Stablecoin issuance sits at the intersection of securities law, payments regulation and monetary policy – and most boards discover that only after the authorisation process has begun.
A business planning to issue a stablecoin (a token whose value is pegged to a reference asset, most commonly a fiat currency or a basket of assets) faces a classification decision before it faces a regulatory one. Get the classification wrong and the authorisation path that follows will be wrong with it. Under MiCA, the European Union's regime for crypto-assets, a stablecoin is either an asset-referenced token (ART) or an e-money token (EMT) – and each triggers a materially different authorisation route. In Dubai, VARA's activity-based rulebooks apply. In Singapore, the Monetary Authority of Singapore (MAS) applies its Payment Services Act framework. The practical lesson for boards is that stablecoin issuance authorisation is never a single-jurisdiction question, and the classification decision is always made on the substance of the rights conferred – not on the label printed in the marketing deck.
This analysis works through the classification logic, the authorisation paths across the leading hubs, the cross-border tensions that boards consistently underestimate, and the structural mistakes we see most often. It closes with a decision matrix by issuer profile and a set of questions every board should put to counsel before committing to a structure.
Why Token Classification Comes Before Authorisation
The classification of your token determines which regulatory regime applies, which regulator you face, and what capital, reserve and disclosure obligations attach. No authorisation analysis is valid until classification is settled.
Token classification logic is built on substance over label. A token called a "utility token" on a whitepaper is still a security if it confers rights that look like investment returns, profit participation or governance over a commercial enterprise. Regulators and courts across every major hub have said so repeatedly. The same principle applies to stablecoins: calling a token "stable" does not determine whether it falls under an EMT regime, an ART regime, a payments licence, or – in some scenarios – securities regulation.
Under MiCA, the classification turns on the nature of the reference asset and the rights conferred. A token referencing a single fiat currency and redeemable at par is an EMT, requiring authorisation as an electronic money institution or by a credit institution. A token referencing a basket of assets – currencies, commodities, or other crypto-assets – is an ART, attracting a separate and generally more demanding authorisation path that includes reserve composition rules and enhanced redemption obligations.
Outside the EU, the analysis shifts but the logic does not. In the United Kingdom, the FCA applies its own framework under the relevant provisions of the payments and financial-services regimes. MAS in Singapore distinguishes between DPT (digital payment token) services and regulated e-money issuance under the Payment Services Act. The FSRA within ADGM operates a "recognised virtual assets" concept that affects which tokens may be intermediated at all, let alone issued. Boards that map only one jurisdiction before committing to a structure routinely discover that the same token requires a second or third authorisation as the user base expands.
For a scoped assessment of how your token would be classified under the regimes relevant to your target markets, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the reference asset, the redemption mechanism, the user base, the distribution model – change the analysis in every case.
How Does MiCA Treat ARTs and EMTs Differently in Practice?
MiCA's distinction between ARTs and EMTs is not a labelling exercise – it produces fundamentally different authorisation obligations, reserve requirements and ongoing governance duties, and boards should treat the two tracks as separate regulatory programmes.
An EMT issuer must be authorised as an electronic money institution or a credit institution under applicable EU law and must comply with the specific EMT provisions of MiCA on top of that base authorisation. The whitepaper obligations under MiCA apply: the issuer must prepare, notify and publish a compliant whitepaper before any offer to the public or admission to trading. Redemption must be available at par at any time. The reserve must be segregated and held in safe, low-risk assets – the exact composition requirements are set by the regime and are not a commercial discretion.
An ART issuer faces a distinct authorisation path. Issuers below the thresholds set by MiCA may be able to seek authorisation from a national competent authority (NCA) rather than directly from ESMA, but the whitepaper requirements, the reserve rules and the governance obligations are more stringent than those for EMTs. Significant ARTs – those meeting the thresholds that trigger ESMA direct supervision – move to a still more demanding level.
In our practice, we have seen boards underestimate the time required to prepare a compliant MiCA whitepaper. The document is not a marketing prospectus: it carries statutory liability for material misstatements and must address the rights and risks of the token with precision. We regularly advise on the legal review of whitepaper drafts and on the interaction between the whitepaper disclosure obligations and the securities-law analysis that must precede it. A whitepaper that discloses rights that look like investment rights can trigger a securities classification review even after a MiCA authorisation is under way.
What Does Authorisation Look Like in the Gulf Hubs?
Dubai's VARA and Abu Dhabi's FSRA operate distinct regimes – a stablecoin issuer targeting the Gulf must assess both, and the analysis does not collapse into a single answer.
VARA's activity-based regime covers virtual-asset issuance as a regulated activity. The VARA rulebooks set out the conditions under which a business may issue virtual assets in or from Dubai (mainland, excluding DIFC). An issuer of a stablecoin must satisfy VARA's requirements on disclosure, reserve management and governance. VARA has been clear that the issuance of a token that functions as an e-money equivalent triggers specific requirements distinct from those applying to utility or exchange tokens. The application process involves a multi-stage review that includes documentation of the reserve structure, the smart-contract audit and the compliance programme.
Within the DIFC, the FSRA administers its own regime under the ADGM/FSRA framework. The FSRA's "recognised virtual assets" concept is relevant: a token must be assessed against the FSRA's own classification criteria before any regulated activity in respect of it may take place. An issuer whose token is not a recognised virtual asset under the FSRA framework faces a more constrained path within the DIFC than outside it.
The practical cross-border tension for issuers targeting both hubs – as many do – is that the two regimes do not passport between each other. An authorisation from VARA does not confer any regulatory standing within the DIFC, and vice versa. Boards building a Gulf strategy should budget for two parallel authorisation tracks, with separate disclosure documents, reserve structures and compliance programmes calibrated to each regulator.
To map the licence, banking and reserve-structure stack for your Gulf build, write to info@oboluslaw.com. If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back.
What Is the Cross-Border Stacking Problem for Stablecoin Issuers?
Stablecoin issuance is inherently cross-border: the issuer may be in one jurisdiction, the reserve assets in another, the distribution infrastructure in a third, and the end users in dozens more – and each link in that chain can trigger a separate regulatory obligation.
The stacking problem is structural. Consider a token issued by an EU entity (triggering MiCA's ART or EMT regime), distributed through an exchange with a Singapore licence (triggering MAS's Payment Services Act requirements for dealing in DPTs), held by users in the UK (triggering FCA financial-promotion rules), with reserve assets held by a US custodian (triggering FinCEN and potentially state money-transmitter obligations). None of those individual regulatory relationships negates the others. Each runs in parallel. A compliance failure in one jurisdiction does not immunise the issuer in the others – it frequently makes the others worse.
Reserve management adds a further cross-border dimension. Regulators require that reserve assets be segregated, safely held and available to meet redemption demands. If reserve assets are held in a jurisdiction where the issuer has no regulatory standing, the access risk in a stress scenario is real. We have seen authorisation applications stall specifically because the proposed reserve structure relied on custodians or banking arrangements in jurisdictions where the issuer could not demonstrate reliable access.
The cross-border AML obligation is equally layered. The Travel Rule (the obligation to pass originator and beneficiary data with each transfer above the applicable threshold) applies under FATF Recommendation 15 and its domestic implementations across all major hubs. A stablecoin transfer routed through multiple VASPs in different jurisdictions triggers Travel Rule obligations at each hop. An issuer that does not build Travel Rule compliance into the token's distribution architecture from day one will find retrofitting expensive and, in some cases, technically constrained by the smart-contract design.
When Does a Stablecoin Become a Security?
A stablecoin can cross into securities regulation when its economic substance – yield, profit participation, or dependency on the managerial efforts of the issuer – resembles a debt or equity instrument more than a payment medium.
This is not a theoretical risk. Algorithmic stablecoins that generate yield by deploying reserve assets into lending or liquidity protocols have attracted regulatory scrutiny in multiple jurisdictions on the basis that they function as collective investment vehicles rather than payment instruments. The SEC in the United States has consistently applied its existing securities framework to token issuances that exhibit investment-contract characteristics, regardless of the token's label. A stablecoin issuer whose reserve strategy produces distributable returns to token holders should take securities counsel before assuming the payments-regulation track is the only one that applies.
The UK FCA has similarly drawn attention to the distinction between regulated stablecoins operating as systemic payment instruments and stablecoins that more closely resemble regulated investments. The MiCA regime in the EU does not fully resolve the question: MiCA's scope excludes tokens that qualify as financial instruments under MiFID II, meaning that an ART or EMT analysis under MiCA is not the end of the securities analysis – it is the beginning of the question of whether MiCA applies at all.
In our cross-border practice, we assess stablecoin structures against the securities-law frameworks of every jurisdiction in which the token will be offered, distributed or traded. The analysis considers the rights conferred, the economic dependency on issuer performance, the governance architecture, and the distribution model. A token that clears the securities analysis in one jurisdiction does not automatically clear it in another.
How Should Boards Structure the Reserve and Banking Stack?
The reserve and banking architecture of a stablecoin issuer is a regulatory deliverable, not a treasury preference – regulators across every major hub treat the reserve structure as a condition of authorisation, not a post-authorisation operational decision.
Under MiCA, the reserve composition rules for EMT issuers and ART issuers differ in scope and detail. Both require that reserve assets be segregated from the issuer's own assets and held in a manner that protects them in an insolvency. The practical effect is that the issuer must identify and contract with a custodian or set of custodians before the authorisation is complete – because the proposed reserve structure is a component of the authorisation application itself.
Banking access for stablecoin issuers is a documented challenge. Correspondent banks in many jurisdictions remain cautious about accounts holding reserves for token issuance programmes, particularly where the issuer's regulatory status is still in progress. We have seen issuers discover mid-application that their proposed banking arrangements are not available – either because the bank withdrew on compliance grounds or because the bank's own regulators imposed restrictions on stablecoin-related accounts. The solution is to resolve the banking architecture early, ideally before the authorisation application is filed, so that the application itself can reference confirmed arrangements.
A micro-matter from our recent practice illustrates the point. In a recent authorisation matter, a payments company had structured its ART reserve across three custodians in two jurisdictions. The national competent authority's review identified that one custodian lacked the requisite authorisation in its home jurisdiction to hold assets of the relevant type. We restructured the reserve architecture, sourced a replacement custodian, and the revised application was accepted for review. The matter proceeded without the delay that a mid-process custodian failure typically produces.
What Does a Compliant MiCA Whitepaper Actually Require?
A MiCA whitepaper is a statutory disclosure document carrying liability for material misstatements – it is not a marketing brochure, and boards that treat it as one expose the issuer to regulatory and civil liability before the first token is issued.
The whitepaper for an ART or EMT must contain prescribed information about the issuer, the token, the rights it confers, the reserve structure, the risks, the governance, and the redemption mechanism. The MiCA regime specifies the categories of information required and imposes civil liability for information that is untrue, inaccurate or misleading. The issuer is the responsible party. Directors who approve a whitepaper that they know to be materially deficient face personal exposure in jurisdictions that implement that liability regime directly.
A whitepaper must be notified to the relevant national competent authority before the token is offered to the public or admitted to trading. The notification process is not a passive one: the NCA reviews the whitepaper for completeness and can require amendments. An issuer that proceeds to offer before notification or before the notification period has run faces enforcement risk in every EU member state where the token is available.
The practical lesson is that the whitepaper should be drafted alongside the legal classification analysis, not after it. A whitepaper drafted to describe a payment token that turns out on legal review to carry investment-like rights will need to be restructured – and the restructuring typically pulls the entire authorisation timeline with it. In our practice, we conduct a rights-and-classification review as the first step of any whitepaper engagement, so that the document describes the token accurately from the outset.
Which Issuer Profile Should Choose Which Path?
The right authorisation path depends on the token's economic design, the issuer's existing regulatory standing, the target markets and the operational timeline – and there is no single correct answer that holds across all profiles.
Profile A – Single-currency EMT issuer targeting the EU. An issuer designing a euro-denominated EMT for use within the EU should seek EMT authorisation under MiCA through an EU-established entity. If the issuer is already an authorised electronic money institution, the MiCA compliance layer is additive, not a replacement authorisation. Timeline is materially affected by the completeness of the application and the NCA's processing queue; we advise clients to treat the process as a matter of several months and to begin banking and reserve structuring well before the application is filed.
Profile B – Multi-currency ART issuer targeting global distribution. An ART referencing a basket of currencies targeting distribution across the EU, the UK and the Gulf requires a more complex structure. MiCA authorisation for the ART is required for EU distribution; a separate FCA registration or authorisation covers the UK; VARA or FSRA authorisation covers the Gulf. The whitepaper prepared for MiCA will not satisfy VARA's disclosure requirements without adaptation. The reserve structure must be agreed with each regulator before the corresponding application is filed. Timeline is a function of the number of parallel tracks and the complexity of the reserve architecture.
Profile C – Algorithmic or yield-bearing stablecoin. A stablecoin that generates yield for holders or whose peg mechanism is algorithmically maintained without a conventional reserve should receive a securities-law analysis before any regulatory path is selected. MiCA's ART/EMT framework may not apply. The issuer may face a securities-offering analysis under MiCA's carve-out for financial instruments, and separately under the relevant law of each distribution jurisdiction. This profile requires the broadest legal scope before any authorisation steps are taken.
Profile D – Token issuer in a non-EU jurisdiction seeking market access. An issuer domiciled outside the EU that wishes to distribute an ART or EMT to EU users must nonetheless comply with MiCA. The issuer must establish an EU entity or, in some cases, rely on reverse solicitation – which is narrowly construed and should not be relied upon as a primary distribution strategy. Obtaining authorisation through a favourably positioned EU member state allows EU passporting from that single authorisation. Lithuania, Malta and several other member states have positioned themselves as entry points; the practical differences turn on the NCA's capacity, the local legal-infrastructure depth and the banking-access environment.
What Are the Most Common Structural Mistakes in Stablecoin Authorisation?
Boards consistently make a small number of structural mistakes that are identifiable before the application is filed – and that, once embedded in the structure, are costly to unwind.
The most common is treating the token classification as settled before the legal analysis is complete. A token described internally as a "payment token" can be an ART, an EMT, or a financial instrument depending on its design. Boards that commission the authorisation application before the classification is determined waste time filing under the wrong regime and, in the worst cases, make public representations about the token's nature that are inconsistent with its legal character.
A second common mistake is separating the reserve structure from the authorisation process. The reserve architecture is not a post-authorisation operational decision: it is a component of the application. Issuers that treat it as a later step arrive at the filing stage without confirmed banking arrangements, which delays authorisation or requires the application to be refiled with amended reserve documents.
A third mistake is failing to account for the securities-law analysis across all distribution jurisdictions. MiCA authorisation does not confer any regulatory standing in the United States, the United Kingdom outside the UK's own regime, Singapore, or Hong Kong. An issuer that distributes a token to users in those jurisdictions without the applicable authorisation – or without a considered legal basis for not requiring one – faces enforcement risk in each.
A fourth, and frequently underestimated, mistake is treating the Travel Rule as an implementation detail. Stablecoin issuers that build their smart-contract architecture without Travel Rule compliance embedded find that the retrofit is technically demanding and operationally disruptive. FATF's guidance on the Travel Rule explicitly covers virtual assets, and every major hub has implemented or is implementing corresponding domestic obligations. Building the compliance architecture into the token design is materially cheaper than correcting it after launch.
A common assumption is that appointing a compliance officer resolves the compliance programme. It does not. A compliance officer manages a programme; the programme itself must be designed to the regulatory expectations of each applicable regime, documented to the standard required by each regulator, and tested before the authorisation application is filed. Regulators assessing an ART or EMT application will review the compliance programme documentation as a condition of authorisation, not as a post-launch deliverable.
Related at OBOLUS
- Token Offerings & Securities Practice – token classification, securities analysis and offering structures for digital-asset businesses.
- MiCA Whitepaper Review in Estonia – practical guidance on whitepaper preparation and NCA notification under MiCA.
- Cross-Chain Bridge Legal Risk: Where the Lines Are Drawn – analysis of the regulatory and liability exposure for cross-chain infrastructure operators.
FAQ
Is my token a security?
Whether a token is a security depends on its economic substance – the rights it confers, the dependency of its value on the issuer's efforts, and the expectations of its holders – not on its label. Regulators in the US (SEC), UK (FCA), EU (under MiCA's scope carve-out for financial instruments) and Singapore (MAS) all apply a substance-based test. A legal classification analysis across each distribution jurisdiction is the only reliable way to answer this question before a token is offered publicly.
Do I need a MiCA whitepaper?
A MiCA whitepaper is required for any offer to the public or admission to trading of an ART or EMT within the EU/EEA. The whitepaper must contain prescribed disclosures, be notified to the relevant national competent authority before the offer, and carry civil liability for material misstatements. Exemptions exist for offers below applicable thresholds and for offers to qualified investors only, but the threshold and exemption conditions must be assessed against the specific facts of each offer.
How should an airdrop be structured legally?
An airdrop is a distribution of tokens without direct payment, but "no payment" does not mean "no regulation." Regulators treat the regulatory character of the token – not the distribution method – as the governing analysis. An airdrop of a security is an unregistered offering. An airdrop of an EMT or ART to EU recipients triggers MiCA whitepaper obligations unless a specific exemption applies. Marketing and financial-promotion rules in the UK, Singapore and Hong Kong apply to communications about airdropped tokens regardless of how the distribution is structured.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label – and we have seen how a mis-classification early in the structuring process converts a product launch into an unregistered offering. To discuss your stablecoin issuance or token offering, contact info@oboluslaw.com or reach us via t.me/oboluslaw.
By Lydia Brennan, Tax & Structuring Analyst – specialising in cross-border token structuring, stablecoin reserve analysis and the interaction between token classification and tax treatment across EU, Gulf and Asia-Pacific jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.