DeFi protocol frontend in Italy
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Italy with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- AML/KYC strict compliance mandatory under Legislative Decree No. 231/2007 (Italian AML/CFT framework transposing EU AML Directives)
- Registration with OAM (Organismo per la Gestione degli Elenchi di Agenti e Mediatori) required — Ministerial Decree Jan 17, 2022
- Post-MiCA (from June 30, 2025): CASP authorization required with full AML program, supervised by Bank of Italy and CONSOB
- Travel Rule (TFR recast) applies to all crypto transfers
- Transaction monitoring and suspicious activity reporting (SAR) obligations
- Sanctions screening against EU Consolidated Financial Sanctions List, OFAC SDN List (for US nexus), and UN sanctions lists
- Fit-and-proper assessments for management/owners required
- Customer due diligence (CDD/KYC) mandatory for all users accessing the frontend if it qualifies as a crypto-asset service
Key Restrictions
- A frontend that takes fees (even as swap fees or routing fees) likely qualifies as operating a 'crypto-asset service' (exchange, order execution, or platform) under MiCA, triggering full CASP authorization
- Local incorporation/governance required: transparent ownership, board with finance/compliance experience, independent compliance function — no pure remote operation without entity
- Geofencing required for users from sanctioned jurisdictions (EU sanctions list compliance); likely need to block US persons unless compliant with OFAC
- Fee-taking (commission, spread, routing fees) increases regulatory risk — may push classification from 'mere software interface' to 'crypto-asset service provider'
- Cannot operate solely under 'decentralized' claim — Italian/EU authorities look at de facto control and revenue model, not just smart contract architecture
- Transitional grace for existing OAM-registered VASPs until Dec 30, 2025; new entrants need authorization by June 30, 2025
Key Risks
- Enforcement risk: fines up to €5 million or 3% of annual turnover for companies (up to €700k for individuals), plus suspension/revocation of authorization
- Regulatory ambiguity: MiCA does not have a clear exemption for 'non-custodial' frontends — interpretation depends on whether the frontend exercises 'control' over user funds or merely facilitates
- Precedent risk: Uniswap Labs CFTC settlement and SEC Wells notice signal that frontend operators can be held liable even if underlying protocols are decentralized
- Sanctions risk: strict liability for OFAC violations — even purely non-custodial frontends that fail to geofence US persons could face US enforcement
- Transition risk: operators who rely on pre-MiCA OAM registration-only regime must upgrade to full CASP authorization by deadlines or cease operations
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
MiCA Regulation (EU) 2023/1114: https://www.boccadutri.com/micar-european-regulation-on-crypto-assets/
Legislative Decree No. 129/2024: https://www.lightspark.com/knowledge/is-crypto-legal-in-italy ; https://cms.law/en/int/expert-guides/cms-expert-guide-to-crypto-regulation/italy
Pre-MiCA (until ~June 2025): Registration-only with OAM for VASPs (exchanges, custody); no full license needed but mandatory AML/KYC compliance. Investors urged to use registered firms.
Post-MiCA (from June 30, 2025): Licensing regime via CASP authorization; single EU passporting allows operation across member states without per-country re-licensing. Transitional grace until Dec 30, 2025, for existing operators.
Capital: €50,000–€150,000 minimum, scaled by services/risks.
AML/KYC: Strict compliance mandatory (Travel Rule, transaction monitoring, suspicious activity reporting); aligns with AMLD5 and GDPR for data protection.
Local Presence/Governance: Transparent ownership; board with finance/compliance experience; risk management systems; independent compliance/audit functions. No explicit branch required due to passporting, but Italian authorities oversee.
Lodge with competent authority (Bank of Italy for custody/ARTs/EMTs; Consob for exchanges/platforms).
Existing OAM-registered VASPs transition by applying before deadlines (June 30, 2025, for new ops; Dec 30, 2025, extension).
Primary Supervisory Authority: Bank of Italy (financial stability, systemic risk, cross-border issuance)
Secondary Authority: CONSOB (securities-related aspects, investor protection, MiCAR disclosure compliance)
Consob (Commissione Nazionale per le Società e la Borsa): Oversees investor protection and market integrity; authorizes crypto-asset service providers (CASPs) for most crypto-assets (excluding asset-referenced tokens (ARTs) and e-money tokens (EMTs)).
Bank of Italy (Banca d'Italia): Authorizes issuance of ARTs and EMTs; handles prudential supervision, financial stability, and AML compliance for CASPs.
Legislative Decree No. 129 (effective September 2024): Transposes EU MiCA into Italian law, regulating issuance and trading of crypto-assets, including ARTs and EMTs, with requirements for authorization, asset segregation, and consumer protection.
Primary national law: Legislative Decree No. 231/2007, the core Italian AML/CFT framework, transposed from EU AML Directives (e.g., 2015/849 as amended by 2018/843), covering prevention of money laundering and terrorist financing via the financial system.
Legislative Decree No. 129/2024 (effective September 2024), aligning with EU MiCAR for CASP authorization and operations.
Legislative Decree No. 204/2024 (December 2024), amending AML Law to formally include CASPs.
Ministerial Decree (January 17, 2022), requiring registration with OAM for virtual currency services (e.g., exchanges, e-wallets) operating in Italy, implementing EU rules on virtual assets.
EU alignments: 5th AMLD (2018/843) and TFR recast extend rules to virtual assets and wallet providers.
OFAC: Applies to all U.S. persons and has extraterritorial reach; VASPs must block cryptoassets linked to SDN-listed persons/entities (including wallet addresses) and report to OFAC. Strict liability applies, with no crypto exceptions.
EU Consolidated Financial Sanctions List
OFAC SDN List (including crypto addresses)
MiCA Regulation: EU Regulation 2023/1114 – https://eur-lex.europa.eu/eli/reg/2023/1114/oj
Evidence fact it.aml.oam-vasp-register-httpswwworganismo-am-it not found (may have been renamed).
Fines up to €5 million or 3% of annual turnover for companies
Suspension or revocation of business authorization
Up to €700,000 for individuals
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend serving Italian residents is likely a regulated crypto-asset service under MiCA (transposed by Legislative Decree No. 129/2024), requiring either OAM registration (pre-June 2025) or full CASP authorization (post-June 2025) with local incorporation, AML/KYC obligations, sanctions screening, capital of €50k–€150k, and strict geofencing; fee-taking significantly increases the likelihood of classification as a regulated service requiring authorization.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?