The regulatory examination chain
Not “is DeFi regulated”, but: which activity, which entity, which jurisdiction, which framework — and what stays open.
This lesson has had no expert review. It was written for this platform and against the evidence it cites; nobody has gone through it independently.
Learning objectives
- You can decompose a regulatory question into the four steps of the examination chain.
- You can identify where in the chain a statement without a source and a date is worthless.
Check your prior knowledge
Answer these for yourself before reading on. Wherever you hesitate is where this lesson pays off.
- What makes an activity subject to authorization?
- Who is the addressee of a supervisory obligation?
- What changes when the same activity happens in a different jurisdiction?
Core concept
The question “is DeFi regulated” has no answer
Regulation addresses activities and entities, not technologies. “DeFi” is neither. Only a chain is answerable: which activity is actually being performed? Is there an identifiable entity performing it? In which jurisdiction? Which framework would be in scope there for that activity? Each step can come out “open” — and that is a result, not an interim state.
The European framework exists and is still developing
For crypto-assets and certain related services, Regulation (EU) 2023/1114 (MiCA) applies in the EU. At the same time the European Commission is running a targeted consultation on reviewing that framework. Both belong in the same statement: there is a framework, and it is explicitly under review. Naming only the first suggests stability; naming only the second suggests a vacuum.
Classification in a given case is a legal question
That a framework exists does not say how a particular arrangement falls under it. That classification is a case-by-case legal question and is not answered here — neither by this lesson nor by this platform. What the analysis can and must do: keep the four steps apart, attach a source and a date to every statement, and mark open points as open, so the legal function starts in the right place.
Definitions
- MiCA
- Regulation (EU) 2023/1114 on markets in crypto-assets.
- Authorization requirement
- The requirement to hold supervisory authorization for a given activity.
- Regulatory perimeter
- The boundary between activities a framework captures and those it does not.
Model
Activity — what is actually being done?
Entity — who does it, and is it identifiable?
Jurisdiction — where, on what connecting factor?
Framework — which would be in scope there?
Uncertainty — what stays open, and why?
Worked example
The same position, two chains
- Case A
- custody and trading through an authorized firm in the EU
- Case B
- the same economic position, entirely on-chain, no entity identifiable
- Step 1 — activity
- the same in both cases
- Step 2 — entity
- A: nameable; B: open
In case B the chain already stops at step 2. Without an identifiable entity, steps 3 and 4 cannot be answered meaningfully.
A: four steps answerable. B: step 1 answered, step 2 open — a result, not an omission.
Reading: “Step 2 open” does not entail “unregulated”. It entails that the question cannot be decided at this level and belongs with the legal function — in exactly those words.
Retrieval
Exercise on real data
Look at the two MiCA entries and read their “does not establish” field in particular. Note which question the source answers — and which it specifically does not.
Look at the regulatory evidence records →Compare the dimension's guiding questions with the five steps above and record where this platform explicitly supplies no data.
Dimension 11: regulation →Application
Write the regulatory section of an analysis for an on-chain lending position — five lines, without deciding a legal question.
Related case studies
Institutional reading
- Bank
- Which authorization would the planned activity require, and does the institution hold it?
- Insurance
- What supervisory treatment would the position receive under one's own regime?
- Advisory
- Which duties does merely raising this with a client already trigger?
Key takeaways
- Regulation addresses activities and entities, not technologies.
- A framework exists and is under review at the same time — both belong in the same statement.
- A missing finding is not a negative finding.
Evidence
- EVD-2026-0006
Amtsblatt der Europäischen Union / EUR-Lex — Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA), OJ L 150, 9.6.2023, p. 40–205
- EVD-2026-0007
Europäische Kommission, GD FISMA — Targeted consultation on the review of the MiCA Regulation