There is no global crypto regulator and no prospect of one. What exists is a set of national and regional regimes that reached different answers to the same three questions, and knowing which three they are makes any unfamiliar jurisdiction readable in an afternoon.
The first is classification: is this thing a security, a commodity, a payment instrument or something new? The answer determines which authority has jurisdiction and which disclosure regime applies, and it is the question jurisdictions disagree about most. A token treated as a security must be registered or exempt before it is offered to the public; the same token treated as a commodity falls under a market-conduct regime instead; treated as a payment instrument it becomes a licensing question about handling money. Nothing about the asset changes — only the shelf it is put on.
The second is intermediary licensing: who may hold customer assets, run a trading venue or exchange crypto for national currency, and on what conditions. This is where the rules that actually protect a retail customer live — segregation of client assets, capital requirements, governance, complaints handling, and whether the firm may trade against its own customers. It is also the most portable part of the picture, because these obligations look broadly like the ones already imposed on payment firms and brokers.
The third is anti-money-laundering, and it is the one area with genuine international convergence. The Financial Action Task Force's Recommendation 15 brought virtual asset service providers into the same perimeter as other financial institutions, and its travel rule — originator and beneficiary information must accompany a transfer above a threshold — has been implemented, at differing speeds and thresholds, across most of the membership. This is why identity verification is near-universal on regulated platforms wherever they are.
The regimes then differ mainly in how the answers arrived. Some legislated a comprehensive framework: the European Union's MiCA is the clearest example, a single licensing regime that passports across the bloc. Some built on existing financial law with targeted amendments, which is broadly the path taken in Japan and Singapore, where exchanges are licensed under payment services legislation, and in Switzerland, where distributed-ledger amendments were threaded through existing statutes. Some created a dedicated authority — Dubai's virtual assets regulator is the most-cited case. And some, most consequentially the United States, have proceeded largely through enforcement and litigation, so the rules were established case by case rather than published in advance.
Two practical consequences follow for a reader. Extraterritoriality is real: obligations follow the customer as well as the firm, so tax residence and securities law can reach an account opened offshore, and a platform's licence somewhere else is not a licence where you live. And the check that matters is always the same regardless of jurisdiction — find the regulator's own published register, search the exact registered corporate name rather than the brand, and treat an entity that cannot tell you which licensed entity it operates under as having answered the question.