Crypto Card KYC Rules 2026: The July 2027 EU Deadline
- The date is 10 July 2027, not 1 July. Article 90 of Regulation (EU) 2024/1624 sets one application date for everything in this article. The only sector that got a later one is football, at 10 July 2029 — which tells you how few exceptions there are.
- Article 79(2) is the clause that reaches an offshore card. EU acquirers “shall not accept payments carried out with anonymous prepaid cards issued in third countries”. The refusal happens at the merchant's bank, so where the card was issued stops mattering.
- The €150 exemption survives, and no crypto card can use it. Article 19(7) needs all four conditions: not reloadable, closed-loop, not linked to a payment account, and not exchangeable for cash or for crypto-assets. A reloadable Visa funded from a wallet fails three of the four outright.
- There is no grandfathering. Existing anonymous accounts “shall be subject to customer due diligence measures before those accounts… are used in any way”. Signing up early buys you the account, not the anonymity.
- €1,000 is not a KYC-free allowance. Article 19(3) makes crypto-asset service providers identify and verify you below €1,000 too. The threshold marks where partial checks become full ones, not where checks begin.
On this page
- The date almost every article gets wrong
- What Article 79 actually prohibits
- The clause that reaches an offshore card
- The €150 exemption no crypto card can use
- What changes from the rules running today
- There is no grandfathering
- €1,000 is not an allowance
- Three rulebooks: EU, UK and US
- What actually survives July 2027
- The playbook, and the final take
- FAQ
Every guide to this market, ours included, has spent two years saying the same vague thing: the window for document-free cards is narrowing. That is not a rule, it is a mood. The crypto card KYC rules that decide whether your card still works have a statute, an article number and a calendar date attached, and almost nothing written for cardholders quotes any of them. So we read the Official Journal text of the EU's Anti-Money Laundering Regulation, the UK's Money Laundering Regulations 2017 as amended in June 2026, and the relevant parts of 31 CFR. The surprise is not the ban. It is the exemption that survives — and the four conditions that make it unusable by any card you would want.
The Date Almost Every Article Gets Wrong
Search for this and you will be told the EU bans anonymous crypto accounts on 1 July 2027. Several pages ranking for the question print that date, including a news headline, a summary site built specifically to index the Regulation article by article, and one of the better commercial card guides in this niche. It is wrong.
Article 90 of Regulation (EU) 2024/1624 — the Anti-Money Laundering Regulation, or AMLR — says it “shall apply from 10 July 2027”. It was signed on 31 May 2024 and published in the Official Journal on 19 June 2024. There is exactly one carve-out from that date, and it is not for payments: Article 90 delays application to 10 July 2029 for the obliged entities at Article 3, points (3)(n) and (o) — football agents and professional football clubs.
What Article 79 Actually Prohibits
Article 79 is headed “Anonymous accounts and bearer shares and bearer share warrants”, which is why card coverage has skipped it. Its first paragraph is the one that ends the category:
“Credit institutions, financial institutions and crypto-asset service providers shall be prohibited from keeping anonymous bank and payment accounts, anonymous passbooks, anonymous safe-deposit boxes or anonymous crypto-asset accounts as well as any account otherwise allowing for the anonymisation of the customer account holder or the anonymisation or increased obfuscation of transactions, including through anonymity-enhancing coins.”
Read the middle of that sentence slowly, because it is doing more work than the headline. The prohibition is not limited to accounts labelled anonymous. It catches any account otherwise allowing for the anonymisation of the customer account holder. A card programme issued under a corporate entity so that no individual is identified — the structure most of this market runs on, and one we have described before — is an account allowing for the anonymisation of the holder. It does not need a separate clause.
| What Article 79 does | Provision | Who it binds |
|---|---|---|
| Bans anonymous crypto-asset accounts outright | Art 79(1) | Credit & financial institutions, CASPs |
| Bans any account allowing anonymisation of the holder | Art 79(1) | Same |
| Bans accounts obfuscating transactions, incl. anonymity-enhancing coins | Art 79(1) | Same |
| Forces CDD on existing anonymous accounts before any further use | Art 79(1) | Same |
| Stops EU acquirers accepting third-country anonymous prepaid cards | Art 79(2) | EU acquirers |
| Nothing about individuals holding or spending | — | Not you |
That last row matters and gets lost in the coverage. The AMLR is a set of duties on obliged entities. It does not criminalise holding a card, and “anonymity-enhancing coins” has a definition at Article 3, point (25) — crypto-assets with built-in features designed to make transfer information anonymous, systematically or optionally — which binds what a firm may custody, not what you may own. The effect on you is second-hand: firms stop offering the product. Which is exactly how this market has always been squeezed, only now with a date.
The Clause That Reaches an Offshore Card
Here is the provision no card guide we found has quoted, and the reason “just use a card issued outside the EU” stops being an answer. Article 79(2):
“Credit institutions and financial institutions acting as acquirers… shall not accept payments carried out with anonymous prepaid cards issued in third countries, unless otherwise provided for in the regulatory technical standards adopted by the Commission in accordance with Article 28 of this Regulation on the basis of a proven low risk.”
An acquirer is the merchant's payment service provider — the bank on the other end of the transaction, the one that contracts with the shop to accept card payments. The AMLR points the duty at that end of the rails. Your issuer can sit in any jurisdiction it likes; the refusal happens where you are spending.
This is a change in kind. Today's rule, which we come back to below, asks the acquirer to check that a third-country anonymous card meets equivalent standards. From 10 July 2027 the default flips to a flat prohibition, and the only way back in is a Commission technical standard adopted on proven low risk. Article 28(1) required the new EU anti-money-laundering authority to submit draft standards by 10 July 2026, and Article 28(1)(c) covers the risk factors in the features of electronic money instruments. Until those are adopted, the statute is what you plan against, and the statute says no. If you have ever had a payment die at the terminal for reasons nobody could explain, this is the next version of that problem.
The €150 Exemption No Crypto Card Can Use
The surprise in the AMLR is not that anonymity is banned. It is that a low-value exemption survives, and that it is drafted so tightly no crypto card can stand inside it. Article 19(7) lets a supervisor exempt a firm, in full or in part, from identifying and verifying a customer for electronic money — but only “where all of the following risk-mitigating conditions are met”. All four. Here they are against the card in your pocket.
| Article 19(7) condition | A typical crypto card | Result |
|---|---|---|
| (a) Not reloadable, stored value ≤ €150 | Reloadable by design; that is the product | Fails |
| (b) Used only for goods/services of the issuer or within a network of providers | Open-loop Visa or Mastercard, accepted everywhere | Fails |
| (c) Not linked to a payment account; no exchange for cash or crypto-assets | Linked to an account, funded in crypto, ATM withdrawal standard | Fails |
| (d) Issuer monitors for unusual or suspicious transactions | Every licensed programme already does this | Passes |
Condition (c) is the one drafted with this market in view. It is not enough that the card cannot be cashed out; it must not permit the stored amount “to be exchanged for cash or for crypto-assets”. A card whose entire proposition is moving value between a wallet and a merchant terminal cannot satisfy a condition written to exclude exactly that. Condition (b) narrows the current wording — which says only that the instrument is used to purchase goods or services — to the issuer or a defined network: a shop gift card, a transport pass, a campus card.
So the €150 tier is not the survival route for anonymous crypto cards. It is a gift-card rule, and it always quietly was. Our reading is that by 10 July 2027 there is no configuration of an open-loop, reloadable, crypto-funded card a supervisor could exempt under Article 19(7) without rewriting it.
What Changes From the Rules Running Today
The current EU position lives in Article 12 of Directive (EU) 2015/849, as amended in 2018 — the rule that produced the €150 anonymous prepaid cards you can still buy in a European supermarket. Put the two side by side and the tightening is specific rather than rhetorical.
| Condition | Now — Directive 2015/849, Art 12 | From 10 Jul 2027 — AMLR Art 19(7) |
|---|---|---|
| Reloadable? | Allowed, if capped at €150 of monthly transactions and usable in one Member State | Not reloadable. No alternative limb |
| Stored value | ≤ €150 | ≤ €150 (unchanged) |
| Where it can be spent | “Exclusively to purchase goods or services” | Issuer or a defined network of providers only |
| Cash out | Exemption unavailable above €50 redeemed | No exchange for cash or crypto-assets, at any value |
| Online payments | Exemption unavailable above €50 per remote transaction | Moot — closed-loop and non-reloadable already |
| Linked to a payment account? | Not addressed | Expressly prohibited |
| Third-country anonymous cards | Accepted if equivalent; a state may refuse them entirely | Acquirers shall not accept, absent Commission standards |
| Who decides | Member State may allow the derogation | Supervisor may exempt, in full or in part |
Four separate doors close in one article: reloadability, open-loop acceptance, crypto convertibility, and the account link. Any one of them alone would be survivable by redesigning the product. Together they describe something that is not a crypto card.
There Is No Grandfathering
The most common piece of advice in this niche — and we have given a version of it ourselves — is to open an account now, while verification is light, on the theory that existing users get grandfathered at their original tier. That theory does not survive contact with the second sentence of Article 79(1):
“Owners and beneficiaries of existing anonymous bank or payment accounts, anonymous passbooks, anonymous safe-deposit boxes held by credit institutions or financial institutions, or crypto-asset accounts shall be subject to customer due diligence measures before those accounts, passbooks, or deposit boxes are used in any way.”
Before those accounts are used in any way. Not at renewal, not at the next material change, not when a threshold is crossed. The drafters anticipated the manoeuvre and wrote the door shut. If a regulated EU firm holds your anonymous balance on 10 July 2027, its lawful options are to verify you or to stop letting you touch it — the same operational event as a freeze, so read our piece on what protects a card balance when a programme stops before leaving money sitting on one.
Opening early is still worth doing, but for an honest reason rather than a legal one: an established account with a spending history is far easier to verify than a cold application filed in a compliance rush. That is an operational advantage, not a right.
€1,000 Is Not an Allowance
The second thing the coverage has backwards is the threshold. You will read that the EU will require identity verification “for transactions over €1,000”, which sounds like a tidy allowance below it. Article 19(3) says the reverse.
| Situation | What is required | Provision |
|---|---|---|
| Establishing a business relationship | Full customer due diligence | Art 19(1)(a) |
| CASP occasional transaction ≥ €1,000 | Full customer due diligence | Art 19(3)(a) |
| CASP occasional transaction below €1,000 | At least identify the customer and verify their identity | Art 19(3)(b) |
| Non-CASP transfer of funds ≥ €1,000 | Full customer due diligence | Art 19(2) |
| Any occasional transaction ≥ €10,000 | Full customer due diligence | Art 19(1)(b) |
| Any suspicion of money laundering | Full CDD, regardless of any threshold | Art 19(1)(d) |
Row three is the one that ends the small-transaction model. For a crypto-asset service provider there is no floor at all: below €1,000 the firm must still apply the Article 20(1)(a) measure, which is “identifying the customer and verifying the customer's identity”. The threshold decides how much due diligence, never whether any happens. That is already the direction of travel elsewhere: the Transfer of Funds Regulation (EU) 2023/1113, in force since 30 December 2024, records that transfers of crypto-assets are subject to the same requirements “regardless of their amount”, precisely because amount-based thresholds do not work on a volatile asset.
Three Rulebooks: EU, UK and US
Anonymity has never been one global setting, and from 2027 the three big rulebooks diverge more, not less. We read each one rather than trusting a summary, because two of the three moved in 2026.
| EU from 10 Jul 2027 | UK today | US today | |
|---|---|---|---|
| Instrument | Reg (EU) 2024/1624 | MLRs 2017, reg 38 | 31 CFR 1022.210, 1010.100 |
| Anonymous ceiling | €150, non-reloadable only | £150 stored, or £150/month UK-only | $1,000/day, or $2,000 closed-loop |
| Cash / online cap | No cash or crypto exchange at all | £50 redeemed; £50 per remote payment | No international transmission permitted |
| Offshore anonymous card | Acquirers shall not accept | Accepted if equivalent (reg 38(4A)) | Programme-level ID duty on the provider |
| Last moved | Applies 10 Jul 2027 | Sums restated in £ on 30 Jun 2026 | 2011 prepaid access rule |
Two details are worth more than the rest of that table. First, the UK quietly changed its numbers on 30 June 2026: S.I. 2026/621 substituted £150 and £50 into regulation 38 where the euro sums used to sit, so any UK guide still quoting €150 is out of date. Second, the UK kept the equivalence test at reg 38(4A) that the EU is about to abandon. From 10 July 2027 a third-country anonymous prepaid card can be acceptable to a British acquirer and refused by a French one on the same afternoon. If you hold an EU card, our MiCA guide covers the licensing half of the same story.
The US arrives at a similar place by a different road. Under 31 CFR 1022.210(d)(1)(iv) a provider of prepaid access must verify the identity of anyone obtaining prepaid access under a prepaid program, collecting name, date of birth, address and an identification number. The escape is the definition at 1010.100(ff)(4): it is not a prepaid program if it is closed-loop under $2,000 a day, or capped at $1,000 a day and permits no international transmission, no transfers between users, and no loading from non-depository sources. A crypto card loaded from a wallet and spent abroad fails three of those. Different statute, same answer.
What Actually Survives July 2027
None of this means privacy disappears from card spending. It means the anonymity moves out of the account and into the architecture, and the surviving designs are the ones where no regulated firm holds your balance at all. The Regulation says so itself, at recital 160: the prohibition “does not apply to providers of hardware and software or providers of self-hosted wallets insofar as they do not possess access to or control over those crypto-asset wallets”. Custody is the hinge. A firm that cannot touch your keys is not keeping an anonymous account, because it is not keeping an account.
| Card architecture | Exposure to Art 79 | What changes for you |
|---|---|---|
| EU-licensed custodial card, light KYC | Direct | Verify or lose access to the balance |
| Third-country custodial card, no KYC | Via Art 79(2) at EU merchants | Declines at EU points of sale |
| Self-custodial card, non-EU issuer | Partial | Wallet untouched; the card programme is not |
| Self-hosted wallet, no card | Outside the prohibition | Art 40 checks when you touch a CASP |
| Closed-loop €150 gift instrument | Exempt under Art 19(7) | Not a card you can spend anywhere |
Row three is the honest one. A self-custodial card keeps your keys off a regulated balance sheet, a real structural difference and the reason that segment is growing. But something still issues the Visa, and that something is a financial institution with an Article 79 duty. Article 40 adds a second layer: providers must assess the risk of transfers to and from a self-hosted address and apply mitigating measures, which may include verifying the person behind that address. Self-custody removes the custodian. It does not remove the issuer, or the on-ramp.
The Playbook, and the Final Take
Nothing here requires panic, and the worst outcome is a balance you cannot reach because you waited. Six things are worth doing in the twenty-one months you have.
| # | Do this | Because |
|---|---|---|
| 1 | Find out who issues your card, and where | An EU-licensed issuer is directly bound; a third-country one is reached at the till |
| 2 | Stop treating a card as storage | Art 79(1) blocks use of the balance before verification, with no notice period written in |
| 3 | Verify early if you intend to verify at all | A seasoned account clears review more easily than a rushed one in mid-2027 |
| 4 | Keep a second card on a different rulebook | UK reg 38(4A) equivalence and EU Art 79(2) prohibition will not fail together |
| 5 | Prefer self-custody for holding, cards for spending | Recital 160 leaves self-hosted wallets outside the prohibition |
| 6 | Diarise 10 July 2027, not 1 July | Art 90 — and most of the internet has the wrong date |
The final take is narrower than the headlines and more useful. The EU is not banning you from spending crypto, and it is not banning self-custody. It is removing the legal basis on which a regulated firm may hold value for a person it has not identified, then closing the side door by telling merchants' banks to refuse the offshore version. What is left after 10 July 2027 is a market split in two: verified cards that work everywhere, and non-custodial architectures where the privacy lives in the wallet rather than in a gap in someone's onboarding. The vague middle — a custodial balance with no name on it — is the part with the expiry date.
Know which rulebook your card answers to
Kardd tracks KYC level, custody model, issuing jurisdiction and the full fee stack across the crypto card market — the four things that decide what happens to your card in July 2027.
Kardd may earn a commission on sign-ups. Affiliate disclosure.
Related Articles
- Anonymous Crypto Card 2026: What's Actually Possible
- Crypto Card Europe Under MiCA 2026: 8 Cards That Survived
- Web3 Card 2026: What It Really Means
- Why No-KYC Crypto Cards Keep Getting Shut Down
- Are No-KYC Crypto Cards Safe? Risks You Need to Know
- Crypto Card Balance Protection 2026: The Insolvency Rules
Frequently Asked Questions
Are no-KYC crypto cards being banned in the EU?
The anonymous account behind them is. Article 79(1) prohibits credit institutions, financial institutions and crypto-asset service providers from keeping anonymous crypto-asset accounts, or any account otherwise allowing anonymisation of the holder. It binds the firm, not you — nothing makes holding a card unlawful. But a regulated EU issuer cannot offer one anonymously from the application date, and Article 79(2) tells EU acquirers to refuse the third-country version.
When exactly do the new EU crypto KYC rules start?
10 July 2027, not 1 July. Article 90 sets that single date, with one exception pushed to 10 July 2029 for football agents and professional football clubs. A great deal of coverage prints 1 July 2027, and nine days matter if you are counting a runway. The Regulation was signed on 31 May 2024 and published in the Official Journal on 19 June 2024.
Is there still a €150 anonymous card exemption after 2027?
There is an exemption, but no crypto card can meet it. Article 19(7) requires all four conditions at once: not reloadable and no more than €150 stored, used only within the issuer's own network, not linked to a payment account and not exchangeable for cash or for crypto-assets, plus issuer monitoring. A reloadable open-loop card funded from a wallet fails the first three.
Will my existing no-KYC card be grandfathered?
No. The second sentence of Article 79(1) says owners and beneficiaries of existing anonymous accounts shall be subject to customer due diligence before those accounts are used in any way. Opening early buys you the account, not the anonymity. The advice to sign up now and get grandfathered at your original tier has no basis in the Regulation — though a seasoned account is genuinely easier to verify later.
Does the EU rule apply to a card issued outside the EU?
Indirectly, through the merchant's bank rather than yours. Article 79(2) says EU credit and financial institutions acting as acquirers shall not accept payments carried out with anonymous prepaid cards issued in third countries, unless Commission technical standards permit it on proven low risk. Because an acquirer sits on the merchant side, the refusal happens where you spend, whatever the issuing jurisdiction.
Is €1,000 a KYC-free allowance for crypto?
It is the opposite. Article 19(3) makes a crypto-asset service provider run full due diligence at or above €1,000 and apply at least the Article 20(1)(a) measure — identifying the customer and verifying their identity — below it. There is no floor. The threshold marks where partial checks become full ones, not where checks begin.
Do self-custodial crypto cards escape the ban?
The wallet does; the card programme around it usually does not. Recital 160 records that the prohibition does not reach providers of hardware, software or self-hosted wallets that hold no access to or control over the wallet. But the entity issuing the Visa is a regulated financial institution with its own duty, and Article 40 requires providers to apply mitigating measures to transfers involving self-hosted addresses. Self-custody removes the custodian, not the issuer.
Sources
Every provision above was read from the official text in September 2026, not from secondary coverage. Regulation (EU) 2024/1624 supplies Articles 3(25), 19, 20, 28, 40, 79 and 90 and recital 160; Regulation (EU) 2023/1113 supplies the 30 December 2024 date and the “regardless of their amount” wording; the superseded position is Article 12 of Directive (EU) 2015/849 as amended. UK text from regulation 38 of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, including the sums substituted on 30 June 2026 by S.I. 2026/621. US text from 31 CFR § 1022.210 and the “prepaid program” definition at 31 CFR § 1010.100. Package dates cross-checked against the European Commission's AML/CFT page. Where this article reads a condition against a product — the Article 19(7) table, the architecture table — that is our analysis of the text, not a regulator's finding, and the technical standards under Article 28 may yet change what the exemption covers. This is general information, not legal advice.