Europe's securities regulator has told crypto-asset service providers to stop muddying the line between what is and isn't protected under new EU rules. The warning from the European Securities and Markets Authority arrives only months after the Markets in Crypto-Assets Regulation, known as MiCA, became binding on firms offering crypto services across the bloc. The message is direct: firms that sell both regulated and unregulated products must make the distinction unmistakable to clients, not bury it in fine print.
Why the mixed business model creates risk
MiCA gave crypto firms a formal licensing framework for the first time, covering things like safeguarding client assets, handling complaints, managing conflicts of interest, and submitting to ongoing supervision by national authorities. But many platforms operating under MiCA authorisation also offer products or services that fall outside its scope - activities not covered by MiCA or by other EU financial legislation such as MiFID II. ESMA's concern is that clients cannot always tell which bucket they're in. A retail user browsing a crypto platform may reasonably assume that because the firm is authorised, everything on offer carries the same regulatory backing. It often doesn't.
The 'halo effect' problem
ESMA describes this dynamic using a term that captures the core risk: a "halo effect." Regulatory approval for one part of a business can create false confidence about everything else attached to it, including products offered by related entities operating through the same interface. The regulator goes further, noting that some firms may actively lean on their licensed status as a selling point, even when promoting services that carry no such protection. That is precisely the kind of conduct MiCA's fairness and best-interest obligations under Article 66(1) are meant to prevent.
What compliant disclosure should look like
ESMA's statement sets out concrete expectations rather than vague principles. Firms should:
- Clearly flag the regulatory status of every product or service at every stage of the client journey, not just at sign-up.
- Separate regulated and unregulated activities into distinct sections of any website or app.
- Ensure client documentation reflects these differences rather than treating all offerings as interchangeable.
- Identify precisely which legal entity is providing each service, since related but separate entities may sit behind the same platform.
- Avoid using MiCA authorisation as a marketing hook for services that fall outside its scope.
The regulator was equally specific about what does not meet the bar. Disclosing unregulated status only in the terms and conditions is insufficient. So is a checkbox pop-up that a client must click through before accessing an unregulated product - a mechanism increasingly common across digital platforms but one ESMA regards as inadequate when used as the sole safeguard. Ambiguity about which entity a client is contracting with, or terminology that implies protection where none exists, are both flagged as practices to avoid.
What this means for the market
The statement reflects a broader pattern in EU financial regulation: once a licensing regime exists, supervisors turn quickly to how it's marketed and understood by consumers, not just how it's technically implemented. For crypto platforms, many of which built hybrid business models combining licensed custody or trading services with ancillary products like staking, lending, or proprietary tokens, this raises real compliance stakes. Firms will need to review website architecture, onboarding flows, and marketing copy to ensure the regulatory status of each offering is obvious rather than assumed. For users, the underlying lesson is straightforward - a licence covers what it covers, and assuming otherwise is a risk regulators are now actively working to close.