CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

ESMA Names AI and Tokenization a Union Supervisory Priority From 2027

CryptaCount Editorial · · 8 min read
AML / KYC / LICENSING ESMA Names AI and Tokenization a UnionSupervisory Priority From 2027

The European Securities and Markets Authority has confirmed that artificial intelligence and tokenization will become a formal supervisory priority across the EU's securities sector starting in 2027. The move signals a decisive shift in how regulators approach digital finance: the rule-writing era of MiCA is giving way to an active, hands-on examination of how firms are actually deploying these technologies in client-facing products. For accounting firms, auditors, and CFOs working with EU-regulated entities, this raises urgent questions about governance documentation, data integrity, and the adequacy of existing crypto accounting software and controls.

What ESMA Has Actually Announced

ESMA's new programme, which it has labelled "Innovation with investor safeguards," will be carried out jointly with national competent authorities across the EU's 27 member states. It has two initial technology focuses: artificial intelligence used in client-facing financial services, and tokenized financial products.

Mapping and firm-level checks

In the first phase, regulators will map where financial firms already use, or are planning to use, AI and tokenization in processes that directly affect customers. This is not a theoretical exercise. ESMA has been explicit that firms are increasingly deploying these tools to compete for market share, and that technological innovation carries both benefits and real risks.

Following the mapping phase, supervisors will begin initial checks on a selected subset of the most affected firms. Those checks will assess three things: governance frameworks around AI and tokenization, the reliability and integrity of the underlying data those systems rely on, and whether client outcomes are genuinely aligned with regulatory expectations.

Scope: beyond back-office operations

A critical detail in ESMA's announcement is that the scrutiny is explicitly directed at core activities rather than purely back-office functions. Firms that have treated AI or tokenization as internal efficiency tools may find that the boundary regulators draw is considerably wider than they assumed. Any customer-facing application, whether a robo-advisory layer, a tokenized fund unit, or an AI-driven order routing system, falls within scope.

Why This Follows Naturally From MiCA

The Markets in Crypto-Assets Regulation established the EU's foundational licensing and disclosure regime for crypto-asset service providers. What MiCA did not do was create a supervisory framework for how tokenization is spreading into the mainstream securities industry, or for how AI is being embedded into investment products and processes that are governed by existing financial services law rather than crypto-specific rules.

ESMA's 2027 priority fills that gap. It effectively extends regulatory attention to financial institutions that may never have sought a MiCA licence but are nevertheless deploying tokenized instruments or AI-driven advisory tools under their existing MIFID II or UCITS authorizations. The implication is that tokenization is no longer a niche crypto concern; it is a mainstream supervisory question for the entire EU securities sector.

For context on how ESMA framed this in its broader digital innovation strategy, see our earlier coverage of ESMA's 2027 Digital Innovation Priority and what it means for firms.

The ECB's Parallel Moves in Tokenization and Stablecoins

ESMA's announcement does not sit in isolation. The European Central Bank has made several significant moves in the tokenization and stablecoin space in close succession.

Tokenized securities and the ECB's wholesale platform

The ECB recently confirmed direct participation in tokenized securities markets, giving the central bank its own exposure to blockchain-based financial infrastructure. That followed the launch of the ECB's new wholesale settlement platform, which bridges distributed ledger technology market infrastructure with the traditional payment system. This platform is separate from the retail digital euro pilot scheduled for 2027.

The stablecoin yield restriction

The ECB and the national central banks of all 27 member states have also pushed to restrict crypto platforms from offering stablecoin yields, rewards, or returns. Their position is that fiat-pegged digital assets constitute money, not savings instruments, and should not be used to replicate deposit-taking functions outside the regulated banking sector. This connects directly to ongoing debates about the MiCA stablecoin liquidity rules, which we examined in our analysis of the ESCB's push to rewrite MiCA stablecoin liquidity requirements.

Taken together, the ECB's wholesale tokenization platform, its participation in tokenized securities, and its position on stablecoin yields paint a picture of a central bank that is both shaping and stress-testing the infrastructure that ESMA will soon be supervising at the firm level.

Accounting and Audit Implications for EU-Regulated Firms

For accounting practices and finance teams advising or working within EU-regulated financial institutions, ESMA's supervisory priority creates concrete near-term obligations.

Governance documentation

Supervisors will examine whether firms have adequate governance frameworks in place for AI and tokenization. In accounting terms, this means internal controls documentation needs to cover the data inputs, model outputs, and decision processes associated with any AI system that influences a financial product or a client communication. Auditors conducting controls reviews under ISA 315 will need to understand and document these systems as part of the entity's information environment.

Data reliability and financial reporting

ESMA's reference to "data reliability" is directly relevant to financial reporting. Tokenized assets raise questions about the completeness and accuracy of records: which ledger is the authoritative source, how are transfers recorded, and at what point does a token transfer constitute a financial event for recognition purposes? Firms relying on digital asset accounting software need to be able to demonstrate that their data pipelines from the blockchain into their general ledger are complete, reconciled, and auditable.

AI systems that influence pricing, valuation, or client suitability assessments introduce a further layer. If an AI model determines the fair value of a tokenized instrument or recommends an allocation, the methodology behind that output needs to be disclosed and, where applicable, subject to independent review.

Client outcome assessment and regulatory reporting

The "client outcomes" element of ESMA's framework will likely feed into MiFID II suitability and best execution reporting. Firms that use AI to generate investment recommendations or to allocate tokenized assets need to be able to demonstrate, through transaction data and outcome records, that the AI's decisions are consistent with client profiles and regulatory requirements. This creates a monitoring and record-keeping obligation that has direct implications for the data architecture of any crypto bookkeeping software or digital asset accounting software in use.

What Firms Should Be Doing Now

The programme begins in 2027, but the mapping phase starts earlier, and firms that are caught underprepared at that stage will face a difficult catch-up exercise during active supervision.

Conduct a technology inventory

Finance teams and compliance officers should catalogue every AI tool and every tokenized product that touches a client-facing process. This includes AI-assisted KYC systems, tokenized fund structures, AI-driven portfolio construction, and any use of smart contracts in settlement or custody. The inventory should note the regulatory authorisation under which each activity sits and whether it is covered by existing MiCA, MiFID II, or UCITS governance frameworks.

Stress-test governance documentation

Existing governance frameworks for technology systems are likely to have been written with conventional software in mind. AI systems that learn and adapt over time, and tokenized instruments whose ownership records exist on a blockchain, require specific additions. Model risk management policies, data governance standards, and escalation procedures need to be reviewed and, where necessary, updated before supervisors ask to see them.

Review data flows into accounting and reporting systems

Every firm using tokenized instruments in its balance sheet or off-balance-sheet structures should trace the data path from the originating ledger to the financial statements. If crypto accounting software is used to ingest on-chain data, the reconciliation logic and exception handling need to be documented and tested. Auditors will need this to complete their IT audit work under current assurance standards.

Engage with national competent authorities early

ESMA's programme is coordinated through national regulators. Firms that are uncertain whether they fall within the initial mapping scope should consider proactive engagement with their national competent authority rather than waiting for a formal request. Early engagement typically results in a more manageable supervisory process and reduces the risk of being selected for intensive firm-level checks at the outset.

Frequently Asked Questions

Which firms are in scope for ESMA's AI and tokenization supervisory priority?

The programme covers firms regulated under EU securities law, including MiFID II investment firms, UCITS managers, and alternative investment fund managers, that use AI or tokenized products in activities directly affecting clients. It is not limited to firms holding a MiCA licence. Any firm deploying these technologies in client-facing processes should assume it falls within the mapping exercise.

When will supervisory checks actually begin?

ESMA has designated AI and tokenization as a supervisory priority from 2027. The mapping phase, which identifies where firms are using these technologies and which are most affected, is expected to precede the firm-level checks. Firms should treat 2026 as the preparation window.

How does this interact with existing MiCA compliance obligations?

MiCA governs the licensing and disclosure requirements for crypto-asset service providers. ESMA's new programme extends supervisory scrutiny to how AI and tokenization are used across the broader securities industry, including by firms that operate under MiFID II or UCITS authorizations rather than MiCA. The two frameworks are complementary rather than mutually exclusive.

What does "data reliability" mean in ESMA's context, and why does it matter for accounting?

Data reliability refers to whether the information feeding into AI systems and tokenized product processes is accurate, complete, and consistent. For accounting purposes, this connects to the completeness and accuracy of financial records: specifically, whether the data flowing from blockchain ledgers into the general ledger is properly reconciled and whether AI-generated valuations or recommendations are based on inputs that can be independently verified.

Will the ECB's stablecoin yield restriction affect firms that currently offer stablecoin rewards to clients?

The ECB and the ESCB's position is that fiat-pegged stablecoins are money, not savings instruments, and that offering yields or rewards on them replicates deposit-taking outside the regulated banking sector. Firms offering such products should take legal advice on whether their current arrangements are compatible with this position and with the evolving MiCA stablecoin framework.

Source: CoinDesk Policy

EUGLOBAL#tokenized_tokens#stablecoinsProposedAML/KYC & Licensing

Related articles

AML/KYC & Licensing
ESMA Names AI and Tokenization a Union Supervisory Priority From 2027
AML/KYC & Licensing
Russian State Actors Using USDT and Telegram to Fund European Sabotage
AML/KYC & Licensing
Blockchain Analytics and Sanctions Compliance: What Crypto Firms Must Do Now
AML/KYC & Licensing
MiCA, Sanctions and DeFi AML: The 2023 Regulatory Outlook for Crypto Accounting