DeFi protocol frontend in Belgium
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Belgium without local incorporation, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- No
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- If the frontend facilitates crypto-to-fiat exchange (directly or via integrated on-ramps/off-ramps), or provides custody/control of user private keys, it must register with the FSMA as a VASP under the Law of 18 September 2017 (Art. 5, §1, 37°) — registration focuses on AML/CFT compliance.
- Must implement customer due diligence (CDD) and beneficial ownership verification for any regulated activities.
- Must report suspicious transactions to the FIU (CTIF-CFI) under the Belgian AML law.
- If the frontend purely aggregates permissionless smart contracts without custody, exchange, or fee-taking that involves fiat conversion, it may fall outside the current FSMA registration scope — but the FSMA assesses on a case-by-case basis.
- Under MiCA (from 30 Dec 2024), a broader range of crypto-asset services will require CASP authorization from the FSMA, which may capture frontends that intermediate user interaction with protocols.
Key Restrictions
- Fee-taking that involves converting crypto-to-fiat or providing custody likely triggers FSMA registration as a VASP.
- Purely crypto-to-crypto aggregation without custody or exchange may not be captured under current Belgian AML rules, but this is subject to FSMA case-by-case assessment.
- Must geofence/block Belgian residents from using the frontend if it is not registered/authorized but could otherwise be offering regulated crypto-asset services.
- Under MiCA (applicable from 30 Dec 2024), any frontend that qualifies as a CASP must be authorized by the FSMA, regardless of decentralization of the underlying protocol.
Key Risks
- Regulatory ambiguity: Belgian law currently captures 'exchange services' and 'custodian wallet providers' but there is no explicit designation for non-custodial DeFi frontends — creates legal uncertainty.
- Enforcement risk: The FSMA could interpret any fee-generating frontend as providing exchange services if it facilitates transactions between users and protocols.
- MiCA transition risk: By end of 2024, MiCA will impose harmonized CASP authorization requirements that may capture frontends currently operating in a grey zone.
- Consumer protection risk: The FSMA actively issues warnings about crypto risks and may scrutinize unregistered frontends targeting Belgian consumers.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Required: Registration with the FSMA.
Scope: This includes services for the exchange between virtual currencies and fiat currencies, as well as exchange services between one or more virtual currencies.
If purely crypto-to-crypto payments without custody/exchange: If the service solely facilitates crypto-to-crypto payments without providing custody or facilitating conversion to/from fiat, it might not strictly fall under the current VASP registration requirements. However, the FSMA would assess the specific business model.
Current Regime (Belgium): It is a registration regime, primarily focused on AML/CTF compliance. It does not imply a full prudential licensing similar to banks, traditional investment firms, or e-money institutions. The FSMA grants "registration" but does not "license" in the broader financial sense that implies comprehensive prudential oversight of capital, risk management beyond AML, consumer protection, etc.
Future Regime (EU MiCA): The upcoming EU Markets in Crypto-Assets (MiCA) Regulation will introduce a comprehensive, harmonized licensing regime across the EU for a much broader range of crypto-asset services. This will supersede the current national AML-driven registration frameworks for many activities.
Impact: MiCA provides a harmonized regulatory framework across the EU for crypto-assets not covered by existing financial services legislation. It covers the issuance, public offering, and admission to trading of various crypto-assets, as well as the authorization and supervision of crypto-asset service providers (CASPs). This is the most significant piece of legislation for the future of crypto regulation in Belgium.
Other provisions (relating to crypto-asset service providers and other crypto-assets): 30 December 2024.
Legal Basis: The Law of 18 September 2017 on the prevention of money laundering and terrorist financing and on the restriction of the use of cash. Specifically, Article 5, §1, 37° designates "providers of custodian wallets" as entities subject to AML/CFT obligations.
Requirement: Providers of "custodian wallet services" are required to register with the FSMA. This is not a full financial services license but an AML registration.
Legal Basis: The Law of 18 September 2017 on the prevention of money laundering and terrorist financing and on the restriction of the use of cash. Specifically, Article 5, §1, 37° designates "providers of custodian wallets" as entities subject to AML/CFT obligations.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — A DeFi protocol frontend operating in/from Belgium is permitted without registration if it is purely non-custodial and does not facilitate crypto-to-fiat exchange; however, if it takes fees, controls keys, or facilitates fiat on/off-ramps, it must register with the FSMA as a VASP under AML law, and from 30 Dec 2024 MiCA's CASP authorization regime will impose broader obligations likely capturing most intermediating frontends.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?