In brief: Regulatory activity is running at pace across every major jurisdiction. This edition covers the expansion of regulatory intelligence beyond financial services and what it means for firms building capability for the first time; the growing precision with which multi-entity complexity is being named and addressed; and the modernisation window that platform transition is creating across the sector. This edition covers 7 - 18 September 2026.
The CUBE Read is CUBE's fortnightly take on regulatory change in financial services and what it means for compliance and risk teams.
Regulatory intelligence is moving beyond financial services. And the timing is right.
The most consistent pattern this fortnight is not the size of the challenge, it is the scale of the opportunity that comes with finally addressing it. Firms across manufacturing, retail, energy, and professional services are at the beginning of a shift that financial services made a decade ago: moving from manual, fragmented regulatory monitoring toward structured, automated intelligence.
The regulatory context is making that shift urgent. The AML perimeter is extending into legal and accounting sectors, with the FCA announcing intelligence-led AML supervision for those sectors from 2028. FATF has published its first assessment of online gambling as a laundering vector, and separately flagged that professional money launderers are exploiting digital hawala networks tied to the formal banking system. ESMA has flagged gaps in the EU regulatory perimeter around prediction markets. Across each of these, the same dynamic is at work: regulated activity is being redefined, and the set of firms with formal compliance and risk obligations is growing.
For firms outside financial services now entering this space, that is not primarily a compliance burden. It is the moment to build the infrastructure that financial services firms have spent years refining.
Two confirmed deadlines are relevant to firms across sectors, not only financial services. The FCA's PS26/17 fund liquidity rule takes effect on 1 February 2027, with a transitional period to 1 August 2027. The UK's T+1 settlement transition has a go-live date of 11 October 2027, with interim operational milestones in December 2026. Both require operational decisions now. Lead times for infrastructure and governance change are measured in months, not weeks, and firms that treat deadline proximity as the trigger for implementation planning consistently find themselves short of time. CUBE’s Cost of Compliance Report found that 74% of firms take more than a year to move from regulatory change identification to full implementation; for firms with hard go-live deadlines in October 2027 and February 2027, that implementation timeline means decisions need to be made now.
AMLA is preparing its first joint FIU exercise and information-sharing guidelines ahead of the 2027 EU AML regulation milestone. The exercise will set the operational baseline for cross-border AML collaboration and is worth monitoring closely; its outputs will shape how national FIUs interact with cross-border institutions well beyond the 2027 date.
ADGM has reported a 54% rise in assets under management in the first half of 2026. Hong Kong investment product sales reached a record $9.9 trillion in 2025, with FICC products in high demand. The HKMA has opened a consultation on an expanded sustainable finance taxonomy, and ASIC has proposed free public access to officeholder names and director IDs on the companies register. Taken together, these developments describe a region that is building out its regulatory infrastructure in step with its growth.
What it means for compliance and risk professionals: The expansion of regulatory scope into new sectors is not a future event. It is already reshaping which teams have formal obligations and which do not. Firms that treat this moment as the prompt to build structured regulatory intelligence, rather than to layer new obligations onto existing manual processes, will find themselves materially better positioned.
Multi-entity complexity is being named. That is the first step to solving it.
A consistent finding is the precision of articulating multi-entity challenges. The ability to name the problem clearly is a precursor to solving it.
The opportunity is proportionate to the challenge. Firms that build systematic approaches to entity-level regulatory change management, rather than managing each jurisdiction through individual expertise, gain a structural advantage. The comparative analysis use case, knowing not just that a rule exists but how it is applied differently across multiple jurisdictions, is where the value of structured intelligence is highest and where manual approaches are most obviously insufficient.
What it means for compliance and risk professionals: The firms best positioned to respond are those treating multi-entity compliance and risk management as a standing capability to be built, not a project to be completed. Those that build that capability now, are compressing a gap that will only widen as scope expands and supervisory expectations rise.
Platform modernisation is accelerating, and it is creating a window firms should use
Moving from legacy regulatory intelligence tools to newer infrastructure is one of the most significant opportunities for compliance and risk functions.
The firms making the most of this moment are treating migration not as a technical lift-and-shift but as a prompt to ask sharper questions about what the function actually needs.
The market structure and capital markets agenda is active across multiple jurisdictions simultaneously. The SEC has proposed its first major overhaul of transfer agent rules in decades, covering record-keeping, operational resilience, and third-party risk. The FCA has opened its crypto authorisation gateway; for firms in scope, the authorisation process is now live, and perimeter clarity is actively developing as applications move through the process. ESMA is consulting on updated prospectus disclosure guidelines under the EU Listing Act reforms. IOSCO and CPMI are seeking feedback on a cyber resilience toolkit for market infrastructure.
Each of these represents a moment when the regulatory requirements for a process or asset class are being actively redefined. Firms whose regulatory intelligence infrastructure is current and well-structured will interpret and respond to these developments faster than firms working through fragmented or manual processes.
What it means for compliance and risk professionals: The practical implication is straightforward. The accountability map is not a governance document to be maintained and filed. It is a live record of decisions made, by whom, on what basis, and with what evidence. Compliance and risk functions that treat it that way are building an asset.
The through line
Across all three themes, the same underlying pattern: the regulatory remit is widening and the moment to build for it is now. New sectors are acquiring compliance and risk obligations that financial services has carried for years, at exactly the point when the tooling to manage them properly is mature and available. Multi-entity and cross-jurisdictional complexity is being named with more precision than before, which is the precondition for solving it. And platform modernisation is creating a window to redesign how regulatory intelligence works inside the business, rather than replicate inherited processes on new systems. The deadline calendar, the regulatory activity, and the platform transition moment are aligned in a way that does not recur frequently.
It is what CUBE is built for: applying AI to regulatory workflows, built on 15 years of regulatory data, inside the platforms compliance and risk teams already use.
FAQS
What does PS26/17 actually require?
PS26/17 finalises the FCA’s rules on liquidity risk management for authorised fund managers (AFMs) of UK UCITS schemes and non-UCITS retail schemes (NURS). The core requirement is that all AFMs must have anti-dilution tools (ADTs) available for use, including swing pricing or a dilution levy for single-priced funds. The rules come into force on 1 February 2027 with a transitional period running to 1 August 2027.
What is T+1 and what changes on 11 October 2027?
T+1 means that securities trades must settle within one business day of execution, replacing the current two-day (T+2) cycle. From 11 October 2027, this becomes the standard settlement cycle in the UK for most securities, including equities and bonds. The EU has also targeted 11 October 2027 as its T+1 go-live date, following ESMA’s recommendation. The coordinated timing means UK and EU capital markets will make the transition simultaneously, aligning with markets in the US, Canada, and parts of Asia that have already moved to T+1.
What is AMLA?
The Anti-Money Laundering Authority (AMLA) is the EU’s new central body for AML and counter-terrorist financing supervision. It is being established ahead of the 2027 EU AML regulation milestone and will take on direct supervisory responsibility for certain obliged entities, particularly those operating across borders.
The FCA has opened a crypto authorisation gateway: what does that mean?
The FCA has opened the formal process through which crypto asset firms can apply for authorisation under the UK regulatory framework. This is operationally significant: the authorisation process is live, and firms in scope need to engage with it now.
How often is The CUBE Read published?
Fortnightly. Each edition covers the regulatory developments most relevant to compliance and risk teams in financial services.