This week’s entry has been written by Eira Järvi, Senior Lawyer at LegalBison, leading global regulatory research and the implementation of CASP licensing and other complex licenses. Eira actively implements global research into active client-facing products.
DeFi on the RiseHowever, within this context, one subject remains more pivotal than all others. How does the team ensure that the project they are building is legally compliant?
This article seeks to dispel the popular belief that if a project is decentralized enough, MiCAR is of no concern to the team. Sorry, but regulatory guidelines bust that myth!
The Myth: MiCA Doesn’t Affect DeFi and Non-Custodial Service ProvidersHowever, the Recital contains the following crucial language: “Where crypto-asset services are provided in a fully decentralised manner without any intermediary, they should not fall within the scope of this Regulation.” The import of this provision lies within two key phrases: “fully decentralised” and “without any intermediary.”
In determining whether services fall within MiCAR’s scope, two conditions may be distilled from Recital 22 and subsequent regulatory guidance:
First, no single entity may exercise control over protocol parameters, governance mechanisms, or the core technological infrastructure upon which the crypto-asset service operates. Second, users must access what amounts to a “common good resource” rather than purchasing services from a designated provider with whom a contractual service-provider relationship exists. The Pitfall of Overestimating the State of DecentralizationTo accomplish the state of true, full decentralization, all elements of the project must meet the criteria of full autonomy and lack of internal or external influence throughout the project’s ecosystem and its many elements, including but not limited to governance, ownership, interfaces, etc., which, upon closer inspection, very few projects manage to achieve.
This example points out the existence of discretionary operational control: even though Arbitrum is, by definition, a layer-2 permissionless and seemingly fully decentralized network, the exercise of control over the user assets is precisely what would fail MiCAR’s full decentralization test. Substance-over-form, in this case, determines the regulatory scope, regardless of the permissionlessness of the underlying ledger.
ESMA’s and EBA’s Perspective on DeFiThis definition draws from the Financial Stability Board’s consultative document, which distinguishes between permissionless (fully decentralized) DLT, permissioned DLT allowing a degree of centralization, and centralized platforms. The ESMA acknowledges that “the exact scope of this exemption remains uncertain” and considers that an assessment of each system should be made on a case-by-case basis, considering the features of the system.
Regarding hardware and software providers of CASP-ancillary services, the position emerging from ESMA’s guidance is that entities merely creating and selling software development tools, applications, or platforms for crypto-asset provision or trading are not automatically classified as CASPs if their activities are confined to the creation and sale of the said services.
However, entities overseeing the creation and development of software or platforms for providing crypto-asset services may be deemed CASPs if they retain control or sufficient influence over the crypto-assets, software, protocol, platform, or business relationships with users. The critical test is therefore one of control and influence rather than mere technological involvement.
These risk factors, while not determinative of regulatory classification, inform the supervisory approach to entities operating at various points on the decentralization spectrum.
FATF Framework and Contractual RelationshipsThe FATF’s reasoning lays the foundation for the assessment of decentralization under MiCAR by establishing two crucial principles:
First, the owners and operators and their degree of control over DeFi can often be identified by their relationship to the activities being undertaken rather than by the labels applied to the arrangement. Second, partial centralization cannot be automatically excluded even if parties other than the main service provider are involved in the service or if portions of the process are automated through smart contracts.The role of contractual relationships in the assessment of decentralization deserves particular attention. Article 73 of MiCAR, which pertains to the outsourcing of services or activities to third parties for the performance of operational functions, regulates how CASPs should address risks associated with third-party providers.
The test is therefore functional rather than technological: it asks what control the operator actually exercises, not what technology the system is built upon.
Key Takeaways:Taking the foregoing analysis into account, and in particular ESMA’s reasoning as set forth in the consultation papers and the January 2025 Joint Report, we are of the opinion that the following propositions hold true for the purposes of this assessment.
First, as long as no individual or entity controls a DeFi protocol or platform and its usage, and no individual fulfills a fundamental and indispensable role in its operation without which the technology cannot be utilized, the DeFi protocol or platform may be deemed exempt from MiCAR’s scope of application by virtue of being “fully decentralised” within the meaning of Recital 22. Second, the mere development of software or auxiliary tools for CASPs is not considered a crypto-asset service unless additional MiCAR-regulated aspects, such as influencing the offer, sale, transfer, custody, or trading of crypto-assets, are included in the scope of activities undertaken by the developer. What We DecodedThe “Fully Decentralised” Exemption is Exceptionally Narrow: MiCA’s Recital 22 states that services provided in a “fully decentralised manner without any intermediary” fall outside the regulation’s scope, but achieving this true state of full decentralization is incredibly rare. If any single entity exercises control over governance, protocol parameters, or core infrastructure, the exemption does not apply.
Software Developers Are Not Automatically CASPs: Merely creating and selling non-custodial software or hardware does not automatically classify an entity as a Crypto-Asset Service Provider (CASP). However, if the developers or operators retain sufficient influence over the crypto-assets, the platform, or the ongoing business relationships with users, they cross the regulatory threshold and will be regulated as CASPs.


















