EST · MMXXVI
Home/Insights/Regulatory/Stablecoin issuance authorisation: What Recent Enforcement Tells Operators
Token Offerings & Securities

Stablecoin issuance authorisation: What Recent Enforcement Tells Operators

Stablecoin issuance authorisation: What Recent Enforcement Tells Operators. Cross-border digital-asset legal counsel for business – licensing, disputes and stru

Stablecoin Issuance Authorisation: What Recent Enforcement Tells Operators

A token issuer expanding into the EU discovers that the stablecoin it has operated for two years now requires prior authorisation under MiCA (the Markets in Crypto-Assets Regulation) – not a registration, not a notification, but a full authorisation from a national competent authority before the token may be publicly offered or admitted to trading. That discovery, made after launch, is the enforcement pattern regulators across multiple jurisdictions are now acting on. The legal question is not abstract: does your stablecoin constitute an asset-referenced token (an ART, pegged to a basket of assets or currencies) or an e-money token (an EMT, pegged to a single fiat currency), and have you obtained the authorisation the applicable regime requires?

Recent enforcement actions across the EU, the UAE and the UK confirm a consistent regulatory position: the label applied to a token at launch does not determine its legal classification. What the token does – the rights it confers, the reference asset it tracks, the manner in which it is redeemable – determines the applicable regime, and therefore the authorisation obligation. This analysis draws on the enforcement signals visible in public regulatory communications, maps the authorisation requirements across the leading stablecoin regimes and gives operators a decision framework for assessing their position before the next supervisory cycle.

The analysis proceeds from the threshold classification question, through the regime-by-regime authorisation map, to the cross-border complications that most issuers underestimate, and closes with a decision matrix and two anonymized micro-matters drawn from practice.

What Recent Enforcement Is Actually Saying

Enforcement communications from ESMA and national competent authorities under MiCA, from VARA in Dubai and from the FCA in the UK share a common structural point: regulators treat the failure to obtain prior authorisation as the primary violation, not the underlying product design. That framing matters enormously for operators. It means a well-structured stablecoin issued without authorisation carries the same formal exposure as a poorly structured one. It also means that the remediation path – obtaining authorisation retroactively or restructuring the instrument – is technically available but operationally costly.

In our cross-border practice, we have seen operators assume that because their stablecoin is collateralised by a single fiat currency it sits comfortably within an existing e-money framework. That assumption is increasingly unsafe. Under MiCA, an EMT issuer must be either a credit institution or an authorised electronic money institution. Neither authorisation is available in weeks. The enforcement signal is that regulators are now checking the capitalisation and reserve composition of circulating stablecoins against the authorised entities list – and acting where there is no match.

The practical takeaway: an operator running a stablecoin without authorisation is not merely at risk of a future enforcement action. It is already in violation in every jurisdiction where the token is publicly offered or admitted to trading. The clock starts at first offer, not at first regulatory contact.

Token Classification: The Threshold Question Every Issuer Must Answer

The legal classification of a stablecoin is a function of substance, not marketing choice – and misclassification is the single most common structural error we identify in issuer mandates. Under MiCA, the taxonomy divides stablecoins into three regulated categories: ARTs, EMTs and "other crypto-assets" (the residual category), each attracting a distinct authorisation path.

An ART is defined by its reference to multiple fiat currencies, one or more commodities, one or more crypto-assets, or a basket combining those. An EMT references a single official currency and claims to maintain a stable value against it. The distinction sounds clean. In practice, a token pegged to the US dollar but holding a reserve of short-dated US Treasury bills and USDC may be an ART rather than an EMT depending on how the reserve is characterised. Similarly, a token marketed as a "yield-bearing stablecoin" may, depending on the rights it confers, attract securities-law analysis in parallel with the MiCA classification exercise.

The principle that substance governs form is a FATF baseline across all leading regimes, not a MiCA peculiarity. In Singapore, the Monetary Authority of Singapore applies the same analytical discipline under the Payment Services Act: a digital payment token that effectively tracks a reference asset is assessed against the DPT service licensing requirements, but a token that confers debt claims may attract a separate securities-law overlay under the Securities and Futures Act. VARA in Dubai similarly examines the economic substance of the instrument before assigning the applicable activity licence.

The consequence for operators is that a token classification opinion – a formal legal analysis of the applicable regime – is not optional pre-launch due diligence. It is the document that determines which regulator you need to approach, in which sequence, and with what capital and reserve evidence.

To obtain a scoped classification analysis before you reach the regulator, contact OBOLUS at info@oboluslaw.com. The process above describes the standard analytical path. Your specific facts – the reference asset, the reserve composition, the user base, the distribution geography – change the outcome.

MiCA ART and EMT Authorisation: What the Regime Actually Requires

Under MiCA, an ART issuer must obtain prior authorisation from the national competent authority of the member state in which it is established before offering the token to the public or seeking admission to trading on a crypto-asset trading platform. The authorisation process requires a detailed white paper, a governance framework, capital and own-funds documentation, a reserve management policy and an operational resilience plan – none of which can be produced quickly.

An EMT issuer does not apply for a separate MiCA authorisation in the same form. It must be an already-authorised credit institution or electronic money institution. The practical consequence is that an operator wishing to issue a EUR-pegged EMT who does not hold an existing EMI authorisation must first obtain one from its chosen national competent authority, then notify that authority under the applicable MiCA provisions before offering the token. The sequencing is rigid: the underlying entity authorisation precedes the token notification.

Passporting is a significant advantage of the MiCA regime. A CASP (crypto-asset service provider) or token issuer authorised in one EU/EEA member state may passport that authorisation across the bloc, avoiding the need for separate national applications. But passporting applies to the authorised entity. If the token itself is an ART, the issuer's authorisation is specific to the ART's terms; a material change to the reserve composition or the reference asset triggers a notification or a fresh authorisation review.

The whitepaper obligation under MiCA is not simply a disclosure document. It carries strict liability for material omissions and inaccuracies. Operators we advise regularly treat it as a compliance artifact. It is, in practice, the central legal instrument of the token relationship: the document against which reserve adequacy, redemption rights and fee structures are measured by supervisors, and against which investors assert claims.

How Does VARA Approach Stablecoin Issuance in Dubai?

VARA's stablecoin regime applies to virtual assets offered within or from the Emirate of Dubai, with the DIFC financial free zone sitting outside VARA's direct remit and governed by the DFSA. For an operator considering a Dubai-domiciled stablecoin issuer, the VARA framework is the starting point.

VARA's activity-based licensing model requires issuers conducting a "Virtual Asset Issuance" activity to obtain VARA approval before the issuance event. The VARA rulebooks – which supplement the overarching Virtual Assets and Related Activities Regulations – set out the governance, disclosure, reserve management and consumer protection requirements that apply. The practical expectation is that a stablecoin backed by a single fiat currency is assessed under the issuance activity rules, while a more complex instrument may attract additional activity licences (for exchange, transfer or management of virtual assets).

What the VARA regime signals most clearly through its public enforcement posture is that the absence of prior approval for a token issuance is treated as an unlicensed activity, not merely a procedural shortfall. In practice, this means that a token offered to users in Dubai – whether by a VARA-regulated entity or otherwise – must have cleared the issuance approval process before any distribution. The jurisdiction matters: operators who issue from an offshore SPV and distribute into the UAE without VARA approval are exposed on the distribution side, not just the issuance side.

We regularly advise operators on the interaction between VARA authorisation and ADGM/FSRA regulated activity authorisation for entities considering a dual-hub UAE structure. The two regimes are not interchangeable, and a FSRA-authorised entity does not carry VARA permissions by virtue of that authorisation alone.

UK and Singapore: Contrasting Approaches to the Same Problem

The FCA's approach to stablecoin regulation has moved toward a formal authorisation requirement for systemic stablecoins used as means of payment, with activity-based regulation expected to extend to fiat-backed stablecoin issuance and custody under forthcoming UK legislation. In the interim, the critical enforcement lever is the financial promotion regime: a stablecoin issuer that communicates a financial promotion to UK persons without FCA authorisation or an exemption is in breach of the applicable financial services legislation, regardless of whether the token itself is formally classified as a regulated instrument. The FCA has demonstrated a willingness to act on financial-promotion violations as a proxy for unauthorised activity.

Singapore's approach under the Payment Services Act is more precisely defined. The Monetary Authority of Singapore has designated specific stablecoins – those pegged to a single fiat currency and meeting applicable reserve and redemption standards – as "MAS-regulated stablecoins" subject to a separate regulatory track. An issuer wishing to designate its token as a MAS-regulated stablecoin must meet minimum requirements on reserve composition, audit, redemption timing and capital. Issuers who do not meet those requirements may still issue the token, but cannot represent it as a MAS-regulated stablecoin – a branding restriction with significant market consequences given the trust premium that regulatory designation confers in institutional and retail markets alike.

The contrast between the UK and Singapore approaches illustrates the cross-border complexity facing any operator targeting both markets from a single issuance vehicle. A stablecoin that satisfies MAS's reserve and audit requirements may still require FCA financial-promotion approval before it can be marketed in the UK. The legal infrastructure must be built for the highest common denominator across all distribution jurisdictions, not just the issuer's home regime.

The Cross-Border Reality: Distribution Tail Risk Is the Enforcement Vector

Most stablecoin enforcement actions we have observed do not begin with the issuer's home regulator. They begin with the regulator in the jurisdiction where the token is most actively used – where trading volumes are highest, where consumer complaints are concentrated, or where a financial crime touchpoint has created a supervisory referral. This is the distribution tail-risk pattern, and it is structurally underweighted in most issuers' legal risk assessments.

The operative principle across MiCA, VARA, the FCA regime and the MAS framework is that offering or distributing a stablecoin to persons within a jurisdiction triggers that jurisdiction's authorisation requirements, regardless of where the issuer is incorporated. A Cayman-incorporated issuer whose stablecoin is actively traded on platforms accessible to EU retail users is, in regulatory substance, offering that token within the EU. The fact that the issuer has no EU office and no EU bank account does not create a jurisdictional shield. MiCA's territorial scope is defined by the offer, not the offeror's domicile.

In our cross-border practice, we structure the distribution perimeter as a distinct legal element of the issuance: geo-blocks, terms of service restrictions and exchange listing agreements are mapped against the authorisation status of the issuer in each relevant jurisdiction. That mapping is not a one-time exercise. It is a living document that must be updated when the issuer enters a new exchange, when its trading volume in a jurisdiction crosses a regulatory threshold, or when the applicable regime changes – as MiCA's progressive entry into force has required for EU distribution across many issuer mandates.

The Travel Rule adds a further layer. Under the FATF Travel Rule (Recommendation 15), VASPs are required to pass originator and beneficiary data with virtual-asset transfers above the applicable jurisdictional threshold. A stablecoin issuer whose token is transferred on non-compliant platforms creates a systemic Travel-Rule gap in its compliance architecture – a gap that is increasingly visible to supervisors who can now interrogate on-chain data flows against registered VASP reporting.

Enforcement Decision Matrix: Which Issuer Profile Faces Which Risk

A structured operator assessment requires matching the issuer's profile to the applicable enforcement exposure. The matrix below is a prose decision framework, not a definitive legal opinion – but it reflects the enforcement patterns that are now established across the leading regimes.

Profile A – Single-fiat EMT issuer, EU distribution, no existing EMI authorisation. This issuer is in the highest-risk category under MiCA. The token is within scope as an EMT. The issuer lacks the prerequisite entity authorisation (EMI or credit institution). Every day of continued distribution after MiCA's token provisions became fully applicable is a day of unlicensed activity. The remediation path is to obtain EMI authorisation in a chosen member state – a process that is measured in months, not weeks – and to notify the applicable authority under MiCA before resuming public distribution. In the interim, the issuer should assess whether a geo-restriction to non-EU jurisdictions is operationally feasible as a risk-mitigation measure.

Profile B – ART issuer, multi-currency reserve, passported through one EU member state. This issuer is within scope but, if authorisation has been obtained and passporting notifications filed, is in the lower-risk category for the EU. The key risk is reserve management: any change in reserve composition that moves outside the parameters disclosed in the authorised white paper triggers a notification obligation. Failure to notify, or to update the white paper in the required form, converts a compliant issuer into a non-compliant one without any change to the token's public-facing operation. Regulators have signalled that reserve-composition drift is an active area of supervisory scrutiny.

Profile C – Offshore-incorporated issuer, no home-jurisdiction authorisation, global distribution through centralised exchanges. This is the enforcement bull's-eye. The issuer has no regulatory capital, no supervisory relationship and no whitepaper liability framework. It distributes to EU, UK, UAE and Singapore users through exchange listings, relying on the exchange's compliance infrastructure as a proxy for its own. That proxy is not available: the exchange's licensing obligation is the exchange's; the issuer's authorisation obligation is the issuer's. The viable options are to obtain authorisation in a jurisdiction with reach across the target markets, to restructure the token as a product offered exclusively in permissive jurisdictions, or to prepare for a supervisory demand to cease distribution.

Profile D – DeFi protocol issuing an algorithmic or crypto-collateralised stablecoin. This profile is the most uncertain under current enforcement doctrine. MiCA explicitly brings algorithmic stablecoins within its scope but effectively prohibits ART issuers from relying on algorithmic mechanisms to maintain the peg. The practical effect is that a protocol issuing a crypto-collateralised token backed by governance mechanisms rather than fiat reserves faces a classification question for which the regulatory answer is not yet settled in all jurisdictions. We advise operators in this profile to obtain a substantive classification opinion and to engage proactively with the relevant national competent authority rather than operating in a legal grey zone until enforcement action crystallises the answer.

Two Matters From Practice

In a recent structuring matter, a payments company sought to issue a EUR-pegged stablecoin for use in cross-border B2B settlement. The operator had assumed that its existing EMI authorisation in an EU member state was sufficient to cover the token issuance. We identified that the token, as designed, constituted an EMT under MiCA and that the operator's EMI authorisation predated MiCA's token provisions. We advised on the notification filing required under MiCA's transitional provisions, restructured the whitepaper to satisfy the reserve-management and redemption-right disclosure requirements, and mapped the passporting notification schedule for the operator's three target distribution markets. The operator was in a compliant position before its planned commercial launch, avoiding a post-launch remediation event.

In a separate matter earlier in the year, a token issuer based outside the EU was distributing a multi-currency stablecoin through listings on several centralised exchanges accessible to EU retail users. A supervisory inquiry arrived from a national competent authority in a member state where trading volume was material. We conducted a rapid classification analysis, confirmed the token was an ART within MiCA's scope, and advised the operator on the options available: a geo-restriction to non-EU access pending authorisation, an application for ART authorisation in a suitable member state, or a voluntary withdrawal from EU-accessible listings. The operator elected a combination of the first and second options. The supervisory timeline was managed without an enforcement decision being issued.

If a supervisory inquiry has arrived or an exchange has requested authorisation evidence, time is the primary constraint. Contact OBOLUS at info@oboluslaw.com for a rapid initial assessment. If a prior structuring was done without classification analysis, a second read of the instrument can surface the exposure and the route forward.

A Common Assumption: The Utility Label Solves the Classification Problem

A persistent belief among operators – particularly those who structured their tokens before MiCA came into force – is that labelling a token as a "utility token" or describing it as providing "access to a service" is sufficient to remove it from the stablecoin or securities-law perimeter. That belief is incorrect under every leading regime and represents the single most common legal error we identify in token structures referred to us for review.

The classification analysis is substance-driven. A token that has a stable reference value, is accepted as a means of payment, is advertised as maintaining a peg, or is issued with redemption rights against a reserve is a stablecoin in regulatory substance, regardless of whether its documentation calls it a utility token, a loyalty point or a platform credit. Regulators apply the same test FINMA in Switzerland articulated in its token-classification guidance years before MiCA: the legal and economic function of the token, not its marketing characterisation, determines the applicable regime.

The enforcement consequence is binary: either the token is within scope and the issuer needs authorisation, or it is not and the issuer does not. There is no intermediate category where a careful label choice reduces the authorisation requirement without changing the instrument's actual function. Operators who have relied on label-based analysis rather than substance-based analysis should treat the current enforcement environment as the prompt to obtain a rigorous classification opinion.

At OBOLUS, we assess classification against the substance of rights conferred – not the marketing label – and we structure the licensing, banking and tax elements of an issuance as one integrated mandate rather than three disconnected workstreams. That integration is particularly important for stablecoin issuers, where the reserve management structure, the banking relationship and the tax treatment of redemptions each carry regulatory implications that interact with the authorisation analysis.

Related at OBOLUS

FAQ

Is my token a security?

Whether a token is a security depends on the rights it confers and the economic substance of the instrument, not its name or the documentation attached to it. Across MiCA, the MAS Payment Services Act, the VARA framework and US securities law, the test is substance-driven. A token that represents an investment in a common enterprise, confers profit expectations tied to the issuer's efforts, or provides debt-like rights against a reserve may be a security in one or more jurisdictions even if it is described as a utility or governance token. A formal classification opinion is the only reliable basis for a launch decision.

Do I need a MiCA whitepaper?

Under MiCA, a whitepaper is required for most public offers of crypto-assets to EU persons, with limited exemptions for offers that are genuinely free of charge, addressed exclusively to qualified investors, or fall below applicable small-offering thresholds. For ART and EMT issuers, the whitepaper is a precondition of authorisation, not merely a disclosure document. It carries strict liability for material omissions and inaccuracies. If your token is distributed to EU retail users and you do not have a MiCA-compliant whitepaper, you are operating outside the authorisation perimeter – regardless of where the issuer is incorporated.

How should an airdrop be structured legally?

A legally sound airdrop structure starts with classification: if the distributed token is a security, an ART, an EMT or a regulated instrument in the target recipients' jurisdictions, the airdrop is a distribution event subject to the applicable authorisation and offering rules. Even for unregulated tokens, airdrops raise financial-promotion obligations in the UK, anti-money-laundering considerations around recipient identity, and potential tax-withholding obligations in certain jurisdictions. The structure should map recipient jurisdictions, apply appropriate access controls, and document the classification basis before the distribution event – not after.

OBOLUS is an independent digital-asset law boutique acting exclusively for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around every structure. Digital assets are the whole of our practice. We assess token classification against the substance of rights conferred – not the marketing label – and we structure licensing, banking and tax as one integrated mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com or reach us via t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in token classification, stablecoin authorisation regimes and cross-border CASP licensing strategy.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours