 2027. The gateway opens on September 30, so firms will be applying against a perimeter that is still changing.

FAQ

What is FCA PS26/18?

PS26/18 is the FCA’s policy statement on cryptoasset perimeter guidance, published on September 16, 2026. It finalises the April 2026 consultation CP26/13 and adds a new chapter, PERG 18, to the Perimeter Guidance Manual through instrument FCA 2026/55. PERG 18 explains when activities involving qualifying cryptoassets and qualifying stablecoins need FCA authorisation under the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026. It is guidance, not rules: it interprets the perimeter Parliament set and cannot change it. The FCA received 78 responses to the consultation.

Does a crypto wallet app need FCA authorisation?

It depends on what the app does. Under PERG 18.8.4, an app or website that gives users the means to place orders in qualifying cryptoassets is likely to be making arrangements with a view to transactions under Article 9Y, unless an exclusion applies. Controlling user assets is not required for that conclusion. Pure information, analytics or dashboard services are unlikely to be arranging under PERG 18.8.8. A self-custody wallet with a built-in swap or trade function should get a specific perimeter assessment before the gateway opens on September 30, 2026.

What is the proposed Article 9Z2A exclusion?

Article 9Z2A is a new exclusion from the arranging activity in the Treasury’s draft Cryptoassets (Miscellaneous Amendments) Regulations 2026, published on September 15, 2026. According to the Explanatory Memorandum, it would cover a person who is neither an authorised person nor a payment service provider and who merely provides a technical service giving access to authorised or exempt firms or decentralised protocols. It would not apply where the provider exercises discretion over, or is substantively involved in, the transactions. The financial promotions regime does not copy the exclusion.

Can overseas crypto firms rely on the overseas persons exclusion?

No. PERG 18.3.6 confirms that the Cryptoasset Regulations do not apply the overseas persons exclusion to the new regulated cryptoasset activities. Section 418 of FSMA, as amended, treats some activities involving UK consumers as carried on in the UK even where the provider is overseas. An overseas firm dealing from outside the UK with a UK-authorised dealer that is not acting for consumers is not deemed to be dealing in the UK. The OPE may still apply to certain activities in specified investment cryptoassets, which are securities-type tokens.

When does the FCA crypto authorisation window open and close?

The FCA’s cryptoasset authorisation gateway opens on September 30, 2026 and closes on February 28, 2027 for firms that want to rely on the savings provisions to keep operating while their applications are decided. The regime starts on October 25, 2027. MLR registrations and existing FSMA or payments permissions do not convert automatically. The FCA offers pre-application meetings through its pre-application support service (PASS), and dual-regulated firms should also engage with the Prudential Regulation Authority.

This article is informational analysis only and does not constitute legal, regulatory, tax, or investment advice. Regulatory frameworks change frequently and interpretation depends on facts and circumstances; primary documents and official regulator guidance always supersede summaries. Firms should consult qualified legal counsel and their relevant supervisory authority before taking any action based on the analysis above.

Rick Steves has seen business and economics through many lenses. He joined the financial services industry in 2009, and has been a financial journalist since 2011. He holds a degree in Business Administration and has experience producing real-time news, from both buy-side and sell-side, as well as for retail traders, brokers and service providers. Steves' work has appeared in a variety of online publications including FX Street, NewsBTC, FinanceFeeds, and The Industry Spread. Rick has great interest in the dynamics of the trading industry. The never-ending clash between technology, economics, regulation, and more importantly, the people.

Most Read

Related Posts

Imdustry insights

Stay Ahead

Get the latest news, insights, and market updates delivered to your inbox every day.

Enter your email address