Crypto World

MiCA Targets DeFi Vaults, But Compliance Could Be Hard to Apply

Published

on

European regulators are weighing whether parts of crypto lending and DeFi should be brought closer to the same regulatory perimeter that already covers more conventional crypto activities. In a targeted consultation connected to the review of the Markets in Crypto Assets (MiCA) framework, the European Commission specifically flagged DeFi and crypto lending and borrowing as areas that were left outside the original rulebook.

The debate is likely to intensify around “lending vaults” — on-chain structures that can funnel large pools of assets into credit markets while avoiding many of the hallmarks of a traditional lender. Their legal treatment, stakeholders say, has often relied on non-binding interpretations that the structures may fall outside MiCA and certain EU fund rules, leaving important questions unresolved about who, exactly, is responsible and what should be regulated.

Key takeaways

  • The European Commission’s MiCA review consultation asks stakeholders to address gaps that were not fully covered when MiCA was first drafted, including DeFi and crypto lending/borrowing.
  • Lending vaults remain difficult to classify because they can distribute roles across smart contracts and multiple participants rather than operating through a single, clearly identifiable service provider.
  • Legal experts argue that regulators should avoid collapsing “DeFi lending” into a single bucket, since different vault designs can have materially different economic functions and control dynamics.
  • Several viewpoints in the consultation discourse emphasize using structural and control-based criteria—rather than a broad “decentralization” test—to decide whether regulation should apply.
  • If lending is added explicitly to MiCA’s regulated services, industry participants will need clarity on compliance expectations that match how vault-based systems actually work.

Brussels revisits MiCA gaps around lending and DeFi

On May 20, 2026, the European Commission opened a targeted consultation seeking stakeholder input on areas that were not fully covered by the original MiCA framework. According to the Commission’s consultation, topics include decentralized finance and crypto lending and borrowing, among other issues.

The importance of this step is practical: MiCA was designed to standardize rules for crypto asset services across the EU, but it did not neatly resolve whether and how every lending model—especially those built with on-chain components—fits into the existing regulatory categories.

In the case of lending vaults, the current uncertainty is not simply academic. Vaults can route liquidity into lending markets while using multi-participant governance or modular contract logic to separate economic functions from operational roles. As a result, their regulatory classification can end up depending on informal interpretations and lawyer-led “functional” analysis—an approach many consider insufficiently predictable.

Advertisement

Why “vault” design complicates regulation

One reason regulators may struggle is that there is no universally recognized legal category for a “vault.” As Yuriy Brisov, an EU digital assets lawyer and partner at Digital & Analogue Partners, put it, EU law does not define a “vault” as a standalone concept; instead, lawyers determine how a structure should be treated by analyzing what it does and how it is controlled.

That matters because vaults can perform lending-like economic functions while spreading activities across smart contracts and different roles. Brisov’s point is that the “label” is less important than the function and the governance/control model—especially when the structure can look unlike a conventional entity offering loans.

Protocol design provides an example of why mapping to existing legal categories can be hard. Morpho’s lending infrastructure describes a Vault V2 setup that divides responsibilities between an owner, curator, allocator, and sentinel. The curator configures strategy and risk parameters, the allocator performs allocations, and the sentinel role is intended to reduce risk. While this architecture does not, on its own, define a regulated lending service under MiCA, it illustrates how “provider” responsibilities may not be concentrated in a single party.

Separately, a client update referenced in the discussion by Jonathan Galea of Cahill Gordon & Reindel highlights that lending vaults can intersect multiple regulatory domains. The analysis points to how vault structures might sit across MiCA, stablecoin-related rules, and EU fund law—again underscoring that vaults cannot be understood using a single regulatory lens.

Advertisement

A warning against one-size-fits-all “DeFi lending”

Beyond classification mechanics, stakeholders also appear concerned about the way any future rules might be framed. Galea’s view, as reflected in the referenced update, is that policymakers should be cautious about treating lending vaults as a single category. In his framing, lending vaults “solve more practical problems than they create,” but they are not uniform: some vaults may direct liquidity into lending markets, while others may instead buy and sell crypto assets, requiring different treatment.

The core risk, Galea argues, is that broad-brush regulation could capture fundamentally different economic activities under the same label. If “DeFi lending” were brought into the perimeter as a single category, structures with different roles and functions could end up facing the same answers—despite being designed for different outcomes.

This is not merely a technicality. In practice, regulatory uncertainty affects how developers design protocols and how users evaluate risk. A framework that fails to distinguish between lending-like operations and asset-trading-like operations could either over-regulate some systems or miss the activities that actually warrant closer oversight.

What criteria should determine whether vault-based lending is regulated?

MiCA already contains an important carve-out: crypto asset services provided in a “fully decentralized manner” are excluded, while MiCA can still apply when only part of an activity is decentralized. But even that concept is likely to be contentious for vault-based systems, where decentralization can be partial or evolve over time.

Advertisement

Galea cautions that using decentralization as the dividing line could penalize newer protocols. In his view, decentralization is a spectrum and a function of time; a test that relies on it could entrench incumbent projects that have had years to distribute control.

Brisov’s alternative emphasis is on structural facts and user exit rights. He suggests that the “safer ground” is structural rather than rhetorical: whether there is an undertaking or appointed manager, whether token or claim holders have a direct coded claim on the pool, and whether users can exit before parameter changes take effect.

He also argues that if lending and borrowing are meant to be regulated, Brussels should explicitly add them to the list of regulated crypto asset services, rather than widening the definition of a crypto asset service provider itself. That distinction matters because it shapes how narrowly or broadly compliance obligations would be interpreted.

Michael Egorov, founder of Curve Finance, adds another angle: if DeFi lending becomes regulated, he argues it should be treated “completely differently” from traditional lending. Egorov’s position is that DeFi may not require certain safeguards that are intrinsic to conventional lending, while still potentially needing other protections that are better tailored to on-chain market structure. He suggests that a dedicated framework could improve safety and accessibility for new users, while also avoiding rules that some protocols could be unable to comply with due to how they are constructed.

Advertisement

What happens next as the consultation closes

The Commission’s consultation is scheduled to close on Sept. 30. What follows will likely determine whether lending vaults remain outside MiCA’s regulatory scope—or whether regulators move toward an explicitly tailored framework for crypto lending and borrowing.

For participants across DeFi and crypto lending, the key unknown is not just whether regulation arrives, but how Brussels will draw the lines between different vault designs and the roles of the parties behind them. As the EU works through consultation feedback, builders and users should watch for signals on the criteria regulators intend to use—especially around structural control, responsibility allocation, and how user exit rights and economic functions map onto any future obligations.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement

Source link

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version