Back to All Posts
The Business Model Question Hiding Inside Stablecoin Regulation

The Business Model Question Hiding Inside Stablecoin Regulation

Most regulatory coverage of stablecoins has focused on a single question: who is allowed to issue them? The answer is now largely written in five major jurisdictions. Less attention has gone to the question that follows immediately from it: once you have the licence, what else are you allowed to do?

That second question turns out to matter more than the first. A new brief from the Bank for International Settlements' Financial Stability Institute, published in August 2026, maps the activity rules for stablecoin issuers across the EU, Hong Kong, Singapore, the UK and the US, and finds that while frameworks broadly agree on what the core business looks like, they diverge sharply on what issuers may do beyond it. That divergence is already shaping who can build a profitable stablecoin business and where. We focused on the issuer entity and activity dimensions of the BIS analysis, rather than its reserve composition or systemic oversight sections, because these are where competitive outcomes are most directly determined.

The market is set, the rules still are not

The stablecoin market has plateaued at roughly USD 300-320 billion since October 2025, according to the BIS brief, with two issuers accounting for about 90% of total market capitalisation. That concentration is the backdrop against which new frameworks are coming into force, each designed to create room for new entrants while managing the risks that the existing, largely unregulated incumbents have already introduced.

The timing is unusual. Five major frameworks are finishing simultaneously: the EU and Hong Kong regimes are in effect; the UK published its final policy statements in June 2026; the US GENIUS Act is law but its implementing rules from the OCC and FDIC are still being finalised; and Singapore is reviewing its positions ahead of a further consultation. The FSB's October 2025 thematic review found significant gaps and inconsistencies in how jurisdictions have implemented agreed standards, meaning this is a moment of formal convergence that coexists with ongoing practical divergence.

Banks get the bigger box

The most structurally significant finding is that bank and non-bank issuers operate under fundamentally different activity rules, and the difference is not incidental.

Where banks issue stablecoins directly under an existing banking authorisation (as in the EU), their ability to engage in lending, proprietary trading, custody and related activities is governed by their banking licence rather than by stablecoin-specific restrictions. The reasoning is explicit: a bank's existing prudential framework already addresses the risks those activities create, so overlaying stablecoin-specific restrictions would be redundant. Where a bank must issue through a subsidiary (as in the UK and the US), that subsidiary is subject to the stablecoin regime's own activity restrictions, but the wider banking group still operates under consolidated supervision.

Non-bank issuers get a much narrower initial position. All five frameworks restrict or effectively prohibit lending, staking, proprietary trading and custody of third-party assets for non-bank issuers. The question is how those restrictions are constructed, because the construction matters.

Two models, two very different implications

The BIS brief identifies two approaches to non-bank activity restrictions.

Under a restrictive model, the issuer is limited to a closed list of permitted activities. Everything outside the list is implicitly prohibited. The US applies this through the GENIUS Act, which names issuance, redemption, reserve management and a narrow exception for separately authorised digital asset services. Singapore applies it through explicit prohibitions: MAS-regulated stablecoin issuers are expressly banned from lending, staking and related activities.

Under a constrained model, the issuer is not prohibited from expanding its activities, but each additional activity requires separate authorisation, supervisory consent or compliance with the applicable sectoral regime. The EU, Hong Kong and the UK all follow this approach, though the mechanics differ. In Hong Kong, non-bank licensees need the HKMA's consent for any business beyond their licensed stablecoin operations. In the UK, activities like safeguarding of qualifying cryptoassets are separate regulated activities requiring FCA authorisation. In the EU, the rules differ between credit institutions and e-money institutions.

The practical difference is significant. The closed-list model is clearer but requires legislative or regulatory changes to accommodate new activities. The constrained model is more flexible but places a continuous supervisory load on both the issuer and the authority, and creates uncertainty about what any given expansion will require. Neither approach obviously dominates, and the choice reflects different positions on how much operational flexibility an issuer needs to build a viable business.

The loophole no framework has closed

The brief's sharpest observation is about what all five frameworks have in common: activity restrictions apply to the issuing entity, not to the wider corporate group.

This means a non-bank stablecoin issuer that is prohibited from lending can have a sister company in the same group that lends. Singapore makes this explicit in its published guidance, clarifying that prohibited activities may still be conducted by related entities in which the stablecoin issuer holds no stake. The other four jurisdictions produce the same result in practice, even where they don't state it as clearly.

For banks, this gap is largely closed through consolidated supervision, intragroup exposure limits and operational resilience requirements that apply across the group. For non-banks, no equivalent group-wide framework exists, and the entity-level restrictions can be circumvented through corporate structure. The BIS brief argues this suggests frameworks may need to extend some form of group-level oversight to non-bank issuers, particularly larger ones where the financial stability concerns are most pronounced.

This is a genuine policy gap rather than an oversight. Building group-level prudential supervision for non-banks is a significant undertaking, and regulators have been cautious about moving faster than the market warrants. But the brief is signalling that the gap is now visible and that the current entity-only approach may not hold as issuers grow and group structures become more complex.

Other differences worth tracking

The brief surfaces several additional divergences that don't make headlines but carry operational weight.

On self-custody of reserve assets, the US and EU allow it subject to segregation requirements. Singapore prohibits it entirely, requiring reserves to be held with external custodians. The UK allows intragroup custody up to 20% of the reserve pool, with the ability to exceed that limit under specific conditions for non-systemic issuers. Hong Kong is silent on the question.

On redemption timelines, the EU requires redemption "at any time," meaning continuously. Hong Kong and the UK mandate next-business-day completion. The OCC's proposed US implementing rules propose two business days. Singapore allows five business days. These aren't just operational parameters. They reflect different models of what stablecoins are for: the EU's approach treats them unambiguously as payment instruments where immediate redeemability is part of the product; the longer windows in other frameworks leave more room for treasury management.

On interest payments to holders, the EU, HK, UK and US all explicitly prohibit them. Singapore doesn't directly prohibit them but the broader activity restrictions for issuers effectively foreclose the arrangements that would make them possible. This is a shared policy choice to keep payment stablecoins distinct from yield-bearing investment products, though the EU is already reconsidering its position as part of a MiCA review.

On multi-jurisdictional issuance, only Singapore explicitly addresses it, prohibiting an MAS-regulated stablecoin from being issued simultaneously in other jurisdictions. The other four frameworks are silent, meaning a single token could in principle be fungible across borders under multiple issuer authorisations, with unresolved questions about how reserves are allocated across markets and how supervisory responsibilities are shared. The BIS brief flags this as a gap that becomes more significant as issuance scales.

What this means for each group

For banks evaluating stablecoin issuance: the activity question needs to be part of the initial structure decision, not an afterthought. Whether issuance runs directly from the bank or through a subsidiary determines which activity permissions apply to the issuing entity, and the two positions are not equivalent.

For non-bank issuers: the choice of jurisdiction shapes not just the licence requirements but the business model that is possible within the regulated perimeter. A closed-list regime offers clarity but requires lobbying or regulatory engagement to expand. A constrained regime offers more flexibility but requires ongoing supervisory relationship management for each new activity.

For group structures: the entity-level gap is currently available but is already visible to regulators. The brief's policy recommendation is explicit that group-level oversight for non-banks is coming. Building compliance infrastructure at the entity level only may underestimate the eventual scope of the requirements.

For regulators: the brief makes the cross-border multi-issuance gap a formal priority. Frameworks that have been silent on whether the same token can be issued across jurisdictions will need to address the reserve allocation and supervisory coordination questions before cross-border fungibility creates obligations that no single authority has the tools to enforce.

The two chapters of stablecoin regulation

Stablecoin regulation has had two chapters. The first is mostly written: it covers who may issue, what the token must look like, and what reserves must back it. Tracking that chapter is what the Stablecoin Regulation Tracker was built for across 200+ markets.

The second chapter is what issuers are allowed to do with the business they've built. The BIS brief is the clearest mapping yet of where that chapter stands across five frameworks, and the answer is that it's being written differently in every jurisdiction. The bank/non-bank asymmetry in activity permissions isn't a regulatory inconsistency. It reflects a deliberate choice about which entities already have sufficient prudential oversight to manage broader activities safely. But for non-banks, the group-level loophole means the entity restrictions that are supposed to manage that risk may not reach far enough. That is the open question that is going to define the competitive landscape once the licensing dust settles.


Source: "Regulating stablecoin issuance: permissible entities and activities," FSI Briefs No 33, Adrien Currat, Johannes Ehrentraud and Denise Garcia Ocampo, Financial Stability Institute, Bank for International Settlements, August 2026. Market size and concentration figures drawn from the source report, which attributes them to Adrian et al (2025) and FSB (2025). This post focuses on the issuer entity, activity permissibility and group-level oversight sections of the brief rather than its reserve composition or systemic designation analysis.

This article is for informational purposes only and does not constitute financial, investment, or legal advice.