“By early next year, the UK is set to become the first G7 country to issue a Digital Sovereign Bond,” announced the Chancellor, Rachel Reeves, at Mansion House last week, in a speech that put tokenisation and agentic payments at the centre of the UK’s financial-services agenda.
UK digital assets developments may not capture headlines quite like the US, yet the UK is on a clear path to provide regulatory clarity to institutional digital assets market participants, to unlock RWA tokenization, and to permit banks and non-banks to issue and engage with stablecoin payments.
The market opportunity
The EU’s experience with rolling out MiCA shows us that the market will shift towards institutional participants, while smaller intermediaries exit or partner with larger players who will carry the regulatory responsibility. Banks and asset managers will invest into digital assets propositions, likely in the custody, payments, and trading use cases first, and tokenization of RWA second.
It’s not just the institutional pivot the UK is one of the most sophisticated and deep liquidity capital markets globally. It runs more foreign exchange than anywhere else – close to 38% of global turnover – and it is the largest hub for interest rate derivatives, at nearly half of global volume. Therefore, the City could, if it plays its hand right, hold on to its crown when wholesale markets move on-chain.
The timeline
On 30 June, the FCA published a long list of policy statements which, together with the Bank of England near-final stablecoin rules, and legislative changes driven by HM Treasury, form the UK Digital Assets Regime.
It may not have a memorable name like “MiCA” or “Genius“, but all the pieces of the UK regulatory puzzle are in place, and its impact on the market will be transformative. It allows in stablecoin payments, and aligns crypto firms with how traditional finance is regulated.
The implementation time is expedient:
- The FCA already accepts the so-called “pre-authorization meetings”.
- An “authorisation gateway”, ie a licensing window, opens on 30 September 2026.
- The window to submit applications runs until 28 February 2027.
- The regime goes live on 25 October 2027.
There are ~50 crypto firms operating in the UK today. To continue trading, they need to make the application window. A firm entering the market cannot begin trading until its authorisation is granted, and if it misses the window, the FCA will not be able to guarantee that its application will be processed by end-October.
The regulated activities
Under the new regime, the regulated activities are: operating a trading platform (a UK qualifying cryptoasset trading platform), dealing as principal or agent, arranging deals, safeguarding (ie custody of client assets), staking, and lending and borrowing. The first practical task for any firm is to work out which activities it is doing, because the specific obligations follow the activity.
A few points are worth drawing out:
- Trading platforms must run a fair, orderly and transparent venue, publish a disclosure document for every asset they admit, and settle trades within 24 hours of execution. A qualifying platform may hold up to a 2% “float” of client assets outside the safeguarding regime, so it can reach global liquidity and net on-platform – a feature specific to crypto.
- Lending, borrowing and staking carry targeted consumer protections: clear information on risks and costs, express consent each time, appropriateness testing, and safeguarding of any collateral. A firm cannot use its own proprietary token in lending or borrowing, to head off conflicts and price-inflation risk.
- Decentralised finance is caught only where there is a genuine point of control in the UK. Truly disintermediated software is not swept in for its own sake.
Safeguarding builds on the existing client-asset framework (CASS). Client cryptoassets held in custody must be protected through a non-statutory trust under the new CASS 17 rules, with records identifying beneficiaries and asset classes, while client fiat continues to sit under the existing client-money rules (CASS 7). Tokenised securities are treated differently. The FCA decided not to apply CASS 17 to them, so for the time being they fall under the existing CASS 6 custody rules, with bespoke rules to be consulted on later.
Operational resilience
Operational resilience is about whether a firm can keep client assets safe and its service running through key loss, unauthorised access, cyber-attack and third-party failure. SYSC 15A now applies to all cryptoasset firms, and the FCA published dedicated guidance on it – FG26/6 – alongside the rules.
That guidance names the techniques it expects to see protecting private keys:
- multi-party computation, so no single party holds a whole key;
- multiple signatures or thresholds to move assets; hardware security modules;
- zero-trust architecture;
- distributed storage and separation of internet-connected wallets from those kept offline;
- cryptographic audit logs, so every action can be proven after the fact. All of it, in the FCA’s words, “used in a way that avoids centralising risks” (FG26/6 §3.2).
The guidance is principles-based rather than prescriptive, which leaves room for the technology to change but works only if firms and supervisors share the same picture of what “good” looks like. The FCA has committed to more specific guidance where particular risks demand it, including on decentralised finance and distributed-ledger technology, neither yet published.
Mapped to Fireblocks capabilities
The key FG26/6 requirements map to capability Fireblocks provides in the UK and has battle tested against regulatory regimes globally:
- Segregation of client assets (PS26/11 §7.20) – Workspaces and Vault Account structures enable granular, per-client asset segregation, the operational backbone of a CASS 17 trust.
- Governance over asset movement (PS26/11 §7.3) – the Policy Engine enforces quorum-based approval before any signature is produced, governing control of the means of access.
- Safeguarding keys and infrastructure (FG26/6 §3.2) – MPC and HSM key management with policy-enforced signing keeps key material distributed, used in a way that avoids centralising risk.
- Cyber and technology resilience (FG26/6 §3.2) – Security Posture Management scans for misconfigurations; Webhook v2 and SIEM integration stream events into your SOC for monitoring and logging.
- Continuity and disruption planning (FG26/6 §3.2) – structured key backup and recovery operates independently of Fireblocks infrastructure; BCP/DR tested and ISO 22301 certified.
- Third-party and outsourcing (FG26/6 §4.3) – the Cyber and Operational Resilience package (MSA audit rights, pooled audit, periodic reporting) supports critical-outsourcing oversight.
One key point: Fireblocks is an ICT third party, so the safeguarding obligation rests with the authorised firm. The infrastructure makes compliance achievable; it does not take on the accountability.
Stablecoins: “the best regime in the world?”
The Chancellor called it one of the best stablecoin regimes in the world. On holder protection it has a strong claim – full backing, a statutory trust, and a legally enforceable right to redeem at par within a day. Whether it is the best depends on who you are: for issuers and the wider market it is less commercially attractive than the US or the EU.
The regime is a two-tier design with a defined path from one to the other once an issuer is designated:
- The FCA regulates non-systemic issuers
- The Bank of England regulates systemic ones
The core requirements are on backing and redemption: as with EU and US regimes, every token holder has a direct, legally enforceable right to redeem at par with the issuer, redemptions must be processed by the next working day (tighter T+0 for systemic issuers), tokens are backed 100% at par at all times, and the backing assets sit in a statutory trust for token holders, separate from the issuer’s own assets. Issuers cannot pass interest to token holders, though non-time-based rewards – transaction-based, say, from the issuer or a third party – are allowed.
Industry has been supportive of the Bank of England offering world-first direct access to its borrowing facility, but disgruntled that for systemic coins, 30% of assets need to sit in unremunerated reserves.
Payments themselves sit outside this rulebook for now, and HM Treasury is the payments regulations to bring in tokenised deposits and stablecoins, with FCA guidance to follow.
Tokenisation: a set of enabling changes
Both UK regulatory agencies and the Labour Government, through all its permutations, have been vocally positive on tokenization. A steady trickle of enabling changes has hit the market.
The Bank of England has confirmed it will open CHAPS settlement from 01:30am (rather than 06:00am) from September 2027, the first step towards near 24/7 operation, so the cash rail is open when a tokenised asset wants to settle.
Longer hours help, but they do not fully solve settlement. A tokenised asset moving on a blockchain still has to settle against cash sitting in a separate system, at the same instant, or settlement risk creeps back in.
Somewhat positively, the Digital Securities Sandbox (DSS) now allows for sandbox firms to use certain stablecoins as the settlement asset. That is where on-chain settlement can actually happen today: the tokenised security and a stablecoin cash leg moving together on the same ledger. Note – the DSS is a live, albeit capped, environment.
Last week, Chris Woolard, appointed HM Treasury’s Digital Markets Champion issued a first report to a tokenization taskforce, to which Fireblocks was appointed together with 53 industry peers.
One of its recommendations bears directly on settlement. On wholesale payment rails (Priority 4), it calls on the authorities to ensure infrastructure and regulation support settlement of tokenised assets in different forms of money – stablecoins and tokenised deposits – and to develop models to settle directly in central bank money via RTGS, through synchronisation.
Further, on collateral , it calls on the Bank of England to be prepared to accept DIGIT as collateral in its Sterling Monetary Framework, and to consider accepting tokenised collateral more widely, including at central counterparties.
Separately, the FCA and Bank of England set out their own principles in their joint call for input on the future of tokenisation: someone must always be legally accountable for the ownership record and for settlement finality, tokenised and non-tokenised assets should be treated alike, and the market should not fragment into disconnected pools of liquidity.
The government’s tokenized gilt, DIGIT, is targeting a first transaction by Q1 2027 on HSBC Orion, which was cleared this week to provide live depository services in the regulators’ Digital Securities Sandbox; HSBC and the London Stock Exchange Group are building a link between their depositories so investors can hold DIGIT through either, with a potential LSE listing under discussion.
And Baillie Gifford and BNY launched Britain’s first fully tokenised fund this summer. Note – tokenized funds can be settled on stablecoins outside the DSS.
The policy frontier: agentic commerce
The newest front is AI and agentic commerce. In July the FCA published the Mills Review, on AI and the future of retail financial services – by its own account the first review of its kind led by a financial regulator. It does not reach for new AI-specific rules; the FCA’s position is that its existing outcomes-based framework already covers much of the risk and should be adapted rather than replaced.
The Review makes seven priority recommendations for the FCA:
- Secure and adapt the regulatory perimeter.
- Strengthen system-wide coordination and oversight.
- Monitor the transition to autonomous models and adapt regulatory frameworks.
- Scale up the FCA’s AI Lab to support AI model and system innovation in financial services.
- Enable the foundations for agentic finance, including a trusted agent protocol.
- Build and adopt an AI-enabled agentic supervisory model.
- Develop a trusted public-interest AI-enabled financial capability service.
Taken together, these point to where the technology is going: retail finance moving from human-led and occasional to AI-enabled, continuous and delegated, where a consumer sets a goal and an agent compares products, switches providers and makes payments on their behalf. Recommendation 6 – an agentic supervisory model – is the one to watch: it would give the regulator its own AI tools so supervision can move from periodic checks towards continuous oversight, as risk spreads from inside a single firm to across the system.
What to focus on
The controls the UK’s standard calls for – distributed key management, quorum-based approval, segregation, tested recovery – are the ones Fireblocks already provides. The priorities are straightforward: get the application in before the window closes in February 2027; build to the “avoid centralising risk” standard; and watch the open questions on stablecoin payments and the promised DeFi and DLT guidance. The firms that treat the next twelve months as a build, and not just a licensing exercise, are the ones ready when the regime goes live in October 2027.
On agentic finance: it is a control problem before it is anything else – who is allowed to act, within what limits, leaving what audit trail, and who is accountable when an agent gets it wrong. Those are the operational-resilience questions about private keys, scaled up to software that moves money on its own.