What France actually requires of a DeFi protocol
A DeFi protocol (a smart-contract system that intermediates financial activity without a traditional operator) does not sit outside French law simply because its code runs on a public blockchain. The Autorité des marchés financiers (AMF), France's securities and markets regulator, and the PSAN regime (Prestataire de Services sur Actifs Numériques – the registered digital-asset service provider framework under French monetary law) together define who must register, what tokens require a prospectus or whitepaper, and where liability lands when something goes wrong. Mis-classifying a token can convert a product launch into an unregistered securities offering. This guide walks through the structuring decision in sequence, from the initial classification question to the cross-border banking and tax interaction that most teams discover too late.
As MiCA's CASP authorisation begins to displace the PSAN framework for EU-scale operations, French-domiciled DeFi projects face a layered decision: comply with the transitional PSAN regime now, prepare for MiCA passporting, or use France as a springboard to a parallel EU entry point. The right answer depends on the protocol's activity profile, its token economics, and where its users sit.
Step 1: Classify the token and the activity before anything else
Token classification is the foundational step, and it controls every downstream choice in France. The AMF applies a substance-over-label analysis. A token's name – "utility," "governance," "points" – carries no legal weight. What matters is the economic rights it confers on holders: a claim on profits or revenues, a right to repayment, or an expectation of return derived from the efforts of others. If those elements are present, the instrument looks like a financial security under French law, and the consequences are significant.
Tokens that are financial securities trigger prospectus obligations and, depending on the offering structure, MiFID-equivalent rules applied through French transposition. Tokens that are actifs numériques (digital assets under French monetary law but not financial securities) fall under the PSAN perimeter instead. A pure utility token conferring only access rights – and where no secondary market price expectation is promoted – may sit outside both perimeters entirely, though that position requires careful factual support.
The AMF's position is that substance governs classification, not the label on the whitepaper. We assess every protocol against this matrix before advising on structure. The classification memo is not a formality. It is the document that determines whether you need a PSAN registration, a full prospectus, or neither – and it must hold up under regulatory scrutiny.
The cross-border complication here is immediate. A French-facing DeFi protocol with non-French users may simultaneously trigger PSAN obligations in France, MiCA CASP authorisation requirements for EU users, and – where US persons can access the interface – the attention of the SEC and CFTC. Structuring the geographic perimeter of the protocol is inseparable from the token classification work.
For a scoped classification assessment of your token and activity profile, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the token mechanics – change the analysis materially.
Step 2: Decide whether PSAN registration is required
PSAN registration is mandatory in France for any entity providing digital-asset services to French users, regardless of where the entity is incorporated. The services caught include the operation of a trading platform, the custody of digital assets on behalf of third parties, and the exchange of digital assets for fiat or for other digital assets. A DeFi protocol that is genuinely non-custodial and fully decentralized sits in a different position – but "fully decentralized" is a factual standard, not a design aspiration.
In practice, most early-stage DeFi protocols have identifiable operators: a foundation, a development company, or a multisig held by named contributors. Where an identifiable entity controls upgrades, holds treasury assets, or operates a user-facing interface, French supervisory practice will look through the smart-contract wrapper to that entity. The AMF has signalled publicly that operator-controlled DeFi is not exempt from registration obligations.
Voluntary PSAN registration – an enhanced track above the mandatory baseline – offers advantages: it allows the entity to hold itself out as AMF-supervised, which matters for banking access and institutional counterparty relationships. The enhanced registration requires a more detailed AML/CFT program, governance policies, and fit-and-proper vetting of directors. The timeline for enhanced PSAN review varies, but applicants should budget for a process measured in months, not weeks, particularly where the AMF raises questions about the protocol's classification or governance structure.
Under the transitional provisions as France moves toward full MiCA alignment, existing PSAN registrations are expected to convert to CASP authorisations on a schedule set by ESMA and the AMF. New applicants should build their compliance program to satisfy both the current PSAN requirements and the prospective MiCA standards – the additional work is modest if the baseline is well constructed.
Step 3: Choose the legal wrapper for the protocol entity
A DeFi protocol needs a legal entity for three reasons: to hold IP, to employ or contract with contributors, and to interface with the banking system. The entity type also signals regulatory intent to the AMF. There is no one-size answer, but the decision typically turns on three variables: the number of contributors, the governance model, and where the treasury assets are held.
A French SAS (simplified joint-stock company) is the dominant choice for early-stage protocols with a defined founding team. It is flexible on governance, compatible with equity-like token arrangements, and straightforward to open a corporate bank account with French fintech banks and EMI providers. The SAS is also the vehicle of choice for French VC investment, which matters if the protocol intends to raise institutional capital.
A French association loi 1901 suits non-commercial open-source foundations. It cannot issue equity, but it can receive donations and grants. Where the protocol is genuinely community-governed and the founding team has transferred meaningful control to on-chain governance, the association model is defensible – but it does not solve the PSAN question if the association operates regulated services.
Some teams choose a dual structure: a French SAS holding the IP and the PSAN registration, paired with a Cayman or BVI foundation managing the token treasury and the DAO governance layer. This split recognises the legal reality that the DAO itself is not a legal person under French law. The French SAS entity faces PSAN obligations and AMF oversight; the offshore foundation handles token distributions and governance mechanics that French law does not yet regulate directly. The interaction between the two layers must be documented carefully to avoid the French entity inadvertently assuming liability for the offshore entity's activities.
In our cross-border practice, we have seen teams underestimate the banking dimension of this choice. A Cayman foundation without a regulated operational entity struggles to access EU payment rails. The French SAS or a PSAN-registered entity provides the credentialing that banks and EMI providers need to onboard the project as a business customer.
What does DAO structure mean legally in France?
A DAO (decentralized autonomous organization) has no independent legal personality under French law. Token-holder votes, on-chain governance proposals, and smart-contract execution are operational mechanisms, not legal acts. The legal consequences of a DAO's actions – signing a contract, holding assets, facing a claim – are attributed to the identifiable natural or legal persons who control the relevant infrastructure.
This has a direct and uncomfortable consequence: where a DAO's multisig holds treasury funds and a protocol is exploited, the signatories may bear personal liability for losses if they had operational control and failed to exercise reasonable care. French courts have not yet produced a settled doctrine on DAO liability, but the general principle of responsabilité civile (civil liability) applies to identifiable actors regardless of how the governance layer is described.
The practical structuring response is to interpose a legal entity – typically the SAS or the offshore foundation – between the on-chain governance mechanics and any asset-holding or service-providing function. The entity holds the assets, enters the contracts, and bears the regulatory obligations. The DAO governance layer influences the entity through documented processes (board instructions, delegate votes with legal effect), not through direct on-chain execution of financial acts.
Smart-contract code itself is not a contract under French law in the absence of identifiable parties and meeting of minds on essential terms. A smart contract (self-executing code that automatically performs defined functions upon trigger conditions) may implement a legal contract or may document one – but the legal contract must exist in a form French law recognises. DeFi protocols that rely solely on code to define the rights of liquidity providers or token stakers face real risk that those rights are unenforceable in a French court.
Step 4: Build the AML, Travel Rule, and compliance program
Any entity caught by the PSAN regime must maintain an AML/CFT program that satisfies the standards the AMF and the French financial intelligence unit, Tracfin, apply. The program must include customer due diligence, transaction monitoring, suspicious activity reporting, and – where the protocol transfers digital assets on behalf of third parties – compliance with the Travel Rule (the obligation under FATF Recommendation 15 to pass originator and beneficiary data alongside a transfer).
The Travel Rule creates a practical problem for DeFi protocols: on-chain transfers typically do not carry the identity data the rule requires. Compliance solutions involve collecting and storing Travel Rule data off-chain at the point of deposit or withdrawal, using a VASP-to-VASP data channel compliant with the applicable technical standards. Protocols that operate smart-contract pools without any off-chain identity layer – where users interact pseudonymously from self-hosted wallets – face a structural conflict with the Travel Rule that must be addressed at the architecture stage, not retrospectively.
In our cross-border practice, we regularly advise on Travel Rule implementation for protocols that onboard users through a regulated front-end while the underlying smart contracts remain permissionless. The solution is entity-level – the PSAN-registered operator collects and transmits Travel Rule data for transfers it intermediates. Transfers that bypass the regulated front-end and interact with the smart contracts directly are outside the operator's control, and the program documentation must clearly define this scope.
Operators we advise routinely underestimate the time needed to build a compliant AML program before the PSAN application. A program assembled under time pressure tends to fail AMF scrutiny at the interview stage. Budget at least two to three months for policy drafting, gap analysis, and staff training before submitting.
If your protocol is approaching a PSAN application and the compliance program is not ready, write to us at info@oboluslaw.com before you submit. A prior application that stalled or drew AMF questions can often be recovered with a structural revision – but only before the formal rejection is issued.
Step 5: Map the tax and banking stack across the cross-border structure
French corporate tax applies to a French-resident SAS on its worldwide income. Token issuances, liquidity mining rewards, and protocol fee revenues all have tax character. The precise treatment depends on classification: treasury-held tokens may be assets or liabilities depending on the accounting treatment adopted; fees received in tokens are income at the date of receipt, typically at the market value at that time. The VAT position of DeFi services is not fully settled in France, though the European Court of Justice's treatment of crypto exchange services as financial services exempt from VAT is the prevailing reference point.
Banking access is the operational pressure point that surprises founders most. French retail banks remain cautious about crypto-native clients. The practical solution for most PSAN-registered entities is to bank with an authorised payment institution or EMI licensed in France or another EU member state and prepared to serve crypto businesses. Several established EMIs in the EU market actively serve PSAN-registered and MiCA-licensed entities. The PSAN registration itself is a credentialing document: a bank's compliance team can review it and make a risk decision. Without registration, the conversation rarely gets past the initial KYB request.
Where the dual-entity structure involves an offshore foundation, the French SAS must document the transfer pricing and intercompany arrangements with care. The AMF and the French tax authority (Direction générale des finances publiques) both have visibility into the structure. Arrangements that shift value to an offshore entity without economic substance will attract scrutiny from both.
A recent matter in our practice illustrates the convergence of these issues. A European DeFi team had structured a French SAS and a Cayman foundation without coordinating the token issuance mechanics between the two. The SAS received protocol fees in tokens; the foundation held the governance token treasury. French tax applied to the SAS's token receipts at market value. The foundation's token distributions were treated by the French tax authority as a constructive dividend to the SAS's shareholders. We restructured the intercompany arrangements and the token allocation documentation in advance of a French audit cycle, resolving the exposure qualitatively before any assessment was raised.
When does MiCA's CASP authorisation replace the PSAN registration?
MiCA's CASP authorisation regime has entered force across the EU, and ESMA coordinates with national competent authorities – including the AMF – on the transition from pre-MiCA national regimes. For French-domiciled DeFi protocols, this means the PSAN regime is a bridge, not a destination. The AMF has been transparent that PSAN-registered entities will need to convert to CASP authorisation on the timetable ESMA sets. The conversion process is not automatic: CASP authorisation requires a formal application, updated governance and compliance documentation, and in some cases an adjustment to the entity's permitted activities.
The upside of this transition is significant. A CASP authorisation granted by the AMF carries MiCA passporting rights across all EU member states. A protocol currently serving French users under a PSAN registration can, after CASP authorisation, expand to Germany, Spain, the Netherlands, and the rest of the EU/EEA without a separate local licence. For DeFi protocols with pan-European ambitions, the French AMF path has a structural advantage over jurisdictions that do not sit inside the MiCA passporting zone.
Teams choosing France specifically for MiCA passporting should build the CASP application requirements into their initial structuring. The incremental compliance cost of going directly to CASP-ready is modest relative to the cost of rebuilding the program after a PSAN registration that does not meet CASP standards.
Related at OBOLUS
- DeFi, Tokenization & Smart-Contract Law – our practice overview for protocols, DAOs, and token issuers across jurisdictions.
- Cross-chain bridge legal risk in France (AMF/PSAN) – how French and MiCA rules apply to bridge operators and their liability exposure.
- Smart-contract dispute resolution: where the legal lines are drawn – analysis of enforcement options when on-chain code and legal obligation diverge.
A common assumption about DeFi and regulation
A common assumption among protocol founders is that attaching a utility label to a whitepaper settles the classification question. It does not. The AMF – and under MiCA, ESMA – applies an economic substance test. If a token confers a right to a share of protocol revenues, appreciates because of the efforts of an identifiable team, or is marketed with return expectations, it will be analyzed as a financial instrument regardless of what the whitepaper calls it. The AMF has the power to require registration and to impose sanctions retroactively where a service was provided without registration. We assess classification against the substance of rights, not the marketing label – and that analysis must be documented and defensible before the protocol goes live.
The cross-border dimension compounds the risk. A utility label that is arguable under French law may be a securities offering under the law of another jurisdiction where the protocol's users sit. Building jurisdiction-by-jurisdiction user access controls into the front-end is not a compliance substitute, but it is a material risk-mitigation step that regulators in multiple markets treat as evidence of good faith.
FAQ
Can a DeFi protocol be regulated?
Yes. The AMF applies its regulatory perimeter to DeFi protocols based on whether an identifiable entity provides regulated services, regardless of how the underlying infrastructure is described. A protocol with an operator controlling upgrades, a front-end interface, or a treasury is not automatically exempt. Fully decentralized, operator-less protocols present a harder case, but "fully decentralized" is a factual standard that most early-stage protocols do not yet meet. The PSAN regime and, prospectively, MiCA's CASP framework both reach protocol operators where the services provided are within the defined perimeter.
What legal wrapper suits a DAO?
No single wrapper is universally correct. In France, the most common approaches are a French SAS for protocols with a defined team and IP to protect, and a dual structure pairing a French SAS with an offshore foundation (Cayman or BVI) for the governance and token treasury layer. The SAS handles the PSAN registration and the banking relationship; the foundation manages the on-chain governance mechanics. The legal interaction between the two layers must be documented carefully. A French association loi 1901 suits non-commercial open-source projects but does not resolve PSAN obligations.
Who is liable when a smart contract fails?
Liability follows control. Where a smart contract fails and an identifiable entity controlled its deployment, held upgrade authority, or operated the user-facing interface, that entity is the primary candidate for a civil claim under French law. DAO token holders who participated in a governance vote approving a vulnerable upgrade may also have exposure, depending on the facts. The absence of a formal contract between users and an operator does not eliminate liability; French civil liability principles apply to identifiable actors. Structuring to separate operational control from governance participation is the standard risk-mitigation approach.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and DeFi protocols on licensing across 70+ jurisdictions and on the tax, banking and compliance structures that sit around them. Digital assets are the whole of our practice. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when recovery is required. We assess classification against the substance of rights, not the marketing label – and that discipline runs through every structuring engagement we take on. To discuss your DeFi protocol's structure in France or across borders, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Roman Levitt, Technology & DeFi Counsel – specialising in smart-contract law, token classification, and DeFi protocol structuring across EU and cross-border regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.