MiCA, AML, FATF travel rule, the Digital Services Act, the AI Act and international tax rules now reshape NFT projects. Non-compliance can lead to fines, deplatforming and reputational damage. Dreyfus delivers actionable compliance roadmaps for issuers, marketplaces, brands and platforms that want to operate in the EU, US, UK and Asia with confidence.
Reviewed by Nathalie Dreyfus, European Trademark and Patent Attorney, Founder of Dreyfus & Associés. Last updated: June 2026.
Compliance was once treated as the last item on a Web 3.0 roadmap. It is now the first gate for European and US market access. EU regulators expect issuers, marketplaces and intermediaries to demonstrate clear governance, AML procedures, consumer protection and tax discipline.
Multiple regimes apply simultaneously. National laws (France, Germany, US states, Singapore, Hong Kong), EU regulations (MiCA, DSA, AI Act, GDPR, AMLD6), FATF guidance for crypto-assets, OECD CARF for tax transparency, and sectoral rules for finance, gaming or art. A compliant project maps all of them.
Beyond fines, compliance protects valuation. Investors, banks, insurers and corporate partners now require a compliance memorandum before they engage. A clean compliance file reduces funding friction, accelerates partnerships and supports listing or token sale events.
MiCA, Regulation (EU) 2023/1114, excludes truly unique and non-fungible NFTs from its scope. Large series, fractionalised or fungible NFTs may fall in scope and trigger crypto-asset service provider obligations.
Source: Regulation (EU) 2023/1114, Article 2.
Directive (EU) 2024/1640 (AMLD6) and Regulation (EU) 2023/1113 (Transfer of Funds Regulation) extend AML obligations to crypto-asset service providers, including KYC, transaction monitoring and travel rule for transfers above 1,000 euros. NFT platforms that qualify as CASPs under MiCA fall within the scope of these obligations; platforms dealing exclusively in truly unique, non-fungible NFTs may fall outside, subject to a case-by-case legal and economic analysis.
Source: Regulation 2023/1113 and Directive 2024/1640.
The OECD Crypto-Asset Reporting Framework, adopted in August 2022, mandates automatic exchange of tax information on crypto-assets between participating jurisdictions. The first reporting exchanges are targeted for 2027 for early adopters, though the timeline varies by jurisdiction. The inclusion of NFTs in CARF scope depends on their qualification as crypto-assets; truly unique NFTs may fall outside, consistent with the MiCA approach.
Source: OECD Crypto-Asset Reporting Framework, 2022.
Article 30 of Regulation (EU) 2022/2065 (Digital Services Act) requires online marketplaces, including NFT marketplaces, to identify traders, verify their information and ensure traceability of B2C transactions.
Source: Regulation (EU) 2022/2065, Article 30.
We qualify your NFT (utility, collectible, fractionalised, security-like) and your role (issuer, intermediary, brand licensor, marketplace) under MiCA, MiFID II, US Howey test, UK FCA guidance and applicable national rules. This decides which regimes apply.
We audit your project against EU and international rules: MiCA, AMLD6, DSA, AI Act, GDPR, FATF travel rule, OECD CARF, national tax rules, consumer protection. We deliver a written gap analysis with priority risks and remediation actions.
We draft KYC, AML and CTF policies, terms of mint, marketplace policies, DPA and DPIA, governance manuals and board reports. We then keep your framework up to date through quarterly regulatory watch and incident playbooks.
MiCA, MiFID II, US securities law, UK FCA, Singapore MAS and Hong Kong SFC qualification of NFTs and token models.
Independent audit of marketplaces, issuers and brand NFT programmes against EU and international rules, with a clear remediation plan.
Drafting and deployment of AMLD6 compliant procedures, FATF travel rule, sanctions screening and transaction monitoring.
International tax review for issuers and holders, OECD CARF readiness, VAT analysis of NFT sales and royalties.
Tailored training for boards, executives and operational teams on Web 3.0 regulation, governance and reputational risk.
Quarterly regulatory watch on MiCA, DSA, AI Act, AML, tax and IP, with actionable alerts when your obligations change.
Compliance prevents fines, deplatforming and criminal exposure under AML, MiCA and DSA. It also reassures investors, banks and partners, accelerates time to market and reduces the litigation and reputational risk that has hit several NFT projects since 2022.
Act quickly and transparently. We audit your project, prioritise the most serious gaps (AML, MiCA, GDPR, consumer protection), put in place remediation, and where relevant engage proactively with regulators (AMF, CNIL, FCA, SEC) to avoid escalation.
Through a structured method: qualification of the token, mapping against EU and international rules, drafting of KYC, AML, DSA and GDPR documentation, integration of compliance into mint terms and platform code, and recurring audits as the regulation evolves.
Training builds an internal compliance culture, reduces operational errors, and helps boards, sales teams and developers identify red flags early. For regulated entities, training is also a documented duty under AMLD6 and CSSF, BaFin or AMF guidance.
We provide a quarterly Web 3.0 regulatory bulletin covering MiCA, DSA, AI Act, AML and tax, plus on-demand alerts on critical changes. We also run yearly compliance refresh audits to keep your documentation, policies and code aligned with regulation.
Yes. We represent clients in dialogue and proceedings with the AMF, CNIL, ANSSI, FCA, SEC and similar authorities, and in civil disputes connected to compliance failures (AML, consumer protection, GDPR, MiCA). Our goal: contain exposure and protect your operating licence.