II The Changing Perimeter

Crypto Stopped Being Outside the Perimeter on 1 January

2026 is the first data year under the Crypto-Asset Reporting Framework, which makes the regime retrospective for anyone who assumed otherwise.

A reporting obligation is not an event. It is a date after which a record exists that did not exist before. That date has passed; it passed on 1 January 2026. The questions left are what the record contains, who holds it, where it does not yet apply, and what else it turns out to be good for.

What commenced, and on whom

The Crypto-Asset Reporting Framework places no obligation on a person who holds crypto-assets. It places one on whoever serves them. Section IV(B)(1) of the OECD rules defines a Reporting Crypto-Asset Service Provider to cover any individual or entity that, as a business, provides a service effectuating exchange transactions for or on behalf of customers — including by acting as counterparty or intermediary to such transactions, or by making a trading platform available. The first three words are the ones read past. An individual can be a reporting provider, and the United Kingdom's implementing instrument says so in its explanatory note: the obligations fall on individuals and entities alike.

Section II sets out what is reported. For each reportable user: name, address, jurisdiction of residence, taxpayer identification numbers, date and place of birth; for an entity, the same for each controlling person. Then, for every type of crypto-asset: aggregate values, unit counts and transaction counts for acquisitions and disposals against fiat currency, for exchanges into and out of other crypto-assets, and for retail payments above USD 50,000. And, listed separately, the aggregate fair market value and number of units transferred to wallet addresses the provider does not know to be associated with a virtual asset service provider.

That last item repays a second reading: the report does not stop at the edge of the platform. It records, in aggregate, the value that left it.

The holder is not passive. Under the UK regulations a cryptoasset user, and a controlling person of an entity user, must provide a self-certification under regulation 5, and a failure to do so carries a penalty not exceeding £300 where the failure is deliberate or due to a failure to take reasonable care. The sum is trivial. The allocation is not.

The calendar, and why it reads backwards

The Reporting Cryptoasset Service Providers (Due Diligence and Reporting Requirements) Regulations 2025 came into force on 1 January 2026. Regulation 6 requires a report for each calendar year on or before 31 May following the end of it, which puts the first report at 31 May 2027, for 2026. Regulation 8 requires the provider to notify each reportable user, by 31 January following the first reporting year, that the information will go to HMRC and may be passed to another jurisdiction's competent authority.

Jersey's obligations began the same day; the first return to Revenue Jersey is due 30 June 2027, for 2026.

In the European Union, DAC8 was to be transposed by 31 December 2025 and applied from 1 January 2026. Article 8ad(6) requires exchange between competent authorities within nine months following the end of the calendar year, which puts the first exchanges at 30 September 2027. That is an authority-to-authority date, not a filing date; national filing deadlines are set by each member state's own law and vary.

None of those is the operative date. That was 1 January. Every report filed in 2027 describes 2026, and 2026 is now more than half spent. A regime whose first deliverable is nine months away is nevertheless already accruing, and the year it will describe can no longer be altered. Nothing is being applied to the past — the framework reaches no period before it commenced — but the present has become the record, and that is what catches an arrangement built on the view that digital assets sat outside the reporting standards. That view did not become wrong in 2027. It became wrong seven and a half months ago, and the year that demonstrates it is already being written down.

Where it is not in force, and when it will be

Switzerland signed the CARF multilateral competent authority agreement on 26 November 2024. On 26 November 2025 the Federal Council decided that the provisions on crypto-assets in the federal act on the international automatic exchange of information in tax matters and in the AEOI ordinance shall not apply in 2026. The amended Common Reporting Standard entered into force there on 1 January 2026; the crypto provisions did not. The Global Forum's commitment list, last updated on 23 June 2026, places Switzerland among the jurisdictions undertaking first exchanges by 2028. A signature is not a commencement.

The United States runs a different instrument. Broker reporting under section 6045 of the Internal Revenue Code requires Form 1099-DA for digital-asset dispositions effected on or after 1 January 2025, with basis reporting on certain transactions effected on or after 1 January 2026. The OECD's list of signatories to the CARF agreement, status as of 3 March 2026, does not include the United States, and the Global Forum's list records it as the sole jurisdiction undertaking first exchanges by 2029.

That same list records 46 jurisdictions undertaking first exchanges by 2027 and 29 by 2028. Those figures carry a date; other totals circulate without one and are unusable.

"Reported" is therefore not a state of the world but a property of a pairing — a provider's nexus and a user's residence — assessed on a date. Two people holding the same asset through providers in different jurisdictions are in different regimes, and will be for at least three more years.

The half that was never about crypto

The amendments to the Common Reporting Standard commenced the same day and attract a fraction of the attention. Central bank digital currencies and specified electronic money products are excluded from the crypto framework and drawn into the CRS instead. And, in the OECD's own words, changes were made "to ensure that indirect investments in crypto-assets through derivatives and investment vehicles are now covered by the CRS". In the United Kingdom the amending regulations took effect on 16 July 2025, with the CRS-update changes applying from calendar year 2026 onwards.

An arrangement resting on the proposition that the CRS reached bank accounts, the crypto framework reached exchanges, and the ground between reached neither, has lost the ground between.

The record is also an input

None of this is published. A report goes to a tax authority and is exchanged with another; no private party reads it. The exposure is not disclosure. It is concentration.

Before anything can be reported it must be assembled. Regulation 4 of the UK instrument requires the due diligence records and the information obtained to be kept for five years after the end of the year they relate to. The product is a structured file, held by a commercial undertaking, pairing a named individual — address, date of birth, tax identification number — with a per-asset account of what was acquired, disposed of and moved off the platform in a year. Files of that description did not previously exist in that number, format or retention period.

Tax commentary stops at the filing deadline. It should not. France's national cybercrime assistance service, in a notice published on 22 January 2026 and updated on 8 June 2026 concerning a personal-data breach in the crypto-asset sector, states that in the most serious cases offenders go as far as threatening and physically assaulting victims or those close to them in order to extort them, and that kidnappings and unlawful confinements were again reported to law enforcement in January 2026.

Be exact about what that establishes. It concerns a service provider's own customer data, not information reported under the framework, and we know of no published instance of reported material causing such an attack. We would not assert one. The narrower claim is sufficient: a structured record pairing an identified person with an estimate of their holdings has a demonstrated second market, and an obligation requiring more such records to exist, in more places, for longer, has moved a security input whether or not anyone intended it. The tax question and the protection question are answered by different people. Since January they take the same input.

What this firm will not do

The refusal runs both ways. We do not tell a principal what to report, when, or in which territory. Residence, nexus and the historic position are questions for tax counsel; structures are designed alongside independent counsel in each relevant territory, and a principal acting on anything above should take advice from an adviser unrelated to Privy Consul. What can be set out without advising is the mechanism and the calendar.

The framework makes nothing true that was not true before. It makes it recorded — in a defined format, held by defined parties, for a defined period. Those are different things, and the difference is the whole of this year.

The governance question sits under Asset Governance & Risk Infrastructure and Cross-Border Wealth Architecture, the onboarding question under KYC & Enhanced Due Diligence, and the consequence nobody commissions until later under Residential & Family Security.

Sources

  1. The Reporting Cryptoasset Service Providers (Due Diligence and Reporting Requirements) Regulations 2025 (SI 2025/744) — in force 1 January 2026; reg 4 (five-year records), reg 6 (report by 31 May), reg 8 (notification), reg 10 (registration), reg 13 (self-certification penalty)
  2. OECD — International Standards for Automatic Exchange of Information in Tax Matters: Crypto-Asset Reporting Framework and 2023 update to the Common Reporting Standard (OECD Publishing, Paris, https://doi.org/10.1787/896d79d1-en) (Section II reporting requirements; Section IV(B)
  3. OECD Global Forum — Jurisdictions committed to implement the CARF in time to commence exchanges in 2027, 2028 or 2029 (last update 23 June 2026)
  4. OECD — Signatories of the Multilateral Competent Authority Agreement pursuant to the Crypto-Asset Reporting Framework (status as of 3 March 2026)
  5. Council Directive (EU) 2023/2226 (DAC8) — Article 2 (transposition by 31 December 2025, application from 1 January 2026) and Article 8ad(6) (exchange within nine months of the end of the calendar year)
  6. Government of Jersey — Crypto-Asset Reporting Framework (CARF) and expansion of the Common Reporting Standard: rules in effect from 1 January 2026, first report due 30 June 2027
  7. Swiss Federal Department of Finance — Federal Council approves amendment to the automatic exchange of information in tax matters, 26 November 2025 (crypto-asset provisions not to apply in 2026)
  8. The International Tax Compliance (Amendment) Regulations 2025 (SI 2025/740) — in force 16 July 2025, with the CRS-update changes effective for calendar year 2026 onwards
  9. Internal Revenue Service — Final regulations and related IRS guidance for reporting by brokers on sales and exchanges of digital assets (Form 1099-DA; gross proceeds from 1 January 2025, basis from 2026)
  10. Cybermalveillance.gouv.fr — Violation de données personnelles dans le secteur des crypto-actifs : situation, risques et recommandations (published 22 January 2026, updated 8 June 2026)