A decentralized autonomous organization (DAO) – a governance structure in which token holders vote on protocol decisions through smart contracts (self-executing code deployed on a blockchain) – sits in a legal no-man's land that regulators across every major jurisdiction are now actively redrawing. The question is not whether DAOs attract legal obligations. They do. The question is which entity, in which jurisdiction, bears them.
As DeFi supervision tightens across the EU, the UAE and the common-law hubs, the structuring decision a DAO's founders make in the first twelve months determines whether the protocol can bank, can contract and can defend itself in litigation. A mis-classified token converts a product launch into an unregistered securities offering. A governance structure with no legal wrapper converts every active token holder into a potential general partner, personally liable for the protocol's debts. Both outcomes are avoidable. Neither is theoretical.
This analysis maps the principal legal wrapper options for DAOs, the cross-border pressures that shape the choice, and the structural signals regulators actually look for – then closes with a decision matrix for the operator deciding where and how to incorporate.
Why a DAO Needs a Legal Wrapper at All
An unwrapped DAO is, in most legal systems, a general partnership by default – and that classification carries unlimited joint and several liability for every participant who exercises governance rights. The structural problem is acute. Token holders who vote on treasury allocations, fee parameters or protocol upgrades may, under partnership doctrine in England and Wales, the United States and several EU member states, be treated as partners carrying the protocol's liabilities personally.
The practical consequences compound quickly. Without a recognized legal entity, a DAO cannot open a bank account, cannot enter an auditor engagement, cannot employ contributors, and cannot hold intellectual property. When a counterparty sues – and in the current enforcement environment, counterparties do – there is no corporate shield, no designated agent for service, and no defined litigation budget. Regulators in jurisdictions operating under MiCA (the EU's Markets in Crypto-Assets Regulation, administered by ESMA and national competent authorities) and under VARA (Dubai's Virtual Assets Regulatory Authority) have both signaled that regulatory accountability tracks the entity that controls a protocol's material functions, not the entity that formally signed an application.
In our cross-border practice, the earliest structuring conversation is always the most consequential. Founders who treat incorporation as an administrative afterthought typically discover the gap when a banking partner demands a corporate tree, a regulator issues a compelled-disclosure notice, or a smart-contract exploit triggers a creditor claim. At that point, retrofitting a wrapper is materially more expensive – and sometimes legally impossible – than building one into the launch architecture.
Contextual bridge: The analysis below describes the principal wrapper vehicles and the regime-level pressures that bear on each. Your specific token mechanics, contributor base and user geography change the conclusion materially.
To map the entity, banking and regulatory posture for your DAO before you launch, contact OBOLUS at info@oboluslaw.com.
The Wrapper Menu: Cayman, BVI, Marshall Islands and Beyond
The four principal legal vehicles used to wrap DAO governance structures each carry a distinct liability profile, regulatory footprint and operational cost – and the choice between them is a legal decision, not an administrative one.
The Cayman Islands Foundation Company, authorized under the Cayman Islands Monetary Authority's oversight environment, is the structure most commonly used by protocols with institutional treasury exposure. It is a legal person, capable of holding assets and entering contracts. It has no shareholders. A supervisory council replaces the board, which maps cleanly onto a DAO's governance model. The foundation can be the on-chain treasury's legal counterpart without creating equity interests that trigger securities analysis in the EU or the United States. CIMA – the Cayman Islands Monetary Authority – operates a Virtual Asset (Service Providers) Act regime that is relevant if the foundation itself provides a virtual asset service.
The BVI Business Company, regulated by the BVI Financial Services Commission under the VASP Act 2022, offers a lighter formation cost and a flexible constitutional document, but it carries equity interests and therefore creates shareholder-attribution risks that a foundation structure avoids. It is better suited as an operational subsidiary – holding IP, employing contributors or contracting with service providers – than as the top-level governance entity.
The Marshall Islands DAO LLC is the vehicle that attracted significant attention after the Marshall Islands enacted a specific DAO recognition statute. It permits on-chain governance mechanisms to be written into the operating agreement, which is a structurally elegant solution for protocols with no clear founder group. The limitation is banking: correspondent banking relationships with Marshall Islands entities remain difficult, and the jurisdiction carries a weaker regulatory pedigree in the eyes of ESMA and MAS than Cayman or Singapore.
The Wyoming DAO LLC – enabled by Wyoming's specific DAO legislation – provides US legal recognition and a relatively low formation cost. Its material disadvantage is US jurisdictional reach: once a DAO has a US legal presence, it invites SEC and CFTC jurisdiction over the protocol's token, its governance token and potentially its smart contracts. Operators with a significant US user base should take independent US legal advice before adopting a Wyoming vehicle as the wrapper of record.
Beyond the standard menu, we also advise on foundation structures in the Netherlands (Stichting), Switzerland (Verein or Foundation under FINMA oversight) and Singapore (company limited by guarantee under MAS regulation). Each carries jurisdiction-specific tax and regulatory implications that interact with the DAO's token economics.
How Does Token Classification Affect Wrapper Choice?
Token classification is the threshold question – and a utility label on a whitepaper does not settle it. The substance of the rights the token confers determines its legal category, not the marketing description. This principle operates identically under MiCA's taxonomy of asset-referenced tokens (ARTs), e-money tokens (EMTs) and "other" crypto-assets; under the FSRA framework in Abu Dhabi's ADGM; under the Payment Services Act administered by MAS in Singapore; and under the securities analysis applied by the SEC and CFTC in the United States.
A governance token that confers a residual economic interest in the protocol's treasury – through fee distributions, buybacks or revenue-sharing mechanisms – is structurally closer to an equity security than to a utility token, regardless of how the whitepaper frames it. Under MiCA, if that token qualifies as an ART or an EMT, the issuer must obtain ESMA-supervised CASP (Crypto-Asset Service Provider) authorization. If it resembles a transferable security under the existing EU financial-instruments regime, MiCA does not apply and MiFID II does – with its own authorization requirement. The distinction between the two regimes turns on legal analysis of the token's rights, not its name.
The wrapper choice follows from classification. A foundation structure in Cayman or Switzerland minimizes equity attribution and supports an argument that governance tokens are not securities. An LLC or share-capital structure in a US jurisdiction strengthens the counterargument. In our practice, we assess classification against the substance of rights from the outset, and we structure the wrapper to be consistent with that classification rather than in tension with it.
The cross-border dimension is equally material. A token that avoids securities classification under MiCA may still require Money Laundering Regulations registration under the FCA's regime in the United Kingdom, or DPT (Digital Payment Token) service authorization under MAS in Singapore, depending on how the token is used within the protocol. Each additional jurisdiction adds a wrapper-level or activity-level compliance obligation that the structuring must accommodate.
What Does a Cross-Border DAO Structure Actually Look Like?
A well-structured DAO typically separates governance, operations and treasury across at least two entities in two jurisdictions – not for opacity, but because the functional roles genuinely require different legal vehicles with different regulatory postures.
The most commonly deployed architecture uses a Cayman Foundation Company as the governance entity – holding the protocol's IP, interfacing with the on-chain governance process, and serving as the legal counterpart for any token issuance. Alongside it, a BVI Business Company or a Singapore company acts as the operational entity, employing or contracting contributors, holding VASP registrations where required, and managing fiat banking. Treasury assets – whether on-chain in a multi-signature wallet or off-chain in a foundation account – sit under the governance entity, governed by the DAO's smart contracts and, at the margin, by the foundation's constitutional documents.
The cross-border tension in this structure arises at the banking layer. Operators we advise routinely find that banks in Singapore and Switzerland will serve the operational entity but not the on-chain treasury, because the treasury's control mechanism – a multi-sig governed by token holders – does not satisfy the bank's beneficial-ownership and KYC requirements. Resolving this tension requires a carefully drafted delegation-of-authority document that maps on-chain governance resolutions to off-chain corporate authorizations in a way that both the bank's compliance team and the DAO's community accept.
A second structural tension arises at the employment layer. DAOs with active contributor communities face questions about whether contributors are employees, independent contractors or something else – and the answer differs between jurisdictions. The Cayman Foundation structure handles this cleanly because the foundation can engage contributors directly or through a BVI subsidiary. The Marshall Islands DAO LLC handles it less cleanly, because its novelty means that labor law analogies are untested in most banking jurisdictions.
The DeFi Protocol as a Regulated Entity: Where Does Liability Land?
A DeFi protocol that routes user funds through smart contracts, earns fees and accumulates a treasury is, in the view of regulators in the EU and several common-law jurisdictions, providing a virtual asset service – and that characterization triggers authorization obligations regardless of whether the protocol describes itself as a software product. The structuring question is not whether the obligation exists, but which entity it attaches to and how the wrapper insulates the rest of the structure.
Under VARA's activity-based licensing framework in Dubai, the regulated activity is defined by what the protocol does for users, not by how the smart contract is drafted. A protocol offering exchange, lending or transfer functions to UAE-located users triggers a VARA authorization requirement for the entity controlling those functions – even if that entity is a Cayman foundation with no Dubai office. ESMA's guidance under MiCA adopts an analogous approach: a CASP authorization requirement attaches to the entity that "offers" crypto-asset services to EU clients, with the offering test focusing on the commercial relationship rather than the technical implementation.
Liability for smart-contract failures sits alongside the authorization question. When a smart contract executes incorrectly – whether through a coding error, an economic exploit or a governance attack – the question of who is liable turns on who deployed it, who controls its upgrades and who profited from its operation. A foundation that formally disclaimed the smart contract but collected fees from its execution is, in our assessment, poorly positioned to rely on that disclaimer in litigation. English courts and, increasingly, DIFC Courts in Dubai have shown willingness to look through formal disclaimers where economic control follows a different path than the corporate documents suggest.
Micro-matter: In a recent structuring engagement, a DeFi protocol had deployed a lending smart contract under a Cayman Foundation structure and had subsequently upgraded the contract through a governance vote. A liquidity shortfall following the upgrade exposed a gap: the foundation's constitutional documents did not clearly authorize the upgrade, and contributor agreements treated the deployer – a separate BVI entity – as the contracting party. We restructured the delegation chain, amended the foundation's governance rules to ratify on-chain votes, and produced a clear liability map for future upgrades. The work was completed before any regulatory inquiry arose, and the protocol resumed normal operation on a structurally cleaner footing.
If your DAO has upgraded smart contracts, changed governance parameters or altered fee structures without updating the underlying legal documents, the gap is likely wider than it appears. Contact OBOLUS at info@oboluslaw.com for a structural review.
AML and the Travel Rule: How Do They Apply to a DAO?
A DAO operating a protocol that processes user funds is, in most leading jurisdictions, subject to the FATF Recommendations on virtual assets – including Recommendation 15, which requires jurisdictions to supervise VASPs for AML and CFT compliance, and the Travel Rule (the obligation to pass originator and beneficiary identification data with a virtual asset transfer above the applicable threshold). The key issue for DAO structuring is that AML obligations attach to the entity performing the VASP function, and an unwrapped DAO has no entity to perform it.
Under MiCA's CASP framework, AML compliance is a condition of authorization. Under VARA in Dubai and under the FSRA in the ADGM, regulated virtual asset activities carry equivalent AML registration and monitoring requirements. The FCA in the United Kingdom maintains a separate cryptoasset registration regime under its Money Laundering Regulations, which applies to UK-connected VASPs independently of MiCA. Across all these regimes, the Travel Rule's data-transfer obligation applies to the VASP as an entity – not to the smart contract, and not to the token holder.
For DAO structuring, the consequence is practical: the wrapper entity must be capable of performing AML checks, generating Travel Rule data and filing suspicious transaction reports. A pure on-chain structure cannot do any of these things. The operational subsidiary in the two-entity structure described above typically carries the AML compliance function, because it is the entity with the banking relationships, the staff and the ability to maintain a compliance program that regulators can audit.
Operators we advise with EU user bases – even where the DAO's primary entity is in Cayman – routinely need to assess whether any MiCA CASP authorization is required at the EU level, whether a local EU entity must hold that authorization, and how the EU entity's AML obligations interact with the on-chain governance process. The interaction is not always clean, and the answer is jurisdiction-by-jurisdiction rather than a single structural fix.
Decision Matrix: Which Wrapper Suits Which DAO Profile?
The right wrapper depends on four axes: the token's economic structure, the protocol's user geography, the treasury's size and composition, and the DAO's appetite for regulatory authorization. No single vehicle is optimal across all four dimensions simultaneously.
Profile A – Protocol DAO with no US users, EU user base, treasury over seven figures, governance token with no direct economic return: The Cayman Foundation Company is the primary governance entity. A Singapore or Malta subsidiary (under the MiCA CASP framework transitioning through MFSA) holds any EU-facing authorization. Treasury sits on-chain, governed by the foundation's constitutional documents through a delegation instrument. The primary risk is EU passporting – a single MiCA CASP authorization in one EU member state allows cross-border service provision across the EU, but the application process and ongoing compliance cost are material. Indicative timeline to full structure: several months across both incorporation and CASP application. Key risk: MiCA classification of the governance token as an ART triggers reserve and issuer-authorization obligations that are structurally incompatible with a decentralized governance model.
Profile B – Early-stage protocol, global users, small treasury, community-governed, no institutional investors: The Marshall Islands DAO LLC offers on-chain governance recognition at low cost. An operational account in a crypto-friendly jurisdiction (Switzerland, Singapore or the AIFC in Kazakhstan under AFSA oversight) handles banking. AML compliance is handled at the operational account level. The primary risk is banking friction and the reputational discount that some institutional partners assign to Marshall Islands entities. Timeline to functional structure: materially shorter than Profile A. Key risk: as the protocol scales, the Marshall Islands vehicle may need to be replaced rather than upgraded, triggering a governance migration that requires community consent.
Profile C – Investment DAO, pooled treasury, members making governance decisions on deployed capital: The structure requires analysis of whether the DAO constitutes a collective investment scheme under the applicable regime – MiCA, MAS, CIMA or the FSRA in the ADGM. If it does, the wrapper must be an authorized fund vehicle, not a foundation. A Cayman exempted limited partnership or a Cayman open-ended fund vehicle, registered with CIMA under the Virtual Asset (Service Providers) Act, is typically the starting point. Contributors hold limited partnership interests or fund shares rather than governance tokens, which avoids the securities-vs-utility tension at the governance layer. Key risk: the collective investment scheme analysis is fact-intensive and jurisdiction-specific; a structure that avoids registration in Cayman may still trigger authorization requirements under MAS or the FCA for the fund manager. We regularly advise on the multi-jurisdiction fund structure for digital-asset vehicles of this type.
Profile D – Protocol DAO with significant US contributor base or US investors: US jurisdictional reach is unavoidable once material US nexus exists. The structure must account for SEC and CFTC analysis of the governance token, FinCEN's VASP registration requirements, and potentially state money-transmitter licensing under the NYDFS BitLicense or equivalent regimes. A Wyoming DAO LLC provides US legal recognition but maximizes US regulatory exposure. Most protocols in this profile use a non-US governance entity (Cayman or Swiss) and a separate US entity for any US-facing operations, with the US entity structured to minimize its role in token issuance and governance.
Objection Handler: Common Assumptions That Create Structural Risk
A common assumption among DAO founders is that decentralization itself provides regulatory insulation – that a protocol with no controlling party is a protocol no regulator can reach. This assumption is incorrect, and regulators have said so explicitly. ESMA's MiCA guidance, VARA's rulebooks and the FATF's updated Recommendation 15 guidance all apply the regulated-entity test to whoever controls the material functions of a protocol, including governance parameter setting, fee collection and smart-contract upgradability. A foundation that holds the protocol's admin keys – even if it exercises them only when the DAO votes – is an entity with control, and control attracts regulation.
A second common assumption is that a utility label on a whitepaper settles token classification. It does not. Classification is determined by the substance of the rights the token confers in practice, not by the description of those rights in a marketing document. A token that entitles holders to a share of protocol revenue – framed as a "governance reward" or "ecosystem incentive" – may be an ART under MiCA, a collective investment scheme interest under the FSRA, or a security under the Howey test applied by the SEC, regardless of what the whitepaper says. The structuring must be consistent with the classification the substance supports, not the classification the founders prefer.
A third assumption is that a legal wrapper is a one-time decision. In practice, as a protocol evolves – adding new token types, expanding into new user geographies, accepting institutional capital or implementing an upgrade that changes the governance model – the wrapper must be revisited. Protocols we advise with more than one significant governance upgrade in their history routinely discover that the legal documents no longer accurately describe the control architecture, which creates both regulatory risk and litigation exposure.
Self-Assessment Checklist Before You Commit to a Structure
Before committing to a wrapper, the DAO's legal and operational team should be able to answer the following questions with precision. If any answer is unclear, the structure is not ready to launch.
- What rights does the governance token confer, and have those rights been assessed for securities, ART and EMT classification under each jurisdiction where the protocol has material users?
- Which entity holds the protocol's admin keys, and is that entity's control over smart-contract upgrades documented in the wrapper's constitutional documents?
- Which entity performs AML checks and maintains Travel Rule compliance, and does it have the banking relationships and compliance infrastructure to do so?
- How does an on-chain governance vote become a legally binding corporate action – and is that delegation chain documented in a form that a bank, a regulator and a court would recognize?
- If a smart contract fails and a creditor sues, which entity is the defendant – and does the wrapper provide a corporate shield between that entity's assets and the governance token holders' personal assets?
- Does the wrapper allow the protocol to hold intellectual property, enter service agreements and employ contributors without triggering a partnership-law analysis?
- Has the structure been reviewed for tax efficiency at the entity level and for the token holders' jurisdiction – specifically for the treatment of staking rewards, fee income and treasury appreciation?
Related to tax efficiency: the structuring question does not end at the entity level. The tax treatment of token issuance, treasury deployment and fee income is jurisdiction-specific and interacts with the wrapper choice in ways that affect the effective cost of compliance. Our colleagues advising on real-world asset tokenization and fund structures regularly encounter tax issues that the initial wrapper analysis did not anticipate.
Related at OBOLUS
- DeFi, Tokenization and Smart-Contract Law – the full scope of our practice for protocol builders and token issuers
- Real-World Asset Tokenization: The Compliance Burden in Practice – how tokenization meets the tax and regulatory stack in cross-border deployments
- AIF for Digital Assets – alternative investment fund structures for institutional capital in digital-asset strategies
FAQ
Can a DeFi protocol be regulated?
Yes. Regulators under MiCA, VARA and the FATF Recommendation 15 framework apply the regulated-entity test to whoever controls a protocol's material functions – including governance, fee collection and smart-contract upgradability. The fact that execution occurs on-chain does not displace the authorization requirement. The entity that controls those functions, typically identified through a legal wrapper, is the entity to which regulatory obligations attach. Decentralization reduces but does not eliminate that attribution.
What legal wrapper suits a DAO?
The optimal wrapper depends on the protocol's token economics, user geography and treasury size. A Cayman Foundation Company suits governance DAOs with institutional treasury exposure and no equity distribution. A Marshall Islands DAO LLC suits early-stage protocols with community governance and limited banking needs. Investment DAOs typically require an authorized fund vehicle under CIMA, MAS or CIMA. No single vehicle is universally optimal – the choice follows from a structured analysis of the protocol's actual control architecture and regulatory obligations.
Who is liable when a smart contract fails?
Liability for a smart-contract failure typically follows control: the entity that deployed the contract, holds the admin keys or controls upgrade rights is the most exposed defendant. A legal wrapper – correctly drafted – provides a corporate shield between that entity's assets and the personal assets of token holders who exercise governance rights. An unwrapped DAO exposes active governance participants to unlimited liability under general-partnership doctrine in most major jurisdictions. Disclaimer language in a whitepaper does not displace that analysis where economic control points elsewhere.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than 70 jurisdictions, on disputes and on-chain asset recovery across more than 25 forums, and on the tax, banking and compliance that sit around them. We assess token classification against the substance of rights, not the marketing label – and we structure legal wrappers that are consistent with that classification from the outset. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Roman Levitt, Technology and DeFi Counsel – advising protocol builders, DAO contributors and token issuers on smart-contract governance structures and cross-border DeFi compliance.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.