/

/

Resource Hub

/

/

Resource Hub

The CUBE Read: 3 reasons more precise regulation can work to your advantage, 22 August-4 September 2026

The CUBE Read: 3 reasons more precise regulation can work to your advantage, 22 August-4 September 2026

In brief: The theme this fortnight isn't one headline rule - it's precision. Regulatory change is increasingly written at the level of a single entity, vendor or licensing decision, and that changes what useful coverage looks like. A cluster of separate actions, from the EBA's consultation on the €30 billion threshold that decides when an investment firm must become a bank, to the US Treasury's new Quantum-Readiness Task Force, shows rules increasingly asking firms to answer questions about a specific entity, vendor or licensing decision, not a whole sector. For compliance and risk teams, where monitoring is still manual and fragmented, that strain compounds quickly, and multi-entity, multi-jurisdiction complexity remains a structural constraint. This edition covers 22 August - 4 September 2026.


The CUBE Read is CUBE's fortnightly take on regulatory change in financial services and what it means for compliance and risk teams.


1. A fortnight of concurrent, unrelated deadlines tests how tracking is set up

Regulatory change increasingly arrives in short, overlapping bursts rather than periodic overhauls. In this fortnight alone: the EBA opened two separate consultations - one on reclassifying investment firms as credit institutions, one on operational risk management standards. The US Treasury launched a Quantum-Readiness Task Force, asking institutions to map cryptographic dependencies vendor by vendor. ASIC cut its licensing turnaround target to 120 days ahead of a digital asset platform licensing deadline. None of these share a rulebook, a region, or a timeline - which is itself the point. That volume isn't unusual - CUBE's Cost of Compliance Report 2025 found 82% of firms track between 26 and 100 regulatory developments a month, and 52% take two to three weeks just to complete an initial impact assessment on each one.

How well that lands depends on the set-up behind it. Where tracking is siloed, paper-heavy, or run without a single central repository, a dozen or so concurrent, unrelated developments in one fortnight is a demanding load to hold. Where it is consolidated, the same fortnight is a scheduling question rather than a scramble.

What it means for compliance and risk teams: awareness is rarely the differentiator - most teams see the headlines. The value sits in routing: getting each of a dozen unrelated items to the right part of the business quickly, and closing it out there.


2. The unit of complexity is shrinking to the entity

For years, coverage complexity was framed as a question of breadth - how many jurisdictions a firm has to watch. The EBA's consultation on the €30 billion asset threshold that triggers reclassification as a credit institution shows a sharper version of the same question: the threshold is assessed at both solo and group level, and a waiver is assessed against factors specific to the firm applying - not the sector it sits in.

The same shape shows up inside firms: multi-jurisdiction and multi-entity complexity is a persistent structural constraint, because thresholds, obligations and waiver conditions attach to individual entities rather than to the group, which means impact has to be assessed one entity at a time.

What it means for compliance and risk teams: coverage measured by jurisdiction count increasingly misses where the real work is - between entities inside a single group, each with its own thresholds, obligations and waiver conditions. Mapped at that level, the same detail becomes useful: which entities sit near a threshold, which waivers are worth pursuing, and where a change in one subsidiary has no bearing on the rest.


3. Financial infrastructure is shifting to token-based settlement and quantum-safe standards, on compressed timelines

A separate cluster of developments this fortnight points at infrastructure rather than conduct. The US Treasury's Quantum-Readiness Task Force is coordinating the financial sector's shift to post-quantum cryptography across three workstreams: sector alignment, third-party and vendor readiness, and digital-asset risk. ASIC's 120-day licensing turnaround sits ahead of a 30 September 2026 deadline for digital asset platforms operating in Australia. The ECB is launching Pontes, its bridge for settling DLT-based transactions in central bank money, in Q3 2026, and Hong Kong's exchange has continued building out cross-border settlement infrastructure with mainland China.

None of this is conduct regulation in the traditional sense - it's the plumbing underneath it changing, on a timeline set by technology rather than a legislative cycle. This isn't a surprise move - the Bank for International Settlements flagged the same urgency in July 2025, warning that firms "must urgently initiate preparations today" for the migration of cryptographic infrastructure.

What it means for compliance and risk teams: these are capability questions as much as compliance and risk ones. Post-quantum standards and token-based settlement arrive through the vendors, custodians and settlement connections firms already work with - which makes readiness a shared conversation, and one that can start well before a policy update is due.


The through-line

Across all three, the same underlying pattern: regulatory change is arriving in smaller, more precisely targeted increments - a threshold, a vendor requirement, a licensing deadline - rather than broad, periodic overhauls, and the sharpest gap is between that pace of precision and the tracking set up to keep pace with it. It's what CUBE is built for: applying AI to regulatory workflows, built on 15 years of regulatory data, inside the platforms compliance and risk teams already use. Narrower rules cut both ways: a threshold, a vendor requirement or a licensing deadline can be answered where it lands, rather than pieced together after the fact - given visibility at that level.


Frequently asked questions

What is the EBA's €30 billion threshold consultation?

The European Banking Authority's consultation, opened 25 August 2026, covers draft technical standards for reclassifying investment firms as credit institutions once total assets cross €30 billion under the Capital Requirements Directive framework - including how the threshold is calculated at solo and group level, how firms report it, and the conditions for a waiver. The consultation closes on 25 November 2026.

What is the US Treasury's Quantum-Readiness Task Force?

It's a public-private initiative launched by the US Department of the Treasury on 24 August 2026 to help the financial sector prepare for the risk quantum computing poses to current cryptographic standards, structured across three workstreams: sector alignment, third-party and vendor readiness, and digital-asset risk.

Why isn't jurisdiction count a good measure of coverage complexity anymore?

A single group can run multiple legal entities that each face different thresholds and obligations, with waiver conditions assessed entity by entity - for example under the EBA's credit-institution reclassification rules. The complexity increasingly sits between entities inside one firm, not just across countries.

What is ASIC's digital asset licensing deadline?

ASIC's transitional no-action position for digital asset businesses expires 30 September 2026; firms needing an Australian Financial Services Licence, or a variation to one, must apply by then. ASIC has also cut its processing target for complete, routine licence applications lodged from 1 July 2026 to 120 days, ahead of Australia's Digital Assets Framework Act commencing on 9 April 2027.

How often is The CUBE Read published?

Fortnightly. Each edition covers the regulatory developments most relevant to compliance and risk teams in financial services.

Keep up to date with our latest news and insights

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

RegTech 100 2026 award
AI 100 award
Bank Tech Awards 2025 award
RegTech of the Year APAC award
RegTech Company of the Year award

2026 ©CUBE Content Governance Global Limited and all its affiliated companies. All rights reserved.

CUBE Content Governance Global Limited is registered in England and Wales. Company No. 07886383. VAT number: GB125503739.

Registered address: CUBE, Tower 42, 25 Old Broad Street, London EC2N 1HN, United Kingdom.

2026 ©CUBE Content Governance Global Limited and all its affiliated companies. All rights reserved.


CUBE Content Governance Global Limited is registered in England and Wales.

Company No. 07886383. VAT number: GB125503739.


Registered address: CUBE, Tower 42, 25 Old Broad Street, London EC2N 1HN, United Kingdom.

TOP

TOP