Australia Crypto AML Regulations 2026: What Changed for VASPs and the Travel Rule

Australia Crypto AML Regulations 2026: What Changed for VASPs and the Travel Rule

On 8 May 2026, AUSTRAC put numbers on how closely it intended to watch Australia's crypto sector: 36 over-the-counter crypto-to-cash businesses under a supervisory campaign it branded ramps and rails, and 27 local exchanges under a second campaign focused on reform readiness and governance. Announcing the campaigns, AUSTRAC Chief Executive Officer Brendan Thomas summed up the country's move from "digital currency exchange" to "virtual asset service provider" in seven words: "This is more than a name change."

(Source: AUSTRAC, "AUSTRAC steps up supervision of virtual assets sector as reforms take effect," 8 May 2026 — https://www.austrac.gov.au/new-and-media/news/austrac-steps-supervision-virtual-assets-sector-reforms-take-effect)

That line is the whole story in miniature, and it lands differently depending on which version of the Australian rules you learned first. Australia did not start regulating crypto in 2026. Exchange between digital currency and money has sat inside the AML/CTF perimeter since April 2018, when digital currency exchange providers first had to register with AUSTRAC and run AML/CTF programs. What the 2026 reforms did was widen the perimeter around that original core and modernise the obligations attached to it.

The dates matter more than usual here, because three different clocks were running at once. From 31 March 2026, the updated AML/CTF framework began applying to existing reporting entities, and businesses already registered as digital currency exchange providers automatically became registered virtual asset service providers without re-registering. For certain newly regulated virtual asset services, AML/CTF program, customer due diligence, reporting and recordkeeping obligations were deferred until 1 July 2026 under the transitional rules. That deferral never applied to fiat-to-virtual-asset exchange — the service AUSTRAC labels item 50A — which had to meet the new obligations from 31 March.

(Source: AUSTRAC, "AML/CTF transitional rules 2026" — https://www.austrac.gov.au/about-us/legislation/updates-legislation/amlctf-transitional-rules-2026)

The summary that holds up is this: Australia's 2026 reform is not a DCE-to-VASP rebrand. It expands which virtual asset services fall inside the AML/CTF framework, and it changes how regulated businesses must handle customers, transactions, transfers and Travel Rule information. And the regulator has already moved past the preparation phase. The supervisory campaigns launched in May 2026 were followed on 30 June 2026 by AUSTRAC publishing its VASP register openly, so that customers and counterparties can check registration status for themselves.

From Digital Currency Exchanges to a Broader VASP Regime

For roughly eight years, if you wanted to describe Australian crypto AML regulation in one sentence, you could say: run a fiat-to-crypto exchange, register with AUSTRAC as a DCE provider, and comply. That description was never complete, but it was close enough that most crypto-native businesses without a fiat on-ramp assumed they sat outside the regime.

The 2026 amendments retired that shorthand. Australia adopted the internationally recognised term "virtual asset service provider," and the change in vocabulary tracked a change in scope rather than branding. The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 rewrote the relevant parts of the AML/CTF Act 2006, with the virtual asset provisions in Schedule 6 commencing on 31 March 2026.

For businesses already on AUSTRAC's books, the transition was designed to be administrative rather than disruptive. Existing registered DCE providers did not have to apply again from scratch; they became registered VASPs automatically on 31 March 2026 and stayed subject to the updated reporting-entity obligations. What they did have to do was update their registration and enrolment details to reflect the specific virtual asset designated services they actually provide, and AUSTRAC set a window of 31 March to 29 July 2026 for that step. The rollover protected the registration. It did not do the operational work.

Underneath the terminology change sits a principle that anyone assessing Australian exposure should internalise. The framework asks which designated virtual asset service a business provides — not what the company calls itself, and not whether the words "exchange" or "wallet" appear in its product description. Two businesses with identical marketing can land on opposite sides of the line, and one business can be captured by a single service item while the rest of its activity sits outside the regime. If you want the international framing before the Australian one, it helps to separate the two layers: the global standard-setting view of what qualifies a business as a Virtual Asset Service Provider defines the concept, while Australian statute defines the perimeter that actually creates obligations.

The public register is the other visible change from the 2026 cycle. AUSTRAC announced on 30 June 2026 that its VASP register is now available to anyone, listing the VASPs registered and regulated in Australia so users can verify a provider before dealing with it.

(Source: AUSTRAC, "Virtual Asset Service Provider Register Goes Public," 30 June 2026 — https://www.austrac.gov.au/virtual-asset-service-provider-register-goes-public)

Banks, payment providers and institutional counterparties have already folded that register into routine onboarding checks, so it pays to be precise about what an entry proves. It confirms that a business is registered with AUSTRAC to provide particular virtual asset services. It does not certify that the business is low risk, financially sound, protecting customer funds adequately, or fully compliant with everything else in the Act. Registration is an entry ticket, not a report card.

Which Virtual Asset Services Are Now Regulated

Start by separating what actually changed from what only reads as new in the coverage. Exchange between virtual assets and money, in either direction, was regulated before the reforms and remains regulated. Presenting fiat on- and off-ramps as a 2026 innovation is one of the most common errors in current commentary.

What the reforms added is a set of further designated services, defined in table 1 of section 6 of the AML/CTF Act and set out in AUSTRAC's guidance by item number:

  • exchanging virtual assets for money, or making arrangements for that exchange (item 50A) — the pre-existing service;
  • exchanging one virtual asset for another, or making arrangements for that exchange (item 50B);
  • providing a virtual asset safekeeping service, which turns on controlling or managing virtual assets or the private keys that access them (item 46A);
  • accepting instructions to transfer virtual assets on behalf of a customer, or making transferred virtual assets available to a customer (items 29–30);
  • providing financial services connected to an issuer's offer or sale of a virtual asset, where the business participates in that offer or sale (item 50C).
(Source: AUSTRAC, "Virtual Asset Designated Services" — https://www.austrac.gov.au/new-austrac/designated-services-newly-regulated-entities/virtual-asset-designated-services)

Two details in that list do a lot of work in practice. The first is "making arrangements." A business does not need to execute every leg of an exchange to be captured under items 50A or 50B; facilitating or intermediating the trade can be enough. The second is the different qualifier attached to item 50C. Most of these services are regulated when provided in the course of carrying on a business as a VASP, but the offer-or-sale service can catch a business that is not a VASP at all and is providing the service as a one-off rather than as its normal line of work.

The practical takeaway is that the compliance perimeter follows the service being performed. That cuts in both directions, and the second direction gets less attention than it deserves. A company that supplies non-custodial software and never controls customer assets or keys should not be described as providing regulated safekeeping merely because its product interacts with wallets. Issuing a token or building blockchain infrastructure does not, by itself, convert every activity of the business into a registrable virtual asset service. The analysis is service-by-service, and it should be documented that way rather than settled by the label on the pitch deck.

There is also a second test that sits alongside the service test and is easy to skip. Providing one of the listed services is not sufficient on its own — the service must also have a geographical link to Australia, as defined in section 100 of the AML/CTF Act. AUSTRAC's guidance frames this around permanent establishment: providing the service at or through a permanent establishment in Australia, or being an Australian resident or the subsidiary of one and providing the service through a permanent establishment overseas. The full territorial analysis deserves its own legal review, but the sequencing is what matters here. First identify the service, then test the link.

💡
For comparison, this is a domestic build on an international template rather than a copy of it. Reading how FATF defines virtual asset services at the global level alongside the Australian item list shows where the two overlap and where Australia has drafted its own boundaries.

What AUSTRAC Requires From Regulated VASPs

Once a business concludes that it provides a designated virtual asset service with an Australian link, a familiar set of obligations attaches. The relevant ones can include enrolling with AUSTRAC, holding VASP registration, maintaining an AML/CTF program, assessing and controlling money laundering, terrorism financing and proliferation financing risk, carrying out customer due diligence, monitoring customers and transactions on an ongoing basis, submitting suspicious matter reports and other applicable transaction reports, keeping records, allocating governance and compliance responsibility, and arranging independent evaluation of the AML/CTF program.

The registration mechanics are where new entrants most often trip. Enrolment and registration are two separate steps: enrolment places the business on the Reporting Entities Roll, and registration places it on the VASP Register. AUSTRAC's position is that a business generally cannot start providing registrable remittance or virtual asset services until its registration has been approved. The 2026 transitional arrangements carved out a narrow exception for the reform window: providers of the newly regulated virtual asset services who applied before 29 July 2026 could keep providing those services while AUSTRAC decided on the application.

(Source: AUSTRAC, "Register with us as a Remittance or Virtual Asset Service Provider" — https://www.austrac.gov.au/new-austrac/register-us/register-us-remittance-or-virtual-asset-service-provider)

The customer due diligence transition is the part most often misdescribed, and the misreading tends to run in a dangerous direction. Existing reporting entities that meet the transitional conditions can keep using their previous applicable customer identification procedures for defined classes of customers while they move across to the reformed initial CDD framework. The transitional period runs from 31 March 2026 to 31 March 2029, it is available only to entities that were enrolled as reporting entities on 30 March 2026 and maintain policies requiring ACIP that complied with the rules in force then, and it required the business to document, by 1 July 2026, which customer classes it applies ACIP to and when each class stops. Those conditions sit in the Anti-Money Laundering and Counter-Terrorism Financing Transitional Rules 2026, registered as F2026L00393.

(Source: Federal Register of Legislation, AML/CTF Transitional Rules 2026 — https://www.legislation.gov.au/F2026L00393/latest/text)

What this transition does not do is postpone customer identification. It governs how an existing business moves between two frameworks, not whether it has to identify customers. Ongoing customer due diligence applies to all customers from 31 March 2026 with no transitional relief at all, and a business relying on the ACIP option has to apply one consistent approach rather than mixing old and new procedures across its customer base. Anyone reading "2029" as a grace period for onboarding controls has misread the rule. Teams that have not revisited onboarding since the reform usually find the gap sits in risk rating rather than document collection, which is where how risk-based Customer Due Diligence works in crypto becomes the more useful reference point. Much of the identity work at the front of that process, for individuals and corporate customers alike, can be handled through automated KYC and KYB verification.

Ongoing monitoring is the obligation that most clearly separates a compliance document from a compliance function. AUSTRAC's 2026–27 regulatory priorities make the point in supervisory language: the regulator wants to see AML/CTF programs operating in daily business, and has signalled it will act where a program exists only on paper. For a VASP, that means customer and transaction monitoring that actually runs against live activity, including continuous crypto transaction monitoring of on-chain flows, with escalation paths that end in a suspicious matter report when the facts warrant one.

How Australia's Crypto Travel Rule Applies to Virtual Asset Transfers

Australia's reform extends transfer-of-value requirements to relevant virtual asset transfers, applying a principle that has been circulating internationally for years. The underlying logic of originator, beneficiary and information travelling with value is set out in how the FATF Crypto Travel Rule works globally; what follows is the Australian implementation built on top of that baseline.

Clear away one misconception immediately, because it causes real scoping errors. Australia's virtual asset Travel Rule is not a cross-border-only requirement, and there is no small-transfer carve-out that lets low-value transfers through untouched. Relevant non-incidental virtual asset transfers can attract Travel Rule obligations based on the role the business plays in the transfer, not on where the counterparty sits or how much value moves. The framework assigns three roles, and the obligations differ by role:

  • the ordering institution, which accepts the payer's instruction to transfer value;
  • the intermediary institution, which receives and passes on a transfer message without dealing with either the payer or the payee;
  • the beneficiary institution, which makes the transferred value available to the payee.

Depending on which role applies, a business may need to collect, verify, obtain or pass on three categories of data: payer information, payee information, and tracing information. The first two are what most people picture when they hear "Travel Rule" — names and identifying details of the two parties. Tracing information is the category that trips up teams building for the first time, because it is about locating the value rather than the people. In AUSTRAC's guidance it can include the virtual asset wallet address, an account identifier, a destination tag or memo, or a unique transaction reference number assigned to the transfer, with the correct element depending on the transfer type.

(Source: AUSTRAC, "The Travel Rule" guidance hub — https://www.austrac.gov.au/industry-and-business/obligations-and-guidance/additional-guidance/travel-rule)

There is no need to turn this into a messaging-protocol specification to grasp the practical principle. Required information has to move through the institutions in the chain so that each participant can identify the payer and payee and trace where the value came from or went. Where that information is missing, incomplete or does not stand up to scrutiny, the answer is a risk-based decision — hold, query the counterparty, escalate, or in some cases decline — rather than letting the gap disappear quietly into a completed transaction. AUSTRAC expects institutions to monitor for transfer messages missing required information, using a risk-based approach rather than a line-by-line inspection of every message.

Self-hosted wallets get specific treatment, and it is more nuanced than either of the two positions people tend to assume. When an ordering institution sends virtual assets to a self-hosted wallet, there is no receiving institution to send Travel Rule information to, so it does not pass the information down a chain. It still has to collect payer information and the payee's full name, and it still has to verify the payer information that requires verification before giving effect to the transfer. Before any of that, AUSTRAC's virtual asset guidance requires the ordering institution to determine what kind of wallet is receiving the value — a custodial wallet controlled by an entity that is licensed or registered under a FATF-aligned regime, a custodial wallet controlled by an entity that is not required to be, a custodial wallet controlled by an entity that should be registered but is not, or a self-hosted wallet controlled by the payee — and to do enough due diligence to have reasonable grounds for that determination. Incoming transfers run the other way: a beneficiary institution receiving virtual assets from a self-hosted wallet must obtain the payer information and tracing information, plus the payee's full name if it does not already hold it, before making the assets available.

(Source: AUSTRAC, "Additional Travel Rule Obligations when Transferring Virtual Assets" — https://www.austrac.gov.au/industry-and-business/obligations-and-guidance/additional-guidance/travel-rule/additional-travel-rule-obligations-when-transferring-virtual-assets)

Two boundaries deserve stating plainly. Nothing here means Travel Rule data is written to a blockchain address; the wallet address is an identifier used in compliance records and messages, not a destination for personal data. And nothing here places self-hosted transfers outside AML/CTF scrutiny — the obligations change shape rather than disappearing, and a separate reporting requirement for transfers involving unverified self-hosted virtual asset wallets is scheduled to begin on 31 March 2029 under the transitional rules.

What the 2026 Reform Changes in Practice for Crypto Businesses

For a business that was already registered and running a fiat-to-crypto exchange, the reform poses one question above all others: does the business now provide additional virtual asset services that previously sat outside its regulated DCE activity? Crypto-to-crypto trading, custody of customer assets or keys, transfer services performed on behalf of customers, and participation in an issuer's offer or sale are the usual candidates. Where the answer is yes, the follow-up is to check which designated service items those activities map to, whether registration details were updated to cover them, and which transitional timing applied to each — because the 1 July 2026 deferral covered the new services while item 50A activity had to meet the new obligations from 31 March. For a business entering Australia now, the sequence runs in a different order and should be settled before launch rather than after the first customer:

  • what exact service is being provided, described operationally rather than in marketing terms;
  • whether that service has the required geographical link to Australia;
  • whether it is a designated virtual asset service under the Act;
  • whether enrolment and VASP registration are required, and whether services can lawfully begin before registration is approved;
  • what AML/CTF program, risk assessment and CDD controls have to exist on day one;
  • whether Travel Rule obligations attach to the transfer model, and in which role.

For existing and new VASPs alike, the practical architecture has to connect things that many businesses still run as separate systems: customer identity, customer risk rating, blockchain transaction monitoring, Travel Rule data, suspicious-activity review, and records. They are not competing tools fighting for the same budget line, because each answers a different question. Travel Rule information tells you who the parties to a transfer are. Blockchain analytics tells you what risk the on-chain transaction itself carries. Customer due diligence tells you who the customer is and what their activity should look like. A monitoring alert that cannot be read against customer context produces noise; a customer file that never sees on-chain behaviour produces blind spots.

The reform also arrived alongside a shift in how the regulator works, which is why treating this as a documentation exercise is risky. Most existing VASPs do not need to rebuild their compliance systems from scratch; they need to re-scope the systems they have against a wider service perimeter and keep those systems current as the rules continue to bed in. That is a change-management problem more than a procurement one, and it is the reason how crypto businesses should keep AML controls updated when regulations change matters as much as the initial build: programs fall out of alignment quietly, between reform cycles, not on commencement day.

AUSTRAC's current activity confirms that implementation is a live regulatory issue rather than a future one. The two supervisory campaigns launched in May 2026 engaged directly with dozens of OTC crypto businesses and local exchanges on business models, governance and risk management, and AUSTRAC's 2026–27 regulatory priorities continue to identify risk management in the virtual asset sector as a focus area.

(Source: AUSTRAC, "Our Regulatory Priorities for 2026–27" — https://www.austrac.gov.au/about-us/policies-and-governance/our-policies/our-regulatory-expectations-and-priorities/our-regulatory-priorities-2026-27)

Being included in a supervisory campaign is not the same as being under enforcement investigation. The campaigns are engagement and uplift exercises. But they do tell you where the regulator is looking, and they signal that questions about scope, governance and monitoring quality are being asked now rather than at some later compliance milestone.

Australia Has Moved Beyond the Old DCE Model

Before the reform, you could describe Australian crypto AML regulation with a short chain: digital currency exchange, fiat-to-crypto exchange, AUSTRAC registration. After 2026, that chain no longer describes the regime.

The current framework reaches a broader range of virtual asset services and ties them to updated obligations across registration, AML/CTF programs, risk management, customer due diligence, ongoing monitoring, reporting, recordkeeping and the Travel Rule. Each of those obligations attaches to services rather than to a business category, which is why the scoping analysis has become the first compliance task rather than a formality.

The practical question for a crypto business is therefore no longer simply whether it operates a digital currency exchange. It is which virtual asset services it actually performs, and which of those services fall inside Australia's designated-service framework.

Australia's 2026 reforms shift crypto AML regulation from a relatively narrow exchange-focused regime toward a broader VASP framework built around the actual services a business provides.

FAQ

Are Crypto Businesses Regulated in Australia in 2026?

Yes. Businesses providing designated virtual asset services with the required connection to Australia can be regulated under the AML/CTF Act and supervised by AUSTRAC. The 2026 reforms expanded the scope beyond Australia's older fiat-to-crypto exchange framework, so businesses that concluded years ago that they sat outside the regime should re-run that analysis against the current designated-service list.

What Is a VASP in Australia?

A Virtual Asset Service Provider is a business providing relevant designated virtual asset services, such as certain exchange, transfer, safekeeping or issuer-related services. Australia adopted VASP terminology in 2026 as part of the expansion of its AML/CTF regime, replacing the narrower digital currency exchange concept that had defined the perimeter since 2018.

Did Australia Replace Digital Currency Exchanges With VASPs?

Yes. Existing registered Digital Currency Exchange providers automatically became registered Virtual Asset Service Providers from 31 March 2026, without needing to re-register. The change accompanied a broader expansion in the types of virtual asset services covered by AML/CTF regulation, and transitioning providers were still expected to update their enrolment and registration details to reflect the services they actually provide.

Which Virtual Asset Services Are Regulated by AUSTRAC?

The framework covers fiat-to-virtual-asset exchange and can also cover virtual-asset-to-virtual-asset exchange, arranging either type of exchange, transfers made on behalf of customers, making transferred assets available to customers, virtual asset safekeeping involving control of assets or private keys, and certain financial services connected to an issuer's offer or sale of a virtual asset. Each is defined as a specific item in table 1 of section 6 of the AML/CTF Act, and the statutory geographical link must also be satisfied.

Do Australian VASPs Need to Register With AUSTRAC?

Businesses providing registrable virtual asset services generally need to enrol with AUSTRAC and apply for VASP registration — two separate steps. Existing DCE providers transitioned automatically to VASP registration, while providers of newly regulated services were subject to specific 2026 transitional arrangements, including the ability to keep operating while a registration application lodged before 29 July 2026 was assessed.

When Did Australia's New Crypto AML Rules Take Effect?

Updated obligations for existing reporting entities took effect on 31 March 2026. Certain AML/CTF obligations for newly regulated virtual asset services were deferred until 1 July 2026 under the transitional rules. Existing fiat-to-virtual-asset exchange services, listed as item 50A, were not covered by that deferral and had to meet the new obligations from 31 March.

Does Australia Have a Crypto Travel Rule?

Yes. Australia's updated AML/CTF framework applies Travel Rule requirements to relevant virtual asset transfers. Depending on whether it acts as ordering, intermediary or beneficiary institution, a VASP may need to collect, verify, obtain or transmit payer information, payee information and tracing information. The requirement is not limited to cross-border transfers, and there is no minimum transfer size that removes it.

Does Australia's Crypto Travel Rule Apply to Self-Hosted Wallets?

Transfers involving self-hosted wallets receive specific treatment rather than an exemption. An ordering institution sending to a self-hosted wallet does not transmit Travel Rule information to another institution, because there is none to receive it, but it still has payer and payee information obligations and must verify payer information where required. It also has to determine what type of wallet is receiving the transfer. Incoming transfers from self-hosted wallets can require the beneficiary institution to obtain payer and tracing information before making the assets available.

Is AUSTRAC VASP Registration the Same as a Crypto Licence?

Not exactly. VASP registration is part of Australia's AML/CTF regulatory framework and is required for relevant virtual asset services. It should not be treated as a universal label proving every type of financial authorisation, solvency, customer protection or regulatory compliance, and it is separate from authorisation requirements administered by other Australian regulators.

Does VASP Registration Mean a Business Is Fully AML Compliant?

No. Registration is one obligation among many. A regulated VASP must continue to meet applicable AML/CTF requirements covering risk management, customer due diligence, transaction monitoring, reporting, recordkeeping, governance and relevant Travel Rule controls. Appearing on the public register confirms registration status; it does not confirm that the underlying program is working.