EST · MMXXVI
Home/Jurisdictions/Compare/Centralised vs DeFi: Where Regulation Bites
DeFi, Tokenization & Smart-Contract Law

Centralised vs DeFi: Where Regulation Bites

Centralised vs DeFi: Where Regulation Bites. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Centralised exchanges, custodians and token issuers carry a well-mapped legal profile: a licensed entity, a jurisdiction, a regulator, a compliance manual. DeFi (decentralised finance) protocols sit at the other end of the spectrum – smart contracts on a public chain, governance tokens distributed to holders, no registered operator in sight. Regulators in every major hub are working through the same question: when does the absence of a central operator actually shield a protocol from supervision, and when does it merely relocate the liability? For any team building in this space, misreading that line can convert a product launch into an unregistered securities offering before the first user connects a wallet.

The honest answer is that no single framework resolves the centralised-versus-DeFi question uniformly. MiCA (Markets in Crypto-Assets Regulation) in the EU, VARA (the Virtual Assets Regulatory Authority) in Dubai, the SEC and CFTC in the United States, and the FCA in the United Kingdom have each staked out positions – sometimes aligned, often divergent. What they share is a substance-over-form analysis: regulators look at who actually controls user funds, who earns fees, who upgrades the code, and who markets the product. The remainder of this page maps the decision axes a legal team must work through before committing to a structure.

The Regulated Perimeter: How It Differs for Centralised vs DeFi

A centralised operator is regulated at the entity level: the exchange, the custodian, the issuer. Under MiCA, a CASP (crypto-asset service provider) authorisation attaches to a legal person performing enumerated activities – custody, exchange, transfer, portfolio management. The entity holds the licence; the licence follows the entity. Passporting across the EU/EEA then flows from that single authorisation. The supervised perimeter is clear and contractually bounded.

DeFi inverts this. No legal person performs the activity – a deployed smart contract does. The regulatory question becomes whether any identifiable person or group controls that contract sufficiently to be treated as the functional operator. ESMA has signalled, in its preparatory work on MiCA, that protocols which retain an admin key, a governance mechanism that can pause withdrawals, or a fee switch that channels revenue to a team are not genuinely decentralised for regulatory purposes. The label on the whitepaper does not settle that analysis.

VARA in Dubai takes a similar approach at the activity level: it regulates virtual-asset activities regardless of the technical form through which they are delivered. A protocol that facilitates exchange or lending – even through non-custodial smart contracts – falls within VARA's scope if there is an identifiable party marketing or maintaining it in or from Dubai. VARA's rulebooks specifically address DeFi service arrangements, treating any UAE-nexus operator as a licensed person for the relevant activity.

The FCA in the UK anchors regulation to the financial-promotion rules: any communication that is a financial promotion for a qualifying cryptoasset must be issued or approved by an authorised person. This applies regardless of whether the underlying product is a centralised platform or a DeFi protocol. A team promoting a liquidity pool to UK users triggers the promotion regime even if the pool itself has no UK legal entity.

Decision Axis 1 – Custody: Who Holds the Keys?

Custody of user assets is the most consequential axis in any centralised-versus-DeFi analysis, because it is the point at which most regulated-activity triggers crystallise. In a centralised model, the platform holds private keys on behalf of users. That is regulated custody in every flagship regime – under MiCA, under VARA, under MAS in Singapore's Payment Services Act framework, and under the FSRA within ADGM in Abu Dhabi. The operator must meet capital, safeguarding and segregation expectations as a condition of authorisation.

In a non-custodial DeFi model, users hold their own keys. Assets are locked in smart-contract vaults, not in an operator wallet. No single entity is in possession. This structural difference genuinely matters: non-custodial protocols sit outside the custody-authorisation trigger in most regimes – provided no off-chain entity controls the contract's admin functions. The moment an upgrade key, a multisig controlled by the founding team, or a DAO treasury with selective withdrawal rights is introduced, custody-equivalent control may exist in law even if not in the marketing materials.

In our cross-border practice, we regularly see teams assume that a non-custodial architecture resolves their regulatory exposure. It narrows it significantly on the custody axis. It does not resolve the financial-promotion, securities-classification or AML axes, each of which runs independently.

Decision Axis 2 – Token Classification: Securities, Utility, or Something Else?

Token classification is the axis where centralised and DeFi operators face identical analytical exposure – the classification turns on the rights the token confers, not on whether the protocol is hosted on a server or deployed on Ethereum. A governance token that entitles holders to a share of protocol fees, or that is marketed with an expectation of appreciation based on the team's development efforts, will draw securities-framework scrutiny in the US, the EU and the UK regardless of the protocol's technical architecture.

Under MiCA, tokens are stratified into ART (asset-referenced tokens), EMT (e-money tokens) and "other crypto-assets", each carrying distinct issuer obligations and whitepaper requirements. A DeFi protocol issuing a governance token must still determine which category applies and comply accordingly. ESMA's guidance makes clear that a token's decentralised distribution mechanism does not exempt the original issuer from MiCA's whitepaper notification requirement.

The SEC's framework in the United States applies the investment-contract analysis to assess whether a token is a security. Both centralised token issuers and DeFi governance-token distributors have faced enforcement on this basis. CFTC has separately asserted commodity-futures jurisdiction over certain DeFi derivatives protocols. The dual-regulator reality means a US-nexus DeFi build must be mapped against both agencies' positions before launch.

A common assumption in the market is that attaching a "utility" label to a token in the whitepaper settles the legal classification. It does not. We assess every token against the substance of the rights it confers: economic entitlement, governance control, transferability, the role of the issuing team in any value expectation. A token that fails that analysis is a potential unregistered security irrespective of what the document calls it.

Decision Axis 3 – AML, the Travel Rule, and the VASP Question

Anti-money laundering obligations are structured around the concept of a VASP (virtual asset service provider) – the FATF definition that most national AML regimes have adopted. A VASP is an entity that conducts virtual-asset activities as a business. Centralised operators are straightforwardly VASPs. The AML question for DeFi is whether a protocol's operators, developers or governance-token holders constitute a VASP for FATF purposes.

FATF's updated guidance on virtual assets makes clear that when a DeFi protocol has an owner/operator – a party that maintains control, profits from the protocol, or has the ability to set parameters – that party is treated as a VASP and must comply with AML/CFT obligations including customer due diligence and the Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer). Genuine full-decentralisation, where no such party exists, sits outside the VASP concept – but FATF explicitly treats this as a narrow carve-out, and regulators apply it narrowly.

For centralised operators, the Travel Rule is a live operational requirement. The data must travel with the transaction across the relevant threshold set by each jurisdiction. For DeFi protocols with an identifiable operator, the same obligation applies even where the underlying settlement is on-chain and peer-to-peer. Operators we advise routinely underestimate this obligation in their early compliance architecture, particularly in cross-border deployments where different national thresholds and technical-standards requirements interact.

A DAO (decentralised autonomous organisation) deployed without a legal wrapper has no legal personality. It cannot enter contracts, hold IP, hire staff or defend litigation. Governance-token holders who participate in a DAO vote may, depending on jurisdiction, be treated as unincorporated associates jointly and severally liable for the DAO's activities. This is not a theoretical risk. US enforcement history includes actions where individuals were held liable as partners in a DAO.

The available legal wrappers vary by jurisdiction. The Marshall Islands and Wyoming have DAO LLC statutes. The Cayman Islands foundation company is widely used to hold protocol assets and act as a contracting counterparty while maintaining separation from token holders. A BVI company or a Swiss association can serve similar purposes. The AIFC in Kazakhstan offers a common-law framework that some DeFi teams with a Eurasian user base have explored for their operating entity. ADGM and the DIFC in Dubai provide common-law company vehicles compatible with smart-contract governance arrangements.

None of these wrappers fully insulates token holders from liability if they exercise substantive control over the protocol's operations. The legal-wrapper question and the control-analysis question must be worked through together. We have seen DAO structures where the foundation wrapper was correctly established but governance-token voting rights were drafted in a way that effectively replicated the control exercised by a traditional board – undermining the intended regulatory treatment.

For a scoped assessment of your DAO or protocol structure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options.

Decision Axis 5 – Smart-Contract Liability: Code-as-Law Meets Legal Accountability

When a smart contract executes incorrectly – whether through a bug, an oracle failure or a deliberate exploit – the question of who bears legal liability follows the question of who controlled the deployment. For a centralised operator that deployed the contract, the answer is relatively straightforward: the operator is the identified party against whom a claim can be brought, subject to the terms of service and applicable consumer-protection law.

For a DeFi protocol, liability depends on who audited the code, who retained upgrade authority, and whether governance-token holders ratified a materially relevant parameter change before the loss event. In England and Wales – the leading forum for crypto-asset litigation – courts have been willing to look through technical architecture to find an identifiable defendant. The landmark decision in AA v Persons Unknown [2019] established that crypto assets are property capable of being frozen. More recently, courts have granted Norwich Pharmacal orders compelling blockchain-adjacent parties to disclose information necessary to identify an unknown defendant.

In practice, a user who suffers loss in a DeFi exploit will look for any party that: (i) marketed the protocol to them, (ii) was compensated for its operation, or (iii) had the technical ability to prevent the loss. Teams that assume the smart contract's self-executing character eliminates this exposure are building on a legal premise courts in England and Wales, Singapore, Hong Kong and New York have consistently declined to accept.

In a recent recovery matter, a fintech operator traced misappropriated stablecoins through a DeFi liquidity pool to two centralised off-ramps; we secured a disclosure order in a leading common-law forum and the assets were frozen before the positions could be liquidated. The window between exploit and withdrawal was measured in hours.

Situation-to-Instrument Matrix: Which Profile Points Where

Matching a business profile to the right regulatory instrument requires working through the axes above in sequence. The following profiles illustrate the logic, not the outcome – every structure requires its own analysis.

Profile A – Centralised exchange with EU ambitions. A spot exchange seeking to serve EU retail users needs a CASP authorisation under MiCA, obtained in a single member state with intent to passport. The application turns on capital sufficiency, governance, AML systems and the specific services enumerated in the authorisation. Timeline is a matter of months per the relevant NCA's queue. Principal risk: scope creep into staking or lending services that require a separate activity authorisation. Cross-border note: an exchange also serving US persons triggers FinCEN money-services-business registration and potentially state-level money-transmitter licensing.

Profile B – Non-custodial DeFi protocol with governance token. A protocol with no admin key, no identifiable fee recipient and fully on-chain governance sits at the boundary of the VASP concept. The primary residual risks are: (i) token classification – if the governance token carries economic rights, MiCA's whitepaper obligation may apply; (ii) financial-promotion rules in the UK and elsewhere, which apply at the point of user-facing marketing regardless of protocol architecture; and (iii) AML exposure if any off-chain team member is identifiable as an owner/operator per FATF guidance. Principal risk: the protocol adds a fee switch or upgrade mechanism post-launch, recreating regulatory exposure without updated compliance architecture.

Profile C – DAO managing a treasury and protocol parameters. A DAO with a Cayman foundation wrapper, a governance token and a deployed lending protocol operates across three legal planes simultaneously: the foundation (entity-level obligations), the token (MiCA or securities-law classification), and the protocol (AML/Travel Rule if the team constitutes a VASP). Timeline for establishing the full legal stack – wrapper, token legal opinion, AML policy – varies by jurisdiction but is typically a matter of weeks to a few months depending on the regulatory queue. Principal risk: governance-token holder liability if the wrapper does not adequately separate token-holder participation rights from operational control.

Profile D – Institutional issuer tokenising a real-world asset. A financial institution tokenising a fund interest or a credit instrument sits fully within the securities-regulation perimeter regardless of whether the instrument is deployed on a public chain or a permissioned ledger. MiCA, ESMA guidance, and the FCA's treatment of security tokens all apply. The DeFi-versus-CeFi axis is largely irrelevant here: the nature of the underlying right determines the classification. The cross-border complexity is significant – a token issued in one jurisdiction but distributed to investors in another triggers the securities laws of each distribution market.

If a prior application stalled or a compliance gap surfaced after launch, a second review can surface the structural reason and the route forward. Write to info@oboluslaw.com or message us via t.me/oboluslaw. Map your options.

The Cross-Border Reality: Jurisdiction Stacking

The centralised-versus-DeFi question rarely resolves within a single jurisdiction. A protocol built by a team in Singapore, deployed on a global public chain, marketed to users in the EU and the UK, and governed by a Cayman foundation faces simultaneous regulatory exposure under MAS's Payment Services Act, MiCA and ESMA's CASP regime, the FCA's financial-promotion rules, and CIMA's VASP Act – each with different classification tests, different thresholds and different enforcement postures.

Centralised operators face the same stacking problem, but with a clearer resolution mechanism: a single licensed entity can typically manage multi-jurisdictional compliance through a combination of passporting (within the EU/EEA under MiCA), bilateral-service exemptions, and allied counsel in each relevant jurisdiction. DeFi protocols have no equivalent mechanism. The absence of a licensed entity does not mean the absence of regulatory obligation – it means the obligation has no obvious bearer, which is precisely the condition regulators in every major hub are working to correct.

We have seen operators structure their DeFi deployment with a Singapore entity for the development function, a Cayman foundation for the protocol assets, and a Malta CASP for any centralised on-ramp or fiat interface. This layered approach can work – but only if each layer is independently compliant and the interfaces between them are documented. Regulators examining the structure look for the substance of control, not the elegance of the diagram.

What Both Models Share: The Enforcement Reality

Centralised and DeFi operators share one enforcement reality: regulators with clear statutory authority, sufficient forensic capability to trace on-chain activity, and an increasing willingness to pursue cross-border enforcement through mutual legal-assistance channels and directly against individuals regardless of where the code is deployed.

SEC, CFTC, OFAC and FinCEN enforcement actions in the United States have reached DeFi protocol operators, developers and governance-token holders. ESMA's preparatory MiCA guidance signals a similar trajectory in the EU. The FCA's strengthened financial-promotion enforcement has already reached UK-resident promoters of protocols with no UK legal entity. VARA has issued public guidance indicating that Dubai-marketed DeFi services require an identifiable operator to hold the relevant VARA licence.

The practical implication is that building a DeFi protocol without legal architecture is not a cost-saving strategy. It is a deferred compliance cost that arrives at enforcement, usually with interest in the form of disgorgement exposure and personal liability for the individuals closest to the operation.

Related at OBOLUS

FAQ

Can a DeFi protocol be regulated?

Yes. Most regulators apply a substance-over-form test. A protocol whose developers retain an upgrade key, earn fees, or market the product to users in a supervised jurisdiction is treated as having an identifiable operator subject to licensing, AML and financial-promotion rules. Genuine full decentralisation – no owner, no admin key, no fee recipient – may sit outside the VASP definition, but regulators treat that carve-out narrowly. Most live protocols do not meet the threshold.

What legal wrapper suits a DAO?

The most widely used structures are a Cayman Islands foundation company, a BVI company and, for US-nexus DAOs, a Wyoming or Marshall Islands DAO LLC. The choice depends on where the protocol's users are concentrated, where the team operates and what the token is classified as. None of these wrappers eliminates liability risk if governance-token holders exercise substantive operational control. The wrapper and the governance design must be engineered together.

Who is liable when a smart contract fails?

Liability follows control. In most common-law forums – including England and Wales, Singapore and Hong Kong – courts examine who deployed the contract, who retained upgrade authority, who marketed the product and who profited from its operation. Any of those parties may be a viable defendant. A self-executing contract does not constitute a legal barrier to a claim. Terms of service, code-audit documentation and governance records are all relevant to the liability analysis when a significant loss event occurs.

OBOLUS is an independent digital-asset law boutique acting exclusively for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance architecture that surrounds them. Digital assets are the whole of our practice. We assess token classification against the substance of rights conferred – not the marketing label – and we advise operators across the full DeFi and centralised spectrum. To discuss your situation, contact info@oboluslaw.com or message t.me/oboluslaw.

By Roman Levitt, Technology & DeFi Counsel – specialising in smart-contract governance, DeFi legal architecture and cross-border token classification for protocol operators and institutional issuers.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours