As the Markets in Crypto-Assets Regulation (MiCAR) takes full effect, numerous DeFi project teams are eyeing EU market expansion. A common misconception persists: that achieving 'full decentralization' exempts them from regulatory obligations. However, recent guidance from the European Banking Authority (EBA) and the European Securities and Markets Authority (ESMA) makes it clear: the 'fully decentralised' exemption is exceptionally narrow. Regulators will look past technical architecture to assess who actually wields operational control—a substance-over-form approach.
The Myth of DeFi Exemption
Recital 22 of MiCAR states that services provided 'in a fully decentralised manner without any intermediary' should fall outside the regulation's scope. Yet, the operative provisions of the Regulation do not define 'fully decentralised' anywhere. In its Joint Report (ESMA75-453128700-1391) published in January 2025, ESMA emphasized that decentralization is a spectrum, not a binary concept. The vast majority of DeFi projects have identifiable entities that exercise varying degrees of control over governance, protocol upgrades, smart contract deployment, and fee structures.
ESMA and EBA's Core Assessment Criteria
According to ESMA's second consultation package, two conditions must be met for a DeFi project to be considered outside MiCAR's scope: First, no single entity may control protocol parameters, governance mechanisms, or core technological infrastructure. Second, users must access a 'common good' resource rather than purchasing services from a designated provider under a contractual relationship.Furthermore, ESMA considers permissionless DLTs as 'common goods,' but if the platform operator retains administrative keys, can upgrade or pause smart contracts, or controls the front-end interface, they remain within MiCAR's scope regardless of the permissionless nature of the underlying ledger.
A vivid illustration occurred on April 21, 2026, when Arbitrum's Security Council froze over 30 ETH (approximately $71 million) associated with the Kelp DAO exploit. Despite Arbitrum being a permissionless Layer-2 network, the Security Council's discretionary operational control over user assets would fail MiCAR's full decentralization test—substance over form determines regulatory scope.
The FATF Framework and Contractual Relationships
The Financial Action Task Force (FATF) updated its guidance in October 2021, stating that merely creating or selling a software application or platform does not constitute a Virtual Asset Service Provider (VASP) if the activity is limited to creation or sale. However, if creators, owners, or operators maintain control or exert sufficient influence over the DeFi arrangement—even through smart contracts or voting protocols—they may fall under the VASP definition. ESMA has adopted this logic: the critical test is one of control and influence, not technological labels.
Compliance Pitfalls for Software Developers
ESMA clarifies that entities merely creating and selling non-custodial software or hardware are not automatically classified as Crypto-Asset Service Providers (CASPs). However, if developers or operators retain sufficient influence over the crypto-assets, the platform, or ongoing business relationships with users, they cross the regulatory threshold and must be licensed as CASPs. For instance, maintaining administrative keys that can pause, freeze, or modify the protocol brings the operator within MiCAR's scope.
Key Takeaways for DeFi Teams
DeFi teams planning to enter the EU should not rely on the 'fully decentralised' exemption as a safe harbor. A comprehensive legal assessment of each project layer (DLT, protocol, dApp) is necessary to determine the actual distribution of control. If any centralized elements exist—such as governance tokens controlled by a small group, upgradeable smart contracts, or administrative keys—compliance with MiCAR is mandatory. This includes applying for CASP authorization, implementing AML/CFT procedures, and ensuring proper outsourcing arrangements. As ESMA and EBA guidance tightens, delayed compliance costs will far outweigh proactive investment.

