Mis-classifying a token can convert a product launch into an unregistered securities offering. That single observation sits at the center of nearly every NFT project legal dispute we have seen in recent years. Whether the token is an edition of digital art, a membership pass, a revenue-sharing instrument or a fractionalized real-world asset, the legal analysis begins not with the marketing label but with the rights the instrument actually confers.
NFT project legal structuring requires teams to resolve, in sequence, four distinct questions: what is the token, who is offering it, from where, and to whom. The answers determine which regulatory regime applies, which legal vehicle holds the IP and the smart-contract code, how royalties and secondary-market proceeds are taxed across the jurisdictions where buyers sit, and who bears liability when the smart contract (the self-executing code that governs minting, transfer and royalty distribution) does not perform as marketed. This analysis works through each of those questions in turn, drawing on the comparative positions taken by regulators in the major hubs.
The regulatory environment for NFTs is in active formation. As leading authorities converge on classification approaches derived from the MiCA regime in Europe and its functional equivalents elsewhere, founders and their counsel face a window in which early structuring decisions carry outsized consequences.
What Is an NFT as a Matter of Law?
The legal category of a non-fungible token is not determined by the blockchain standard that issues it; it is determined by the rights the token confers on its holder. That is the starting principle applied by every serious regulatory authority, and it is the most frequently misunderstood point in the market.
A token that gives its holder a claim to a share of revenue, a right to profits, or an economic interest in an underlying asset functions, in substance, as a security or a collective investment instrument – regardless of whether the project team calls it a "utility pass" or an "art edition." The MiCA framework, administered by ESMA and national competent authorities across the EU, explicitly acknowledges that NFTs may fall outside its scope where they are genuinely unique and non-fungible, but it also identifies when a nominally unique token is in substance an asset-referenced instrument or a financial instrument under the Markets in Financial Instruments Directive. The distinction turns on economic substance, not label.
In the United States, the SEC and CFTC apply a functional analysis rooted in decades of securities doctrine. An NFT that promises holders a share of royalty income, that is marketed on the basis of expected appreciation driven by the project team's efforts, or that is fractionalized into fungible sub-units for trading will attract scrutiny as an unregistered security. The enforcement record in this space is not hypothetical; it reflects regulatory action taken against projects that relied on a whitepaper utility label without substantive analysis.
In Singapore, the MAS applies an analogous functional test under the Payment Services Act and the Securities and Futures Act: the question is whether the digital token constitutes a capital markets product. In Hong Kong, the SFC takes the same approach under its VASP licensing regime, and has signaled that NFTs linked to investment returns or collective schemes will be treated accordingly.
The practical upshot is that the legal starting point for any NFT project is a classification opinion – a structured analysis of the rights bundle the token encodes, the marketing representations made around it, and the reasonable expectations a purchaser in the target market would form. A common assumption held by founders is that attaching a utility function to a revenue-sharing token resolves the classification question. It does not. Regulators assess the full picture.
What Entity Structure Should an NFT Project Use?
The legal vehicle through which an NFT project is organized shapes every subsequent decision: where IP sits, who can enter contracts with platforms and marketplaces, how proceeds are distributed, and which jurisdiction's insolvency law governs a failure.
Most projects operate across at least three legal planes simultaneously. The creative IP – artwork, code, brand – typically sits in a company incorporated in a favorable jurisdiction for IP holding and tax treatment. The smart-contract deployment and protocol governance may sit in a DAO (decentralized autonomous organization) wrapper or in a foundation structure. The commercial relationships – exchange listings, platform agreements, influencer contracts – require a counterparty with legal personality, which a bare DAO does not provide in most jurisdictions.
For projects that are clearly outside the financial-instrument perimeter, common structures include a foundation or non-profit entity in Switzerland (operating under FINMA regulatory visibility without necessarily requiring a licence), a company limited by guarantee in the BVI under BVI FSC oversight, or a Cayman Islands foundation company under the CIMA framework. Each has different implications for tax, liability and governance.
Where the project has a commercial studio producing content or providing services, a separate operating company – often in a jurisdiction with a developed IP regime and a network of double-tax treaties – typically sits alongside the foundation. The studio invoices the foundation for development services; the foundation controls the protocol and treasury. This bifurcation is not structuring for its own sake. It serves the legitimate purposes of separating commercial risk from protocol assets and creating a defensible entity layer for regulator and platform engagement.
For projects that incorporate governance tokens alongside their NFT collections – giving holders votes over treasury deployment or royalty parameters – the DAO question becomes acute. FINMA in Switzerland has developed a body of practice around association and foundation structures for token-governed protocols. The AIFC in Kazakhstan, operating under AFSA supervision, offers a common-law framework attractive to projects seeking a regulated but flexible environment in Central Asia. In the DIFC, projects can establish recognized bodies under DIFC law with governance rights that have legal effect in UAE courts.
The cross-border reality is unavoidable: an NFT collection sold globally has buyers in every major jurisdiction. The entity structure cannot be designed around one regulator's comfort zone alone. We regularly advise on structures that operate across three or more jurisdictions simultaneously, coordinating the foundation, the studio and the commercial vehicle so that each element is defensible to its local authority.
The process above describes the standard analytical path. Your facts – the token design, the buyer geography, the team's regulatory history – alter the analysis materially. For a scoped structuring assessment, contact OBOLUS at info@oboluslaw.com.
How Does IP Ownership Work in an NFT Project?
IP ownership in an NFT project is almost never what the parties assume it to be at the time of launch, and the misalignment surfaces either in enforcement or in a secondary-market dispute.
When an artist mints an NFT, the default position under the copyright law of most jurisdictions is that the artist retains the underlying copyright. The buyer of the NFT acquires a token – an on-chain record of ownership of that token – but does not automatically acquire any copyright in the associated work. The scope of the buyer's rights depends entirely on the terms attached to the token, whether in a licence agreement incorporated by reference in the smart contract or in a separate terms-of-service document.
Many projects launch with terms that are ambiguous on three critical points: whether the buyer may use the associated art commercially, whether sub-licensing is permitted, and what happens to the licence on a secondary transfer. Each of those gaps is a potential liability. In the jurisdictions where NFT markets are most active – the United States under SEC and federal copyright oversight, the UK under FCA-adjacent frameworks, and across the EU under MiCA and applicable IP directives – courts are applying existing IP doctrine to on-chain instruments without modification. The fact that transfer is recorded on a blockchain does not create a new form of ownership.
The tokenization of real-world assets adds a further dimension. When an NFT purports to represent an interest in physical property, a fund unit, or a contract right, the legal question is whether the on-chain instrument actually conveys that interest as a matter of the governing law, or whether it is merely a record that an off-chain interest exists. In most jurisdictions, the off-chain instrument – the deed, the assignment, the share certificate – remains the legally operative document. The NFT is an index, not a deed. Structuring a project around the assumption that the token is the asset exposes the team to liability when the on-chain and off-chain records diverge.
In our practice, we see IP assignment agreements between the founding team and the project entity drafted after the smart contract is deployed. This sequence creates significant risk: if the founders retain copyright until the assignment is executed, and the assignment is never properly completed, the foundation does not own what it thinks it owns. We address this at the outset, before minting begins.
What Are the Tax Implications of Secondary Royalties Across Borders?
Secondary-market royalties – the percentage of resale value that flows back to the creator or the project treasury on each NFT transfer – are one of the most commercially significant and legally under-analyzed features of NFT projects.
The tax treatment of royalty income varies materially by jurisdiction and by the characterization of the underlying token. In most EU member states operating under the post-MiCA framework, royalty income received by a company is taxed as ordinary business income. Where the royalty flows to an individual creator, it may be characterized as employment income, self-employment income or capital income depending on the facts. The VAT position is unsettled in several member states: whether an NFT sale constitutes a supply of services or a supply of goods for VAT purposes affects the rate, the place of supply and the recovery of input VAT.
In the United States, the IRS treats digital-asset transactions as property transactions for federal tax purposes. A royalty stream from NFT secondary sales received by a US person or a US-connected entity is taxable income. The characterization as royalty income rather than capital gain matters significantly for the applicable rate. For non-US project teams receiving royalties into offshore entities, the US withholding tax analysis turns on whether the royalty has a US source – which it may, if the underlying IP was created or licensed in the United States.
Singapore's MAS-adjacent tax framework, administered by the Inland Revenue Authority of Singapore, treats digital-token transactions under general income tax principles. The question of whether royalty income from NFT sales is Singapore-sourced depends on where the economic activity generating that income is located.
The cross-border compounding effect is significant. A project incorporated in Switzerland (FINMA environment) with buyers in the US, EU and Singapore, distributing royalties to a multi-jurisdictional founding team, faces at minimum four distinct tax analyses simultaneously. The entity structure – where the IP is held, where the smart contract is deployed, where the operating team sits – determines whether those analyses produce acceptable outcomes or create overlapping taxable events without available treaty relief.
We structure the royalty flow as part of the initial mandate, not as an afterthought. The smart contract encodes the royalty mechanics; the entity structure must encode the tax mechanics simultaneously. Treating them as separate workstreams is the error we most frequently correct in restructuring engagements.
When Does an NFT Become a Regulated Financial Instrument?
An NFT crosses the regulated financial-instrument perimeter when the rights it encodes give its holder an economic claim that a court or regulator would characterize as a security, a collective investment scheme interest, or an asset-referenced token under the applicable regime.
The triggers are well-established in the major jurisdictions, even where the specific NFT guidance remains in draft or is delivered through enforcement rather than formal rulemaking. The following profile elements, individually or in combination, will attract regulatory scrutiny:
- Revenue-sharing rights: the holder receives a proportional share of project income, platform fees or royalty pools.
- Profit participation: the token grants rights to distributions from a treasury or fund managed by the project team.
- Fractionalization: a nominally unique token is divided into fungible sub-units tradeable on secondary markets, converting a non-fungible instrument into something that functions as a security.
- Pooled investment features: holders contribute assets to a pool managed by the team, expecting returns from the team's efforts.
- Promises of appreciation: marketing emphasizes expected price increases driven by the team's work rather than the holder's own use of the token.
Under MiCA, an NFT that is in substance an asset-referenced token (a token maintaining a stable value by reference to other assets) or that constitutes a financial instrument under MiFID II falls within the regulated perimeter regardless of the label. The issuer would require CASP authorisation or a more specific financial-services licence. The national competent authority in the relevant member state – operating under ESMA coordination – is the relevant regulator.
In the UK, the FCA's financial-promotion rules apply to communications about cryptoassets that are "qualifying cryptoassets." The scope of that definition, and its intersection with NFTs that carry financial rights, requires specific analysis for each project seeking to market to UK persons.
For projects that straddle the perimeter – where some token editions are clearly artistic and others carry revenue rights – the structuring question becomes whether to maintain a single collection with differentiated terms or to separate the financial-instrument editions into a distinct offering with appropriate regulatory clearance. We have advised on both approaches. The single-collection model is simpler operationally but creates a regulatory surface area that must be actively managed; the bifurcated model adds structural complexity but provides cleaner regulatory boundaries.
Who Bears Liability in a DAO-Governed NFT Project?
Liability in a DAO-governed NFT project defaults, absent a proper legal wrapper, to the individuals who exercised control – the founding team and, in some jurisdictions, active governance participants. This is the central liability risk of the "sufficiently decentralized" model as a legal strategy.
A DAO without a legal wrapper is, in most jurisdictions, a general partnership or an unincorporated association. General partnership law in England and Wales, in the major US states and in most EU member states imposes joint and several liability on partners for the obligations of the partnership. If the DAO's smart contract causes a financial loss – through a bug, an exploit, an unauthorized parameter change put to a governance vote – the question of who is liable resolves, in the absence of a legal entity, by reference to who controlled the relevant decisions.
The Wyoming DAO LLC statute, the Marshall Islands DAO framework, and the foundation structures available in Switzerland and Liechtenstein each provide legal personality with limited liability. Each carries different governance constraints. In our practice, the choice of DAO wrapper turns on three factors: where the founding team is based (and therefore exposed), where the primary user base and associated legal risk sits, and whether the project requires a regulated activity licence in any jurisdiction that has specific entity-type requirements.
Smart-contract liability is a distinct but related question. When a smart contract misfires – executing a transfer that the parties did not intend, or failing to execute a royalty payment that the token terms promised – the liability analysis depends on whether the smart contract terms are incorporated into an enforceable legal agreement and which jurisdiction's contract law governs. In England and Wales, courts have held that digital assets can be property and that smart-contract terms can constitute binding contract terms where the usual formation elements are present. The DIFC Courts have reached analogous conclusions.
The cross-border dimension is particularly sharp here. A DAO governing an NFT protocol with participants in 40 jurisdictions cannot rely on a single governing-law clause to resolve all potential disputes. We address this through a combination of a clear legal wrapper, a choice-of-law and choice-of-forum provision in the token terms, and – for projects with material treasury assets – a protocol-level arrangement with a custodian in a jurisdiction where courts have developed crypto-asset jurisprudence.
If a prior structure was deployed without a legal wrapper, or if a governance dispute has surfaced, a structural review can identify the exposure and the remediation path. Write to OBOLUS at info@oboluslaw.com or message us at t.me/oboluslaw.
A Restructuring Engagement: Revenue-Sharing NFT Reclassification
In a recent matter, a digital-media studio had launched a collection of NFTs that included a contractual right to receive a share of platform subscription revenues. The collection had been structured as a pure art release, without regulatory counsel, on the basis that the utility of the token – access to exclusive content – was the primary value driver. When the studio sought to list the token on a regulated exchange in a leading Asian financial center, the exchange's legal team identified the revenue-sharing right as a probable securities-law trigger and declined the listing pending structural remediation.
We were engaged in the subsequent quarter to advise on the remediation path. The analysis covered three questions: whether the existing token terms could be amended without creating a further regulatory event, which jurisdiction offered the clearest route to a compliant structure, and how the studio could ring-fence the non-financial editions of the collection – which were genuinely artistic – from the regulated editions. We coordinated with allied counsel in the relevant Asian jurisdiction and with the studio's local IP counsel. The outcome was a bifurcated structure: the revenue-sharing editions were reclassified under the applicable financial-services framework, and the artistic editions continued under amended terms that removed any economic-return language. The exchange listing proceeded for the compliant tranche.
The case illustrates a consistent pattern in our practice: regulatory exposure in NFT projects is almost always a structuring problem, not an enforcement problem – if it is identified before the irreversible steps are taken.
Which Legal Structure Fits Which NFT Project Profile?
The right structure for an NFT project is a function of the token's rights profile, the founding team's jurisdiction, the target market, and the project's governance model. There is no universal answer, but the following decision branches cover the profiles we encounter most frequently.
Profile A – Pure digital art or collectible, no financial rights, founder team based in the EU. The token is clearly outside the MiCA financial-instrument perimeter. The primary legal vehicle is a company or studio in a favorable EU member state, with IP assigned to the operating entity before minting. The main legal risks are IP ownership clarity and consumer-facing terms. Regulatory engagement with an NCA under ESMA coordination is not required, but GDPR-compliant data practices and clear buyer-terms are. Timeline to a defensible launch structure is typically a matter of weeks.
Profile B – Membership or access NFT with community governance (DAO), international buyer base. The governance token creates DAO-wrapper risk. The recommended structure includes a foundation in Switzerland or a Cayman Islands foundation company, with a separate operating studio for commercial contracts. IP is held by the foundation. The DAO wrapper gives legal personality. Token terms include a choice of law and a dispute-resolution provision pointing to a well-developed crypto forum. Regulatory analysis is required for each of the primary buyer jurisdictions. Timeline to full structural deployment is typically several months, depending on complexity.
Profile C – NFT with revenue-sharing or profit-participation rights, global marketing contemplated. This profile sits at or over the financial-instrument perimeter in most major jurisdictions. The project requires either a regulatory licence (CASP under MiCA, a capital-markets licence under SFC in Hong Kong, or equivalent) or a structural redesign that removes the financial-instrument elements. If the financial rights are essential to the commercial model, the structure must be built around the regulatory requirements from the outset – entity type, capital, disclosure and ongoing reporting obligations included. Attempting to retrofit compliance after launch is materially more expensive and carries reputational risk.
Profile D – Fractional NFT or tokenized real-world asset. Fractionalization converts a non-fungible instrument into a fungible one. In virtually every major jurisdiction, this triggers the financial-instrument analysis. The applicable regime depends on the nature of the underlying asset and the jurisdiction of issue and offer. Legal structuring requires, at minimum, a classification opinion, a prospectus-equivalent disclosure document, and a regulated offering process. Allied counsel in the relevant jurisdiction is required for any primary offering to retail investors.
Do AML Rules and the Travel Rule Apply to NFT Transactions?
AML obligations apply to NFT transactions where the NFT platform or the project team constitutes a virtual asset service provider (VASP) under the FATF Recommendations – specifically Recommendation 15, which requires VASPs to implement AML/CFT controls including customer due diligence and transaction monitoring.
Whether an NFT marketplace or a project's primary-sale mechanism constitutes a VASP depends on the jurisdictional implementation of the FATF standard. Under MiCA, crypto-asset service providers require authorisation; the scope of that requirement extends to secondary-market platforms that provide trading or exchange services. The EU's AML framework – separately from MiCA – applies AML obligations to CASPs. In the US, the FinCEN analysis of whether an NFT platform is a money-services business turns on whether the platform transmits value or merely facilitates peer-to-peer transactions.
The Travel Rule – the obligation, derived from FATF Recommendation 16, to pass originator and beneficiary information alongside a virtual-asset transfer – applies to VASP-to-VASP transfers. Its application to NFT transfers is context-dependent: where the NFT is classified as a virtual asset and the transfer is processed by a VASP, Travel Rule compliance is required in jurisdictions that have implemented the standard. The technical implementation of the Travel Rule for non-fungible, one-of-a-kind tokens creates practical challenges that the industry is still resolving.
For project teams, the AML analysis at the structuring stage determines whether a know-your-customer program must be built into the minting and secondary-sale infrastructure from day one. Retrofitting KYC into a live smart contract is materially harder than encoding the compliance hooks at the outset.
A Common Assumption: The Utility Label Settles Classification
A common assumption among project founders – and, regrettably, among some non-specialist counsel – is that attaching a utility function to a token resolves the regulatory classification question. It does not, and the enforcement record in multiple jurisdictions confirms the point.
The utility label is a marketing description, not a legal conclusion. Regulators assess classification against the economic substance of the rights conferred. A token that gives its holder both a utility function (say, access to a game or a platform) and an economic right (say, a share of in-game revenue or a redemption right at a stated value) is analyzed as a whole. If the economic right is material – if a reasonable investor would factor it into the purchase decision – the token's classification follows the economic right, not the utility label.
This is the analytical approach applied by ESMA under MiCA, by the SFC in Hong Kong, by the MAS in Singapore, and by the SEC in the United States. We assess classification against the substance of rights, not the marketing label. That assessment must be documented before the token is offered publicly, because the analysis becomes significantly harder to conduct credibly after the offering terms are public.
The practical implication is that a pre-launch classification opinion – prepared by counsel with cross-border visibility, covering at minimum the primary jurisdiction of issue and the primary jurisdictions of offer – is not a luxury for large projects. It is the document that determines whether the project team is operating within or outside the law from the moment the first token is minted.
Related at OBOLUS
- DeFi, Tokenization and Smart-Contract Law – our practice group for protocol legal structuring and token law advice
- Legal Counsel for DeFi Protocols – how we advise protocol teams from launch through governance and disputes
- Interim Relief for Digital Assets: Injunctions and Receivers – emergency remedies available when NFT or token assets are misappropriated
FAQ
Can a DeFi protocol be regulated?
Yes. Whether a DeFi protocol is regulated depends on whether it provides a service that falls within the regulated perimeter in one or more jurisdictions where it is accessible – irrespective of whether it operates through smart contracts rather than a corporate intermediary. Regulators in the EU under MiCA, the UK under FCA rules, and the US under SEC and CFTC frameworks assess the economic function of the protocol. Where a protocol performs an exchange, lending, custody or asset-management function, the regulatory analysis applies to the persons who control or deploy it, not merely to the code itself.
What legal wrapper suits a DAO?
The appropriate legal wrapper for a DAO depends on the jurisdiction of the founding team, the nature of the protocol's activities and the regulatory environment in the primary markets served. Common options include a Swiss association or foundation, a Cayman Islands foundation company, a Wyoming DAO LLC or a Marshall Islands DAO. Each provides legal personality and some form of limited liability while accommodating on-chain governance. The choice turns on the tax treatment of the treasury, the licensing requirements imposed by applicable regulators and the forum preferred for dispute resolution.
Who is liable when a smart contract fails?
Liability for a smart-contract failure turns on whether the contract terms are incorporated into a binding legal agreement, who controlled the relevant deployment or governance decision, and which jurisdiction's law governs. In England and Wales and in the DIFC Courts, courts have held that digital assets are property and that smart-contract terms can constitute enforceable contract provisions. Where a DAO lacks a legal wrapper, the founding team and active governance participants may face direct liability as members of an unincorporated association or general partnership. A legal wrapper with a clear governing-law clause materially reduces, but does not eliminate, this exposure.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – and we assess token classification against the substance of rights, not the marketing label. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Lydia Brennan, Tax & Structuring Analyst – specialist in cross-border tax structuring for NFT projects, token offerings and DeFi protocol treasury arrangements across EU, UK and Asia-Pacific jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.