Global Trustee and Fiduciary Services Bite-Sized Issue 7 2026

4 AI CRYPTOASSETS CYBER DORA IOSCO MONEY MARKET FUNDS SUSTAINABLE FINANCE/ESG ASIA PACIFIC AUSTRALIA EUROPE IRELAND LUXEMBOURG NORTH AMERICA UNITED KINGDOM Global Trustee and Fiduciary Services Bite-Sized | Issue 7 | 2026 Quick Links • The Bank of England should conduct more granular modelling of the impact of imposing holding limits on high-value use cases; • HM Treasury should consider with the Bank of England and the FCA whether the existing legal frameworks are sufficient to detect and deter illicit activity using private unhosted and unregulated wallets, and should be prepared to legislate to restrict their use if necessary; • HM Treasury should set out further details about how it will determine whether stablecoins are systemic; • The FCA should reconsider whether a k-factor requirement for stablecoin issuers that increases with the volume of stablecoins is appropriate. Link to Report here CYBER SFC Urges Licensed Firms to Guard Against Emerging AI-enabled Cyber Threats On 2 June 2026, the Securities and Futures Commission (SFC) issued a circular calling upon licensed firms to strengthen their cybersecurity measures against emerging threats enabled by frontier artificial intelligence (AI) models. The SFC says that AI-enabled cyber threats came to the fore as cyberattacks continued to evolve locally and globally. Notably, the SFC says that Hong Kong recorded a double-digit increase in overall cyberattack incidents last year. Against this backdrop, the SFC warns in the circular that fast-advancing frontier AI models have the potential to enable more frequent, targeted and sophisticated cyberattacks, which could result in significant operational disruptions and risks for licensed firms, their staff and clients. The SFC also noted that recent advancements in AI have made it easier for malicious actors to identify and exploit system vulnerabilities at a faster pace, coordinate attacks across multiple interconnected systems and orchestrate large-scale attacks. At the same time, the SFC says that the proliferation of AI-enabled tools lowers the barriers for them to engage in phishing, social engineering, deepfake impersonation and reconnaissance. Consequently, the SFC states that licensed firms are exposed to heightened cybersecurity risks. In its circular, the SFC urges licensed firms, especially internet brokers and virtual asset trading platforms, to implement robust and up-to-date measures to protect their systems, prevent confidential client information from unauthorised access or disclosure, and safeguard client assets against misappropriation. In addition, the SFC sets out areas for licensed firms to review and enhance their cybersecurity frameworks to ensure they remain up-to-date and effective. The SFC says that these areas include patching and vulnerability management, detection and monitoring measures, as well as incident response and recovery. Link to Circular here DORA Dutch AFM: Trading Systems Require Stricter ICT Risk Management Under DORA On 11 June 2026, the Dutch Authority for the Financial Markets (AFM) published a report – ‘DORA in practice: Observations and recommendations on ICT risk management framework’. The AFM says that since January 2025, European rules for digital resilience via DORA (Digital Operational Resilience Act) have therefore been fully applicable. The AFM states that it has investigated how trading platforms have set up their Information and Communication Technology (ICT) risk management framework and calls on them to consider the findings and recommendations from its thematic exploration and, where possible, to apply them in their further DORA implementation.

RkJQdWJsaXNoZXIy MTM5MzQ2Mw==