Stablecoin issuance sits at the intersection of monetary regulation, securities law, and payment-system oversight — a combination that surprises operators who assumed their peg mechanism resolved the classification question. It does not. Across the leading hubs, regulators are converging on the view that a stablecoin is a regulated instrument by default, and the issuer bears the burden of proving otherwise. The compliance programme that follows from authorisation is not a box-checking exercise; it is an ongoing operational commitment that touches reserve management, disclosure, AML, redemption mechanics, and cross-border banking simultaneously. This page works through the authorisation requirements, the contrasting regulatory positions across the major regimes, and the structural decisions that determine whether a stablecoin project is built on defensible ground.
What Makes a Stablecoin a Regulated Instrument?
A stablecoin is regulated not because of its price stability mechanism but because of the rights it confers on the holder and the function it performs in the economy. The relevant question in every jurisdiction is the same: does the instrument represent a claim on an issuer, replicate the economic function of money, or confer rights that look like those attached to a security or an e-money product? If the answer to any of those questions is yes, authorisation follows from that answer — not from the label on the whitepaper (the public disclosure document that describes the asset and its terms). Operators who discover this late, after token issuance, face the prospect of retroactive enforcement and the unwinding of a live product.
The token classification analysis begins with substance. Under MiCA (the EU's Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities), stablecoins fall into two defined categories: asset-referenced tokens (ARTs, which reference a basket of assets, currencies, or commodities) and e-money tokens (EMTs, which reference a single fiat currency and are treated as electronic money). Both require issuer authorisation before public offer. The category determines the regulatory path, the reserve obligations, and the disclosure requirements. Misidentifying the category — or structuring a token to fall outside both — does not remove the obligation; it relocates the risk to enforcement.
Outside the EU, the analysis is less codified but no less demanding. FINMA in Switzerland applies its own token taxonomy (payment, utility, and asset tokens), and a stablecoin referencing fiat typically falls into the payment category, attracting banking or fintech-licence obligations. The FCA in the United Kingdom treats fiat-backed stablecoins used for payment as regulated activities, with a dedicated regime now being implemented. The MAS in Singapore and the SFC in Hong Kong each apply their own frameworks, and VARA in Dubai sits within a still-maturing activity-based licence structure. In every case, the starting point is the same: what does the token actually do, and what rights does it create?
The process above describes the standard path. Your facts — the peg mechanism, the reserve structure, the user base, the banking arrangement — change the analysis materially. To map the classification and authorisation path for your token before you commit to a structure, contact OBOLUS at info@oboluslaw.com or map your options.
How Does MiCA's ART and EMT Authorisation Work in Practice?
Under MiCA, an issuer of an ART or an EMT must obtain authorisation from the national competent authority of its EU member state of establishment before making a public offer — and the authorisation process is substantive, not administrative. The CASP (Crypto-Asset Service Provider) framework runs parallel: an entity that both issues a stablecoin and provides exchange or custody services needs authorisation under both tracks. The passporting benefit — once authorised in one member state, the issuer may offer across the EEA — is a meaningful advantage for operators targeting the EU market, but it does not reduce the initial burden; it defers the per-country licensing cost.
The authorisation package for an EMT issuer must demonstrate that the reserve backing the token is held in segregated, low-risk assets; that the holder has a claim at par (redemption at face value); and that the issuer maintains a compliance programme meeting the AML and governance expectations of the relevant NCA. For ARTs, the reserve composition, the stabilisation mechanism, and the governance of the issuer are each subject to detailed ongoing obligations. The whitepaper — the disclosure document filed with the NCA and published before any offer — must cover the rights attaching to the token, the reserve arrangements, the redemption procedure, and the risks. Omitting material information from the whitepaper is itself a regulatory infringement.
Timeline and capital requirements under MiCA are not fixed across all NCAs; the specific figures are set by each competent authority and are subject to change. In our cross-border practice, we consistently advise issuers to build in a pre-application engagement phase with the chosen NCA — most authorities expect preliminary dialogue before a formal filing, and the quality of that dialogue shapes the review timeline significantly. Lithuania, Malta, and several other member states have historically been receptive to inbound crypto-asset applicants; under MiCA all NCAs apply the same substantive standard, but their administrative processes and responsiveness vary.
Where Does Securities Law Intersect With Stablecoin Issuance?
A stablecoin can be a security — and that possibility is not theoretical. Securities law in the United States is enforced by the SEC and CFTC, neither of which has issued a comprehensive stablecoin-specific regime, and both of which have asserted jurisdiction over instruments that, despite a stable price, confer investment-return characteristics or are marketed in a way that creates an expectation of profit. The Howey test (whether an instrument is an investment contract, applied to determine SEC jurisdiction) does not ask whether the token price is stable; it asks whether the purchaser is investing money in a common enterprise with an expectation of profit derived from the efforts of others. A yield-bearing stablecoin — one that passes interest from the reserve to the holder — is precisely the structure that attracts this analysis.
Outside the US, the securities-classification risk is equally present, though differently expressed. ESMA guidance under MiCA explicitly distinguishes ARTs and EMTs from crypto-assets that qualify as financial instruments under MiFID II; if a token falls into the latter category, the stablecoin framework does not apply — the securities regime does. FINMA applies a similar logic: a stablecoin with equity-like rights is an asset token and potentially a security. The SFC in Hong Kong and the MAS in Singapore each apply their own securities tests, and operators offering a stablecoin to users in those jurisdictions must analyse local law regardless of where the issuer is domiciled.
The cross-border dimension compounds the risk. A token issued in an EU member state and offered to US persons, or a token issued in a BVI entity and offered into Singapore, triggers the securities analysis of multiple jurisdictions simultaneously. Operators we advise routinely underestimate how quickly the distribution footprint of a stablecoin expands beyond the issuer's intended perimeter — particularly once the token is listed on a secondary exchange.
What Does Ongoing Reserve Management Compliance Actually Require?
Reserve compliance is the operational core of stablecoin authorisation, and it is where the gap between pre-launch structuring and post-launch execution is most often exposed. Under MiCA, an EMT issuer must hold reserves equivalent to the outstanding token supply in segregated accounts at regulated credit institutions; the reserve must be invested in low-risk, highly liquid assets; and the composition must be disclosed. For ARTs, the reserve composition is more complex, as it must mirror the referenced basket, and the issuer must maintain a stabilisation mechanism with defined intervention triggers. These are not one-time requirements — they are continuous.
Reserve management intersects with banking in a way that most issuers do not fully anticipate. Holding reserves at a regulated credit institution requires that the issuer can open and maintain accounts at such an institution — and crypto-related entities face persistent banking access difficulties in most jurisdictions. The banking problem is not solved by the licence; the licence is a precondition for the banking conversation, not a guarantee of it. In our practice, we have seen authorised entities — or entities well advanced in the authorisation process — struggle to open reserve accounts because the banks themselves apply a separate risk-assessment process. Addressing this in parallel with the authorisation, not after it, is the structuring discipline that separates a workable programme from one that stalls at the banking stage.
Audit and attestation obligations add a further layer. Most regimes require periodic proof that the reserve equals or exceeds the outstanding token supply. The frequency and form of that attestation — whether a third-party audit, a regulator filing, or a public disclosure — varies by regime. Under MiCA, the obligation is explicit and tied to a disclosure cycle. Under VARA in Dubai, similar reserve and disclosure expectations apply within the issuer's activity-based licence conditions. Operators must build the audit infrastructure before launch, not retrofit it.
If a prior application stalled at the banking or reserve-structuring stage, a second read of the entity structure and the banking strategy can surface the reason and the route forward. Write to OBOLUS at info@oboluslaw.com or map your options.
How Do AML and the Travel Rule Apply to Stablecoin Issuers?
Stablecoin issuers are, in most jurisdictions, virtual asset service providers (VASPs) — and the AML obligations that apply to VASPs apply in full to them. The FATF Recommendation 15 framework, which covers virtual assets, expects issuers to conduct customer due diligence, maintain transaction monitoring, report suspicious activity, and apply sanctions screening. These are baseline obligations that do not require the issuer to operate an exchange or provide custody; the act of issuing a token that is transferable on-chain is often sufficient to trigger registration or licensing under the applicable AML regime.
The Travel Rule (the obligation, derived from FATF Recommendation 16, to pass originator and beneficiary identifying information with a virtual asset transfer above a defined threshold) applies with particular force to stablecoin transfers, which are often high-volume and cross-border by design. The data-threshold is set by each jurisdiction and varies — making cross-border compliance a matrix exercise rather than a single policy. An issuer whose token circulates across the EU, the UK, Singapore, and the US faces four distinct Travel Rule regimes, each with its own threshold, technical implementation standard, and enforcement posture.
Tether (USDT) and Circle (USDC) each hold contract-level authority to freeze or blacklist individual wallet addresses — a capability that regulators and law-enforcement agencies use as a practical enforcement lever in fraud and sanctions cases. An issuer building a new stablecoin must decide at the architecture stage whether to replicate that capability, and on what terms. The decision has compliance implications (a freeze function may be expected by regulators as a sanctions-compliance tool) and commercial implications (users and DeFi integrators may resist it). We have seen this decision deferred until late in the development cycle, at which point retrofitting it is technically costly and operationally disruptive.
Which Jurisdiction Should a Stablecoin Issuer Choose?
The optimal domicile for a stablecoin issuer is not the jurisdiction with the lightest regime — it is the one that aligns the issuer's target markets, banking access, and long-term regulatory posture. The following matrix describes the principal decision profiles we encounter in practice.
Profile A: EU-market-focused EMT issuer. An operator targeting EU retail and institutional users, operating a fiat-pegged stablecoin, should structure for MiCA EMT authorisation in a receptive member state — Lithuania and Malta have historically processed crypto-asset applications efficiently, though under MiCA all NCAs apply the same substantive standard. Passporting across the EEA is the principal benefit. The capital and reserve requirements are meaningful; banking access in the chosen member state is the principal operational risk. Timeline to authorisation is typically measured in months rather than weeks, and the process requires a pre-application dialogue phase that extends that window further.
Profile B: Global issuer with a multi-currency peg. A complex ART issuer targeting multiple geographies should consider a dual-hub structure: MiCA authorisation for the EU distribution leg, combined with a VARA or ADGM licence for the Gulf and Asian distribution leg. Each hub requires a separate legal entity and a separate compliance programme. The tax treatment of reserve income and the VAT/GST implications of token redemption must be analysed in each jurisdiction — these are not incidental costs.
Profile C: Institutional stablecoin for settlement use. An issuer targeting institutional counterparties for payment or settlement — not retail distribution — may find that a Singapore MAS licence (under the Payment Services Act) or a FINMA fintech licence in Switzerland provides a credible regulated base with appropriate institutional-grade expectations. Both regimes are selective about applicants; the compliance programme expected is sophisticated, but the resulting licence carries weight with institutional banking counterparties.
Profile D: Early-stage project evaluating options. An issuer that has not yet fixed the peg mechanism, the distribution geography, or the entity structure should not select a domicile until the token classification analysis is complete. Selecting a jurisdiction before classifying the token correctly is a common structural mistake: the chosen regime may not cover the token type, or may impose obligations that the project cannot operationally satisfy. The classification exercise — securities, ART, EMT, or something else — must precede the domicile decision.
A Stablecoin Project Restructured Mid-Development
In a recent matter, a payments-adjacent business had developed a fiat-backed token it had internally classified as a utility token — on the basis that the token could be redeemed only for services within its ecosystem, not for cash. By the time the team engaged us, the token mechanics had been substantially built and a whitepaper drafted. The analysis revealed that the redemption mechanism, as designed, created a legal claim on the issuer at a defined conversion rate — bringing the instrument squarely within the EMT definition under MiCA and a similar e-money characterization under the applicable national law. We advised on a structural adjustment to the redemption terms and the reserve arrangement, revised the whitepaper to reflect the correct regulatory classification, and supported the issuer's pre-application engagement with the relevant NCA. The project launched under the correct framework, avoiding what would have been an unregistered public offer of a regulated instrument.
Does a Utility Label on a Whitepaper Settle the Classification?
A common assumption among early-stage projects is that labelling a token "utility" in the whitepaper resolves the legal classification. It does not. Regulators across all major jurisdictions apply a substance-over-form analysis: they look at what the token actually does — the rights it confers, the obligations it creates, the economic function it performs — and measure that against the statutory definition of the regulated instrument. ESMA has been explicit on this point in its MiCA guidance. The FCA has made the same point in its cryptoasset perimeter guidance. The SEC has litigated it repeatedly.
The practical consequence is that a token can be labelled utility and still be an EMT, an ART, or a security — depending on its mechanics. We assess classification against the substance of rights, not the marketing label. A whitepaper that describes the token accurately, consistent with the regulatory classification that the substance of the instrument attracts, is a legal document. A whitepaper that mislabels the instrument is an enforceable disclosure against the issuer in most jurisdictions, and it does not insulate the issuer from the regulatory obligation it was designed to avoid.
Self-Assessment: Is Your Stablecoin Project Authorisation-Ready?
Operators approaching stablecoin issuance should work through the following questions before committing to a legal structure or a public offer. These are not exhaustive, but they identify the points at which the analysis most commonly breaks down.
- Has the token been classified under the law of every jurisdiction where it will be publicly offered — not just the issuer's home jurisdiction?
- Is the peg mechanism and redemption right designed in a way that is consistent with the chosen regulatory category (EMT, ART, payment token, or other)?
- Has the reserve structure been confirmed with a banking counterparty that is prepared to hold regulated reserves for a crypto-asset issuer?
- Does the whitepaper contain all the information required by the applicable regime, including the reserve composition, the redemption procedure, and the risk factors specific to the stabilisation mechanism?
- Is the AML/KYC programme designed for the volume and type of transaction the token is expected to generate, including Travel Rule compliance across all distribution jurisdictions?
- Has the ongoing attestation and audit obligation been operationally planned — not just acknowledged in principle?
- Is the yield or return, if any, generated by the reserve clearly not passed to the holder in a form that could attract securities-law characterization?
A "no" or "uncertain" answer to any of these is a structural issue, not an administrative one. Addressing it before authorisation is categorically less costly than addressing it after a regulator raises it.
Related at OBOLUS
- Token Offerings & Securities practice – how OBOLUS advises on token classification, securities analysis, and offering structure
- Utility token legal opinion in the United States – federal and state analysis for operators targeting US markets or US persons
- VAT treatment of crypto services in Mauritius – indirect tax analysis for issuers considering an Indian Ocean hub domicile
FAQ
Is my token a security?
Whether a token is a security turns on the rights it confers and the economic function it performs — not on how it is labelled. In the United States, the Howey test is the primary analytical tool; in the EU, MiCA distinguishes regulated crypto-assets from financial instruments under MiFID II, and tokens with equity- or debt-like characteristics fall into the securities category. In Singapore, Hong Kong, and the UK, equivalent substance-over-form tests apply. Classification must be performed jurisdiction by jurisdiction for every market where the token will be accessible.
Do I need a MiCA whitepaper?
Under MiCA, a whitepaper is required before any public offer of a crypto-asset in the EU — with limited exemptions for offers below defined thresholds or targeted at qualified investors. For ART and EMT issuers, the whitepaper must be filed with and approved by the relevant national competent authority before publication. The document must cover the issuer, the token's rights and obligations, the reserve structure (where applicable), the redemption mechanism, and the material risks. Issuing without a compliant whitepaper is a regulatory infringement regardless of the token's classification.
How should an airdrop be structured legally?
An airdrop — the gratuitous distribution of tokens to wallet addresses — is not automatically exempt from securities or AML regulation. The key questions are whether the recipients are identifiable, whether the token confers regulated rights, and whether the distribution constitutes a "public offer" under the applicable regime. Under MiCA, a free-of-charge distribution to the public may still require a whitepaper if the token falls within a regulated category. AML obligations can attach where the issuer maintains a record of recipients. Legal structuring of an airdrop should begin with the token's classification, not with the distribution mechanics.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking, and compliance obligations that sit around them. Digital assets are the whole of our practice. We assess classification against the substance of rights, not the marketing label, and we structure licensing, banking, and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Roman Levitt, Technology & DeFi Counsel — specialising in token classification, DeFi protocol structuring, and the regulatory treatment of on-chain instruments across the leading hubs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.