DeFi protocol frontend in Sweden
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Sweden with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Conduct KYC by obtaining customer information before transactions (se.aml.conduct-kyc-by-obtaining-customer)
- Perform risk assessments of products/services, customers, distribution channels, and geographic factors (se.aml.perform-risk-assessments-of-productsservices)
- Apply enhanced due diligence where risks are higher (se.aml.apply-enhanced-due-diligence-where)
- Register/authorise with Finansinspektionen as a CASP under MiCA; transition for pre-MiCA registrants until 30 Jun 2026 (se.aml.registrationauthorization-required-with-fi-transition)
- Adhere to EU sanctions integrated via FI and the Certain International Sanctions Act (1996:95) (se.aml.eu-sanctions-integrated-via-fi, se.aml.certain-international-sanctions-act-199695)
Key Restrictions
- Must obtain CASP authorisation from Finansinspektionen if the frontend constitutes providing crypto-asset services (e.g. reception/transmission of orders, execution, or advice) under MiCA
- Geofencing/region screening may be required to avoid offering services to Swedish residents without authorisation
- Fee-taking (transaction fees, spreads, or frontend fees) likely triggers classification as a regulated crypto-asset service under MiCA, requiring authorisation
- Local entity incorporation in Sweden required to obtain and maintain CASP authorisation with FI
Key Risks
- Regulatory ambiguity remains around when a DeFi frontend qualifies as a CASP vs. an ancillary service provider under MiCA, especially if the protocol is fully permissionless
- FI may take an expansive view of what constitutes 'providing' crypto-asset services, potentially capturing even non-custodial frontends that charge fees
- Enforcement risk if operating without registration/authorisation while serving Swedish residents, given Sweden's historically stricter-than-EU AML stance on VASPs
- If no fees are charged and no active solicitation occurs, the frontend might argue it falls outside CASP scope — but this is untested in Swedish regulatory practice
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Swedish Financial Supervisory Authority (Finansinspektionen / SFSA): Primary regulator for supervising CASPs, licensing issuers of e-money/asset-referenced tokens, enforcing MiCA, AML/KYC, and consumer protection; appointed national competent authority via act effective June 30, 2024.
Primary laws: Swedish Anti-Money Laundering and Terrorist Financing Law (AML Act, SFS 2017:630); Money Laundering Crimes Criminal Code; former Currency Exchange Act (SCEA, 1996:1006, now amended/reduced post-MiCA); Lag med kompletterande bestämmelser till EU:s förordning om marknader för kryptotillgångar (2024:1159, effective 30 Dec 2024).
EU alignment: MiCA directly effective; CASPs now under direct AML Act regulation; prior SCEA expansions (effective 1 Jan 2020) imposed stricter-than-EU AML on virtual currency exchanges and custodians.
Registration/authorization required with FI; transition for pre-MiCA registrants until 30 Jun 2026.
Conduct KYC by obtaining customer information before transactions.
Perform risk assessments of products/services, customers, distribution channels, and geographic factors for money laundering/terrorist financing.
Apply enhanced due diligence where risks are higher.
EU sanctions: Integrated via FI; OFAC SDN: https://sanctionssearch.ofac.treas.gov
Certain International Sanctions Act (1996:95): riksagen.se (via FI link)
MiCA (EU Regulation 2023/1114): Direct effect in Sweden.
FI crypto-asset services page: https://www.fi.se/en/payments/apply-for-authorisation/crypto-assets-and-crypto-asset-services/cryptoasset-services/
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend serving Swedish residents is likely a regulated CASP under MiCA/Swedish law if it charges fees or actively solicits users, requiring FI authorisation, local incorporation, and full KYC/AML compliance; purely passive, non-fee, permissionless frontends face regulatory ambiguity.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?