The Commission asked
Which of the following issues are most significant?
| Provision or item | Rating |
| crypto-asset token in compliance | 3 (moderate) |
| tokenised financial instrument in compliance | 3 (moderate) |
| earmarking etc) over a token, | Column 2 of 6 (scale label not machine-verified, see form page 111) |
| Recognising ownership in a token towards third-parties | 3 (moderate) |
| Using tokens as collateral | Column 4 of 6 (scale label not machine-verified, see form page 111) |
| differentiate between native and non-native | 3 (moderate) |
| Recognising tokens as objects of | Column 4 of 6 (scale label not machine-verified, see form page 111) |
| token holders in intermediated | Column 4 of 6 (scale label not machine-verified, see form page 111) |
| of rights arising from /over tokens or the | Column 4 of 6 (scale label not machine-verified, see form page 111) |
| Custody of tokens | Column 5 of 6 (scale label not machine-verified, see form page 112) |
| tokens in insolvency proceedings including | 3 (moderate) |
| risk Others | Column 6 of 6 (scale label not machine-verified, see form page 112) |
Don't
Issuing a
with national
law
Issuing a
with national
law
Transferring
ownership (acquisitions,
dispositions,
including
good faith
acquisition /
bona fide
ownership
Possibility to
tokens in
national law
property
Rights of
custody
chains
Enforcement
and exercise underlying
assets
Treatment of
intermediary
Please explain your answers to question 80.1 and provide examples from national law. In particular specify if any of the answers is specifically referring to native or non-native tokens and specify if any of the answers would be different depending on if the token is recording a tokenised financial instrument or crypto-assets:
There is material uncertainty because technical control of a token and legal ownership are not always the same thing. This is a fundamental trust problem: the ledger can prove who controls a key while the law may assign the underlying right elsewhere. Priority should therefore be given to ownership/entitlement, third-party effect, custody, insolvency and enforceability. Yes. The most significant uncertainty is the gap between a cryptographic fact and a legal fact.
Control of a private key can demonstrate the technical ability to transfer a token. It does not necessarily establish legal ownership, beneficial entitlement, authority to dispose of the asset, or the rights of third parties. This distinction becomes critical in theft, compromised keys, delegated authority, custody, collateral, inheritance and insolvency.
German law provides a useful comparison. The Electronic Securities Act (eWpG) deliberately creates legal certainty for electronic securities within its scope. An electronic security generally has the same legal effect as a certificated security and is treated as a “thing” for purposes of §90 BGB. The Act identifies the registered holder, provides rules for transfers and good-faith acquisition, and establishes an applicable-law rule for rights in electronic securities.
That is useful precisely because it demonstrates the remaining problem. The law has deliberately mapped particular tokenised financial instruments into a defined legal architecture. The same certainty does not automatically follow for every native crypto-asset simply because cryptographic ownership or transfer can be demonstrated. I therefore distinguish native and non-native tokens.
For a non-native token representing a security, deposit, claim, real-world asset or other off-chain right, the critical question is what legal right the token represents and whether transfer of the token actually transfers that underlying right. The token and the legal claim cannot simply be assumed to be identical.
For a native crypto-asset, there may be no separate issuer or underlying off-chain asset. The central questions instead concern whether the token itself is recognised as property, when ownership legally transfers, the effect of theft or unauthorised transfer, good-faith acquisition, collateral, competing third-party claims and insolvency.
Intermediated custody creates another layer. The law should distinguish clearly between ownership of an asset, a contractual claim against an intermediary and beneficial entitlement to assets held collectively. Insolvency is where ambiguity in that trust relationship becomes most dangerous.
The objective should not be to force every token into the legal model developed for traditional securities. It should be to make the legal consequences of the architecture predictable.
Cryptographic control, legal ownership, beneficial entitlement and authority to dispose should not be treated as automatically synonymous.
That distinction will become even more important as smart accounts, multisignature arrangements and autonomous agents increasingly exercise technically valid authority over assets without necessarily possessing beneficial ownership or unlimited legal authority.
Original form, page 110. Open PDF
The Commission asked
What is the urgency with which each issue should be addressed by regulators?
| Provision or item | Rating |
| Issuing a crypto-asset token in compliance with national law | 2 (low urgency) |
| Issuing a tokenised financial instrument in compliance with national law | 2 (low urgency) |
| Transferring ownership (acquisitions, dispositions, earmarking etc) over a token, including good faith acquisition / bona fide ownership | 2 (low urgency) |
| Recognising ownership in a token towards third-parties | 3 (moderate urgency) |
| Using tokens as collateral | 4 (high urgency) |
| Possibility to differentiate between native and non-native tokens in national law | 3 (moderate urgency) |
| Recognising tokens as objects of property | 3 (moderate urgency) |
| Rights of token holders in intermediated custody chains | 4 (high urgency) |
| Enforcement and exercise of rights arising from /over tokens or the underlying assets | 4 (high urgency) |
| Custody of tokens | Column 5 of 6 (scale label not machine-verified, see form page 115) |
| Treatment of tokens in insolvency proceedings including intermediary risk | 4 (high urgency) |
| Others | Column 6 of 6 (scale label not machine-verified, see form page 115) |
Please explain your answers to question 80.2 and provide examples from national law. In particular specify if any of the answers is specifically referring to native or non-native tokens and specify if any of the answers would be different depending on if the token is recording a tokenised financial instrument or crypto-assets:
The highest urgency should be attached to the questions that determine what a person actually owns and what happens when something goes wrong: property status, transfer, third-party effect, custody, enforcement and insolvency.
These are more fundamental than adding further rules governing issuance.
Again, Germany provides a useful example. The eWpG creates explicit legal effects for electronic securities within its scope, including rules concerning registered ownership, transfer, good-faith acquisition and applicable law. That demonstrates that technological innovation does not require abandoning private-law certainty.
But the solution should not be to require every digital asset to enter an approved register or intermediary structure before receiving legal recognition.
That would solve legal uncertainty by creating another permission architecture.
Native crypto-assets require particular attention because there may be no issuer, register operator or underlying off-chain claim around which traditional private law can organise itself. The law should be capable of recognising ownership and resolving competing claims without manufacturing an intermediary merely because existing legal concepts find an intermediary convenient.
Non-native tokens present a different problem. Where a token represents a security or another off-chain asset or claim, legal certainty is required concerning the relationship between the token and the represented right. A technically valid token transfer should not leave the parties uncertain whether the underlying legal entitlement moved with it.
Custody and insolvency are immediately important because they determine whether someone actually owns an asset or merely holds a claim against an intermediary when that intermediary fails.
I would also treat the distinction between cryptographic control, ownership and delegated authority as an immediate issue.
Possession of a valid signing key establishes technical capability. It should not automatically establish beneficial ownership or unlimited legal authority.
This distinction already matters for custodians, multisignature arrangements, compromised wallets and delegated keys. It will become considerably more important as autonomous software and AI agents transact through smart accounts on behalf of human and institutional principals.
Europe has an opportunity here to provide genuine scaffolding: clear property rights, predictable transfer rules, enforceable ownership, clear treatment of custody and insolvency, and legal recognition of delegated authority. That increases freedom rather than restricting it.
Legal certainty should tell people what their rights are when they choose an architecture. It should not determine which architecture they are allowed to choose.
Original form, page 114. Open PDF
The Commission asked
What are the 3 most important elements that should be addressed in EU law ? Please explain your answer and provide examples: Most important element number 1:
Ownership/property status and effect against third parties
EU law should clearly establish whether and when a token is an object of property, who legally owns it, and whether that ownership is enforceable against third parties.
Cryptographic control and legal ownership should not automatically be treated as synonymous. Possession of a private key demonstrates technical ability to transfer an asset, but it does not necessarily establish beneficial ownership or legal authority to dispose of it. This distinction matters for theft, compromised keys, multisignature arrangements, delegated authority and increasingly autonomous agents.
Germany's eWpG provides a useful example for electronic securities. Qualifying electronic securities are given the same legal effect as certificated securities and are treated as objects of property under §90 BGB. EU law should provide comparable certainty for digital assets across borders without requiring every token to adopt the institutional architecture of a traditional security.
For native crypto-assets, legal recognition should not depend on the existence of an issuer, custodian or authorised register operator. For non-native tokens representing an off-chain asset or claim, the law should clearly establish the relationship between ownership of the token and ownership or entitlement to the represented asset.
Legal recognition of ownership is scaffolding. It should protect the individual's rights, not become leverage for requiring an approved ledger, custodian or token architecture.
Most important element number 2:
Transfer, including good-faith acquisition and unauthorised transfers
EU law should establish predictable rules for when ownership of a token legally transfers, the consequences of an unauthorised transfer, competing claims, and whether and under what circumstances good-faith acquisition is possible.
A blockchain can establish with considerable certainty that a transaction occurred. It cannot by itself establish that the person controlling the signing key was the beneficial owner or possessed legal authority to make that transfer.
Germany's eWpG again provides a useful example. It expressly defines requirements for transferring electronic securities and provides rules for good-faith acquisition. Similar legal certainty is needed across the EU for digital assets.
The treatment should recognise the difference between native and non-native tokens. For a native crypto-asset, the principal question may be whether transfer of the token transfers the property itself. For a token representing a security, deposit or other off-chain claim, EU law must additionally establish whether transfer of the token transfers the represented legal right.
The objective should be to make the legal consequences of a voluntary transaction predictable, not to require transactions to occur through an approved intermediary simply because intermediated transactions are easier for regulators to categorise.
Most important element number 3:
Custody and insolvency treatment
EU law should clearly establish the rights of token holders when assets are held through an intermediary and what happens to those assets if the intermediary becomes insolvent.
A holder should be able to know whether they legally own the underlying token, possess a beneficial interest in segregated assets, or merely hold a contractual claim against the custodian. The law should also make clear whether assets may be rehypothecated, how shortfalls are allocated, and how additional intermediaries in a custody chain affect those rights.
Germany's eWpG demonstrates one approach by expressly addressing individual and collective registration of electronic securities and the legal position of holders within those structures. The broader EU problem is ensuring that custody does not make ownership ambiguous precisely when the intermediary fails.
This is especially important because self-custody and intermediated custody represent fundamentally different trust relationships. In self-custody, the individual retains technical control and accepts the vulnerabilities associated with that control. In intermediated custody, authority is deliberately transferred to another party and additional counterparty and insolvency risks are created.
EU law should protect people when they choose that intermediary relationship. It should not use those protections to make intermediation mandatory. The goal should be clear rights in failure, not regulation that eliminates the ability to avoid intermediary risk in the first place.
Original form, page 117. Open PDF
The Commission asked
There are different “ ownership models ” that could be used to increase legal certainty over tokens. Please indicate maximum two models listed below that you think EU law could apply if it were to improve the legal certainty of tokens in the EU: Maximum 2 selection(s) Please select as many answers as you like MODEL 1: The token is the asset by law, the law recognises a ledger-based asset and the ownership rights are constituted directly by the ledger entry. MODEL 2: The token is the asset by law, where the law recognises that e.g. securities (dematerialised or physical) can be replaced by an entry into a DLT register and by this “replacing” (immobilisation) of the securities the function of the initial security is substituted by entry into a DLT register and the ownership rights are constituted by the representation on the ledger.
- Selected
- MODEL 3: Token is the asset by law. In this case the law does not actively
- Selected
- MODEL 4: The token is the legal carrier of rights associated with a related (often
- MODEL 3 - b) Is it preferable to establish constitutive rules of ownership
- Functional rules regulating the effects of recording an asset on chain
- MODEL 3 - c) Are the different ownership models better suited for native or
- For native
- MODEL 3 - d) Can the same ownership model be implemented for all types
- No
- MODEL 4 - b) Is it preferable to establish constitutive rules of ownership
- Functional rules regulating the effects of recording an asset on chain
- MODEL 4 - c) Are the different ownership models better suited for native or
- For non-native tokens
- MODEL 4 - d) Can the same ownership model be implemented for all types
- No
MODEL 3: Token is the asset by law. In this case the law does not actively regulate legal aspects such as what property is or how transfer of ownership occurs etc. but instructs on the legal consequences of entries in a DLT register (this is often called a functional approach). The law could at EU level stipulate who may exercise rights, i.e. the person recorded in the DLT register as holder of a tokenised asset, that these rights have full third-party effect and protects from competing claims. This also creates legal certainty for collateral use. The EU law would create a uniform rule of “digital entitlement” that functions across all Member States’ property law structures. MODEL 4: The token is the legal carrier of rights associated with a related (often off-chain) asset. The law defines tokens as legal objects that do not create new rights, but can –like a “container” –represent various kinds of rights, such as membership rights, ownership, intellectual property rights, usage rights or rights of lien etc. The token would represent the rights stemming from the underlying assets and the law would ensure that the transfer of a token on the ledger legally transfers ownership of the rights stemming from the underlying asset. (Inspired by Lichtenstein Law . Art 2 TVTG defines token as a piece of information on a TT System which can represent claims or rights of memberships against a person, rights to property, or other absolute or relative rights. Art 5 TVTG states that the TT Key holder has the power of disposal over the Token. It is further assumed that the person possessing the power of disposal over a Token also has the right to dispose of the Token. For every previous holder of the power of disposal, it is presumed that he was the person possessing the right of disposal at the time of this ownership). MODEL 5: Any other legal ownership structures, for example based on the approaches taken by different countries, including France, Germany, Luxembourg or adopted in other jurisdictions or internationally, that could be implemented in EU law. You selected: MODEL 3 - a) What would be the legal interoperability of any such EU level measure with national private laws of Member States, or at least laws of the Member State that you are familiar with?
I favor the functional approach in Model 3 for native on-chain assets and the rights-carrier approach in Model 4 where a token represents an off-chain asset or claim. The law should not pretend every token has the same ontology. What matters is that the holder can determine what right the token carries, against whom, and what legal consequence follows from transfer. Model 3 appears capable of interoperating with German private law and, in my view, offers a useful route to EU- wide legal certainty precisely because it need not replace national property law wholesale.
Germany's eWpG already demonstrates a functional bridge between an electronic register and existing private law. It gives electronic securities the same legal effect as certificated securities, treats them as objects of property under §90 BGB, identifies the registered holder and provides rules governing transfer and good-faith acquisition.
An EU rule of digital entitlement could perform a similar function across Member States: establish defined legal consequences of an on-chain record, including who may exercise rights, third-party effect and protection against competing claims, while leaving broader national property-law systems intact where possible.
The important limitation is that the EU rule should not require an authorised intermediary or centrally approved register merely to obtain legal recognition. A genuinely decentralised ledger must be capable of producing legally recognised evidence and legal effects without the law manufacturing a gatekeeper where the architecture itself has none.
EU law should create interoperability between technical fact and legal consequence, not use legal recognition as leverage to prescribe the technical architecture.
MODEL 3 - b) Is it preferable to establish constitutive rules of ownership based on the asset being recorded on chain or functional rules regulating the effects of recording an asset on chain? Constitutive rules of ownership based on the asset being recorded on chain Functional rules regulating the effects of recording an asset on chain Don’t know / no opinion / not applicable Please explain your answer to MODEL 3 b):
I prefer functional rules regulating the legal effects of recording an asset on-chain.
A constitutive rule stating that the blockchain record itself conclusively creates ownership risks collapsing several different concepts into one: cryptographic control, registration, beneficial ownership and legal authority.
They are not always the same.
A stolen private key can produce a technically valid transaction. A custodian can control keys without beneficially owning the assets. A multisig participant can possess signing authority without ownership. An autonomous agent may be authorised to execute transactions within a limited mandate without owning the assets it controls.
The law should therefore specify what legal consequences follow from an on-chain record while preserving mechanisms for dealing with theft, fraud, mistake, delegated authority, competing claims and good-faith acquisition.
The ledger can provide exceptionally strong evidence of what occurred technically. The law should determine the legal consequences of that fact rather than pretending the technical fact answers every legal question.
This is also more technologically neutral. It recognises the evidentiary and transactional properties of DLT without making a particular technical record the source of every underlying legal right.
MODEL 3 - c) Are the different ownership models better suited for native or non-native tokens? For native For non-native tokens Don’t know / no opinion / not applicable Please explain your answer to MODEL 3 c):
Model 3 is particularly well suited to native tokens.
For a genuinely native crypto-asset there may be no separate off-chain asset, issuer or legal claim represented by the token. The token is the asset.
In that situation, creating legal consequences around the on-chain record is considerably more natural than attempting to locate an underlying off-chain right that does not exist.
Bitcoin and Ether are obvious examples conceptually: the asset exists natively within the relevant network rather than functioning as a digital receipt for an external asset.
The law should therefore be capable of recognising digitally native property on its own terms.
That does not mean that the ledger should conclusively determine every legal question. Theft, compromised keys, inheritance, insolvency, delegated authority and competing claims can still require legal rules. But those rules should operate around the native asset rather than pretending it represents something outside the network.
MODEL 3 - d) Can the same ownership model be implemented for all types of tokens (crypto-assets and DLT financial instruments)? Yes No Don’t know / no opinion / not applicable MODEL 3 - d) What would need to be different depending on the type of the token?
The same ownership model should not be imposed identically on all tokens because native and non-native tokens represent fundamentally different legal relationships.
For a native crypto-asset, the token can itself be the object of property. There may be no external issuer, security, deposit, physical asset or contractual claim behind it.
For a tokenised financial instrument, the token generally represents or carries rights that already exist within a wider legal relationship: rights against an issuer, shareholder rights, repayment rights, claims to assets or other legally defined entitlements.
EU law should therefore establish common principles of digital entitlement, transfer, third-party effect, custody and insolvency while allowing the legal consequences to reflect what the token actually is.
Technological similarity should not erase legal difference.
Please explain your answers for MODEL 3 and provide examples:
Model 3 is strongest for native digital assets because it allows law to recognise legal consequences of a digital record without inventing an underlying off-chain asset.
Germany's eWpG demonstrates that national private law can successfully connect electronic registration to property-law consequences. It expressly recognises qualifying electronic securities as property and establishes rules for ownership transfer and good-faith acquisition.
I would extend the principle, but not necessarily the institutional architecture.
A public permissionless ledger should not require an authorised central register operator merely to receive legal recognition. The useful principle is that a reliable digital record can have predictable legal effects.
The law should then address the exceptional cases the ledger cannot resolve by itself: theft, fraud, compromised authority, good-faith acquisition, inheritance, insolvency and competing claims.
The objective should be legal recognition of digital property, not regulatory ownership of its infrastructure.
You selected: MODEL 4 - a) What would be the legal interoperability of any such EU level measure with national private laws of Member States, or at least laws of the Member State that you are familiar with?
Model 4 should be capable of interoperating with German private law, but it requires greater care because the token and the underlying right are legally distinct things unless legislation expressly connects them.
This model is particularly useful where a token represents a security, ownership interest, intellectual-property right, lien, claim against an issuer or another off-chain entitlement.
EU law could establish that a valid transfer of the token transfers the associated legal right, giving the token a legally recognised carrier function across Member States.
Germany's eWpG demonstrates a related approach for electronic securities: §25 provides that transfer of ownership of the electronic security also transfers the right arising from that security.
EU harmonisation could provide similar certainty across borders.
However, the underlying right still matters. A token representing shares, a debt claim, real estate, intellectual property or a bank deposit cannot automatically override every substantive rule governing those different assets.
The objective should therefore be legal interoperability between the token and the underlying right, not the fiction that tokenisation makes every underlying asset legally identical.
MODEL 4 - b) Is it preferable to establish constitutive rules of ownership based on the asset being recorded on chain or functional rules regulating the effects of recording an asset on chain? Constitutive rules of ownership based on the asset being recorded on chain Functional rules regulating the effects of recording an asset on chain Don’t know / no opinion / not applicable Please explain your answer to MODEL 4 b):
I prefer functional rules here even more strongly than under Model 3.
For a non-native token, recording something on-chain cannot by itself determine every aspect of ownership because an underlying legal right exists outside the ledger.
A token representing a share, bond, property interest, intellectual-property right or other claim should have clearly defined legal consequences when transferred. Ideally, the law should make the connection sufficiently strong that transferring the token reliably transfers the represented right.
But the ledger cannot determine whether the underlying right existed validly in the first place, whether the issuer possessed authority to tokenise it, or whether mandatory rules governing that asset have been satisfied.
Functional rules can create a strong legal bridge between token and underlying right without pretending that the digital representation creates reality simply by being written to a ledger.
MODEL 4 - c) Are the different ownership models better suited for native or non-native tokens? For native For non-native tokens Don’t know / no opinion / not applicable Please explain your answer to MODEL 4 c):
Model 4 is naturally suited to non-native tokens because its purpose is to make the token the legal carrier of a right or asset that exists outside the token itself.
Examples include tokenised bonds, shares, deposits, intellectual-property rights, claims against an issuer, liens or interests in physical assets.
The important legal function is to make the relationship between token and represented right unambiguous.
If I acquire the token, I should know whether I acquired the underlying right.
If I transfer the token, I should know whether that right transferred.
If the issuer becomes insolvent, I should know whether I own an asset, possess a secured claim or merely stand among unsecured creditors. That is fundamentally different from a native crypto-asset, where there may be no separate underlying right for the token to carry.
MODEL 4 - d) Can the same ownership model be implemented for all types of tokens (crypto-assets and DLT financial instruments)? Yes No Don’t know / no opinion / not applicable MODEL 4 - d) What would need to be different depending on the type of the token?
The same model should not be imposed on every token.
For a native crypto-asset, the token itself can be the property. There is no need to invent an underlying right for it to carry.
For a non-native token, the legal architecture must define the relationship between the token and the underlying asset or claim.
For tokenised financial instruments specifically, existing substantive rights and obligations under securities, corporate and financial law continue to matter. Tokenisation should provide a new means of recording, holding and transferring those rights rather than silently changing their substantive content.
The common EU layer should therefore concentrate on legal certainty around digital entitlement, transfer, third- party effect, custody and insolvency, while the specific legal consequences reflect the nature of the underlying asset.
The law should follow the actual relationship rather than forcing different relationships into one model merely because they use the same technology.
Please explain your answers for MODEL 4 and provide examples:
Model 4 provides a useful legal bridge between DLT and existing property and financial law for non-native assets.
A tokenized bond should reliably carry the rights of the bond. A tokenized share should reliably carry the relevant shareholder rights. A token representing another asset or claim should tell the holder precisely what legal entitlement travels with the token.
Germany's eWpG provides a useful example. For qualifying electronic securities, German law connects ownership of the electronic security with the right arising from that security and establishes rules governing transfer and good-faith acquisition.
The EU could create comparable cross-border certainty without requiring every token to pass through one prescribed institutional architecture.
This distinction between Model 3 and Model 4 is important.
For a native asset, the token may be the thing.
For a non-native asset, the token may carry rights to something else.
Those are different trust relationships and should not be collapsed simply because both are represented using DLT.
The strongest EU framework would recognize that distinction while providing interoperable rules for ownership, transfer, third-party effect, custody and insolvency.
Again, the purpose should be scaffolding: make rights clear and enforceable while preserving architectural choice.
Original form, page 121. Open PDF
The Commission asked
Interested parties that wish to bring other relevant issues, not raised in this consultation, to the Commission’s attention, should feel free to communicate them here:
The greatest issue this review needs to address is not any single MiCA provision. It is the architecture created when they are assembled.
MiCA should be considered alongside Europe's wider direction in digital identity, tokenized finance and settlement, including Pontes and Appia. Licensing, certification, identity, stablecoin, protocol-access, custody and settlement rules can each be justified individually. Together they can create something very different.
A system does not need to prohibit alternatives to eliminate meaningful choice. It can make the cost of exercising them progressively prohibitive.
If participation increasingly requires an approved intermediary, identity, asset, protocol or settlement route, individuals may retain theoretical freedom while losing practical freedom.
The walk-away test has failed.
This is the Double-Edged Sword problem. Technologies that make relationships more verifiable can also make control extraordinarily efficient.
Cryptographic verification is not itself trust.
Trust is willingly accepted vulnerability in the presence of risk. Where vulnerability is compulsory and meaningful exit has disappeared, the relationship is not trust. It is control.
I am therefore particularly concerned by proposals involving certification of DeFi protocols and non-custodial wallets, embedded compliance mechanisms and restrictions on CASPs connecting customers to uncertified protocols.
Certification can produce useful evidence. It should not automatically become permission.
Non-custodial software does not possess the authority of a custodian. A genuinely decentralized protocol does not possess the authority of an intermediary. If nobody can seize assets, reverse transactions, unilaterally change the protocol, custody funds or decide participation, regulation should not require someone to acquire those powers merely to create an identifiable party capable of regulatory control.
That changes the trust architecture itself.
The same applies to money and settlement. Central-bank money for tokenized settlement and interoperability can provide value. But providing an option is different from designing the regulatory environment until it becomes the only economically viable destination.
Europe should not confuse strategic autonomy with architectural enclosure. Nor should institutional permission be confused with safety. European supervisors continue to document serious deficiencies and control failures within regulated financial institutions. Regulation can reduce particular risks. It does not eliminate vulnerability.
Risk moves.
If the state restricts an individual's ability to hold an asset, use open-source software, interact with a permissionless protocol or choose another settlement architecture, it should identify the specific vulnerability, justify the intervention, make its authority inspectable and preserve meaningful exit wherever possible.
That is the distinction between scaffolding and the cage.
Scaffolding establishes property rights, exposes material risks and hidden authority, protects against fraud and intermediary failure, makes legal relationships predictable, and allows identity to prove what needs proving without requiring every verifier to retain another copy of the person.
Then it leaves people room to choose.
The cage begins when protection becomes permission: disclosure becomes approval, certification becomes access, identity becomes persistent identification, intermediaries become mandatory, and legal recognition becomes conditional upon approved architecture.
Europe needs more legal certainty, not less. But it needs discipline about what legal certainty is for.
Regulate vulnerability where it exists: reserve risk at the reserve layer, issuer risk at the issuer layer, custody risk at the custody layer, fraud at the point of fraud, systemic exposure where it actually exists.
Do not manufacture intermediaries because they are easier to regulate. Do not manufacture control because it is easier to supervise. Do not make permissionless systems permissioned in practice while calling them permissionless in theory.
Specific vulnerability should justify specific authority. That authority should be bounded, inspectable and revocable. People should retain a meaningful ability to refuse it and choose another architecture.
That is Trust Architecture.
MiCA should be judged not only by whether each rule appears reasonable in isolation, but by where they lead when combined.
If every road ultimately leads through institutionally approved identity, intermediaries, assets, protocols and settlement infrastructure, Europe will not have built trustworthy digital finance.
It will have built a sophisticated system of capture and called it trust.
Original form, page 133. Open PDF