Malta has begun discussions on a new approach to regulating DeFi and DAOs. The country’s financial regulator wants to understand how to legally describe projects that are governed by code but are not always fully decentralized.
On June 12, the Malta Financial Services Authority opened a public consultation on DeFi within the framework of European MiCA regulation. Market participants can submit comments until July 10.
The Regulator Seeks a Form for Code-Based Organizations
The main idea of the document is to introduce a new legal category for “software-based organizations.” This could include DAOs and other DeFi structures where governance is implemented through smart contracts, voting, and automated rules.
The Maltese regulator does not propose treating DAOs as a completely separate legal phenomenon. Instead, it wants to include them in a broader category of software-managed organizations.
This approach gives the regulator more flexibility. It allows for separate descriptions of the organization itself, its participants, and their responsibilities, without mixing this with the technical rules of the protocol and code.
MiCA Does Not Fully Cover Decentralized Models
The MFSA document specifically notes that MiCA excludes fully decentralized models from its scope. If a project has no intermediaries and no central control, it may not fall under the requirements of this regulation.
But this is where the main debate begins. The regulator believes that many DeFi projects only appear to be fully decentralized. In practice, they may still have developer teams, funds, large token holders, interface administrators, or groups that actually influence decisions.
This creates a problem of responsibility. If a project claims it is “just code” but someone controls key elements, regulators will look for who is actually responsible for risks, disclosure, and user protection.
Malta Returns to Its Role as a Crypto Jurisdiction
For Malta, the topic of digital assets is not new. Back in 2018, the country was one of the first in Europe to introduce a comprehensive system for regulating the crypto market.
Now the regulator is trying to adapt this experience to a new phase of the market. After MiCA, European authorities have a general framework for crypto assets, but DeFi and DAOs remain among the most complex areas.
The problem is that traditional regulation is used to working with companies, licenses, directors, and legal entities. In DeFi, the structure can be distributed, and key decisions are made through tokens, code, and communities.
Why It Is Difficult to Fit DAOs Into the Law
DAOs often describe themselves as decentralized autonomous organizations. But in reality, the degree of autonomy varies.
Some projects truly have no obvious center of control. Others have developers, treasuries, multisigs, large funds, founders, or interfaces without which users cannot actually interact with the protocol.
These are the cases that interest regulators. If a project has individuals or structures that make important decisions, it is harder to consider it fully decentralized. Then questions arise: who is responsible for violations, who discloses risks, who interacts with users, and who can be subject to oversight.
The EU Increases Focus on DeFi
The Maltese initiative fits into a broader European trend. EU regulators are increasingly studying how to apply MiCA to decentralized finance and blockchain-based organizations.
In March, a working paper from the European Central Bank showed that governance in four major DeFi protocols remains highly concentrated. This means that many projects may not pass the test for full decentralization.
In May, the European Commission also began a targeted review of MiCA. Topics discussed included stablecoin interest, DeFi, and possible gaps in existing regulation.
Not Everyone Wants a Separate MiCA for DeFi
At the same time, there is no consensus in Europe on whether a separate set of rules is needed for DeFi. European Commission adviser Peter Kerstens previously said that the priority should be integrating tokenization into the broader digital asset system, not urgently creating a second version of MiCA for DeFi.
This is an important position. Some market participants fear that overly early and strict regulation of DeFi could stifle experimentation and complicate infrastructure development.
Others believe that without rules, the market will remain a gray area. Users will face risks, and projects will be able to hide behind decentralization even where control is actually retained by a limited group of participants.
The Problem at the Boundary Between Code and Control
The main question for DeFi regulation is where the neutral protocol ends and the organization with responsible parties begins.
If the code is fully autonomous, there are no administrators, no controlling team, and no way to intervene in the system, traditional regulation indeed faces limitations.
But if a project has admin keys, updates through a small group, a centralized interface, or a fund that distributes resources, that is a different picture. In such cases, regulators may consider that there is a managed structure behind the protocol.
What Malta’s Approach Could Change
The MFSA proposal could become one of the first practical steps toward a legal description of DAOs in Europe. Not through a slogan of full autonomy, but through the broader term “software-managed organization.”
This approach can help separate several levels. There is the organization itself, the protocol, the software code, the governance participants, and the users. Each level may require different rules.
If this model gains support, it could influence further DeFi discussions in the EU. Especially regarding responsibility, disclosure, treasury management, and user protection.
What Next?
Until July 10, market participants can submit their comments to the MFSA. After that, the regulator will have to decide whether the proposed category will become the basis for a full-fledged legal regime.
For DeFi projects, this is an important signal. Europe is increasingly unwilling to take decentralization claims at face value. Regulators will look at actual control, governance concentration, and the role of teams behind the protocols.
The main takeaway is simple. Malta is trying to find legal language for DeFi and DAOs within the new European reality after MiCA. If a project is truly decentralized, it may remain outside the direct scope of the rules. But if there is a managed structure behind the code, regulators will look for a way to assign responsibility.
Read More: Old Aztec Contracts Targeted by Hacker Again