The European Securities and Markets Authority has proposed extending MiCA oversight to the businesses that connect customers to decentralized finance protocols, while stopping short of trying to regulate the protocols’ code or permissionless networks directly. The approach would create a new regulated crypto-asset service category for firms that provide access through interfaces, transaction routing, or similar customer-facing tools.

In its response to the MiCA review, ESMA also argued that the current exemption for decentralized finance should be tightened. The watchdog is asking for clearer tests to distinguish systems that are genuinely decentralized from arrangements that still depend on ongoing human input or control.

Focus on gateways rather than software

ESMA’s proposal centers on the access points most users rely on to reach DeFi services. That includes intermediaries such as exchanges, wallet applications, and other firms that present interfaces or route transactions to underlying protocols.

The regulator’s position is that these gateways are a more practical target for supervision than the underlying software itself. By concentrating on the firms that stand between users and protocols, MiCA could be applied without attempting to police decentralized code directly.

Narrowing the DeFi exemption

A key part of ESMA’s submission is its call to narrow the DeFi exemption so it does not weaken the broader MiCA framework. The authority wants more explicit criteria for deciding when a protocol can truly be treated as decentralized and when it should be considered dependent on people or identifiable groups.

That distinction remains difficult in practice. Some protocols may appear decentralized on the surface while still being shaped or maintained by a relatively small group with meaningful influence over operations or development.

Disclosure, marketing and enforcement proposals

Beyond access-point licensing, ESMA outlined several areas where it wants tougher or clearer rules. These include stricter oversight of influencer and third-party marketing, better disclosure of costs, and proportionate requirements for services tied to staking, borrowing, and lending.

The authority also called for regulation of DeFi lending practices and greater consistency in how tokens are classified. In enforcement, ESMA said it wants broader powers to take down fraudulent websites, seize cryptoassets linked to market manipulation or illicit activity, act against unauthorized foreign entities, and restrict exchanges involving stablecoins that do not meet compliance requirements.

Background and possible implications

A 2025 ESMA-EB A report described DeFi as still representing a modest share of the global crypto market. That report identified application interfaces, self-custody wallets, and centralized platforms as the main routes through which users reach DeFi services, helping explain why ESMA is focusing on those gateways in its latest review response.

The broader market impact may be limited, since regulatory announcements often affect particular tokens or business models more than the entire crypto market. Even so, the proposal fits a wider European regulatory trend under MiCA and could matter for firms operating across borders, as tighter rules on user access points may add compliance obligations for companies serving multiple jurisdictions.

The next confirmed step is ESMA’s MiCA review response itself, which sets out the agency’s recommendations. If policymakers take up those proposals, firms offering customer access to DeFi in Europe could face a more clearly defined licensing and compliance framework.

Source: Cryptopolitan