The European Banking Authority is quietly turning into something it has never been before: a frontline supervisor with the power to fine. Long known as a rule-writer that left enforcement to national agencies, the EBA is stepping into direct oversight of the largest crypto issuers and critical technology providers, a shift that reaches a series of milestones through 2026.
At the centre sits the Markets in Crypto-Assets framework, known as MiCA. Under it, asset-referenced tokens and e-money tokens, essentially stablecoins, can be designated significant once their user numbers, value or transaction volumes cross defined thresholds. When that happens, supervision passes from national regulators to the EBA itself. The authority can now impose fines and periodic penalty payments on these issuers, and it has been building the machinery to set those penalties consistently, transparently and in proportion to the breach. The aim is to avoid a patchwork in which the same misconduct draws a slap on the wrist in one country and a fortune in another.
The stakes are not abstract. Stablecoins promise instant, borderless payments, but a large one that wobbles could ripple straight into the conventional banking system it sits beside. Regulators remember how quickly confidence evaporated in past crypto collapses, and they are determined that any token large enough to matter inside Europe answers to a supervisor with real authority rather than a light-touch registry.
MiCA is only part of the story. From 2026 the EBA also takes on responsibilities under the Digital Operational Resilience Act, which extends oversight to critical third-party technology providers, the cloud and software firms that banks increasingly cannot function without. A serious outage at one such provider could freeze payments across the continent, so the law pulls them, for the first time, into the supervisory net. The authority is simultaneously absorbing duties tied to margin models under derivatives rules, broadening its remit well beyond traditional deposit-taking banks.
Not everyone is applauding. Parts of the banking sector have grumbled that Europe’s capital and reporting demands are growing heavier just as competitors elsewhere ease off, and fresh operational-risk reporting templates that become mandatory from a June 2026 reference date add to the paperwork. The complaint is familiar: every new safeguard carries a compliance cost, and firms argue that piling obligations onto European institutions blunts their edge against rivals in lighter-touch jurisdictions.
The counter-argument is equally well worn. Resilience is cheaper than rescue, and a single market for finance needs a single, credible enforcer rather than twenty-seven interpretations of the same rule. By gathering crypto supervision, operational-resilience oversight and penalty powers under one roof, the EBA is betting that consistency will, over time, lower the system’s true cost. Whether that bet pays off depends on how firmly, and how fairly, the authority chooses to wield its new and unfamiliar teeth.




