Token legal classification is the foundational question in any digital-asset product build, and getting it wrong converts a compliant launch into an unregistered securities offering. Regulated entities – exchanges, custodians, licensed payment institutions, fund managers – face an additional layer of exposure: a mis-classified token in their product suite can trigger enforcement across every jurisdiction in which they hold a licence. As regimes from MiCA to VARA to the SFC's VASP licensing regime converge on substance-over-label analysis, the marketing copy on a whitepaper settles nothing.
The operative legal question is not what a token is called. It is what rights the token confers – and on that question, regulators across the EU, the UAE, Singapore, Hong Kong, Switzerland and the UK have each developed distinct analytical frameworks that can produce different answers on the same instrument. This page maps that analysis for regulated entities that need a defensible, multi-jurisdictional classification position before they move.
Why Token Classification Is Not a One-Time Question
Classification is a continuous legal assessment, not a label applied at launch and left in place. Tokens evolve: governance rights are added, staking mechanics are introduced, value accrual features are built into the protocol. Each change can shift the classification outcome, and regulated entities bear the compliance cost of every reclassification event. In our practice, we see the most acute risk at two moments – the initial design stage, when product teams are still building features, and a secondary issuance or airdrop, when the instrument is redistributed to a new population without a fresh legal assessment.
A secondary trigger that many operators miss is jurisdictional scope creep. A token classified as a utility instrument under one regime may meet the definition of a transferable security – or, under MiCA, an asset-referenced token (ART) – in a different member state or third country, particularly where it carries any form of price-stabilisation mechanism or yields a return linked to an underlying asset. Regulated entities operating across borders carry that exposure in every market their users access.
The process above describes the standard path. Your facts – the entity type, the user base, the token mechanics and the jurisdictions in which you hold licences – change the analysis. For a scoped classification assessment tailored to your product, contact OBOLUS at info@oboluslaw.com or map your options here.
What Legal Regimes Govern Token Classification?
MiCA – the EU's Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities – is now the reference point for classification in any EU or EEA distribution. It creates three primary categories: e-money tokens (EMTs), which reference a single fiat currency; asset-referenced tokens (ARTs), which reference any other value or basket; and a residual "other crypto-assets" category that carries lighter obligations. Tokens that qualify as financial instruments under MiFID II fall outside MiCA entirely and into existing securities law – a boundary that regulators are scrutinising with growing attention.
Outside the EU, the analytical tools differ materially. VARA in Dubai applies activity-based regulation rather than a token-taxonomy statute, meaning the classification question is bound up with whether the activity in question – exchange, custody, lending – is licensed. The SFC in Hong Kong applies a securities-analysis test centred on whether token holders have rights analogous to shares, debentures or collective investment scheme units. FINMA in Switzerland uses its own three-category taxonomy – payment, utility and asset tokens – while the FCA in the UK runs a separate financial-promotion-compliance layer that applies regardless of the underlying classification outcome. Singapore's MAS, under the Payment Services Act, focuses its classification on whether a token functions as a digital payment token (DPT), with securities analysis running in parallel under the Securities and Futures Act.
The practical consequence for a regulated entity is that a single token can require parallel classification opinions covering each regime in which it is offered or traded. A token that clears the MiCA "other crypto-assets" category may still meet Singapore's DPT definition, VARA's transfer/settlement activity scope and the FCA's financial-promotion regime simultaneously. None of those analyses cancels the others.
How the Classification Analysis Actually Works
The starting point is always the rights the token confers in law – not the rights the whitepaper describes, not the marketing intent of the team. Regulators across jurisdictions have converged on a functional test: what can a holder actually do with this instrument, and does that function map to a regulated category? ESMA guidance under MiCA, FINMA's token taxonomy and the SFC's analytical framework each ask variants of the same question. The label is evidence; it is not the answer.
In practice, the analysis runs along four axes. First, value referencing: does the token track or stabilise against another asset? Any affirmative answer raises ART or EMT classification risk under MiCA, and similar concerns under FINMA's asset-token category. Second, profit expectations: do holders have a reasonable expectation of profit derived from the efforts of others? That formulation – familiar from US securities analysis – maps onto the "investment contract" concept that regulators in multiple common-law jurisdictions apply by analogy. Third, governance rights: are they voting rights over a commercial enterprise, or are they protocol-level participation rights with no direct economic claim? The distinction matters, but it is rarely clean. Fourth, transferability and secondary-market design: a token engineered to trade on a secondary market against fiat currency attracts closer securities scrutiny than one restricted to in-protocol use.
For regulated entities, the analysis does not stop at the token. The entity's existing licence creates a compliance perimeter. If a licensed exchange lists a token that is later determined to be a security, the exchange may be operating a securities venue without the appropriate authorisation. If a licensed custodian holds an ART on behalf of clients, reserve and safeguarding obligations attach. The classification position of the token and the compliance position of the entity are interdependent.
What Does a MiCA Whitepaper Obligation Require of a Regulated Entity?
Under MiCA, a whitepaper is a mandated pre-issuance disclosure document, not a marketing brochure. For issuers of ARTs, the whitepaper must be reviewed by the issuer's competent authority before publication. For EMT issuers, a separate authorisation process applies. For "other crypto-assets" – the residual category that covers most utility-type tokens – the whitepaper requirement is lighter: notification rather than approval in most cases, but the content obligations are still substantive, covering token mechanics, rights, risks, the issuer's governance and the technical infrastructure. ESMA has published technical standards on whitepaper content that national competent authorities enforce.
The cross-border dimension matters acutely for passporting. A CASP (Crypto-Asset Service Provider) authorised in one EU member state can passport its services across the EU/EEA, but the whitepaper regime follows the token's classification. An entity that classifies its token incorrectly and submits a lighter whitepaper than the regime requires will face a compliance gap that is visible the moment a user in a second member state accesses the offering. Regulators across the EU share supervisory information; a classification position that holds in one jurisdiction can be challenged by a national competent authority in another.
What Are the Most Common Classification Mistakes Regulated Entities Make?
A recurring error in our practice is the assumption that a utility label in a whitepaper insulates the issuer from securities analysis. It does not. A token may be described as granting access to a software service; if it also accrues in value by reference to platform growth, yields a staking return and is freely tradeable on a secondary market, the substantive rights analysis will treat that accumulation of features as a composite instrument that may satisfy the definition of a financial instrument or an ART regardless of the label. Regulators read the smart contract, not the marketing deck.
A second common error is treating classification as a domestic question. Operators we advise routinely discover that a token they classified for EU distribution purposes also requires a parallel analysis under the MAS regime in Singapore because their marketing reached Singaporean users, or under VARA because their Dubai entity lists it as an accessible product. Classification has a jurisdictional footprint that expands with each market in which the token is accessible.
A third mistake is failing to reassess after a material protocol change. A governance token that begins as a pure voting instrument acquires a different legal profile once the protocol introduces staking rewards, yield mechanisms or fee-sharing. The original classification opinion does not travel forward through those changes. Regulated entities with ongoing compliance obligations need a review trigger built into their product change-management process.
Decision Matrix: Which Entity Profile Requires Which Classification Process?
The appropriate classification process varies by entity type, distribution scope and token mechanics. Three profiles capture most of the regulated-entity population.
Profile A – Licensed exchange listing a third-party token. The exchange does not issue the token; it assesses it for listing. The process is an internal classification review against the regimes applicable in each jurisdiction where the exchange is licensed. The exchange needs a defensible documented position that the token is not a security (or, if it is, that the exchange holds the appropriate securities-venue authorisation). Timeline: a focused review typically concludes in a matter of weeks for straightforward instruments; complex multi-jurisdictional tokens take longer. Key risk: enforcement exposure if a token listed as a utility instrument is subsequently found to be a financial instrument under the applicable regime.
Profile B – Licensed payment institution issuing a token ancillary to its payment service. The institution is both issuer and regulated entity. The process requires a full classification analysis, a determination of whether the token qualifies as an EMT under MiCA (if EU-based) or an equivalent category in the applicable regime, and a whitepaper filed with the competent authority. Timeline depends on whether ART/EMT authorisation is required. Key risk: the token may attract reserve and safeguarding obligations that the institution's existing capital structure does not accommodate.
Profile C – Fund manager structuring a tokenised fund interest. The token represents an interest in a collective investment scheme or an equivalent structure. In most flagship regimes – MiCA, the SFC framework, FINMA guidance – that instrument falls outside the crypto-assets regime entirely and is governed by securities or funds law. The classification process is an assessment of whether fund-interest characterisation applies and what that requires from a securities-registration or private-placement perspective. Key risk: inadvertent public offering obligations in each jurisdiction where investors are based.
How Does the Cross-Border Classification Stack Work in Practice?
For a regulated entity operating in more than one jurisdiction, the classification exercise produces a stacked set of positions – one per applicable regime – that must be consistent with each other or explicitly reconciled. Where they diverge, the entity must decide how to structure its offering to avoid triggering the most restrictive outcome in any single market, or it must obtain the authorisation that the most restrictive regime requires and rely on that to anchor the rest.
In our cross-border practice, the most common structuring approach involves a primary classification analysis in the entity's home-licence jurisdiction – often an EU member state under MiCA, or Singapore under the Payment Services Act – followed by a secondary analysis covering the key distribution markets: the UAE, the UK and Hong Kong are the markets we assess most frequently alongside EU passporting questions. Allied counsel in the relevant jurisdiction provide the market-specific analysis; we coordinate the consolidated position and the resulting disclosure architecture.
A practical constraint that often surprises operators is the banking dimension. Banks that service regulated entities in multiple jurisdictions are increasingly conducting their own token classification review before allowing accounts to be used for token-related flows. A classification position that has not been formalized and documented creates friction at the banking layer even if it has been informally discussed with a regulator. We recommend that any classification opinion produced for a regulated entity be documented to a standard that a correspondent bank's compliance team can review.
In a recent matter, a licensed payment institution sought to issue a token ancillary to a cross-border payment product accessible in three EU member states and Singapore. The token mechanics included a yield feature that had been added late in the product-design cycle. Our analysis identified that the yield feature, in combination with secondary-market listing, created ART classification risk under MiCA and a potential collective investment scheme issue under the MAS regime. We restructured the yield mechanics before launch to maintain the "other crypto-assets" classification in the EU and the DPT characterisation in Singapore, and produced a coordinated whitepaper and disclosure package that satisfied both regimes. The launch proceeded without regulatory challenge.
If your classification position has never been stress-tested against the banking layer or against a secondary distribution market, a focused review can identify the gap before it surfaces in an enforcement context. Write to info@oboluslaw.com or map your options here.
How Should an Airdrop or Secondary Distribution Be Structured Legally?
An airdrop is a distribution of tokens – typically without consideration – to a defined population of wallet addresses or protocol participants. The absence of consideration does not remove the classification question; it changes one variable in the analysis. If the airdropped token is a security or an ART, distributing it without consideration still constitutes an offering of a regulated instrument in the jurisdictions where recipients are based. The regulatory exposure is to each recipient's home jurisdiction, not the issuer's jurisdiction alone.
The legal structuring of an airdrop for a regulated entity involves four components. First, a prior classification opinion covering the instrument in each major distribution jurisdiction – any jurisdiction where more than a de-minimis number of recipients are anticipated. Second, a recipient eligibility filter: regulated entities should geo-block or otherwise restrict distributions to jurisdictions where the token cannot be lawfully distributed without prior authorisation. Third, a transfer-restriction mechanism where required by the applicable regime – in some cases, the airdropped token should carry a technical lock-up that prevents immediate secondary trading until any required holding period or registration condition is satisfied. Fourth, documentation: a short-form disclosure document, or a whitepaper if required, that satisfies the applicable regime's content standards even for a non-consideration distribution.
Airdrop structuring for regulated entities is not a simplified version of the standard token-offering process. In some respects it is more demanding, because the distributing entity cannot rely on a subscription process or a purchaser's accreditation to filter the recipient population. The compliance burden falls entirely on the issuer's pre-distribution design.
A Common Assumption: The Utility Label Settles the Classification
A common assumption among product teams – and, candidly, among some legal advisers who work primarily in the technology sector – is that designating a token as a "utility token" in the whitepaper creates a regulatory safe harbour. It does not. No major regime grants legal weight to a self-applied label. MiCA, FINMA's guidance, the SFC's analytical framework and the FCA's approach each require a substantive analysis of the rights the token actually confers. A token described as a utility instrument but structured to yield a return, to appreciate in value by reference to platform performance, or to carry transferable governance rights over a commercial enterprise will be assessed on those substantive characteristics.
The practical risk for a regulated entity is compounded by the interaction between the classification outcome and the entity's existing licence. An entity that relies on a utility label and distributes what is, in substance, a financial instrument may find that its regulatory clearance is contingent on a classification position that its regulator does not share. Enforcement in that scenario can jeopardise not only the token product but the entity's existing permissions. We assess classification against the substance of rights conferred, not the marketing label – and we document the analysis to a standard that can withstand regulatory scrutiny across the applicable regimes.
Related at OBOLUS
- Token Offerings & Securities – Practice Overview – how OBOLUS structures token-offering mandates across regimes and forums
- Stablecoin Issuance Authorisation in Estonia – MiCA EMT and ART authorisation in an EU member state with an active digital-asset regime
- Token Legal Classification for Early-Stage Founders – the classification process for pre-revenue token projects before the regulated-entity layer applies
FAQ
Is my token a security?
The answer depends on the rights the token confers in substance – not its label. The relevant test varies by jurisdiction: MiCA applies a financial-instruments analysis under MiFID II; FINMA uses its own token taxonomy; the SFC in Hong Kong and MAS in Singapore apply securities-law frameworks that focus on the economic rights of holders. A token that yields a return, tracks an asset's value or confers rights analogous to shares or collective-investment-scheme units is at material risk of securities classification in one or more jurisdictions, regardless of how it is marketed. A formal classification opinion, documented against the applicable regimes, is the only defensible basis for a distribution decision.
Do I need a MiCA whitepaper?
If you are offering crypto-assets to the public in the EU or EEA, a whitepaper is generally required under MiCA, with the content and notification or approval requirements varying by token category. ART issuers must have their whitepaper reviewed and approved by their home-state competent authority before publication; EMT issuers are subject to a separate authorisation regime. "Other crypto-assets" issuers must notify their competent authority and comply with prescribed content standards. Exemptions apply for certain private placements and professional-investor-only offerings, but these are specific and their scope is defined by the applicable provisions – relying on an exemption without documented legal analysis is not advisable for a regulated entity.
How should an airdrop be structured legally?
An airdrop requires the same classification analysis as any other token distribution, because the absence of consideration does not remove the regulatory characterisation of the instrument. For regulated entities, a compliant airdrop structure requires a prior classification opinion covering each major distribution jurisdiction, a geo-blocking or eligibility filter to exclude jurisdictions where the token cannot be lawfully distributed, and a disclosure document satisfying the applicable regime's content standards. Transfer restrictions should be considered where the classification outcome requires a holding period or registration condition before secondary trading. The design work happens before distribution, not after.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess classification against the substance of rights conferred – not the marketing label – and document the analysis to a standard that withstands regulatory scrutiny across the applicable regimes. To discuss your situation, contact info@oboluslaw.com.
By Roman Levitt, Technology & DeFi Counsel – specialising in token classification, smart-contract legal analysis and the interaction between protocol design and multi-jurisdictional securities law.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.