The European Securities and Markets Authority has outlined a regulatory framework that would place licensing and supervisory obligations on the identifiable services and intermediaries that give users access to decentralized finance protocols, rather than on the autonomous smart contracts themselves. In its response to the European Commission's MiCA review consultation submitted on September 30, ESMA described gateways as user-facing access points such as web applications, wallet interfaces and liquidity aggregators, where operators remain legally identifiable and commercially reachable.
If adopted, the proposal would mean compliance burdens fall on front-end operators, aggregators and other DeFi access services in the EU, not on protocols directly. ESMA also proposed new powers to freeze crypto assets linked to suspected market abuse or terrorist financing and to block fraudulent websites, warning that current procedures often move too slowly and freezing requests can arrive after funds have disappeared. The authority called for stricter marketing rules, especially where influencers and third parties promote crypto-asset products, and for clearer cost disclosures across staking, lending and borrowing.
ESMA recommended rules for classifying crypto-assets, including hybrid tokens, and supported giving the regulator power to issue binding opinions on token classification. It also urged a framework for tokenised securities and on-chain settlement to support an integrated European tokenised capital market. The proposals would reinforce powers against third-country firms soliciting EU investors without MiCA authorisation and would explicitly stop regulated crypto firms from offering services linked to stablecoins that do not comply with MiCA.
The approach parallels the UK Financial Conduct Authority's authorisation gateway and follows ESMA's crypto custody stress test and a MiCA register that now exceeds 280 firms, including Standard Chartered. The practical effect may already be visible in DeFi infrastructure, as compliance pressure on front-end operators was cited among factors after DeFi dashboard Zapper shut down after seven years. Whether the final definitions of gateway or access service will be broad or narrow remains unresolved, so the proposal should be treated as a developing regulatory position rather than an enacted requirement.
From a Bitcoin network perspective, the proposal formalizes a dynamic already present since 2009: a monetary network with no identifiable operator cannot be licensed directly, so regulatory attention shifts to businesses mediating access.