← All articles

AMLA Is Writing the AML Rulebook That Will Govern Creator Payouts

Oarized · 28 July 2026

What AMLA Is Writing Right Now

The EU's Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) has been operating out of Frankfurt since summer 2025, and through 2026 it has been doing the unglamorous work of turning the bloc's new anti-money laundering regulation into rules a compliance team can actually implement.

Two pieces of that work matter directly to anyone moving money to creators. First, AMLA ran a consultation on draft Regulatory Technical Standards for customer due diligence, which opened 9 February 2026 and closed 8 May 2026. It sets out, in detail, what information and documents an obliged entity has to collect before it can onboard a customer. Second, AMLA is now consulting on draft guidelines for ongoing monitoring of business relationships, launched 3 June 2026, with a public hearing held 2 July 2026 and the comment window open until 3 September 2026.

"Ongoing monitoring" is the less-discussed half of AML compliance next to onboarding checks: it means keeping customer information current and watching transaction patterns over time so unusual activity gets flagged after the relationship starts, not just at signup. AMLA is writing these guidelines under Article 26(5) of the AML Regulation, and they are explicitly meant to apply across both financial and non-financial obliged entities on a risk-based, proportionate basis.

Who Becomes an 'Obliged Entity'

The regulation AMLA is implementing is Regulation (EU) 2024/1624, the AML Regulation (AMLR), which entered into force on 9 July 2024 and formally applies across all 27 member states from 10 July 2027. Its main practical effect for the creator economy is that it widens the list of "obliged entities" — businesses legally required to run customer due diligence, monitor transactions, and file suspicious-activity reports — well beyond banks.

The expanded list includes crypto-asset service providers (CASPs), crowdfunding service providers and intermediaries, traders in high-value goods above set thresholds, and, from 10 July 2029, professional football clubs and agents. For a platform that pays out to creators, the entry that matters is CASP. If a payout platform settles creator earnings in stablecoins, or lets creators withdraw to a crypto wallet, and it — or the processor it routes through — is licensed as a CASP under MiCA, that entity now inherits the full AML obligations under the AMLR. That is a separate, additional layer on top of MiCA's own conduct-of-business rules, not a substitute for them.

This is distinct from the payment-institution and e-money-institution licensing questions that already apply to euro-denominated creator payouts. A platform can be fully PSD2/PSD3-compliant on its bank-rail payouts and still pick up new AML exposure the moment it adds a crypto or stablecoin payout option.

The €1,000 Line for Crypto Payouts

The AMLR lowers the general customer due diligence threshold for occasional transactions from €15,000 under the old directive to €10,000. For most obliged entities, that is the trigger point below which they are not required to run full identity checks on a one-off customer, absent suspicion.

Crypto-asset service providers get a much tighter version of that rule. According to legal analyses of the regulation from firms including Timelex and Freshfields, CASPs must apply customer due diligence on occasional transactions starting at €1,000, roughly a tenth of the general threshold, reflecting the higher money-laundering risk regulators assign to crypto rails.

That number is worth sitting with if a platform's payout model involves crypto. Many EU UGC creators are paid in per-video or per-campaign amounts in the low hundreds of euros; a single active creator can cross a cumulative €1,000 in payouts within a month. A payout platform building on a CASP-licensed rail — its own license or a partner's — needs identity verification to happen much earlier in the creator relationship than a euro bank-rail payout of the same size would require. Waiting until a creator's total payouts look large in hindsight is not compliant with a threshold this low; the due diligence has to be built into onboarding, not bolted on after volume grows.

The 2027 and 2028 Dates That Matter

None of this is retroactive or immediate. The AMLR's core obligations, including the customer due diligence rules discussed above, apply from 10 July 2027. AMLA's own direct supervision — where the authority itself, rather than a national regulator, oversees a shortlist of high-risk, cross-border entities — only begins during 2028. The football club and agent provisions do not apply until 10 July 2029.

So why does a consultation AMLA ran in the summer of 2026 matter to a platform that will not be legally bound by these rules until 2027? Because the technical standards and guidelines being finalized now are the actual rulebook national regulators, and eventually AMLA, will apply once the regulation goes live. The AMLR itself is a framework law; the RTS on customer due diligence and the guidelines on ongoing monitoring are where the operational detail — what documents to collect, how often to re-verify a customer, what counts as a red flag in a transaction pattern — actually gets specified.

Compliance and product teams building payout infrastructure with a 2027 launch or scale-up in mind are, in effect, building against a spec that is still being drafted. The draft guidelines on ongoing monitoring remain open for public comment until 3 September 2026, which means the text can still change based on industry input submitted this quarter.

What It Means for EU Payout and Clipping Platforms

For a platform that pays creators exclusively through a licensed e-money or payment institution partner on euro rails, most of the AMLR's CASP-specific provisions do not apply directly. The platform still has to feed accurate identity and beneficial-ownership data into that partner's due diligence process, since the underlying obligation sits with the licensed entity handling the money movement, but the €1,000 crypto threshold is not the relevant number.

The calculus changes the moment stablecoin or crypto payouts are on the roadmap. That is worth flagging now, not in 2027, for three reasons. First, the €1,000 CDD threshold for CASPs means identity verification has to be designed into onboarding for any creator likely to earn more than a few payouts a month, not added later as a scaling problem. Second, "ongoing monitoring" is a distinct capability from onboarding KYC — a platform needs to keep watching transaction patterns after a creator is verified, which is a different engineering and operations lift. Third, AMLA's draft guidelines are still open for comment through 3 September 2026, so platforms with a stake in how "risk-based and proportionate" gets defined in practice have a real, time-limited window to respond before the text is finalized.

The practical takeaway is not to panic about a 2027 application date. It is to treat AMLA's 2026 consultations as the actual product spec for whatever crypto or stablecoin payout rail gets built in the next 18 months.