← Regulations / Italy / Operating Models / DeFi frontend

DeFi protocol frontend in Italy

Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.

Conditional AI-Generated · Unreviewed

DeFi frontend is conditionally permitted in Italy with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • AML/KYC strict compliance mandatory under Legislative Decree No. 231/2007 (Italian AML/CFT framework transposing EU AML Directives)
  • Registration with OAM (Organismo per la Gestione degli Elenchi di Agenti e Mediatori) required — Ministerial Decree Jan 17, 2022
  • Post-MiCA (from June 30, 2025): CASP authorization required with full AML program, supervised by Bank of Italy and CONSOB
  • Travel Rule (TFR recast) applies to all crypto transfers
  • Transaction monitoring and suspicious activity reporting (SAR) obligations
  • Sanctions screening against EU Consolidated Financial Sanctions List, OFAC SDN List (for US nexus), and UN sanctions lists
  • Fit-and-proper assessments for management/owners required
  • Customer due diligence (CDD/KYC) mandatory for all users accessing the frontend if it qualifies as a crypto-asset service

Key Restrictions

  • A frontend that takes fees (even as swap fees or routing fees) likely qualifies as operating a 'crypto-asset service' (exchange, order execution, or platform) under MiCA, triggering full CASP authorization
  • Local incorporation/governance required: transparent ownership, board with finance/compliance experience, independent compliance function — no pure remote operation without entity
  • Geofencing required for users from sanctioned jurisdictions (EU sanctions list compliance); likely need to block US persons unless compliant with OFAC
  • Fee-taking (commission, spread, routing fees) increases regulatory risk — may push classification from 'mere software interface' to 'crypto-asset service provider'
  • Cannot operate solely under 'decentralized' claim — Italian/EU authorities look at de facto control and revenue model, not just smart contract architecture
  • Transitional grace for existing OAM-registered VASPs until Dec 30, 2025; new entrants need authorization by June 30, 2025

Key Risks

  • Enforcement risk: fines up to €5 million or 3% of annual turnover for companies (up to €700k for individuals), plus suspension/revocation of authorization
  • Regulatory ambiguity: MiCA does not have a clear exemption for 'non-custodial' frontends — interpretation depends on whether the frontend exercises 'control' over user funds or merely facilitates
  • Precedent risk: Uniswap Labs CFTC settlement and SEC Wells notice signal that frontend operators can be held liable even if underlying protocols are decentralized
  • Sanctions risk: strict liability for OFAC violations — even purely non-custodial frontends that fail to geofence US persons could face US enforcement
  • Transition risk: operators who rely on pre-MiCA OAM registration-only regime must upgrade to full CASP authorization by deadlines or cease operations

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

MiCA Regulation (EU) 2023/1114: https://www.boccadutri.com/micar-european-regulation-on-crypto-assets/

licensing 60% confidence

Legislative Decree No. 129/2024: https://www.lightspark.com/knowledge/is-crypto-legal-in-italy ; https://cms.law/en/int/expert-guides/cms-expert-guide-to-crypto-regulation/italy

licensing 60% confidence

Pre-MiCA (until ~June 2025): Registration-only with OAM for VASPs (exchanges, custody); no full license needed but mandatory AML/KYC compliance. Investors urged to use registered firms.

licensing 60% confidence

Post-MiCA (from June 30, 2025): Licensing regime via CASP authorization; single EU passporting allows operation across member states without per-country re-licensing. Transitional grace until Dec 30, 2025, for existing operators.

licensing 60% confidence

AML/KYC: Strict compliance mandatory (Travel Rule, transaction monitoring, suspicious activity reporting); aligns with AMLD5 and GDPR for data protection.

licensing 60% confidence

Local Presence/Governance: Transparent ownership; board with finance/compliance experience; risk management systems; independent compliance/audit functions. No explicit branch required due to passporting, but Italian authorities oversee.

licensing 60% confidence

Lodge with competent authority (Bank of Italy for custody/ARTs/EMTs; Consob for exchanges/platforms).

licensing 60% confidence

Existing OAM-registered VASPs transition by applying before deadlines (June 30, 2025, for new ops; Dec 30, 2025, extension).

licensing 20% confidence

Primary Supervisory Authority: Bank of Italy (financial stability, systemic risk, cross-border issuance)

licensing 20% confidence

Secondary Authority: CONSOB (securities-related aspects, investor protection, MiCAR disclosure compliance)

licensing 20% confidence

Consob (Commissione Nazionale per le Società e la Borsa): Oversees investor protection and market integrity; authorizes crypto-asset service providers (CASPs) for most crypto-assets (excluding asset-referenced tokens (ARTs) and e-money tokens (EMTs)).

licensing 20% confidence

Bank of Italy (Banca d'Italia): Authorizes issuance of ARTs and EMTs; handles prudential supervision, financial stability, and AML compliance for CASPs.

licensing 20% confidence

Legislative Decree No. 129 (effective September 2024): Transposes EU MiCA into Italian law, regulating issuance and trading of crypto-assets, including ARTs and EMTs, with requirements for authorization, asset segregation, and consumer protection.

aml 20% confidence

Primary national law: Legislative Decree No. 231/2007, the core Italian AML/CFT framework, transposed from EU AML Directives (e.g., 2015/849 as amended by 2018/843), covering prevention of money laundering and terrorist financing via the financial system.

aml 20% confidence

Legislative Decree No. 129/2024 (effective September 2024), aligning with EU MiCAR for CASP authorization and operations.

aml 20% confidence

Legislative Decree No. 204/2024 (December 2024), amending AML Law to formally include CASPs.

aml 20% confidence

Ministerial Decree (January 17, 2022), requiring registration with OAM for virtual currency services (e.g., exchanges, e-wallets) operating in Italy, implementing EU rules on virtual assets.

aml 20% confidence

EU alignments: 5th AMLD (2018/843) and TFR recast extend rules to virtual assets and wallet providers.

aml 60% confidence

OFAC: Applies to all U.S. persons and has extraterritorial reach; VASPs must block cryptoassets linked to SDN-listed persons/entities (including wallet addresses) and report to OFAC. Strict liability applies, with no crypto exceptions.

aml 60% confidence

MiCA Regulation: EU Regulation 2023/1114 – https://eur-lex.europa.eu/eli/reg/2023/1114/oj

Evidence fact it.aml.oam-vasp-register-httpswwworganismo-am-it not found (may have been renamed).

enforcement 20% confidence

Fines up to €5 million or 3% of annual turnover for companies

enforcement 20% confidence

Suspension or revocation of business authorization

enforcement 20% confidence

Up to €700,000 for individuals

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a DeFi protocol frontend serving Italian residents is likely a regulated crypto-asset service under MiCA (transposed by Legislative Decree No. 129/2024), requiring either OAM registration (pre-June 2025) or full CASP authorization (post-June 2025) with local incorporation, AML/KYC obligations, sanctions screening, capital of €50k–€150k, and strict geofencing; fee-taking significantly increases the likelihood of classification as a regulated service requiring authorization.

Questions this verdict aims to answer

  • Is operating the frontend a regulated activity even if the protocol is decentralized?
  • What geofencing or KYC obligations apply?
  • Does fee-taking change classification?