All episodes
Episode 112 · Regulation · Aug 20th, 2026 · 66 min

Joseph Axisa from Axis on the state of MiCA compliance

Joseph Axisa
Joseph Axisa
Managing Partner at Axis Group

MiCA's transitional deadline closed on July 1st, 2026.

Some of the biggest names in the industry lost the ability to serve European clients overnight.

But one jurisdiction rose to become a MiCA licensing hub: Malta.

It's now ranked 4th for CASP (Crypto Asset Service Providers) authorizations, and 2nd for Other Crypto Assets.

In this episode, we spoke with Joseph Axisa, Managing Partner at Axis, a MiCA advisory practice based in Malta, working with some of the industry's most recognisable names, including Arbitrum DAO, Rain, Ether.Fi, Rhinofi, and Legion.cc

Show notes

  • (0:00) Coming Up
  • (2:56) Joseph’s story into digital assets
  • (6:30) Overview of Axis services
  • (8:16) How companies navigated MiCA compliance
  • (11:55) Choosing Malta for MiCA compliance
  • (17:48) Filing requirements post MiCA licence
  • (19:19) Submitting a MiCA whitepaper
  • (25:23) Common objections from regulator
  • (27:45) Get 10% off with Kryptos subledger
  • (29:10) Title II whitepaper & Other Category
  • (31:57) Do all L1 & L2s need MiCA licence
  • (32:44) PSD2 and EMD2 v/s MiCA for payment platforms
  • (37:29) Interpreting onchain actions and smart contracts for MiCA
  • (39:56) Etherscan as a passive front-end
  • (42:46) Decentralization exemption under Recital 22
  • (45:17) DeFi protocols and MiCA
  • (47:14) Reverse solicitation v/s direct solicitation
  • (49:47) Onchain vaults don’t trigger MiCA, but AIFMD
  • (57:53) How Axis Advisory uses AI
  • (01:04:00) Closing thoughts
  • (01:05:09) Favourite quote
  • (01:05:57) How to reach out to Joseph & Axis

Transcript

[00:00:00] Joseph Axisa: A lot of the curator vault-oriented protocols don't trigger MiCA, right? Unless they actually offer MiCA services such as custodying the stablecoins, offering execution, et cetera.

[00:00:11] Joseph Axisa: Most of them actually trigger AIFMD, which is the funds regime within the European Union.

[00:00:16] Umar: And how are DeFi protocols coping with MiCA?

[00:00:19] Joseph Axisa: I would say the main reason that some of these DeFi protocols aren't seeking authorization isn't necessarily because they don't want it or they don't think it would be good for, I would say, legitimacy purposes. It's more because they know that if, listen, if I implement KYC for my protocol, I'm basically done for.

[00:00:35] Joseph Axisa: I'm not gonna get any form of user base.

[00:00:38] Joseph Axisa: Which is why a lot of these default protocols operate through like Panama structures, BVI structures, et cetera.

[00:00:43] Umar: Joseph Axisa is a Lawyer specialized in DeFi and digital assets and the Managing Partner at Axis Group based in Malta.

[00:00:52] Umar: Malta has become one of the busiest jurisdictions for MiCA compliance, ranking fourth for Crypto Asset Service Providers and second for Other Crypto Assets.

[00:01:04] Umar: Axis Group is composed of Axis Advisory, the legal, regulatory, and corporate advisory arm,

[00:01:12] Umar: Axis Corporate Services, the corporate service provider firm for Malta incorporations and registered office,

[00:01:19] Umar: and Axis Ledger, the accounting firm focused on digital assets. Some of their clients include industry recognizable names like the Arbitrum DAO, Rain Cards, ether.fi, Rhino.fi, and Legion.

[00:01:35] Umar: Welcome to The Accountant Quits podcast, where we help accounting and finance professionals learn how to manage a business using crypto.

[00:01:43] Umar: On this episode with Joseph, we discuss the state of MiCA compliance, submitting MiCA whitepapers, interpreting onchain actions and the decentralization exemption, onchain vaults and risk curators, and much more.

[00:02:00] Umar: The Accountant Quits is the official podcast of the Onchain Finance Institute, the leading educational provider for finance teams using digital assets. Their programs, the Crypto Accounting Academy and Crypto Treasury Management Academy, focus on practical knowledge, including tools required to work with digital assets.

[00:02:21] Umar: Inside their platform, you can also connect with peers working in web3, join focused chat groups, access job opportunities, and attend practical workshops on onchain finance.

[00:02:32] Umar: You can join the community for free by heading to onchainfinanceinstitute.com/community

[00:02:38] Umar: The link is also in the show notes.

[00:02:41] Umar: Now enjoy my conversation with Joseph. Joseph, welcome here, and thanks a lot for making the time.

[00:02:53] Joseph Axisa: Yeah, my pleasure. Thanks for the invite, Umar.

[00:02:56] Umar: So before we get into the mechanics of MiCA, Joseph, I always like to start a bit with the origin story of my guests into digital assets. So like I mentioned in the intro for the listeners, Joseph is based in the beautiful island of Malta.

[00:03:12] Umar: Could you walk us through your journey that led you to found Axis Advisory back in 2023, and how you became one of the busiest MiCA advisory shops?

[00:03:23] Joseph Axisa: Yeah. So, so basically I would say, first of all, I got into crypto completely by mistake, which some of, some people find that quite surprising. So I had applied with a firm to work on capital markets because I did my dissertation back at university on capital markets legislation within the European Union.

[00:03:37] Joseph Axisa: That firm had a very good collaboration sort of arrangement with a crypto firm. The intern at the crypto firm didn't want to work in crypto. I had just applied with the other firm, so they basically swapped interns. So all of a sudden, I'm in this new uncharted territory of Bitcoin, Ethereum, hearing these different tokens, and I had no, no idea.

[00:03:57] Joseph Axisa: What I did back then is I had, like, 1.5k in savings as a student, and as any reasonable individual would do, I dumped it all in Ethereum, right? One of, one of, one of my ethos in life is if I want to learn something, I need to put my money where my mouth is, and it's, it's a good incentive usually to learn, right?

[00:04:13] Joseph Axisa: That firm was BCAS, which, when it was operating, I think it was one of the premier shops in Malta and across the European Union, to be completely honest, pre-MiCA, for anything from DeFi, legal, regulatory, or corporate advisory. I got to work with tier one protocols, tier one institutions, within the industry, , through there.

[00:04:31] Joseph Axisa: I had left BCAS in mid 2023. I would say didn't know exactly what I was gonna do. Now, I always wanted to open up a firm, but the plan was when I turn forty, I'll look at opening up a firm. I did it a lot sooner than forty, but now I feel like forty. So that's also a bit of a pro column analysis there. Then I started Axis because I was, at that point in time, part of the team over at dYdX before.

[00:04:54] Joseph Axisa: And I think through that, being a lawyer, being associated with dYdX, who at the time was, I think, the largest perpetual futures exchange onchain in the industry, people started reaching out to me for small queries, right? Read through disagreements. We have this particular deal. Can you take a look? All of a sudden, it got to a point where, you know, I looked back three months after these initial inquiries started, and I was like, "Okay, I'm basically running an advisory shop here."

[00:05:17] Joseph Axisa: So I was like, "Let me give it a name so it's not Joseph." So that's where Axis Advisory was born. Since then, obviously, it become Axis Group, and what Axis Group is composed of is Axis Advisory, which is our legal, regulatory, and corporate advisory firm, Axis Corporate Services, which is our corporate service provider firm based in Malta for Malta corporations, registered office and the like, and Axis Ledger, which is our accounting and bookkeeping firm predominantly focused on digital assets.

[00:05:43] Umar: And for the listeners, like I mentioned in the intro, Joseph is more commonly known in the industry, I mean, his Twitter handle is Immutable Lawyer. So maybe you know Immutable Lawyer, but today you're seeing Joseph, in flesh.

[00:05:56] Joseph Axisa: Yeah- Now- Most people don't know Joseph, I would say, Umar.

[00:05:59] Umar: Okay, okay. Now, I mean, you did briefly go through what, like the services that Axis offers.

[00:06:07] Umar: This episode today will be focused a lot on like MiCA compliance, but if you had to give us, an overview of the different services that you provide around token legal opinions, fundraising support, you even launched Axis Ledger that you just mentioned, focused on crypto accounting and tax.

[00:06:26] Umar: How, how wide does your, services span today?

[00:06:30] Joseph Axisa: Yeah, I would say it, it evolved quite a bit based on sort of client needs. So, I would say there are two main different, client typologies that we work with, which is usually your DeFi protocol and your institution that wants to get authorized within the European Union.

[00:06:44] Joseph Axisa: On the DeFi side, we've, we usually assist DeFi protocols of a startup to more mature nature. I would say the bulk of our clients on the DeFi side are definitely the clients that are raising capital now to go to market in a couple of months, and there we guided them to corporate structuring, token issuance strategies, you know, SAFE agreements, SAFT agreements, which one to use depending on the VC.

[00:07:03] Joseph Axisa: You're actually allocating token tools, token strategies as well. We assist them on selecting a good corporate director in the jurisdiction of choice too, because, you know, you need to be very, very careful with the corporate director that's gonna be responsible for your operations at the end of the day.

[00:07:17] Joseph Axisa: And your, then your classic ongoing legal, regulatory, or corporate, advisory. So any contractual matters that they want us to look into, corporate related matters, etc.

[00:07:25] Joseph Axisa: Then on the MiCA side, I would say we focus on a couple of different things. So first of all, it's MiCA whitepapers, which will be number one, and that's usually accompanied by an EU token legal opinion or a regulatory assessment for the token, basically assessing whether the token qu- qualifies as a financial instrument, as an EMT, as an ART, or as another crypto asset.

[00:07:45] Joseph Axisa: So that's the bulk, I would say, of the work that we've been doing over the past year or so, definitely, and we have a lot of volume in that regard. We're also working on about 15 to 20 authorizations at the moment for crypto asset service providers and fintechs, which will be anything from payment institutions, PFPs, or electronic money institutions as well.

[00:08:04] Joseph Axisa: We work with the likes of Raincards, EtherFi, Rhino Finance, and the like as well.

[00:08:08] Umar: We'll touch on those a little bit later on. I mean, we'll go through the MiCA white paper, in more detail later. But I want to start this episode with, you know, just having your general thoughts on, uh, what just happened, like, in the past three years. So MiCA entered into force back in June 2023, but the transitional deadline was July 1st of this year, so just a few weeks ago.

[00:08:34] Umar: Now, you've been helping organizations secure their MiCA license since 2023, but now that this transitional period has closed, what are the just your general thoughts on how companies navigated this?

[00:08:48] Joseph Axisa: Yeah. I, I would say sort of the, the main and sort of effective date of, of MiCA, sort of when institutions were able to actually start applying was sort of last year, right?

[00:08:57] Joseph Axisa: So January last year. I would say the final text was agreed upon in June, and then there, there was sort of this quasi transitional period, for people to start applying under the Markets in Crypto Assets Regulation. I would say there were two tranches of clients there, right? We spoke to people even in 2024, late 2024, et cetera, that were already preparing for MiCA.

[00:09:16] Joseph Axisa: So they were already, wanting to start working on their application pack with Malta, to start looking at what they would need as an authorized institution, what the overhead is, what key functions they would need to operate the institution. So that was one class of client, which usually your more serious client, they would want to be prepared because the European market is very important to them, so they don't want to lose out.

[00:09:35] Joseph Axisa: Then you have the other type of client, which is more, "Mm, let me wait and see. Let me try and sort of revert solicit client from the EU, and I'll see whether anything bad happens."

[00:09:46] Joseph Axisa: The other type of client, usually, I would say for the most part, when the first July deadline, I would say, was closed couple of weeks ago now, was panicking quite a bit, and they wanted to submit their application within a couple of weeks, which is impossible because especially when you apply in the Maltese jurisdiction, the application pack that you have to submit and the checks and balances that you have to integrate within your operations are very, very, very onerous.

[00:10:10] Joseph Axisa: So it's not just about drafting a couple of policies, a couple of procedures, and you're ready to go. So those were, I would say, the two main scenarios that our firm faced, and I would imagine that a lot of other frames- firms faced as well, during this entire process.

[00:10:22] Umar: From where you sit in Malta right now, are you seeing more firms come to you now after this transitional-

[00:10:28] Joseph Axisa: Yeah ...

[00:10:29] Umar: period has now elapsed

[00:10:30] Joseph Axisa: Yeah, I, I would say definitely. So keep in mind, like, that transitional deadline of 1st of July as a maximum, because there were certain jurisdictions which had other deadlines before that 1st July deadline, was there since sort of the final text of MiCA and since MiCA came into effect.

[00:10:46] Joseph Axisa: But if you look at Twitter, it would give you the impression, Twitter a couple of weeks ago, it would give you the impression that sort of this deadline was agreed upon now, and this deadline has been something that, you know, people get to know about now. It's been there for ages, for months and months, right?

[00:11:00] Joseph Axisa: I would say now definitely once people got to know that, okay, after this transitional deadline, I technically cannot directly solicit users from the European market, we're seeing a larger influx of institutions sort of having that wake-up call proverbially and saying, "Okay, I actually need to get authorized now," 'cause I didn't know it was gonna be actually this enforcement sort of heavy, right?

[00:11:18] Joseph Axisa: You can't directly solicit for market to European jurisdictions unless you have a crypto asset service provider authorization under MiCA if you are a crypto asset service provider. It's because w- sort of another sort of type of client that we have is clients that actually want to see whether they need a CASP at all to operate within the European Union, and this would be, like, your on-chain hybrid service providers, you know, that would have on-chain components, and they would sort of want to see whether there's an, if we're a DeFi kind of oriented protocol, do we actually need a CASP or not?

[00:11:47] Joseph Axisa: For the most part, most of those would trigger regulatory implications under MiCA due to some form of centralized control within their tech sector.

[00:11:54] Umar: Perfect. Now, for the listeners, I wanted to give them as much context on the different categories we have, in MiCA today. Also, there's quite a bit of acronyms that we might be using during the episode- Yeah

[00:12:08] Umar: so you guys can have, like, full context. So there's different buckets that your organization could fall under with MiCA. You actually have four. The first one is e-money tokens or EMTs, so those are single currency stablecoins like let's say USDC, where that issuer, like Circle, they need to hold an EMI license.

[00:12:28] Umar: And Circle, for example, I believe their license is in France. Right. Then you have CASP or crypto asset service providers. These are, let's say, your exchanges, your OTC desks, custodians, payment platforms. Then you've got another category, but is not being used at the moment, is asset referenced tokens or ARTs, where, like, the value is pegged to a basket rather than a single currency.

[00:12:54] Umar: So that's how it differs with the EMT I just described earlier. Now, as per ESMA's MiCA register, there's no organization that, who has received ART authorization across the entire EU to date.

[00:13:08] Umar: And the last one is your other crypto assets. Basically everything that isn't ART, EMT, and we'll dig into that in the next question.

[00:13:17] Umar: Now, for this episode, I actually wanted to pull some numbers from MiCA's register.

[00:13:23] Umar: EMT, I noted there's a total of 21 entities. France tops the list. Malta is second with two entities there.

[00:13:31] Umar: CASP, we have a total of 295 entities. Germany comes first with 65. Malta is fourth with 22.

[00:13:42] Umar: And for the other bracket, we have a total of 493 entities.

[00:13:47] Umar: Ireland is first, and Malta is actually second with 95.

[00:13:51] Umar: So Joseph, I wanna ask you, how do you sell Malta as a jurisdiction to clients? What has driven... like, Malta is doing very well here as a jurisdiction for companies to get their MiCA license.

[00:14:04] Joseph Axisa: Yeah, I would say there, there are a couple of things.

[00:14:06] Joseph Axisa: I would say to point out one thing also, kind of the numbers aren't indicative of interest in the island for one main reason, because there are a lot of applications at the regulator that are in progress at this particular point in time as well. So I would expect that number to jump significantly, maybe double, potentially even triple on the crypto asset service provider side in the next six to eight months, so to speak.

[00:14:27] Joseph Axisa: I mean, us alone working on about 15 to 20, so that number would already double, I would say, just with our, sort of authorization, and we're just one firm, right? And there are quite, quite a number of firms working on applications at the moment. But there are several pros to Malta. I would say it is a small island state at the end of the day.

[00:14:43] Joseph Axisa: So there, there are certain advantages actually to being a, a small island, island state. We- we're very modular, I would say, as a first, and we're very receptive of crypto since basically 2017, 2018. We were one of the first countries globally in the entire world to have a dedicated regime for crypto asset regulation in 2017, 2018, which was called the VFA Act, the Virtual Financial Assets Act.

[00:15:05] Joseph Axisa: We used to refer to what's now termed crypto assets under MiCA as virtual financial assets based on our previous regime. That regime was actually more onerous than MiCA in some instances, right? So what that led to is over a number of years before MiCA actually was implemented, applicable, effective within more than the entirety of the European Union, you had corporate service providers, accountants, lawyers, auditors, compliance officers, MLROs, et cetera, this goes on, directors as well, that were already very familiar with an onerous regime applicable to crypto assets.

[00:15:38] Joseph Axisa: What that led to is a bit of an advantage with firms seeking to have people ready with context to get an authorization as a crypto asset service provider. In other jurisdictions that were not that receptive to crypto, that had no local national regime to crypto assets, what you're finding now is when you go to incorporate a company, they're like, "Oh, we don't take crypto asset service providers."

[00:15:58] Joseph Axisa: You go to an auditor, it's the same. You go to a lawyer, they may not have the entire context on what crypto is, how a CASP works. That is not the case in Malta. What that also led to as a kind of byproduct of having an early regime is a huge local ecosystem. Again, we're a small island, but we have some of the biggest companies globally which are based in Malta.

[00:16:16] Joseph Axisa: You know, your Crypto.com, your OKXs, Gate.io, and a lot that are still coming. So we have a huge local ecosystem. You have service providers that you're gonna need for your authorization that have five plus years of context on how these companies are to be authorized, supervised, etc. And what you also have, naturally speaking, is a regulator that has been dealing with these forms of applications also for five plus years.

[00:16:42] Joseph Axisa: So you don't have a regulator that's dealing with a crypto authorization and supervisory element now, you have a regulator that's been doing this for over five years now, over half a decade. So even when you go to a regulator, when we go to our regulator with an application that's a bit more complex, because if you look at Rain, Ether.fi, etc.,

[00:16:58] Joseph Axisa: they have a lot of on-chain elements there, your more complex authorizations, they're able to understand our language a bit more. They're able to be a bit more crypto native. So I would say those are the advantages. Then there's also the tax advantage, which if you have a non-Malta domicile UBO as part of the company, which most of, I would say, the entrants do, you know, there is a 5% effective tax rate, which we call the imputation system, applicable to the corporate entity.

[00:17:22] Joseph Axisa: What I find surprising, though, is that when I mention this taxing to clients, they would not know about it. And initially, when I saw this huge influx of institutions coming to Malta to get authorized, I was like, "Maybe it's the tax element." But it's actually the elements that I mentioned before, which is like a regulator that's able to understand, service providers that are able to understand, lawyers that are able to advise.

[00:17:42] Joseph Axisa: Those are the main three reasons I would say that institutions come to Malta to get authorized.

[00:17:48] Umar: And post-license, what would be-- how, how strict and heavy are the filing requirements, let's say for a CASP or that Other category?

[00:17:58] Joseph Axisa: I, I would say it's not a matter of strictness, more a matter of ongoing compliance with your operations.

[00:18:03] Joseph Axisa: So let's say you've been licensed as a Class II, which is a very popular, I would say, type of business model at the moment. Like right now we're seeing a lot of these neobanks, Umar, right? So they're your classic payment card provider. They offer a payment account. They offer OTC conversion within the app.

[00:18:18] Joseph Axisa: So you're able to spend with a card, you're able to convert crypto to fiat, fiat to crypto. That's usually a Class II and the payment service provider authorization in one company, right?

[00:18:27] Joseph Axisa: Usually, it's not a matter of how strict it is when you're being supervi-supervised by the MFSA. Usually, it's more a matter of, okay, you have certain policies, procedures, and a business plan that you've submitted as part of your application.

[00:18:39] Joseph Axisa: You have to make sure that you have the correct systems in place to abide by those policies and procedures. So your AML policies, your compliance pack, your compliance program, etc. Now, there's also DORA as well, which is the Digital Operational Resilience Act. So there's another layer on top of what MiCA requires.

[00:18:55] Joseph Axisa: Now you have the layer of what DORA requires, which is basically a cybersecurity-oriented, regulation within the EU. So it's a matter of, again, cross-referencing back to the context of service providers. If you have good service providers in place on the compliance and the AML side in particular, it's going to be quite a breeze to make sure that you're meeting the MFSA's expectations.

[00:19:16] Umar: Fantastic. Thanks sharing, Joseph. Now, next I want to go through the MiCA whitepaper itself. It's a huge part of what you guys do at Axis. So for the listeners, under MiCA, any issuer offering crypto asset to the public or, you know, seeking admission to trading, let's say in the EU, they have to publish a detailed whitepaper, has to be filed in, ESMA's website in machine-readable format.

[00:19:43] Umar: Now, could you walk us through what actually goes in a MiCA whitepaper in fact? Yeah. And you've built a platform at Axis that handles this whole process, so maybe you can share also a little bit more on that from, you know, the intake to that final filing into ESMA.

[00:20:00] Joseph Axisa: Yeah. So, so let's start off sort of with the concept of a, of a MiCA, whitepaper.

[00:20:04] Joseph Axisa: So in the industry, for years now, there's always been this concept of a whitepaper, which is basically this is what the protocol does, this is what the token does, this is the supply, this who takes care of the ongoing development of the protocol, et cetera, et cetera.

[00:20:17] Joseph Axisa: What the MiCA whitepaper is, in a nutshell, is your prospectus regulation equivalent applicable to financial instruments, units in collective investment funds, et cetera, for crypto assets.

[00:20:28] Joseph Axisa: Now, it's very catered towards the crypto asset, digital asset industry, right? So what goes into a MiCA whitepaper is the equivalent mutatis mutandis applicable provisions for crypto assets. So you'd have, you know, a whitepaper applies in two instances, first of all. Either you're admitting your token to trading on an exchange, on a crypto asset service provider licensed as a authorized as a Class III under MiCA, so you'd need to submit a whitepaper before you admit the trading on a crypto asset service provider, or you're doing an ICO, so you're doing an offer to the public within the European Union.

[00:21:01] Joseph Axisa: For the admission to trading whitepaper, what usually goes in that is disclosures relating to who the company is that issues the token, is taking care of the token, so to speak. For most of the whitepapers we've submitted, that's usually a Cayman Foundation or a BVI business company, right, which is the classic corporate structure that's used a, a lot, I would say, for token issuances globally.

[00:21:21] Joseph Axisa: I would say it's the hub for token issuances globally.

[00:21:24] Joseph Axisa: You'd have disclosures relating to who the directors are. You'd have disclosures relating to the supply of the token, you know, vesting of the token, et cetera. Financials of the company that's submitting the whitepaper, so the Cayman Foundation, is it well-capitalized?

[00:21:37] Joseph Axisa: Does it have enough money? How much runway does it have? Et cetera.

[00:21:40] Joseph Axisa: The, the whitepaper, though, is also accompanied, more importantly in both instances, with a token legal opinion, and that's the most important part, I would say. You need to make sure that the crypto asset you're admitting to trading or offering to the public within the European Union is actually an Other crypto asset.

[00:21:57] Joseph Axisa: Now, by Other crypto assets, that, that's actually the name of the classification which you touched upon as well, Umar.

[00:22:02] Joseph Axisa: So it would be your classic equivalent of a utility token. Now, a utility token under MiCA has a different definition, but in the industry, what we refer to as utility tokens or your classic governance tokens would normally be classified as other crypto assets.

[00:22:16] Joseph Axisa: What that legal opinion tackles, that regulatory classification tackles is, is it a financial instrument? And our firm, we go through each and every single financial instrument, whether it's a unit in a money market fund, it's an equity, it's a bond, et cetera. Is it an ARP? Is it an EMT? Basically, you go through all the different applicable product types or asset types under MiCA, and it's by elimination, so to speak.

[00:22:41] Joseph Axisa: That is very important. The first thing that exchanges will ask you for, usually, surprisingly, it's not a-- it's not the white paper. It's do you have a legal opinion ready for the token? Because usually that's the one that takes a bit more time. Now, we've developed a, a process internally where we can do this quite efficiently, I would say.

[00:22:56] Joseph Axisa: We've submitted 50% plus of all non exchange sub-notified MiCA white papers and more than, as you, as you mentioned, Umar, Malta is the number two, white paper notifier to ESMA within the European Union. So that's why we created micawhitepaper.com, which will be launching in the next couple of weeks, and it's a semi-automated system for submitting and notifying MiCA white papers.

[00:23:17] Joseph Axisa: So we have integrated payment systems, integrated onboarding systems. We have an integrated communication channel within the website as well, iXBRL conversion, which is the machine-readable format. Every white paper needs to be in iXBRL format as well. So it's an end-to-end solution to make the process a lot more efficient.

[00:23:34] Joseph Axisa: As part of the white paper process as well, something to touch upon, you also need ESG data. Now, am I a fan of the concept of ESG or that crypto assets are causing climate change? I think it's incorrect, but the European Union has created this concept that every token needs to be accompanied by ESG data as well.

[00:23:51] Joseph Axisa: So before you notify your white paper, it has to be accompanied by the necessary ESG data. And there are several providers that, that offer this, um, and that we work with quite a bit as well. It's usually not an arduous process.

[00:24:02] Joseph Axisa: I would say the main three types of classification are: Is your token issued yet? Has it been issued within a specific time period? It's a couple of business days, I would say. Or has the the token been live for more than one year? And that has a bearing on sort of the ESG data component, and the metrics that you have to submit as part of the white paper process.

[00:24:20] Joseph Axisa: But yeah, on the platform, it's basically end-to-end.

[00:24:22] Joseph Axisa: So the ESG data, fill in questionnaire, provider provides ESG data. It's in the platform too. It makes it a lot easier, I would say, for clients that want to offer their tokens or admit to trading within the EU to actually get their white paper done. Because the reality is, it's a repetitive process. We ask for the same information every time, so we've developed the platform to basically be able to do it at a lower cost because we want to make our services more accessible.

[00:24:45] Joseph Axisa: Because the reality is, when you scan the administer, we looked at a lot of white papers that were, in our opinion, non-compliant with MiCA. So we want to offer a more accessible service and a service that leads to a white paper being fully, fully compliant with MiCA standards as well.

[00:24:59] Umar: And for the listeners, I'm sharing right now a screenshot of the website. So it's micawhitepaper.com, and you're saying it's gonna be available in two weeks, right?

[00:25:12] Joseph Axisa: Yeah, I would say in two, three weeks. The, basically the only thing we have to get sorted is the payment API, which will be sorted in the next two, three weeks.

[00:25:18] Joseph Axisa: And then it's basically good to go. So I'm looking forward to, to people using it actually.

[00:25:23] Umar: Given the volume of these whitepapers that you filed, are there, like, recurring reasons the regulator or the MFSA in Malta will send you back for revision, you know? Or are there, like, things that founders should know about before they even start this process with you at Axis?

[00:25:40] Joseph Axisa: Yeah. I, I, I would say, so first of all, we have 100% success rate for our whitepaper and notifications, right? Now, technically speaking, the, the regime under MiCA for whitepapers is notification based. So it's not an approval based system. Technically speaking, you do not need the approval of the local regulator, of any regulator you notify the whitepaper to.

[00:26:00] Joseph Axisa: However, if it has material deficiencies, obviously the regulator will probably come back to you and tell you, "Listen, this needs to be fixed." You can't submit half of a whitepaper. That probably won't be accepted, right? Usually, I would say the main, main section that the regulator has come back to us and told us, "Listen, this needs to be beefed up a bit," is the financials of sort of the entity that's submitting that whitepaper.

[00:26:20] Joseph Axisa: 'Cause the reality is, and probably Umar you've faced this quite a bit given you're more on the accounting finance side of things, is that a lot of these Cayman Foundations or BVI business companies that are operated offshore, sometimes they're not well taken care of from a financial point of view. So in the financial section when you ask for how much capital does it have, runway, cost expenditure, et cetera, you know, these are some of the queries that we ask the clients to get a better picture and understanding of that entity.

[00:26:44] Joseph Axisa: They're like, "Um, we don't actually precisely know." So usually when clients tell us, "Listen, this is all the information I have," and we ask them, "But do you actually want to submit it with this information?" The MFSA actually comes back to us and tell us, tells us this needs to be beefed up. So it's a bit of an I-told-you-so moment for the client, you know?

[00:27:02] Joseph Axisa: That's, that's I would say the main section. Other than that, usually the other sections, which is either the legal opinion or anything else, they're relatively run-of-the-mill in the sense we know what standard the MFSA requires, we know what standards we have to, we have to meet also from an ESMA, point of view.

[00:27:16] Joseph Axisa: So we haven't, I would say, gotten any pushback aside from that section, which is not necessarily pushback, it's more, "Listen, like, add a bit more detail to this particular section." Because at the end of the day, whitepapers are there, or rather the concept, I would say the overarching concept is to make the investor base that's gonna buy your token have a bit more knowledge on what token they're buying.

[00:27:35] Joseph Axisa: So ideally they will have a bit of knowledge on, listen, the entity that issued this token, if it's gonna go bankrupt in the next two months or not. So that's why I would say you need a bit more detail.

[00:27:45] Umar: Before we continue, we'll take a quick commercial break from our sponsor. Whenever you use cryptocurrencies for your business, the framework for your bookkeeping is a combination of traditional accounting software like QuickBooks, Xero, Oracle NetSuite, and a crypto subledger which would extract, process, and feed in transactions from wallets, exchanges, and custodians into your accounting software.

[00:28:09] Umar: Kryptos Enterprise is a SOC 2-certified accounting software built for crypto and integrates with 150 plus blockchains, 100 plus exchanges, 50 plus wallets and over 5,000 DeFi protocols.

[00:28:25] Umar: Using a crypto subledger, you can automatically categorize and track your gas fees, realized gains and losses on trades, and create custom categorization rules.

[00:28:36] Umar: And once categorized, you have the ability to bulk sync your transactions into your accounting software.

[00:28:43] Umar: And with their MCP server, you can now connect your AI assistant like Claude, Cursor, or ChatGPT into your Kryptos account to categorize, reconcile, and sync transactions.

[00:28:55] Umar: If you're still managing crypto on spreadsheets, you're making your life harder than it needs to be.

[00:29:01] Umar: Right now, Kryptos is offering you 10% for the first year of subscription. Check out the link in the description to claim this offer.

[00:29:10] Umar: Now, I mentioned this Other category earlier. I, I said there are 493 entities, and they don't fall under ART or EMT. Now, if these entities want to offer their crypto asset to the public in the EU, they need to submit also a whitepaper.

[00:29:27] Umar: It's called the Title II whitepaper. Now, you've filed a large, of these kinds of whitepapers as well, and I looked up in Malta, you have well-known companies like WalletConnect, ether.fi, which is one of your clients, Aerodrome, Berachain, the Sei Foundation, to name a few. Could you walk us through this Title II whitepaper, and what this other category basically, like what kind of companies actually fit under this other category, and how it differs, let's say, from another whitepaper, let's say for a CASP?

[00:30:01] Joseph Axisa: Yeah, I would say, again, whitepapers are mainly asset-centric, right? So they don't necessarily cater for the services providers. So sort of to segregate the two, a whitepaper is mainly for token issuers, so it's very, very token-centric. So you have to submit a whitepaper in three instances. Either you're issuing and offering an EMT, an EMT to the public, which is your classic stablecoin, USDC, as you mentioned, Umar.

[00:30:24] Joseph Axisa: An ART, which we have none at this particular moment, or an other crypto asset. I would say definitely the most amount of whitepapers that have been submitted is other crypto assets, because the reality is, within the industry, a lot of the tokens that are available for trading at the moment are governance tokens, utility tokens from an industry point of view, payment tokens, which would be, you know, why buy a token and I can pay for gas fees on a chain, which would fall under the industry term of a utility token.

[00:30:49] Joseph Axisa: So that's definitely why there's most volume in that, in that regard, because it's, it captures, I would say, the vast majority of tokens that you would find on CoinMarketCap, for example. I would say the same elements that we discussed on the admission to trading and offering to the public whitepapers apply to these.

[00:31:04] Joseph Axisa: So it would be your same sort of equivalent disclosures. Whitepapers for EMTs or ARTs then have different disclosures that have to be made, such as the reserves, the backing, the entity that's issuing that has to be based in the European Union, that it has the necessary authorization to do so. You know, if you're issuing an EMT within the EU, you have to be an EMI.

[00:31:23] Joseph Axisa: So there's a bit of a matrix here, which how I would classify the, classify it as is your stablecoin issuer as an EMT, your ART provider, which we have none at the moment, although we might be the first one to get an ART authorization within the EU, fingers crossed. And then you have your other crypto assets, which would be, just to mention one, for example, the BERA token on Berachain, since you mentioned Berachain,

[00:31:46] Joseph Axisa: right? The FEI token, uh, which is on the Sei blockchain. You know, Ethereum ETH, as a gas fee token on the Ethereum blockchain. Those would be your other crypto assets.

[00:31:55] Umar: Wait, just to make sure I understand. So basically all the, like, all L1s, L2s need to have, like, MiCA licenses?

[00:32:03] Joseph Axisa: That they need to have if they want to admit their token to trading in the EU or offer their token to the public within the EU, they will need to have their MiCA white paper. The sort of MiCA authorizations, which are crypto asset service providers, so, you know, OKX, for example, being an exchange licensed as a Class III, authorized as a Class III crypto asset service provider within the EU, that's your service provider.

[00:32:25] Joseph Axisa: Then you have your token issuers, token offerors, which is an L1 that has a native token to pay for gas fees on a chain. It's either going to admit that token to trading on an exchange license as a CASP, so it would need a white paper for admission to trading, or it may offer the token to the public within the EU.

[00:32:40] Joseph Axisa: So it would need a white paper for an offer to the public

[00:32:43] Umar: Got it. Now, there are already legal frameworks that govern electronic payments across the EU, and for the listeners, if these acronyms are familiar, so PSD2 and EMD2, the Payment Services Directive and the Electronic Money Directive.

[00:33:01] Umar: Now, let's say for a crypto payments platform, for a stablecoin issuer or a company offering like off-ramping of stablecoins, on-ramping, off-ramping. Now, there's a tension between MiCA and these existing directive.

[00:33:16] Umar: Let's say, let's take an example for a payments platform built around stablecoins. How would you help a client figure out which of the, their activities, you know, trigger these existing payment directives on top of MiCA, and which one would stay within MiCA, if you have a good example to give us?

[00:33:36] Joseph Axisa: Yeah, de- definitely. So there was, just to give a bit more context, a no action letter by the European Banking Authority, a couple, a couple of months back, I think it was earlier this year, which basically said that electronic money tokens, so your USDC, as an example, are also e-money under EMD2, which is the Electronic Money Directive within the EU.

[00:33:57] Joseph Axisa: And electronic money is deemed to be funds, which goes then under PSD2. So at any point in time where you're applying for a crypto asset service provider at this point in time within the EU, if I'm applying for a crypto asset service provider and I'm enabling the custody, the trading, et cetera, of electronic money tokens, technically then I'm also triggering PSD2.

[00:34:17] Joseph Axisa: So the trend you see at this particular point in time with many authorized institutions within Europe is that it's very rare to find, for example, a Class III exchange, so your classic full-blown trading exchange that only has a CASP. Usually, they have a CASP and a PSP authorization, because if they're handling stablecoins, they would need a PSP authorization to handle those stablecoins.

[00:34:39] Joseph Axisa: So it's a bit of a trickle-down ef- effect and a bit of a conflict between the two regulatory regimes here that we have, which is basically an EMT, which is a stablecoin onchain. An EMT is e-money because an electronic money institution is issuing it, so it's deemed to be e-money as well, and e-money is deemed to be funds, which funds then fall under PSD2.

[00:34:59] Joseph Axisa: So usually, if you have, for example, a custody account for stablecoins, that custody account is also deemed to be a payment account, which is why you need a PSP.

[00:35:08] Joseph Axisa: Now, there have been people that have said that with PSD3, again, another acronym, we're voicing a lot of acronyms at the moment. It might be confusing.

[00:35:16] Joseph Axisa: Maybe we have to provide a glossary at this point. With PSD3, this particular dynamic or this particular conflict between the two regulatory frameworks might be solved.

[00:35:26] Joseph Axisa: This obviously PSD2 is, is still, I would say, a bit of time down the road, so we don't know yet, but hopefully it is. Because the only reason that some of these CASP are getting payment service provider authorizations to operate these payment accounts, which are custody accounts under MiCA, providing custody and administration of crypto assets, is basically because they're handling stablecoins.

[00:35:45] Joseph Axisa: Most of the time, they're not running a PSP business. They're just, they're just having stablecoins within their operations. Notwithstanding that, you also have crypto asset service providers that apply for a PSP authorization because they actually need a PSP authorization. Th-this conflict between the laws aside, because they're either offering payment instruments, which would be card programs, for example.

[00:36:05] Joseph Axisa: They're either in the payment remittance business. So it could be a, a myriad of different things which are in the schedule, of the Payment Services Directive. So there is a bit of a conflict here, but just to give you an example, Umar, because you asked for an example, just to give a more tangible sort of feel to this.

[00:36:20] Joseph Axisa: For example, let's say these neobanks, right, which are the trend at the moment within crypto. You see neobank popping up all the time. In my opinion, these are all PSPs. So these are all payment service providers that will also need a crypto asset service provider authorization. So, uh, let's say neobank XYZ, you're able to deposit stablecoins within this PSP. You're able to convert those stablecoins to fiat or deposit fiat and buy stablecoins. They will issue you a card to then spend that fiat or crypto. If they're using Rain on the back end, you can spend crypto, and Rain then settles with Visa, for example.

[00:36:56] Joseph Axisa: That would be a classic example of a dual-authorized CASP and payment service provider within the European Union. And if you look at all these neobanks, they basically operate the same business model, and it's a bit of a distribution game at this point in time. So they're, they're not offering a lot of different sort of features, so to speak.

[00:37:13] Joseph Axisa: They're your classic deposit, convert, spend, remit, reconcile, etc. So that's, I would say, a classic example of an entity that would need a, a dual authorization in this regard

[00:37:24] Umar: Okay, very clear. Thanks for sharing that example.

[00:37:28] Joseph Axisa: Yeah.

[00:37:29] Umar: Now, I want to move on to a bit of a different topic, which is around an article that you wrote.

[00:37:35] Umar: So this, this topic is around interpreting onchain actions and smart contracts for MiCA.

[00:37:41] Umar: I will share the article, with our listeners. And in this article, you go through a gray area in MiCA, which is whether DeFi front ends and interfaces should themselves be regulated. So your analysis draws a distinction between, you know, the passive front end that you, you're seeing the on-chain data versus an active front end that is encoding smart contract calls, estimating gas fees, and, assembles a transaction payload for the user to sign.

[00:38:11] Umar: Now, for listeners who are advising or building products, you know, that sit in front of smart contracts, how do you walk through that active versus passive test with a client?

[00:38:22] Joseph Axisa: Yeah, I would say first of all, even for our clients that are seeking a crypto asset service provider authorization within the EU, the first thing that we always do is regulatory assessment.

[00:38:31] Joseph Axisa: So the benefit with Axis, and this is a bit of our unique selling point, is that we have an in-house technical team. So we're not just a lawyer that will ask you for a summary of what your product does and then advise you based on the summary you provide. Because what usually happens is clients give you a summary on what they think won't raise eyebrows, so then you're potentially misadvising them on certain things.

[00:38:51] Joseph Axisa: So what we literally ask for is send me your GitHub, send me your tech docs, we will look at the code. When you implement this approach, you find that a lot of these default protocols that allegedly wouldn't trigger regulation by sort of the opinions of other people would actually trigger regulation within the EU to a sort of degree under the, the MiCA regulation in particular.

[00:39:11] Joseph Axisa: On the front-end side, this has been a hot topic now for ages, even before MiCA, to be completely honest. You know, there was this whole sort of front-end shouldn't be regulated, it's just a website at the end of the day, it's a general user interface. But the reality is, and that's why we segregated them between active and passive front-end, because I like to give a bit of archetypes when we write sort of our research pieces, right?

[00:39:31] Joseph Axisa: Because it's very difficult to discuss everything generally. So at least you have an active front-end and a passive. A passive front-end is a read-only front-end. So it has no API integrations, does not build your transaction, does not process your transaction, that API does not choose the liquidity pool that transaction is settled into, etc.

[00:39:49] Joseph Axisa: Right? That's your passive front-end, which in our opinion wouldn't be regulated within the European Union because it's not doing anything.

[00:39:56] Umar: Sorry, can you just give an example of what that passive front-end could be, like the well-known web3 projects?

[00:40:02] Joseph Axisa: So I would say a passive front-end would be, for example, Etherscan.

[00:40:05] Joseph Axisa: That's a passive front-end. Now, a lot of people don't know that you can actually build a transaction in Etherscan to process the transaction, but you can actually get that done through Etherscan. Uniswap, I forgot the exact name of this front-end, also have a passive front-end, uh, which is basically a read-only sort of general user interface where you see the transactions that are happening, liquidity thresholds and liquidity pools, etc.

[00:40:25] Joseph Axisa: That's a classic example of a read-only front-end, right? You can't process transactions directly through that front-end whereby that front-end through API calls can actually have some arbitrary discretion over where that transaction is settled, for example.

[00:40:39] Joseph Axisa: Your active front-ends are, a classic example of this, an aggregator, so a DeFi aggregator I go to the aggregator, I tell it I want to convert USDC to USDT for the sake of the argument, and it does not give me an option, for example, on where the transaction is going to be settled.

[00:40:57] Joseph Axisa: It does not give me the choice to choose the liquidity pool. It does not give me the choice to choose the venue, nothing of the sort. So it does everything for me, which is from a user experience point of view, great, fantastic. From a regulatory point of view, what's actually happening on the back end is that front end is connected to certain API integrations that build the transaction for the conversion of USDC to USDT that stores the ideal liquidity pool to convert from USDC to USDT, et cetera.

[00:41:26] Joseph Axisa: There are a myriad of different actions this front end could be doing, which potentially triggers one or two services under MiCA, which would predominantly be reception and transmission of orders and execution of orders on behalf of clients. Now, I'm not saying it triggers both or it always triggers both or one or the other, but certain front ends we have analyzed, which we try not to mention on our blog post because we don't want to put these protocols under the, under the eye of a regulator.

[00:41:51] Joseph Axisa: I would say that's pretty insensible sometimes. They actually would be triggering these particular regulatory services under MiCA. So that's a classic example of an active front end. The most form of an active front end that triggers regulation, in our opinion, is an aggregator, which there are a lot obviously, within the industry.

[00:42:08] Joseph Axisa: Why? Because I don't want to be the one looking at whether Uniswap is best or Cowswap is best to execute the transaction. I'd rather go to one portal. That portal picks the best route for me and executes that transaction for me, as well. In fact, so much so that this is the case that we're actually working on a regulatory authorization for a protocol that does something very, very similar.

[00:42:28] Joseph Axisa: It's almost equivalent to this. So with a swap and bridge provider, you want to convert USDC from Ethereum to USDT on, uh, Solana, and it chooses the ideal liquidity for you and gets you from one chain to the other. And obviously it needs a regulatory authorization, so we're working on the regulatory authorization for them.

[00:42:46] Umar: In the same article, you go through an exemption, the MiCA Recital 22, which- Yeah ... exempts services provided it's a, in a, it's in a fully decentralized manner without an intermediary. How realistic is it for projects today to claim that exemption?

[00:43:03] Umar: Do you have examples of DeFi projects that would claim that?

[00:43:07] Joseph Axisa: So I would say that Recital causes quite a bit of issues. From an industry perspective, it causes a bit of issues because they see that recital, which is fully decentralized without any intermediary in place equals exempt from MiCA, and they're like, "We're a DeFi protocol, so MiCA doesn't apply to us."

[00:43:23] Joseph Axisa: The reality is when you look at the tech stack, they would have admin keys to upgrade functions. They would have admin keys to move funds from one liquidity pool to the other. They would be able to upgrade contracts via proxy contracts, initialization contracts, etc., which is not DeFi. It's basically an onchain service, but onchain finance, as I call it, but not decentralized finance.

[00:43:44] Joseph Axisa: A classic example of a pure true DeFi protocol, in my opinion, is a DeFi protocol where I can deposit assets to, and no one arbitrarily, in some way, shape, or form, can execute a button, push a button, execute a transaction to move my funds, administer my funds, or influence my funds in any way, shape, or form.

[00:44:03] Joseph Axisa: I would say to-- We haven't assessed it, so it's a disclaimer, but if I were to think of one that would potentially benefit from this exemption, it would be something like Compound, for example, where Compound is decentralized to the point where actually its initial development company completely abandoned the development of the Compound protocol, but Compound still has user assets in it and still works to this day.

[00:44:24] Joseph Axisa: So it's, it completely runs on its own. There isn't one single party that can halt, stop, or cease the operation of this particular protocol. That's potentially a protocol type that would potentially benefit from this. The issue that this recital has caused is, first of all, it's in a recital, so it's not as detailed as a regulatory provision defining what they actually mean by fully decentralized, defining what they actually mean by intermediary.

[00:44:48] Joseph Axisa: Is it an intermediary in the traditional finance sense, or are they thinking of an intermediary in some form of crypto sense? ESMA and the EBA has provided zero guidance on what, in their opinion, would be a protocol that's fully decentralized without any intermediary in place.

[00:45:02] Joseph Axisa: Notwithstanding, there have been some consultation papers, there have been some discussions at the EU level as well on what DeFi is.

[00:45:08] Joseph Axisa: So I think they're still trying to understand what they actually mean or what is to be a fully decentralized protocol without any intermediary in place.

[00:45:17] Umar: I mean, for all these DeFi projects with MiCA, what they have to provide, like, kind of information for their users, like those are pseudonymous users, what they have to, like, provide?

[00:45:28] Joseph Axisa: If they are regulated under MiCA?

[00:45:30] Umar: Yeah, for their pseudonymous users who use those DeFi platforms.

[00:45:35] Joseph Axisa: So if you're regulated under MiCA, so let's say-- let, let's classify the two, right? For the sake of, I would say Clarity even, even with the listener. So you have-- we have onchain finance, which in my opinion is in DeFi.

[00:45:45] Joseph Axisa: So that euphoric, uh, Uniswap V4, I would say implementation, and you're able to operate these smart contracts at your whim. You're able to move funds, you're able to whatever, move positions within the pool, et cetera. That's onchain finance in my opinion. Then we have DeFi, and let's reference Compound for the sake of the argument, right?

[00:46:04] Joseph Axisa: To give an example. Now, disclaimer again, we haven't assessed whether Compound is fully, fully decentralized, but in my opinion, maybe it is one that would classify as such. On the onchain finance side, if some-one of these protocols wants to get regulatory authorization under MiCA, there are AML, directives in place within the European Union that you have to abide to.

[00:46:22] Joseph Axisa: So you can't have just pseudonymous users using your protocol. You have to KYC or KYB in the case of a company, your user base. But I would say the main reason that some of these DeFi protocols aren't seeking authorization isn't necessarily because they don't want it or they don't think it would be good for, I would say, legitimacy purposes.

[00:46:40] Joseph Axisa: It's more because they know that if, listen, if I implement KYC for my protocol, I'm basically done for. I'm not gonna get any form of user base. Which is why a lot of these DeFi protocols operate through like Panama structures, BVI structures, et cetera. I would go on a whim and say that a lot of these onchain finance protocols that send them that are even difficult to operate through a Cayman Islands or BVI company due to the vault packs that are available in the Cayman Islands.

[00:47:04] Joseph Axisa: So you see the bulk of them, the front ends would be offered through a Panama company, for example, for some form of regulatory arbitrage, which is never airtight, by the way.

[00:47:14] Umar: Okay. You operate from Panama, but let's say, I don't wanna name projects, but that DeFi protocol is not MiCA licensed, but I can still use them in Europe. Is that like wha-what- I

[00:47:26] Joseph Axisa: would say-- Yeah, I would say then we get into the argument of whether something is reverse solicitation or direct solicitation.

[00:47:33] Joseph Axisa: So in the European Union, and to be fair globally, when you have a regulation, you have two forms of basically solicitation, let me call them, let's call them marketing for the sake of simplicity. There's reverse solicitation, which is I have a protocol that I operate from the Cayman Islands, but European users come to me.

[00:47:50] Joseph Axisa: I don't put a banner up in Malta stating, "Come trade on XYZ aggregator." You just use my protocol because you found it through Twitter. I have good tech, I have good slippage schemes, whatever it, whatever it can be, and you use my protocol. That would be reverse solicitation. I would not be triggering MiCA in the case of reverse solicitation.

[00:48:08] Joseph Axisa: And also to highlight, reverse solicitation is very, very tricky in the MiCA context, so it's very, very strict. So there are certain scenarios where, you know, with certain things you do, this wouldn't apply. Direct solicitation is I have a protocol that I operate from the Cayman Islands. It would trigger MiCA if I directly solicit.

[00:48:25] Joseph Axisa: So if I put a banner up in Malta stating, "Come trade on my protocol," and I go and directly solicit them, put a banner up on Malta. The reality is I'd probably get slapped with a fine, an enforcement action equivalent or a warning from the regulator stating, "Listen, you have to cease these activities. In our opinion, your protocol needs to get licensed and you're not licensed."

[00:48:42] Joseph Axisa: That's the two classes of forms of solicitation under most regulation, to be fair, within the European Union and globally, but specifically in the MiCA context. Now, what most of these protocols do is they operate offshore, but they have some regulatory risk mitigation measures that they put in place. So simple things, you know, which again, none of these are completely airtight at the end of the day.

[00:49:04] Joseph Axisa: So on your front end, you don't put the German flag as a German language site, you know, for people to, to translate to. You don't go to conferences in the EU and market the services of your protocol. You don't employ KOLs that have region-oriented YouTube channels to market your protocol. There are different and various things that protocols try to do, especially the more serious ones, I would say, to make sure that they're not directly soliciting to the European Union

[00:49:30] Umar: Wow.

[00:49:30] Umar: Okay. This is very interesting.

[00:49:32] Joseph Axisa: It's mainly what I do. So at Paxos, sort of, well, Patrick, Jake, and the team that handles the MiCA authorizations, which I find relatively boring, I handle more the DeFi protocols, right? Which this stuff is what I find interesting, because it's a bit more legal engineering, I would say.

[00:49:47] Joseph Axisa: Yeah, yeah,

[00:49:47] Umar: Now, there's a next topic I want to go through today, Joseph, is around onchain vaults. So for the listeners, onchain vaults are, if you're hearing it for the first time, they are vehicles for onchain asset management. The difference between traditional management here is that, you know, they use smart contracts and, uh, rather than, let's say, the expensive middlemen, the trustees, custodians, et cetera.

[00:50:10] Umar: Now, the argument here is that a well-designed lending vault should fall outside of MiCA's CASP perimeter because none of the... There's, like, MiCA lists 10, crypto asset services and what a curator does on the onchain vaults, it doesn't fit one of those services. The curator is analogous to what a fund manager is in TradFi.

[00:50:34] Umar: They would decide what crypto assets to buy. Now, recently, the European Commission, they launched a consultation that asked whether crypto lending and borrowing currently untouched by the, by MiCA should now be brought into scope. Uh, responses are due by 31st August of this month.

[00:50:55] Umar: Now, I want to ask you, what does that mean for a curator who's structured around a vault?

[00:51:01] Umar: Is MiCA's reading today favorable to them?

[00:51:05] Joseph Axisa: So I would say just because you have a crypto protocol and there's something to emphasize does not mean that only MiCA may apply to you. Like you could have a token which would represent Tesla stock for the sake of the argument, and MiCA specifically states that, and this is why like the regulatory assessment and the token legal opinion is important, because just because you're onchain doesn't mean that MiCA applies.

[00:51:26] Joseph Axisa: If you're onchain but your token functions as a financial instrument, a bond, an equity, a CFD, whatever it may be, then you go outside of MiCA completely and you go into the traditional financial instrument regime which is called MiFID II in the European Union. So it's all substance-based. Just because you're on-chain does not mean that only MiCA applies.

[00:51:43] Joseph Axisa: You could be triggering different forms of regulations or directives within the European Union. Now coincidentally, as I even mentioned before this podcast, Umar, we literally wrote a paper like two days ago on how vaults would be regulated within the European Union that I think we can also link, in this podcast.

[00:51:58] Joseph Axisa: Now again, we, we take a tech-first approach to analyzing everything. So we don't just look at what's marketed or what's branded by these vault providers or by these curators and these vault providers, right? We actually look at the substance. So we look at what smart contract calls are there, who has control, who sets the investment policy, etc.

[00:52:16] Joseph Axisa: What we found from that research piece, paper, blog post, call it whatever you may, is that a lot of the curator vault-oriented protocols don't trigger MiCA, right? Unless they actually offer MiCA services such as custodying the stablecoins, offering execution, etc. Most of them actually trigger AIFMD which is the funds regime within the European Union.

[00:52:38] Joseph Axisa: Because if you look at a vault, first of all, the main use case of a vault is fund managers and fund providers. If you look at the main update of these vault products, it's usually these fund managers and fund providers that are actually really, really interested in vault products because they make things such as accounting, the bookkeeping of the vault and the reconciliation from a fund admin point of view really, really easy and this is kind of a unique selling point of blockchain technology.

[00:53:01] Joseph Axisa: Like if I transfer from Joseph to Umar, it's very easy to see onchain and reconcile after the fact. So that's a unique selling point of these vault products that are onchain. What we saw when we looked at the specific sort of smart contract calls is that, le-let's mention a curator vault, right? So I deposit an asset into a vault.

[00:53:19] Joseph Axisa: There is a curator which sets a particular investment policy. These assets are gonna be deposited into Aave, they're gonna be lent out, they're gonna generate yield, we're gonna buy spot Bitcoin, whatever it may be. It can be anything really and truly, right? I can license the tech from a vault provider, operate the vault, and I can tweak the investment policy however I want.

[00:53:38] Joseph Axisa: Now, to trigger sort of the fund regime at a high level and generally speaking within the European Union, you need to satisfy some limbs. So you have the pooling of capital. So you have to have users pooling capital in a particular sort of smart contract in this particular case, right? There needs to be an investment purpose so that capital is pooled, that capital is collected from users to actually generate a return for the users, and there needs to be a defined investment policy.

[00:54:02] Joseph Axisa: I would say those are sort of the three limbs that would generally be satisfied when you trigger fund regulation or to operate a fund within the European Union in particular. In a lot of common law countries, actually, the, the definition is very, very similar, if not equivalent as well. If you look at how some of these curator vaults work, it satisfies each and every limb.

[00:54:22] Joseph Axisa: You have the pooling of capital, which is the deposits that are accrued in a vault. So Umar, Joseph, anyone can deposit capital into the vault, right? I deposit capital with an investment purpose. I'm not depositing my USDC into a vault for me to say I deposited USDC into a vault. I've, I deposit my USDC into a vault because I want to generate return on my USDC, right?

[00:54:43] Joseph Axisa: Whether it's three percent, four percent, that's completely irrelevant. There's also a defined investment policy, right? There is caps on certain things that can be done. There are absolute caps, relative caps, there are risk implementations. So that would be deemed a defined investment policy by European Union standards, and we looked at ESMA guidance to see whether this is the case.

[00:55:02] Joseph Axisa: We looked at on-chain actions to see whether they're satisfied and cross-referenced, sort of e-equivalently. And this is basically what we found. So if I were to look, 'cause I actually have the blog post in front of me here, sort of the on-chain actions that would trigger these. So for example, on the raising capital side of things, you're looking to raise capital from investors to pool that capital.

[00:55:21] Joseph Axisa: There's usually deposit or mint functions, and there's usually transfer functions as well. So I deposit from my wallet to the vault, and then it's transferred from my wallet to the vault, right? There's a pooled return because these are usually converted to what's called shares, which is more so an onchain sort of accounting, term more than anything.

[00:55:41] Joseph Axisa: Or sometimes they even get depository token. So I deposit USDC, and I get T-USDC, which would be my deposit, and then I can use that T-USDC, for example, to deposit into other yield protocols to generate yield on top of the yield I'm already generating in the vault. There's the defined investment policy. So as I mentioned, there are like submit cap functions, absolute cap functions, relative cap functions, there's supply queues, reallocation, max debt for the particular strategy if you're using lending pools.

[00:56:09] Joseph Axisa: I can go on and on, but the TLDR and the summary of this is that a classic curator vault as it's operated in this industry fits perfectly within the definition of a fund by European standards.

[00:56:20] Joseph Axisa: Now, there are some vault types where this is not the case, such as I deposit into a vault, but I have day-to-day discretion over how my funds are used or allocated within the vault.

[00:56:30] Joseph Axisa: The other exclusion from being a fund is there is a commercial purpose, right? So the two exclusions are you either have day-to-day discretion and control over your assets as an investor, or there is a commercial purpose. Those are the two reasons why you wouldn't be deemed a fund if you look and operate like a fund.

[00:56:46] Joseph Axisa: In the case, in most cases of these vault operators, if not all It's an investment purpose, right? I deposit into a vault to generate a return. I don't deposit in, in a vault to not generate a return. There are some though where users have some form of day-to-day discretion or control, I would say. But that's a very long article.

[00:57:02] Joseph Axisa: I would recommend people read it. I don't think-- I'm completely biased here, by the way. I don't think there's a more technically nuanced word verbiage paper out there on this particular topic, cross-referencing the European Union regulation, of funds as sort of they relate to vaults.

[00:57:20] Umar: I don't think so as well, Joseph.

[00:57:22] Umar: I'm briefly skimming through the article right now, and it's, yeah, it's really impressive. So I'll definitely be sharing the article. And just to understand something, so, there's two website, axisadvisory.xyz and axisgroup.xyz, right?

[00:57:36] Joseph Axisa: Yes. Yes. axisadvisory.xyz is our old website, which will be redirecting as of this week to axisgroup.xyz because now axisgroup.xyz is completely done.

[00:57:45] Joseph Axisa: We made some minor tweaks and integrations. But yeah, our main sort of website moving forward is definitely axisgroup.xyz.

[00:57:51] Umar: Okay, fantastic. Now there's, there's a last topic, Joseph. I'm looking at the time. The time has gone by fast. We are on the hour mark. But there's a last topic which I try to touch now on every episodes, which is around using AI.

[00:58:05] Umar: So as a lawyer working across MiCA, MiFID II, and now increasingly, increasingly the EU AI Act as well- Yeah ... how are you using AI today, at Axis, whether, yeah, across the different service lines and, you know, is there a part of MiCA compliance you think that AI can meaningfully take over the next few years?

[00:58:30] Joseph Axisa: Yeah. I would, I would say from a firm specific point of view, if you look at my LinkedIn articles, the only articles that I have published on LinkedIn myself, through my personal LinkedIn, are only in relation to AI and law firms. I personally got into sort of the business of law firms, advisory firms, et cetera, because I really hated how they were operated in the past.

[00:58:49] Joseph Axisa: I'm like, "I need to do this differently. I think I can do this differently and better," right? Now time will tell whether I can, by the way. It's still very early stages. But the point is, especially with AI, it unlocks quite a bit for traditional advisory firms like us, right? Before AI, you had to bill hourly for every single thing.

[00:59:06] Joseph Axisa: You had to extract as much value from clients with each and every minute in 15 minute increments for every single little thing you do, whether it's communications, calls, whatever it may be. AI kind of breaks that Ouroboros wheel, so to speak. So what law firms have always suffered from, in my personal opinion, is a capacity issue.

[00:59:22] Joseph Axisa: So you have two employees. Those two employees work eight hours a day, so they can bill a particular hourly rate for eight hours a day. Every time you reach your capacity, you have to get more employees. So your revenues and your margins and your capacity have to constantly be up to that, which leads to your profit margin basically staying the same or increasing by a couple of percentile points per year, for example.

[00:59:46] Joseph Axisa: How we're using AI at Axis, first of all, we're running quite a bit of experiments. Anything from agentic systems to running open source models on our own server, to make sure there's confidentiality obligations that are being met, and also from a GDPR standpoint, everything is sound. And we're also using like things like Claude Cowork, et cetera.

[01:00:04] Joseph Axisa: How we're using it at the moment before one of these experiment is good enough to justify implementing it across the firm is currently, for example, for first draft agreement, first draft policies, we use Claude Cowork and proprietary skills that we've developed in Claude Cowork to actually get that first draft.

[01:00:19] Joseph Axisa: Now, we don't put any client data in Claude. We don't put any data that would be lead to the identifiability of the client. And Claude will have a very strict policy for this, and we monitor everyone's usage on Claude quite viciously, so to speak. I want my employees at the end of the day to use Claude as much as possible.

[01:00:36] Joseph Axisa: Like, when I see someone that has twenty percent usage this month, I'm like, "You're either being inefficient or you're not doing your work." The, the-- it, it's one of the two. It can't be a good thing ever. What this leads to for firms, in my opinion, is you get to do work faster, you get to do it better, and we're able to charge lower fees for clients at the end of the day, which for me is the most important thing.

[01:00:59] Joseph Axisa: Again, I got into this with the whole concept of I need to improve the user experience for end clients even with law firms. You know that you usually send an email, hop on a call, then get charged hourly for every time a client says hello to you. I hate that completely. In fact, we never charge any, any form of time for calls, whether they take an hour, two, three, whatever.

[01:01:18] Joseph Axisa: I hate it. It makes the relationship too artificial at that point in time. With LLMs, I would say that initial first draft, that initial first layer of having your skeleton for an agreement, for an assessment, etc., is done for you. And usually where you would have charged ten hours to get the, the, the first draft, now I can charge fifty percent less and charge a fixed fee.

[01:01:37] Joseph Axisa: So we've basically omitted almost entirely the hourly rates at our firms. I only allocate an hourly rate for a client where the client requests it. We have more of a subscription-based model at the moment. So right now what we have is we literally put it onto Twitter yesterday, actually, on the Axis Group XYZ Twitter.

[01:01:53] Joseph Axisa: We literally have new subscription services. So for most of these DeFi protocols, you pay anywhere from 4.5k to 9k a month, depending on scale, depending on complexity, depending on what you need, and you basically get a set of agreement reviews, agreement draft, consulting, advisory, etc., per month.

[01:02:10] Joseph Axisa: This has a couple of pros. First of all, for me, it's more recurring revenue, so it's great for the firm, and that's the selfish point of view. For the client, they can budget more, and they're getting double the deliverable for lesser cost. Because I made all our clients aware, like, "Listen, we're testing this out, we're using AI for first draft.

[01:02:28] Joseph Axisa: Are you comfortable with this?" All of our clients were like, "Yes. If you can do it faster and better, it's great." And the reality is, with LLMs, they can do a better job more than most lawyers. Like, any lawyer that says that this is not the case is probably lying to themselves or to someone else. So that's the reality of the situation.

[01:02:45] Joseph Axisa: So I think there are several pros to implementing AI as a firm. I think you have to be very careful, very strict from a data point of view, from a privilege point of view, because you don't want to give data to Anthropic on your clients at the end of the day. But I think it unlocks a problem that has sort of plagued the law firm advisory firm industry for decades now, which for us is honestly a blessing.

[01:03:08] Joseph Axisa: Like, if I can make my law firm more accessible to end clients and provide services cheaper, like, clients at the end of the day are not paying me for an agreement. They're paying me for my judgment on the agreement. They're paying me because we have six years of working with the best companies in the space.

[01:03:26] Joseph Axisa: They don't care about whether you mark the provision as 2.8 or 2.8A1. They, they couldn't care less. What they're paying for is the context that you've accumulated over time. So they're indifferent as to whether you're drafting word for word on the agreement. What they want is, "Listen, based on the 100 times you've done this, is this fine?"

[01:03:42] Joseph Axisa: So I think we're transitioning to an era where clients pay law firms for judgment. They don't pay them for word soup at the end of the day, which is where lawyers need to be, in my opinion

[01:03:54] Umar: Yeah. Joseph, this has been a fascinating conversation. It's time to wrap up the episode. As closing thoughts, the title of the episode today was The State of MiCA Compliance.

[01:04:05] Umar: Has there been anything that we didn't touch on that you'd like to share with the listeners, or how would you just summarize this episode for the listeners?

[01:04:13] Joseph Axisa: Yeah, I would say, I would say to summarize, I would say the key takeaways for sort of listeners to take away, it's sort of the different obligations for token issuers, and we've discussed different asset types and the two types of a white paper that we need to notify, which is the offer to the public white paper and the admission to trading one.

[01:04:27] Joseph Axisa: We've also touched upon, I think very well, although briefly, but it's, you know, a podcast episode at the end of the day, on sort of crypto asset service providers, certain iterations and how those are regulated. And most importantly, I think is the main thing to take home is just because you say you're DeFi doesn't mean you're not regulated because the large majority of DeFi protocols within the industry are just on-chain finance, centralized control protocols on-chain.

[01:04:51] Joseph Axisa: So if you're operating a DeFi protocol and you're going-- you're marketing your DeFi protocol in the European Union, I'll be very, very careful. That's all, I would say.

[01:04:58] Umar: Perfect. I always like to also end the episode by asking my guests if they have a favorite quote or a maxim that they live by.

[01:05:09] Joseph Axisa: I do actually.

[01:05:11] Joseph Axisa: Um, and I actually have a tattoo. I have quite a couple of tattoos. And it's, you know, before I started the firm, I was very much into stoicism, like stoic philosophy, and this term called like amor fati, which is basically like nothing that's not meant to happen will happen, sort of trust your destiny kind of thing.

[01:05:26] Joseph Axisa: And there's another one which is like, the obstacle is the way. Now running a firm at 27 years of age, there are a lot of obstacles there. So I try to think of those two whenever I have a day where I'm like, "Jesus Christ, I really don't want to deal with this today." But yeah, they keep me grounded, I would say.

[01:05:40] Joseph Axisa: They really keep me grounded.

[01:05:41] Umar: Yeah. I'm sure you're a fan of Ryan Holiday's books as well.

[01:05:44] Joseph Axisa: Yes, I've read them all.

[01:05:46] Umar: Okay. Fantastic. Joseph, if people want to reach out to you at Axis, what's the best way to do it? Is it through your website, through socials?

[01:05:57] Joseph Axisa: Yeah. So you can reach, reach out to us and book a call through our website, actually.

[01:06:01] Joseph Axisa: There's the button to book a call immediately, and you'll get access to my calendar, which also ropes in the team. You can reach me on Twitter or Telegram @immutablelawyer, as well, or at joseph@axisgroup.xyz. Um, so yeah,

[01:06:15] Joseph Axisa: those are, I would say, our main forms of communication, mainly Telegram, to be honest. Like my Telegram, every time I wake up and open it, I get attacked by 50 group chats every day, so...

[01:06:27] Umar: Perfect. I'll be sharing all those links in the show notes for the listeners. Joseph, thanks a lot for your time. It's been a pleasure, and, we'll stay in touch.

[01:06:36] Joseph Axisa: Perfect. Thanks a lot, Umar