Jul 13 2026
International Protection, White Collar Crime
Home
News and Insights
The potential imbalance between US and UK criminal jurisdictional reach — Part 3
Reading time: 6 min
In the first article in this series, we considered a familiar but uncomfortable question: why can the United States sometimes appear able to reach conduct that the United Kingdom could not, or would not, prosecute itself? The example was insider dealing, where the UK criminal offence under the Criminal Justice Act 1993 has carefully drawn territorial limits, whereas US prosecutors may frame broadly similar conduct through securities fraud, wire fraud, conspiracy, and other routes where a sufficient US nexus is alleged.
In the second article, we considered the Supreme Court’s decision in El-Khouri v Government of the United States of America [2025] UKSC 3, which went some way to correcting that imbalance in extradition cases. The Court’s essential point was simple, but far-reaching: for the purposes of the dual criminality test in section 137 of the Extradition Act 2003, the question is where the requested person’s relevant conduct occurred, not merely where its effects were felt. Conduct carried out in London does not become conduct carried out in New York simply because the alleged market effect was felt there.
This third article in the series asks a related, and perhaps more novel, question: after El-Khouri, will the battleground shift from “effects” to “infrastructure”? In other words, if a requesting state cannot simply say that overseas conduct had domestic effects, might it instead argue that the case is domestic because some apparently routine part of the transaction touched its financial, technological, or communications infrastructure? We examine this question also in light of new technology to store and transfer value, specifically cryptoassets.
Modern financial crime rarely happens in one place. A trader may sit in London, message a contact in Dubai, execute a trade through a UK broker, reference securities listed in New York, fund the account from Switzerland, and route data through servers no one has ever consciously thought about. Crypto cases add another layer: wallets, exchanges, validators, protocols, cloud services, IP addresses, stablecoin issuers, and blockchain analytics providers may all point to different jurisdictions.
This creates an attractive argument for prosecutors. Even if the human conduct took place outside the requesting state, some part of the infrastructure may have passed through it. A payment may have cleared through a US correspondent bank. An email may have passed through a US server. A messaging app may be operated by a US company. A stablecoin may be issued by a US-linked entity. A trade may have referenced a US issuer. A crypto exchange may have used US compliance systems or liquidity providers.
The question then becomes: in the circumstances, is that enough?
After El-Khouri, at least for the purposes of the UK extradition dual criminality analysis, the answer should often be: not by itself. The Supreme Court drew a distinction between the substance of the alleged criminal conduct and incidental factual details. In that case, payments were alleged to have included hotel rooms in New York, but the Court treated those facts as incidental rather than sufficient to make the conduct occur in the United States. The substance of the alleged insider dealing scheme took place elsewhere.
That distinction may become increasingly important.
There is a useful way to think about the problem. In cross-border financial crime cases, alleged connections with the requesting state often fall into three broad categories.
First, there are effects. These are consequences felt in the requesting state: market impact, investor harm, movement in the price of listed securities, or alleged damage to the integrity of a domestic market. El-Khouri makes clear that effects alone do not determine where the requested person’s conduct occurred for the purposes of section 137 of the Extradition Act 2003.
Second, there is infrastructure. These are the systems through which modern transactions pass: wires, servers, exchanges, clearing systems, payment rails, custodians, and communications platforms. Infrastructure can matter, but only if it forms part of the conduct alleged to constitute the offence, rather than being an accidental or incidental route by which information or money travelled.
Third, there is conduct. This is what the requested person actually did: where they made the agreement, sent the instruction, placed the trade, received the information, acquired the asset, used the proceeds, or possessed the relevant property. After El-Khouri, this is the category that should matter most when deciding whether conduct occurred in the requesting state or outside it. The Supreme Court emphasised that section 137 distinguishes between conduct occurring in the category 2 territory and conduct occurring outside it; where the conduct is outside the requesting state, the more demanding extra-territorial dual criminality test applies.
This distinction is not merely academic – it may decide whether someone is extradited.
Crypto is incredible fertile ground for jurisdictional overreach because almost every transaction is multi-jurisdictional if one looks hard enough. A token may be notionally decentralised, but the user interface may be hosted by a US company. The protocol may be governed by a foundation in Switzerland. The stablecoin leg may involve a US issuer. The exchange account may be offshore but use US dollar banking payment rails. The blockchain may be validated globally. The suspect may be in London throughout.
Indeed, this is a topic we have previously discussed in great detail
Can I be extradited for allegations involving crypto? Extradition and crypto
If prosecutors can rely on any one of those links as making the case “American”, “British”, or otherwise domestic, then jurisdiction risks becoming almost limitless. That would be precisely the type of over-expansion that dual criminality is designed to restrain in the extradition context. The UK test is not whether the requesting state has a plausible policy interest in the case – it is whether the statutory conditions for extradition are met.
The same point arises under POCA. In El-Khouri, the Supreme Court also considered the territorial scope of section 329 of POCA. It rejected the argument that section 329 criminalises acquiring, using, or possessing criminal property abroad merely because the property derives from criminal conduct abroad. The Court clarified that the acquisition, use, or possession must itself occur in the United Kingdom. Section 340(11)(d) defines “money laundering”; it does not expand the territorial reach of the substantive offences in sections 327 to 329.
That POCA point matters because it resists a similar temptation: treating the global movement of value as enough to create domestic criminality. Foreign criminal conduct may generate criminal property, but the statutory offence still requires careful attention to the location of the relevant act.
The next wave of cases may not be about whether effects are enough – El-Khouri has made that harder. The more interesting fight may be about what counts as merely incidental.
A hotel room in New York was incidental. But what about a US bank account used to pay a bribe? What about a US-based exchange used to convert tokens? What about a US server used to send a fraudulent instruction? What about a US stablecoin issuer freezing, minting, or redeeming tokens as part of the alleged scheme?
There is no single answer. The more the US-linked fact is part of the actus reus of the offence alleged, the stronger the argument that the conduct occurred, at least in part, in the requesting state. The more it is background plumbing, the stronger the defence argument that it is merely incidental infrastructure.
This creates a very practical defence exercise. Do not accept the requesting state’s characterisation of the case at face value. Break the alleged conduct down into its component acts. Identify who did what, where, and when. Separate human decisions from automated routing. Separate the substance of the offence from its technological path. Ask whether the domestic connection is an essential step in the alleged criminality or simply a convenient narrative hook.
Jurisdictional arguments have a habit of expanding quietly. Today’s necessary nexus can become tomorrow’s boilerplate allegation. “US securities were affected” becomes “US wires were used”. “US wires were used” becomes “a US platform was involved”. “A US platform was involved” becomes “a US cloud provider hosted some data”. At some point, the connection stops feeling like jurisdiction and starts feeling like geography by coincidence.
That is the danger of nexus creep.
For lawyers, the point is not to deny that cross-border crime requires cross-border enforcement – it plainly does. The point is to insist that extradition and criminal jurisdiction remain disciplined by statute, comity, and principle. El-Khouri is important because it reminds courts not to confuse consequences with conduct. The next step is to ensure they do not treat infrastructure as conduct unless that infrastructure is genuinely part of the substance of the alleged offending.
The imbalance discussed in the first article has not disappeared. US prosecutors may still assert broad jurisdiction in suitable cases, particularly where US markets, investors, communications, banking systems, or financial institutions are involved. The second article explained why El-Khouri may limit the practical effect of that reach where extradition from the UK is sought and the relevant conduct occurred outside the US.
The third point is this: the next frontier is likely to be the characterisation of infrastructure. If the requesting state can point only to effects, El-Khouri is a serious obstacle. If it can point to infrastructure, the question becomes whether that infrastructure was part of the offending conduct or merely part of the scenery. That distinction may sound narrow, but in modern financial and crypto cases it may be decisive.
Cross-border financial crime investigations are increasingly shaped by global financial systems, digital infrastructure and cryptoassets. As prosecutors seek to establish jurisdiction through technological and financial connections, the distinction between alleged criminal conduct and incidental infrastructure is likely to become an increasingly important issue in extradition proceedings.
The Supreme Court’s decision in El-Khouri reinforces the importance of examining where the alleged conduct actually occurred, rather than relying solely on where its effects were felt or where technology happened to route money, data or value. In our view, careful analysis of these jurisdictional links will remain central to defending complex international financial crime and extradition cases as cross-border investigations continue to evolve.
Not necessarily. According to the principles discussed in El-Khouri, the use of US infrastructure alone may not be sufficient if it is merely incidental rather than part of the alleged criminal conduct.
The Supreme Court confirmed that UK courts should focus on where the requested person’s conduct took place, rather than simply where any alleged effects were experienced.
Crypto transactions often involve exchanges, wallets, blockchain networks, cloud services and payment systems located in multiple jurisdictions, creating competing claims over where conduct is said to have occurred.
“Nexus creep” refers to the gradual expansion of jurisdiction based on increasingly indirect connections, such as servers, payment rails or cloud providers, rather than the alleged criminal acts themselves.
The distinction may determine whether extradition requirements are satisfied. Courts may need to decide whether a connection with a jurisdiction forms part of the alleged offence or is simply part of the technological background.
So, when is a case really “American”, “British”, or something else entirely? The unsatisfying but legally honest answer is: it depends on the actual conduct, not the broader impression created by the facts.
That may be the lasting lesson of El-Khouri. A case does not become domestic merely because its consequences were felt domestically. Nor should it become domestic merely because modern technology happened to route money, data, or value through domestic infrastructure. Courts and practitioners should keep asking the simple questions: what is the alleged criminal act, who did it, and where was it done?
In a world of cloud servers, crypto wallets, dollar rails, and global markets, those questions are harder than they sound. But they are still the right questions.
Gherson’s International Protection Team has extensive experience advising individuals facing complex cross-border criminal investigations and extradition proceedings. We regularly assist clients in matters involving competing jurisdictional claims, international financial crime allegations, cryptoasset investigations and multi-jurisdictional defence strategies. If you have questions arising from this article or require specialist advice, please contact us, send us an e-mail, or, alternatively, follow us on X, Facebook, Instagram, or LinkedIn to stay-up-to-date.
The information in this blog is for general information purposes only and does not purport to be comprehensive or to provide legal advice. Whilst every effort is made to ensure the information and law is current as of the date of publication it should be stressed that, due to the passage of time, this does not necessarily reflect the present legal position. Gherson accepts no responsibility for loss which may arise from accessing or reliance on information contained in this blog. For formal advice on the current law please do not hesitate to contact Gherson. Legal advice is only provided pursuant to a written agreement, identified as such, and signed by the client and by or on behalf of Gherson.
©Gherson 2026
View all news & InsightsAuthors