
EU Commission reopens MiCA review on crypto lending, putting DeFi vaults in scope
A May 20 consultation running through Sept. 30 tests whether onchain lending fits MiCA and who counts as the regulated provider.
The European Commission is consulting on whether crypto lending and borrowing should be brought into MiCA, reopening a carve-out that left onchain credit largely outside the EU rulebook. DeFi lending vaults sit at the center of the problem because their control is split across roles, making it unclear who would be regulated if lending is pulled into scope.
MiCA’s Lending Carve-Out Is Back on the Table in Brussels
MiCA was built to license and supervise crypto-asset service providers across the EU, but it left crypto lending outside the original perimeter. That gap is now being stress-tested.
On May 20, 2026, the European Commission launched a targeted stakeholder consultation on areas left outside MiCA, explicitly including decentralized finance and crypto lending and borrowing. The consultation closes Sept. 30, 2026, and the outcome could determine whether lending vaults remain in a gray zone or face a new EU-wide compliance regime.
For traders, this is not an abstract policy cleanup. Lending vaults can route billions of dollars into onchain credit markets without looking like a conventional lender with a single balance sheet and a single operator. If Brussels decides that activity is functionally “lending” and should be regulated, the next question is the one that actually bites: who is the provider.
That uncertainty is already part of the market structure. The current legal status of vaults is described as relying on non-binding interpretations that they sit outside MiCA and EU fund rules. That is workable until it is not, and a Commission-led review is the mechanism that can turn “interpretation” into “requirement.”
Why DeFi Lending Vaults Break the “Who Is the Provider?” Model
EU law does not have a dedicated category for “vaults,” which pushes regulators toward a functional test. EU digital assets lawyer Yuriy Brisov, a partner at Digital & Analogue Partners, put it bluntly: “EU law has no category called a ‘vault.’ A lawyer therefore defines it the way a regulator would qualify it: by function, not by label.”
Function is where the friction starts. A DeFi lending vault pools user assets and allocates them into onchain credit strategies. The economic exposure can resemble lending, but the operational reality is fragmented across smart contracts and multiple participants. That fragmentation is not cosmetic. It is the design.
Morpho’s Vault V2 is a clean example because it splits responsibilities among an owner, curator, allocator, and sentinel. The curator configures strategy and risk parameters. The allocator executes allocations. The sentinel has powers intended to reduce risk. None of those roles maps neatly to the MiCA mental model of a single crypto-asset service provider running a service end-to-end.
That split control is also the likely enforcement hook if lending is pulled into scope. If policymakers decide a vault is “not fully decentralized,” they still need a person or entity to license, supervise, or sanction. Role-based control is the obvious place to look, and it creates second-order pressure on how protocols design permissions, governance, and delegation.
The policy debate is already forming around how to draw the line. MiCA excludes crypto-asset services provided in a “fully decentralized manner,” but it can apply where only part of an activity is decentralized. That carve-out sounds binary, but vaults are often neither fully centralized nor fully decentralized in practice.
Jonathan Galea, a partner at Cahill Gordon & Reindel, warned against treating “lending vaults” as one uniform category, arguing that “lending vaults solve more practical problems than they create.” His point is classification risk. Some vaults direct liquidity into lending markets, while other vaults may buy and sell crypto assets and should be treated differently. “Bring ‘DeFi lending’ into the perimeter as a single label, and structures that deserve opposite answers risk ending up captured together.”
Galea also pushed back on decentralization as the dividing line, calling it a moving target: “Decentralization is a spectrum and a function of time: a test built on it would penalize newer, more novel protocols while entrenching mature incumbents that have had years to distribute control.” Brisov’s alternative is structural and control-based: “The safer ground is structural: there is no undertaking, no appointed manager, the holder has a direct coded claim on the pool, and the user can exit before any parameter change takes effect.”
Sept. 30 Is the First Deadline: What to Monitor as the EU Debates Decentralization vs Structure
Sept. 30, 2026 is the first hard date because it closes the Commission’s consultation window. The next signal is whether subsequent Commission communications point toward adding lending and borrowing explicitly to the list of regulated crypto-asset services, rather than trying to stretch the definition of a crypto-asset service provider.
The second signal is interpretive, but it will drive outcomes: how EU policymakers apply MiCA’s “fully decentralized manner” exclusion to activities that are only partially decentralized. Vaults with onchain execution but offchain or role-based parameter control are the obvious edge case.
The third signal is where enforcement meets design. If policymakers focus on role-based control as the way to identify a regulated “provider,” expect the debate to shift from labels like “DeFi lending” to permissioning details like who can set risk parameters, who can route liquidity, and who can intervene in stress.
My Read: The Regulatory Risk Isn’t ‘DeFi Lending’—It’s How Brussels Draws the Line
The threshold that matters is not whether Brussels says “lending is risky.” That is already assumed. The real test is whether the Commission tries to regulate by category label or by control surface.
If the line is “not fully decentralized,” partially delegated vaults become the easy target, and the market impact is structural: protocols will be pushed to either centralize into a licensable operator or decentralize permissions beyond what risk management teams are comfortable with. If the line is role-based control, the compliance perimeter becomes a map of who can change parameters and move liquidity, and that is where vault design starts to change in practical terms.