Regulation is not receding. It is consolidating.
Exedra Gate is where the proof is built, while the work is happening.
Exedra Gate holds no money, advises nobody, ranks nothing and matches nobody. Funds move only between the parties and their licensed institutions.
The dates are published. None of them are projections.
Two of these milestones have already been reached and three have not. Since 17 January 2025, DORA has bound financial entities across the Union. AMLA is operating in Frankfurt now. During 2027, AMLA selects the 40 cross-border groups it will supervise directly. From 10 July 2027, one harmonised anti-money-laundering rulebook applies directly in every member state. In 2028, that direct supervision begins. Sources for each are linked in the list that follows.
Each date, and the regulation that sets it 4 sources
Supervision in Europe is gaining institutions, not losing them. Each entry below is a fixed, published fact with its primary source attached. Read together, they describe a direction that has not reversed in a generation.
- SINCE 17 JANUARY 2025
DORA applies. The Digital Operational Resilience Act binds financial entities across the Union: banks, insurers, investment firms and their critical ICT providers, with incident reporting and resilience testing as supervised obligations (Regulation (EU) 2022/2554, Art. 64).
- OPERATING NOW
AMLA is seated in Frankfurt. The EU's new Anti-Money-Laundering Authority exists, with a mandate, a budget and a calendar: common supervisory standards, joint supervisory teams with national authorities, and peer review of those authorities (AMLA).
- FROM 10 JULY 2027
One AML rulebook, every member state. The harmonised anti-money-laundering regulation applies directly across the Union, replacing national transpositions with a single text (Regulation (EU) 2024/1624).
- 2027 AND 2028
Direct supervision begins. During 2027, AMLA selects the 40 cross-border groups it will supervise directly; that supervision starts in 2028. The floor rises for everyone else through common standards and peer review (AMLA).
What changed when the proof moved onto the company
The workload has moved onto the economy. A supervisor no longer needs to reconstruct what a company did; the company is expected to produce the reconstruction itself, complete, dated and attributable, years after the fact. The documents are getting lighter. The burden of proof is getting heavier.
That changes what preparation is. Two companies subject to the same rules are separated by one property: what each can show on the day it is asked. Preparation has become a competitive property, in diligence, in audits, in disputes, and in the ordinary business of being believed.
- Counted as countries
- 63
- each with a named competent authority for a public offer of securities
- Counted as authorities
- More than 120
- the difference is North America, and the two counts are never added together
None of this is a German rule, or a European one. The count, the sources and the reason the two figures differ are below.
How the perimeter is counted, and why the two counts differ
None of this is a German rule, or a European one. The public offering of securities is regulated through a named competent authority in 63 countries. Thirty of them are the states of the European Economic Area, each authority designated in a register ESMA publishes (ESMA, register of competent authorities under Article 31(1)), and the count runs on through the United Kingdom, Switzerland, the Gulf, Asia, North America and beyond. Counted as authorities rather than as countries there are more than 120, because the United States adds a securities administrator in each of the fifty states alongside the federal regulator, and Canada is commonly described as having no federal securities regulator at all, only thirteen provincial and territorial ones (NASAA).
Counted as countries, 63 have a named competent authority for a public offer of securities. Thirty of them are the states of the European Economic Area, which apply one prospectus regulation between them. The United Kingdom and Switzerland sit beside them, the United States and Canada are two more, and the count runs on through the Gulf, Asia and other markets. Counted as authorities the number is larger, and the difference is North America. The United States is one country in that count, and inside it sit the federal Securities and Exchange Commission and a securities administrator in each of the fifty states. Canada is one country, and is commonly described as having no federal securities regulator at all, only thirteen provincial and territorial ones. Counted that way there are more than 120 authorities. The two counts measure different things and are never added together.
The enforcement record behind these calendars, statute by statute and figure by figure, is kept on its own page. The risk, sourced.
Five failures, named precisely. None of them require bad intentions.
The public offer that was never meant to be one Reg. 2017/1129
A founder posts his round on LinkedIn. A newsletter reaches five hundred contacts. Concrete terms are discussed at an open industry evening. Under the EU prospectus regime, an offer that leaves the private perimeter can be prohibited, and the decision published with the company's name: fines, possible personal liability, possible investor rescission (Reg. (EU) 2017/1129, Art. 1(4)). Nobody had bad intentions. They did not know, and the burden of proving the exemption sits with the offeror.
The memory problem: four years later, nobody agrees what was said
An investor states that he never received the report and that nobody named the risk. The company knows it informed him. Knowing is not proving, and in these disputes the burden of proof tends to sit with the firm. When money is lost, memory changes. The file does more work than the recollection, and an absent file is the other side's best argument. The case patterns, with sources.
Fragmentation: the proof lives between the systems
Five tools, five formats, five sets of timestamps. Signing in one system, identity in another, the data room in a third, the cap table in a spreadsheet, the thread that connects them in an inbox. The proof lives between the systems, where nobody is responsible for it, and a reconstruction assembled by hand can be attacked precisely because it was assembled.
Data sovereignty: every extra jurisdiction is a standing liability
One vendor stores in the United States, one in Sweden, one in Asia. Each location needs a legal basis, a privacy-policy entry, a processor agreement, a search on every subject-access request and a purge on every erasure. Europe is pulling its data home, and every additional jurisdiction is a standing liability that renews itself annually.
Language: a translation nobody governed is a second document
Contracts, reports and disclosures exist in two or three languages that nobody reconciled. The versions quietly diverge, and years later each party holds the copy that favours its own recollection. A translation nobody governed is a second document, not the same one.
A closed room, where the work becomes its own proof.
Issuer and investor speak inside the system rather than in an inbox. Identity checks, the data room, contracts, signatures, deadlines and reports run in one flow, and everything that happens becomes proof as it happens. Nobody writes the protocol afterwards.
An invitation, an identity check, a contract, a signature and a data-room access arrive in order, each carrying a fingerprint, thread onto one chain, and close in a final entry carrying an independent timestamp. The same chain continues past that entry: an investor update, its opened and read receipts for each recipient, a question answered inside the room, an appointment and its reminder, an obligation met alongside the artefact that proves it, a certified translation beside the original, and finally the exit, where every record leaves with the client.
A reviewer can confirm, with free standard tools, that the documents are unchanged and existed at the stated moment. The timestamp comes from an independent authority. How the chain and the timestamp work.
Closing ends a raise. It does not end the record.
The room stays open afterwards, and the entries keep arriving: investor updates that show sent, opened and read for each recipient, with prefilled questions coming back; secure messaging inside the room, with a polite email follow-up when a message goes unanswered; appointments, reminders and a calendar feed; obligations and deadlines carried alongside the artefact that proves each one was met; certified translations delivered beside the original rather than instead of it. If the relationship ends, the client leaves with every record.
A signature is given on the phone in the counterparty's pocket, wherever he happens to be. The Exedra Gate app is arriving, and will carry the same room onto the device itself.
One place, and the client decides where that place stands
The answer to fragmented storage is not another vendor. It is one place with one legal basis, deployed where the client's obligations point: as a managed service, as a white-label deployment on a server of the client's choosing, in Germany, in Switzerland, or inside the client's own data centre. Where four vendors meant four legal bases, four processor agreements and four registers to search, one place means one.
Custom features are built on request for clients who need them. That is a plain fact about how Exedra Gate works with institutions, and it is quoted and delivered as an engagement rather than configured from a form. Deployment models, stated.
Inside the room, discovery arrives as a byproduct
Verified investors already inside the system can see which rounds are open, with green and infrastructure assets prominent among them. The issuer decides visibility, raise by raise; every raise begins invitation-only. Nothing is ranked, nothing is recommended, nothing is promoted. The platform presents; the investor concludes. How visibility is controlled.
The compliance rail is live in production today. Global visibility is in build and opens to founding clients first; investors invited by an issuer are onboarding now.
A filmed walkthrough is in production.
The film records one engagement end to end on a live system: the invitation, the identity check, the contract, the signature taken on a phone, and the evidence pack checked afterwards by a reviewer.
A screening claim, never an endorsement.
The badge attests the check, never the investment: screened as of a date; no adverse matches surfaced in the checked sources. It is not investment advice, not an endorsement, and not a guarantee.
What the screening actually covers
Exedra Gate screens an issuer: the company, its directors, its beneficial owners. Ownership above 25% is declared under signature and corroborated where public registers permit. Re-screening on a defined rhythm is part of the engagement while the certificate stands, and a person approves every finding.
Time will show who was prepared.
The questions arrive on their own schedule, usually about work done years earlier, and they are answered from records or from memory. Access is by invitation, and a short note on the company and its situation is enough to start.