Promethean

Decentralised Finance (“DeFi”) Regulation in Malta: The Malta Financial Services Authority (“MFSA”) Discussion Paper: Regulatory Direction and Practical Implications (2026)

  • News
  • 7 mins read

Malta continues to position itself as an early adopter jurisdiction in digital financial services. In this context, the MFSA, which is the national financial regulator in Malta, has issued a Discussion Paper No. 03-2026 on DeFi, dated 12th June 2026, meaning financial services built on blockchain technology without traditional intermediaries such as banks or brokers. The paper is open for public consultation until the 10th July 2026.

This document is not law and does not create binding obligations. It is a supervisory consultation paper aimed at understanding how DeFi operates and how it may be assessed under existing regulatory frameworks, including the European Union Markets in Crypto-Assets Regulation (“MiCA”), which is the European Union (“EU”)-wide regulatory regime governing crypto-assets and related service providers.

Regulatory Context and Purpose of the MFSA Paper

The MFSA Discussion Paper is part of a broader regulatory effort to understand emerging financial technologies. Its objective is to analyse whether and how decentralised financial systems can be assessed within existing financial regulation frameworks.

DeFi refers to blockchain-based financial applications that operate through smart contracts (self-executing code on a blockchain) and aim to remove intermediaries such as banks, payment providers, or exchanges.

The MFSA acknowledges that while DeFi is presented as “decentralised”, in practice many systems still involve identifiable points of control, such as developers, governance token holders, or operators of user interfaces.

The publication is timely. MiCA’s transitional period ends on the 1st July 2026, after which crypto-asset service providers operating without authorisation will be in breach of EU law. Against this backdrop, the question of where DeFi sits relative to MiCA’s perimeter has become a live and urgent regulatory issue. DeFi regulation in Malta is therefore not merely a forward-looking exercise, it is a present concern for operators active in the market today.

The paper focuses on:

  • mapping DeFi structures and business models;
  • identifying regulatory perimeter issues;
  • assessing risks related to financial crime;
  • evaluating consumer protection gaps;
  • analysing operational and systemic risk considerations.

Key Characteristics of DeFi Identified by the MFSA

The MFSA describes DeFi as an ecosystem built on blockchain infrastructure, typically involving:

  • Smart contracts (automated code executing financial transactions);
  • Distributed Ledger Technology (“DLT”), meaning a shared digital database maintained across multiple nodes;
  • liquidity pools instead of traditional order books;
  • decentralised governance models, often through tokens or Decentralised Autonomous Organisations (“DAOs”);
  • composability, meaning different protocols can interact and build on each other.

However, the MFSA highlights a key regulatory observation: decentralisation is not absolute. Many DeFi systems still depend on identifiable actors who may exercise de facto control.

This observation is supported by recent research. A working paper published by the European Central Bank in early 2026 examined governance and decision-making across four major DeFi protocols and found that control remained highly concentrated among a limited group of participants. This finding strengthens the MFSA’s position that “fully decentralised” may be the exception rather than the rule in practice.

Regulatory and Legal Challenges

The paper identifies several structural challenges for regulators:

  • Accountability gap: difficulty identifying who is legally responsible for protocol operation or failure;
  • Anti-Money Laundering (“AML”) and Counter-Terrorist Financing (“CTF”) risks: increased difficulty in tracing transactions due to pseudonymity;
  • Smart contract risk: vulnerabilities in code, including hacks or exploits;
  • Consumer protection issues: lack of intermediaries who would normally provide safeguards or recourse;
  • Governance uncertainty: unclear decision-making structures in decentralised protocols;
  • Systemic risk: potential contagion effects in interconnected DeFi ecosystems.

On the financial crime side, the Financial Action Task Force (“FATF”)’s 2026 Targeted Report on Stablecoins and Unhosted Wallets found that stablecoins accounted for approximately 84% of illicit virtual asset transaction volume in 2025. This data point underscores the AML/CFT risk dimension that the MFSA identifies and reinforces the case for applying proportionate compliance obligations where identifiable intermediaries exist within DeFi systems.

The MFSA also considers whether certain DeFi activities may fall within the scope of regulated crypto-asset services under MiCA, particularly where identifiable intermediaries exist.

Regulatory Approach Considered by the MFSA

Rather than proposing immediate regulation, the MFSA explores possible approaches, including:

  • regulating identifiable “control points” (for example, user interfaces or protocol operators);
  • focusing on intermediaries such as crypto-asset service providers (“CASPs”), meaning regulated firms providing crypto services under MiCA;
  • applying Anti-Money Laundering obligations to entities facilitating access to DeFi systems;
  • assessing DeFi structures based on functional control rather than technical labels;
  • considering whether partial decentralisation is sufficient to avoid regulatory classification.

A key theme is that decentralisation is treated as a spectrum rather than a binary concept.

Two concepts introduced in the Discussion Paper merit particular attention for market participants.

First, the MFSA proposes a potential new legal category of “software-based organisations” to capture Decentralized Autonomous Organizations (“DAOs”) and other DeFi entities governed primarily through code. Rather than treating DAOs as a standalone legal form, this framework would distinguish between the organisation using software governance on one hand, and the underlying protocol or code on the other. This approach is intended to allocate accountability at the organisational level without necessarily regulating the protocol itself. The MFSA is seeking industry views on whether this framing is appropriate and workable in practice.

Second, the paper introduces the concept of “Guardian Agents”, mechanisms designed to impose automated constraints on DeFi protocol behaviour, such as risk limits, circuit breakers, or fail-safe mechanisms. The MFSA invites views on whether Guardian Agents can function as regulatory equivalents of financial safeguards, and how their design and scope should be assessed when determining whether a protocol is effectively decentralised.

Practical Implications for Market Participants

For developers, investors, and operators, the paper signals that:

  • Labelling a protocol as “decentralised” does not automatically exclude regulatory scrutiny;
  • Regulatory assessment will focus on actual control and governance in practice;
  • Front-end operators and interface providers may become regulated touchpoints;
  • Anti-Money Laundering obligations may apply where fiat conversion or identifiable intermediaries exist;
  • Consumer protection principles remain relevant even in non-custodial

For DAO contributors and protocol developers specifically, the proposed “software-based organisations” framework signals that governance participation, including through token voting, may attract regulatory accountability, depending on the degree of control exercised. Parties with material influence over protocol parameters, treasury management, or user interface operations should take early legal advice on their potential exposure under the emerging framework.

Strategic Outlook for 2026

The MFSA approach reflects a broader European regulatory trend: regulators are increasingly focusing on substance over form. This means that what a system does in practice is more important than how it is labelled technologically.

In parallel, the European Commission launched a review of MiCA in May 2026, with DeFi among the topics under active consideration. This review, combined with the MFSA’s own consultation, suggests that the regulatory framework governing DeFi regulation in Malta and across the EU is likely to develop materially over the next 12 to 18 months. The MFSA has positioned itself and Malta to contribute meaningfully to that process.

Conclusion

The MFSA Discussion Paper (No. 03-2026) does not introduce new binding obligations but clearly signals a regulatory direction: decentralisation does not eliminate regulatory exposure. For participants in the DeFi space, engagement with the consultation process (open until 10th July 2026) is an opportunity to shape how DeFi regulation in Malta develops. Functional control points, governance participation, and interface operation are the pressure points regulators will focus on, and the time to assess exposure is now.

How Promethean Can Assist

Promethean advises clients operating in the digital assets and financial technology space on the interpretation and practical application of evolving regulatory frameworks, including guidance issued by the MFSA and the implementation of the MiCA in the European Union.

We assist clients in assessing whether DeFi structures may fall within regulatory perimeters, identifying potential control points, analysing governance and operational models, and structuring compliant frameworks for decentralised or hybrid financial systems. Our work also includes regulatory perimeter analysis, licensing considerations for CASPs, and risk assessment in relation to AML obligations.

As regulatory interpretation in this area continues to evolve, Promethean supports market participants in navigating uncertainty, engaging with supervisory expectations, and aligning innovative financial models with applicable legal requirements.

For further information or assistance in relation to DeFi regulation in Malta, responding to the MFSA consultation, or the broader EU regulatory landscape, contact us.