Faculty of law blogs / UNIVERSITY OF OXFORD

Decentralization: The Search for a Legal Definition

Posted:

Time to read:

4 Minutes

Author(s):

Salvatore Luciano Furnari
PhD at the University of Roma Tor Vergata and Fintech and MiCAR lawyer with a focus on blockchain, crypto-assets, and DeFi

Decentralization is the criterion on which the regulatory treatment of decentralized finance ultimately depends, yet no legal instrument defines it. In a recent paper, I argue that this definitional vacuum is the root cause of the uncertainty surrounding decentralized protocols and so I propose a legal definition resting on three cumulative and verifiable criteria: the presence of at least three independent decision-making centres; the structural interdependence of participants within a protocol-governed environment; and the non-custodial nature of the infrastructure.

A threshold criterion without content

The most legally significant reference to decentralization in EU law is Recital 22 of the Markets in Crypto-Assets Regulation (MiCA), under which crypto-asset services provided ‘in a fully decentralised manner without any intermediary’ fall outside the scope of the Regulation. The concept is therefore decisive, but it appears only in a recital: no operative provision refers to protocols or to the offering of decentralized services, and no definition is supplied.

Supervisory practice has filled that space with candid admissions of uncertainty. In their January 2025 joint report under Article 142 MiCA, the EBA and ESMA confirmed that the Regulation applies where only part of an activity is decentralized, while acknowledging that MiCA does not specify how full decentralization is to be interpreted. ESMA had already observed that determining whether a service is partially or fully decentralized is not straightforward, and the French AMF has likewise concluded that only a case-by-case legal analysis can answer the question. The Danish FSA has gone furthest, proposing three assessment principles: whether a user can identify a legal entity as counterparty; whether smart contracts operate autonomously and without embedded control mechanisms; and whether decision-making power is genuinely dispersed. That guidance is valuable, but it is non-binding and offers no clear definition of a threshold capable of producing determinate outcomes.

The picture is no different at international level. ISO describes decentralization in terms too abstract to generate operational criteria. The FATF avoids a definition altogether and asks instead whether a person with sufficient control or influence exists. IOSCO states expressly that there is no agreed definition and identifies several distinct dimensions along which decentralization may be assessed. The BIS warns of a ‘decentralisation illusion’, and a recent ECB working paper documents how far governance token concentration in leading protocols departs from the theoretical ideal. 

Each authority approaches the concept from the angle of its own mandate; none engages with the definitional question as such.

Why measurement cannot do the work of legal qualification

The technical literature has been more ambitious. It has produced the Gini and Nakamoto coefficients, multilayered frameworks assessing the governance, network and storage layers separately, the five-dimensional TIGER framework, and indices quantifying a system’s exposure to the risk of centralization (such as the Apokedro index). These tools are analytically valuable, but they share two features that make them unsuitable for legal qualification: either they are static, capturing a snapshot at a moment when governance tokens remain tradable and their distribution can shift abruptly, or else they are probabilistic.

Legal norms, by contrast, operate through binary classification: a system is either within the regulatory perimeter or outside it. For a supervisor deciding whether the Recital 22 exemption ‘applies’, knowing that a given system has a 2% probability of being centralized is of no help.

Three cumulative criteria

Trying to cover the above illustrated absence of a clear definition, the paper proposes a three-step approach in order to assess whether a protocol is decentralized (ie whether a service is offered in a decentralized way or not):

First, at least three independent decision-making centres. A system is decentralized when (simply) it is not centralized. Centralization occurs where decision-making power over the entire system can be traced back to a single locus of control. The minimum number of independent actors (zero being excluded) that a system needs in order not to be centralized is three. Two actors still do not constitute a single centre of control, but the mutual veto inherent in a two-party structure compels unanimity and paralyses the system in its absence. Three is the smallest number at which a majority can form, and therefore the smallest number at which collective and decentralized governance becomes structurally possible.

Second, structural interdependence within an immutable protocol-governed environment. A protocol must be assessed holistically, taking into account its users and not only those who develop or control it. Even where control is de facto attributable to a single entity, the protocol cannot function without a plurality of actors performing distinct roles. Traditional services also require multiple actors—securities markets depend on brokers, clearing houses and trading venues—but there the decisive role belongs to a central authority. In a decentralized system it belongs to the immutable protocol itself: a set of rules to which all participants conform, which none of them can operate unilaterally, and whose basic functioning should not be subject to the stable control of any single entity (see the first point above). The result is a form of mutualistic symbiosis: the protocol sets the rules letting participants in the protocol enjoy the services created not by the protocol but by the action of other participants pursuing their self-interest.

Third, a non-custodial infrastructure. The second limb of Recital 22, ‘without any intermediary’, is best read not as an additional condition to the words ‘in a fully decentralised manner’ but as a clarification of the first. The regulatory architecture built for financial intermediaries—capital adequacy, liquidity buffers, asset segregation, best execution, suitability—rests on a single structural assumption: that a regulated entity obtains, holds or exercises discretion over the assets of its clients. Where no entity ever acquires possession, custody or effective control over user assets, the risks those rules address—insolvency, misappropriation, commingling, contagion—do not arise in the same form. Entity-level prudential requirements would then be both technically inappropriate and practically ineffective, since the protocol would continue to operate regardless of whether any associated legal person complies. This does not make such systems risk-free: the residual risks concern the integrity of the code, the conditions of its modification, and users’ exposure to smart contract vulnerabilities. They are risks of a different kind, calling for a different regulatory response.

The three criteria are specifically designed to address the question whether a DeFi protocol is decentralized or not. They are cumulative, so the absence of any one of them is sufficient to bring a system within the orbit of the traditional regulatory categories. Together they define a minimum threshold, verifiable in practice and stable enough to support legal application.

Implications

The paper tries to identify some precise and observable elements in order to assess whether a service is offered in a decentralized way or not. In this way, decentralization ceases to be a self-evident label and becomes a composite legal concept. Supervisory authorities gain a structured test in place of an unguided case-by-case assessment; developers and users gain a degree of legal certainty as to when the exemption is available; and the risk that the label is invoked strategically, without satisfying any substantive criterion, is correspondingly reduced. Future instruments, whether legislative or in the form of technical standards or guidance, would do well to articulate decentralization along these three verifiable elements rather than leaving its content to be determined afresh in every case.

The author’s paper, ‘Decentralization: the Search for a Legal Definition’, is available here.

Salvatore Luciano Furnari, PhD at the University of Roma Tor Vergata, is a Fintech and MiCAR lawyer with a focus on blockchain, crypto-assets, and DeFi.