CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

ESMA Names AI and Tokenization a Union Supervisory Priority From 2027

CryptaCount Editorial · · 10 min read
AML / KYC / LICENSING ESMA Names AI and Tokenization a UnionSupervisory Priority From 2027
The European Securities and Markets Authority has formally designated artificial intelligence and tokenization as a Union Strategic Supervisory Priority, with coordinated national supervision scheduled to begin across the EU in 2027. For accounting firms, auditors, and CFOs with EU-regulated clients or group entities, this is not an abstract regulatory signal. It triggers a concrete preparation window covering investor disclosure quality, third-party dependency mapping, and the internal records that crypto accounting software and digital asset accounting teams will need to produce on demand.

ESMA Names AI and Tokenization a Union Supervisory Priority From 2027

What a Union Strategic Supervisory Priority Actually Means

ESMA uses the Union Strategic Supervisory Priority mechanism to coordinate national competent authorities across the bloc on risks that do not respect jurisdictional borders. The authority identifies up to two such priorities every three years, selecting themes that reflect emerging developments and systemic trends affecting investors EU-wide.

How the USSP Framework Operates in Practice

Under a USSP, national regulators do not act independently or inconsistently. ESMA sets the analytical framework, national supervisors map the landscape in their jurisdictions, a subset of firms faces initial supervisory checks, and the findings feed back into common approaches that may eventually crystallise into formal guidance or binding technical standards. The process is iterative by design: the 2027 cycle is explicitly framed as an expertise-building and harmonisation exercise, not an enforcement wave. That said, firms selected for initial checks can expect document requests, interviews, and scrutiny of investor-facing materials from day one.

The Current USSP Landscape

The new AI and tokenization priority will run alongside the existing USSP on cyber and operational resilience, which launched in 2025. ESMA is simultaneously closing its USSP on environmental, social and governance disclosures, meaning the supervisory bandwidth freed up there is now redirected toward digital innovation. Firms that navigated the ESG priority cycle already have a procedural template they can adapt.

The Three Risk Categories ESMA Has Identified

ESMA's announcement names three specific risk areas that supervisors will watch. Understanding these categories helps compliance and finance teams prioritise where internal review effort should go first.

Biased or Misleading AI Outputs

Where firms use AI in investment research, client suitability assessments, order routing, or portfolio construction, supervisors will look at whether outputs could mislead investors or introduce systematic bias. This extends to AI-assisted disclosures and marketing materials. For audit teams, it raises a new category of review: are the AI-generated outputs embedded in client-facing processes subject to adequate human oversight and auditability trails?

Investor Comprehension of Tokenized Products

ESMA has flagged that retail and even sophisticated investors may struggle to understand tokenized products. The supervisory focus here falls squarely on the quality and clarity of product documentation, key investor information documents, and any digital or on-chain disclosure mechanism a firm employs. Accounting firms advising issuers of tokenized securities or funds need to ensure that the financial statements and notes accompanying these products accurately characterise the underlying asset, custody arrangement, and any smart contract mechanic that affects investor rights.

Third-Party Concentration Risk

The reliance of multiple firms on a small number of AI model providers or blockchain infrastructure vendors is an explicit concern. This mirrors the logic of the Digital Operational Resilience Act but extends it into the product and model layer. CFOs and operational risk leads should expect supervisors to request registers of critical technology dependencies, contractual arrangements with providers, and evidence of exit or substitution strategies.

Supervisory Actions Planned for 2027

The announced programme of work has three operational components that firms can map their preparation against.

Mapping and Documentation

National supervisors will first identify where tokenization is emerging in their jurisdictions and record how firms use or plan to use AI and tokenization in investor-facing products and internal processes. This mapping exercise means that firms should expect questionnaires or data requests from their national competent authority, even before any on-site or targeted review. Firms that have already built structured inventories of their AI tools and tokenized product lines will be able to respond quickly and accurately.

Initial Firm-Level Checks

A subset of the most affected firms will undergo initial supervisory checks. ESMA has not published selection criteria, but the phrase "most affected" suggests firms with significant tokenized AUM, those actively deploying AI in client-facing functions, or those identified as systemically relevant in the mapping phase. Audit firms with financial institution clients in these categories should factor this into engagement risk assessments for 2026 and 2027 planning cycles.

Sharing Innovation Examples and Developing Common Approaches

Alongside scrutiny, ESMA plans to document cases where AI has improved investor outcomes, reduced bias, and produced reliable results. This creates a positive incentive: firms that can demonstrate responsible deployment may find their practices cited as reference points in subsequent ESMA guidance. For compliance teams, there is reputational and regulatory value in maintaining a clear record of how AI tools have been validated, tested, and monitored over time.

Accounting and Disclosure Implications for Firms

The ESMA priority does not exist in isolation. It overlaps with obligations that are already live or imminent under MiCA, DORA, and IFRS disclosure requirements for digital assets. Firms need to think about at least four accounting and reporting dimensions.

Classification and Measurement of Tokenized Assets

Where a firm holds or distributes tokenized securities, tokenized money market instruments, or tokenized fund units, the accounting classification question matters enormously. Under IFRS 9, the contractual cash flow characteristics test and the business model assessment still apply regardless of whether the instrument sits on a distributed ledger. The token wrapper does not change the underlying economics, but it may change how settlement risk, custody risk, and smart contract failure risk are treated in disclosures. Firms using digital asset accounting software should confirm that their systems capture the full lifecycle of tokenized instruments, from issuance through secondary transfer to redemption or write-down.

AI Model Governance as an Audit Matter

If AI outputs feed into financial estimates, valuations, or suitability assessments that underpin financial statements or client reports, external auditors face a new question: how do they obtain sufficient appropriate evidence about the reliability of those outputs? This is already live under ISA 500 and ISA 540 (revised) for complex estimates, but ESMA's focus on AI bias makes it a heightened area of attention. Engagement teams should revisit whether their current audit programmes adequately address AI-generated inputs.

Third-Party Risk Disclosures

The concentration risk concern has a direct parallel in financial reporting. IFRS 7 and IAS 1 require disclosure of significant risks arising from financial instruments and judgements about going concern. Where a firm's tokenized product infrastructure or AI-driven process depends materially on one or two vendors, that dependency may need to appear in the notes to financial statements, particularly if a vendor failure would be material to the firm's operations or its ability to serve clients. Crypto bookkeeping software that logs vendor dependencies alongside transaction data helps build the audit trail needed for these disclosures.

Investor-Facing Disclosure Quality

ESMA's explicit concern about investor comprehension means that compliance teams should subject current product disclosures for tokenized offerings to a plain-language review. Where prospectuses, KIIDs, or marketing materials use technical language about smart contracts, on-chain settlement, or AI-driven rebalancing without adequate explanation, they are exposed to challenge during the 2027 supervisory checks. Finance and legal teams working together on disclosure reviews now will avoid costly remediation later. For context on how other institutional frameworks are approaching tokenization oversight and what institutional players are doing about it, the range of approaches across jurisdictions is wide, which makes the ESMA harmonisation effort particularly significant for EU-facing firms.

What Firms Should Do Before 2027

The two-year lead time before formal supervisory activity begins is an advantage that many firms have wasted in previous regulatory cycles. The following steps are grounded in what ESMA has actually announced, not speculative future requirements.

Build an AI and Tokenization Inventory

Document every AI tool deployed in investor-facing or market-facing functions: what it does, who supplies it, how outputs are validated, and what escalation process exists when outputs are flagged as anomalous. Do the same for tokenized products: asset type, issuer, custody arrangement, smart contract address and auditor, settlement mechanism. This inventory is the foundation for responding to supervisory questionnaires and for the third-party concentration risk analysis ESMA has signalled.

Review Disclosure Frameworks

Cross-reference existing product documentation against the investor comprehension risk ESMA has named. If your disclosure assumes a reader who understands distributed ledger mechanics, it almost certainly needs revision. Plain-language testing with representative investor groups, where feasible, provides evidence of good faith effort that can be referenced during supervisory engagement.

Integrate Supervisory Preparation Into Audit Planning

Audit firms advising regulated clients should include the ESMA USSP in their 2026 engagement planning discussions. Risk assessments, management representation letters, and audit committee communications should acknowledge the incoming supervisory cycle. Where tokenized assets or AI-driven processes are material, the audit methodology should address them explicitly, not treat them as a footnote to a conventional financial instruments programme. The Eurosystem's own moves into tokenized infrastructure, covered in our analysis of how the Eurosystem's Pontes platform reshapes digital asset accounting, illustrate how quickly institutional infrastructure is evolving and why audit programmes need to keep pace.

Engage with National Competent Authorities Early

The mapping phase that precedes firm-level checks is an opportunity for proactive engagement. Firms that submit clear, well-organised responses to mapping questionnaires signal organisational maturity and reduce the likelihood of being selected for more intensive review. Where a national competent authority runs a regulatory sandbox or innovation hub, participating now builds the relationship and the record before formal supervision begins.

ESMA Names AI and Tokenization a Union Supervisory Priority From 2027

Frequently Asked Questions

When does the ESMA AI and tokenization supervisory priority formally begin?

ESMA has announced the priority will start in 2027. National competent authorities will begin the mapping and initial firm-check work from that date, though preparatory questionnaires could arrive before the formal launch.

Which firms are most likely to face initial supervisory checks?

ESMA has indicated checks will focus on "the most affected firms," which points to those with significant tokenized product exposure, material AI deployment in investor-facing functions, or high third-party technology concentration. Firms active in tokenized securities, AI-driven robo-advice, or algorithmic execution should assume they are in scope.

Does this priority create new legal obligations under EU law?

A Union Strategic Supervisory Priority is a coordination mechanism, not a binding legal instrument. However, supervisory expectations expressed through a USSP carry significant practical weight: supervisors use them to benchmark firm behaviour and the findings can inform subsequent regulatory action, including binding technical standards under MiCA or DORA.

How should accounting firms adjust their audit programmes for tokenized client assets?

Auditors should confirm that their evidence-gathering approach covers the full lifecycle of tokenized instruments under the applicable financial reporting framework, typically IFRS 9 for classification and measurement. They should also assess whether AI-generated inputs to material estimates meet the reliability standards required under ISA 540 (revised) and document their procedures explicitly in working papers.

What is the link between the ESMA priority and DORA obligations already in force?

DORA focuses on operational and ICT resilience, including third-party ICT risk management. The ESMA USSP extends scrutiny into the product and model layer, covering AI outputs and tokenized product design rather than just system availability and cyber security. Firms already maintaining ICT vendor registers under DORA have a strong head start, but they will need to expand those registers to cover AI model providers and blockchain infrastructure vendors specifically.

Source: Cointelegraph

]]>
EUGLOBAL#tokenizationGeneralProposedAML/KYC & Licensing

Related articles

AML/KYC & Licensing
MiCA, Sanctions and DeFi AML: The 2023 Regulatory Outlook for Crypto Accounting
AML/KYC & Licensing
AI Governance in Compliance: The Accountability and Control Gap Regulators Are Already Watching
AML/KYC & Licensing
UBS and Nethermind Push Blockchain Compliance Below the Smart Contract Layer
AML/KYC & Licensing
Blockchain Analytics and Sanctions Compliance: What Crypto Firms Must Do Now