Back to Directory
    Legal

    DA-03 - Regulating Digital Assets in the European Union and the United Kingdom MiCA, MiFID, FSMA and the Governance Gap

    Evelyse Carvalho-Ribas6 Aug 2026

    Track Your Progress

    Sign in to earn XP, take quizzes, and unlock AI tools.

    Sign In
    Evelyse Carvalho-Ribas
    DA-03 · DIGITAL ASSETS & TOKENISATION

    Regulating Digital Assets in the European Union and the United Kingdom: MiCA, MiFID, FSMA and the Governance Gap

    MiCA · MiFID II · FSMA · Supervisory Discretion · Governance Gap

    Series
    ECR-Digital Assets Series · DA
    Author
    Evelyse Carvalho-Ribas
    Credentials
    PhD in Law, University of Leeds, School of Law, 2026
    Practice
    20+ years across EU · UK · Australia · Americas · Asia-Pacific
    Published Through
    MoroAK Professional Knowledge Infrastructure
    Year
    2026

    Evelyse Carvalho-Ribas

    PRIMARY AUTHORITY DOMAIN
    Cultural-creative tax incentives · Structural fiscal access constraints (SFACs) · Cross-border cultural-fiscal governance · National frameworks · EU internal market law · UNESCO 2005 Convention · Bilateral treaty practice.
    SECONDARY DOMAIN
    Digital and tokenised assets · National financial regulation · Supranational supervisory frameworks · International tax coordination · Technological architecture · Governance design.
    DOMAIN SYNERGIES
    Both domains are unified by the same structural problem: complexity at the intersection of national, supranational, and international legal orders — where regulatory fragmentation, administrative opacity, and institutional misalignment prevent legitimate access to legal, fiscal, and financial frameworks. In fiscal governance, this manifests as SFACs blocking cross-border access to tax incentives. In digital assets, it manifests as the absence of a coherent governance-grade framework linking legal classification, regulatory supervision, technical design, and cross-border value flows. Evelyse Carvalho-Ribas' analytical methodology — multi-relational, governance-first, jurisdiction-aware — applies with equal rigour across both.
    UNIQUE FRAMEWORK CONTRIBUTION
    Originator of the SFAC concept (Structural Fiscal Access Constraints) — the first taxonomised framework for diagnosing why cross-border tax incentives systematically fail. Creator of the CCTIM (Cultural-Creative Tax Incentive Model), a soft-governance reform architecture reducing SFACs without requiring legal harmonisation or fiscal sovereignty surrender. Creator of a governance-grade interpretative framework for digital and tokenised assets capable of linking legal classification, regulatory supervision, technical design, and cross-border value flows within a coherent analytical model.
    ACADEMIC CREDENTIAL
    PhD in Law, University of Leeds, School of Law, 2026. Thesis: “Toward a Shared Coordinate Framework for Cultural-Creative Tax Incentives.” Examined across national, bilateral, EU, and UNESCO legal frameworks. 25+ jurisdictions analysed. LLM in International Commercial and Business Law, University of East Anglia, School of Law, 2007.
    PROFESSIONAL CREDENTIAL
    Qualified Lawyer in Brazil and Portugal. Foreign Lawyer in England and Wales. 20+ year career built on the legal, tax, and regulatory architecture of two core pillars: tax incentives and digital assets & tokenisation. Working directly with national authorities, regulators, and institutions to surface legal and administrative blind spots and address misalignment between domestic regimes and international obligations. With international tax lawyers and advisers, accountants and financial advisers, policymakers and government bodies, institutions and foundations. In digital assets, active since 2015, working with founders and builders across tokenised ecosystems (L1-L3), DeFi, AI, legal and compliance teams, across real estate, agriculture, carbon, infrastructure, IP, education, health, and the arts.
    INSTITUTIONAL AFFILIATIONS & NETWORKS
    University of Leeds (PhD, School of Law) · University of East Anglia (LLM, School of Law) · IFA — International Fiscal Association · IBFD — International Bureau of Fiscal Documentation · IBA — International Bar Association · OECD tax policy and governance networks · UNESCO cultural policy and governance networks · European Film Forum · European Audiovisual Observatory · CISAC · WIPO — World Intellectual Property Organization · Digital assets and tokenisation regulatory networks (EU, UK, Lusophone markets) · MoroAK — Co-Founder & Educator Zero · Active practice across EU · UK · Australia · Americas (Canada · US · Mexico · Brazil · Chile) · Asia-Pacific (Singapore · Hong Kong · Japan).
    PUBLISHING INFRASTRUCTURE
    Published through MoroAK Professional Knowledge Infrastructure · moroak.com · All courses, cohorts, papers, and digital toolkits available through Evelyse Carvalho-Ribas' educator profile on MoroAK's platform. For advisory enquiries and mandate scoping, contact through evelyse@moroak.com.

    Abstract

    The regulation of digital assets in the European Union and the United Kingdom is often analysed primarily through legislative texts, taxonomies, and formal regulatory perimeters. While statutory frameworks have become considerably more sophisticated — notably through the Markets in Crypto-Assets Regulation (MiCA), the Markets in Financial Instruments Directive (MiFID II), and the UK’s Financial Services and Markets Act 2000 (FSMA) and its post-Brexit amendments — significant legal uncertainty persists in practice. This paper addresses a central structural source of that uncertainty: regulatory outcomes in the digital asset domain are shaped less by the formal content of legal rules than by how those rules are interpreted, prioritised, and enforced by supervisory institutions operating within multi-layer governance systems.1

    Digital asset regulation engages overlapping governance layers, including legislative design, administrative and supervisory discretion, inter-institutional coordination, and enforcement strategy. These layers interact dynamically and often asymmetrically across and within jurisdictions. As a result, similar or even functionally identical factual arrangements may produce divergent regulatory outcomes, even within broadly harmonised or convergent legal frameworks such as the EU’s single market for financial services or the UK’s FSMA-based perimeter.2

    Adopting a comparative legal and institutional approach, this paper examines how MiCA, MiFID II, and FSMA are applied by European and UK authorities, with particular attention to token and product classification, perimeter assessments, and supervisory prioritisation. Drawing on applied professional practice across multiple jurisdictions, it illustrates how authorities assess governance arrangements, economic substance, and control structures, rather than relying solely on formal legal categories or token labels. The analysis applies the Multi-Layer Governance Framework for Blockchain and Digital Assets (Carvalho-Ribas) to integrate legislative, institutional, and governance perspectives into a single interpretative architecture.3

    The practical implications of this analysis are significant for advanced professional audiences. For legal and tax advisers, it highlights the limits of text-based interpretation detached from governance and economic substance. For regulators and supervisory authorities, it offers a structured lens through which institutional practice, prioritisation choices, and cross-border coordination can be assessed and compared. For policymakers, it underscores the importance of aligning legislative design with the operational realities of supervision and enforcement. The paper is intended for an advanced, non-introductory audience, including lawyers, tax advisers, regulators, supervisory authorities, policy designers, and senior compliance officers engaged in the regulation, supervision, or governance of digital asset systems across the EU and UK.


    MiCA · MiFID II · FSMA · Digital Assets · Regulatory Interpretation · Supervisory Discretion · Governance Gap · Enforcement Logic · Perimeter Assessment · ESMA · FCA · BaFin · NCA Coordination · Multi-Layer Governance

    Carvalho-Ribas, Evelyse. ‘Regulating Digital Assets in the European Union and the United Kingdom: MiCA, MiFID, FSMA and the Governance Gap’. DA-03. ECR-Digital Assets Series. Published through MoroAK Professional Knowledge Infrastructure, 2026. Available at moroak.com.

    Definitions

    This section establishes the operative definitions used throughout the paper to anchor regulatory interpretation within a coherent analytical framework, ensure continuity with preceding papers in this series, and prevent mischaracterisation of the analysis as compliance guidance, licensing instruction, or jurisdiction-specific regulatory advice. The definitions adopted are functional, governance-oriented, deliberately system-neutral, and designed for comparative institutional analysis across jurisdictions.4

    Regulatory Interpretation
    The process through which supervisory authorities, regulators, and enforcement bodies attribute legal meaning to legislative provisions when applying them to concrete factual situations within their competence. This process extends beyond textual exegesis to encompass institutional mandate, policy objectives, risk appetite, resource constraints, supervisory capacity, and enforcement strategy. Regulatory interpretation is therefore fundamentally an administrative and governance activity situated at the intersection of law and institutional practice, rather than a purely doctrinal exercise.5
    Supervisory Discretion
    The legally and institutionally conferred capacity of regulatory authorities to prioritise, sequence, and calibrate regulatory action within the boundaries of their statutory mandate and public law principles. Discretion manifests in decisions concerning scope interpretation, enforcement focus and sequencing, supervisory engagement intensity, transitional arrangements, and tolerance thresholds for uncertainty. In digital asset regulation, discretion assumes structural significance due to the novelty, complexity, cross-border character, and rapid evolution of regulated systems, as recognised in both EU administrative law principles and UK public law jurisprudence governing regulatory decision-making.6
    Governance Gap
    The structural divergence between legislative design ambition and supervisory reality, where formal regulatory frameworks do not fully capture or accommodate the governance structures, economic incentives, control dynamics, and operational realities of blockchain and Web3 systems. The governance gap is not merely a drafting defect or transitional friction; it emerges from the dynamic interaction between multi-layer systems and supervisory institutions operating under constraints of mandate boundaries, expertise limitations, inter-institutional coordination challenges, and resource allocation pressures.
    Legislative Framework
    The body of enacted legal instruments — regulations, directives, and statutes — that formally define regulatory scope, obligations, exemptions, and enforcement powers. In the EU and UK contexts, key frameworks include Regulation (EU) 2023/1114 (MiCA), Directive 2014/65/EU (MiFID II), and the Financial Services and Markets Act 2000 (FSMA) as amended by the Financial Services and Markets Act 2023.7 These frameworks establish the structural boundaries of regulation but do not, in themselves, determine concrete regulatory outcomes, which emerge through interpretative application by competent authorities within their institutional contexts.
    Institutional Mandate
    The legally defined objectives, competences, powers, and limitations of a regulatory or supervisory authority as established by statute, secondary legislation, or founding instruments. Mandates condition how legislation is interpreted and prioritised: authorities with investor-protection mandates (ESMA, FCA) emphasise economic substance, governance control, and user risk exposure, while those with prudential or market-integrity mandates (ECB, PRA) focus on systemic risk, operational resilience, and financial stability implications.
    Perimeter Assessment
    The interpretative process by which regulatory authorities determine whether a particular activity, product, service, or arrangement falls within their regulatory scope or triggers licensing, authorisation, or compliance obligations. This assessment is inherently factual, context-dependent, and institution-specific, relying on analysis of activities conducted, governance arrangements, economic substance, and market impact rather than self-classification, project documentation, or promotional representations alone.8
    Multi-Layer Governance
    The dynamic interaction between legal-normative, institutional-administrative, governance-decision, economic-value, technical-functional, and jurisdictional layers that collectively shape regulatory outcomes in complex digital asset systems. This definition maintains consistency with the Multi-Layer Governance Framework for Blockchain and Digital Assets (Carvalho-Ribas) developed and applied throughout this series, adapted here to emphasise institutional interpretation and supervisory practice.
    Enforcement Logic
    The patterned and strategic manner in which regulatory authorities deploy investigative, supervisory, and sanctioning powers in pursuit of their mandate and policy objectives. Enforcement logic reflects institutional considerations including deterrence effects, precedent-setting, resource allocation priorities, cross-border coordination, and signalling to market participants. It constitutes a critical dimension of regulatory interpretation, particularly in emerging domains where statutory provisions require contextual application.9
    CONCEPTUAL BOUNDARIES AND SCOPE
    This paper covers: the interpretative application of MiCA, MiFID II, and FSMA in institutional practice; the role of supervisory discretion and institutional mandate; governance-oriented analysis of regulatory outcomes and enforcement patterns; comparative institutional perspectives across EU and UK supervisory architectures; and application of the Multi-Layer Governance Framework. This paper does not cover: licensing or authorisation procedures and timelines; compliance checklists or implementation guidance; token issuance structuring, marketing strategies, or whitepaper drafting; techniques intended to achieve specific perimeter outcomes or avoid regulatory classification; jurisdiction-specific transactional advice or structuring opinions.

    Legislative Architecture vs Supervisory Reality

    MiCA, MiFID II, and FSMA represent sophisticated legislative responses to financial innovation, yet each shares a common architectural feature: reliance on interpretation, institutional judgment, and administrative discretion for practical operation. None functions as a self-executing or exhaustive rulebook. Understanding their application to digital assets therefore requires examining how legislative design interacts with supervisory reality, rather than treating statutory text as determinative of outcomes.10

    MiCA establishes a harmonised EU framework for crypto-assets and related services through directly applicable regulation, introducing common definitions (ARTs, EMTs, other crypto-assets), issuer and service provider obligations, and supervisory structures. Its architecture is deliberately layered: while core concepts and prohibitions are legislatively fixed, significant operational detail is delegated to Level 2/3 technical standards (RTS/ITS), ESMA guidelines, and national competent authority (NCA) implementation. ESMA published its first consultation package on MiCA implementing measures on 12 July 2023, covering RTS on CASP authorisation content, complaints handling, and conflicts of interest identification and prevention, followed by a second package on 5 October 2023 addressing business continuity, ICT security, and record-keeping requirements.11 MiCA’s effectiveness thus depends on coordinated supervisory interpretation across 27 Member States and ESMA.

    MiFID II, originally designed for traditional financial instruments and markets, maintains relevance to digital assets through its functional, activity-based approach that prioritises economic substance over formal labels. Its architecture assumes active supervisory judgment, particularly in perimeter questions about whether tokens constitute transferable securities under Annex I Section C, whether DeFi protocols constitute collective investment schemes, or whether token services amount to investment advice, portfolio management, or placement activities. The absence of digital asset-specific provisions does not limit MiFID’s reach; rather, it creates structured space for NCAs and ESMA to extend existing concepts to novel arrangements through guidance, Q&As, and enforcement practice.12

    FSMA provides the UK’s principles-based statutory foundation, characterised by broad perimeter concepts (“carrying on regulated activities in the UK”) and extensive rulemaking powers delegated to the Financial Conduct Authority (FCA). Post-Brexit, FSMA’s architecture has been strengthened through the Financial Services and Markets Act 2023 (Royal Assent 29 June 2023), which transferred retained EU law (including MiFID implementing measures) to FCA rulemaking while maintaining activity-based tests. Section 69 and Schedule 6 of the 2023 Act provide the mechanism for bringing crypto-related activities within the FSMA regulatory perimeter through amendments to the Regulated Activities Order (RAO).13

    Regulatory certainty cannot be derived from legislative text in isolation. Legal analysis treating MiCA, MiFID II, or FSMA as mechanically determinative — without accounting for supervisory practice, institutional incentives, and interpretative evolution — risks fundamental misapprehension of how regulation operates in reality.

    Blockchain and Web3 systems intensify reliance on supervisory judgment because they challenge the categorical assumptions of traditional legislative design. These systems integrate multiple functions — settlement infrastructure, programmable money, governance participation, investment exposure, yield generation — within unified architectures while operating across borders in territorially ambiguous ways. Legislative instruments can delineate boundaries and prohibitions, but cannot comprehensively anticipate governance models, token designs, or DeFi configurations. Supervisory authorities must therefore interpret how concepts like “transferable security,” “financial instrument,” “crypto-asset service,” or “regulated activity” apply to arrangements without direct statutory analogues.14

    Feature MiCA (EU) MiFID II (EU) FSMA (UK)
    Architecture Harmonised regulation, directly applicable; layered implementation via RTS/ITS and NCA application Functional, substance-over-form; activity-based tests applied to novel arrangements Principles-based; broad perimeter + FCA rulemaking + PERG guidance
    Interpretive locus ESMA guidelines + 27 NCAs; distributed interpretation with convergence mechanisms NCAs + ESMA Q&As; institutional judgment on transferable security / financial instrument tests FCA: single authority with broad discretion; PERG, Dear CEO letters, enforcement precedent
    Discretion embedded? Yes: NCA transitional periods (Art 143), activity-based CASP assessment, Level 2/3 delegation Yes: perimeter questions, CIS test, investment service characterisation Yes: “by way of business” test, “regulated activity” determination, innovation sandbox
    Crypto-specific? Yes (dedicated regime) No (functional extension to crypto via existing concepts) Being built: s.69 FSMA 2023 + HM Treasury secondary legislation
    Where uncertainty concentrates MiCA/MiFID boundary; NCA implementation divergence; DeFi perimeter Token as financial instrument? DeFi as CIS? Governance tokens as securities? Perimeter evolution; stablecoin regime design; SMCR application to crypto

    This paper proceeds from the premise that EU and UK digital asset regulation is co-produced by legislative architecture and institutional practice. Statutory frameworks establish formal boundaries and competences, but supervisory reality determines how those boundaries are tested, contested, and enforced through guidance, supervision, and enforcement actions.

    MiCA in Practice and MiFID Financial Instrument Spillover

    III.A — MiCA: Classification, Scope, and Supervisory Latitude

    The Markets in Crypto-Assets Regulation (MiCA) is frequently presented as a comprehensive, self-contained regulatory response to digital assets across the European Union. In practice, MiCA functions less as a prescriptive rulebook and more as a governance framework that allocates roles, priorities, and interpretative authority across multiple institutional layers — legislation, technical standards, national competent authorities (NCAs), and ESMA coordination. Its effectiveness and operational limits become visible only through supervisory application rather than legislative text alone.15

    MiCA introduces formal token categories — asset-referenced tokens (ARTs, Title III, Arts 16–47), e-money tokens (EMTs, Title IV, Arts 48–58), and other crypto-assets including utility tokens (Title II, Arts 4–15) — alongside a harmonised regime for crypto-asset service providers (CASPs, Title V). However, classification under MiCA is not a discrete, mechanical exercise. Token categories interact continuously with the nature of activities performed, governance structures, economic functions, and service models. Supervisory practice assesses token qualification and CASP obligations holistically and concurrently, rather than sequentially, reflecting MiCA’s explicit recognition that token characteristics alone do not determine the regulatory perimeter.16

    Supervisory latitude is structurally embedded in MiCA’s institutional design. The regulation establishes a distributed model where NCAs retain primary responsibility for authorisation, ongoing supervision, and enforcement, coordinated through ESMA’s oversight, peer review, and binding mediation mechanisms. This architecture accommodates market diversity and practical supervision limits while introducing interpretative variation, particularly where MiCA intersects with MiFID II, the second Payment Services Directive (PSD2), the Anti-Money Laundering Directives (AMLD5/6), or national consumer protection rules.17

    MiCA’s transitional provisions (Art 143) exemplify this latitude: Member States may grant existing crypto-asset service providers a transitional period of up to 18 months from 30 December 2024, during which they may continue operating without full CASP authorisation. The length and conditions of these transitional arrangements vary across Member States, producing a documented source of implementation divergence. France, operating its pre-existing PSAN (Prestataires de Services sur Actifs Numériques) registration under the loi PACTE (Loi n° 2019-486 du 22 mai 2019), adopted enhanced registration requirements from 1 January 2024 in anticipation of MiCA. Germany, which had introduced crypto custody licensing under the Kreditwesengesetz (KWG) since 1 January 2020, adopted a distinct transitional approach reflecting its existing supervisory infrastructure.18


    III.B — MiFID and Financial Instrument Spillover

    Despite MiCA’s introduction as a dedicated crypto-asset regime, MiFID II remains a central reference point in the EU regulatory landscape for digital assets. Its continued relevance reflects not regulatory inertia, but the structural limits of asset-specific legislation when confronted with blockchain and Web3 systems that perform financial functions across multiple layers. MiFID II’s functional, substance-over-form orientation ensures it operates as a spillover regime where crypto-asset arrangements intersect with traditional financial activities or exhibit security-like characteristics.19

    MiFID II is not displaced by MiCA; the regimes coexist within a deliberately layered regulatory architecture. MiCA Art 2(4) explicitly excludes crypto-assets qualifying as “financial instruments” under MiFID II Annex I Section C (transferable securities, money-market instruments, units in collective investment undertakings, derivatives, emission allowances). This carve-out preserves MiFID’s jurisdiction and necessitates substantive interpretative assessment at regime boundaries, informed by token structure, governance arrangements, economic substance, and market function rather than preliminary technical classification.20

    Interpretative overlap emerges because many crypto-assets exhibit characteristics resonant with MiFID financial instrument concepts. Profit participation through yield mechanisms, transferable rights to economic value or governance influence, common enterprise structures, and reliance on third-party managerial effort invite direct comparison with transferable securities. MiFID II’s principles-based framework — particularly Article 4(1)(44)’s definition of transferable securities as “those classes of securities which are negotiable on the capital market” — requires NCAs and ESMA to assess these features contextually. ESMA was mandated under MiCA Art 2(5) to issue guidelines on the conditions and criteria for the qualification of crypto-assets as financial instruments, addressing this classification boundary directly.21

    Institutional incentives shape this interpretative process systematically. Investor protection-oriented NCAs prioritise economic substance and risk transfer when information asymmetries or retail exposure exist, extending MiFID’s reach to capture governance tokens resembling profit-sharing or DeFi yield products akin to collective investment schemes. Conversely, innovation-supportive authorities or those with capacity constraints may adopt narrower interpretations where functional utility predominates over investment characteristics.22

    MICA / MIFID II REGIME BOUNDARY: KEY CLASSIFICATION VARIABLES
    ECONOMIC SUBSTANCE
    Does the token confer profit participation, yield, or investment return? If yes → potential MiFID transferable security. If utility-dominant → MiCA “other crypto-asset”. Substance assessed by NCA, not by issuer label.
    GOVERNANCE CONTROL
    Who controls the system? Concentrated developer/foundation control + token with economic rights → “common enterprise” / “reliance on efforts of others” indicators. Genuine decentralisation may reduce MiFID characterisation risk.
    TRANSFERABILITY
    Is the token freely transferable and traded on secondary markets? MiFID Art 4(1)(44) requires negotiability on capital markets. Restricted-transfer tokens may fall outside MiFID but remain within MiCA.
    ACTIVITY PERFORMED
    What service does the provider offer? Custody, exchange, execution, advice, portfolio management? MiCA CASP and MiFID investment firm obligations may overlap where service models are hybrid.

    The UK Approach and the Governance Gap

    IV.A — FSMA, Perimeter Control, and Regulatory Pragmatism

    The United Kingdom’s regulatory approach to digital assets is anchored in a statutory architecture that prioritises perimeter control and supervisory judgment over detailed asset categorisation. FSMA 2000, as amended by the Financial Services and Markets Act 2023, provides a broad legal foundation where regulatory scope emerges through statutory concepts (“regulated activities”), secondary legislation, FCA rulemaking, and Perimeter Guidance (PERG). In structural contrast to the EU’s harmonised, taxonomy-driven MiCA regime, the UK model relies explicitly on institutional discretion to determine when and how regulation applies to novel arrangements.23

    Central to this approach is the FCA’s activity-based perimeter logic. Regulation targets activities — dealing, arranging, advising, managing, safeguarding — not assets per se. The operative question is whether token-related conduct constitutes a “regulated activity in the UK by way of business,” assessed against economic substance (profit expectation, reliance on others’ efforts), governance realities (who controls outcomes), and consumer/market impact rather than token nomenclature. The FCA’s initial framework, set out in PS19/22 “Guidance on Cryptoassets” (July 2019), distinguished between security tokens (within the regulatory perimeter), e-money tokens (regulated under the Electronic Money Regulations 2011), and unregulated tokens (exchange tokens and utility tokens outside the FSMA perimeter but within AML scope).24

    The financial promotions regime for crypto-assets, finalised in PS23/6 (June 2023, effective 8 October 2023), extended section 21 FSMA 2000 to qualifying cryptoassets — imposing risk warnings, cooling-off periods for first-time investors, bans on referral incentives, and requirements for clear and fair promotions. This represents a significant expansion of the regulatory perimeter through FCA rulemaking rather than primary legislation, illustrating the UK’s reliance on institutional discretion to calibrate regulatory intensity.25

    The EU/UK contrast is structural rather than merely stylistic. MiCA pursues ex ante harmonisation through detailed token categories and technical standards, managing complexity through ESMA/NCA coordination across 27 Member States. The UK accepts legislative indeterminacy, concentrating regulatory intelligence in FCA supervisory judgment supported by PRA prudential oversight. MiCA redistributes uncertainty to regime boundaries and Level 2/3 implementation; FSMA embeds it in perimeter interpretation and ongoing supervision. Neither eliminates uncertainty; each channels it differently.26


    IV.B — The Governance Gap: Where Regulation and System Design Diverge

    The governance gap captures the structural divergence between the assumptions embedded in legislative frameworks and the operational governance realities of blockchain and Web3 systems. Both EU and UK regulatory regimes — MiCA, MiFID II, FSMA — are constructed around identifiable legal persons, accountable decision-making structures, and allocable responsibility, underpinning licensing, disclosure, and enforcement mechanisms. Blockchain systems, however, frequently distribute governance across foundations, DAOs, developer collectives, service intermediaries, and token-weighted voting, often without clear authority hierarchies or legal personality.27

    Legislative frameworks implicitly assume governance mapping onto familiar organisational forms: authorised entities for MiCA CASPs, investment firms under MiFID II, or “persons carrying on regulated activities” under FSMA. Blockchain arrangements challenge this model by fragmenting decision rights across protocol parameters (upgrade keys), economic resources (treasuries), technical infrastructure (validator sets), and social coordination (off-chain developer signalling), producing governance that is simultaneously distributed and concentrated.28

    Decentralisation claims frequently exacerbate this mismatch. Projects asserting “permissionless,” “trustless,” or “community-governed” status suggest diminished regulatory relevance or diffused accountability. Supervisory authorities assess such claims pragmatically through control diagnostics: who possesses admin/upgrade keys, multisig signers, or parameter change authority; who curates front-ends or oracles; who coordinates emergency responses. Where influence concentrates — formally through foundations or informally through developer coordination — accountability expectations persist irrespective of narrative framing.29

    The UK’s Property (Digital Assets etc) Bill, introduced in the House of Lords on 11 September 2024 following the Law Commission’s 2023 report (Law Com No 412), addresses a specific dimension of this governance gap by confirming that digital assets can constitute personal property — a “third category” beyond things in possession and things in action. While the Bill does not resolve the broader governance gap in regulatory architecture, it provides foundational legal clarity for ownership, custody, and enforcement that current UK common law had left uncertain.30

    The governance gap is not a drafting defect. It emerges from the dynamic interaction between multi-layer blockchain systems and supervisory institutions operating under constraints of mandate boundaries, expertise limitations, and resource allocation pressures. Legislative expansion alone does not close the gap; governance-grade institutional response is required.

    SOURCES OF THE GOVERNANCE GAP
    ACCOUNTABILITY FRAGMENTATION
    Decision rights distributed across protocol parameters, treasuries, validator sets, and off-chain coordination. No single “person carrying on regulated activity” maps to the system. SMCR, MiCA senior management requirements, and MiFID fit-and-proper tests cannot attach to pseudonymous signers or diffuse DAOs.
    DECENTRALISATION NARRATIVES
    Claims of “permissionless” or “trustless” governance suggest reduced regulatory relevance. Authorities consistently apply substance tests: admin keys, upgrade authority, treasury control, front-end curation, emergency response coordination reveal de facto control despite formal distribution.
    INSTITUTIONAL CAPACITY LIMITS
    NCAs, ESMA, and the FCA face resource constraints, mandate boundaries, and expertise limitations. Crypto supervision competes with traditional financial services oversight. Cross-border coordination costs compound capacity challenges, producing selective enforcement that targets accessible intermediaries rather than diffuse protocols.

    Supervisory Discretion, Enforcement Logic, and the Multi-Layer Framework

    V.A — Supervisory Discretion and Enforcement Logic

    Supervisory discretion and enforcement logic are central to understanding how digital asset regulation operates in practice across the European Union and United Kingdom. Legislative frameworks establish powers and objectives, but regulatory meaning emerges through discretionary supervisory action within institutional constraints. In structurally complex domains like blockchain and Web3, enforcement functions not as exceptional remedy but as routine governance through which authorities clarify expectations, assert jurisdictional competence, and shape market conduct.31

    Authorities intervene through mechanisms extending beyond formal non-compliance. Actions are triggered by perceived threats to core objectives: consumer safeguarding (retail losses from scams, platform failures), market integrity (insider trading, market manipulation), financial stability (systemic runs on stablecoins), and institutional legitimacy (unregulated actors undermining authorised markets). The FCA has been notably stringent in its approach to crypto firm registration under the Money Laundering Regulations: by early 2022, over 80% of crypto firm applications had been refused or withdrawn, signalling consumer risk thresholds far exceeding formal AML/CTF requirements.32

    Enforcement serves critical signalling functions. High-profile actions articulate interpretative positions where legislation or guidance remains underdeveloped: FCA registration suspensions signal consumer risk thresholds; BaFin’s enforcement against firms conducting unauthorised crypto-custody business (classified as a financial service under s.1(1a) sentence 2 no. 6 KWG since 1 January 2020) clarifies licensing boundaries; AMF warnings against unauthorised crypto-asset offerings and its maintenance of a blacklist of non-compliant platforms establish activity-based perimeter tests for the French market.33

    Precedent accumulation shapes evolving enforcement logic. While continental EU systems lack strict stare decisis, supervisory decisions, ESMA opinions, FCA Final Notices, and EBA Reports function as quasi-binding reference points influencing future practice. Discernible patterns emerge: concentrated treasury control, developer upgrade dominance, retail yield products lacking investor safeguards — these governance and economic configurations become enforcement prioritisation indicators across both EU and UK jurisdictions.34

    Selective enforcement reflects unavoidable institutional reality. Finite capacity, competing mandates, and cross-border coordination costs necessitate prioritisation. Intervention concentrates on visible, scalable, redressable cases: registered firms operating crypto ATMs without adequate safeguards; EU-targeting platforms lacking CASP authorisation; governance hubs with identifiable legal personality. Pseudonymous developers or truly diffuse DAOs prove less accessible, shifting enforcement toward intermediaries (exchanges, wallets, front-ends) and controllers with jurisdictional nexus.35


    V.B — The Multi-Layer Governance Framework Applied

    The Multi-Layer Governance Framework for Blockchain and Digital Assets (Carvalho-Ribas) provides structured methodology for understanding how supervisory authorities prioritise and engage different structural layers when interpreting legislation and shaping enforcement strategy. In EU and UK practice, regulatory interpretation does not proceed uniformly across layers. Authorities selectively privilege dimensions according to mandate, risk materiality, and competence.36

    Governance layer centrality dominates supervisory reasoning across regimes. Authorities systematically assess decision loci — who controls upgrades, multisigs, parameter changes, emergency intervention; who coordinates off-chain developer action; who vetoes proposals despite formal DAO voting. Both ESMA’s MiCA CASP governance requirements and FCA’s application of accountability expectations to crypto firms treat governance realities as preceding formal classification, directly informing authorisation decisions, enforcement targeting, and remedial orders.37

    Economic layer privilege follows closely. Value flows — incentive misalignment, treasury extraction, yield asymmetries, governance token economics — provide concrete evidence for economic substance tests under MiFID transferable security analysis, MiCA investor protection triggers, and FCA “collective investment scheme” determinations under s.235 FSMA 2000. The CIS test — requiring (i) arrangements with respect to property, (ii) purpose of enabling participation in profits, (iii) no day-to-day control by participants, and (iv) pooling of contributions — directly captures DeFi yield products where liquidity is pooled and managed by protocol operators or governance token holders.38

    Jurisdictional layer delimits practical regulatory reach. Enforcement attaches through governance nexus (foundation domicile, controller residence), economic touchpoints (EU/UK treasury beneficiaries, service targeting), and effects doctrine (retail investor harm), not network node geography. FCA’s “in the UK” tests, MiCA’s reverse solicitation carve-out (Art 61), and ESMA’s cross-border coordination presuppose pragmatic jurisdictional assertion where intervention capacity exists.39

    MULTI-LAYER FRAMEWORK: SUPERVISORY LAYER PRIORITISATION
    GOVERNANCE
    Primary. Decision loci, upgrade authority, treasury control, accountability structures. Both ESMA and FCA treat governance realities as preceding formal classification. Governance concentration triggers enforcement even where formal decentralisation is claimed.
    ECONOMIC
    Secondary. Value flows, yield mechanisms, incentive alignment/misalignment. Provides evidence for substance tests: MiFID transferable security, MiCA investor protection, FSMA CIS. Economic hybridity confounds nominalist classification.
    LEGAL
    Functional. Operationalised through governance and economic diagnostics rather than formalistic taxonomy. MiCA ART/EMT, MiFID investment service tests, and FSMA regulated activity analysis converge on substance when confronted with hybrid arrangements.
    INFRASTRUCTURE
    Instrumental. Technical architecture informs custody risk, control diagnostics (admin keys, pause functions), and operational resilience. Non-determinative absent governance or economic implications.
    JURISDICTIONAL
    Delimiting. Enforcement attaches through governance nexus and economic touchpoints, not network geography. FCA “in the UK” tests, MiCA reverse solicitation, ESMA cross-border coordination.

    High-Value Domain for Global Practice

    Interpretative literacy in EU and UK digital asset regulation constitutes a high-value professional domain because it directly corresponds to how regulatory authority is exercised in practice. As legislative frameworks such as MiCA and FSMA expand in scope and technical complexity, institutional demand increasingly favours professionals who can operate beyond formal rule identification and compliance mapping. Regulatory effectiveness hinges less on exhaustive rule knowledge than on understanding how institutions interpret, prioritise, and enforce provisions within multi-layer governance environments where governance realities often diverge from legislative presuppositions.40

    For regulators and supervisory authorities, governance-grade interpretative reasoning enables coherent oversight of systems that evolve faster than legislative cycles. NCAs and the FCA confront arrangements — hybrid DeFi protocols, governance tokens with yield, DAOs interfacing retail — that defy established organisational or financial models. Professionals capable of analysing control structures, economic incentives, and accountability gaps contribute to consistent decision-making, reduce ad hoc enforcement, and support internal alignment between investor protection, market integrity, and innovation facilitation mandates.41

    For cross-border advisers, EU/UK interpretative competence provides unifying analytical discipline. Rather than jurisdiction-specific checklists vulnerable to supervisory evolution, governance-oriented reasoning enables defensible classification across permeable regime boundaries. Advisers can articulate why identical token arrangements trigger FCA consumer intervention but ECB stablecoin scrutiny, or BaFin ART authorisation alongside AMF DeFi perimeter tests, grounding risk assessment in convergent institutional logic despite divergent formal triggers.

    Governance-grade reasoning demonstrates durability and transferability distinguishing it from transactional compliance. Checklist approaches map static requirements but fail against supervisory expectation shifts or enforcement logic evolution. Structural literacy equips professionals to engage regulatory systems as living institutions, adapting to ESMA Q&As, FCA Dear CEO campaigns, or NCA innovation hub feedback without foundational recalibration.42

    HIGH-VALUE PRACTICE AREAS: EU/UK DIGITAL ASSET REGULATION
    INTERPRETATIVE ANALYSIS
    MiCA/MiFID boundary navigation, FCA perimeter assessment, ESMA supervisory convergence. Governance-oriented reasoning across legislative texts and institutional practice.
    GOVERNANCE DIAGNOSTICS
    Control structure assessment, decentralisation claims analysis, accountability mapping. Treasury control, developer influence, DAO governance gap identification for regulatory engagement.
    INSTITUTIONAL COORDINATION
    ESMA/NCA coordination, FCA/PRA alignment, cross-border supervisory college operation. Understanding institutional incentives and mandate-driven prioritisation across EU/UK divergence.

    Knowledge and Practice Continuity

    This paper forms part of a structured doctrinal system dedicated to the legal, regulatory, and governance analysis of blockchain, Web3, and digital asset systems across multiple jurisdictions and institutional contexts. Within this system, each paper performs a distinct analytical function while remaining structurally interdependent with the others. The series examines how blockchain and digital asset-based systems are shaped, constrained, and governed through the interaction of multiple governance layers — national, supranational, and international — and through the analytical lenses of structural decomposition, institutional assessment, and comparative regulatory practice.

    From a knowledge and practice architecture perspective, this Authority PDF constitutes a foundational layer, establishing the interpretative concepts, institutional frameworks, and governance diagnostic methods that are then deployed through structured professional training, advanced coursework, and implementation cohorts. Each tier builds on prior analytical clarity and institutional literacy, ensuring continuity between doctrine, interpretation, and professional practice.

    Written Paper Professional Training Advanced Course Implementation Cohort
    FUNCTION FUNCTION FUNCTION FUNCTION
    Doctrinal foundation: regulatory interpretation, governance gap analysis, supervisory discretion frameworks Applied interpretative capacity: governance-oriented reasoning across EU and UK institutional contexts Integrated governance analysis: MiCA, MiFID, FSMA applied across legislative, institutional, and enforcement layers Execution environment: structured professional practice with live regulatory and supervisory engagement
    MODE MODE MODE MODE
    Analytical · Doctrinal Applied · Interpretative Integrated · Cross-layer Operational · Authority-facing
    OUTPUT OUTPUT OUTPUT OUTPUT
    Authority PDF: interpretative framework, governance gap analysis, institutional diagnostic methodology Professional training: governance-oriented reasoning, perimeter analysis, enforcement pattern recognition Advanced course: MiCA/MiFID/FSMA cross-regime analysis, supervisory engagement, institutional navigation Implementation cohort: live advisory, regulatory submissions, supervisory engagement across EU and UK
    AUDIENCE AUDIENCE AUDIENCE AUDIENCE
    Lawyers, tax advisers, regulators, policymakers, compliance officers, institutional analysts Mid-career professionals, compliance teams, advisory firms, regulatory bodies Senior practitioners, institutional advisers, cross-border structuring professionals Advanced professionals, governance designers, policy coordinators, institutional stakeholders

    Conclusions

    This paper has examined EU and UK digital asset regulation not as static collections of legal rules, but as institutional governance systems through which regulatory meaning emerges in practice. While MiCA, MiFID II, and FSMA establish formal frameworks, concrete regulatory outcomes arise from how supervisory authorities interpret, prioritise, and enforce these instruments within multi-layer governance environments shaped by mandate constraints, resource realities, and institutional cultures. Persistent legal uncertainty in the digital asset domain reflects not primarily legislative deficiency, but structural complexity and the interpretive discretion inherent to supervising rapidly evolving, multi-functional systems.43

    Across jurisdictions, regulatory interpretation privileges governance realities and economic substance over formal classification. Authorities consistently assess decision loci, control mechanisms, value flows, and risk allocation before applying statutory categories. Legislative taxonomies provide analytical reference points, but institutional practice reveals their insufficiency against hybrid arrangements integrating infrastructure, yield generation, governance participation, and programmable settlement.

    Enforcement constitutes integral interpretive practice, not exceptional remedy. Supervisory intervention clarifies contested boundaries, signals institutional risk thresholds, and corrects governance gaps through patterned action driven by mandate-driven logic — investor protection against yield scams, market integrity against insider parameter changes, stability against uncollateralised stablecoin runs — rather than formal breach alone.44

    The Multi-Layer Governance Framework for Blockchain and Digital Assets (Carvalho-Ribas) provides structured methodology for this complexity. Layer separation clarifies institutional prioritisation — governance control preceding token qualification; economic substance informing perimeter tests — while interaction mapping reveals enforcement flashpoints: treasury opacity triggering accountability breaches; developer influence satisfying “efforts of others” tests; jurisdictional targeting via foundation domicile.45

    This analysis reaffirms structural diagnosis as prerequisite to credible regulatory engagement. Absent governance-oriented reasoning, market participants risk formal compliance misaligned with supervisory reality; institutions risk siloed analysis missing cross-layer risk; policymakers risk legislative ambition disconnected from implementation capacity. By integrating legislative architecture with institutional practice, this paper establishes analytical foundation for subsequent diagnostic work examining regulatory stress concentrations and their remediation across EU/UK digital asset supervision.


    Frequently asked

    What is the 'governance gap' in EU and UK digital-asset regulation?

    It is the persistent gap between increasingly sophisticated statutory frameworks — MiCA, MiFID II, and the UK's FSMA — and regulatory outcomes in practice. DA-03 shows it is not merely a drafting defect or transitional friction; it emerges from the dynamic interaction between multiple governance layers, so functionally identical arrangements can produce divergent outcomes even within broadly harmonised frameworks.

    Why do similar arrangements get regulated differently under MiCA, MiFID II, and FSMA?

    Because regulatory outcomes are shaped less by the formal content of the rules than by how those rules are interpreted, prioritised, and enforced by supervisory institutions. Digital-asset regulation engages overlapping layers — legislative design, administrative and supervisory discretion, inter-institutional coordination, and enforcement strategy — that interact dynamically and often asymmetrically across and within jurisdictions.

    How does the paper apply the Multi-Layer Governance Framework to the EU and UK?

    It applies the Multi-Layer Governance Framework (Carvalho-Ribas) to integrate the legislative, institutional, and enforcement layers rather than reading regulation off legislative texts or token labels — examining how MiCA, MiFID II, and FSMA are actually applied by European and UK authorities, including token and product classification, perimeter assessment, MiCA's reverse-solicitation carve-out (Art 61), and ESMA's cross-border coordination.

    What is the practical risk for cross-border digital-asset activity?

    That perimeter and classification turn on pragmatic jurisdictional assertion — 'in the UK' tests, MiCA's reverse-solicitation carve-out, and supervisory coordination — so identical factual arrangements may fall inside one perimeter and outside another. Legislative convergence between the EU and UK does not guarantee convergent supervisory treatment.

    What is the evidentiary basis, and is this legal advice?

    DA-03 is a comparative legal and institutional analysis of how MiCA, MiFID II, and FSMA are applied by EU and UK authorities, part of the ECR Digital Assets (DA) series applying the Multi-Layer Governance Framework. It is authority research and general information — expressly not a compliance guide, investment advice, or jurisdiction-specific tax planning.

    WORK WITH EVELYSE CARVALHO-RIBAS
    ECR advises on governance, regulatory, and fiscal dimensions of blockchain, Web3, and digital asset systems — with particular depth in EU and UK regulatory interpretation, MiCA/MiFID/FSMA perimeter analysis, and the governance gap between legislative design and supervisory reality. Advisory mandates are structured, jurisdiction-aware, and governance-first. Available for:
    → Token Classification & Regulatory Analysis — Governance-grade classification analysis across MiCA (EU: ARTs, EMTs, other crypto-assets, CASP obligations), MiFID II (transferable security / financial instrument spillover), and FSMA (FCA perimeter assessment, regulated activity tests). Integrates governance realities, economic substance, and institutional practice to produce defensible classification reports. For founders, institutional investors, DeFi operators, and digital asset platforms navigating EU/UK regulatory boundaries. Enquire →
    → Governance Structure Design — Design and assessment of governance architectures aligned with EU and UK supervisory expectations. Applies the Multi-Layer Governance Framework to identify governance gaps, map accountability structures, and design arrangements that satisfy MiCA CASP governance requirements, SMCR accountability expectations, and MiFID fit-and-proper standards. For builders, DeFi operators, institutional investors, and policy advisers. Enquire →
    → Cross-Border Digital Asset Strategy — Multi-jurisdictional structuring, regulatory mapping, and supervisory-engagement strategy across EU and UK, Americas, and Asia-Pacific. Integrates MiCA/MiFID/FSMA perimeter analysis with CARF/DAC8 tax reporting, AML/CFT compliance (FATF R.15), and institutional coordination across cumulative compliance burdens. For founders, institutional investors, international tax lawyers, and enterprises managing cross-border operations. Enquire →
    → Institutional & Policy Advisory — Structured, governance-based input for regulators, supervisory authorities, ministries, and policymakers designing or assessing digital asset regulatory frameworks. Comparative EU/UK analysis of institutional practice, supervisory convergence, and enforcement logic. For governments, ministries, foundations, and international organisations. Enquire →
    → Evidentiary & Submission Work — Expert reports, regulatory submissions, and evidentiary support for proceedings, supervisory reviews, and enforcement actions involving digital asset classification, governance assessment, and cross-border regulatory exposure across EU and UK jurisdictions. Enquire →
    → Expert Briefing / In-House Training — Bespoke briefings and structured training for legal, compliance, tax, and advisory teams on EU/UK digital asset regulation. Covers MiCA/MiFID/FSMA interpretative analysis, governance gap diagnostics, supervisory discretion and enforcement logic, and the Multi-Layer Governance Framework. For law firms, R&D companies, financial institutions, and regulatory bodies. Enquire →
    For educational programmes (training, courses, cohorts), visit moroak.com/education

    This paper is published through MoroAK Professional Knowledge Infrastructure. All courses, cohorts, trainings, papers, and digital toolkits are available through ECR's educator profile on moroak.com. Advisory mandates and mandate scoping are handled through ECR's practice entity — contact via evelyse@moroak.com.

    Endnotes

    1 On the centrality of institutional interpretation to regulatory outcomes in complex financial systems, see Zetzsche DA, Arner DW, Buckley RP, ‘Decentralized Finance’ Journal of Financial Regulation 6(2) 172–203 (2020); De Filippi P, Wright A, Blockchain and the Law: The Rule of Code (Harvard University Press 2018) https://doi.org/10.2307/j.ctv2862wn8. ↩
    2 See Carvalho-Ribas E, ‘The Structural Architecture of Blockchain and Web3 Systems: Layered Analysis for Legal and Regulatory Classification’, DA-02, ECR-Digital Assets Series (MoroAK 2026), sections II–VI, developing the multi-layer analytical architecture applied throughout this paper. ↩
    3 The Multi-Layer Governance Framework for Blockchain and Digital Assets was introduced in DA-01 and structurally operationalised in DA-02. See Carvalho-Ribas E, ‘Blockchain, Web3 and Digital Assets: Legal Ontology, Governance Complexity, and the Limits of Analogical Regulation’, DA-01, ECR-Digital Assets Series (MoroAK 2026), sections III–V. ↩
    4 The definitions in Section I are functional and governance-oriented. They do not reproduce verbatim any single regulatory authority’s statutory definitions but are constructed to support governance-grade legal analysis across jurisdictions. Where official legal definitions exist (e.g., MiCA Art 3, FSMA RAO, PSA 2019 s 2), they are referenced alongside the working definitions adopted here. ↩
    5 On regulatory interpretation as institutional practice rather than purely doctrinal exercise, see Brummer C, Cryptoassets: Legal, Regulatory, and Monetary Perspectives (Oxford University Press 2019), ch 1; Walch A, ‘Deconstructing “Decentralization”: Exploring the Core Claim of Crypto Systems’ in C Brummer (ed), Crypto Assets: Legal and Monetary Perspectives (OUP 2019). ↩
    6 On the structural significance of discretion in EU administrative law, see Case C-270/12 United Kingdom v European Parliament and Council [2014] ECLI:EU:C:2014:18 (ESMA Short Selling). For UK public law principles governing regulatory discretion, see R (on the application of Munjaz) v Mersey Care NHS Trust [2005] UKHL 58; Financial Services and Markets Act 2000, s 1B(1)–(4) (FCA statutory objectives). ↩
    7 Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets (MiCA), OJ L 150, 9.6.2023, pp. 40–205; Directive 2014/65/EU of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments (MiFID II), OJ L 173, 12.6.2014, pp. 349–496; Financial Services and Markets Act 2000 (c.8), as amended by Financial Services and Markets Act 2023 (c.29), Royal Assent 29 June 2023. ↩
    8 FCA, Perimeter Guidance Manual (PERG), especially PERG 2.6 (regulated activities) and PERG 2.7 (specified investments). See also ESMA, ‘Advice on Initial Coin Offerings and Crypto-Assets’ (ESMA50-157-1391, 9 January 2019), paras 7–15, on substance-over-form assessment in perimeter determinations. ↩
    9 On enforcement logic as institutional governance practice, see Hacker P, Thomale C, ‘Crypto-Securities Regulation: ICOs, Token Sales and Cryptocurrencies under EU Financial Law’ (2018) 15 European Company and Financial Law Review 645; FCA, ‘Approach to Enforcement’ (EG 2.1–2.5), setting out the FCA’s enforcement philosophy including deterrence, public accountability, and market integrity signalling. ↩
    10 Van Pelt R, Jansen S, Baars D, Overbeek S, ‘Defining Blockchain Governance: A Framework for Analysis and Comparison’, Information Systems Management 38(1) 21 (2021); Ostrom E, ‘Beyond Markets and States: Polycentric Governance of Complex Economic Systems’, American Economic Review 100(3) 641 (2010). ↩
    11 ESMA first consultation package on MiCA implementing measures (12 July 2023): RTS on CASP authorisation content, complaints handling, and conflicts of interest identification and prevention. Second consultation package (5 October 2023): business continuity, ICT security, and record-keeping requirements. See ESMA, ‘Markets in Crypto-Assets Regulation: First Consultation Package’ (ESMA75-453128700-438, 12 July 2023); ESMA, ‘Markets in Crypto-Assets Regulation: Second Consultation Package’ (ESMA75-453128700-478, 5 October 2023). ↩
    12 MiFID II Art 4(1)(15) defines ‘financial instrument’ by reference to Annex I Section C; Art 4(1)(44) defines ‘transferable securities’ as “those classes of securities which are negotiable on the capital market.” On the functional extension of MiFID concepts to crypto-assets, see ESMA, ‘Advice on Initial Coin Offerings and Crypto-Assets’ (ESMA50-157-1391, 9 January 2019), paras 79–91. ↩
    13 Financial Services and Markets Act 2023 (c.29), s 69 and Schedule 6. Section 69 provides HM Treasury with powers to make secondary legislation bringing crypto-related activities within the FSMA regulatory perimeter through amendments to the Financial Services and Markets Act 2000 (Regulated Activities) Order 2001 (SI 2001/544). Royal Assent 29 June 2023. ↩
    14 Carvalho-Ribas E, DA-01 (n 3), sections IV–V, analysing the limits of analogical regulation in blockchain contexts. See also De Filippi P, Wright A (n 1), ch 4; Reijers S and others, ‘A System-Based View of Blockchain Governance’ (2023) Information and Software Technology. ↩
    15 MiCA (n 7), Recitals 1–6 and Art 1, establishing the Regulation’s objectives and scope. For critical assessment of MiCA’s operational limits, see Zetzsche DA, Annunziata F, Arner DW, Buckley RP, ‘The Markets in Crypto-Assets Regulation (MiCA) and the EU Digital Finance Strategy’ (2021) 16 Capital Markets Law Journal 203. ↩
    16 MiCA Art 3(1)(5)–(9), defining crypto-asset categories: asset-referenced tokens (Art 3(1)(6), Title III, Arts 16–47); e-money tokens (Art 3(1)(7), Title IV, Arts 48–58); other crypto-assets including utility tokens (Art 3(1)(9), Title II, Arts 4–15). On the holistic classification approach, see ESMA (n 11), first consultation package, section 3.2. ↩
    17 MiCA Art 93 (NCA supervisory powers), Art 94 (right to information), Art 97 (precautionary measures), Art 110–113 (ESMA oversight, supervisory convergence, and binding mediation). On the interaction between MiCA and PSD2, see Directive (EU) 2015/2366 (PSD2), Art 4(3)–(5). On AML interaction, see Regulation (EU) 2023/1113 (Transfer of Funds Regulation, recast), OJ L 150, 9.6.2023, pp. 1–39. ↩
    18 MiCA Art 143 (transitional provisions), permitting Member States to grant existing CASPs up to 18 months from 30 December 2024 to continue operating. France: Loi n° 2019-486 du 22 mai 2019 relative à la croissance et la transformation des entreprises (loi PACTE), Art 86, establishing PSAN registration (AMF). Enhanced registration requirements from 1 January 2024. Germany: Kreditwesengesetz (KWG) s 1(1a) sentence 2 no. 6, crypto custody licensing since 1 January 2020 (BaFin). ↩
    19 MiFID II (n 7), particularly Art 4(1)(15) (financial instruments) and Annex I Section C. On MiFID II’s continued relevance post-MiCA, see ESMA, ‘Report on Trends, Risks and Vulnerabilities’ No 1, 2024, noting ongoing classification challenges at the MiCA/MiFID boundary. ↩
    20 MiCA Art 2(4): “This Regulation shall not apply to crypto-assets that qualify as: (a) financial instruments as defined in Article 4(1), point (15), of Directive 2014/65/EU”. See also Hacker P, Thomale C (n 9); Lange B, Governing Blockchain: Regulatory Frameworks and Policy Challenges (Edward Elgar 2023). ↩
    21 MiFID II Art 4(1)(44); MiCA Art 2(5), mandating ESMA to issue guidelines on the conditions and criteria for the qualification of crypto-assets as financial instruments. See also ESMA (n 8), paras 79–91, on the substance-based approach to determining whether crypto-assets constitute transferable securities. ↩
    22 On institutional incentives shaping regulatory interpretation, see Walch A (n 5); OECD, Why Decentralised Finance Matters and the Policy Implications (OECD Publishing 2022), ch 3. For innovation-supportive regulatory approaches, see EU Commission, ‘Digital Finance Strategy for the EU’ COM(2020) 591 final, 24 September 2020. ↩
    23 FSMA 2000 (n 7), Part I (The Regulators), Part II (Regulated and Prohibited Activities); Financial Services and Markets Act 2023 (n 13), s 1 (revocation of retained EU law), s 3 (designation of activities), s 69 and Schedule 6 (crypto-asset powers). FCA Handbook, PERG 2 (Authorisation and regulated activities). ↩
    24 FCA, ‘Guidance on Cryptoassets’, Policy Statement PS19/22 (July 2019). The guidance established the FCA’s three-category framework: security tokens (within the regulatory perimeter), e-money tokens (regulated under Electronic Money Regulations 2011), and unregulated tokens (exchange and utility tokens within AML scope under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, as amended). ↩
    25 FCA, ‘Financial promotion rules for cryptoassets’, Policy Statement PS23/6 (June 2023, effective 8 October 2023). The regime extends FSMA 2000 s 21 (restrictions on financial promotion) to qualifying cryptoassets, imposing requirements including risk warnings, cooling-off periods for first-time investors, bans on referral incentives, and clear, fair, and not misleading promotions. ↩
    26 On the structural contrast between EU harmonisation and UK principles-based regulation in financial services, see Ferran E, ‘The Break-Up of the United Kingdom and the European Union: Brexit and the Future of UK Financial Regulation’ (2017) 17 Journal of Corporate Law Studies 1. See also Armour J and others, Principles of Financial Regulation (OUP 2016), ch 2 on regulatory architecture and institutional design. ↩
    27 On the governance gap in blockchain regulation, see Carvalho-Ribas E, DA-02 (n 2), section V (Governance, Accountability, and the Regulatory Gap); Walch A (n 5); De Filippi P, Wright A (n 1), ch 8 (Blockchain Governance). ↩
    28 MiCA Title V (CASPs), Arts 59–71 (authorisation and operating conditions), requiring identifiable legal persons with senior management accountability; MiFID II Art 9 (management body), Art 16 (organisational requirements); FSMA 2000 s 59 (approval of individuals performing controlled functions). See also Van Pelt R and others (n 10) on governance fragmentation in distributed systems. ↩
    29 On supervisory assessment of decentralisation claims, see CFTC, ‘Primer on Smart Contracts’ (November 2018); SEC Commissioner Hester Peirce, ‘Token Safe Harbor Proposal 2.0’ (April 2021). For the control diagnostics approach, see Walch A (n 5); Carvalho-Ribas E, DA-01 (n 3), section V.B. ↩
    30 Law Commission of England and Wales, Digital Assets (Law Com No 412, June 2023); Property (Digital Assets etc) Bill [HL], introduced House of Lords 11 September 2024. The Bill provides that “a thing is not prevented from being the object of personal property rights merely because it is neither a thing in action nor a thing in possession” — establishing a statutory ‘third category’ of personal property. ↩
    31 On enforcement as routine governance in financial regulation, see Armour J and others (n 26), ch 24 (Enforcement); FCA, ‘Approach to Enforcement’ (EG 2.1–2.5). For the EU dimension, see ESMA, ‘Peer Review Report on the Guidelines on the Enforcement of Financial Information’ (ESMA42-111-4138, 2022). ↩
    32 FCA, Annual Report and Accounts 2021/22, reporting that over 80% of crypto firm applications under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (as amended) had been refused or withdrawn by early 2022. See also FCA, ‘Statement on FCA-registered crypto asset firms’ (March 2022); Temporary Registration Regime extensions (2021–2022). ↩
    33 BaFin: crypto custody classified as a financial service under Kreditwesengesetz (KWG) s 1(1a) sentence 2 no. 6 since 1 January 2020, requiring BaFin authorisation. AMF (France): PSAN registration under loi PACTE (n 18); AMF maintains a public blacklist of unauthorised service providers at amf-france.org/fr/espace-epargnants/proteger-son-epargne/listes-noires. See also ESMA, ‘National Competent Authorities’ approaches to the regulation of crypto-assets’ (June 2022). ↩
    34 On the quasi-precedential effect of supervisory decisions in EU financial regulation, see Moloney N, EU Securities and Financial Markets Regulation (3rd edn, OUP 2014), ch 15; ESMA, ‘Guidelines on MiFID II Product Governance Requirements’ (ESMA35-43-3448). For UK enforcement precedent, see FCA Final Notices at fca.org.uk/news/final-notices. ↩
    35 On selective enforcement and intermediary targeting, see Brummer C (n 5), ch 5; OECD, Blockchain at the Frontier: Impacts and Issues in Cross-Border Co-operation and Global Governance (OECD Business and Finance Policy Papers, No. 4, OECD Publishing 2022), ch 4. ↩
    36 Carvalho-Ribas E, DA-01 (n 3), introducing the Multi-Layer Governance Framework; Carvalho-Ribas E, DA-02 (n 2), operationalising the framework through structural layer decomposition. Applied here to institutional interpretation and supervisory practice. ↩
    37 MiCA Title V Chapter 2 (governance arrangements for CASPs), particularly Arts 64–66 (management body requirements, organisational requirements, prudential safeguards). FCA Senior Managers and Certification Regime (SMCR): note that SMCR does not apply to MLR-only registered crypto firms; it attaches to firms authorised under FSMA 2000, Part 4A. ↩
    38 FSMA 2000 s 235 (collective investment schemes): (1) arrangements with respect to property of any description, (2) purpose or effect of enabling persons taking part to participate in or receive profits or income, (3) participants do not have day-to-day control, (4) contributions are pooled or managed as a whole. See FCA v Capital Alternatives Ltd [2015] EWCA Civ 284 on application of CIS test to novel arrangements. ↩
    39 MiCA Art 61 (reverse solicitation carve-out for third-country CASPs); FCA Handbook, PERG 4.6 (territorial scope of the general prohibition). On effects-based jurisdiction in crypto regulation, see FATF, ‘Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers’ (October 2021), paras 32–38. ↩
    40 On the professional demand for governance-grade regulatory reasoning, see Federal Reserve Board (Allen J, Alley R, Seira A, Watsky C), ‘Governance of Permissionless Blockchain Networks’ (FEDS Notes, 9 February 2024); OECD, Why Decentralised Finance Matters and the Policy Implications (n 22), ch 5 (Policy Implications). ↩
    41 On institutional benefits of structured analytical methodology, see Ostrom E, ‘Collective Action Theory’ in C Boix and S Stokes (eds), Oxford Handbook of Comparative Politics (OUP 2007); Bank for International Settlements, Sound Practices: Implications of Fintech Developments for Banks and Bank Supervisors (2018). ↩
    42 On the durability of governance-oriented analysis versus transactional compliance, see Van Pelt R and others (n 10); Lumineau F, Wang W, Schilke O, ‘Blockchain Governance — A New Way of Organizing Collaborations?’, Organization Science 32(2) 500 (2021). ↩
    43 For a comprehensive treatment of regulatory complexity in digital asset supervision, see Zetzsche DA, Arner DW, Buckley RP (n 1); OECD, Blockchain at the Frontier (n 35), ch 5–6; Reijers S and others (n 14). ↩
    44 On enforcement as interpretive practice in emerging financial domains, see Moloney N (n 34), ch 15; FATF, ‘Targeted Update on Implementation of the FATF Standards on Virtual Assets and VASPs’ (June 2024), reporting approximately 75% of jurisdictions had not yet fully implemented the travel rule for VAs/VASPs. ↩
    45 Carvalho-Ribas E, DA-01 (n 3); Carvalho-Ribas E, DA-02 (n 2). The Multi-Layer Governance Framework integrates legal-normative, institutional-administrative, governance-decision, economic-value, technical-functional, and jurisdictional layers into a unified analytical architecture for blockchain and digital asset regulation. See also Ostrom E, ‘Beyond Markets and States’ (n 10), providing the polycentric governance theoretical foundation. ↩

    References

    Universal DA Core Bibliography
    National Institute of Standards and Technology, ‘Blockchain’ (NIST Glossary, NISTIR 8202 et seq, last updated 2025).
    EU Blockchain Observatory and Forum.
    EU European Securities and Markets Authority, ‘Advice on Initial Coin Offerings and Crypto-Assets’ (ESMA50-157-1391, 9 January 2019).
    EU European Commission, ‘Proposal for a Regulation on Markets in Crypto-assets (MiCA)’ COM(2020) 593 final.
    EU Regulation 2023/1114 on Markets in Crypto-assets (MiCA).
    Federal Reserve Board, ‘Governance of Permissionless Blockchain Networks’ (FEDS Notes, 9 February 2024).
    Internet Policy Review, ‘Blockchain Governance’ (Glossary, 19 April 2021).
    OECD, Blockchain at the Frontier: Impacts and Issues in Cross-Border Co-operation and Global Governance (OECD Business and Finance Policy Papers, No. 4, OECD Publishing 2022).
    OECD, Why Decentralised Finance Matters and the Policy Implications (OECD Publishing 2022).
    OECD, Addressing the Tax Challenges of the Digital Economy (OECD Publishing 2014).
    Ostrom E, ‘Collective Action Theory’ in C Boix and S Stokes (eds), Oxford Handbook of Comparative Politics (OUP 2007).
    Ostrom E, ‘Beyond Markets and States: Polycentric Governance of Complex Economic Systems’, American Economic Review 100(3) 641 (2010).
    Reijers S and others, ‘A System-Based View of Blockchain Governance’ (2023) Information and Software Technology.
    Van Pelt R, Jansen S, Baars D, Overbeek S, ‘Defining Blockchain Governance: A Framework for Analysis and Comparison’, Information Systems Management 38(1) 21 (2021).
    Allen J, Alley R, Seira A, Watsky C, ‘Governance of Permissionless Blockchain Networks’, FEDS Notes (9 February 2024).
    UK Jurisdiction Taskforce, Legal Statement on Cryptoassets and Smart Contracts (2019).
    UK HMRC, ‘The Taxation of Decentralised Finance (DeFi) Involving The Lending and Staking of Cryptoassets’, Summary of Responses (2025).
    WIPO, Blockchain Technologies and IP Ecosystems: A WIPO White Paper (WIPO 2022).
    Zachariadis M, Hileman G, Scott SV, ‘Governance and Control in Distributed Ledgers’ (2019).
    Paper-Specific References
    Carvalho-Ribas, Evelyse. ‘Regulating Digital Assets in the European Union and the United Kingdom: MiCA, MiFID, FSMA and the Governance Gap’. DA-03. ECR-Digital Assets Series. Published through MoroAK Professional Knowledge Infrastructure, 2026. Available at moroak.com.
    Carvalho-Ribas, Evelyse. ‘The Structural Architecture of Blockchain and Web3 Systems: Layered Analysis for Legal and Regulatory Classification’. DA-02. ECR-Digital Assets Series. Published through MoroAK Professional Knowledge Infrastructure, 2026. Available at moroak.com.
    Carvalho-Ribas, Evelyse. ‘Blockchain, Web3 and Digital Assets: Legal Ontology, Governance Complexity, and the Limits of Analogical Regulation’. DA-01. ECR-Digital Assets Series. Published through MoroAK Professional Knowledge Infrastructure, 2026. Available at moroak.com.
    Armour J and others, Principles of Financial Regulation (OUP 2016).
    Bank for International Settlements, Sound Practices: Implications of Fintech Developments for Banks and Bank Supervisors (2018).
    Brummer C, Cryptoassets: Legal, Regulatory, and Monetary Perspectives (OUP 2019).
    Council Directive (EU) 2023/2226 of 17 October 2023 amending Directive 2011/16/EU (DAC8), OJ L 2023/2226, 24.10.2023.
    De Filippi P, Wright A, Blockchain and the Law: The Rule of Code (Harvard University Press 2018).
    Directive 2014/65/EU (MiFID II), OJ L 173, 12.6.2014.
    Directive (EU) 2015/2366 (PSD2).
    EU Commission, ‘Digital Finance Strategy for the EU’ COM(2020) 591 final, 24 September 2020.
    ESMA, ‘Markets in Crypto-Assets Regulation: First Consultation Package’ (ESMA75-453128700-438, 12 July 2023).
    ESMA, ‘Markets in Crypto-Assets Regulation: Second Consultation Package’ (ESMA75-453128700-478, 5 October 2023).
    FATF, ‘Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers’ (October 2021).
    FATF, ‘Targeted Update on Implementation of the FATF Standards on Virtual Assets and VASPs’ (June 2024).
    FCA, ‘Guidance on Cryptoassets’, Policy Statement PS19/22 (July 2019).
    FCA, ‘Financial promotion rules for cryptoassets’, Policy Statement PS23/6 (June 2023).
    FCA v Capital Alternatives Ltd [2015] EWCA Civ 284.
    Ferran E, ‘The Break-Up of the United Kingdom and the European Union: Brexit and the Future of UK Financial Regulation’ (2017) 17 Journal of Corporate Law Studies 1.
    Financial Services and Markets Act 2000 (c.8).
    Financial Services and Markets Act 2023 (c.29).
    Hacker P, Thomale C, ‘Crypto-Securities Regulation: ICOs, Token Sales and Cryptocurrencies under EU Financial Law’ (2018) 15 European Company and Financial Law Review 645.
    Lange B, Governing Blockchain: Regulatory Frameworks and Policy Challenges (Edward Elgar 2023).
    Law Commission of England and Wales, Digital Assets (Law Com No 412, June 2023).
    Loi n° 2019-486 du 22 mai 2019 (loi PACTE) (France).
    Lumineau F, Wang W, Schilke O, ‘Blockchain Governance — A New Way of Organizing Collaborations?’, Organization Science 32(2) 500 (2021).
    Moloney N, EU Securities and Financial Markets Regulation (3rd edn, OUP 2014).
    OECD, Crypto-Asset Reporting Framework and Amendments to the Common Reporting Standard (OECD 2023).
    Property (Digital Assets etc) Bill [HL], introduced 11 September 2024.
    Regulation (EU) 2023/1113 (Transfer of Funds Regulation, recast), OJ L 150, 9.6.2023.
    Regulation (EU) 2023/1114 on Markets in Crypto-assets (MiCA), OJ L 150, 9.6.2023.
    Walch A, ‘Deconstructing “Decentralization”: Exploring the Core Claim of Crypto Systems’ in C Brummer (ed), Crypto Assets: Legal and Monetary Perspectives (OUP 2019).
    Zetzsche DA, Annunziata F, Arner DW, Buckley RP, ‘The Markets in Crypto-Assets Regulation (MiCA) and the EU Digital Finance Strategy’ (2021) 16 Capital Markets Law Journal 203.
    Zetzsche DA, Arner DW, Buckley RP, ‘Decentralized Finance’ Journal of Financial Regulation 6(2) 172–203 (2020).

    Carvalho-Ribas, Evelyse. ‘Regulating Digital Assets in the European Union and the United Kingdom: MiCA, MiFID, FSMA and the Governance Gap’. DA-03. ECR-Digital Assets Series. Published through MoroAK Professional Knowledge Infrastructure, 2026. Available at moroak.com.

    ECR Logo
    Evelyse Carvalho-Ribas · Regulating Digital Assets in the European Union and the United Kingdom: MiCA, MiFID, FSMA and the Governance Gap · DA-03 · © 2026

    Unlock the Learning Journey

    Sign in to track your progress, earn XP, generate AI summaries and quizzes, and build your learning streak.

    Sign In