On paper, choosing a legal wrapper for a decentralized autonomous organization (DAO) – a collectively governed protocol whose rules run on-chain – looks like a checkbox exercise. In practice, the choice of structure determines who owes fiduciary duties, who holds assets, who faces regulator scrutiny, and which courts can reach the people behind the protocol. With regulators across the major hubs increasingly treating DeFi as within scope rather than beyond it, the stakes of a careless choice have risen sharply.
Three wrappers dominate the field: the foundation (a non-share-capital entity common in Switzerland, the Cayman Islands, the BVI and Panama), the limited liability company (the Wyoming DAO LLC and Marshall Islands DAO LLC being the most discussed variants), and the unincorporated association (the default for protocols that take no formal step at all). Each interacts differently with the cross-border reality of a protocol whose smart contracts execute globally, whose token holders sit in dozens of jurisdictions, and whose treasury may be denominated in assets subject to OFAC, MiCA or MAS oversight. This analysis compares the three structures across the axes that matter to an operator or founding team.
Why Legal Wrappers Matter for DAOs
A DAO without a legal wrapper is not invisible to the law – it is simply exposed to it without a shield. In the absence of a recognized entity, courts in most common-law and civil-law systems treat a DAO as an unincorporated association, meaning participants may face joint and several personal liability for the protocol's obligations. That exposure is not theoretical: enforcement actions and private litigation against DeFi protocols have tested exactly this question in US federal courts, with plaintiffs naming token holders as general partners. The unincorporated association problem sits at the center of the DAO legal debate.
A legal wrapper resolves three distinct problems at once. It creates a legal person capable of holding assets, executing contracts and opening bank accounts. It allocates liability – typically capping members' exposure to their contribution. And it provides a jurisdictional anchor, which matters the moment a regulator, a counterparty or a litigation adversary needs to identify who to serve. In our cross-border practice, we regularly advise founding teams that underestimate the second problem until a banking relationship breaks down or an exchange refuses to list their token without evidence of a proper issuer entity.
The cross-border angle is immediate. A DAO with US-resident contributors, EU-resident token holders and a treasury in USDC is simultaneously within the potential reach of the SEC, ESMA's national competent authorities under MiCA, and FinCEN's Travel Rule requirements. The wrapper chosen – and the jurisdiction in which it sits – shapes how each of those regimes lands on the team.
For a scoped assessment of your DAO's structural exposure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the contributor base, the treasury composition – change the analysis. Map your options.
The Foundation Model: Who It Suits and What It Costs
A foundation is a purpose-driven, non-share-capital entity that holds assets and pursues a defined objective without distributable profit going to members or shareholders – making it structurally well suited to a protocol whose stated purpose is stewardship rather than revenue extraction. The Swiss foundation (Stiftung), the Cayman Islands foundation company and the BVI restricted purpose company are the most frequently deployed variants in the DeFi context.
The Swiss foundation sits under FINMA's general supervisory environment. It requires a board, a defined purpose inscribed in its deed, and oversight by the cantonal supervisory authority for foundations. It cannot distribute assets to founders in a manner inconsistent with its purpose, which limits its use as a vehicle for founder liquidity. That constraint is, paradoxically, part of its appeal: it signals to regulators and token holders that the entity is not a disguised profit vehicle. Operators we advise who deploy a Swiss foundation typically pair it with an operational entity elsewhere – a Swiss GmbH or a BVI company – to separate stewardship from commercial activity.
The Cayman foundation company is a hybrid: it has legal personality, can have members or be memberless, and can be structured with a supervisor role whose function maps roughly onto a DAO's governance process. The Cayman foundation company has become the default wrapper for large DeFi treasuries precisely because it can hold assets, enter into contracts with auditors and contributors, and wind down in an orderly fashion under the supervision of the Cayman Islands Monetary Authority (CIMA) framework without triggering the tax and distribution complications of a share-capital structure. The BVI restricted purpose company under the BVI FSC's framework offers a similar profile at a lower maintenance cost.
The key risk with a foundation is governance capture. If the protocol's on-chain governance reaches a decision that the foundation's board cannot implement without breaching its fiduciary duties to the foundation's purpose, a structural conflict arises. In our practice, we have seen this tension emerge when a DAO vote directed a foundation to distribute treasury funds in a manner the board considered inconsistent with the founding deed. Anticipating that tension in the drafting stage – through carefully worded purpose clauses and board discretion provisions – is the highest-value intervention a lawyer makes at the formation stage.
The LLC Model: Wyoming, Marshall Islands and the Limits of Novelty
The Wyoming DAO LLC – created by Wyoming's DAO legislation – was the first statutory attempt to give an on-chain governance structure direct legal recognition: the operating agreement can be partly or wholly replaced by a smart contract, and the LLC provides liability protection to its members. The Marshall Islands followed with its own DAO LLC framework. Both structures are genuinely novel and useful for US-adjacent protocols, but they carry material limitations that the promotional narrative around them tends to understate.
A Wyoming DAO LLC is a US domestic entity. That means it is within the jurisdictional reach of the SEC, the CFTC and FinCEN from day one, regardless of where its members sit. For a protocol whose token may constitute a security under the Howey test, a Wyoming LLC is not a shield – it is a US address. The question of whether the LLC form eliminates personal liability for members also remains unsettled in practice: the novelty of the statutes means there is limited case law testing their interaction with federal securities claims or with the "general partner" liability theories that plaintiffs' firms have deployed against DeFi participants.
The Marshall Islands DAO LLC sits outside the US federal regulatory perimeter, offers similar structural recognition and has attracted protocols seeking a non-US wrapper with common-law familiarity. The practical limitations are different: banking access for a Marshall Islands entity is constrained, and the absence of a deep local legal market means disputes or regulatory questions require allied counsel in the relevant jurisdiction rather than a domestic practitioner base. For a protocol whose team is comfortable managing those constraints, the Marshall Islands LLC can function well as a governance entity paired with a Cayman or BVI treasury vehicle.
The broader tension with the LLC model is that it imports a membership-centric ownership paradigm into a structure that DeFi protocols often explicitly reject. If every governance token holder is technically a member of the LLC, the administrative burden of tracking membership, maintaining operating agreement compliance and managing member exit is substantial. Most protocols address this by limiting LLC membership to a small founding group and keeping governance token holders outside the entity – but that design choice reintroduces the question of what legal rights token holders actually hold.
The Unincorporated Association: Why "No Wrapper" Is Still a Structural Choice
An unincorporated association is what a DAO becomes by default when its founders take no formal legal step. It is not nothing – it is a recognized legal category in most common-law systems, and it carries real consequences. In England and Wales, an unincorporated association's members may be personally liable for its debts and obligations. In the United States, a protocol governed by token holders who vote on and execute protocol decisions may be characterized as a general partnership, exposing each participant to joint and several liability for the protocol's acts.
The unincorporated association is occasionally presented as a philosophically coherent choice – a form of structural decentralization that avoids placing a legal chokepoint on a trustless system. That argument has merit at the level of protocol design. It has very little merit at the level of legal risk management. Regulators including ESMA, the FCA and the SEC have each signaled that the absence of a formal entity does not place a DeFi protocol outside the scope of applicable law – it simply affects where enforcement lands and on whom.
There are narrow scenarios where deliberate structural minimalism makes sense: a fully autonomous protocol with no ongoing development team, no upgradeable contracts and no treasury under anyone's control. In practice, very few protocols meet that standard. Most have a multisig, a grants committee, a development entity or a foundation that receives fees – any of which provides a point of regulatory contact. Operators we advise who begin with an unincorporated structure typically encounter the limitation when they first seek an exchange listing, attempt to open a fiat bank account or respond to a regulator's inquiry.
Cross-Border Analysis: Which Wrapper Travels Best?
The cross-border performance of a DAO wrapper depends on three axes: regulatory recognition, banking access and enforcement exposure. No single structure is optimal on all three, which is why the most sophisticated protocols use a multi-entity stack rather than a single wrapper.
On regulatory recognition, the Cayman foundation company has the broadest track record. CIMA's framework is familiar to institutional counterparties, and a Cayman entity can open accounts with major crypto-native custodians and some traditional prime brokers. Under MiCA, however, a non-EU entity whose tokens are offered to EU retail investors triggers whitepaper and potential CASP authorisation obligations regardless of where the issuer is incorporated. The foundation's Cayman domicile does not immunize it from MiCA's reach. Similarly, MAS's Payment Services Act framework in Singapore treats digital payment token services as regulated activities regardless of where the service provider is incorporated if Singapore residents are being served.
On banking access, the Swiss Stiftung has meaningful advantages in Europe: Swiss banks, while selective, are more familiar with foundation structures for digital-asset protocols than most offshore jurisdictions. The BVI and Cayman structures historically faced pressure from correspondent banks, though the environment varies by bank and year. A Marshall Islands LLC faces the most constrained banking environment of the standard options.
On enforcement exposure, the Wyoming LLC is the most exposed for US-nexus protocols; the Cayman and BVI foundations offer the most insulation from US jurisdiction, though that insulation is not absolute – US persons as members, a US token launch or US-targeted marketing each provide a hook for US enforcement. The practical answer for a protocol with global token distribution is a multi-layer structure: a Cayman or Swiss foundation holding the treasury and IP, an operational entity (often a BVI company or a Swiss GmbH) contracting with contributors, and a governance layer that maps to whichever on-chain mechanism the protocol uses.
In a recent structuring matter, a DeFi protocol team came to us after operating for several months under an unincorporated structure. They had a functioning treasury, a live token and a grants program. We mapped their contributor base and user geography, identified that their token distribution and treasury management triggered regulatory touch-points in the EU and Singapore, and designed a two-entity stack – a Cayman foundation for treasury stewardship and a BVI operational company for contributor contracts – that gave them a clean issuer entity, separated governance from commerce, and positioned them to respond to exchange and banking due-diligence requests. The structure was implemented within a commercially realistic timeframe, and the team subsequently opened its first institutional banking relationship.
Token Classification and the Wrapper: Why the Entity Choice Affects Securities Risk
The choice of legal wrapper is not independent of token classification. The substance of the rights a token confers – not the label on the whitepaper – determines whether it is a security, an e-money token, an asset-referenced token or something else. But the entity structure shapes how that classification analysis lands and on whom.
A token issued by a foundation whose stated purpose is protocol stewardship, with no profit distribution to founders and governance rights that are genuinely collective, presents a different securities-law profile than the same token issued by a Wyoming LLC whose members retain residual economic rights. The SEC's application of the Howey test – which turns on an investment of money in a common enterprise with an expectation of profit from others' efforts – will interrogate the economic reality of the arrangement, and the legal wrapper is part of that reality. A utility label on a whitepaper does not settle the classification. We assess classification against the substance of rights, not the marketing framing, and we have seen enforcement actions proceed against token issuers who relied exclusively on self-applied labels.
Under MiCA, the classification logic is distinct but similarly substance-driven. A token that confers rights against an issuer – redemption, interest, revenue participation – will be assessed as an ART (asset-referenced token) or EMT (e-money token) regardless of how the issuer describes it. The foundation structure is compatible with both the MiCA "other crypto-asset" category (which requires a whitepaper) and potentially with the ART regime if the token's economic mechanics bring it within scope. Choosing the wrong wrapper and the wrong classification track simultaneously creates a compounding compliance problem that is far more expensive to unwind than to prevent.
If your token classification is in question, contact OBOLUS at info@oboluslaw.com before the launch clock starts. A prior application stalled or a bank account closed often traces back to a structural reason that a second read can identify. Map your options.
Decision Matrix: Matching the Wrapper to the Protocol Profile
Different protocol profiles call for different structures. The analysis below maps four common operator profiles to the most suitable wrapper, the indicative process, and the primary risk to manage.
Profile A: Early-stage protocol, small founding team, non-US, token not yet public. The Cayman foundation company is generally the right first step. It separates the treasury from founders' personal balance sheets, provides a credible issuer entity for future token documentation, and is familiar to institutional counterparties. The process involves engaging Cayman counsel (or allied counsel we coordinate), filing the foundation deed, appointing a supervisor, and establishing governance documentation that maps onto on-chain governance. The timeline is measured in weeks, not months, for a standard structure. The primary risk is over-engineering the governance layer before the protocol's on-chain mechanics are settled – foundation deeds should be flexible enough to accommodate protocol evolution.
Profile B: Mature protocol, US-resident contributors, existing token distribution, governance active. The LLC wrapper is worth evaluating if the team wants explicit statutory recognition of on-chain governance – but the US regulatory exposure must be priced in. A more common approach is a BVI company for operational contracting, a Cayman or Swiss foundation for treasury and IP, and explicit legal advice on whether any US-resident contributor's role triggers registration obligations under US federal law. The timeline for a multi-entity restructuring of a live protocol is longer and the process more involved than a greenfield structure. The primary risk is the transition period: between the decision to restructure and completion of the new structure, the team is operating in a gap that should be documented carefully.
Profile C: DAO seeking EU market access, token to be offered to EU retail. MiCA compliance is the organizing constraint. The entity structure must produce a legal issuer capable of filing a whitepaper with an EU national competent authority, and the token must be classified correctly under the MiCA regime before the whitepaper is drafted. A Cayman or Swiss foundation as the primary vehicle, paired with passporting through a MiCA-authorised CASP or a direct authorisation in a member state, is the standard architecture we see in this context. The timeline for MiCA CASP authorisation is a regulatory process measured in months; the whitepaper filing has its own notice and review period. The primary risk is launching on an "other crypto-asset" whitepaper while the token's economics in fact bring it within the ART regime.
Profile D: Fully decentralized, no treasury, no development team, no upgradeable contracts. This profile is the rare case where the unincorporated structure is defensible. If there is genuinely no entity controlling protocol parameters, no multisig, no fee-receiving address and no identifiable development team, the legal analysis changes materially. In practice, achieving and maintaining that standard requires deliberate protocol design from day one and ongoing verification that no governance action has re-introduced a controlling party. We advise clients considering this route on the specific conditions under which the decentralization argument holds and the points at which it begins to break down.
Governance Documentation and Smart-Contract Interaction
A legal wrapper only functions if its governance documentation is consistent with the on-chain mechanics of the protocol. A Cayman foundation whose deed vests decision authority in a three-person board, while the on-chain governance allocates authority to token holders by majority vote, has a structural inconsistency that creates legal uncertainty every time a significant governance decision is made. In our practice, we regularly advise protocol teams that the drafting of the foundation deed or LLC operating agreement is as technically demanding as the smart-contract audit – it requires understanding the on-chain mechanism in enough detail to reflect it accurately in the legal document, or to create a principled hierarchy between on-chain and off-chain authority.
The smart contract itself – the self-executing code that implements protocol rules – is not a contract in the legal sense in most jurisdictions without additional steps. It is code that produces outputs that may or may not have legal consequences. The question of whether a smart contract failure gives rise to liability, and on whom, turns first on whether the protocol has a legal entity that could owe a duty, second on whether any participant made representations about the contract's function, and third on whether a user had a contractual relationship with any identifiable party. A well-drafted legal wrapper, paired with terms of service that accurately describe the protocol's mechanics and the limits of any representations, materially reduces the ambiguity on all three questions.
The Travel Rule (the obligation to pass originator and beneficiary data with a transfer) applies to VASPs and, increasingly, to DeFi protocols that handle transfers in a way that brings them within scope of the FATF Recommendation 15 standard. Whether a DAO's governance token transfer mechanism or its treasury disbursement function constitutes a covered transfer is a fact-specific analysis that depends on the protocol's architecture. A legal wrapper that produces a VASP entity – intentionally or by implication – triggers that analysis immediately. Founders building on DeFi rails should address this question before deployment, not after an exchange or regulator raises it.
Related at OBOLUS
- DeFi, Tokenization & Smart-Contract Law – our core practice for protocol teams and token issuers across all stages
- Real-World Asset Tokenization in the Isle of Man – jurisdiction-specific analysis for asset-backed token structures
- Crypto Exchange Licensing: The Compliance Burden in Practice – how exchange licensing intersects with token and protocol compliance obligations
A Common Assumption Addressed: Decentralization as a Legal Defense
A common assumption among protocol founders is that sufficient decentralization renders a protocol beyond the reach of securities law, AML requirements and consumer-protection regimes. That assumption conflates a philosophical position with a legal one. Regulators including ESMA and the SEC have each, through guidance and enforcement, indicated that they evaluate the degree of decentralization as a factual matter – not as a self-reported status. A protocol that retains a multisig controlled by the founding team, upgradeable contracts subject to a development company's deployment key, or a fee switch that directs revenue to identifiable parties, will not be treated as fully decentralized regardless of its marketing.
The correct framing is that decentralization is a spectrum, and the legal consequences shift as a protocol moves along it. The value of good legal structuring at the outset is that it maps the protocol's actual decentralization profile honestly, documents the steps being taken to reduce centralization over time, and selects a wrapper that reflects the current reality rather than the aspirational state. That approach is more defensible before a regulator than a post-hoc decentralization argument mounted under enforcement pressure.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and protocol teams on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance structures that sit around them. Digital assets are the entirety of our practice. We assess token classification against the substance of rights, not the marketing label, and we act only for businesses – not retail participants. To discuss your DAO's structure, contact info@oboluslaw.com or message us at t.me/oboluslaw.
To pressure-test your DAO structure before you commit, message us via t.me/oboluslaw. Map your options.
FAQ
Can a DeFi protocol be regulated?
Yes. Most leading regulators – including ESMA under MiCA, the FCA under the UK financial-promotion regime and the SEC under US federal securities law – treat DeFi protocols as potentially within scope. The analysis turns on whether identifiable parties perform regulated activities: issuing tokens, operating a trading platform, providing custody, or transmitting value. The absence of a legal entity shifts where enforcement lands, but does not eliminate it. Decentralization is evaluated as a factual matter, not accepted as a self-reported status.
What legal wrapper suits a DAO?
The right wrapper depends on the protocol's stage, geography, treasury size and token structure. A Cayman foundation company is the most widely used vehicle for treasury stewardship and token issuance at scale. A Wyoming or Marshall Islands DAO LLC suits US-adjacent protocols seeking statutory recognition of on-chain governance, though each carries distinct regulatory exposure. The unincorporated association default is defensible only for genuinely autonomous protocols with no controlling party. Most mature protocols use a multi-entity stack rather than a single wrapper.
Who is liable when a smart contract fails?
Liability for a smart-contract failure is fact-specific. It turns on whether a legal entity owed duties to users, whether any party made representations about the contract's function, and whether users had a contractual relationship with an identifiable counterparty. A well-structured legal wrapper – paired with accurate terms of service – materially reduces that ambiguity by creating a defined legal person and a documented scope of representations. Without a wrapper, liability may fall on individual contributors or token holders, depending on jurisdiction.
By Roman Levitt, Technology & DeFi Counsel – specializing in smart-contract architecture, DAO structuring and DeFi protocol legal design across multiple jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.