EU Weighs Pulling DeFi Lending Vaults Into MiCA as Consultation Nears Its Close
Key Takeaways
- •The European Commission launched a targeted consultation on May 20, 2026, as part of its review of MiCA.
- •Crypto lending, borrowing, and decentralized finance are among the topics excluded from the original MiCA framework that are now under review.
- •Lending vaults are a key issue because their legal status remains unsettled and they may fall outside both MiCA and EU fund rules under current interpretations.
- •MiCA excludes crypto asset services provided in a fully decentralized manner, but it can still apply when only part of an activity is decentralized.
- •The Commission’s consultation closes on Sept. 30 and could lead to either continued exclusion of lending vaults or a new regulatory framework.

When the European Union adopted the Markets in Crypto Assets (MiCA) regulation, crypto lending was left outside its rulebook. Brussels is now reconsidering that choice.
On May 20, 2026, the European Commission opened a targeted consultation on the review of the MiCA regulation, asking stakeholders to weigh in on areas left outside the original framework. These include decentralized finance (DeFi) and crypto lending and borrowing.
Among the most contested areas are lending vaults, which can channel billions of dollars into onchain credit markets without resembling conventional lending. Their legal status currently rests on non-binding interpretations that they fall outside both MiCA and EU fund rules, leaving room for the consultation to shape how lawmakers think about the boundaries of existing financial categories.
Yuriy Brisov, an EU digital assets lawyer and partner at Digital & Analogue Partners, tells Magazine the law pertaining to vaults at present is unclear:
“EU law has no category called a ‘vault.’ A lawyer therefore defines it the way a regulator would qualify it: by function, not by label.”
That ambiguity is only one of myriad regulatory problems. Vaults can perform the economic functions of lending while spreading other functions across smart contracts and multiple participants rather than a single company. If Brussels decides lending should come inside the regulatory perimeter, what does that mean for DeFi — and where does it leave the people and protocols behind these vaults?
Morpho puts the problem into practice
The lending infrastructure of decentralized lending protocol Morpho offers some clues as to why this question will be so hard to answer. The way its vaults are set up and managed does not map neatly onto any existing regulatory model.
Its Vault V2 architecture divides responsibilities between an owner, a curator, an allocator and a sentinel. The curator configures strategy and risk parameters, the allocator executes allocations, and the sentinel holds powers intended to reduce risk. While none of this establishes any of these participants as providing a regulated lending service under MiCA, it shows why identifying the relevant “provider” is less straightforward than with a conventional lender.
Related: Bitwise to launch onchain vaults via Morpho
Jonathan Galea, a partner at Cahill Gordon & Reindel, explored the issue in a recent client update on lending vaults and their position under EU financial regulation. His analysis looks at how vault structures can sit across MiCA, stablecoin rules and European fund law.
Galea says policymakers should be careful about treating lending vaults as a single category, telling Magazine, “lending vaults solve more practical problems than they create.”
He says lending vaults help direct fragmented liquidity into lending markets, while other vaults may buy and sell crypto assets and should be treated differently:
“Bring ‘DeFi lending’ into the perimeter as a single label, and structures that deserve opposite answers risk ending up captured together.”
That distinction would matter if Brussels decides to regulate lending, since a broad category covering “DeFi lending” could capture structures with very different economic functions — and the people exercising control over them.
Who should actually be regulated?
MiCA currently excludes crypto asset services that are provided in a “fully decentralized manner,” although it can apply where only part of an activity is performed in a decentralized way.
One possible solution would be to make decentralization the dividing line, but Galea argues that could disadvantage newer protocols. He says:
“Decentralization is a spectrum and a function of time: a test built on it would penalize newer, more novel protocols while entrenching mature incumbents that have had years to distribute control.”
Brisov says the focus should instead be on the structure of the vault and the control people have over it:
“The safer ground is structural: there is no undertaking, no appointed manager, the holder has a direct coded claim on the pool, and the user can exit before any parameter change takes effect.”
He says if Brussels decides that lending and borrowing warrant regulation, they should be explicitly added to the list of regulated crypto asset services rather than broadening the definition of a crypto asset service provider itself.
Related: ‘DeFi doesn’t exist anymore,’ just onchain finance: Andre Cronje
Curve Finance founder Michael Egorov argues that the rules also need to account for the differences between decentralized lending and conventional finance. He says:
“If DeFi lending is ever brought into the scope of regulation, it should be treated completely differently. DeFi doesn’t need some of the safeguards which traditional lending requires, and yet, at the same time, it may need others.”
Egorov says regulation should be approached “really carefully,” and that a dedicated framework could improve safety and open DeFi lending to new users, while avoiding rules that some protocols cannot comply with because of how they are built.
The Commission’s consultation closes Sept. 30, and what follows could determine whether lending vaults remain outside MiCA or become subject to a new regulatory framework. For protocols, curators and other participants in these structures, the practical question is not only whether rules arrive, but how they would be applied to systems designed to distribute functions across code and multiple actors.
For Brussels, the challenge is not simply whether to regulate DeFi lending; it is how to write rules that distinguish between very different forms of onchain lending and the people (if any) that actually exercise control over them.