Token classification in Abu Dhabi Global Market (ADGM) – the international financial centre operating under its own common-law framework within Abu Dhabi – is the first legal question every founder, custodian and fund manager must answer before a product touches the market. Get it wrong and a utility token sale becomes an unregistered securities offering; get it right and the path to regulated activity, banking and institutional capital opens considerably. Under the Financial Services Regulatory Authority (FSRA), ADGM's independent regulator, every digital token is assessed by the rights it confers, not by the label its issuer applies.
This page sets out how the FSRA classification regime works, what it means for inbound issuers, and where the cross-border interaction with tax, banking and other regulatory regimes creates the practical risk that most teams encounter only after a structure has been committed to.
How does the FSRA classify tokens in ADGM?
The FSRA applies a substance-over-label test: a token is classified by the economic rights it confers on holders, not by the terminology in the whitepaper or marketing materials. The FSRA's recognised virtual assets framework distinguishes between virtual assets that are investment instruments and those that are not, and the boundary between these two categories carries significant regulatory consequences. A token that grants its holder a share in profits, a claim on an asset pool, or a governance right over economic outcomes is likely to be treated as a security or investment contract. A token whose sole function is access to a defined software service – with no investment expectation and no transferable economic benefit – sits on the other side of that line.
The key analytical axes the FSRA applies track those used in mature common-law jurisdictions. First: does the holder have a right to share in the profits or revenues of an enterprise? Second: is the holder dependent on the managerial efforts of others to realise any economic value? Third: is the token transferable in a way that allows secondary-market pricing? A token that scores positively on any one of these axes will attract close scrutiny. A token that scores positively on all three is almost certainly within the regulated perimeter.
In our advisory work on cross-border token structures, one classification question comes up more than any other: whether a token that begins as a utility instrument can migrate, over time, into a security. The answer under the FSRA framework – as under most sophisticated regimes – is yes. A token's initial design does not fix its classification permanently. If secondary trading creates price appreciation expectations, or if the issuer's roadmap introduces economic rights that were not present at launch, the analysis needs to be rerun.
Contact OBOLUS for a scoped classification assessment before your structure is finalised. The analysis above describes the standard path. Your specific token – its rights architecture, its economic model, its intended user base – changes the result. Write to us at info@oboluslaw.com or use our contact form to start a confidential conversation.
What counts as a "recognised virtual asset" under the FSRA?
The FSRA maintains a list of assets it recognises for regulated activity purposes – a concept without a direct equivalent in most other leading digital-asset regimes. Only tokens that appear on the FSRA's recognised virtual assets list may be handled by ADGM-licensed entities in the course of regulated activity. This architecture means that classification and licensing interact directly: an exchange or custodian cannot simply list a token on the basis that it is not a security; it must confirm that the FSRA has recognised it.
In practice, the recognised assets list has historically included the largest and most liquid crypto-assets. Tokens with smaller market caps, bespoke governance structures or novel economic rights require a more deliberate engagement with the FSRA before an ADGM-licensed entity can handle them in regulated activity. Issuers planning a product launch through ADGM-licensed intermediaries need to factor this process into their timeline.
The recognised virtual assets concept also creates a cross-border wrinkle for inbound operators. A token that is treated as a commodity or utility instrument in, say, Singapore under the Payment Services Act administered by MAS (Monetary Authority of Singapore), or that falls outside the investment category in the EU under MiCA (Markets in Crypto-Assets Regulation) supervised by ESMA and national competent authorities, may still need to go through a separate recognition process in ADGM before it can be touched by regulated intermediaries here. The classifications do not map onto each other automatically. Operators we advise routinely underestimate this friction when planning a multi-hub strategy.
What happens if a token is classified as a security in ADGM?
A token classified as a security under the FSRA regime triggers the full suite of regulated-activities obligations. Offering it to the public without authorisation, intermediating its transfer without an appropriate FSRA licence, or providing investment advice about it without the relevant permission – each of these becomes a breach of the applicable provisions of the ADGM framework, carrying both civil and criminal exposure. The threshold question is not whether an enforcement action is likely; it is whether the structure is sound enough to withstand scrutiny if one occurs.
For issuers, a security-token classification opens two paths. The first is to restructure the token so that the economic rights giving rise to classification as a security are removed or modified before launch. In our cross-border practice, we frequently help clients work through whether such a redesign is commercially viable or whether it would hollow out the value proposition. The second path is to proceed with the security-token structure, obtain the relevant FSRA permissions, and manage the offering under the applicable prospectus or private-placement regime. The second path is slower and more capital-intensive, but for certain institutional products – tokenised funds, tokenised real estate, digital bond instruments – it is the correct and commercially defensible path.
A practical note on cross-border structuring: many issuers attempt to manage classification risk by routing an offering through an entity in a jurisdiction perceived as more permissive. This strategy has limits. If the token is marketed to users in ADGM, if ADGM-licensed intermediaries handle the distribution, or if the issuer entity has a nexus with ADGM, the FSRA's jurisdictional reach will likely be engaged regardless of where the issuing entity is incorporated. Shell structures in offshore jurisdictions do not reliably insulate an offering from ADGM regulatory scrutiny.
Does a token offering in ADGM require a whitepaper or prospectus?
Disclosure obligations in ADGM depend entirely on the classification outcome and the nature of the offer. A token that is not a security and is not a recognised virtual asset handled by a regulated entity may have no mandatory whitepaper requirement under the FSRA framework itself – though other legal obligations, including AML and consumer-protection rules, will still apply. A security token offering triggers prospectus or disclosure document obligations that are materially more demanding, including financial statement requirements, risk-factor disclosure, and FSRA pre-clearance.
The EU's MiCA regime introduced a mandatory whitepaper regime for most crypto-asset offerings directed at EU users, administered by ESMA and the relevant national competent authority in the issuer's home member state. That obligation is separate from, and runs in parallel to, any ADGM-specific disclosure requirements. An issuer with a global distribution strategy – ADGM users, EU users, and possibly users in Singapore, Hong Kong and the UK – faces a stack of disclosure obligations that do not align neatly. We regularly advise on this multi-regime stack and on the sequencing of filings.
One common error is to treat the whitepaper as a legal classification document. It is not. A whitepaper that describes a token as a "utility token" does not fix the legal classification. Regulators – the FSRA, ESMA, the FCA, the SFC – all assess classification against the substance of the rights, not the marketing language. An issuer who structures a whitepaper around a utility narrative but builds in economic rights that look like investment returns has not solved the classification problem; they have created an evidentiary record that may be used against them.
How does ADGM token classification interact with other regulatory regimes?
Token classification is rarely a single-jurisdiction problem. A token issued by an ADGM entity or distributed to ADGM users will simultaneously engage the laws of every jurisdiction where users are located, where intermediaries operate, and where the token is listed or traded. The cross-border interaction creates risk along three axes: regulatory, tax and banking.
On the regulatory axis: a token that avoids security classification in ADGM may nonetheless be treated as a security by the SFC in Hong Kong, by the SEC or CFTC in the United States, or by the FCA in the UK. Each of those determinations is made independently under each regime's own rules. A clean ADGM classification does not port to other jurisdictions. For issuers planning global distribution, the classification exercise needs to be run in each material jurisdiction. In practice, this means identifying the three or four regimes that matter most for the distribution strategy and stress-testing the token design against each.
On the tax axis: the classification of a token for regulatory purposes does not automatically determine its tax treatment. A token classified as a utility instrument for FSRA purposes may still generate taxable income at the issuer or holder level depending on the applicable tax law. ADGM operates within the UAE tax framework, which has its own rules on corporate tax, VAT and the treatment of digital-asset transactions. The interaction between the regulatory classification and the tax position needs to be mapped before launch, not after the first sale.
On the banking axis: UAE-based banks apply their own internal criteria for onboarding digital-asset businesses, which are often more conservative than the regulatory framework itself. An issuer with a clean FSRA classification may still find that its banking options are constrained by the risk appetite of individual institutions. In our experience, banking access is one of the most common operational blockers for ADGM-based token issuers, and it requires a dedicated workstream that runs alongside the regulatory analysis, not after it.
If your structure touches multiple jurisdictions, a single-hub classification analysis is not enough. To map the full regulatory, tax and banking interaction for your token, contact OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw.
How does ADGM classification apply to airdrops and early-stage distributions?
An airdrop – a distribution of tokens to wallet addresses, typically at no direct cost to recipients – is not exempt from classification analysis simply because no consideration changes hands. If the distributed token carries economic rights that would make it a security in a paid offering, the same analysis applies to the airdrop. The FSRA's approach, consistent with the treatment in most major jurisdictions, looks at the nature of the instrument, not the mechanics of its delivery.
Early-stage founders frequently use airdrops to bootstrap community and distribute governance tokens. The governance-token question is one of the more difficult classification problems in the current environment. A token that grants voting rights over protocol parameters – with no direct economic right – sits close to the utility end of the spectrum. A governance token that also controls a treasury, determines fee distributions, or grants pro-rata claims on protocol revenue is materially closer to a security. The line is not always clear, and the FSRA – like regulators in most leading hubs – will look at the aggregate economic picture.
The cross-border dimension of airdrops is particularly acute. An airdrop directed at wallet addresses globally will, by definition, reach users in jurisdictions whose laws the issuer may not have assessed. US persons, EU users, Hong Kong residents – each brings a different regulatory regime into the picture. Structuring an airdrop to exclude regulated jurisdictions requires deliberate address-screening and legal eligibility protocols, not simply a disclaimer in the terms of service.
In a recent matter, a Web3 protocol considering an ADGM-anchored governance token distribution engaged us to map the classification exposure across its three principal user-base jurisdictions before launch. We identified a specific economic right embedded in the token's fee-sharing mechanic that created a credible security-classification risk in two of the three jurisdictions. The protocol redesigned the mechanic before distribution. The process took a matter of weeks and avoided a post-launch restructuring that would have been considerably more disruptive.
Self-assessment: five questions every token issuer in ADGM should answer
Before engaging with the FSRA or finalising a token structure, a founding or legal team can run a preliminary self-assessment against five threshold questions. These questions do not replace legal advice, but they identify the issues that will determine the classification outcome and the regulatory path.
First: does the token confer any right to share in the profits, revenues or residual value of the issuing entity or the protocol? If yes, the security analysis is engaged.
Second: does the token's value proposition depend, wholly or substantially, on the managerial or entrepreneurial efforts of the issuing team or a central development organisation? If yes, the investment-contract framing is available to a regulator.
Third: is the token transferable and, if so, is secondary-market trading anticipated or facilitated? Transferability is not itself a classification trigger, but it is a significant factor in the overall analysis.
Fourth: will ADGM-licensed intermediaries handle the token – as custodians, as exchange operators, or as distributors? If yes, the FSRA's recognised virtual assets requirement is directly engaged.
Fifth: are there users, investors or intermediaries in jurisdictions outside ADGM for whom the classification analysis may differ? If yes, the multi-regime assessment is necessary before distribution begins.
A founding team that can answer all five questions cleanly and on the basis of the actual token design – not the intended design – is well-positioned to engage productively with ADGM counsel and, where appropriate, with the FSRA directly.
A common assumption: a "utility" label resolves the classification question
A common assumption among early-stage founders is that labelling a token as a utility instrument in the whitepaper, the terms of service, and the marketing materials is sufficient to fix its legal classification. It is not. Regulators in every leading jurisdiction – the FSRA, ESMA, the FCA, the SFC – apply a substance-over-form analysis. The label on the document is one data point. The economic rights encoded in the smart contract, the incentive mechanics of the distribution, and the reasonable expectations of purchasers are the decisive factors.
We assess classification against the substance of rights, not the marketing label. A utility label applied to a token with embedded economic returns does not reduce regulatory risk; in the worst case, it creates an evidentiary problem by suggesting awareness of the classification issue and a deliberate attempt to avoid it. The correct approach is to conduct the classification analysis honestly – against the actual token design – and then either modify the design if a regulated instrument is not the goal or proceed with eyes open if it is.
The myth that a utility label provides legal cover is one of the most persistent sources of avoidable risk in token structuring. We encounter it across every jurisdiction we advise in, from ADGM and VARA-regulated Dubai to MiCA jurisdictions in the EU and the SFC's Hong Kong regime. The substance-over-label principle is now settled in every forum that matters.
Related at OBOLUS
- Token Offerings & Securities practice overview – the full scope of our token structuring, classification and offering work for digital-asset businesses
- Airdrop legal structuring for early-stage founders – structuring compliant token distributions across multiple regulatory regimes
- Pre-exit tax restructuring for early-stage founders – managing the tax position of a token issuance before a liquidity event
FAQ
Is my token a security?
Whether a token is a security depends on the rights it confers, not its label. Under the FSRA regime in ADGM – and under most leading regulatory frameworks – the core questions are whether holders share in profits or revenues, whether value depends on a central team's efforts, and whether the instrument is transferable in a way that creates investment expectations. A token that scores positively on these factors is likely to require a securities-law analysis and, depending on jurisdiction, regulated-offering treatment. Classification must be assessed against the actual token design, not the intended one.
Do I need a MiCA whitepaper?
A MiCA whitepaper obligation arises when a crypto-asset offering is directed at users in the European Union, regardless of where the issuer is incorporated. If your token distribution reaches EU users – even as part of a broader global airdrop or sale – the applicable MiCA whitepaper provisions, supervised by ESMA and the relevant national competent authority, will be engaged. A clean ADGM classification does not substitute for MiCA compliance. The two regimes operate in parallel, and an issuer with users in both regions must satisfy both sets of disclosure requirements independently.
How should an airdrop be structured legally?
An airdrop must be structured around a classification analysis of the token being distributed, not around the absence of monetary consideration. If the token would be a security in a paid sale, distributing it for free does not change that analysis. Legal airdrop structuring involves: confirming the classification of the token in each material user-base jurisdiction; implementing eligibility protocols to exclude persons in jurisdictions where distribution is restricted; and ensuring that the distribution mechanics do not inadvertently create economic rights – such as fee entitlements or treasury claims – that trigger a security analysis. A terms-of-service disclaimer is not a substitute for this process.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label – the standard that every leading regulator, including the FSRA, applies. To discuss your structure, contact info@oboluslaw.com.
By Roman Levitt, Technology & DeFi Counsel – specialising in token design, smart-contract legal architecture and cross-border classification analysis for digital-asset issuers operating across the ADGM, VARA and MiCA regulatory perimeters.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.