EST · MMXXVI
Home/Insights/Tax/DAO legal wrapper: A Cross-jurisdiction Comparison
DeFi, Tokenization & Smart-Contract Law

DAO legal wrapper: A Cross-jurisdiction Comparison

Dao legal wrapper: A Cross-jurisdiction Comparison. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

A DAO legal wrapper (a recognized legal entity placed around a decentralized autonomous organization to confer enforceable rights, limit member liability and satisfy regulatory obligations) is no longer an optional refinement for serious protocol operators. As DeFi matures and regulators across the major hubs move from guidance to enforcement, the question is not whether a DAO needs a legal structure – it is which structure, in which jurisdiction, and how it interacts with the governance token, the treasury and the user base across borders. This analysis maps the leading options, compares them across the decision axes that matter most to operators, and identifies where the legal exposure concentrates when no wrapper exists.

Why DAO Legal Wrappers Exist – and What Happens Without One

Without a legal wrapper, every participant in a DAO risks being treated as a general partner in an unincorporated association, exposing personal assets to the full range of the protocol's liabilities. That risk is not theoretical. Regulators in multiple jurisdictions have moved against DeFi protocols on exactly this theory, asserting that the absence of a formal entity does not insulate contributors from regulatory obligations or from civil liability when a smart contract (self-executing code that performs contractual logic on a blockchain) fails or is exploited.

The liability gap is the first and most urgent driver. A DAO that issues tokens, holds a treasury denominated in digital assets, or interacts with users who pay fees for services is, from the perspective of most tax authorities and most financial regulators, engaged in commercial activity. Without an entity, that activity pools back onto identifiable participants – developers, core contributors, multisig signatories. The wrapper shifts that exposure onto a defined legal person with capped liability and a clear regulatory interface.

The second driver is contractual capacity. A DAO with no legal personality cannot sign a custody agreement, open a bank account, hold intellectual property, or enter a vendor arrangement. DeFi protocols that reach operational scale routinely discover that the off-chain infrastructure they need – exchange listings, institutional partnerships, grant arrangements – requires a counterparty the law will recognize. A wrapper provides that counterparty.

The third driver is governance token classification. A token that entitles holders to vote on treasury allocations, fee parameters or protocol upgrades may, in several major regimes, constitute a regulated financial instrument. The legal treatment of that token – whether it is a security, a collective investment interest, a utility token or a governance right without economic entitlement – depends in part on the structure that sits behind it. A well-chosen wrapper does not by itself determine the classification, but it shapes the analysis materially.

The audience pain is real and acute: mis-classifying a token can convert a product launch into an unregistered securities offering. The wrapper analysis and the token classification analysis are not separable – they must run in parallel from day one.

The Cayman Foundation Company – the Leading Offshore Model

The Cayman Islands Foundation Company is currently the most widely used DAO wrapper globally, and for a defined operator profile it remains the strongest off-the-shelf option. A Foundation Company has no shareholders; it is governed by its constitutional documents, by a board of directors and, optionally, by a supervisor with a defined oversight mandate. Members or token holders can be given governance rights without acquiring equity interests – a structural feature that directly addresses the concern that participation in a DAO constitutes an investment contract.

The Cayman regime – supervised by the Cayman Islands Monetary Authority (CIMA) – is well understood by institutional counterparties and by legal advisers in the major common-law forums. The Foundation Company structure has been used as the wrapper for treasury management, for grant-making programs and as the contracting entity for core contributor agreements. It does not, on its own, address the regulatory status of the protocol's activities in the jurisdictions where users reside; a Cayman wrapper insulates the organizational layer, not the service delivery layer.

In our cross-border practice, operators who choose a Cayman Foundation frequently pair it with an operating entity – a BVI company, a Singapore entity or a UAE subsidiary – that holds the commercial contracts and bears the regulated-activity analysis in the markets where activity is concentrated. The Foundation sits above the operating layer, holds the intellectual property and the treasury, and interfaces with the governance token. The operating entity interfaces with users and regulators.

The structural limitation of the Cayman Foundation model is the ongoing cost and governance overhead. The requirement for a Cayman-resident director or supervisor, the need to maintain corporate records and file annual returns with the BVI FSC (where the operating vehicle is in the BVI) or CIMA, and the increasing expectation that substance requirements are met, all add to the operational burden. For a protocol at early stage, that overhead may be disproportionate.

For a counterpoint: a Cayman Foundation Company registered under the Virtual Asset (Service Providers) Act is not automatically a licensed VASP. If the protocol's activities cross the threshold for VASP registration or licensing, a separate application is required. The wrapper and the regulatory status are distinct questions.

Marshall Islands DAO LLC and Vermont BBLLC – Purpose-Built Structures

The Marshall Islands DAO LLC and Vermont's Blockchain-Based Limited Liability Company (BBLLC) both represent legislative attempts to give on-chain governance legal force – encoding the principle that decisions made through smart contract votes constitute valid organizational decisions recognized by the incorporating jurisdiction's law.

The Marshall Islands DAO LLC is a sovereign-nation structure with no corporate income tax at the entity level and no requirement that members be identified in public filings. Its appeal for protocol operators is the explicit statutory recognition of DAO governance and the relative simplicity of formation. The practical limitation is banking: the Marshall Islands carries a reputation risk that makes account opening difficult in most major financial centers. An operator relying on this structure for treasury management that involves fiat conversion or institutional partnerships will frequently find that the banking counterparty – however sophisticated – declines the relationship on correspondent-bank risk grounds.

Vermont's BBLLC is the inverse proposition: strong legal recognition within a respected common-law US state, but with the full weight of US regulatory exposure attached. For a protocol with US-based contributors, US-facing users or a governance token that the SEC might characterize as a security, a Vermont entity creates rather than resolves regulatory exposure. It works best for protocols that are genuinely US-centric, have already worked through the securities analysis and need the jurisdictional solidity of a US LLC for commercial reasons.

In our assessment, neither the Marshall Islands DAO LLC nor the Vermont BBLLC is the right primary wrapper for a cross-border protocol. Both are better understood as purpose-specific tools – the Marshall Islands structure where sovereignty and tax neutrality are the dominant concerns, the Vermont BBLLC where US legal enforceability is the primary objective.

Swiss Association and Liechtenstein Token Law – the European Dimension

Within Europe, two structures attract operator interest: the Swiss Verein (association under Swiss civil law) and the Liechtenstein token container model created under the Liechtenstein Blockchain Act.

The Swiss association is a membership organization with no share capital. Governance power attaches to membership, not to an equity interest. For a DAO where the governance token is intended to represent participation rights rather than economic entitlement, a Swiss association provides a European legal analogue to the Cayman Foundation model. FINMA has published guidance on the treatment of governance tokens, and a Swiss-domiciled DAO operating under a Verein structure has the advantage of being situated in a jurisdiction with a mature and well-regarded regulatory environment, a deep pool of legal expertise and strong banking relationships – though account opening remains selective.

The Liechtenstein token container concept is structurally distinct. It separates the token as a transferable container from the underlying right – allowing any civil-law right (membership, revenue share, voting entitlement) to be attached to a token and transferred on-chain in a legally recognized way. For a DAO that needs to confer enforceable rights on token holders without those rights being characterized as regulated securities, the Liechtenstein model offers a degree of statutory clarity that common-law jurisdictions do not yet replicate. Liechtenstein is an EEA member, and MiCA applies to it; the interaction between the Blockchain Act token classification and the MiCA (Markets in Crypto-Assets Regulation) CASP regime requires careful mapping.

The limitation of both structures is geographic: Swiss and Liechtenstein entities carry high credibility in European institutional markets but may be less familiar to Asian or US institutional counterparties. For a protocol with a globally distributed user base, the European structures solve the EU regulatory interface but do not resolve the analysis for the Asia-Pacific or US segments.

How MiCA Changes the DAO Wrapper Calculus for EU-Facing Protocols

MiCA – the EU's Markets in Crypto-Assets Regulation, now directly applicable across EU member states and supervised by ESMA together with national competent authorities – does not yet address DAOs as a distinct regulatory subject, but its perimeter reaches DeFi and DAO operations in ways that operators frequently underestimate. A DAO that issues a token qualifying as an asset-referenced token (ART) or an e-money token (EMT) under MiCA is subject to the issuer-authorization regime regardless of the wrapper structure. A CASP authorization is required for providing services such as exchange, custody, transfer or advice in relation to crypto-assets to EU users, again regardless of whether the entity is a DAO, a Foundation or a conventional company.

The practical consequence is that a DAO with EU users and no MiCA-compliant structure is in a progressively narrowing gap: the passporting benefit under MiCA applies only to a CASP authorized in an EU or EEA member state. For a protocol that began as a fully decentralized community project, obtaining CASP authorization requires establishing an identifiable legal entity in an EU or EEA jurisdiction – something a Cayman Foundation or a Marshall Islands DAO LLC cannot substitute for. A Malta MFSA or Lithuanian Bank of Lithuania route (under the MFSA VFA-to-MiCA transition or the Lithuanian MiCA CASP path) is the mechanism most accessible to new entrants, but it requires committing to a formal corporate structure, a compliance program and the capital and fee obligations the regulator sets.

Operators we advise are increasingly running a dual-wrapper analysis: a Cayman or Swiss Foundation at the DAO organizational layer, and a separate MiCA-authorized CASP entity in an EU jurisdiction for the user-facing service layer. The two entities interface through a commercial agreement that separates the governance function from the service-delivery function. This architecture does not eliminate the regulatory obligation; it structures the compliance so that it can be managed and supervised at the right level.

CTA #1 — For operators encountering the EU dimension for the first time: The structure above describes the standard path. Your facts – the entity, the user base, the token classification and the banking – change the analysis materially. For a scoped assessment of your DAO's EU exposure, contact OBOLUS at info@oboluslaw.com.

Token Classification and the Wrapper: The Inseparable Analysis

Token classification under any major regulatory regime turns on the substance of the rights conferred, not on the label applied in the whitepaper or the marketing materials. A common assumption among founders is that attaching a "utility" label to a governance token in the documentation settles the legal classification. It does not. Regulators in the US, the EU, Singapore and the UK each apply their own analytical framework, and in each case the inquiry focuses on whether the token represents an investment in a common enterprise with an expectation of profit attributable to the efforts of others – or an analogous test under the applicable local law.

For DAO governance tokens specifically, the classification analysis runs along two axes: the economic rights attached to the token and the governance rights. A token that carries no economic entitlement – no share in fees, no right to a distribution from the treasury, no redemption right – presents a stronger argument for non-security treatment than one that entitles holders to a share of protocol revenue. But governance rights alone can, in certain analytical frameworks, constitute the basis for a collective investment scheme characterization if the governance decisions effectively direct the deployment of pooled capital.

The wrapper choice intersects the classification analysis in a specific way. A Cayman Foundation or a Swiss Verein can be structured so that the governance token represents membership rights in a non-profit entity rather than an equity or investment interest. That structural choice does not guarantee a particular regulatory outcome, but it gives the operator a defensible doctrinal position in the jurisdictions where the substance-over-form analysis is most developed.

We assess classification against the substance of rights, not the marketing label. That means examining the token's economic entitlements, the governance structure behind it, the identity of the persons who can influence the protocol's direction and the distribution of the token to the public – before a whitepaper is published, not after a regulator issues a notice.

Liability Distribution Across the DAO: Developer, Multisig and Token Holder Exposure

The allocation of liability within a DAO structure depends on the wrapper, the jurisdiction and the factual matrix of who controls what. In the absence of a wrapper, liability defaults toward the most identifiable participants: founding developers who deployed the core contracts, multisig signatories who hold upgrade keys or treasury access, and publicly known core contributors. The wrapper operates to shift liability from individuals to the entity and to define the contractual and regulatory interface more clearly.

Even with a well-designed wrapper, certain liability risks persist. A developer who retains an admin key or an upgrade proxy holds functional control over the protocol regardless of the governance token distribution. Regulators and courts in common-law jurisdictions – particularly in England and Wales, the DIFC Courts and Singapore – have shown an increasing willingness to look through nominal decentralization to the persons who exercise effective control. The worldwide freezing order (an injunction freezing a defendant's assets globally), obtainable in England and Wales and in the DIFC Courts, has been applied in crypto-fraud contexts where the defendant was identifiable through on-chain analysis even without a formal corporate structure.

In a recent recovery matter we handled, a payments protocol had suffered a governance attack. The attacker had obtained enough governance tokens to pass a proposal redirecting treasury funds. We worked with on-chain forensics to trace the flow and obtained a disclosure order in a leading common-law forum. The treasury assets were frozen before the attacker could convert to fiat. The matter underscored the point: a wrapper does not make a DAO immune to legal process – it simply clarifies who is the proper defendant and through which forum relief is sought.

For token holders, liability is generally limited by the wrapper if the entity's corporate veil is maintained. The risk of token-holder liability arises where a regulator characterizes the token as conferring membership in an unregistered investment scheme, or where contributors can be shown to have operated as general partners. A well-maintained Foundation Company or LLC structure, with proper corporate governance and clear separation between the entity's obligations and the personal obligations of participants, manages but does not eliminate that risk.

Cross-Border Decision Matrix: Which Profile Should Choose Which Wrapper

The right wrapper depends on the protocol's user geography, treasury size, regulatory obligations and the capitalization of the founding team. No single structure is universally optimal. The following profiles map the leading decision axes.

Profile A – Global DeFi Protocol, No EU Service Layer, Large Treasury. A Cayman Foundation Company is the natural primary wrapper. It provides liability limitation, institutional recognition, neutral tax treatment and the flexibility to accommodate complex governance arrangements. A BVI or Singapore operating subsidiary handles commercial contracts. The timeline for establishing a Cayman Foundation is typically a matter of weeks; the ongoing compliance burden is manageable for a protocol with treasury resources to support it.

Profile B – EU-Facing Protocol, Token May Qualify as ART or EMT. A dual structure is advisable: a Cayman or Swiss Foundation at the organizational layer, and a MiCA-compliant CASP authorized by the MFSA or the Bank of Lithuania for the user-facing service delivery. The CASP authorization timeline varies by jurisdiction and by the completeness of the application; operators should budget for a process measured in months, not weeks, and engage counsel before the whitepaper is published.

Profile C – Early-Stage Protocol, US-Centric Team, No Institutional Counterparties Yet. A Wyoming DAO LLC (established under Wyoming's 2021 DAO statute, which recognized DAO LLCs as a formal LLC subtype) or a Delaware LLC offers simplicity and familiar legal infrastructure. The US regulatory exposure – particularly around token classification under SEC doctrine – must be addressed independently. The wrapper does not resolve the securities question; it simply provides a legal container while the analysis runs.

Profile D – Asian Protocol, MAS or SFC Exposure. A Singapore entity authorized under the MAS Payment Services Act as a Digital Payment Token (DPT) service provider, or a Hong Kong entity seeking a VASP licence under the SFC regime, may be the appropriate primary regulatory interface. These regimes have significant capital and compliance requirements; the Cayman or BVI Foundation structure can sit alongside the operating entity to manage the treasury and governance layers. The two-entity model is well established in both Singapore and Hong Kong practice.

The cross-border interaction is the hardest part. A protocol that chooses a single-jurisdiction wrapper often discovers that it has optimized for one regulatory environment while creating complications in two or three others. The wrapper analysis must run in parallel with the tax analysis, the token classification analysis and the AML/Travel Rule compliance assessment.

CTA #2 – For operators who have already run a first structure analysis and hit a complication: If a prior application stalled, an account was closed or a prior legal opinion did not hold under scrutiny, a second read of the structure can surface the reason and the route forward. Write to OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw.

AML, the Travel Rule and DAO Compliance Obligations

DAO wrapper structures do not insulate a protocol from AML and Travel Rule (the obligation under the FATF Recommendations to pass originator and beneficiary data alongside a virtual asset transfer) obligations where the protocol's activities meet the VASP threshold in the applicable jurisdiction. The FATF definition of a VASP – an entity that facilitates the exchange, transfer, safekeeping or administration of virtual assets, or the offer and sale of virtual assets – captures a wide range of DeFi activity, including some protocols that their operators characterize as non-custodial or fully decentralized.

Under MiCA and the associated Transfer of Funds Regulation, the Travel Rule applies to transfers involving a CASP. A DAO that operates a user-facing trading or transfer service through a MiCA-authorized entity must embed Travel Rule compliance into that entity's operations. In the VARA regime in Dubai and under the ADGM/FSRA framework in Abu Dhabi, similar AML and Travel Rule obligations apply to virtual asset service activities regardless of the organizational form of the entity conducting them.

The practical challenge for DAOs is that Travel Rule compliance requires the ability to identify counterparties, maintain records and share data with counterpart VASPs or CASPs. Those capabilities sit uneasily with the privacy architecture of many DeFi protocols. The wrapper structure must be designed to locate the compliance obligation in the entity that can technically perform it – the regulated operating entity – while insulating the governance and treasury layers from the compliance burden.

Operators we advise are increasingly building compliance into the architecture of the regulated-entity subsidiary rather than attempting to retro-fit it onto the DAO's on-chain governance layer. This is the operationally coherent approach: the regulated entity is the one that holds the user relationships, processes the transactions and files the reports. The DAO's governance layer directs the parameters under which the regulated entity operates, but it does not itself perform regulated activities.

Smart Contract Failure – Legal Liability in a Wrapped DAO

When a smart contract fails – whether through an exploit, a re-entrancy attack, an oracle manipulation or a governance vote that depletes a liquidity pool – the legal liability analysis runs first to the wrapper entity and then, depending on the facts, to the individuals who designed, deployed or maintained the contract. The wrapper determines who is the proper defendant and which law governs.

In England and Wales, the DIFC Courts and Singapore, courts have shown willingness to engage with digital-asset disputes and to apply established principles of contractual and tortious liability to on-chain interactions. The principle that a smart contract can constitute a legally binding contract, with the code operating as the terms, is now well established in common-law analysis. Where the code deviates from reasonable user expectations – or where the operator has made representations that the smart contract does not match – misrepresentation and breach of contract claims are available to affected users.

For the DAO wrapper specifically, the liability question turns on the governance structure. A Foundation Company or an LLC whose directors or managers made representations about the security or reliability of the underlying smart contract may face direct liability claims. A protocol that published an audit and relied on that audit to induce user participation faces a different exposure than one that published no representations at all. The wrapper does not eliminate the exposure; it defines its corporate locus.

In a recent matter, a mid-size DeFi protocol governed by a Foundation structure suffered an oracle manipulation that resulted in significant user losses. The affected users brought claims in a common-law jurisdiction against the Foundation on the basis that the Foundation's directors had made public statements about the protocol's security posture. We advised on the liability perimeter, the directors' obligations and the interaction between the insurance coverage the Foundation had procured and the claims being asserted. The matter resolved without trial. The key takeaway: wrapper structure shapes, but does not eliminate, director exposure when public representations have been made.

Addressing the Common Assumption: "Decentralization Removes Regulatory Jurisdiction"

A common assumption among DeFi operators is that a sufficiently decentralized protocol has no operator and therefore no regulatory nexus – that if no single entity controls the protocol, no regulator can assert jurisdiction over it. This assumption is tested and frequently fails in practice.

Regulators in the US, EU and UK have each articulated positions under which the persons who deploy, maintain, upgrade or profit from a protocol can be treated as its operators regardless of nominal decentralization. The SEC has brought enforcement actions against protocol developers on this theory. ESMA has noted in its MiCA guidance that "sufficiently decentralized" is a factual determination, not a label operators can self-assign. The FCA in the UK has made clear that the financial promotion rules apply to communications about crypto-assets regardless of the organizational form of the person making the communication.

Decentralization can, under the right circumstances, provide a genuine legal defense – but that defense requires genuine decentralization, meaning no identifiable person retaining meaningful upgrade authority, no concentrated token ownership that effectively controls governance outcomes and no off-chain coordination that drives on-chain decisions. Most active protocols do not meet that standard. For those that do not, the legal wrapper is not merely protective decoration; it is the mechanism through which the regulatory obligation is acknowledged, located and performed.

The analysis we run for clients begins with a factual assessment of who actually controls the protocol at each layer: the smart contract upgrade path, the governance token distribution, the multisig keyholders, the off-chain contributor structure, and the financial flows. That factual map determines the true regulatory exposure, and the wrapper is designed around it – not the other way around.

Related at OBOLUS

FAQ

Can a DeFi protocol be regulated?

Yes. A DeFi protocol whose activities meet the VASP or CASP threshold in a given jurisdiction – providing exchange, transfer, custody or related services in relation to virtual assets – can be subject to registration or licensing requirements under that jurisdiction's regime. Regulators including ESMA under MiCA, VARA in Dubai, MAS in Singapore and the FCA in the UK have each articulated how their perimeters reach DeFi activity. Nominal decentralization does not by itself remove regulatory jurisdiction; the factual control analysis governs.

What legal wrapper suits a DAO?

The optimal wrapper depends on user geography, treasury structure and the regulatory obligations the protocol faces. A Cayman Foundation Company is the most widely used model globally: it provides liability limitation, institutional recognition and flexible governance arrangements. For EU-facing protocols, a separate MiCA-authorized CASP entity is typically required alongside the Foundation. Early-stage US-centric protocols may use a Wyoming DAO LLC or Delaware LLC while the regulatory analysis develops. No single structure is optimal across all profiles.

Who is liable when a smart contract fails?

Liability flows first to the wrapper entity – the Foundation, LLC or association – and then potentially to individuals who designed, deployed, maintained or made representations about the smart contract, depending on the facts and the governing law. In common-law jurisdictions, courts engage with on-chain activity through established contractual and tortious principles. A well-maintained wrapper limits individual liability, but director exposure can arise where public representations about the protocol's security have been made and relied upon by users.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token and DAO classification against the substance of rights, not marketing labels – and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. To discuss your situation, contact info@oboluslaw.com.

By Lydia Brennan, Tax & Structuring Analyst – specializing in cross-border DAO structuring, token classification and the tax treatment of decentralized protocol revenue across multiple jurisdictions.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours