Everything here is already the law. The only forecast is the direction.
Sections 01–07 are published rules and recorded enforcement outcomes, each with its primary source attached, not our opinion. Section 07 then closes with our own reading of those figures, and says so plainly. The authorities throughout are doing precisely what their mandates require of them.
Which leaves one question, and it is not rhetorical. A bank, a counterparty or an authority asks a company to account for how a raise was run. What could the company actually show, and who would have to go and find it?
Getting the perimeter wrong is criminal law, not paperwork.
Whether an activity needed a licence, whether an offer was public, whether a statement was misleading: these are answered by criminal statutes, not by internal policy. And the answer does not wait for anyone to lose money.
Sources and the detail (§)
- In Germany, offering financial services without a licence is a crime, punishable by up to five years' imprisonment (§ 54 KWG). The same provision covers unlicensed crowdfunding services under the EU regime.
- Misleading statements in investment marketing are criminal even if no investor loses a cent, and carry up to three years (§ 264a StGB).
- A public share offering without the required prospectus exposes a company to fines of up to €5 million or 3% of turnover, which are statutory maxima (§ 24 WpPG). And BaFin names suspects publicly while investigating: in December 2025 it publicly named a company on suspicion alone.
The defensible position is not the belief that the company stayed inside the perimeter. It is a contemporaneous record of how it stayed inside it: who was invited, what they were sent, what they opened, and on what date. Exedra Gate produces that record while the work is happening (whether that work is a raise or the compliance file behind it), because a contemporaneous record cannot be created after the fact.
Where does the evidence of a company's last offer live today, and could it show who received it without asking a single person to remember?
See how a raise runs on one railThis is not a German rule, or a European one.
The public offering of securities is regulated through a named competent authority in 63 countries. Counted as authorities rather than as countries there are more than 120 of them, and the difference is North America: the United States adds a securities administrator in each of the fifty states alongside the federal regulator, and Canada is commonly described as having no federal securities regulator at all, only thirteen provincial and territorial ones.
Counted as countries, 63 have a named competent authority for a public offer of securities. Thirty of them are the states of the European Economic Area, which apply one prospectus regulation between them: Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain and Sweden. The United Kingdom and Switzerland sit beside them, the United States and Canada are two more, and the count runs on through the Gulf, Asia and other markets. Counted as authorities the number is larger, and the difference is North America. The United States is one country in that count, and inside it sit the federal Securities and Exchange Commission and a securities administrator in each of the fifty states. Canada is one country, and is commonly described as having no federal securities regulator at all, only thirteen provincial and territorial ones. Counted that way there are more than 120 authorities. The two counts measure different things and are never added together.
Sources and the detail (§)
- Thirty of the 63 are the states of the European Economic Area, where the authority competent for a public offer is designated and published: Germany's Bundesanstalt für Finanzdienstleistungsaufsicht, France's Autorité des marchés financiers, Italy's Commissione Nazionale per le Società e la Borsa, Spain's Comisión Nacional del Mercado de Valores and twenty-six more (ESMA, register of competent authorities under Article 31(1)). The United Kingdom's Financial Conduct Authority and Switzerland's Eidgenössische Finanzmarktaufsicht sit beside them, and the count runs on through the Gulf, Asia, North America and beyond.
- North America is where a count of countries and a count of authorities separate. The North American Securities Administrators Association describes its own membership as "67 state, provincial, and territorial securities administrators in the 50 states, the District of Columbia, Puerto Rico, the U.S. Virgin Islands, Canada, and Mexico" (NASAA). NASAA is a voluntary association rather than a regulator and its members sit in three countries, so 67 is a count of administrators and not of jurisdictions. The two counts are therefore not added together, and the total is given as more than 120 rather than as a sum.
- A published name does not wait for a finding of wrongdoing, and that is the stated rule rather than an inference. The mechanic was examined in thirteen of these authorities and is not asserted for the rest. Where an authority states its own test, the test is suspicion: BaFin may inform the public, naming the company, of the suspicion itself, where facts justify the assumption of unauthorised business (§ 37(4) KWG), a provision that in the same breath requires the company to be heard first and requires BaFin to correct the record publicly if what it published proves wrong.
- FINMA lists companies precisely because its own findings "were inconclusive", the information it required having been refused or supplied falsely, and says plainly that being on the list "does not automatically mean that its activities are unlawful" (FINMA warning list). The FCA publishes warnings naming entities that "appear to us" to be carrying on a regulated activity without authorisation, and told Parliament this lets it act "in circumstances where our prospects for taking successful enforcement action may be limited" (FCA letter to the Minister for Pensions, 5 October 2020). The SEC states that inclusion on its public alert lists "does not mean that the SEC has concluded that a violation of the US securities laws has occurred" (SEC public alerts).
- Spanish law goes furthest of the thirteen: the CNMV may publish the opening of a sanctions procedure once the parties have been notified, with personal data removed except as regards the names of the alleged infringers, on a reasoned weighing of the public interest against the harm publication causes them (Ley 6/2023, art. 336).
- The thirteen, in full: the Bundesanstalt für Finanzdienstleistungsaufsicht (Germany), the Eidgenössische Finanzmarktaufsicht (Switzerland), the Financial Conduct Authority (United Kingdom), the Autorité des marchés financiers (France), the Commissione Nazionale per le Società e la Borsa (Italy), the Autoriteit Financiële Markten (Netherlands), the Comisión Nacional del Mercado de Valores (Spain), the Monetary Authority of Singapore, the Securities and Futures Commission (Hong Kong), the Capital Market Authority (United Arab Emirates, which replaced the Securities and Commodities Authority on 1 January 2026), the Dubai Financial Services Authority (Dubai International Financial Centre), the Financial Services Regulatory Authority (Abu Dhabi Global Market), and the United States Securities and Exchange Commission.
Two counts, measuring two different things. Sixty-three is the number of countries. More than 120 is the number of authorities, and the gap between them is North America. Neither number says anything about how any of those authorities enforces, and a figure published by one of them is not comparable with a figure published by another.
None of this is Exedra Gate's to move. Nothing in a private system changes which authority is competent, what it publishes, or when. What sits inside a company's control is narrower: whether the record of what it actually did exists in one governed place, or in five tools and an inbox spread across the countries it raised in.
If a raise reached investors in four countries, who decided which four sets of rules applied, and where is that decision written down today?
See what the record containsThe punishment that never leaves the internet.
Publication is not a side effect of enforcement. In these markets it is a substantial part of the sanction itself, and it is mandated, not discretionary.
Sources and the detail (§)
- BaFin is required by law to publish enforcement measures on its website, by name, for at least five years. Anonymity is the exception, not the rule (§ 60b KWG).
- Switzerland's highest court upheld exactly this in September 2025: five years of named publication for the operators of an unauthorised issuing house, and it held that relying on a favourable legal opinion was no excuse (TF 2C_596/2024).
- In the UK in February 2026, seven social-media influencers were criminally sentenced for promoting an unauthorised scheme. The fines were small: hundreds of pounds. The criminal record, and the named press release, are what remain.
- The five years is not one rule. Germany's banking act sets a floor: publications remain up for at least five years (§ 60b(5) KWG, above), and that floor originates in Article 71(3) of MiFID II. German securities and fund law sets the opposite, a deletion duty: publications are to be deleted five years after they appear (§ 123(5) and § 124(4) WpHG, and § 341a KAGB for funds).
- Warning lists run on a different track from the enforcement publication above, and their retention is mostly unstated. Of eleven authorities examined on the point, nine publish no removal process at all. FINMA is the exception that states one: an entry comes down "once FINMA has completed its investigations and taken any appropriate measures" (FINMA warning list). An unpublished removal process is a different finding from a stated policy of permanence, and only the first of the two is established.
Enforcement is rarely fast. It is eventual, and it is permanent. A name, once published, is findable by every future counterparty, bank, and search engine.
Nothing in a private system changes what an authority publishes, and Exedra Gate will not suggest otherwise. What sits inside a company's control is the quality of the account it can give to a bank, a board, an auditor or a counterparty, and whether that account exists as a record or only as a recollection.
If a counterparty searched a company tomorrow and asked to be walked through the raise behind it, how long would that answer take to assemble?
What happens when it cannot be shownThe money stops before the questions finish.
Precautionary measures are built to precede conclusions. That is their function. They land while everything is still open, and they land on the operating accounts a company runs on.
Sources and the detail (§)
- Germany's Financial Intelligence Unit blocked roughly €752 million in immediate measures in 2025, up from €18.8 million the year before. The largest single freeze: €585 million (FIU annual report).
- UK courts issued 2,182 account-freezing orders (£221.6 million) in the year to March 2025 (Home Office statistics).
- BaFin's President, describing one 2026 operation: "several hundred accounts" examined and frozen in a single day (annual press conference, May 2026).
What follows a measure like that is documentary: show the counterparty, the authorisation, the disclosure, the consent, the date. Companies that hold those artifacts in one governed place answer from a record. Companies that hold them across five tools and an inbox answer from memory, and from whoever still happens to work there.
Who in a company could produce the complete file for a single investor this week? And what happens to that answer when that person is on leave?
See what the rail recordsIt attaches to the person, not only to the company.
A corporate structure does not absorb all of this. A material part of the exposure is personal, it is held by named individuals, and it does not stay behind when they leave.
Sources and the detail (§)
- BaFin can demand the removal of managing directors and prohibit them from the role (§ 36 KWG).
- FINMA bans individuals from senior functions across the whole industry, for up to five years (Art. 33 FINMASA).
- In the UK, a chief executive was personally fined £1.1 million and prohibited from senior functions (Final Notice, 2025).
- Switzerland's data-protection offences target individuals (up to CHF 250,000) (revised FADP).
Personal exposure is answered with personal evidence: the approvals an individual gave, the documents they authorised, the terms they signed, each carrying a date that can be checked without their help. That record decides nothing and excuses nothing. It simply means the account of what a person did exists outside that person's memory, and outside their employment.
When an officer leaves a company tomorrow, does the record of what that person personally approved leave with them?
How the record is madeThe question can arrive a decade later.
Retention duties and limitation periods are measured in years. Corporate memory is measured in staff turnover. The distance between those two is where reconstruction happens: slowly, and in front of exactly the people a company would rather appear composed to.
Sources and the detail (§)
- German AML law requires keeping the record (including the reasoning behind decisions NOT to report) for five years, and up to ten (§ 8 GwG).
- For civil claims, the limitation clock starts when the investor learns of the problem, and the long-stop is ten years (§ 199 BGB). A raise can be questioned long after everyone who ran it has moved on.
This is the asymmetry the whole page turns on, and it is worth stating without decoration. Enforcement is eventual, and permanent. Memory is neither. A record is, provided it was made at the time and independently timestamped so that its age can be demonstrated rather than asserted.
A 2021 raise: who ran it, and are they still there to explain it?
See how a raise closesEvery number here is rising. The next rulebook already has dates.
Five cited lines, read together. Our reading of them follows the list, and is marked as ours.
Sources and the detail (§)
- BaFin's intervention measures nearly doubled in one year (72 → 140), and suspicion-warnings rose 505 → 639 (BaFin annual report 2025).
- FINMA concluded 55 enforcement proceedings in 2025, up from 38, alongside 463 investigations into suspected unlicensed activity (FINMA annual report).
- The EU's new anti-money-laundering authority, AMLA, is established in Frankfurt. It selects the 40 entities it will supervise directly during 2027 and begins that direct supervision in 2028, while the harmonised AML rulebook applies to every member state from July 2027 (AMLA).
- Switzerland's financial regulator is publicly asking for more individual-accountability powers than it has today (as reported, 2026).
- The movement is not uniformly heavier. On 5 June 2026 the European Union's Listing Act raised the threshold below which a public offer needs no prospectus at all to EUR 12,000,000 over twelve months, with a member-state option to set it at EUR 5,000,000 (Regulation (EU) 2024/2809, Arts. 1(3) and 4(3)).
That is the published record. What follows is our reading of it, and it is ours: an interpretation, not a citation. Supervisory capacity is being added, not withdrawn. A new authority has been constituted, with a mandate and a calendar, and a harmonised rulebook takes effect across every member state on a fixed date. And the one regulator on this list that is publicly asking for anything is asking for broader individual-accountability powers (FINMA, as reported above). That is not the same as every requirement getting heavier, and the Listing Act above is the counter-example: the document required at the gate got lighter, while what has to be provable afterwards did not. We read that as supervision being reallocated rather than simply increased. Read together, we think that trajectory runs one way: a heavier burden of proof, more reporting, more checks, and more sensitive personal data held about more people, tightened a little further each year, on published timetables, by institutions behaving exactly as they were designed to behave. It is what a market does once it decides that private capital deserves the scrutiny public capital has always had. We do not expect it to reverse, and we would not build a company on the hope that it might.
On that reading, the problem reduces to a single variable. A company does not choose the rules, the timing, or the questions. It chooses only whether the answer already exists on the day someone asks for it. Preparing for a trajectory like that is not pessimism. It is the response we think the record supports, and it is precisely why Exedra Gate exists.
If the questions asked in 2028 are more searching than the ones asked in 2021, and a 2021 raise can still be questioned, how many companies would be comfortable opening theirs today?
See what being prepared actually looks likeThey know how this goes
The requests for documents nobody can find. The thread that lived in a departed colleague's inbox. The months of reconstruction, in front of the counterparties a company most wants composed. Nobody who has lived it needs this page to name the cost. They need the next engagement to run differently.
Neither had they
The names on the enforcement registers are mostly not villains. They are ordinary companies that believed this happens to other people, and ran their work across five tools and an inbox until the day a question arrived that memory could not answer.
The rules above are not the company's to move. This part is.
The statutes, the timetables, the publication periods, the years a question can travel: all fixed, and none of them by the companies they reach. Whether the answer exists when someone asks for it is the one thing a company decides, and it can only be decided in advance.
So: what would a company show, and how long would it take to find?
This page describes published rules and enforcement practice, with sources, as at the dates given. It is general information, not legal advice, and not a description of any specific obligation applying to any particular reader. Exedra Gate is not a law firm and never holds or moves investor funds.