As the Markets in Crypto-Assets Regulation (MiCAR) takes full effect in the European Union, many decentralized finance (DeFi) teams believed they could bypass regulatory obligations by simply claiming “full decentralization.” However, the European Banking Authority (EBA) and the European Securities and Markets Authority (ESMA) have made it clear: regulators look beyond technical jargon and assess who actually exercises operational control.
MiCA’s DeFi Exemption: Extremely Narrow Conditions
Recital 22 of MiCAR states that crypto-asset services provided in a “fully decentralized manner without any intermediary” fall outside the regulation’s scope. But the key lies in two phrases: “fully decentralized” and “without any intermediary.” The operative articles of MiCAR contain no definition of “fully decentralized”; the term appears only in the recitals, which are not legally binding. Consequently, regulators have been empowered to clarify the scope through technical standards.
Based on Recital 22 and subsequent guidance, two conditions must be met for exemption: first, no single entity may exercise control over protocol parameters, governance mechanisms, or core technical infrastructure; second, users must access what is effectively a “public good” rather than purchasing services from a designated provider. This means that even if a project is built on a permissionless blockchain, if the development team retains admin keys, controls the front-end interface, or has the ability to upgrade smart contracts, the project likely falls under MiCAR.
The Trap of Overestimating Decentralization
Many DeFi teams mistakenly equate a permissionless technical architecture with regulatory “full decentralization.” But ESMA and EBA apply the “substance over form” principle. For example, in April 2026, the Arbitrum Security Council froze over 30 ETH (approximately $71 million) related to a Kelp DAO vulnerability. This case demonstrated that even a permissionless Layer-2 network like Arbitrum exhibits centralized elements when its governance body exercises discretionary control over user assets, failing the MiCAR test.
In its joint report of January 2025 (ESMA75-453128700-1391), ESMA acknowledged that decentralization is not binary but exists on a spectrum from centralization to varying degrees of decentralization. The report confirmed that very few DeFi systems achieve true full decentralization as envisioned by Recital 22. Even ostensibly decentralized protocols typically have identifiable entities exercising varying degrees of control over governance, upgrades, smart contract deployment, and fee structures.
Contractual Relationships and Third-Party Classification
Regarding software providers that assist CASPs, ESMA indicated that entities whose activities are limited to creating and selling software tools are not automatically classified as CASPs. However, if the entity retains control or sufficient influence over the crypto-assets, platform, or business relationships with users during development, the regulatory threshold may be triggered. The key distinction: permissionless DLT can be considered a “public good” requiring no formal contractual relationship, whereas permissioned DLT or commercial platforms typically involve contractual arrangements, constituting third-party relationships.
ESMA’s analysis of MiCAR Article 73 (outsourcing) concluded that permissionless DLT used by CASPs should not be classified as a third-party provider because no service-level agreement is needed. However, if the platform operator retains functional control — such as admin keys, front-end access, or the ability to pause or modify the protocol — MiCAR compliance is required regardless of the underlying ledger’s permissionless nature.
Key Takeaways
- The “fully decentralized” exemption is extremely narrow: Truly decentralized projects with no entity exercising control are extremely rare. Governance rights, key control, or upgrade capabilities disqualify the exemption.
- Substance over form determines compliance: Regulators assess actual operational control, not technical labels. Admin keys, front-end control, and pause/freeze abilities are centralization indicators.
- Decentralization is a spectrum: ESMA does not treat decentralization as binary. Even highly automated protocols with smart contracts may face regulatory scrutiny if identifiable entities exert any degree of control.
- Software developers are not automatically CASPs: Developing non-custodial software alone does not trigger CASP classification, but sufficient influence over assets or business relationships brings the activity under MiCAR.
This article is based on research conducted by LegalBison in April 2026. It is for informational purposes only and does not constitute legal advice.

