On paper, wrapping a DAO (decentralized autonomous organization) in a legal entity looks like a single filing. In practice, a founder who underestimates that step can convert a community treasury into an unregistered securities offering, expose core contributors to unlimited personal liability, and shut the protocol out of every regulated banking relationship it needs to survive. The regulatory question is not academic. It is the difference between a fundable project and a compliance emergency.
A DAO legal wrapper – the off-chain legal entity that holds a DAO's assets, signs contracts, employs contributors, and interfaces with regulators – is the foundational instrument for any early-stage team building in DeFi, tokenization or smart-contract infrastructure. Choosing the right wrapper turns on the protocol's token model, its user geography, the governance structure, and where the team intends to bank. Get those four variables right and the wrapper holds. Get them wrong and no amount of retroactive restructuring fully repairs the damage.
This page maps the decision logic: which entities work, which jurisdictions support them, how the process runs, and where early-stage founders consistently make costly errors.
Why a legal wrapper is not optional for a DAO
An unwrapped DAO is, in most common-law and civil-law systems, a general partnership by default – meaning every token holder with governance rights may be jointly and severally liable for the protocol's obligations. That result is rarely what founders intend, and it is the first consequence regulators and claimants reach for when a protocol causes a loss. Under the applicable provisions of the laws governing unincorporated associations across major jurisdictions, there is no statutory shield protecting members from personal liability unless a recognized legal form has been deliberately adopted.
Beyond liability, an unwrapped DAO cannot open a bank account, hold intellectual property, enter employment contracts, accept investment through a recognized instrument, or respond to a regulatory inquiry with legal standing. Each of those gaps compounds over time. By the time a Series A investor or a regulated exchange partnership requires a clean legal structure, retrofitting is expensive and sometimes impossible without resetting the token distribution entirely.
The cross-border dimension sharpens the risk further. A DAO with contributors in three jurisdictions, users across five more, and a treasury denominated in stablecoins may simultaneously engage the laws of each of those countries. The wrapper must address not just where the entity sits, but where governance is exercised and where economic benefit flows – because those are the hooks that regulators use.
Under the FATF Recommendations, including the obligations on virtual asset service providers, DAOs that exercise sufficient control over a protocol may themselves be characterized as VASPs (virtual asset service providers) subject to AML/CFT (anti-money laundering and counter-financing of terrorism) obligations. That analysis is fact-specific, but the trend across leading regulators – ESMA, MAS, the FCA and VARA – is toward substance-over-form classification. A wrapper that was designed to hold a treasury without triggering licensing may nonetheless do so if the protocol's actual functions are intermediary in nature.
Token classification comes before entity selection
No wrapper decision is sound without first resolving how the protocol's token is classified under the laws of the jurisdictions that matter to the project. A common assumption among early-stage founders is that a utility label on a whitepaper settles the legal classification. It does not. Regulators and courts assess token rights by their substance – what economic entitlements they carry, whether they represent a share of profit or a governance stake that functions like equity, and whether their distribution involved a promise of return from the efforts of others.
Under MiCA (the EU's Markets in Crypto-Assets Regulation), tokens are assessed against the definitions for asset-referenced tokens, e-money tokens and other crypto-assets, with each category attracting different obligations on the issuer. A token that is described as a governance instrument but that carries redemption rights or is marketed with expected appreciation will attract scrutiny against the ART and EMT definitions. The same token, distributed to US persons, may engage the SEC's longstanding investment-contract analysis.
In our practice, we assess classification against the substance of the rights conferred by the token – not the marketing label. That analysis drives the wrapper choice: a token that is clearly a security in the EU and the US requires a different entity structure, a different jurisdiction, and a different offering mechanics than a pure utility instrument that does not carry investment-return expectations.
The cross-border complexity here is material. MiCA applies to tokens offered to EU persons regardless of where the issuer is domiciled. MAS's Payment Services Act regime and the SFC's VASP licensing regime in Hong Kong each apply their own classification logic. An early-stage founder who launches globally without resolving this analysis in each material jurisdiction is building on an unstable base.
For a scoped token classification analysis before you commit to an entity structure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your token design, your user base, and your distribution mechanics will change the analysis and may change the wrapper entirely.
What legal wrapper suits a DAO? The main options mapped
Four entity forms dominate the market for DAO legal wrappers, each with a distinct profile suited to different protocol architectures and team situations.
The Marshall Islands DAO LLC is a purpose-built entity form that explicitly recognizes DAOs as a legal structure and allows on-chain governance to be referenced in the constitutional documents. It provides member liability protection, can hold assets and sign contracts, and is tax-neutral for non-resident members. It works best for protocols that want a lightweight, jurisdiction-neutral vehicle and that do not require a local regulatory touch point. The limitation is banking: established correspondent banks do not yet treat Marshall Islands DAOs with the same confidence as Cayman or BVI entities, so treasury management can be constrained.
The Cayman Islands Foundation Company is the structure of choice for protocols that intend to raise capital from institutional investors or that need a vehicle recognized by prime brokers and regulated custodians. CIMA and the Cayman Virtual Asset Service Providers Act govern crypto activity in the jurisdiction, and a foundation company can be structured with a purpose-based constitutional mandate, no members (preventing equity claims), and an independent supervisor. The governance structure maps well onto DAO mechanics. The cost of formation and annual maintenance is higher than lighter vehicles, but institutional capital expects it.
The BVI Company, governed by the BVI Financial Services Commission under the BVI VASP Act 2022, is the workhorse structure for projects that need speed, flexibility and a common-law environment at reasonable cost. It holds assets cleanly, can issue tokens as instruments of the company, and is widely accepted by exchanges and OTC desks for KYC purposes. For protocols that need to wrap quickly before a token launch, a BVI company is frequently the fastest credible option.
The Swiss Association (Verein), overseen ultimately by FINMA for regulated activities, is well-suited to protocols with a strong community-governance ethos and a non-profit or protocol-development mandate. Several major DeFi protocols have used the Swiss association as the legal home for a foundation that holds intellectual property and oversees the protocol's development fund. FINMA's token taxonomy – distinguishing payment, utility and asset tokens – gives a structured framework for the token analysis. The association structure does not work well when the protocol needs to employ a large contributor team directly or manage investor relationships in a conventional equity sense.
Beyond these four, the AIFC in Kazakhstan (overseen by the AFSA) and the ADGM in Abu Dhabi (overseen by the FSRA) are increasingly used by teams that want a regulated environment in a cost-competitive jurisdiction, particularly where the founder team is based in those regions.
How does the DAO wrapper process actually run?
The wrapper engagement has five sequential phases, and compressing them is the most consistent mistake founders make.
Phase one is the classification and scoping analysis. Before any filing, the legal team maps the token's rights, the protocol's functions, the governance mechanics and the contributor structure against the regulatory tests in each material jurisdiction. This is not a legal opinion on the token alone – it is a combined view on the entity, the token and the AML/VASP trigger. It typically runs over a period of weeks and produces a written memo that the founders can use in investor conversations and regulatory submissions. Skipping it or compressing it produces a wrapper that is correctly formed but structurally misaligned.
Phase two is jurisdiction selection and entity design. The classification output directly determines the shortlist of viable jurisdictions. The entity design covers the constitutional documents, the governance bridge between on-chain voting and off-chain legal authority, the token issuance mechanics, the IP assignment and the contributor framework. In a BVI or Cayman structure, this phase includes drafting the memorandum and articles, the foundation charter, or the purpose deed.
Phase three is formation and registration. In a Cayman foundation structure, this involves instructing local Cayman counsel – through allied counsel in the relevant jurisdiction – to register the company, appoint the supervisor and file the constitutional documents. In a BVI structure, formation can move quickly once the documents are complete. Swiss association registration with the cantonal authority takes longer, particularly if a bank account is needed concurrently.
Phase four is banking and treasury setup. This is frequently the longest phase and the one most underestimated. A DAO wrapper that cannot open a bank account or a business account with a regulated stablecoin custodian is functionally incomplete. The banking analysis depends on the entity type, the jurisdiction, the protocol's AML/CFT posture, the nature of the tokens it holds, and whether it has a regulated activity classification. We regularly advise on the combination of a primary bank account, a regulated custodian relationship and a stablecoin treasury arrangement that together provide adequate operational redundancy.
Phase five is ongoing compliance: the annual filing and supervision obligations, the AML/CFT program, the Travel Rule posture for any transfer functions, and the governance documentation that keeps the off-chain entity synchronized with on-chain votes. This phase is frequently neglected after formation, with the result that the wrapper drifts out of compliance with its own constitutional mandate.
What are the most common structuring mistakes early-stage DAOs make?
Five patterns recur with enough frequency that they constitute a predictable risk map for early-stage DeFi founders.
The first is selecting a jurisdiction based on speed rather than fit. A Marshall Islands DAO LLC can be formed quickly, but if the protocol's primary investor base is EU-regulated funds that require a Cayman or BVI entity for their own fund documents, the fast wrapper creates a rework cycle that costs more in time and money than the slower structure would have.
The second is failing to bridge on-chain governance and off-chain legal authority. If a DAO votes on-chain to deploy treasury funds but the off-chain entity's authorized signatories are not bound by that vote, the legal wrapper is cosmetic. We have seen disputes arise between the on-chain community and the legal entity's directors precisely because the constitutional documents did not replicate the governance mechanism with legal force.
The third is treating the AML/CFT program as a post-formation task. By the time the protocol is live and processing transactions, the AML program needs to be operational. Regulators applying the FATF Recommendations expect VASPs – and entities that may be characterized as VASPs – to have a program in place before they begin operating, not after.
The fourth is ignoring the tax residency of the entity and its key decision-makers. An entity formed in the Cayman Islands but managed by founders physically located in Germany, France or the UK may be treated as resident in those jurisdictions for tax purposes under their controlled foreign company rules, eliminating the offshore tax benefit entirely.
The fifth – and most consequential – is launching a token without resolving its classification in each material jurisdiction. A token that is a utility instrument in Switzerland may be an unregistered security in the US if distributed to US persons through a public launch. MiCA's whitepaper notification and disclosure obligations apply from the date of offer, not from the date of regulatory inquiry. We assess token classification before the issuance mechanics are finalised, not after a regulator has written a letter.
Cross-border decision matrix: which profile needs which structure
The right wrapper depends on the protocol's profile across four variables: the token classification, the investor base, the contributor geography and the banking target. The following profiles map the most common early-stage scenarios.
Profile A – Governance token, institutional-capital target, global user base. This profile calls for a Cayman Foundation Company as the primary wrapper. The Cayman entity is recognized by institutional LPs and their fund counsel, provides a clean non-equity structure that prevents governance tokens from being re-characterized as shares, and has a well-developed supervisory framework under CIMA. The timeline from instruction to first formation filing is typically a matter of weeks; banking setup adds further time. The key risk is that the foundation's supervisor must be genuinely independent – a governance-in-name-only supervisor is the first thing a sophisticated investor's counsel will challenge.
Profile B – Protocol utility token, seed-stage team, EU user concentration. A BVI company provides the fastest credible formation, with an AML/CFT program aligned to the BVI VASP Act 2022 requirements. The parallel task is the MiCA whitepaper analysis, because an offer to EU persons triggers the applicable disclosure and notification regime regardless of where the issuer is incorporated. A BVI entity does not carry a MiCA passport – it does not confer the right to operate within the EU without further steps – but it provides a clean legal base from which to manage the EU relationship through a notified whitepaper or, ultimately, a CASP authorization in a member state.
Profile C – DeFi protocol with no token yet, contributor-focused build phase. A Swiss association or a Cayman foundation works well here, with the Swiss option preferred where the team has a European presence and wants FINMA's token taxonomy as the analytical backdrop for future token design. The association holds the IP and the development grant, and it can employ contributors under Swiss employment law. FINMA does not regulate the association unless it performs regulated activities. The timeline risk is Swiss banking – opening an account for a crypto-adjacent association requires careful preparation of the AML/CFT documentation.
Profile D – Regional protocol targeting MENA users, team in Dubai or Abu Dhabi. VARA in Dubai or the FSRA within ADGM in Abu Dhabi provides a regulated environment with a local licensing pathway. For a team already operating in the UAE, the regulatory touch point is local, the banking environment is accessible, and the DIFC Courts provide a strong dispute resolution forum backed by a developed body of commercial law. The wrapper here is likely a VARA-licensed or FSRA-regulated entity, and the structuring analysis focuses on which VARA activity licence applies to the protocol's actual functions.
If a prior application stalled or a banking relationship was refused, a structural review can often identify the specific mismatch – between the entity type, the AML/CFT documentation and the banking target – and map the corrective path. To pressure-test your structure before you commit, message us via t.me/oboluslaw.
A recent structuring matter
In a recent engagement, a DeFi protocol team – three founders building a tokenized credit infrastructure product – came to us after formation of a Marshall Islands DAO LLC, having discovered that their lead investor required a Cayman structure for the fund's own subscription documents. The on-chain governance mechanism had already been live for several months, and a token distribution to early contributors had occurred under the Marshall Islands entity. We advised on a restructuring path that placed a new Cayman Foundation Company above the existing DAO LLC, mapped the prior token distribution against the applicable MiCA and BVI VASP Act frameworks to confirm no registration trigger had been missed, and drafted a governance bridge document that gave the Cayman foundation's supervisory board binding authority over treasury deployments authorized by on-chain votes. Banking was established through a combination of an EMI account and a regulated custodian for the stablecoin treasury. The investor's counsel accepted the restructured arrangement and the financing closed.
Who is liable when a smart contract fails?
Smart-contract failure liability is one of the least-settled questions in DeFi law, and the answer the legal wrapper provides is practical, not theoretical. Without a wrapper, a plaintiff seeking recovery after a contract exploit, a pricing-oracle failure or a governance attack has no identified defendant with legal standing – so they pursue the developers as individuals. With a properly structured wrapper, the entity is the counterparty to users, the holder of the IP, and the party against whom claims run in contract or tort.
The cross-border dimension matters acutely here. An English court hearing a claim arising from a smart-contract exploit will apply conflict-of-laws principles to determine the applicable law and the proper defendant. If the protocol's legal wrapper is a Cayman foundation, English counsel instructed through the DIFC Courts or under the England and Wales jurisdiction can proceed against a known entity. If there is no wrapper, the claim must identify individuals – and the disclosure orders required to do that (such as Norwich Pharmacal orders, which compel third parties with information to disclose it) add time, cost and uncertainty to any recovery.
Under the principles established in the English courts – including the landmark recognition in AA v Persons Unknown [2019] that crypto assets are property capable of being the subject of a freezing order – a claimant can move quickly against both the wrapper entity and, where the facts support it, the developers behind a failed or exploited protocol. The wrapper does not eliminate liability; it structures it, makes it insurable, and gives the protocol a way to respond to claims without exposing contributors personally.
We have seen disputes arise from oracle manipulations, reentrancy exploits and governance-vote attacks, each with a different liability profile. The consistent pattern is that protocols with a properly documented wrapper and a clear governance record are better positioned to defend or settle those claims efficiently than unwrapped protocols facing undefined liability across multiple contributors.
Related at OBOLUS
- DeFi, Tokenization and Smart-Contract Law – the full practice overview covering DeFi legal structuring, token issuance and smart-contract advisory.
- DeFi Protocol Legal Structuring in Mauritius – jurisdiction-specific guidance on using Mauritius as a DeFi structuring hub under the VAITOS Act.
- Payment Institution Licensing Under Heightened Scrutiny – for DAO treasuries and DeFi protocols navigating payment-services regulation and banking access.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights conferred, not the marketing label – a discipline that matters when a regulator challenges a whitepaper months after launch. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums including England and Wales, the DIFC Courts, Singapore and the Cayman Islands. To discuss your DAO structure, contact info@oboluslaw.com.
FAQ
Can a DeFi protocol be regulated?
Yes. Regulators including ESMA, MAS, the FCA and VARA apply substance-over-form analysis. A DeFi protocol that performs functions equivalent to a regulated activity – custody, exchange, lending or transfer – may be classified as a VASP subject to licensing, AML/CFT and Travel Rule obligations regardless of how it describes itself. The FATF Recommendations explicitly address DeFi within the virtual asset service provider perimeter. Whether a specific protocol crosses the threshold is a fact-specific analysis that turns on the degree of control exercised by identifiable persons and the nature of the services provided to users.
What legal wrapper suits a DAO?
The right wrapper depends on the token model, the investor base, the contributor geography and the banking target. A Cayman Foundation Company suits institutional-capital protocols; a BVI company suits seed-stage builds needing speed and flexibility; a Swiss association works for IP-holding foundations with a European presence; a Marshall Islands DAO LLC is purpose-built but has banking constraints. No single form is universally correct. OBOLUS maps the four decision variables before recommending a structure, ensuring the wrapper aligns with the protocol's actual regulatory exposure rather than the founder's preferred jurisdiction.
Who is liable when a smart contract fails?
Without a legal wrapper, contributors may face personal liability as members of an unincorporated association or general partnership. With a properly structured wrapper, the entity is the counterparty to users and the party against whom claims run. English courts, the DIFC Courts and Singapore courts have each recognized crypto assets as property capable of being frozen or recovered through judicial process. A clear wrapper and governance record does not eliminate liability, but it structures and limits it, makes it insurable, and enables the protocol to respond to claims through a recognized legal person rather than exposing individual contributors.
By Roman Levitt, Technology and DeFi Counsel – specializing in DAO structuring, token classification and smart-contract legal architecture for early-stage and growth-stage DeFi protocols.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.