Skip to content
SWITALSKI.LAW – home
EN PL

MiCA DeFi Exemption: When DeFi Falls Outside MiCA and What ESMA Proposes

Recital 22 keeps fully decentralised services outside MiCA, but the MiCA DeFi exemption has no definition. Notes on front-ends, the Danish FSA test and ESMA's 30 September 2026 proposals.

Top-down view of scattered matte grey spheres on a dark surface, one of them in brushed gold.Illustration generated with AI

KEY TAKEAWAYS

  1. Recital 22 of MiCA confirms that crypto-asset services provided in a fully decentralised manner, without any intermediary, fall outside MiCA, but the regulation never defines full decentralisation.
  2. An interface can fall within MiCA even if the protocol behind it is fully decentralised; the Danish FSA treats such an interface operator as executing client orders.
  3. On 30 September 2026, ESMA proposed a statutory definition of DeFi, a narrow exemption and a new regulated service for CASPs that give clients access to DeFi protocols.
  4. ESMA’s proposals are not law: the Commission’s report under Article 140 MiCA is due by 30 June 2027, and any amendment must then pass the ordinary legislative procedure.

MiCA does not apply to crypto-asset services provided in a fully decentralised manner, without any intermediary. Recital 22 of Regulation (EU) 2023/1114 (MiCA) confirms this, but the regulation never says what “fully decentralised” means. In practice, most DeFi set-ups have an identifiable party behind the interface, the admin keys or the governance votes, and supervisors look for that party. This article explains where the line runs today and what ESMA proposed on 30 September 2026. It reflects the legal position as of 7 October 2026.

MiCA Excludes Fully Decentralised DeFi but Does Not Define It

Recital 22 MiCA sets two rules for activities with decentralised elements. MiCA applies to persons and to the services they perform, provide or control, directly or indirectly, even when part of the activity runs in a decentralised manner. Only where crypto-asset services are provided in a fully decentralised manner, without any intermediary, do they fall outside the regulation.

The same recital deals with tokens. Crypto-assets with no identifiable issuer fall outside Titles II, III and IV, but a CASP providing services in respect of them remains within MiCA. A DeFi token can therefore sit outside the issuer rules while the CASP listing it cannot.

A recital guides interpretation; it does not create an exemption on its own. The exclusion works through the definitions instead. Without a legal person or other undertaking providing crypto-asset services to clients on a professional basis, as Article 3(1)(15) MiCA requires, there is nobody to authorise.

What MiCA does not do is define “decentralised”. ESMA itself notes diverging views across the EU on what full decentralisation means. If an activity does not meet that bar, it needs CASP authorisation under MiCA like any other crypto-asset service.

How Supervisors Test Decentralisation Today

The most concrete public test so far comes from the Danish FSA (Finanstilsynet). Its 2024 principles for assessing decentralisation bind no other supervisor, but they show how a national authority reads Recital 22. The assessment has two steps.

Technical decentralisation. The Danish FSA asks whether the service runs only through self-executing smart contracts that no legal entity controls. Editing access to key inputs points the other way: deciding who may provide liquidity or trade, replacing contracts or updating price oracles.

Decentralised governance. If the service is not technically decentralised, the question becomes who controls it. That may be the DAO itself as a partnership, a majority holder of governance tokens, or a delegated body with real decision-making powers.

Two points carry most weight in practice. The Danish FSA assesses decentralisation at the moment the service becomes available to the public, so a plan to decentralise later does not help. It also warns that wrongly classifying an offering as fully decentralised may amount to providing services without authorisation.

Few large protocols are likely to pass the governance step. An ECB working paper published in March 2026 found that the top 100 holders controlled over 80% of governance tokens in Aave, MakerDAO, Ampleforth and Uniswap. Around a third of the most active voters could not be identified at all. The data date from October 2022 and May 2023, and the paper states the authors’ views, not the ECB’s.

Front-End Operators: Where the Line Runs in Practice

A protocol and its interface are two separate questions. The Danish FSA illustrates this with a company that runs an interface to a decentralised exchange whose liquidity comes from automated market makers. The company controls only the interface.

In that example, the company executes orders on behalf of clients under Article 3(1)(16)(e) MiCA. Its software turns a user’s trading interest into an order on the exchange. It does not operate a trading platform, because it does not control the smart contracts that make up the exchange. It needs authorisation only for what it controls.

From a practitioner’s perspective, these functions usually point to an identifiable intermediary:

  • routing or aggregating orders across pools or protocols;
  • charging a fee on each transaction;
  • choosing which tokens and pools users see;
  • controlling the domain, the app store listing or geoblocking;
  • marketing the service to users in the EU.

Several of these match the criteria the Commission asked stakeholders to rate in 2026, discussed below. In my practice advising crypto-asset service providers, I am not aware of any public supervisory decision that tests this line for a DeFi front-end. Until one exists, the Danish example is the most useful reference point.

The same scope question, whether an activity is a crypto-asset service requiring authorisation under Article 59 MiCA, also decides P2P crypto trading under MiCA.

Is your DeFi interface within MiCA?

Send the structure of your product: its functions, keys and governance. The attorney who reviews it is the one who handles the matter.

Send a brief

What ESMA Proposed on 30 September 2026

ESMA set out its position in its response to the Commission’s MiCA review consultation (ESMA75-113276571-1721). The document is a proposal to the Commission, not binding guidance.

A Statutory Definition and a Narrow Exemption

ESMA sees diverging views across the EU on what “fully decentralised” means. It also names a risk of decentralisation washing: an identifiable operator using DeFi language to stay outside MiCA. ESMA proposes defining DeFi in MiCA itself and keeping the exemption as narrow as possible. Its fallback option is technical guidelines issued by ESMA.

For teams relying on Recital 22 today, a statutory definition would replace case-by-case national readings with one EU test. In my view, that test is likely to be stricter than most current self-assessments.

A New Regulated Service: DeFi Access Through CASPs

ESMA proposes a new crypto-asset service: giving clients access to DeFi protocols. It would cover CASPs that provide the technical interface, route transactions or intermediate the client’s interaction with smart contracts. The proposed obligations are:

  • risk disclosures to clients;
  • transparency on how protocols are selected and transactions routed;
  • management of conflicts of interest;
  • due diligence on the protocols offered;
  • operational and cyber safeguards.

Their intensity would depend on how much control the CASP has over the protocol. ESMA adds that open-source code, self-custody, smart contracts and permissionless infrastructure should not, on their own, amount to regulated intermediation.

In practice, due diligence would make CASPs the gatekeepers that decide which protocols reach EU clients. A CASP planning a DeFi feature should account for this in its crypto product structuring now.

DeFi Borrowing Through CASPs

ESMA treats borrowing through DeFi protocols that CASPs make available as a separate risk category. Its approach targets the CASP, not the autonomous protocol. The EBA takes the same direction. On 24 September 2026, it recommended that the Commission consider regulating crypto lending, including where CASPs facilitate access to decentralised lending protocols.

What the Commission Is Asking and When It Decides

The Commission’s targeted consultation on the MiCA review opened on 20 May 2026 and closed on 30 September 2026, after an extension. The consultation document is a working document of the Commission services, not a policy position or a legislative proposal.

Question 61 asks stakeholders to rate six criteria for the absence of full decentralisation:

  • an identifiable intermediary providing a crypto-asset service;
  • control by an identifiable person over key functions, for example through admin keys or upgradeability;
  • significant concentration of governance power;
  • custody of user assets by the protocol;
  • protocol code that is not open source;
  • marketing by an identifiable person or entity.

Questions 62 to 65 explore indirect regulation instead. The options include CASP due diligence on protocols and certification of protocols and smart contracts. Others are certification in place of a full CASP licence and a ban on connecting CASP clients to uncertified protocols.

Article 142 MiCA required a Commission report assessing DeFi by 30 December 2024. In May 2026, the Commission said the consultation seeks to respond to that request. The broader review report under Article 140 MiCA is due by 30 June 2027, with a legislative proposal where appropriate. Any amendment would then go to the European Parliament and the Council. In my assessment, binding DeFi rules are years away, while supervisory expectations will move sooner.

What CASPs and Front-End Teams Should Do Now

The exemption can still be relied on, but only with evidence. These steps reflect my practical view, not legal requirements:

  1. Map each function of your interface to the services in Article 3(1)(16) MiCA, and record why each one is or is not a service you provide.
  2. List admin keys, upgrade rights, treasury control and governance concentration, and identify who holds each of them.
  3. Run the Commission’s six criteria as a conservative internal test, while treating them as consultation questions, not law.
  4. If you are a CASP planning DeFi access, build protocol due diligence and risk disclosures before they become mandatory.
  5. If you serve EU users from outside the EU, do not plan around reverse solicitation under MiCA.

Article 61(1) MiCA applies only where an EU client initiates the service at its own exclusive initiative. A contractual clause or disclaimer claiming otherwise does not change that.

FAQ

Not automatically. Recital 22 MiCA excludes only services provided in a fully decentralised manner without any intermediary, and a company running an interface is often an identifiable intermediary. The Danish FSA treats a company running an interface to a decentralised exchange as executing client orders under Article 3(1)(16)(e) MiCA.

No. Recitals guide the interpretation of EU regulations but do not create obligations or exemptions of their own. The exclusion of fully decentralised DeFi follows from the definitions in Article 3(1)(15) and (16) MiCA. Without a person providing crypto-asset services on a professional basis, there is no provider to authorise.

Possibly, but not yet. On 30 September 2026, ESMA proposed adding a definition of DeFi to MiCA and keeping the exemption as narrow as possible, with ESMA technical guidelines as a fallback. Any definition would require a Commission legislative proposal and adoption by the European Parliament and the Council.

Current MiCA has no separate DeFi access service, but a CASP’s authorisation must cover the service that access involves, such as executing or transmitting orders. ESMA has proposed a new regulated service of giving clients access to DeFi protocols. Its obligations would cover risk disclosure, protocol selection, conflicts of interest, protocol due diligence and operational safeguards.

Not before the Commission completes its MiCA review. The Commission’s report under Article 140 MiCA is due by 30 June 2027 and may come with a legislative proposal for the European Parliament and the Council. In practice, supervisory expectations may move earlier, through Q&As and supervisory statements.

If your DeFi product depends on Recital 22, test it today against the Danish two-step assessment and the Commission’s six criteria. If it fails either, plan for CASP authorisation, not for the exemption.

Mateusz Świtalski
About the author
Mateusz Świtalski

Mateusz Świtalski is a Polish attorney-at-law practising in Poznań, specialising in EU crypto and fintech regulation. He works directly with founders from incorporation through to full licensing authorisation.

Read full bio

have a question on this?

Send me a brief.

One named attorney, end to end — tell me what you are building and I will reply within one business day.

    Your data is used solely to respond to your message. Controller: Mateusz Świtalski Kancelaria Radcy Prawnego, Małachowskiego 8/P1, Poznań, info@switalski.law. Full details and your rights – Privacy Policy.

    1 business day
    Reply time
    Fixed fee
    Where possible
    NDA on request
    Standard wording

    Direct counsel – no account managers, no anonymous queue. · Confidential · EN / PL

    Continue reading

    Practitioner notes from the EU fintech frontline

    MiCA 17 September 2026 Reverse Solicitation Under MiCA: Why the Exemption Will Not Save Your EU Client Base Read article MiCA 8 September 2026 P2P crypto trading under MiCA: when trading your own capital becomes a service Read article