The European Commission’s targeted consultation on the review of MiCA asks whether the Regulation should be extended to decentralised finance (DeFi), staking, crypto-asset lending and non-fungible tokens (NFTs). These questions have a common difficulty: financial regulation usually imposes obligations on an identifiable person, while a decentralised protocol can distribute control among participants or operate through code that no one can change alone.
In my contribution, I argued for a functional approach. The decisive questions are who can change the rules, who can control users’ assets and who actually provides a service. A front-end, a governance token or a smart contract does not answer those questions by itself. The point is to distinguish genuine decentralisation from arrangements in which an identifiable actor still has decisive power.
DeFi can bring continuous access, transparent execution rules, direct participation and composability. It also exposes users to smart-contract and oracle failures, governance capture, liquidations and transaction-ordering risks. A clear regulatory boundary must take both sides seriously.
Decentralisation is a question of effective control
Recital 22 of MiCA says that crypto-asset services provided in a fully decentralised manner without an intermediary should fall outside the Regulation. It does not supply a sufficiently operational test for deciding when that condition is met. The consultation’s Question 61 therefore matters well beyond any one DeFi application. EUR-Lex
My proposed test examines three cumulative conditions. First, essential functions must be governed by no identifiable decision-maker, as in an immutable arrangement, or by at least three genuinely independent centres of effective decision-making; no person or coordinated group should be able to make a material decision alone. The three-centre threshold is a proposed minimum for assessment, not a rule currently contained in MiCA. Independence must be examined in substance, including beneficial ownership, delegated votes and arrangements to act together.
Second, participants must operate under common rules that no identifiable actor can materially amend, suspend or override unilaterally. Third, no such actor should be able to dispose of, divert or otherwise exercise effective control over users’ crypto-assets through privileged keys, upgrades or operational dependencies. An authority should examine the function at issue and revisit its assessment when the facts change.
This approach also clarifies two recurring mistakes. Crypto-assets locked in a smart contract are not necessarily in the custody of a person. Conversely, publishing open-source code does not establish that control has been decentralised. Marketing and a decentralised-looking governance structure are evidence to examine, not legal conclusions. My proposal builds on the analysis developed in Decentralization: the Search for a Legal Definition.
Front-ends and CASPs: responsibility for one’s own conduct
The distinction between a protocol and an intermediary has practical consequences. In my response, a person who merely provides an interface to a genuinely decentralised, non-custodial protocol should not be treated as providing a MiCA-regulated service on that fact alone. The conclusion can differ if that person actually performs a regulated function or retains effective control over a material part of the service.
The same principle applies when an authorised crypto-asset service provider (CASP) enables its customers to reach a DeFi protocol. In response to Question 62, I opposed a general obligation to audit the protocol or answer for incidents in code and governance that the CASP cannot control. The CASP remains accountable for the service it actually supplies and for its own representations. It should explain the limits of its role and give users clear information about smart-contract vulnerabilities, irreversible transactions, loss of assets and the possible absence of anyone able to intervene. Informed users can then decide whether to interact directly with the protocol and bear the risks of that interaction.
A voluntary label instead of compulsory certification
Questions 63–65 explore certificates for DeFi protocols, smart contracts and non-custodial wallets. My answer rejects making certification a condition for deploying a protocol, offering wallet software or connecting users to an application. A genuinely decentralised protocol may have no person who can be ordered to apply for a certificate, pay for it and maintain it. Where an identifiable team exists, compulsory authorisation or certification could instead encourage that team to establish its operations outside the EU while leaving the protocol accessible to European users.
A voluntary label could have a different function. If a protocol is governed by a DAO, its members could vote to request an assessment and authorise someone to submit the application. An independent assessor could review the relevant code, security measures and governance arrangements. The competent authority could then evaluate that assessment and, where published criteria are met, record the label in a public register. The entry should identify the version of the code examined, the scope of the review and its period of validity.
The incentive would be positive: greater visibility, more useful information for users and possible access to relevant innovation initiatives. Declining the label must carry no prohibition or disadvantage in accessing the protocol. The label would describe an assessment, not guarantee against loss or amount to a MiCA authorisation. Equally, it would not replace a CASP licence where an identifiable person actually provides a regulated service.
Staking: a technical process with a custody boundary
In response to Question 66, I supported the current approach of not creating a separate licence for staking. At protocol level, staking contributes to validation and security on proof-of-stake networks. The legal analysis changes when an intermediary holds a client’s assets or private keys. In that situation, the existing MiCA framework for custody and administration applies, as the European Commission’s answer published by ESMA explains. A distinct staking authorisation would add another layer of cost without necessarily improving user protection. www.esma.europa.eu
Those costs are material. Based on my professional experience, a MiCA authorisation can require at least EUR 200,000 in advisory expenditure, while recurring compliance costs for some operators can reach EUR 1 million a year. These are experience-based illustrations, not official EU-wide averages. Any proposal to add a staking licence should confront its effect on new European entrants. If the EU nevertheless chooses that route, dedicated funding should help start-ups meet authorisation and compliance costs.
Lending and borrowing: distinguish protocols from intermediaries
Question 67 raises a related boundary. I opposed a new authorisation requirement for lending and borrowing carried out through genuinely decentralised DeFi protocols. Where an identifiable intermediary offers the activity, its treatment should continue to depend on the substance of the arrangement and on the rules already applicable to that intermediary.
At the same time, the EU could create a proportionate route for authorised CASPs to offer crypto-asset lending or borrowing below defined thresholds without requiring a banking licence solely for that limited activity. The scale of outstanding loans and retail exposure could inform those thresholds. Credit, liquidity and counterparty risks should be disclosed clearly. Such a route would require a deliberate legislative choice and would not displace rules governing activities reserved to banks.
NFTs: regulate the rights, not the digital wrapper
Finally, in response to Question 68, I opposed a dedicated financial licence for providers dealing in genuinely unique and non-fungible tokens. An NFT representing an artwork or collectible should generally be approached like the asset it represents. Fraud, misleading descriptions and disputes about authenticity are serious matters, but they can be addressed through existing consumer, contract and intellectual-property law; the use of a token alone does not justify a new financial authorisation for the marketplace.
The qualification must still follow substance. Article 2(3) of MiCA excludes unique and non-fungible crypto-assets from MiCA, while ESMA’s guidelines explain why a unique identifier is insufficient and why a token that qualifies as a financial instrument remains subject to the relevant financial rules. Calling something an NFT cannot exempt financial rights from regulation. www.esma.europa.eu
A workable boundary for MiCA’s next phase
The consultation is an opportunity to make MiCA’s perimeter clearer. The contribution’s proposals share a simple method: identify the actual service and the person who can control it, then attach obligations to that person’s conduct and powers. For genuinely decentralised arrangements, clear information and optional, well-defined trust signals are more workable than mandatory licences addressed to a protocol with no identifiable operator. For intermediaries who hold assets or perform regulated services, existing protections continue to matter.
That boundary is both a legal question and a choice about Europe’s capacity to host the next generation of digital infrastructure.
This article summarises my responses to Questions 59 and 61–68 of the Commission’s targeted MiCA review consultation. It presents policy proposals and should not be read as a statement of current EU law where a change is expressly suggested.