Token issuers choosing Abu Dhabi Global Market (ADGM) as the seat for a token sale face a specific legal challenge: the agreement that governs the offering must satisfy the Financial Services Regulatory Authority (FSRA) regime while remaining enforceable in the jurisdictions where purchasers sit, where banking clears, and where the issuer entity is actually managed. Getting that intersection wrong does not produce a minor compliance gap. It converts a product launch into an unregistered offering under applicable securities law, exposing founders and directors to personal liability alongside the issuing entity.
A token sale agreement (the binding instrument between a token issuer and a purchaser, governing the terms on which digital tokens are sold or pre-sold) in ADGM must reflect two things at once: the FSRA's framework for virtual-asset activities and the substance-over-form classification logic that regulators across every major hub now apply. A utility label on a whitepaper does not settle the legal classification. The rights the token actually confers determine its regulatory treatment – and the agreement must be drafted to reflect that analysis, not override it.
This page sets out how OBOLUS approaches token sale agreement drafting for clients operating through ADGM, the key legal decision points, and the cross-border issues that most commonly surface during the process.
What the FSRA framework requires from a token sale
The FSRA, the regulatory authority of ADGM, applies a regulated-activities model to virtual assets. Activities involving the issuance, custody, trading or management of virtual assets may require authorisation under the FSRA framework, and the nature of that requirement turns on how the token is classified. A token that confers investment rights – participation in profits, voting over the issuer's affairs, or a claim on the issuer's assets – is likely to fall within the FSRA's perimeter for investment tokens, triggering regulated-activity obligations. A token that grants access to a defined product or service, without investment characteristics, sits in a different part of the regime.
Classification is therefore the threshold question, and it must be resolved before the agreement is drafted. The FSRA applies a substance-over-form test: the regulator looks at the rights the token confers in practice, not the description on the project's website. We have seen issuers arrive with documents in which the token is described as "purely functional" but the underlying smart contract vests governance rights that look considerably more like equity participation. That gap between marketing and mechanics is exactly the gap that enforcement actions exploit.
ADGM is a common-law jurisdiction – its courts apply English common-law principles, and FSRA-authorised firms operate within a legal environment that treats contractual certainty, disclosure obligations, and investor protection seriously. That is one of the regime's strengths for a well-structured offering. It is also why the drafting standard expected in ADGM is higher than in some lighter-touch registration regimes.
For a scoped classification and drafting assessment, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your token mechanics – the rights structure, the vesting schedule, the governance layer – change the analysis at every step.
Why token classification drives every drafting decision
Token classification under the FSRA framework determines which regulatory obligations attach, which representations the issuer can lawfully make to purchasers, and which conditions precedent the agreement should include. Each of those outcomes flows directly from a single upstream finding: what kind of token is this?
The FSRA's recognised-virtual-assets concept means that not all digital assets are treated identically. A token that meets the criteria for a recognised virtual asset sits within the regulatory perimeter in a defined way; one that does not may be treated as outside the scope of the regime entirely, or as an unregulated product. Neither outcome is automatically favourable. An unregulated token can still trigger securities-law analysis in the purchaser's home jurisdiction – and that is where cross-border risk becomes acute.
In our practice, the classification analysis works through three questions in sequence. First: does the token confer any right that resembles an investment expectation – profit participation, an enforceable claim on the issuer, or an interest in an underlying pool of assets? If yes, the token is likely an investment token and the offering is a regulated activity. Second: is the token used or usable as a means of payment within or outside the issuer's ecosystem? If so, payment-services analysis applies in the relevant jurisdictions. Third: is the token purely a software access credential, with no financial rights and no secondary-market expectation built into the design? If all three answers are clean, a utility characterisation may hold.
Each answer shapes a specific section of the agreement. An investment token requires fulsome disclosure, risk factors, eligible-investor restrictions, and secondary-sale conditions. A utility token agreement focuses on the product-delivery obligation, the refund and default mechanics, and the disclaimer of investment characteristics – which must be accurate, not aspirational.
What goes into a compliant ADGM token sale agreement?
A compliant token sale agreement for an ADGM-based issuer contains several layers that a generic template will not supply. Each layer addresses a specific legal risk point, and omitting any one of them is a drafting error with potential enforcement consequences.
The classification statement is the first layer. The agreement must state, accurately, what the token is and what rights it confers. That statement cannot contradict the FSRA classification analysis. If the token is an investment token, the agreement must say so and engage the relevant disclosure standards. If it is a utility token, the agreement must describe the product-delivery obligation in terms specific enough to be enforceable – a vague promise of "access to the platform" is not a contractual obligation.
The eligible purchaser filter is the second layer. The FSRA regime, like every serious virtual-asset framework, restricts who may participate in certain categories of offering. The agreement must include representations from the purchaser confirming eligibility, jurisdiction of residence, and investor status where required. Those representations need to be structured as conditions precedent to the transfer of tokens, not afterthoughts in a schedule.
The delivery and default mechanics form the third layer. When will tokens be delivered? What triggers a delay? What is the refund or compensation mechanism if delivery fails? These provisions matter both contractually and regulatorily. Under the FSRA framework, a pre-sale or SAFT-style structure (a Simple Agreement for Future Tokens, the instrument under which a purchaser pays now for a right to receive tokens later) is subject to its own treatment, and the agreement must be designed accordingly.
The representations and risk factors layer sits alongside delivery mechanics. The agreement should include an accurate and specific risk-factor section: regulatory risk, smart-contract risk, liquidity risk, and key-person risk are the standard categories. The FSRA and the broader ADGM legal environment expect disclosure to be meaningful – the boilerplate risk-factor blocks from US-market templates frequently fail this standard because they are written for a different regulatory context.
Finally, the governing law and dispute resolution clause must be chosen deliberately. ADGM courts apply English common law, and the ADGM courts and ADGM Arbitration Centre are established, credible forums. However, if the majority of purchasers sit in a different jurisdiction, or if the issuer holds assets elsewhere, a governing-law choice that looks good on paper may be difficult to enforce in practice. That is a cross-border interaction that must be assessed at drafting, not at the point of dispute.
How the whitepaper interacts with the agreement
The whitepaper and the token sale agreement are not independent documents – they are legally interdependent, and inconsistencies between them create liability. A whitepaper that describes a token as granting governance rights creates a representation; if the agreement then disclaims any such rights, the issuer has a contractual contradiction that a purchaser's counsel will identify within hours of review.
Under MiCA (the EU's Markets in Crypto-Assets Regulation), issuers making a public offering into the EU/EEA must comply with whitepaper disclosure requirements – and those requirements interact directly with the token classification. An ADGM-based issuer selling to EU purchasers must therefore design the whitepaper to satisfy both the FSRA's disclosure expectations and MiCA's requirements. That is a dual-compliance drafting exercise, not simply a matter of adding a EU-facing appendix.
For issuers not reaching the MiCA threshold – because the offering is restricted to non-EU purchasers, or because it qualifies for an exemption – the whitepaper is still a primary disclosure document, and its legal status in the FSRA context means it can be incorporated by reference into the agreement. That is useful: it allows the agreement to be shorter and more focused on mechanics, while the whitepaper carries the detailed technical and economic disclosure. But incorporation by reference is only sound if the whitepaper itself is legally reviewed, not just commercially drafted.
The cross-border interaction: tax, banking, and purchaser jurisdiction
An ADGM token sale does not operate in a vacuum. Three cross-border interactions require legal attention before the agreement is finalised, and each has a feedback loop into the drafting.
The first is purchaser jurisdiction. The agreement must restrict participation by purchasers in jurisdictions where the offering would trigger additional regulatory obligations – typically US persons (given SEC and CFTC reach), jurisdictions under FATF grey-list or sanctions programmes, and jurisdictions that have not yet established a clear virtual-asset regime. These restrictions must be in the agreement as representations and conditions, and they must be operationalised in the know-your-customer process, not left to the smart contract alone.
The second cross-border interaction is banking. Token sale proceeds are often received in fiat before being deployed, or converted from crypto at settlement. ADGM-based issuers will typically bank within ADGM, in the broader UAE, or in a third-country banking hub. Each of those banking relationships has its own transaction monitoring expectations, and the agreement's payment mechanics must align with what the issuer's bank will actually process. We have seen transactions stall not because the legal structure was wrong, but because the payment mechanism described in the agreement was not operationally viable at the banking level.
The third is tax. The UAE has no personal income tax and currently applies a corporate-tax regime with a specific free-zone framework. ADGM entities may benefit from that free-zone treatment, subject to qualifying conditions. However, token sale proceeds may be treated as taxable income in other jurisdictions if the issuer or its beneficial owners have tax residence there. The agreement cannot resolve a tax analysis, but it can be drafted in ways that preserve optionality – or foreclose it. In our cross-border practice, we work closely with tax counsel to ensure the agreement structure does not inadvertently create a taxable event or permanent establishment in an unintended jurisdiction.
A structuring problem resolved at the agreement stage
In a recent matter, a technology company established in ADGM approached us shortly before a planned token pre-sale. The issuer had a whitepaper describing a governance token and a SAFT-style agreement drafted by advisers in another jurisdiction. The governance rights described in the whitepaper – voting on protocol parameters and a share of transaction fee revenue – placed the token squarely within the FSRA's investment-token category. The agreement, however, included a standard utility-token disclaimer and did not address eligible-investor requirements or the FSRA's disclosure standards. We restructured the offering in two steps: first, separating the protocol-access mechanics from the governance and revenue-participation features into two distinct instruments, reducing the investment characteristics of the primary sale token; second, redrafting the agreement to reflect the residual classification, with a compliant eligible-purchaser filter and jurisdiction-specific exclusions. The offering proceeded on a timetable approximately six weeks from our initial engagement.
What issuers most commonly get wrong
A common assumption among first-time ADGM token issuers is that registering an entity within ADGM and attaching a utility label to the token satisfies the regulatory requirement. It does not. Entity registration and token classification are separate legal questions, and neither the FSRA nor any other major regulator treats a marketing label as a substitute for substantive analysis.
The second common error is treating the token sale agreement as a secondary document – something to be finalised after the whitepaper is published and the community-building phase has begun. That sequence is legally dangerous. Public statements about the token, including statements on social media, in community forums, or in an early-access whitepaper, can constitute representations that later bind the issuer. If the agreement is drafted after those representations are made, the drafter is working backward to accommodate facts that may already be legally problematic.
Third, issuers frequently underestimate the governance dimension. An agreement that gives token holders meaningful control over the protocol – upgrade decisions, treasury allocation, fee changes – may create governance rights that look, legally, like equity participation. That analysis applies regardless of whether the token is technically denominated as a security. The FSRA, like ESMA under MiCA and the SFC in Hong Kong, will look at the economic and governance substance of the instrument.
Fourth, jurisdiction-exclusion clauses are commonly written as boilerplate without operational implementation. Excluding US persons from participation requires more than a clause in the agreement; it requires a KYC and compliance process that identifies and rejects US-resident purchasers at onboarding. The agreement and the compliance process must be designed together.
If a prior drafting process stalled or a classification question remains unresolved, a second review can surface the structural issue and the path forward. Contact OBOLUS at info@oboluslaw.com. If the offering clock is already running, reaching us earlier in the process creates more options.
Which issuer profile needs what level of documentation?
Not every token sale requires the same level of agreement complexity, and a mismatch in either direction creates problems. An over-engineered agreement for a small-scale, closed-circle token distribution wastes resources and may introduce compliance obligations the issuer did not intend to trigger. An under-documented agreement for a large-scale public offering leaves the issuer exposed across every dimension discussed above.
Profile A is an early-stage project conducting a private pre-sale to a small number of sophisticated investors in ADGM. The instrument is typically a SAFT or a convertible note with a token delivery feature. The documentation requirement is focused: a clean classification analysis, a compliant SAFT with eligible-investor representations, jurisdiction-exclusion mechanics, and a delivery schedule with clear default provisions. Timeline from instruction to execution is typically a matter of weeks, not months, if the classification question is clear and the investor group is fixed.
Profile B is a project conducting a broader token generation event (TGE) with public participation across multiple jurisdictions. The documentation requirement expands significantly: a full classification analysis, a whitepaper reviewed for legal consistency, jurisdiction-specific eligibility assessments (EU under MiCA, US exclusion mechanics, sanctions screening), a principal agreement and any applicable schedules for different purchaser categories, and a KYC/AML process that operationalises the agreement's restrictions. Timeline is longer and depends on the complexity of the token structure and the number of jurisdictions covered. The key risk at this profile level is the gap between the commercial launch schedule and the legal completion timeline.
Profile C is a project that has already published a whitepaper and is now seeking to formalise the agreement retrospectively. This is the highest-risk profile and requires a legal audit of prior public statements before any agreement is drafted. We assess existing representations for consistency, identify the classification footprint created by prior disclosures, and draft an agreement that addresses the legal situation as it actually exists – not as the issuer wishes it had been structured.
Related at OBOLUS
- Token offerings and securities law for digital-asset businesses – our full practice overview for token issuers across jurisdictions
- Exchange listing legal counsel – the structuring angle – how listing agreements interact with token classification and issuer obligations
- Crypto exchange setup in Luxembourg – a comparative view of exchange licensing under a MiCA-aligned EU regime
FAQ
Is my token a security?
Whether a token is a security depends on the rights it confers in substance, not its label. The FSRA applies a substance-over-form test, assessing profit participation, governance rights, and claims on the issuer's assets. ESMA under MiCA and the SFC in Hong Kong apply comparable logic. A token that grants only software access, with no financial or governance rights, is less likely to be classified as a security – but that analysis must be documented formally before any offering commences, and it should be revisited if the token mechanics change.
Do I need a MiCA whitepaper?
An ADGM-based issuer conducting a public offering that reaches EU or EEA purchasers must comply with MiCA's whitepaper requirements. MiCA applies based on where purchasers are located, not where the issuer is domiciled. If your offering is genuinely restricted to non-EU purchasers, a MiCA whitepaper may not be required – but that restriction must be enforceable through the agreement and the KYC process, not merely stated. If there is any doubt about whether EU persons will participate, the safer approach is to prepare a MiCA-compliant document from the outset.
How should an airdrop be structured legally?
An airdrop – the gratuitous distribution of tokens to a defined or open class of recipients – is not automatically outside the regulatory perimeter. If the tokens being distributed are investment tokens, the airdrop may still constitute a public offering in jurisdictions where recipients sit, triggering disclosure obligations. The key legal steps are: classify the token first; identify the recipient jurisdictions; assess whether any jurisdiction treats a gratuitous distribution as a regulated event; and ensure the airdrop mechanics are documented in a distribution agreement or terms of participation that address eligibility and exclusion. Recipient jurisdiction analysis is the step most commonly skipped.
About OBOLUS. OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise token issuers, exchanges, custodians and funds on structuring and licensing across more than 70 jurisdictions, on disputes and on-chain asset recovery across more than 25 forums, and on the tax, banking and compliance considerations that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights conferred, not the marketing label – and we design agreements to reflect that analysis at every level, from ADGM to the purchaser's home jurisdiction. To discuss your token sale structure, contact info@oboluslaw.com or reach us via t.me/oboluslaw.
By Roman Levitt, Technology & DeFi Counsel – specialising in token classification, smart-contract legal analysis, and cross-border token offering documentation across the ADGM and major international regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.