Published 3 October 2026
The FCA's application window for UK cryptoasset firms opened on 30 September 2026, as we reported in August. Two weeks before it opened, the regulator published the document that is supposed to tell firms whether they need to apply at all. For anyone running a website or app that connects users to a DeFi protocol, that document does not yet give a settled answer.
On 16 September 2026 the FCA published Policy Statement PS26/18, its final cryptoasset perimeter guidance. It adds a new chapter, PERG 18, to the FCA's Perimeter Guidance Manual. The "perimeter" is the line between activity that needs FCA authorisation and activity that does not.
The FCA's press release lists the activities that may need authorisation once the regime starts on 25 October 2027: issuing qualifying stablecoins, operating a trading platform, dealing and arranging deals, safeguarding cryptoassets, and arranging staking.
The guidance asks the question directly. PERG 18.7.5 covers "interfaces connecting users to automated protocols" and whether they need authorisation. The answer is that it depends on whether a regulated activity is being carried on in the UK "by an identifiable person", assessed case by case.
Two other passages matter more in practice:
Elsewhere the guidance says that providing information, analytics, data or dashboards is addressed separately (PERG 18.8.8), and that wrapping and bridging services are not regulated activities in themselves but may involve one, depending on how they are built.
The feedback section of PS26/18 is unusually candid. The FCA received 78 responses to the consultation. Of the 62 that addressed intermediary activities, it reports that 63% were unsupportive of the guidance on arranging deals, and 59% thought it took too broad a view of the activity and too narrow a view of the exclusions, so that some technical service providers could end up inside the perimeter.
The FCA's response was that it "broadly" proceeded with the guidance as consulted on, because it cannot create, remove or change exclusions through guidance. Only legislation can do that.
That legislation is already moving. PS26/18 says the Government has laid a new statutory instrument before Parliament that changes the scope of the arranging and dealing activities. According to the FCA's own summary, it introduces new exclusions, including one that takes "certain technical services" out of the arranging deals activity.
The FCA is explicit that its final guidance "does not yet include the new SI". It plans to consult on further changes in early Q4 2026 and aims to publish final amended guidance in early 2027.
We have not read the statutory instrument itself. Legal commentary from Travers Smith and The Industry Spread identifies the technical services exclusion as a new Article 9Z2A, covering providers that give access to an authorised firm or to a decentralised protocol. The two do not describe its conditions in quite the same way, and neither is a substitute for the text, so treat the detail as provisional.
So the timeline looks like this:
| Date | Event |
|---|---|
| 16 September 2026 | Final perimeter guidance published, without the new exclusions |
| 30 September 2026 | Application window opens |
| Early Q4 2026 | FCA consultation on guidance for the new exclusions |
| Early 2027 | Final amended guidance expected |
| 28 February 2027 | Application window closes |
| 25 October 2027 | Regime comes into force |
A firm that runs a DeFi interface has to decide whether to apply during a window that closes around the same time the guidance it needs is finalised. The FCA's policy overview says firms that apply after the window closes cannot rely on the transitional provisions and may need to stop the relevant activity until they are authorised.
Nothing changes today. None of this regulates you as a user, and the regime does not start until October 2027. What may change over the next year is which front-ends remain available to UK users, since some operators may apply for authorisation, some may rely on the new exclusion, and some may block UK access instead.
Authorisation of an interface would not make the protocol behind it safe, and it would not bring compensation scheme cover for losses. The basics still apply: understand what you are signing when you set up and use a wallet, and know the common DeFi scams, which often arrive as fake versions of exactly these front-ends.
This article is general information, not legal or financial advice.
Affiliate link. As an Amazon Associate I earn from qualifying purchases, at no extra cost to you.