Tokenising a fund sits at the intersection of two regimes that rarely speak the same language: the securities law that governs who can issue and distribute fund interests, and the smart-contract architecture that determines how those interests actually move on a blockchain. A founder who treats this as a technology problem first, and a legal problem second, is likely to discover – at launch, or at the first regulatory inquiry – that a tokenised fund interest (a representation of ownership or economic rights in a fund encoded on a distributed ledger) is almost always a regulated financial instrument. The classification question is not solved by the label on the whitepaper.
This analysis examines how securities law applies to fund tokenisation across the leading regimes, where smart-contract mechanics create new legal risk, and what a cross-border structure actually requires. It is written for general counsel and founders who need the legal answer before committing to an architecture.
Classification: The Real Test for a Tokenised Fund Interest
A tokenised fund interest is almost certainly a security in every major jurisdiction, regardless of what the token is called. The decisive question is the substance of the rights conferred: does the holder receive a share of profits, have a claim on assets, or depend on the managerial effort of others? If the answer is yes to any of those, the instrument will be caught by securities regulation. Regulators from the SEC and CFTC in the United States to ESMA under MiCA and the SFC in Hong Kong have each, in their own terms, anchored classification to economic substance rather than technical form. A utility label on a whitepaper has no legal effect on that analysis.
The practical consequence is stark. Mis-classifying a token converts what the issuer intends as a product launch into an unregistered securities offering – with all the civil liability, enforcement exposure and potential rescission rights for holders that follow. In our practice, the classification memo is always the first document we produce, before any technology decisions are made. The instrument has to be understood before the architecture can be chosen.
Under the SEC's longstanding Howey test framework, the investment-of-money prong and the common-enterprise prong are almost always satisfied in a fund tokenisation. The managerial-effort prong is equally hard to defeat: the fund manager controls deployment of capital, and token holders have no independent say in day-to-day decisions. EU operators working under MiCA face a parallel analysis. Tokenised interests that fall within the asset-referenced token (ART) or financial-instrument categories carry authorisation obligations that apply at the issuer level, not just the exchange level.
What Smart Contracts Actually Do – Legally
A smart contract (self-executing code on a blockchain that automatically performs terms when defined conditions are met) is not a legal contract in the traditional sense, though it may evidence or partially constitute one. The code automates enforcement of economic terms – distributions, redemptions, transfers – but it cannot substitute for the legal instrument that creates the underlying obligation. Fund counsel and technologists often talk past each other here: the smart contract is the delivery mechanism; the legal agreement is the source of the rights.
This distinction has immediate consequences for fund tokenisation. The offering document, the subscription agreement and the constitutional documents of the fund entity remain the authoritative legal instruments. The smart contract should be coded to reflect those documents, not the other way around. Where the code diverges from the legal instrument, the legal instrument will govern – but the divergence may cause real economic harm before anyone notices, and a court will be asked to decide what was intended.
A second legal question concerns immutability. Smart contracts, once deployed, are often difficult or impossible to modify without a migration. Fund interests, by contrast, may need to be redeemed, cancelled, transferred by court order or adjusted for regulatory compliance purposes. Any tokenised fund structure needs an upgrade and override mechanism that is legally defensible – ideally backed by a custodian or administrator who holds a legally recognised power to act off-chain where the on-chain mechanism is unavailable. FINMA in Switzerland, the FSRA within ADGM, and the SFC in Hong Kong have each signalled that regulatory obligations cannot be delegated to code alone.
The CFAAR network, established in London in September 2021, addresses related questions in the recovery context: the immutability of a smart contract that holds misappropriated assets is a practical obstacle, not a legal shield against a freezing order.
In a recent matter, a fund manager preparing a tokenised limited-partner interest structure engaged us to review the proposed smart-contract architecture against the fund's constitutional documents. We identified three areas where the code's automatic distribution logic conflicted with the fund's waterfall provisions under the applicable offering memorandum. Those conflicts were corrected before deployment. The risk of a seven-figure distribution error – and the regulatory question that would have accompanied it – was addressed before it materialised.
Which Securities Regime Applies When Your Fund Is Cross-Border?
The regime that applies to a tokenised fund is determined not only by where the fund is domiciled but by where the token is offered, where the manager operates, and where the investors are located. These four questions can produce four different answers. A Cayman Islands fund managed from London, distributed via a smart contract to token holders in the EU and the United States, sits simultaneously in the perimeter of the FCA, MiCA, and the SEC – each with independent jurisdiction to act.
Fund managers consistently underestimate the US reach. The SEC's position is that any offering to US persons of an instrument that meets the Howey criteria requires either registration or an applicable exemption, irrespective of where the issuer is located. Regulation D and Regulation S provide the principal exemption routes, but each imposes transfer restrictions and investor qualification requirements that must be encoded – and enforced – at the token level. A transfer-restriction smart contract that fails to block an ineligible transfer does not cure the underlying violation; it is evidence that the compliance architecture was inadequate.
Within the EU, the MiCA regime administered by ESMA and the national competent authorities draws a careful line. Tokenised fund interests that qualify as financial instruments fall outside MiCA's direct perimeter and into the existing MiFID II and AIFMD frameworks. That sounds like relief; in practice it means a more demanding authorisation regime, not a lighter one. The operator is dealing with established fund-regulation requirements applied to a new technology, rather than a purpose-built crypto regime.
For operators seeking a single-jurisdiction base for a multi-investor tokenised fund, the leading candidates in our cross-border practice are the Cayman Islands under CIMA, the BVI under the BVI FSC and the VASP Act 2022, and the ADGM in Abu Dhabi under the FSRA. Each offers a recognised fund structure alongside a digital-asset regulatory regime, which reduces the number of regulatory conversations a manager must have simultaneously. The Seychelles alternative investment fund structure is increasingly considered for smaller mandates seeking a lean initial structure.
For a scoped assessment of your fund's cross-border regulatory perimeter, contact OBOLUS at info@oboluslaw.com. The process above describes the standard analytical path. Your facts – the entity, the investor base, the manager location, the distribution channel – change the analysis materially. Map your options.
DAO Structures and Fund Equivalence: When a Protocol Becomes a Fund
A DAO (decentralised autonomous organisation) that pools capital from token holders and deploys it under a shared governance structure can meet the functional definition of a collective investment scheme in most major jurisdictions, even if the founders intended it as a governance mechanism rather than an investment vehicle. Regulators look at substance: is money pooled, is it managed on behalf of holders who do not control day-to-day decisions, and does each holder have an expectation of return? If yes, the DAO is a fund, and it is subject to fund regulation.
The absence of a legal entity does not resolve this. English courts, the SFC, and the SEC have each moved toward treating tokenised interests in protocol treasuries as regulated instruments when the economic substance supports it. The practical risk for a DAO that crosses this line without registration or an applicable exemption is that every token distribution event was an unregistered securities offering, and every participant who received tokens may have a rescission right.
The legal wrapper question is therefore not cosmetic. A DAO that intends to operate within the regulatory perimeter needs a legal vehicle – typically a foundation, a limited partnership or a purpose-built company – that can hold assets, enter contracts, apply for regulatory authorisation, and respond to legal process. The AIFC in Kazakhstan and the ADGM in Abu Dhabi have each developed legal concepts that accommodate DAO-adjacent structures within a recognised regulatory framework. The Cayman Islands foundation company is widely used for governance-token structures where the founders want legal personality without a direct shareholder relationship.
In our practice, we regularly advise DAO-adjacent structures on the point at which governance token rights begin to look like economic rights. The line is not always clear. But drawing it before distribution – rather than after a regulator draws it for you – is the structuring imperative.
The Token as a Financial Instrument: ART, EMT, and the MiCA Boundary
Under MiCA, the classification of a tokenised fund interest depends on the category into which it falls: an asset-referenced token (ART, a token that references multiple assets or a basket), an e-money token (EMT, referencing a single fiat currency), or a token that constitutes a financial instrument under MiFID II and therefore falls entirely outside MiCA. A tokenised fund interest will, in most structures, fall in the third category – it is a financial instrument, not a MiCA-regulated crypto-asset.
That distinction matters enormously for the authorisation path. A financial instrument requires the issuer to work through the MiFID II and AIFMD frameworks: an alternative investment fund manager authorisation, a prospectus or private-placement regime, and compliance with distribution rules in each target member state. ESMA's supervisory coordination means that a filing in one member state is visible to all NCAs. The passporting benefit of a CASP authorisation under MiCA does not extend to financial instruments – each distribution channel needs its own analysis.
For non-EU operators structuring a tokenised fund to be offered to EU investors, the third-country regime under AIFMD applies. Some member states maintain national private-placement regimes that allow inbound distribution subject to local notification requirements; others do not. A manager relying on reverse solicitation – the principle that an investor-initiated contact does not constitute a regulated offer – should understand that this concept is interpreted narrowly and inconsistently across member states, and that a smart contract that accepts subscriptions from any connected wallet does not look like investor-initiated contact to a regulator.
Who Bears Liability When the Smart Contract Fails?
Liability for a smart-contract failure in a fund context is shared across at least three potential defendants – the developer, the manager, and the auditor – and the allocation depends on the applicable law, the nature of the failure, and the contractual documents that governed the development and deployment. There is no jurisdiction in which "the code failed" is a complete defence. The legal analysis starts with who owed a duty to whom, and what representations were made about the contract's behaviour.
The developer owes a duty of care in most common-law systems to the party that commissioned the contract. Where the developer made representations about the contract's security or its conformance with the fund documents, a claim in misrepresentation or negligence may be available. A developer who deployed code that had not been audited, or who ignored audit findings, is in a significantly worse position than one who worked to a published specification and disclosed limitations.
The fund manager owes a duty to investors under the offering documents. If the manager adopted a smart-contract architecture and investors subscribed in reliance on the offering memorandum's description of that architecture, the manager is responsible for ensuring the code does what the document says it does. Delegating that responsibility to a third-party developer without independent audit or legal review does not transfer it. In our practice, we have seen fund managers take the position that a code audit substitutes for legal review. It does not: an audit verifies that the code does what it was written to do; legal review verifies that what it was written to do is what the document requires.
The FCA in the UK, FINMA in Switzerland, and the SFC in Hong Kong have each indicated that operational risk frameworks applicable to regulated funds extend to the technology layer. A fund manager who cannot demonstrate adequate governance of its smart-contract infrastructure is not managing operational risk in a way that satisfies regulatory expectations.
If a smart-contract failure has already occurred or a regulatory inquiry is under way, our disputes desk is available immediately at info@oboluslaw.com. If a prior structure has attracted regulatory attention or an investor complaint, a second read of the contractual and technical stack can surface the structural reason and the route to resolution. Map your options.
Decision Matrix: Which Structure for Which Operator Profile
Choosing the right vehicle for a tokenised fund turns on four variables: the investor base (qualified vs. retail), the manager's home jurisdiction, the target distribution geography, and the complexity of the underlying strategy. The matrix below describes the principal routes in qualitative terms; timelines and capital requirements vary by jurisdiction and category, and should be confirmed against current regulatory guidance before any commitment is made.
Profile A – Institutional manager, US and EU investors, complex strategy. This profile points to a Cayman Islands closed-ended fund (LP structure) with a MiFID II-authorised manager for EU distribution and a Regulation D / Regulation S exempt offering for US investors. The tokenised interests are issued under the fund's existing constitutional documents; the smart-contract layer is a transfer-agent replacement, not a new legal instrument. The CIMA filing and the AIFMD third-country notification drive the timeline, which is typically measured in months rather than weeks.
Profile B – Emerging-market manager, non-US/non-EU investor base, mid-complexity strategy. This profile is frequently served by an ADGM fund under the FSRA, with a VARA-registered distribution entity in Dubai for marketing to UAE and Gulf investors. The AIFC in Kazakhstan offers a comparable structure for Central Asian distribution. In both cases, the digital-asset and fund regulatory conversations happen within the same authority, which reduces coordination friction. Capital requirements and timelines vary by activity category – consult current FSRA or AFSA guidance.
Profile C – DeFi-native protocol, global contributor base, governance-and-yield model. This profile sits closest to the DAO-equivalence risk described above. The appropriate structure is a foundation or purpose trust in a jurisdiction that recognises these vehicles – the Cayman Islands foundation company is the most widely tested – with clearly documented limits on the economic rights of governance-token holders. The token issuance is accompanied by a detailed classification memo for each target jurisdiction. US persons are typically excluded by transfer restriction. Regulatory evolution in this space is active; ongoing compliance counsel is not optional.
A Common Assumption: Technology Determines Regulatory Status
A common assumption among first-time fund tokenisation clients is that the smart-contract architecture determines the legal treatment: if the code is non-custodial, permissionless or DAO-governed, then no regulated entity is involved and no authorisation is required. This assumption is wrong in every major jurisdiction, and it is becoming more wrong as regulators develop specific guidance for DeFi-adjacent structures.
The FCA's financial-promotion regime applies to communications that, among other things, relate to a controlled investment – regardless of whether the communication is made via a website, a smart contract interface or a token drop. ESMA has published guidance indicating that the decentralised character of a protocol does not automatically exempt the persons who created and deployed it from MiCA or MiFID II obligations where those persons retain sufficient control or influence over the protocol's operation. The SEC has pursued enforcement actions on exactly this theory.
What "sufficient control" means in practice is a factual question, and it is one that turns on governance mechanics, token-holder rights, upgrade authority and treasury control. A DAO where the founding team holds the upgrade key, controls the treasury multisig, and sets the fee parameters is not, functionally, decentralised – not in any sense that a regulator will accept as a basis for exemption. We assess these questions against the substance of the arrangement, not the marketing description.
Self-Assessment: Is Your Tokenised Fund Structure Legally Defensible?
Before committing to an architecture, a fund manager or DAO founder should be able to answer each of the following questions affirmatively. If any answer is uncertain, that uncertainty represents a legal risk that should be resolved before deployment.
First: has the tokenised interest been classified against the securities law of every jurisdiction where investors are located or where the offering is communicated? A classification memo covering the US, the EU and the primary target jurisdiction is the minimum. Second: do the smart-contract mechanics accurately reflect the fund's constitutional documents and offering memorandum? A side-by-side legal review – not just a code audit – is required. Third: is there an upgrade, override or migration mechanism that allows the manager to comply with a court order, a regulatory direction or an investor-mandated redemption that the contract's automatic logic does not accommodate? Fourth: has the transfer-restriction logic been tested against the eligibility criteria in the offering documents, and does it actually block ineligible transfers? Fifth: is the legal entity that sits behind the tokenised interests capable of holding assets, entering contracts, applying for authorisation and receiving legal process? If the answer is a DAO without a legal wrapper, the answer to this question is generally no.
In our practice, operators who work through these questions before deployment consistently face fewer regulatory complications than those who retrofit compliance after the fact. The structuring investment at the outset is materially smaller than the remediation cost after a regulator or an investor raises the issue.
Related at OBOLUS
- DeFi, Tokenization and Smart-Contract Law – our core practice covering the full legal stack for on-chain structures.
- Smart-Contract Legal Review Under Heightened Scrutiny – scoped review of deployed or pre-deployment smart contracts against legal obligations.
- AIF for Digital Assets in Seychelles – the Seychelles alternative investment fund structure for digital-asset mandates.
FAQ
Can a DeFi protocol be regulated?
Yes. Whether a DeFi protocol is subject to regulation depends on whether its operation – or the actions of the persons who created, deployed or continue to control it – falls within the perimeter of a regulatory regime. ESMA has indicated that residual control or influence by founding teams can bring a protocol within MiCA or MiFID II. The FCA and the SEC have each taken enforcement positions on this question. Decentralisation is a spectrum, not a binary; regulators assess the facts of control and economic function, not the label.
What legal wrapper suits a DAO?
The most widely used structures are the Cayman Islands foundation company, a Marshall Islands DAO LLC, and – for regulated-activity contexts – a limited partnership or purpose trust in a jurisdiction that recognises the vehicle. The appropriate choice depends on whether the DAO needs to hold assets, enter contracts, employ staff, apply for authorisation, or respond to legal process. A DAO without any legal wrapper has no capacity to do any of those things, which creates liability exposure for the individuals who act on its behalf.
Who is liable when a smart contract fails?
Liability is typically shared across the developer (who built the contract), the manager or issuer (who adopted and deployed it), and potentially the auditor (who reviewed it). In a fund context, the fund manager remains responsible to investors for the accuracy of representations in the offering documents, including any description of smart-contract mechanics. Delegating development to a third party does not transfer legal responsibility. Independent legal review – separate from a code audit – is the primary tool for limiting manager exposure before deployment.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label, and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com.
By Roman Levitt, Technology and DeFi Counsel – specialising in smart-contract legal architecture, token classification and cross-border fund tokenisation structures.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.