DeFi protocol frontend in Austria
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Austria with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- VASP registration with FMA required under FM-GwG if the frontend provides 'services related to virtual currencies' (exchange, transfer, safekeeping, or financial services)
- Customer due diligence (KYC) under FM-GwG must be implemented if the frontend is classified as a VASP
- Transaction monitoring and suspicious activity reporting to the Financial Intelligence Unit (FIU)
- Appointment of a designated AML officer
- Fit and proper requirements for management and shareholders
- Establishment of internal controls and risk management systems for AML/CFT
- Under MiCA (from 30 Dec 2024), CASP authorization will add requirements beyond AML: capital requirements, governance arrangements, operational resilience, complaint handling procedures, and prudential safeguards
Key Restrictions
- If the frontend merely provides an interface to permissionless smart contracts without taking custody, executing transfers, or facilitating exchange (fiat↔crypto or crypto↔crypto), it may fall outside the scope of FM-GwG VASP registration — but this distinction is fact-specific and untested in enforcement
- Fee-taking (e.g., frontend fees, routing fees) may trigger classification as 'exchange between virtual currencies' or 'financial services relating to virtual currencies', bringing the frontend into VASP/CASP scope
- Geofencing EU/EEA users may not eliminate obligations if services are directed at Austrian residents; a local entity and FMA registration are required for in-scope activities
- Under MiCA (30 Dec 2024), CASPs providing custody/administration, exchange, or transfer services need authorization as a CASP from FMA, with passporting rights across EU
Key Risks
- Regulatory ambiguity — the line between a 'mere interface' to a decentralized protocol and a regulated VASP/CASP service is not clearly defined in Austrian law or FMA guidance, creating classification risk
- Enforcement risk: Austria/FMA has shown willingness to act (e.g., KuCoin EU ban from new business), meaning regulators may classify fee-taking frontends as regulated CASPs
- If classified as a VASP/CASP, operating without registration is a criminal/administrative offense with potential fines and business suspension
- Tax reporting risk: income from fees may attract corporate income tax and VAT obligations; unclear treatment of protocol-level vs frontend-level fees
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Currently (Pre-MiCA Full Implementation): Partial, primarily AML/CFT-focused. Austria has a framework that primarily addresses anti-money laundering and counter-terrorist financing (AML/CFT) aspects, along with existing securities and tax laws that apply depending on the classification of the crypto asset. This means many crypto activities are not specifically regulated as financial services unless they fall under traditional definitions (e.g., a token classified as a security).
Finanzmarktaufsicht (FMA) – Austrian Financial Market Authority:
Crypto Involvement: The FMA is responsible for the registration of Virtual Asset Service Providers (VASPs) under AML/CFT laws and will be the competent authority for licensing and supervising crypto-asset service providers (CASPs) under MiCA. It also provides guidance on the classification of crypto assets.
Geldwäsche- und Terrorismusfinanzierungsgesetz (GWG) – Anti-Money Laundering and Counter-Terrorist Financing Act (as amended):
Services covered (as per the FMA): Exchange between virtual currencies and fiat currencies, exchange between one or more virtual currencies, transfer of virtual currencies, safekeeping and administration of virtual currencies or instruments enabling control over virtual currencies, and financial services in connection with the issuance/sale of virtual currencies.
Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA):
Applicability: Stablecoin-related provisions (Asset-Referenced Tokens and E-Money Tokens) will apply from June 30, 2024. All other provisions (covering most other crypto-assets and crypto-asset service providers) will apply from December 30, 2024.
VASP Registration: There is no dedicated "custody license" per se. Instead, entities providing custody of virtual assets are classified as Virtual Asset Service Providers (VASPs) and are required to register with the Austrian Financial Market Authority (FMA).
Scope: The FM-GwG defines "providers of services related to virtual currencies" to include "the safekeeping of virtual currencies for third parties" (i.e., custody).
Requirements for Registration:
Fit and Proper Management: Key persons involved in the management must demonstrate their suitability and reliability.
Robust AML/KYC Framework: Implementation of comprehensive policies and procedures for customer due diligence (KYC), transaction monitoring, risk management, and reporting of suspicious activities to the Financial Intelligence Unit (FIU).
Internal Controls: Establishment of internal controls and risk management systems to prevent money laundering and terrorist financing.
Designated AML Officer: Appointment of a dedicated officer responsible for AML compliance.
Finanzmarkt-Geldwäschegesetz (FM-GwG): § 2 Z 22 FM-GwG defines virtual currency and § 32a FM-GwG outlines the registration requirements for providers of services related to virtual currencies.
The remaining provisions of MiCA for other crypto-assets and crypto-asset service providers will apply from 30 December 2024.
EU-Wide Authorization: Custodians will need to obtain authorization as a CASP from the FMA. Once authorized, they can "passport" their services across the EU.
MiCA introduces robust requirements beyond AML, but Austrian regulator action (banning KuCoin EU from new business) shows that enforcement was still needed to address gaps, with KuCoin subsequently hiring a new AML chief and expanding compliance in Vienna
Organizational Requirements: Clear governance arrangements, effective risk management, internal controls, and operational resilience.
Fit and Proper Requirements: For management and shareholders.
Prudential Safeguards: Capital requirements (see below).
Complaint Handling: Procedures for client complaints.
Titles III (ARTs) and IV (EMTs) of MiCA, covering stablecoins, will apply from 30 June 2024.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — operating a DeFi protocol frontend in/into Austria may require FMA registration as a VASP (under FM-GwG) and, from 30 Dec 2024, CASP authorization under MiCA if the frontend takes custody, executes exchanges/transfers, or charges fees that bring it within the scope of regulated virtual asset services; a pure informational interface with no custody, exchange, or fee-taking likely falls outside scope, but the boundary is untested and fact-specific.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?