Crypto-asset advice: what the AMF’s new guidance changes for Financial Investment Advisors (CIF) ?

Keywords: CIF, crypto-asset advice, MiCA, CASP, AMF DOC-2006-23

More and more clients are asking their adviser whether they should invest in crypto-assets. Until recently, a Financial Investment Adviser (Conseiller en investissements financiers – CIF) could, in certain cases, provide guidance in this area with relative flexibility. That is no longer the case.

On 27 July 2026, the French Financial Markets Authority (Autorité des marchés financiers – AMF) updated its position-recommendation DOC-2006-23 (the document setting out its answers to recurring questions on the CIF regime) to clarify the scope of crypto-asset advice.

This update comes as the MiCA Regulation, which harmonizes the regulation of crypto-assets at the European level, is now fully applicable, and as the transitional period available to former Digital Asset Service Providers (DASP) ended on 1 July 2026.

From now on, as soon as a CIF crosses the line into personalized crypto-asset advice, it must hold authorization as a Crypto-Asset Service Provider (CASP). The question of exactly where that line falls is precisely what the AMF’s new guidance addresses.

A CIF status that does not cover crypto-assets

CIF status, governed by Articles L. 541-1 et seq. of the French Monetary and Financial Code (Code monétaire et financier – CMF), authorizes its holder to provide an investment advisory service. This service consists of giving a client a personalized recommendation (that is, advice presented as suited to the client’s situation) concerning one or more transactions relating to financial instruments (Article D. 321-1, 5° of the same Code).

The concept of a financial instrument is decisive here: it covers, in particular, shares, bonds and units in collective investment undertakings (OPC), but not crypto-assets. The AMF expressly confirms this in its new question-and-answer 2.5 of DOC-2006-23: a CIF’s advisory service covers neither crypto-assets nor services relating to them.

In practice, however, this limit was more a matter of principle than of actual practice, since DASP status offered another route. The DASP regime (Digital Asset Service Provider, corresponding to the former French PSAN status) was the French framework that regulated these players before MiCA, at a time when the term used was “digital assets” rather than “crypto-assets.” In its 2022 guidance, the AMF distinguished between two situations:

• where the CIF was itself approved as a DASP for advising subscribers of digital assets, it carried out that activity under the rules specific to that service;

• otherwise, that advice fell under the “other wealth management advisory activities” that a CIF may carry out, and was then subject only to the organizational and conduct-of-business rules of the CIF regime.

In both cases, the CIF could, in practice, advise its clients on digital assets.

This arrangement, however, rested on a temporary regime. DASPs registered or authorized in France before 30 December 2024, or providing advisory services to subscribers of digital assets before that date, could continue their activity until a MiCA authorization was granted or refused, and at the latest until 1 July 2026.

That deadline having now passed, the benchmarks set in 2022 are obsolete.

Crypto-asset advice now falls solely under the CASP regime established by MiCA. In other words, what was permitted yesterday under DASP status or under wealth management activities is no longer permitted today on that basis alone.

A broader scope of advice under MiCA

The difficulty lies not only in the authorization requirement: it also lies in MiCA’s very definition of advice, which is broader than it first appears.

Under Article 3(1)(24) of the MiCA Regulation, the provision of crypto-asset advice means offering, giving, or agreeing to give personalized recommendations to a client, whether at the client’s request or on the CASP’s own initiative, concerning one or more transactions relating to crypto-assets or the use of crypto-asset services.

This definition goes beyond investment advice as defined under MiFID II, which is limited to transactions in financial instruments: it also covers advice on the use of crypto-asset services, such as custody or portfolio management. The European Securities and Markets Authority (ESMA) confirmed this in its question-and-answer of 18 June 2026 (ESMA_QA_2882): a mere introductory service that recommends a service or a CASP without targeting a specific transaction may already constitute advice, provided the recommendation is personalized, is not addressed exclusively to the public, and is directed at an investor or the investor’s representative. The only exception is a simple reference to a CASP that is accessible in the same way to all potential investors.

In this context, the AMF warns of a risk specific to CIFs that direct their clients toward a CASP. The very fact of being a CIF may lead the client to believe that this referral stems from a personalized recommendation based on a review of the client’s situation, particularly where the adviser has already gathered information about the client’s assets in connection with an investment advisory service. The risk is then one of reclassification as crypto-asset advice, an activity for which the CIF is not authorized.

Clarification the profession had been waiting for

The entry into application of MiCA and the obsolescence of the 2022 benchmarks left CIFs without up-to-date guidance, at a time when the scope of crypto-asset advice, broader than that of investment advice, creates a risk of reclassification in the event of poorly controlled communications.

By adding a new question-and-answer to DOC-2006-23, which relays ESMA’s position and illustrates it with non-exhaustive examples, the AMF addresses this need for legal certainty and identifies certain situations in which CASP authorization is, or is not, required.

What the AMF’s position actually changes

To draw this line, the AMF reasons on the basis of a simple distinction between two categories of communications.

General communications fall outside the scope of crypto-asset advice. This is the case for educational information, marketing communications addressed to an undifferentiated public, or directing a client to the AMF’s published whitelist of authorized CASPs. Their common feature is that they do not target any particular person.

Individual communications, addressed to a specific client, call for greater caution. They remain permitted, but subject to two conditions: no personalized recommendation may be made, and the CIF must inform the client that it is not authorized to recommend crypto-assets, while referring the client to the AMF’s whitelist. Subject to this reservation, the following are notably permitted:

• simply informing a prospect, whether for payment or free of charge, of the existence of a CASP, before any wealth review or collection of information on the prospect’s personal situation;
• simply informing a client, whether for payment or free of charge, of the existence of a CASP belonging to the same group as the CIF, provided the client is duly and clearly informed of the nature of that relationship;
• a diversified asset allocation that may include crypto-assets, without any recommendation concerning a specific crypto-asset or a specific service;
• recommendations relating directly to financial instruments, even where those instruments are backed by crypto-assets (AIFs exposed to crypto-assets, index-linked debt securities), which then fall under investment advice covered by CIF status.

The options available to CIFs

To go beyond these regulated communications and deliver an actual personalized recommendation on crypto-assets or crypto-asset services, only one option remains: obtaining a CASP authorization.

Unlike investment services providers (Prestataire de services d’investissement – PSI), CIFs cannot obtain this through simple notification; they must file an authorization application and would be well advised to approach the AMF beforehand.

The requirement is, however, calibrated: the AMF specifies that authorization limited to the advisory service alone carries proportionate requirements, substantially less extensive than those attached to an application also covering, for example, the custody and administration of crypto-assets on behalf of clients.

Conclusion

The AMF’s position does not change the applicable law: it clarifies its implementation, now that the transitional period has ended. The point requiring vigilance is clear: absent CASP authorization, only a general communication, or an individual communication accompanied by the required clarifications, protects the CIF from reclassification. The dividing line between permitted communication and advice subject to authorization nonetheless remains a fine one and must be assessed on a case-by-case basis.

CIFs whose activity is moving toward recurring support on crypto-assets therefore have an interest in assessing, as of now, the merits of obtaining CASP authorization limited to the advisory service, the formalities for which remain proportionate.

AI Act: New Obligations for Employers as of 2 August 2026

In this article, Allison BENICHOU CORCHIA analyses the new obligations imposed on employers by Regulation (EU) 2024/1689 of 13 June 2024 on Artificial Intelligence (the “AI Act”). Although the deadline of 2 August 2026, initially set for the compliance of high-risk AI systems, has been postponed to 2 December 2027 under the “Digital Omnibus” package — the formal adoption of which by the Council is still pending — the date of 2 August 2026 nevertheless remains decisive.

Keywords. Artificial Intelligence, AI Act, AI systems, penalties.

Introduction

In this article, Allison BENICHOU CORCHIA, Partner in the Employment Law department of the law firm d&a partners, highlights some of the new obligations placed on companies following the adoption of the first European legal framework dedicated to AI.

AI is now embedded in many tools used in the workplace: automated recruitment, performance evaluation, data analysis and monitoring of employees’ activity. While these technologies can greatly increase productivity and deliver considerable time savings, they also raise major legal issues, particularly with regard to the protection of fundamental rights.

To address these new challenges, on 13 March 2024 the Members of the European Parliament adopted Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonized rules on artificial intelligence (hereinafter the “AI Act”), thereby establishing the first harmonized legal framework on AI within the EUROPEAN UNION.

The AI Act, which entered into force on 1 August 2024, pursues a central objective: to improve “the functioning of the internal market and promote the uptake of human-centric and trustworthy artificial intelligence”. Its application is gradual: phased in since 2025, it will continue until 2027, and even 2028 for certain high-risk systems.

This text marks an important milestone: it now imposes new — and sometimes little-known — obligations on companies whenever they use AI systems within their organization.

Pursuant to Article 3 of the Regulation, its rules apply to “any natural or legal person, public authority, agency or other body using an AI system under its authority”. The European Regulation on AI imposes several specific obligations on employers in their capacity as deployers of AI systems.

Employers, as deployers of AI systems, are thus subject to several specific obligations, in particular where they use these technologies in the context of recruitment, performance evaluation, decision-making concerning employees or the monitoring of employees’ activity.

This article will successively address the classification of AI systems adopted by the Regulation (I) and the obligations it imposes on employers (II), before considering the risks in the event of non-compliance (III).

I/ A Risk-Based Approach: Classification of AI Systems

The European Regulation is based on a graduated approach: the more the use of an AI system is likely to affect fundamental rights, the more demanding the resulting obligations.

The AI Act thus distinguishes four levels of risk, each entailing specific requirements for employers, which should not be overlooked and should be anticipated as of now.

1/ Prohibited AI Systems

Since 2 February 2025, practices deemed unacceptable by the AI Act have been prohibited. Eight practices are thus banned, including social scoring systems and emotion recognition in the workplace (except for medical or safety reasons).

2/ High-Risk AI Systems

These include, in particular, employee evaluation tools, automated recruitment systems, algorithmic work management systems, and systems likely to affect an employee’s career or employment contract.

3/ Limited-Risk AI Systems

These are subject to transparency obligations, owing to the risks of manipulation or deception they present. They include chatbots, AI-generated content and deepfakes: users must be informed that they are interacting with an AI or that content has been artificially generated.

4/ Minimal-Risk AI Systems

Most AI systems fall into this category, such as recommendation systems, spam filters or video games. They are not subject to any specific obligation under the Regulation.

II/ Enhanced Obligations for Employers

Beyond the classification of systems, the AI Act imposes on employers a set of cross-cutting obligations, some of which are already applicable.

The first obligation, in force since 2 February 2025, consists of ensuring a sufficient level of AI literacy. Article 4 of the Regulation on Artificial Intelligence, entitled “AI literacy”, thus establishes a general training obligation for providers and deployers of AI systems. As a result, companies are required to train users in the AI tools deployed within their organization.

The text provides that “Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used”.

The objective is to ensure that everyone involved with AI systems within the company has the skills and knowledge required to make informed decisions and use these systems responsibly.

The AI Act lays down new obligations for employers, depending on the risk level of the AI system.

Limited-risk systems must comply with a principle of transparency and a principle of information, which consists in particular of notifying users that they are interacting with an AI and providing users with clear information about AI-generated content.

The following have been classified as high-risk systems under the AI Act: automated recruitment tools, employee evaluation or scoring systems, algorithmic work management tools, and decision-making tools affecting an employee’s career or employment contract. Consequently, these systems will have to meet strict requirements. Initially set for 2 August 2026, the entry into application of these obligations is in the process of being postponed to 2 December 2027 under the “Digital Omnibus” package, the formal adoption of which by the Council is still pending to date.

These systems will have to be subject to effective human oversight: designed by the provider to enable human control (Article 14 of the Regulation), they will have to be overseen, on the employer’s side, by people who have the necessary competence, training and authority (Article 26 of the Regulation). This requirement operates alongside Article 22 of the GDPR, which already governs fully automated decisions producing legal effects with regard to employees.

Article 26 of the Regulation further requires the employer-deployer to inform workers and their representatives before putting a high-risk AI system into service in the workplace (paragraph 7), as well as the persons subject to a decision involving such a system (paragraph 11).

These requirements are accompanied by obligations relating to the traceability of the system’s operation and of the data used, documentation, and the provision of information to employees and their representatives.

III/ Risks in the Event of Non-Compliance with the AI Act

The AI Act does not merely establish a theoretical framework. It also provides for particularly significant financial penalties in the event of non-compliance with the obligations it lays under.

Companies and other economic operators that develop, market or use prohibited AI systems are exposed to particularly severe financial penalties.

The AI Act provides for administrative fines of up to EUR 35 million or where the offender is a company, up to 7% of its total worldwide annual turnover, whichever is higher.

Non-compliance with the other obligations established by the Regulation is also subject to substantial financial penalties: Article 99 of the Regulation provides for a fine of up to EUR 15 million or, for a company, up to 3% of total worldwide annual turnover, whichever is again higher.

For SMEs and start-ups, however — and this is good news — it is the lower of the two amounts that applies.

In light of these new requirements introduced by the AI Act, companies must therefore adopt a resolutely proactive approach in order to secure their practices.

The first step is to carry out a precise audit of the tools in use, in order to identify the AI systems, present within the company and to assess the scope of the resulting obligations.

It is then up to employers to assess the risks associated with their use, in light of the classification adopted by the Regulation and the potential impact on employees’ rights.