The European Union has put a date on it. From 10 July 2027, the Anti-Money Laundering Regulation (AMLR) applies in full across all 27 member states, and with it comes the most consequential financial privacy rule the crypto industry has faced: regulated exchanges, custodians, and crypto-asset service providers operating in the EU will no longer be permitted to list, custody, or facilitate trading in anonymity-enhancing coins.

Monero. Zcash. Dash. Anything whose design obscures transaction detail by default or by option.

The reaction across crypto media has been predictably binary — “the EU bans privacy” versus “nothing really changes.” Both are wrong. Here’s what the regulation actually does, where its edges are, and why the more interesting story is what the industry is building in response.


What Article 79 Says

The operative provision is Article 79 of the AMLR, which prohibits crypto-asset service providers from maintaining accounts that hold “anonymity-enhancing coins” — defined broadly as crypto assets designed to obscure transaction information, whether that obscuring is on by default or available as an optional feature.

That definition is deliberately wide. It does not name a token list. It describes a property. Which means the compliance question for any given asset is not “is it on the banned list” but “does its design conceal transaction detail” — a question regulated firms will answer conservatively, because the cost of guessing wrong is their licence.

Alongside the privacy coin provision, AMLR brings:

  • A ban on anonymous crypto accounts held at regulated providers — no unverified custodial wallets, full stop
  • Mandatory ID verification for any transaction of €1,000 or more, applying to fiat-to-crypto and crypto-to-crypto
  • A €10,000 cap on cash payments across the EU, the traditional-finance half of the same policy

Read together, these aren’t three separate rules. They’re one policy: within the EU’s regulated financial perimeter, every value transfer above a modest threshold must be attributable to an identified person.

What It Doesn’t Do

Three clarifications that get lost in the headlines:

Owning privacy coins remains legal. The AMLR regulates service providers, not holders. An EU resident holding XMR in a self-custodied wallet on 11 July 2027 is not committing an offence. What disappears is the regulated on-ramp and off-ramp.

It is not a protocol ban. Monero will continue to produce blocks. The network has no EU-facing chokepoint to squeeze. This is a rule about the interface between the regulated financial system and the network, not about the network.

It does not ban zero-knowledge technology. ZK proofs used for scaling, for selective disclosure, or for compliance-preserving identity are unaffected — arguably encouraged. The target is unattributable value transfer, not privacy-preserving computation. That distinction is doing enormous work, and it’s where the next generation of privacy tooling is being built.

The Practical Consequence: Liquidity Migration

The predictable outcome is not that privacy coins die. It’s that their liquidity moves from regulated venues to unregulated ones, from custodial to non-custodial, and from Europe to elsewhere.

We have a preview of this. When major exchanges delisted Monero in prior compliance waves, XMR did not disappear — trading migrated to atomic swaps, decentralised exchange infrastructure, and peer-to-peer venues. Spreads widened. Volumes fragmented. The asset kept functioning.

The policy question worth asking honestly: does pushing this activity outside regulated, monitored venues improve anti-money-laundering outcomes, or does it destroy the visibility that regulated intermediaries currently provide? Reasonable people disagree, and the AMLR represents Europe committing hard to one answer.

The Enforcement Context

The AMLR doesn’t arrive in a vacuum. It lands after a sustained run of criminal enforcement against privacy tooling on the other side of the Atlantic:

  • Roman Storm, Tornado Cash co-founder, was convicted of operating an unlicensed money transmitting business — a verdict that raised the still-unresolved question of whether publishing non-custodial software constitutes providing a financial service. We covered what the Storm trial means for DeFi when the verdict landed.
  • Keonne Rodriguez, Samourai Wallet’s CEO, received a five-year sentence — the statutory maximum — with CTO William Lonergan Hill sentenced to four years.

Between US prosecutions of privacy developers and EU regulation of privacy assets, the message to builders is coherent even if it was never coordinated: privacy tools that cannot demonstrate who used them and for what carry existential legal risk to their authors.

The Response: “Pragmatic Privacy”

Which brings us to the more interesting half of this story.

Capital and engineering talent are not exiting privacy — they’re reorganising around a different design goal. Projects including Railgun, Nocturne, Zama, Aleo, and Nillion are converging on what the sector has started calling pragmatic or compliance-friendly privacy: systems where transaction detail is shielded from the public by default, but where the participant retains a cryptographic ability to prove specific facts to a specific counterparty.

The primitives that make this work:

  • View keys and selective disclosure — prove to your auditor, tax authority, or counterparty exactly what they need, and nothing else
  • Proof-of-innocence constructions — cryptographically demonstrate that your funds do not derive from a sanctioned address set, without revealing your transaction graph
  • Encrypted computation (FHE) — process data without decrypting it, keeping inputs private from the operator itself

The target market is not the person avoiding surveillance. It’s the corporate treasury that cannot publish its payroll on a public ledger, the trading desk whose positions are its edge, the tokenised trade-finance deal where counterparty terms are commercially confidential. Those are large, well-funded, entirely legitimate demands for privacy — and they are what will fund the technology’s next decade.

What to Do Before July 2027

If you hold privacy coins in the EU: you have roughly a year to decide between self-custody and exit. Nothing forces a sale, but the regulated venues that would let you exit later will be closed. Plan the path, and plan the tax treatment of whichever route you choose.

If you operate a CASP in the EU: your delisting and account-remediation programme needs to start well before the deadline. The Article 79 definition is property-based, not list-based — you will need a documented, defensible methodology for classifying assets, and you will need it audited.

If you build privacy infrastructure: design for selective disclosure from day one. A system that can prove compliance-relevant facts without revealing everything has a regulatory future in Europe. A system that cannot, does not. This is not a technical limitation — the cryptography exists and is production-ready.


The AMLR is best understood not as an anti-crypto measure but as Europe applying its existing, decades-old AML philosophy to a new asset class with unusual consistency. Whether that philosophy works any better on-chain than it has off-chain is a question the next several years will answer — probably not to anyone’s satisfaction.

Sources: thirdweb · Yahoo Finance · Bitcoin Magazine · IRS-CI