Latest News

UAE Central Bank Law Grace Period Ends as Financial Firms…

The one-year grace period for businesses to align with the United Arab Emirates’ new Central Bank law reaches its end on September 16, placing financial and technology companies under a tougher licensing and enforcement regime that can impose administrative fines of up to AED 1 billion ($272 million).Federal Decree-Law No. 6 of 2025, concerning the Central Bank, regulation of financial institutions and activities, and insurance business, took effect on September 16, 2025. Article 184 gave entities and individuals subject to the legislation one year to reconcile their positions, while allowing the Central Bank’s board to extend the period if it considers an extension appropriate.The Central Bank’s own guidance confirms the one-year reconciliation period. No general extension had been publicly announced ahead of the deadline.The legislation represents a major consolidation of UAE financial regulation, replacing the previous 2018 Central Bank framework and the 2023 insurance law with a unified regime covering banks, insurers and a broader range of technology-enabled financial services.

Virtual-Asset Payments and DeFi Enter Broader Perimeter

The changes are particularly significant for fintech and crypto-related businesses because the law focuses on the financial activity being performed rather than the technology through which it is delivered.Article 61 explicitly classifies payment services using virtual assets as a licensed financial activity. The list also covers deposits, credit and financing, open-finance services, currency exchange and money transfers, stored-value services, retail payments and digital money, as well as arranging, promoting or marketing licensed financial activities.That means using blockchain infrastructure, applications or decentralized systems does not itself remove a business from the Central Bank’s licensing perimeter where the underlying service constitutes a regulated financial activity.Pure technology providers can remain outside that perimeter where they simply provide software or technical infrastructure to licensed institutions without themselves offering financial services to customers or managing customer funds. Businesses directly or indirectly facilitating regulated services, however, may face licensing requirements depending on their activities.The law generally does not apply to the UAE’s financial free zones or institutions regulated by their respective authorities, meaning entities supervised within the Abu Dhabi Global Market or Dubai International Financial Centre remain subject to their separate regulatory frameworks.

Penalties Rise Sharply After Transition Period

The enforcement consequences are substantial. Conducting a regulated financial activity without the required licence or authorisation can carry imprisonment and a fine ranging from AED 50,000 to AED 500 million, or either penalty.The broader administrative enforcement framework allows sanctions ranging from warnings and corrective measures to restrictions on activities and financial penalties. Depending on the violation, administrative fines can begin at AED 100,000 and reach AED 1 billion, while proportional penalties can extend to as much as 10 times the value involved in a violation or the amount of unjust enrichment.The Central Bank can also publish enforcement decisions, increasing the potential reputational consequences alongside financial penalties.The deadline does not automatically invalidate existing customer contracts. Article 132 provides that regulations and decisions issued under the law do not operate retroactively against agreements entered into before their issuance, while earlier regulations, standards and circulars remain effective until replacements are introduced.For crypto, payments and fintech companies operating in the UAE outside the financial free zones, the expiry nevertheless marks an important regulatory dividing line: technology-led financial services are now operating under a framework that increasingly applies the same licensing, governance, risk-management and consumer-protection principles regardless of how those services are delivered.