Crypto Regulation: What the Frameworks Try to Do
4 steps · one page
In short
The single most decision-relevant fact about any digital-asset arrangement is which regulator, if any, oversees the firm you are dealing with — and what that oversight actually covers.
This article describes regulatory structures and intentions rather than current implementation status, and that is a deliberate choice. Digital-asset regulation has been moving in every major jurisdiction — rules phasing in, transitional arrangements expiring, court decisions shifting classifications, and legislation in progress. Dates, thresholds, and status claims date quickly; structural intentions age far more slowly. A reader needing to know what applies to a specific firm or asset today should check the relevant regulator's own materials rather than any secondary source, including this one. Nothing here is legal advice, and nothing here should be relied on as a current statement of the law in any jurisdiction.
The custody article established the general form of this: regulation attaches to firms rather than to assets, so protections vary enormously and a firm may be registered for one purpose while unregulated for another. This article explains what the frameworks are trying to achieve, so a reader can interpret what they find when they check.
What regulators are trying to solve
Five problems recur across every framework, and recognising them makes any specific regime easier to read. Who is accountable. Requiring firms to be authorised, to have identifiable management, and to meet operational standards — which addresses the unverifiable-counterparty problem the fraud article identified as a recurring signal. Whose assets are whose. Client-asset segregation, so a firm's insolvency does not consume client holdings — the exposure that turned depositors into unsecured creditors. What must be disclosed. Requirements to publish meaningful information about an asset, its issuer, and its risks before it is offered, extending to digital assets the disclosure logic Pillar 7 described for securities. Whether reserves exist. For tokens referencing a currency, requirements on what backs them, how it is held, who may redeem, and how it is verified — the five checks that article set out, converted into obligations. And market conduct. Rules against manipulation, insider dealing, and misleading promotion, including the wash trading the NFT article described. The EU's MiCA framework is the most comprehensive attempt at this to date, and its structural approach is worth understanding whatever a reader's jurisdiction: it creates an authorisation regime for firms providing digital-asset services, imposes distinct and stricter requirements on tokens referencing currencies or other assets, sets disclosure obligations on those offering assets to the public, applies market-abuse rules, and — critically for how the EU works — provides for authorisation in one member state to permit operation across the bloc. That passporting structure is why the framework matters beyond its own borders: it makes the EU a single addressable market for authorised firms, which shapes where firms choose to be authorised. One structural detail follows from it: passporting is a property of full authorisation and of nothing else — a firm operating under any lesser or interim national permission has rights in that member state only, so "where is the firm authorised, and is it authorisation proper?" are the two halves of the same check. And the check has a canonical place to run: the EU's markets supervisor, ESMA, maintains a public register for the framework — authorised service providers, published asset white papers, and entities identified as non-compliant — which is the primary source this article's four questions are answered from for EU arrangements.
How to read any regime, and what none of them do
Four questions extract what matters from any framework, in any jurisdiction. Does it cover the firm, the asset, or both? Most regimes authorise firms and impose obligations on issuers; very few make any judgement about whether an asset is a good one. Does the authorisation cover the specific activity? A firm authorised for exchange services may not be authorised for custody or for lending, and this distinction rarely survives marketing. Is there a compensation scheme if the firm fails? Often not, and this is where readers most frequently assume banking-style protections that do not extend to digital assets. And does it apply to you? Frameworks generally protect residents of their own jurisdiction dealing with authorised firms — a reader in one jurisdiction using a firm authorised in another may have the protections of neither. Now what no framework does, which is the more important half. Authorisation is not endorsement. A regulated firm can offer an asset that goes to zero, and the framework will have functioned exactly as designed — this is the same point the wrapper article made about regulated products: regulation regulates the wrapper, not the price behaviour of what is inside. Compliance does not make an asset sound. Disclosure requirements ensure information exists; they do not make the underlying valuable, and the value question this pillar declined to settle is not one any regulator has settled either. Rules do not reach offshore or unhosted activity. A framework binds firms within its reach, and much of the activity in this sector — including most of the fraud — occurs outside any of them. And no framework recovers a lost key or reverses a transaction, because those are properties of the technology rather than failures of supervision. The practical consequence is worth stating plainly. Of the seven risks the closing article assembles, regulation meaningfully addresses counterparty risk and the regulatory-and-legal uncertainty itself, and partially addresses fraud by making authorised firms accountable and unauthorised ones identifiable. It does not address price, self-custody, code and design, or entitlement — four of the seven remain exactly as they were. A reader who upgrades from an unregulated firm to a regulated one has genuinely reduced their exposure, and has reduced it in two of seven dimensions.
Worked example
Worked example (fictional). Priya, resident in an EU member state, considers three arrangements. Firm A is authorised in her member state for exchange and custody, publishes an asset disclosure document, and segregates client assets. Firm B is authorised in another member state for exchange only, operating in hers under passporting, and offers custody as an ancillary service. Firm C is based outside the EU, is accessible through a website, and describes itself as "fully compliant" without naming a regulator. What the checks reveal. Firm A appears on the public register with both activities listed. Firm B appears with exchange only — so the custody she would rely on most is the part not covered, which is exactly the gap the second question exists to find. Firm C appears on no register, and "fully compliant" names no authority, which makes it an assertion rather than a status. Now the limit. Priya uses Firm A and buys an asset that falls 80%. Nothing went wrong. The firm was authorised, the disclosure was published, the assets were segregated, and the framework worked precisely as designed. She was protected against the firm failing and against being misled, and she was never protected against the asset falling — nor was any such protection ever offered. And the residual. Had she self-custodied instead, no framework would have applied at all: not because self-custody is prohibited, but because there is no firm to regulate, and the protections in this article are all protections against firms. (All names and figures fictional.)
Frequently asked
9 questions
What is MiCA?
The EU's comprehensive framework for digital assets. Structurally it creates an authorisation regime for firms providing digital-asset services, imposes distinct and stricter requirements on tokens referencing currencies or other assets, sets disclosure obligations on those offering assets to the public, applies market-abuse rules, and allows authorisation in one member state to permit operation across the bloc.
Why does this article avoid specific dates and thresholds?
Because digital-asset regulation has been moving in every major jurisdiction — rules phasing in, transitional arrangements expiring, court decisions shifting classifications. Status claims date quickly; structural intentions age slowly. For what applies today, check the regulator's own materials rather than any secondary source.
What are regulators actually trying to fix?
Five recurring problems: who is accountable, whose assets are whose, what must be disclosed, whether reserves genuinely exist behind currency-referencing tokens, and market conduct including manipulation and misleading promotion.
Does being regulated mean an asset is safe?
No — and this is the most important thing in the article. Authorisation is not endorsement. A regulated firm can offer an asset that goes to zero and the framework will have functioned exactly as designed. Regulation regulates the wrapper, not the price behaviour of what's inside.
My firm says it's "fully compliant". Is that meaningful?
Only if it names an authority you can verify on a public register — for EU arrangements, ESMA's public MiCA register of authorised providers, published white papers, and identified non-compliant entities. Compliance without a named regulator is an assertion rather than a status.
The firm is authorised — am I covered for everything it does?
Not necessarily. Authorisation is activity-specific: a firm authorised for exchange may not be authorised for custody or lending, and that distinction rarely survives marketing. Check which activities the register actually lists.
I'm in one country using a firm authorised in another. What applies?
Possibly the protections of neither. Frameworks generally protect residents of their own jurisdiction dealing with authorised firms, and cross-border arrangements vary — within the EU, passporting can extend authorisation across member states, but that's a feature of that framework rather than a general rule, and it attaches to full authorisation only.
How much of the risk does regulation actually remove?
Meaningfully, two of the seven risks in this pillar — counterparty risk and the regulatory-and-legal uncertainty itself — and partially a third, fraud, by making authorised firms accountable and unauthorised ones identifiable. It does not address price, self-custody, code and design, or entitlement. Moving from an unregulated firm to a regulated one is a genuine improvement in two dimensions out of seven.
Does any framework protect self-custodied assets?
No, and not because self-custody is prohibited — because there's no firm to regulate. Every protection described here is a protection against firms.
References
- ESMA — European Securities and Markets Authority (host of the public MiCA register of authorised crypto-asset service providers, published white papers, and non-compliant entities; entry point for the framework's implementing standards) —
- EUR-Lex — the official EU legal-text repository (Regulation (EU) 2023/1114 on markets in crypto-assets, in its consolidated form) —
- SEC Investor.gov — Investor Alert: Exercise Caution with Crypto Asset Securities (US position: offerings must be registered or exempt; entities involved in lending or staking may be subject to securities laws; check registration before dealing) —
- CFTC / SEC — Investor Alert: Watch Out for Fraudulent Digital Asset and "Crypto" Trading Websites (the RED List of unregistered foreign entities — the US analogue of a public register check) —
Educational and informational only — not investment advice, a recommendation, or an offer to buy or sell any security. Investing involves risk, including the possible loss of principal. Worked examples use fictional companies and figures.