In January 2026 I published six lessons for firms entering the UK’s Digital Securities Sandbox. Since then I have helped a UK-based fintech with their regulatory submissions for a new CSD and CCP, and I have watched AI capability move faster in six months than in the previous two years.
With the FCA’s gateway for qualifying stablecoin issuers opening on 30 September 2026, it felt like the right moment to revisit those lessons: which ones still hold, which have shifted, and what six months of building has taught me that wasn’t in the original list.
The original lessons appear in italics. The updates follow.
1. Versioning Matters More Than You Think
A credible regulator-first strategy lives or dies on the quality of your submissions: internal consistency across documents, coherence between architecture, governance and operating model, and a clear understanding of what has changed since the last submission, and why. You don’t just need documents. You need a model of your ecosystem.
This has only got more important.
Parts of a submission get reused in other parts. Policies and rulebooks get quoted into self assessments. And you cannot simply make it sequential, finishing the policies and then attesting against them, because answering the attestations feeds back into the policies themselves.
Nor can you hand the problem to your favourite LLM. Asking one to check consistency across a full submission is flaky, because it cannot hold all the documents in its context window at once.
The serious answer is to generate the documentation from a single, fully consistent model. If the source is consistent, the outputs are far more likely to be.
2. It’s the Ecosystem, Not the Organisation
DLT initiatives are inherently multi-organisational. A large proportion of your risk sits in the supply chain of your supply chain. Ecosystem risk management becomes central, not optional, and Important Business Services only make sense beyond the legal entity boundary.
Regulatory focus on supply chain risk has sharpened considerably. Understanding your suppliers, and their suppliers, and so on down the chain, is now essential, especially for anything deemed a critical supplier.
One addition worth making: think about the correlation of risks between suppliers. If everyone in your ecosystem uses AWS, an outage does not just affect you, it affects your partners, your fallbacks and your recovery options all at once. Concentration risk compounds precisely when you need diversity most.
3. Regulatory Perimeter Creep Is Real
There is a natural desire to keep regulatory focus on a single entity within a group. In practice, this rarely holds. An entity becomes a critical intra-group supplier, arm’s-length arrangements come under scrutiny, and each new piece of supervisory guidance pulls more of the group into scope.
Here is a rare piece of good news: this one may actually get easier.
There is growing acceptance of how to handle “services” firms, entities in a group structure that provide common services to several other entities in the group. The direction of travel is that these services firms may not automatically get dragged into the same regime by default.
The underlying advice stands, keep your group structure, service models and contracts regulator-ready, but the default assumption of creep is softening.
4. Static Operating Models Are Expensive, Dynamic Digital Twins Are Invaluable
Regulatory approval requires vast amounts of documentation. Too often it is produced by external experts, delivered as static artefacts, and filed away the day after submission. That is an extraordinarily fast-depreciating asset. Static documents cost money. Dynamic digital twins create leverage.
The FCA has published the information it expects in the application form, and it is substantial: business model, governance, prudential arrangements (a £350,000 permanent minimum requirement for issuers, before fixed overheads or K-factors), backing asset management, redemption, safeguarding.
What has changed is the speed of modelling all of this, and the change is entirely down to AI. In 2023, process modelling, the policy hierarchy and the creation of risk and control registers took months. In 2024 that had shortened to weeks, using RAG and the LLM APIs. In 2026 it can be produced in a morning, using Claude and RegDefy’s MCP server.
The obvious question is quality. And the answer is that it is excellent, because Claude aligns much better with regulations, attestations and maturity models than earlier generations did.
5. Identify Everything. Model Only What Matters.
Ecosystems are messy. You could model forever. Don’t. Identify everything: systems, processes, controls, parties. Then model a critical subset in depth. The discipline here is brutal prioritisation. Waste is the enemy.
The principle stands, but the economics underneath it have moved.
With Claude as your modeller, much more of the digital twin can be modelled for the same effort, giving a far richer articulation of the ecosystem. The “critical subset” can simply be bigger.
More interesting still: rebuilding your model in the light of new information, a review, regulator feedback, a clarification, a change of direction, is now a realistic option rather than a last resort. When the cost of refactoring drops, agile principles come into play. You stop defending an ageing model because it was expensive to build, and start treating rebuilds as routine.
6. The People Model Unlocks Everything
Nothing clarifies an ecosystem faster than mapping the teams of people within it. A proper people model prevents the senior leadership team, or worse, the CEO, from “owning everything”, enables federated accountability, and starts to define roles, responsibilities and decision rights organically.
The FCA has been unusually direct about what it is assessing: not perfect firms, but credible, capable leadership teams who understand how the rules apply to their business, how roles integrate within the governance framework, and how operational risks are managed.
Federating ownership out is the key to embedding the model into the organisation, and it is what converts an operating model into a digital twin. Once the KRIs are defined, assign owners. From that point, every team member can use Claude to query what they need to do, and an overdue KRI reading appears in its owner’s overdue items list. Accountability stops being a diagram and starts being a to-do list.
7. The AI Warning – NEW
This one was not on the original list, because six months ago the problem barely existed.
As content production gets easier, and creating a 20 page BYOD policy is now one click, the bottleneck moves to reviewing. The review process is where hallucinations and misunderstandings get caught, and it cannot be skipped.
But here is the trap: reviewing is done by your most senior people. So as production accelerates, the cost concentrates upwards, and the load lands on exactly the people with the least time.
The main answer is to use multiple LLMs in a maker/checker configuration, one model producing, a different model challenging, before a human ever sees the draft. These feedback loops are the key to speeding the whole process up even further, without letting quality quietly collapse.
Final Thought, and a Call to Action
The original closing line was: regulation doesn’t kill innovation, poor models do. Six months on I would add a corollary: AI doesn’t remove the work, it moves it. The firms that thrive through the stablecoin gateway will be the ones that know where the work went.
If you are preparing an application for the window opening on 30 September 2026, this is the moment to get ahead of these issues. A short conversation now can save months of remediation later. Get in contact.
