The European Banking Authority (EBA) has called for crypto borrowing and lending to be brought under the European Union’s Markets in Crypto-Assets (MiCA) framework, in a submission that could shape the next major rewrite of the bloc’s crypto rulebook.
In its response to the European Commission’s targeted consultation on MiCA, the Paris-based regulator said crypto lending should be regulated, including cases where crypto-asset service providers facilitate their clients’ access to decentralized finance (DeFi) lending protocols.
Extending MiCA’s perimeter
MiCA, which took full effect for crypto-asset service providers across the EU in late 2024, currently covers services such as custody, exchange and portfolio management — but borrowing and lending in crypto assets were left out of the original framework. That gap has grown more conspicuous as lending products proliferated across European platforms, and the EBA now wants the Commission to consider closing it.
Specifically, the regulator recommended that the Commission conduct a cost-benefit analysis of legislative changes that would add intermediating crypto borrowing and lending to the list of regulated services under MiCA, along with specific compliance requirements and ongoing supervision for firms offering those services.
Suitability tests, leverage limits and disclosure
The EBA outlined a menu of potential measures that read like a checklist of the tools regulators deploy in traditional consumer finance. These include suitability tests for users before they can access lending products, limits on leverage, and additional disclosure requirements covering the risks of lending out crypto assets.
The authority also raised the possibility of restricting certain lending activity involving asset-referenced tokens or e-money tokens that require MiCA authorization — in plain terms, keeping unregulated lending markets away from regulated stablecoins. A further, more ambitious suggestion is a certification regime for DeFi lending protocols themselves, which would extend some form of regulatory recognition to smart-contract-based services that currently sit outside any supervisory perimeter.
Why the EBA is worried
Behind the technical language sits a practical concern: crypto lending is growing across the bloc, and the boundary between centralized and decentralized finance is blurring. The EBA cited previous research that found borrowing and lending activities in at least 16 EU member states, and noted that easier access to DeFi through crypto firms and artificial intelligence tools is accelerating the trend.
The reference to AI tools reflects an emerging worry among supervisors: as chatbots and agents make it trivially easy for retail users to move funds into yield-generating protocols, the traditional gatekeeping function of regulated intermediaries weakens. If a platform’s AI assistant can route a user into an unregulated lending protocol in a few clicks, the EBA argues, the platform should bear some responsibility for what happens next.
Part of a broader MiCA review
The recommendations form part of the EBA’s wider input into the Commission’s review of MiCA, a process that also covers the framework’s stablecoin rules, the classification of crypto assets and reporting requirements. The Commission has been gathering feedback from national regulators, industry groups and market participants, with legislative proposals expected to follow.
The timing is delicate for the European crypto industry. Firms are still absorbing the cost of MiCA compliance — authorization processes, capital requirements and governance obligations — and several major exchanges have restructured or scaled back their EU operations in response. Adding lending to the regulated perimeter would create new compliance burdens, but also a level of legal certainty that could let banks and larger institutions enter the market, a trade-off the Commission’s cost-benefit analysis will have to weigh.
DeFi’s regulatory moment approaches
Perhaps the most significant signal in the submission is the EBA’s willingness to engage with DeFi directly. European regulators have long struggled with how to supervise protocols that run without a traditional operator, and MiCA largely deferred the question. A certification regime for lending protocols, even in embryonic form, would be among the first concrete EU proposals to bring decentralized services inside a supervisory framework.
Industry observers expect pushback. DeFi developers argue that code is not a service provider and that certification requirements could freeze innovation or push protocols to geoblock European users altogether. Consumer groups, by contrast, have pointed to a string of lending-protocol exploits and liquidation cascades as evidence that unsupervised lending markets leave retail users exposed.
For now, nothing is decided: the EBA has offered analysis and options, not lawmaking. But the direction of travel is clear. Europe’s banking regulator believes crypto lending has outgrown its regulatory exemption, and the Commission will now have to decide whether the industry’s fastest-growing corner gets a rulebook of its own.
Market snapshot at time of writing: Bitcoin at 84,348 US dollars, Ether at 2,667.91 US dollars and Solana at 114.68 US dollars, according to CoinGecko data.
suitability tests for borrowing against your own collateral is where this gets absurd. imagine a credit check to open a CDP
of course the EBA wants lending inside MiCA. every regulator looks at celsius and blockfi and thinks, we need that in our jurisdiction
thats literally the point tho, they force the front doors to comply and pretend the protocol behind it is fine
certification regime for defi lending protocols sounds fun until you ask who actually gets certified. the DAO? the front end devs? good luck with that paperwork
the paperwork question is real. some DAO with a swiss association wrapper will get certified and everyone else pretends to be DeFi still
^ the EBA trying to fit a smart contract into a KYC form and wondering why it doesnt fit lol
Regulating CASP access to DeFi lending protocols is where this gets messy. How do you supervise a protocol itself? The consultation answers will be telling.
how do you supervise a protocol? same way they did with e money regs, you chase whoever hosts the front end and call it a day
chasing the front end host just pushes everything offshore like it did with mixers. the contracts keep running whether brussels certifies them or not
same fight as the TFR rules. perimeter creep, one consultation at a time
TFR took years to land and still has loopholes you can drive a van through. expect the same 80 percent solution here
Segregating regulated stablecoins from unregulated lending is the only practical suggestion here. The DeFi certification part will drag on for years.