ESMA ¦ Opinion on the Provision of Crypto-Asset Services in Relation to Non-MiCA-Compliant ARTs and EMTs

ESMA ¦ Opinion on the Provision of Crypto-Asset Services in Relation to Non-MiCA-Compliant ARTs and EMTs

ESMA closes the door on non-compliant stablecoins at EU crypto-asset service providers

The European Securities and Markets Authority (ESMA) has told national competent authorities that authorised crypto-asset service providers (CASPs) should not provide any crypto-asset service in relation to asset-referenced tokens (ARTs) or e-money tokens (EMTs) that do not comply with the Markets in Crypto-Assets Regulation (MiCA). The Opinion of 8 October 2026 covers trading, exchange, order execution, reception and transmission of orders, placing, advice, transfer services, custody and portfolio management. Warnings, disclosures and client acknowledgements are not an acceptable substitute. Where legacy exposures remain, supervisors are expected to require remediation within three months of publication, which places the outer limit at around 8 January 2027.

A supervisory convergence tool with a clear target

The Opinion is issued under Article 29(1)(a) of the ESMA Regulation, which allows ESMA to address national competent authorities (NCAs) in order to build a common supervisory culture and consistent supervisory practices across the Union. It creates no new legal obligation for CASPs by itself. It carries weight because NCAs are expected to apply it when they assess the business models of the firms they authorise and supervise.

ESMA positions the Opinion as a complement to European Commission Q&A 2404 and its earlier public statement on certain crypto-asset services in relation to non-MiCA-compliant ARTs and EMTs. Those texts dealt with the circumstances in which a CASP’s activity could itself amount to an offer to the public, a request for admission to trading or a placing of such a token. The new Opinion leaves that position as it is and goes further.

Bastian Schwind-Wagner
Bastian Schwind-Wagner

"ESMA has ended the comfortable middle ground in which platforms kept non-compliant stablecoins on offer and pointed to a risk warning. Once a token lacks MiCA’s issuer safeguards, every service around it – trading, custody, transfers, advice – is presumed to breach the duty to act in clients’ best interests.

The three-month window is short, and wind-downs are exactly when monitoring gets stretched. Firms should map every affected token across all service lines, restrict clients to the permitted exit routes and watch outbound transfers closely, so that a supervisory clean-up does not turn into a gap for illicit flows."

The test no longer depends on whether a service is an offer to the public

ESMA detaches the supervisory conclusion from the qualification of each individual service. A CASP does not need to be making an offer to the public or seeking admission to trading within the meaning of Articles 16(1) or 48(1) of MiCA for its services to be problematic. The question is whether the continued provision of services in relation to a non-compliant token is compatible with the CASP’s own obligations under Title V and with the objectives of Titles III and IV, which govern ARTs and EMTs.

A non-MiCA-compliant ART or EMT is defined as a token for which the conditions for a lawful offer to the public or admission to trading in the Union, including any exemptions or transitional arrangements, are not met. That definition shifts the focus away from the label a platform attaches to its activity and toward the regulatory status of the token itself.

Article 66(1) becomes the anchor of the analysis

ESMA grounds its position in the general duty under Article 66(1) of MiCA to act honestly, fairly and professionally in the best interests of clients and prospective clients. In ESMA’s reading, the risks clients face when using services in relation to a non-compliant token come from the absence of the issuer-level safeguards MiCA requires, not from the service itself. Those safeguards include redemption rights, reserve-of-assets and safeguarding requirements, governance obligations, disclosure and ongoing supervision of the issuer.

According to ESMA, a CASP cannot adequately identify, manage or mitigate those risks with the tools available to it. This gives rise to a presumption that providing any MiCA service in relation to such tokens is incompatible with Article 66(1), because the CASP would be knowingly facilitating client exposure to risks created by the missing Title III and Title IV safeguards. For compliance functions, the listing of a token thus becomes a conduct matter under Article 66(1), with direct supervisory consequences.

Three reasons why availability itself is the problem

ESMA identifies three ways in which continued availability of non-compliant tokens through authorised CASPs would undermine MiCA. First, it would allow systematic circumvention of the issuer regime, so that tokens in the same regulatory category would be subject to different standards depending solely on whether they were issued in compliance with MiCA. Second, it would distort competition between compliant issuers, which carry the cost of reserves, redemption, governance and disclosure, and non-compliant issuers, which do not. Third, it would weaken investor confidence, because holders of tokens in the same category could not expect a uniform level of protection, transparency and supervisory oversight.

ESMA adds a supervisory argument. Services relating to non-compliant tokens limit the ability of NCAs to enforce the quality of white papers and marketing communications and to monitor whether trading is detrimental to holders, particularly retail holders. Where no issuer is within reach of an EU supervisor, the CASP is the only point at which the token touches the regulated perimeter.

Disclosure is not a mitigant

Many platforms have kept such tokens available while warning clients about their status. ESMA rejects that approach. Warnings do not prevent the continued availability and use of tokens that fail to meet the conditions of Titles III and IV. Additional disclosures are unlikely to convey the significance of safeguards that are not in place, since MiCA’s protections work collectively against a wide range of risks rather than addressing a single identifiable one.

ESMA also notes that any CASP assessment of those risks would rest on complex legal, regulatory and operational judgments that may differ in scope, methodology and conclusion from one firm to another. Clients cannot reasonably be expected to evaluate the absence of these safeguards themselves, nor to rely on a platform’s own interpretation of the risk. ESMA concludes that investor protection, market integrity and the effectiveness of MiCA can only be achieved by not providing the services at all.

Every service is in scope, individually or in combination

ESMA expects NCAs to examine whether a CASP’s services, individually or in combination, allow EU clients to acquire, trade, exchange, subscribe for, increase exposure to, or otherwise access or maintain non-compliant ARTs or EMTs. The list is deliberately comprehensive and covers operating a trading platform, exchange services, order execution, reception and transmission of orders, placing, advice, transfer services, custody and portfolio management.

The combination test has practical bite. A firm that removes a token from its order book but continues to custody it, accept incoming transfers or allow conversions through a separate service line may still be facilitating access. CASPs are expected to implement technical, contractual and organisational controls that prevent the availability of such tokens in the Union, including controls that stop EU clients from acquiring or increasing positions.

A narrow and supervised path for wind-down

The Opinion acknowledges that an abrupt cut-off could harm existing clients. NCAs may therefore allow CASPs that do not yet comply to provide strictly limited residual services where necessary for an orderly wind-down. These are confined to liquidation, conversion, withdrawal, transfer or safekeeping of existing holdings. They must not facilitate new acquisitions, promotion, trading, active distribution or continued market availability of the token.

Residual services must be time-limited, clearly communicated to clients and subject to close supervisory scrutiny. In its conclusion, ESMA narrows the permitted functionalities further to sell-only, conversion, transfer or withdrawal functions that are needed to avoid client detriment, applied on a risk-based basis and closely supervised. Where NCAs identify legacy exposures, remediation is expected as soon as possible and no later than three months after the date of publication.

What the Opinion means for financial crime controls

The Opinion is framed around investor protection, market integrity and financial stability rather than anti-money laundering. It still has consequences for financial crime risk management. Tokens issued outside MiCA typically sit outside the issuer authorisation, reserve and governance framework, and often outside the reach of any EU supervisor. When such tokens are withdrawn from authorised platforms, client holdings will move, and some of them will leave through channels that are harder to observe.

Wind-down periods put pressure on monitoring. Conversion and withdrawal flows concentrate in a short window, clients may seek to transfer holdings to self-hosted wallets or to providers outside the Union, and some may try to restructure positions to avoid the restrictions. CASPs should expect higher volumes of outbound transfers in affected tokens, review their transaction monitoring scenarios and Travel Rule processes for these flows, and document how they distinguish legitimate exits from attempts to keep using the token through other channels.

The Opinion also raises a governance question for firms with a group structure. The controls ESMA describes target EU clients. Where a group serves EU and non-EU clients from different entities, onboarding, geolocation and account-attribution controls determine whether the restriction actually holds. Weak client classification would leave room for the circumvention ESMA wants to stop.

Practical priorities for CASPs before January 2027

Firms should start with a complete inventory of ARTs and EMTs supported across all service lines, including custody-only and transfer-only support, and determine the MiCA status of each token on the basis of verifiable issuer authorisation rather than market perception. For every non-compliant token, they need a documented wind-down plan that restricts functionality to the permitted exit routes, sets a firm end date within the three-month window, and records how clients were informed.

Compliance and risk functions should be involved from the start, since the decision to delist or restrict a token touches conduct obligations under Article 66(1), client communication, operational resilience and financial crime monitoring at the same time. NCAs will monitor implementation in cooperation with ESMA, and supervisors are likely to ask whether a token was removed and whether the firm can show that its controls keep EU clients from reaching it through any other service.

A clear signal on the scope of the MiCA perimeter

The Opinion settles a question the market had left open for too long. Authorised CASPs cannot act as a bridge between EU clients and stablecoins that have not met MiCA’s issuer requirements, and they cannot neutralise that problem with warnings. For supervisors, it provides a common basis for challenging business models built on continued access to non-compliant tokens. Firms that have relied on risk warnings now need to remove the affected tokens from their EU offering, quickly and with an orderly exit for existing clients.

The information in this article is of a general nature and is provided for informational purposes only. If you need legal advice for your individual situation, you should seek the advice of a qualified lawyer.
Did you find any mistakes? Would you like to provide feedback? If so, please contact us!
Dive deeper
  • European Securities and Markets Authority (ESMA) ¦ Opinion on the provision of crypto asset services in relation to non-MiCA-compliant asset-referenced tokens and e-money tokens ¦ Link
Bastian Schwind-Wagner
Bastian Schwind-Wagner Bastian is a recognized expert in anti-money laundering (AML), countering the financing of terrorism (CFT), compliance, data protection, risk management, and whistleblowing. He has worked for fund management companies for more than 24 years, where he has held senior positions in these areas.