Blog/Guides

Crypto Card KYC Rules 2026: The July 2027 EU Deadline

Kardd Team|September 23, 2026|12 min read
KEY TAKEAWAYSREAD FROM THE STATUTESEPTEMBER 2026
  • The date is 10 July 2027, not 1 July. Article 90 of Regulation (EU) 2024/1624 sets one application date for everything in this article. The only sector that got a later one is football, at 10 July 2029 — which tells you how few exceptions there are.
  • Article 79(2) is the clause that reaches an offshore card. EU acquirers “shall not accept payments carried out with anonymous prepaid cards issued in third countries”. The refusal happens at the merchant's bank, so where the card was issued stops mattering.
  • The €150 exemption survives, and no crypto card can use it. Article 19(7) needs all four conditions: not reloadable, closed-loop, not linked to a payment account, and not exchangeable for cash or for crypto-assets. A reloadable Visa funded from a wallet fails three of the four outright.
  • There is no grandfathering. Existing anonymous accounts “shall be subject to customer due diligence measures before those accounts… are used in any way”. Signing up early buys you the account, not the anonymity.
  • €1,000 is not a KYC-free allowance. Article 19(3) makes crypto-asset service providers identify and verify you below €1,000 too. The threshold marks where partial checks become full ones, not where checks begin.
Affiliate Disclosure: Kardd.co may earn a commission if you sign up for a card mentioned here. Every rule below is quoted from the statute itself — the Official Journal text, the UK statutory instrument, the US Code of Federal Regulations — read in September 2026. Full disclosure.

Every guide to this market, ours included, has spent two years saying the same vague thing: the window for document-free cards is narrowing. That is not a rule, it is a mood. The crypto card KYC rules that decide whether your card still works have a statute, an article number and a calendar date attached, and almost nothing written for cardholders quotes any of them. So we read the Official Journal text of the EU's Anti-Money Laundering Regulation, the UK's Money Laundering Regulations 2017 as amended in June 2026, and the relevant parts of 31 CFR. The surprise is not the ban. It is the exemption that survives — and the four conditions that make it unusable by any card you would want.

The Date Almost Every Article Gets Wrong

Search for this and you will be told the EU bans anonymous crypto accounts on 1 July 2027. Several pages ranking for the question print that date, including a news headline, a summary site built specifically to index the Regulation article by article, and one of the better commercial card guides in this niche. It is wrong.

Article 90 of Regulation (EU) 2024/1624 — the Anti-Money Laundering Regulation, or AMLR — says it “shall apply from 10 July 2027”. It was signed on 31 May 2024 and published in the Official Journal on 19 June 2024. There is exactly one carve-out from that date, and it is not for payments: Article 90 delays application to 10 July 2029 for the obliged entities at Article 3, points (3)(n) and (o) — football agents and professional football clubs.

Why nine days matter. If you are running down a card balance, closing a position, or deciding whether to verify an account before it locks, you are counting backwards from a deadline. Football got a two-year extension. Cards got nothing. Plan against 10 July 2027.

What Article 79 Actually Prohibits

Article 79 is headed “Anonymous accounts and bearer shares and bearer share warrants”, which is why card coverage has skipped it. Its first paragraph is the one that ends the category:

“Credit institutions, financial institutions and crypto-asset service providers shall be prohibited from keeping anonymous bank and payment accounts, anonymous passbooks, anonymous safe-deposit boxes or anonymous crypto-asset accounts as well as any account otherwise allowing for the anonymisation of the customer account holder or the anonymisation or increased obfuscation of transactions, including through anonymity-enhancing coins.”

Read the middle of that sentence slowly, because it is doing more work than the headline. The prohibition is not limited to accounts labelled anonymous. It catches any account otherwise allowing for the anonymisation of the customer account holder. A card programme issued under a corporate entity so that no individual is identified — the structure most of this market runs on, and one we have described before — is an account allowing for the anonymisation of the holder. It does not need a separate clause.

What Article 79 doesProvisionWho it binds
Bans anonymous crypto-asset accounts outrightArt 79(1)Credit & financial institutions, CASPs
Bans any account allowing anonymisation of the holderArt 79(1)Same
Bans accounts obfuscating transactions, incl. anonymity-enhancing coinsArt 79(1)Same
Forces CDD on existing anonymous accounts before any further useArt 79(1)Same
Stops EU acquirers accepting third-country anonymous prepaid cardsArt 79(2)EU acquirers
Nothing about individuals holding or spendingNot you

That last row matters and gets lost in the coverage. The AMLR is a set of duties on obliged entities. It does not criminalise holding a card, and “anonymity-enhancing coins” has a definition at Article 3, point (25) — crypto-assets with built-in features designed to make transfer information anonymous, systematically or optionally — which binds what a firm may custody, not what you may own. The effect on you is second-hand: firms stop offering the product. Which is exactly how this market has always been squeezed, only now with a date.

The Clause That Reaches an Offshore Card

Here is the provision no card guide we found has quoted, and the reason “just use a card issued outside the EU” stops being an answer. Article 79(2):

“Credit institutions and financial institutions acting as acquirers… shall not accept payments carried out with anonymous prepaid cards issued in third countries, unless otherwise provided for in the regulatory technical standards adopted by the Commission in accordance with Article 28 of this Regulation on the basis of a proven low risk.”

An acquirer is the merchant's payment service provider — the bank on the other end of the transaction, the one that contracts with the shop to accept card payments. The AMLR points the duty at that end of the rails. Your issuer can sit in any jurisdiction it likes; the refusal happens where you are spending.

This is a change in kind. Today's rule, which we come back to below, asks the acquirer to check that a third-country anonymous card meets equivalent standards. From 10 July 2027 the default flips to a flat prohibition, and the only way back in is a Commission technical standard adopted on proven low risk. Article 28(1) required the new EU anti-money-laundering authority to submit draft standards by 10 July 2026, and Article 28(1)(c) covers the risk factors in the features of electronic money instruments. Until those are adopted, the statute is what you plan against, and the statute says no. If you have ever had a payment die at the terminal for reasons nobody could explain, this is the next version of that problem.

The €150 Exemption No Crypto Card Can Use

The surprise in the AMLR is not that anonymity is banned. It is that a low-value exemption survives, and that it is drafted so tightly no crypto card can stand inside it. Article 19(7) lets a supervisor exempt a firm, in full or in part, from identifying and verifying a customer for electronic money — but only “where all of the following risk-mitigating conditions are met”. All four. Here they are against the card in your pocket.

Article 19(7) conditionA typical crypto cardResult
(a) Not reloadable, stored value ≤ €150Reloadable by design; that is the productFails
(b) Used only for goods/services of the issuer or within a network of providersOpen-loop Visa or Mastercard, accepted everywhereFails
(c) Not linked to a payment account; no exchange for cash or crypto-assetsLinked to an account, funded in crypto, ATM withdrawal standardFails
(d) Issuer monitors for unusual or suspicious transactionsEvery licensed programme already does thisPasses

Condition (c) is the one drafted with this market in view. It is not enough that the card cannot be cashed out; it must not permit the stored amount “to be exchanged for cash or for crypto-assets”. A card whose entire proposition is moving value between a wallet and a merchant terminal cannot satisfy a condition written to exclude exactly that. Condition (b) narrows the current wording — which says only that the instrument is used to purchase goods or services — to the issuer or a defined network: a shop gift card, a transport pass, a campus card.

So the €150 tier is not the survival route for anonymous crypto cards. It is a gift-card rule, and it always quietly was. Our reading is that by 10 July 2027 there is no configuration of an open-loop, reloadable, crypto-funded card a supervisor could exempt under Article 19(7) without rewriting it.

What Changes From the Rules Running Today

The current EU position lives in Article 12 of Directive (EU) 2015/849, as amended in 2018 — the rule that produced the €150 anonymous prepaid cards you can still buy in a European supermarket. Put the two side by side and the tightening is specific rather than rhetorical.

ConditionNow — Directive 2015/849, Art 12From 10 Jul 2027 — AMLR Art 19(7)
Reloadable?Allowed, if capped at €150 of monthly transactions and usable in one Member StateNot reloadable. No alternative limb
Stored value≤ €150≤ €150 (unchanged)
Where it can be spent“Exclusively to purchase goods or services”Issuer or a defined network of providers only
Cash outExemption unavailable above €50 redeemedNo exchange for cash or crypto-assets, at any value
Online paymentsExemption unavailable above €50 per remote transactionMoot — closed-loop and non-reloadable already
Linked to a payment account?Not addressedExpressly prohibited
Third-country anonymous cardsAccepted if equivalent; a state may refuse them entirelyAcquirers shall not accept, absent Commission standards
Who decidesMember State may allow the derogationSupervisor may exempt, in full or in part

Four separate doors close in one article: reloadability, open-loop acceptance, crypto convertibility, and the account link. Any one of them alone would be survivable by redesigning the product. Together they describe something that is not a crypto card.

There Is No Grandfathering

The most common piece of advice in this niche — and we have given a version of it ourselves — is to open an account now, while verification is light, on the theory that existing users get grandfathered at their original tier. That theory does not survive contact with the second sentence of Article 79(1):

“Owners and beneficiaries of existing anonymous bank or payment accounts, anonymous passbooks, anonymous safe-deposit boxes held by credit institutions or financial institutions, or crypto-asset accounts shall be subject to customer due diligence measures before those accounts, passbooks, or deposit boxes are used in any way.”

Before those accounts are used in any way. Not at renewal, not at the next material change, not when a threshold is crossed. The drafters anticipated the manoeuvre and wrote the door shut. If a regulated EU firm holds your anonymous balance on 10 July 2027, its lawful options are to verify you or to stop letting you touch it — the same operational event as a freeze, so read our piece on what protects a card balance when a programme stops before leaving money sitting on one.

Opening early is still worth doing, but for an honest reason rather than a legal one: an established account with a spending history is far easier to verify than a cold application filed in a compliance rush. That is an operational advantage, not a right.

€1,000 Is Not an Allowance

The second thing the coverage has backwards is the threshold. You will read that the EU will require identity verification “for transactions over €1,000”, which sounds like a tidy allowance below it. Article 19(3) says the reverse.

SituationWhat is requiredProvision
Establishing a business relationshipFull customer due diligenceArt 19(1)(a)
CASP occasional transaction ≥ €1,000Full customer due diligenceArt 19(3)(a)
CASP occasional transaction below €1,000At least identify the customer and verify their identityArt 19(3)(b)
Non-CASP transfer of funds ≥ €1,000Full customer due diligenceArt 19(2)
Any occasional transaction ≥ €10,000Full customer due diligenceArt 19(1)(b)
Any suspicion of money launderingFull CDD, regardless of any thresholdArt 19(1)(d)

Row three is the one that ends the small-transaction model. For a crypto-asset service provider there is no floor at all: below €1,000 the firm must still apply the Article 20(1)(a) measure, which is “identifying the customer and verifying the customer's identity”. The threshold decides how much due diligence, never whether any happens. That is already the direction of travel elsewhere: the Transfer of Funds Regulation (EU) 2023/1113, in force since 30 December 2024, records that transfers of crypto-assets are subject to the same requirements “regardless of their amount”, precisely because amount-based thresholds do not work on a volatile asset.

Three Rulebooks: EU, UK and US

Anonymity has never been one global setting, and from 2027 the three big rulebooks diverge more, not less. We read each one rather than trusting a summary, because two of the three moved in 2026.

EU from 10 Jul 2027UK todayUS today
InstrumentReg (EU) 2024/1624MLRs 2017, reg 3831 CFR 1022.210, 1010.100
Anonymous ceiling€150, non-reloadable only£150 stored, or £150/month UK-only$1,000/day, or $2,000 closed-loop
Cash / online capNo cash or crypto exchange at all£50 redeemed; £50 per remote paymentNo international transmission permitted
Offshore anonymous cardAcquirers shall not acceptAccepted if equivalent (reg 38(4A))Programme-level ID duty on the provider
Last movedApplies 10 Jul 2027Sums restated in £ on 30 Jun 20262011 prepaid access rule

Two details are worth more than the rest of that table. First, the UK quietly changed its numbers on 30 June 2026: S.I. 2026/621 substituted £150 and £50 into regulation 38 where the euro sums used to sit, so any UK guide still quoting €150 is out of date. Second, the UK kept the equivalence test at reg 38(4A) that the EU is about to abandon. From 10 July 2027 a third-country anonymous prepaid card can be acceptable to a British acquirer and refused by a French one on the same afternoon. If you hold an EU card, our MiCA guide covers the licensing half of the same story.

The US arrives at a similar place by a different road. Under 31 CFR 1022.210(d)(1)(iv) a provider of prepaid access must verify the identity of anyone obtaining prepaid access under a prepaid program, collecting name, date of birth, address and an identification number. The escape is the definition at 1010.100(ff)(4): it is not a prepaid program if it is closed-loop under $2,000 a day, or capped at $1,000 a day and permits no international transmission, no transfers between users, and no loading from non-depository sources. A crypto card loaded from a wallet and spent abroad fails three of those. Different statute, same answer.

What Actually Survives July 2027

None of this means privacy disappears from card spending. It means the anonymity moves out of the account and into the architecture, and the surviving designs are the ones where no regulated firm holds your balance at all. The Regulation says so itself, at recital 160: the prohibition “does not apply to providers of hardware and software or providers of self-hosted wallets insofar as they do not possess access to or control over those crypto-asset wallets”. Custody is the hinge. A firm that cannot touch your keys is not keeping an anonymous account, because it is not keeping an account.

Card architectureExposure to Art 79What changes for you
EU-licensed custodial card, light KYCDirectVerify or lose access to the balance
Third-country custodial card, no KYCVia Art 79(2) at EU merchantsDeclines at EU points of sale
Self-custodial card, non-EU issuerPartialWallet untouched; the card programme is not
Self-hosted wallet, no cardOutside the prohibitionArt 40 checks when you touch a CASP
Closed-loop €150 gift instrumentExempt under Art 19(7)Not a card you can spend anywhere

Row three is the honest one. A self-custodial card keeps your keys off a regulated balance sheet, a real structural difference and the reason that segment is growing. But something still issues the Visa, and that something is a financial institution with an Article 79 duty. Article 40 adds a second layer: providers must assess the risk of transfers to and from a self-hosted address and apply mitigating measures, which may include verifying the person behind that address. Self-custody removes the custodian. It does not remove the issuer, or the on-ramp.

The Playbook, and the Final Take

Nothing here requires panic, and the worst outcome is a balance you cannot reach because you waited. Six things are worth doing in the twenty-one months you have.

#Do thisBecause
1Find out who issues your card, and whereAn EU-licensed issuer is directly bound; a third-country one is reached at the till
2Stop treating a card as storageArt 79(1) blocks use of the balance before verification, with no notice period written in
3Verify early if you intend to verify at allA seasoned account clears review more easily than a rushed one in mid-2027
4Keep a second card on a different rulebookUK reg 38(4A) equivalence and EU Art 79(2) prohibition will not fail together
5Prefer self-custody for holding, cards for spendingRecital 160 leaves self-hosted wallets outside the prohibition
6Diarise 10 July 2027, not 1 JulyArt 90 — and most of the internet has the wrong date

The final take is narrower than the headlines and more useful. The EU is not banning you from spending crypto, and it is not banning self-custody. It is removing the legal basis on which a regulated firm may hold value for a person it has not identified, then closing the side door by telling merchants' banks to refuse the offshore version. What is left after 10 July 2027 is a market split in two: verified cards that work everywhere, and non-custodial architectures where the privacy lives in the wallet rather than in a gap in someone's onboarding. The vague middle — a custodial balance with no name on it — is the part with the expiry date.

Know which rulebook your card answers to

Kardd tracks KYC level, custody model, issuing jurisdiction and the full fee stack across the crypto card market — the four things that decide what happens to your card in July 2027.

Kardd may earn a commission on sign-ups. Affiliate disclosure.

Related Articles

Frequently Asked Questions

Are no-KYC crypto cards being banned in the EU?

The anonymous account behind them is. Article 79(1) prohibits credit institutions, financial institutions and crypto-asset service providers from keeping anonymous crypto-asset accounts, or any account otherwise allowing anonymisation of the holder. It binds the firm, not you — nothing makes holding a card unlawful. But a regulated EU issuer cannot offer one anonymously from the application date, and Article 79(2) tells EU acquirers to refuse the third-country version.

When exactly do the new EU crypto KYC rules start?

10 July 2027, not 1 July. Article 90 sets that single date, with one exception pushed to 10 July 2029 for football agents and professional football clubs. A great deal of coverage prints 1 July 2027, and nine days matter if you are counting a runway. The Regulation was signed on 31 May 2024 and published in the Official Journal on 19 June 2024.

Is there still a €150 anonymous card exemption after 2027?

There is an exemption, but no crypto card can meet it. Article 19(7) requires all four conditions at once: not reloadable and no more than €150 stored, used only within the issuer's own network, not linked to a payment account and not exchangeable for cash or for crypto-assets, plus issuer monitoring. A reloadable open-loop card funded from a wallet fails the first three.

Will my existing no-KYC card be grandfathered?

No. The second sentence of Article 79(1) says owners and beneficiaries of existing anonymous accounts shall be subject to customer due diligence before those accounts are used in any way. Opening early buys you the account, not the anonymity. The advice to sign up now and get grandfathered at your original tier has no basis in the Regulation — though a seasoned account is genuinely easier to verify later.

Does the EU rule apply to a card issued outside the EU?

Indirectly, through the merchant's bank rather than yours. Article 79(2) says EU credit and financial institutions acting as acquirers shall not accept payments carried out with anonymous prepaid cards issued in third countries, unless Commission technical standards permit it on proven low risk. Because an acquirer sits on the merchant side, the refusal happens where you spend, whatever the issuing jurisdiction.

Is €1,000 a KYC-free allowance for crypto?

It is the opposite. Article 19(3) makes a crypto-asset service provider run full due diligence at or above €1,000 and apply at least the Article 20(1)(a) measure — identifying the customer and verifying their identity — below it. There is no floor. The threshold marks where partial checks become full ones, not where checks begin.

Do self-custodial crypto cards escape the ban?

The wallet does; the card programme around it usually does not. Recital 160 records that the prohibition does not reach providers of hardware, software or self-hosted wallets that hold no access to or control over the wallet. But the entity issuing the Visa is a regulated financial institution with its own duty, and Article 40 requires providers to apply mitigating measures to transfers involving self-hosted addresses. Self-custody removes the custodian, not the issuer.

Sources

Every provision above was read from the official text in September 2026, not from secondary coverage. Regulation (EU) 2024/1624 supplies Articles 3(25), 19, 20, 28, 40, 79 and 90 and recital 160; Regulation (EU) 2023/1113 supplies the 30 December 2024 date and the “regardless of their amount” wording; the superseded position is Article 12 of Directive (EU) 2015/849 as amended. UK text from regulation 38 of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, including the sums substituted on 30 June 2026 by S.I. 2026/621. US text from 31 CFR § 1022.210 and the “prepaid program” definition at 31 CFR § 1010.100. Package dates cross-checked against the European Commission's AML/CFT page. Where this article reads a condition against a product — the Article 19(7) table, the architecture table — that is our analysis of the text, not a regulator's finding, and the technical standards under Article 28 may yet change what the exemption covers. This is general information, not legal advice.

Related Articles

We may earn commission from affiliate links on this site at no extra cost to you. Read our affiliate disclosure