EST · MMXXVI
Home/Insights/Regulatory/Token legal classification: Practical Lessons for Boards
Token Offerings & Securities

Token legal classification: Practical Lessons for Boards

Token legal classification: Practical Lessons for Boards. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to O

Token legal classification sits at the center of every digital-asset product decision a board makes. Mis-classifying a token can convert a product launch into an unregistered securities offering – triggering enforcement, disgorgement and reputational damage that no whitepaper disclaimer can undo. The question is never just domestic: the entity's home regime, the jurisdictions of its users and the rails on which the token travels each apply their own test, often simultaneously.

The substance-over-label principle (the legal rule that what a token does, not what it is called, determines its regulatory category) is now the governing standard across every major regime. A board that treats classification as a marketing decision – rather than a legal one – takes on risk that compounds with each new user market entered. This analysis maps the classification tests that matter, the cross-border collisions that create the sharpest exposure and the practical steps that reduce both.

Why Token Classification Is the Most Consequential Decision in a Digital-Asset Build

Classification determines the entire regulatory perimeter of a project. Get it wrong and the licensing obligation, the disclosure regime, the transfer restrictions and the AML/CFT posture all shift – often retroactively. In our practice, we see boards treat classification as a threshold cleared at the outset and never revisited. That approach fails for one structural reason: tokens evolve. A token launched as a utility instrument can acquire value-store characteristics through secondary-market behaviour, governance additions or staking yield. Each evolution is a new classification event.

The risk compounds across borders. Under the MiCA regime (the EU's Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities), classification into the asset-referenced token, e-money token or "other" crypto-asset category triggers distinct obligations – whitepaper requirements, issuer authorisation and, for the first two categories, reserve and redemption rules. A token that qualifies as an ART (asset-referenced token) in Frankfurt may simultaneously look like a security in Singapore under the Payment Services Act framework administered by MAS, or a financial product in Hong Kong under SFC oversight.

Boards need a classification memorandum that addresses every material user-jurisdiction at launch, not a generic label appended to the whitepaper.

What Classification Tests Actually Apply – and Where They Diverge

No single global standard governs token classification; the divergence between regimes is the principal source of cross-border risk. Three analytical traditions dominate in the jurisdictions that matter most to token issuers.

The first is the investment-contract test derived from US securities law and applied by the SEC and, in commodity contexts, the CFTC. The test asks whether there is an investment of money in a common enterprise with an expectation of profit derived from the efforts of others. US persons and US-accessible offerings are in scope regardless of where the issuer is incorporated. The SEC has applied this test broadly; a utility label does not displace the analysis if the economic reality points to a profit expectation.

The second tradition is the rights-conferred test used across EU and EU-aligned regimes. Under MiCA, the issuer looks at what the token entitles the holder to do – redeem for a reference basket, claim e-money value or access a product or service. The MiCA category follows that entitlement. ESMA's guidance on the boundary between security tokens and other crypto-assets reinforces that the classification exercise is fact-specific and requires legal analysis, not a template.

The third is the substance-and-structure test applied in common-law hubs – England, Singapore, Hong Kong, the DIFC. Courts and regulators in these forums ask whether the totality of rights – economic, governance, informational – resembles an instrument regulated under financial services law. The FCA's cryptoasset perimeter guidance, MAS's digital payment token framework and the SFC's VASP licensing regime each apply variants of this logic.

A common assumption is that a token deployed on a decentralized protocol is outside every regulatory perimeter. That assumption is incorrect. The issuer's conduct in the promotion, the initial distribution and the maintenance of the network each expose identifiable parties to the applicable regime – even where no central issuer formally exists at the point of secondary trading.

How Classification Goes Wrong: Four Recurring Patterns

Classification failures cluster around four patterns we observe repeatedly across matters in the EU, the Gulf and the Asia-Pacific region.

Pattern one: the utility label without a utility function. A token is described as giving access to a platform that does not yet exist, or whose functionality is so thin that no reasonable holder would acquire it for access alone. Secondary-market price behaviour then becomes the primary driver of demand – and the investment-contract analysis follows. Regulators in multiple jurisdictions treat a meaningful, present utility as a necessary (though not sufficient) condition for a non-security classification.

Pattern two: the governance token that monetises. A token issued as a pure governance instrument – voting rights only – can remain outside the securities perimeter in several regimes. The problem arises when governance is bundled with fee-sharing, revenue distribution or buy-and-burn mechanics that create an economic return. At that point, the token begins to look like equity. The addition of yield or buyback mechanics after launch is the most common trigger for a retrospective reclassification risk.

Pattern three: the stablecoin misread as a utility instrument. An issuer that references a single fiat currency or a basket of currencies and issues tokens redeemable at par has, under MiCA, almost certainly issued an EMT (e-money token) or an ART. EMT issuance requires authorisation as an e-money institution in an EU member state. Treating the instrument as a utility token to avoid that regime is the most expensive classification error we encounter at the EU level.

Pattern four: the airdrop that creates an unregistered distribution. Airdrops of tokens that carry a profit expectation, distributed to persons in jurisdictions that apply an investment-contract test, can constitute an unregistered offering. The absence of consideration does not cure the classification issue; the economic substance and the expectation of recipients determine whether the distribution event triggers disclosure obligations.

To assess where your token sits across these patterns, contact OBOLUS at Map your options. The process above describes the standard analytical path. Your facts – the tokenomics, the user-base jurisdictions, the distribution method – shift the analysis in ways a general framework cannot anticipate.

Cross-Border Classification Collisions: The Multi-Regime Problem

For a business sitting between a European issuer entity and a user base that spans the US, the Gulf and Asia, the legal question turns on which regime's classification controls – and the answer is all of them, simultaneously, to the extent each has jurisdictional reach.

The EU's MiCA regime applies to issuers targeting EU residents or listed on EU-accessible platforms. The SEC's position on securities applies to offers and sales to US persons and to conduct occurring on US soil. MAS's framework applies to digital payment token services provided in Singapore or marketed to Singapore residents. Each test runs independently. A token can be a utility instrument under one regime and a regulated financial product under another – simultaneously and without contradiction.

This creates a classification matrix rather than a single classification decision. Operators we advise routinely run a three-column analysis: (1) the home-jurisdiction treatment, (2) the treatment in each material user-market, and (3) the treatment in the jurisdiction of any exchange or platform where the token will be listed. That matrix then drives the whitepaper, the offering restrictions, the transfer mechanics and the AML/CFT posture.

The cross-border complexity is particularly acute in the Gulf. VARA in Dubai and the FSRA in ADGM each apply their own activity-based tests, and a token that qualifies as a "virtual asset" under the VARA rulebooks may attract a distinct treatment under the FSRA's recognised virtual assets framework. Issuers targeting both Dubai and Abu Dhabi cannot assume that a single analysis covers both regulators.

MiCA Classification in Practice: The Three-Category Test

Under MiCA, every crypto-asset issued or offered to the public in the EU must be classified into one of three categories, and that classification determines the entire regulatory treatment. The classification is not elective; it follows from the instrument's characteristics.

An EMT (e-money token) maintains a stable value by referencing one official currency. The issuer must be authorised as a credit institution or an e-money institution in an EU member state. The passporting mechanism – a single authorisation allowing activity across the EU and EEA – applies, but only after the authorisation is granted.

An ART (asset-referenced token) references multiple assets – fiat currencies, commodities or other crypto-assets – or a single non-fiat asset. ARTs face the most demanding regulatory treatment under MiCA: issuer authorisation by the NCA of the member state of establishment, a detailed whitepaper, reserve asset requirements and restrictions on use as a payment medium at scale.

All other crypto-assets that do not qualify as financial instruments under existing financial services law fall into the "other crypto-assets" category. Issuers of these instruments must publish a whitepaper, notify the relevant NCA and meet certain disclosure standards – but do not need advance authorisation (subject to thresholds). This is the category most utility tokens will occupy if they genuinely confer access rights and carry no monetary reference. The critical point: a whitepaper prepared for an "other crypto-asset" does not provide a safe harbour if the token's characteristics actually place it in the EMT or ART category, or if it is a financial instrument under existing securities law.

ESMA has been clear that the boundary between MiCA-regulated crypto-assets and MiFID-regulated financial instruments requires case-by-case analysis. Boards should not assume that MiCA covers all their tokens; a security token remains governed by securities law, not MiCA, in each EU jurisdiction.

Classification Decision Matrix: Which Profile Points to Which Regime

Different token profiles carry different classification trajectories. The following matrix describes the dominant paths in our cross-border practice. It is not a substitute for legal advice on a specific instrument; it is a diagnostic tool for boards mapping their initial exposure.

Profile A – Access token with live utility and no monetary reference. The token gives access to a functioning product or service. Secondary-market value derives from demand for that access, not from a profit expectation. In most major regimes, this profile is the closest to a clear non-security, non-ART classification. The risks are: (i) US person access without sufficient functional utility, (ii) governance additions that create economic return, and (iii) exchange listing that drives price speculation disconnected from utility demand. Timeline to classification opinion: relatively short for a well-documented project. Key risk: utility atrophy after launch.

Profile B – Governance and fee-sharing token. Holders vote on protocol parameters and receive a share of protocol revenue. Under the US investment-contract test, this profile is high-risk. The fee-sharing mechanic creates the expectation of profit from others' efforts. Under MiCA, the token is likely an "other crypto-asset" but may approach the boundary with a MiFID financial instrument depending on the structuring. Timeline to opinion: longer, because the economic analysis requires detailed tokenomics review. Key risk: retrospective reclassification if fee-sharing is added post-launch.

Profile C – Fiat-referenced stablecoin. The issuer references EUR, USD or another official currency. Under MiCA, this is an EMT. EU authorisation is required before issuance. The timeline is tied to the e-money licensing process in the chosen member state, which varies by regulator and application quality. Key risk: operating without authorisation pending the licence application.

Profile D – Multi-asset reference token. The issuer references a basket (e.g. a mix of currencies and crypto-assets). Under MiCA, this is an ART. The regulatory burden is the highest in the MiCA spectrum. Key risk: the volume thresholds that trigger enhanced oversight are set at a level that a growing project can reach faster than the regulatory process moves.

If a prior classification opinion no longer reflects your current tokenomics, a second read can surface the gap and the route to compliance. Write to OBOLUS at Map your options. If a prior application stalled or a listing was rejected on classification grounds, a structural review can identify whether the issue is curable.

Whitepaper Obligations: What the Requirement Actually Demands

A MiCA whitepaper is a regulated disclosure document, not a marketing brochure; the legal standard requires accurate, fair and not misleading disclosure of material information about the issuer, the token and the risks. The obligation applies to public offers and admissions to trading of crypto-assets in the EU, subject to exemptions for small offers and offers limited to qualified investors.

The whitepaper must be notified to the NCA of the home member state before publication, though for "other crypto-assets" (as distinct from ARTs and EMTs) it need not be pre-approved. The issuer is liable for its contents. A legal opinion appended to the whitepaper that merely recites the utility label without conducting the classification analysis adds no protection – and may compound liability if the analysis is later found to be wrong.

In our practice, we see two recurring whitepaper failures. The first is the whitepaper that accurately describes the token as it exists at launch but does not address the roadmap – leaving the issuer exposed when the token acquires characteristics (governance, yield, price reference) not contemplated in the original document. The second is the whitepaper that is prepared for an "other crypto-asset" classification when the instrument's actual characteristics place it in the ART or EMT category. Both errors are structural, not drafting failures, and both require a classification re-analysis before the whitepaper can be corrected.

Outside the EU, the Travel Rule (the FATF obligation to pass originator and beneficiary data with a transfer) applies to the token's transfer mechanics regardless of the classification outcome. A token that avoids the securities perimeter still sits within the AML/CFT perimeter in every major hub that has implemented Recommendation 15. Issuers should not treat a non-security classification as a full AML clearance.

Practical Illustration: Cross-Border Classification in a Token Offering

In a recent matter, a fintech group sought to issue a token across EU, Gulf and Asia-Pacific markets simultaneously. The initial classification opinion – prepared by a single-jurisdiction adviser – concluded the token was a utility instrument and proceeded on that basis. By the time the group engaged us, it had received a comment letter from an EU regulator noting that the token's fee-sharing mechanic and price-reference mechanism created ART characteristics. A second classification analysis, run against MiCA, the VARA rulebooks and the MAS digital payment token framework in parallel, confirmed the token required ART authorisation in the EU, a separate VARA licence in Dubai and a standard payment institution licence in Singapore. The group paused the public offer, restructured the tokenomics to remove the monetary-reference mechanic and re-filed. The delay cost months of development time and a restated whitepaper. The lesson: a cross-border classification opinion is not an aggregation of single-jurisdiction opinions; it requires a framework that maps the interactions between regimes.

Airdrop Structuring: The Overlooked Classification Event

An airdrop – the distribution of tokens to wallet addresses without direct monetary consideration – is widely assumed to sit outside the regulatory perimeter. That assumption does not survive scrutiny in most major jurisdictions. The classification question at an airdrop is not "was there payment?" but "does the recipient acquire a regulated instrument?" If the token is a security in a given jurisdiction, its distribution by airdrop is a distribution of a security and triggers the applicable disclosure or exemption regime.

Under the US framework, an airdrop of tokens that qualify as investment contracts to US persons – even gratuitously – can constitute an unregistered offering. The absence of consideration does not defeat the analysis; the SEC has taken positions consistent with applying securities law to promotional distributions. Operators we advise with US-accessible airdrops typically implement a geofenced distribution, KYC-based eligibility screening or a combination, depending on the token's classification.

Under MiCA, a gratuitous distribution does not automatically exempt the issuer from whitepaper obligations if the airdrop constitutes a public offer. The "small offer" exemption applies to offers below the applicable threshold across a twelve-month period; above that threshold, the whitepaper notification obligation applies regardless of whether recipients pay. Boards planning large-scale airdrops should run the exemption calculation before distribution, not after.

The structural tool most commonly used in well-advised airdrop programs is the work-for-token or task-completion mechanic, where distribution is contingent on the recipient completing a functional interaction with the protocol (rather than a passive lottery). This mechanic does not change the classification of the token, but it strengthens the argument that the distribution is tied to utility demand rather than speculative expectation. It is a mitigating factor, not a classification defence on its own.

A Common Assumption Boards Make – and Why It Does Not Hold

A common assumption is that labelling a token "utility" in the whitepaper settles the legal classification. It does not. The substance-over-label principle is explicit in every major regime that has addressed token classification: the rights conferred by the instrument, the economic reality of how it is acquired and held, and the reasonable expectations of the holder all determine the category. A whitepaper that describes a token as a utility instrument does not change the legal analysis if the token's actual characteristics point to a security or an ART.

The label may, in fact, increase exposure. An issuer that publicly represents a token as a utility instrument and subsequently faces a reclassification has a disclosure problem in addition to a classification problem. Regulators and claimants in enforcement and civil actions have both used the gap between the label and the substance as evidence of intent to circumvent the regulatory regime.

The correct approach is to conduct the classification analysis first, document the conclusion with legal reasoning, and then describe the token in the whitepaper and marketing consistently with that analysis. Where the analysis produces genuine uncertainty – as it often does at the margin between a utility token and a governance/yield instrument – the whitepaper should acknowledge the regulatory uncertainty rather than assert a conclusion the legal analysis cannot fully support.

We assess classification against the substance of rights, not the marketing label. That standard is the one regulators apply, and it is the standard that protects the board when a regulator asks the question.

Related at OBOLUS

FAQ

Is my token a security?

There is no universal answer; the classification depends on the rights the token confers and the regime of each jurisdiction where it is offered or traded. Under the US framework, the investment-contract test asks whether there is a profit expectation from others' efforts. Under MiCA, the test asks whether the token is an ART, an EMT or a financial instrument under existing securities law. A legal opinion must address each material jurisdiction separately, not by reference to a single label. Engage qualified counsel before the public offer, not after a regulator raises the question.

Do I need a MiCA whitepaper?

An issuer offering crypto-assets to the public in the EU – or seeking admission to trading on an EU-accessible platform – generally requires a MiCA-compliant whitepaper, unless an exemption applies. Exemptions exist for small offers below the applicable threshold within a twelve-month period and for offers limited to qualified investors. The whitepaper must be notified to the NCA before publication for "other crypto-assets"; ARTs and EMTs require fuller NCA engagement. The obligation attaches to the offer, not to the issuer's location. A non-EU issuer targeting EU users is within scope.

How should an airdrop be structured legally?

The starting point is the classification of the token being airdropped. If it is a regulated instrument in any jurisdiction reached by the distribution, the airdrop is a distribution of that instrument and triggers the applicable exemption or disclosure regime. Practical measures – geofencing, eligibility screening and work-for-token mechanics – reduce exposure but do not replace the classification analysis. Boards should run the exemption thresholds under MiCA, assess US-person reach under the investment-contract test and document the structuring rationale before distribution begins, not after.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess classification against the substance of rights, not the marketing label – the standard regulators apply in every major hub. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when token-related disputes arise. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in cross-border token classification, MiCA compliance and VASP regulatory analysis for issuers operating across the EU, Gulf and Asia-Pacific.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours