A Financial Institution’s Guide to Updated EU Market Abuse Regulation
MAR fundamentals and key shifts reshaping compliance this year
📅 July 29, 2026
📅 July 29, 2026
Picture a bank employee who overhears, in a hallway conversation, that a client’s takeover bid is about to fall through. Or a portfolio manager who gets an email a few minutes before the rest of the market learns that a company has lost a major contract. Neither of them broke into anything. Nobody handed them a folder marked “confidential”. And yet, under EU law, what they do next with that information can be the difference between a normal trading day and a market abuse case.
That is the territory the EU Market Abuse Regulation (MAR), formally Regulation (EU) No 596/2014, was built to cover. It is one of the more consequential pieces of financial regulation in Europe, and also one of the more misunderstood, because its core concepts (what counts as “inside,” what counts as “public,” when a delay is legitimate) sound intuitive right up until a real case tests them.
MAR was adopted on April 16th, 2014, and has applied across the EU since July 3rd 2016, replacing an earlier and looser directive-based regime. Its job is simple to state and hard to execute: make sure nobody trades on an unfair informational advantage, make sure companies tell the market what they know when they’re supposed to, and make sure nobody manipulates prices through fake signals or coordinated behavior.
The regulation groups this into three prohibited categories, set out in Articles 8, 10, and 12 of MAR:
The logic behind all three categories is the same. Markets only work if participants are trading on roughly the same information. The moment some of them have a durable edge because of what they know rather than how well they analyze it, prices stop reflecting reality, and investors stop trusting the system enough to put capital into it. MAR exists to protect that trust, not as an abstract principle, but because capital markets are genuinely fragile when confidence erodes.
MAR’s reach is broad. Under Article 2 of the regulation, it applies to:
Critically, Article 2(3) of MAR states that the regulation applies to a transaction, order, or behavior concerning a covered instrument whether or not it happens on a regulated trading venue at all. That “irrespective of venue” language is what gives the regulation its long reach: an off-market trade, a private transaction, even conduct outside the EU that affects an EU-listed instrument, can still fall within scope.
Per Article 2 of MAR, the regulation covers instruments admitted to trading, or with a pending admission request, on:
It also extends to emission allowances and related auctioned products, and to spot commodity contracts where trading in them could affect the price of a related financial instrument. This means a compliance team can’t simply ask “is this a listed share.” The correct question is closer to “could this instrument’s price move because of, or move, something that is covered.”
Most compliance programs built around MAR after 2016 have run on a somewhat stable set of assumptions:
However, between February and June 2026, three separate developments, legislative, judicial, and regulatory, moved all three of those assumptions at once. Institutions still working from a 2016 reading of the rules are already behind.
The EU Listing Act has amended MAR’s disclosure framework, and the revised regime entered into application on June 2026. Two changes are significant for financial institutions.
The first is that protracted processes no longer trigger continuous disclosure. Under the old regime, intermediate steps in a drawn-out process, an M&A negotiation, a restructuring, a multi-stage procurement, could each independently qualify as inside information requiring disclosure. From June 5 2026, issuers no longer have to disclose inside information tied to a protracted process until it reaches completion. That removes a real source of disclosure judgment calls, though it shifts the burden onto correctly identifying the moment a process has concluded.
The second is that the delay condition itself has been rewritten. The old test for delaying disclosure required that the delay “not be likely to mislead the public,” a standard that generated more disagreement than clarity in practice. The replacement test asks something narrower and more mechanical: “does the delayed information contradict the issuer’s own latest public statement on the same matter?” The European Commission adopted two Delegated Regulations on April 8th 2026 to put this into effect, setting out a non-exhaustive list of what counts as a “final event” in a protracted process. ESMA’s summary of the reform is clear about the intent; fewer administrative burdens for issuers, paired with clearer disclosure triggers.
Alongside this, a related update to the rules gives senior managers (PDMRs) more flexibility during closed periods, the windows when they’re normally barred from trading. That flexibility, previously limited to share transactions, now extends to other types of financial instruments too. ESMA had already addressed a related question directly, confirming on August 1st 2025 that the Listing Act’s exemption under Article 19(12a) covers PDMR participation in events like takeover bids, share capital increases, and rights issues occurring during a closed period.
Two rulings from the Court of Justice of the European Union (CJEU) , issued in March and April 2026, have changed how “inside information” gets interpreted almost as much as the legislative reforms above.
In Finansinspektionen v Carnegie Investment Bank AB (C-363/24), decided March 19th, 2026, the Court held that a routine internal notification, in this case an email telling a bank that a client had been placed on an insider list and was barred from trading, can itself constitute inside information, even without any stated reason for the listing. The Court also confirmed that information doesn’t need to later prove accurate to qualify as inside information at the time it was received; what matters is whether it was credible and plausible when it arrived. For institutions that have treated insider list notifications as internal housekeeping, this ruling raises the stakes on how those communications are handled.
In Brännelius (C-229/24), decided April 16th, 2026, the Court addressed the flip side: when does information stop being “inside information” because it has become public? The ruling ties public disclosure closely to the formal mechanisms in Article 17 of MAR and its implementing rules. Information that a diligent observer could technically access is not automatically “public” in the legal sense until it has gone out through the prescribed channels. That’s a stricter reading than many institutions have worked with, and it narrows the room for arguing information was “effectively public” without formal disclosure ever happening.
ESMA opened a consultation in February 19th 2026 proposing changes to its delay-of-disclosure guidelines to align them with the Listing Act reforms. That consultation closed on April 29th2026, and a final report with revised MAR Guidelines is expected in Q4 2026. In the meantime, ESMA continues to update its MAR Q&A document on a rolling basis as new questions arise from the amended framework.
Put plainly, institutions are being asked to comply with a materially amended framework before the supervisory guidance meant to interpret it has been finalized. That gap is worth naming explicitly in internal policy documents, rather than treating the current guidelines as the last word.
A few things are worth acting on before the Q4 2026 guidelines land:
MAR itself hasn’t been rewritten from the ground up. But the disclosure timing rules, the judicial definition of inside information, and the supervisory guidance interpreting both have all shifted within a few months this year. Treating that as routine regulatory maintenance, rather than a real recalibration, is how institutions end up carrying risk they never priced in.
Staying current on regulatory developments is one thing. Building a compliance program, and a team, that can operate under them is another.

IFI designs customized training programs for financial institutions navigating sanctions, AML/CFT, strategic trade controls, market integrity, and emerging regulatory frameworks across jurisdictions. Rather than generic compliance content, our programs are built around your institution’s actual risk profile, regulatory footprint, and the teams who need to act on it, from front-office desks to disclosure committees to senior leadership.
Get in touch with us to discuss a training program built around your institution’s needs.










This site uses cookies. By continuing to browse the site, you are agreeing to our use of cookies.
Accept settingsHide notification onlySettingsWe may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.
Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.
These cookies are strictly necessary to provide you with services available through our website and to use some of its features.
Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.
We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.
We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.
These cookies collect information that is used either in aggregate form to help us understand how our website is being used or how effective our marketing campaigns are, or to help us customize our website and application for you in order to enhance your experience.
If you do not want that we track your visit to our site you can disable tracking in your browser here:
We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.
Google Webfont Settings:
Google Map Settings:
Google reCaptcha Settings:
Vimeo and Youtube video embeds:
You can read about our cookies and privacy settings in detail on our Privacy Policy Page.
Privacy Policy