EST · MMXXVI
Home/Jurisdictions/France/Cross-chain bridge legal risk in France (AMF/PSAN)
DeFi, Tokenization & Smart-Contract Law

Cross-chain bridge legal risk in France (AMF/PSAN)

Cross-chain bridge legal risk in France (AMF/PSAN). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Cross-chain bridges operate in a legal grey zone that French regulators are actively working to clarify. Under the AMF/PSAN (Autorité des Marchés Financiers / Prestataires de Services sur Actifs Numériques) regime, any entity that facilitates the exchange, custody or transfer of digital assets for third parties in France may fall within a regulated perimeter – regardless of whether that entity is a smart contract, a DAO, or an offshore company with French users. The AMF has signaled that substance governs, not structure. This guide maps the regulated perimeter, the classification decision tree, the cross-border complications, and the practical steps a bridge operator must take before, or promptly after, touching the French market.

What is a cross-chain bridge under French law?

A cross-chain bridge is a protocol or service that locks assets on one blockchain and mints equivalent representations on another, enabling users to move economic exposure across networks. Under the AMF's interpretive approach, the legal question is not technical but functional: does the bridge provide a service that falls within the defined PSAN activity categories?

France's PSAN regime, which predates and now coexists with the European Union's MiCA (Markets in Crypto-Assets Regulation) framework administered by ESMA, identifies specific regulated activities. These include the custody of digital assets on behalf of third parties, the exchange of digital assets against other digital assets, and the operation of a digital-asset trading platform. A bridge that locks user funds – even temporarily – and issues wrapped tokens may satisfy the definition of custody. One that routes swaps through liquidity pools may satisfy the definition of exchange.

The classification is not resolved by calling the bridge a protocol rather than a service. The AMF has consistently applied a substance-over-form analysis. Mis-classifying a token or an activity can convert a product launch into an unregistered offering or an unlicensed service provision – exposure that carries both civil and criminal dimensions under French law.

CTA #1 – The regulated perimeter above describes the standard analytical path. Your facts – the bridge architecture, the user base, the governance structure, the entity domicile – change the analysis materially. Map your options with OBOLUS before you deploy into France.

How does the PSAN registration framework apply to bridges?

Registration under the PSAN regime is mandatory for certain activities and optional (but strongly advisable) for others; the distinction turns on which activity category the bridge falls into, and whether the operator serves French users from an entity established in France or from abroad.

The AMF administers PSAN registration. A mandatory registration is required for any entity providing custody of digital assets on behalf of third parties, buying or selling digital assets for legal tender, exchanging digital assets for other digital assets, or operating a platform for the exchange of digital assets. An optional registration (which confers reputational standing and regulatory engagement rights) exists for additional activity categories including financial services advice relating to digital assets.

A cross-chain bridge operator must conduct a step-by-step activity analysis:

  • Does the protocol take custody of user assets at any point in the bridging process, even if only for the duration of a block confirmation? If yes, the custody category is engaged.
  • Does the bridge involve a swap – even an automated one – in which the user deposits asset A and receives asset B, where A and B are distinct digital assets? If yes, the exchange category may be engaged.
  • Is there a liquidity provision function that amounts to operating a trading venue? The AMF's guidance on platform operation is broad.
  • Does the bridge issue a wrapped token that may be characterised as a security token or a financial instrument under the Code monétaire et financier? If yes, the MiFID-derived financial-instrument perimeter – not only the PSAN regime – applies.

The timeline for a PSAN registration, once an application is complete and the AMF's anti-money-laundering dossier is in order, has historically been measured in months rather than weeks. Under MiCA transition rules, a CASP authorisation in another EU member state may passport into France – but that requires a qualifying authorisation first. The AMF remains the competent French authority during the transition period.

Does the MiCA transition change the risk analysis for bridges?

MiCA introduces a single EU-wide CASP authorisation that, once granted, passes across all EU/EEA member states – including France – without a separate national filing. That passporting right is significant. A bridge operator authorised as a CASP in a member state such as Malta (under the MFSA) or Lithuania (under the Bank of Lithuania) can, in principle, serve French users without a standalone AMF PSAN registration, provided the passporting notification is properly filed.

Two complications limit the cleanness of that path. First, MiCA's CASP activity categories and the existing PSAN activity categories do not map identically. A bridge operator needs to verify that the activity it performs is covered by the CASP authorisation it holds, not merely that it holds a CASP authorisation. Second, MiCA's DeFi provisions are expressly provisional. The regulation requires the European Commission to produce a report on decentralised finance and, if appropriate, a legislative proposal. That report is expected in the coming years. Until it arrives, fully decentralised protocols without an identifiable legal entity fall into a regulatory gap – but that gap is narrowing, not widening.

In our cross-border practice, we regularly see operators assume that a MiCA CASP exemption for fully decentralised protocols is a durable shield. It is not. The AMF has signaled an interest in identifying the persons who deploy, govern or profit from ostensibly decentralised protocols. A governance token that concentrates control in a small group of identifiable addresses may be enough to attribute legal personality and, with it, regulatory responsibility.

What token classification issues arise specifically with bridge tokens?

Token classification is the most consequential legal step a bridge operator undertakes in France. The AMF does not accept a utility label on a whitepaper as settling the question. Classification turns on the substance of the rights the token confers.

Bridge-related tokens fall into several possible categories, each with a different regulatory consequence:

  • Wrapped tokens that represent locked underlying assets may be characterised as e-money instruments if they are denominated in, or redeemable for, a fiat currency at par. Under MiCA, such a token would constitute an EMT (e-money token) requiring issuer authorisation as an electronic money institution.
  • Bridge governance tokens that confer voting rights, revenue-sharing rights, or a right to a share of protocol fees may be characterised as financial instruments or securities under French law. If they do, issuing them without a prospectus or a compliant whitepaper triggers securities-law exposure.
  • Pure utility tokens – those that confer only a right to use the protocol and carry no financial-instrument attributes – sit outside the securities perimeter, but still within the PSAN registration perimeter if the operator provides a regulated activity.
  • ART (asset-referenced tokens) under MiCA – tokens whose value is stabilised by reference to a basket of assets – carry their own authorisation regime, separate from the CASP track.

In a recent matter, a Web3 infrastructure company operating a multi-chain bridge sought to list its governance token on an EU exchange. The pre-launch classification analysis revealed that the token's fee-distribution mechanism created a revenue entitlement that brought it within the financial-instrument definition. We restructured the token's economic model ahead of listing, removing the entitlement and replacing it with a pure governance function. The token launched without a prospectus requirement. The client avoided regulatory intervention that would have delayed the launch by a significant period.

How does the Travel Rule and AML framework apply to bridge operators?

AML/CFT compliance is a threshold obligation for any PSAN-registered entity and, under MiCA, for any CASP operating in France. The Travel Rule – the obligation under FATF Recommendation 15 to pass originator and beneficiary data alongside a digital-asset transfer – applies to regulated transfers above the applicable threshold.

Cross-chain bridges present a structural Travel Rule challenge. A bridge locks asset A on chain 1 and mints asset B on chain 2. The two legs of that transaction may occur on entirely different blockchains, with different transaction identifiers, different address formats, and – critically – no native interoperability for the metadata that the Travel Rule requires. A PSAN-registered bridge operator must implement a technical solution that captures originator and beneficiary data on both legs and transmits it to the receiving obliged entity.

The AMF and ACPR (Autorité de Contrôle Prudentiel et de Résolution, the prudential supervisor) jointly supervise AML compliance for PSAN entities. Failure to implement Travel Rule procedures is not a minor compliance gap; it is a condition that can result in registration refusal, withdrawal of registration, or referral for prosecution. The FATF's guidance on virtual assets and virtual-asset service providers is the international baseline; French implementing legislation applies it domestically.

In our practice, we advise bridge operators to model Travel Rule compliance as an architecture decision, not an after-the-fact compliance layer. A bridge built without Travel Rule data capture built into its smart contracts will require a retrofit that is materially more expensive and technically riskier than building it in from the outset.

CTA #2 – If a prior registration application stalled, or if an existing bridge is operating without a formal AML/Travel Rule framework, a structured review can identify the gap and the path forward. Map your options with OBOLUS.

What are the cross-border banking and tax interactions for a bridge operator in France?

A bridge operator choosing France as its regulatory home must resolve the banking question in parallel with the PSAN registration. French banks remain cautious about onboarding crypto-native entities, particularly those operating DeFi infrastructure. A PSAN registration improves the probability of a successful bank onboarding materially, but it does not guarantee it.

Operators we advise frequently structure their French-regulated entity alongside a complementary offshore holding or treasury structure. The offshore vehicle – often in the BVI (under the BVI FSC's VASP Act regime) or the Cayman Islands (under CIMA's VASP Act) – holds the protocol treasury and governance tokens, while the French PSAN entity provides regulated services to EU users. That structure requires careful design to ensure it does not constitute a regulatory circumvention; the French entity must have genuine substance.

On the tax side, the French treatment of digital-asset transactions has evolved. The corporate tax treatment of bridge fees, wrapped-token issuance gains, and governance-token distributions is not uniform and depends on the specific transaction type and entity form. VAT treatment of digital-asset services is governed by EU VAT Directive principles as implemented in France. Both require advice specific to the operator's fact pattern; neither can be resolved by reference to a general rule.

For bridge operators with a substantial staking or liquidity-pool component, the French rules on the tax treatment of staking rewards and liquidity-provision income deserve early attention. The French tax authority (Direction générale des Finances publiques) has published guidance on individual taxation of crypto assets; the corporate treatment of bridge protocol revenues is less settled and benefits from a proactive ruling strategy.

Decision matrix: which structure suits which bridge operator profile?

No single structure is optimal for every bridge operator. The right choice depends on the operator's user base, token architecture, governance model, and risk tolerance. The following profiles capture the most common fact patterns we encounter.

Profile A – A centralised bridge with an identified operating company, EU users, and a fee-generating model. This profile engages the PSAN mandatory registration (or MiCA CASP authorisation if passporting from another EU member state). The operator needs an AML/KYC programme, a Travel Rule solution, and a French banking relationship. Timeline to operational compliance is typically measured in months from a complete application. Key risk: the token classification must be completed before any governance or revenue-sharing token is issued.

Profile B – A DAO-governed bridge with no identified legal entity, governance tokens distributed broadly, and a French user base. This profile faces the highest legal uncertainty. The AMF may attribute regulatory responsibility to the deployers or the governance-token holders who exercise material control. Key risk: the absence of a legal entity does not create a regulatory safe harbour; it creates a personal-liability risk for identifiable actors. The appropriate step is to establish a legal wrapper before the protocol reaches material scale.

Profile C – A bridge operated by a non-EU entity that provides services to French users through a website accessible in France. This profile engages the PSAN regime on the basis of the AMF's territorial reach: a service is provided in France if it is marketed to, or used by, French residents. The operator must either register with the AMF, obtain a passporting CASP authorisation, or implement robust geofencing that demonstrably excludes French users. Key risk: informal geofencing without technical enforcement is not a reliable defence.

FAQ

Can a DeFi protocol be regulated?

Yes, in France and across the EU a DeFi protocol can fall within the regulated perimeter if it performs a function that the PSAN regime or MiCA defines as a regulated activity – regardless of whether that function is performed by code rather than a human operator. The AMF applies a functional test. If identifiable persons deploy, govern or profit from the protocol, they may be attributed regulatory responsibility. Full decentralisation, with no identifiable controlling party, sits in a gap that current rules acknowledge but do not resolve definitively.

What legal wrapper suits a DAO?

The choice of legal wrapper for a DAO operating in or toward France depends on the DAO's governance model and activity. Common options include a French SAS (société par actions simplifiée), a Swiss association, a Cayman foundation company, or a Marshall Islands DAO LLC, each with different liability, tax and regulatory consequences. There is no universal answer; the wrapper must match the DAO's token structure, revenue model and the jurisdictions in which it has material users or contributors. OBOLUS assesses the full stack before recommending a form.

Who is liable when a smart contract fails?

Liability for a smart-contract failure in France is assessed under general civil and commercial law principles, with no specific smart-contract liability statute currently in force. The deploying entity or individual is the primary candidate for liability in tort and contract. A PSAN-registered operator that deploys a bridge smart contract may face additional regulatory and civil liability if the contract failure causes user losses. Audit records, governance logs and the terms under which users interact with the protocol are the key evidence in any dispute. This makes pre-deployment legal review material, not optional.

Related at OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label, and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com.

By Roman Levitt, Technology & DeFi Counsel – specialising in smart-contract legal architecture, DeFi protocol structuring and token classification under EU and cross-border digital-asset regimes.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours