The rise of decentralized finance (DeFi) has led many teams to proclaim, “We are DeFi, so MiCA does not apply to us.” However, the European Banking Authority (EBA) and the European Securities and Markets Authority (ESMA) hold a very different view. Regulatory guidelines have made it clear that the “fully decentralized” exemption is extremely narrow, and teams should not blindly rely on it.
The Common Misconception About DeFi
Recital 22 of the Markets in Crypto-Assets Regulation (MiCAR) states that services provided in a “fully decentralized manner without any intermediary” fall outside the regulation’s scope. Yet the term “fully decentralized” is not defined in the binding articles—only in the non-binding recitals. Many startups have mistakenly believed that if their project is sufficiently decentralized, no compliance is needed. However, ESMA and EBA have shattered this myth through consultation papers and a joint report published in January 2025.
ESMA and EBA’s Stance: Substance Over Form
In the joint report (ESMA75-453128700-1391 / EBA/Rep/2025/01), the regulators emphasize that decentralization is not binary but a spectrum. Even when a project relies on autonomous smart contracts, if any identifiable entity exercises control over governance, protocol parameters, fee structures, or core infrastructure, that entity is likely subject to MiCAR. The focus is on functional control, not technical labeling.
A notable example occurred on April 21, 2026, when the Arbitrum Security Council froze over 30 ETH (worth ~$71 million) linked to a Kelp DAO exploit. Despite Arbitrum being a permissionless Layer 2 network, the governance body’s ability to freeze funds demonstrated “discretionary operational control,” disqualifying the system from the fully decentralized exemption. ESMA has consistently stated that possession of admin keys, front-end access control, or the ability to upgrade or pause smart contracts are key triggers for regulatory classification.
The FATF Framework and Contractual Relationships
The Financial Action Task Force (FATF) has provided a foundational analytical framework. In its updated guidance (October 2021), FATF notes that owners and operators of DeFi arrangements can often be identified through their association with the activity, not by the labels they attach. Importantly, permissionless DLT is treated as a “public good” and does not create a third-party service provider relationship under MiCAR Article 73. However, if a platform operator retains control over smart contracts deployed on a permissionless chain—such as the ability to modify or suspend them—the centralized elements will bring the operator within MiCAR’s scope.
Key Takeaways and Compliance Advice
Based on the analysis, the following conclusions are critical for DeFi projects:
- The fully decentralized exemption is extremely narrow: Any single entity’s control over governance, protocol, or infrastructure negates the exemption.
- Substance over form determines compliance: Regulators look beyond marketing claims and assess actual operational control.
- Decentralization is a continuum: ESMA evaluates each case individually based on the specific characteristics of the system.
- Software developers are not automatically CASPs: However, if they retain sufficient influence over the platform or ongoing business relationships, they may cross the regulatory threshold.
DeFi teams should conduct thorough legal assessments before launching in the EU, rather than simply asserting that they are decentralized. This article is based on research conducted by LegalBison in April 2026. It is for informational purposes only and does not constitute legal advice.

