Decentralized Finance Regulatory Perimeter .

1. Meaning of the DeFi regulatory perimeter

The regulatory perimeter means the boundary determining:

Which persons, activities, assets, platforms and transactions fall within the jurisdiction of financial regulators and financial legislation.

In traditional finance, the perimeter is comparatively straightforward. Banks, brokers, exchanges, investment advisers, payment providers and other identifiable intermediaries have legal identities and can be licensed or supervised.

DeFi complicates this model.

A DeFi protocol may involve:

  • smart contracts;
  • decentralised exchanges (DEXs);
  • liquidity pools;
  • automated market makers;
  • lending and borrowing protocols;
  • stablecoins;
  • staking;
  • derivatives;
  • token issuance;
  • DAOs;
  • governance-token holders;
  • developers;
  • front-end operators;
  • oracle providers;
  • liquidity providers;
  • wallet providers.

Consequently, the central legal question is not simply:

"Is DeFi regulated?"

It is:

"Which DeFi activity or participant performs a regulated financial function, and which legal entity or person exercises sufficient control or influence to fall within the regulatory perimeter?"

The Financial Stability Board (FSB) has specifically observed that DeFi seeks to replicate traditional financial functions while apparently disintermediating them, but that the degree of decentralisation varies considerably. It also concludes that DeFi can inherit and amplify traditional financial vulnerabilities such as leverage, liquidity mismatch, operational fragility and interconnectedness.

2. DeFi is not necessarily synonymous with "unregulated"

A common misconception is:

"If there is no central company, there can be no regulation."

That is legally problematic.

A regulator may look beyond the technological architecture and examine the economic function actually being performed.

For example:

Traditional finance

A bank:

accepts deposits → lends money → earns interest.

DeFi

A protocol:

accepts crypto collateral → provides loans → charges interest.

The technological mechanism is different, but the financial function is remarkably similar.

This is why international regulatory thinking increasingly follows the principle:

Same activity, same risk, same regulation.

The FSB's global crypto framework expressly advocates regulation of crypto-asset activities on a functional basis and proportionate to the risks involved.

3. The main components of the DeFi regulatory perimeter

A useful way to analyse the perimeter is through five layers.

Layer 1 — Asset

What is being dealt with?

  • cryptocurrency;
  • stablecoin;
  • security token;
  • derivative token;
  • NFT;
  • tokenised real-world asset.

Layer 2 — Activity

What is actually happening?

  • exchange;
  • lending;
  • borrowing;
  • custody;
  • payments;
  • investment;
  • derivatives;
  • issuance;
  • market-making.

Layer 3 — Actor

Who is performing the activity?

  • company;
  • exchange;
  • developer;
  • DAO;
  • protocol operator;
  • governance participant;
  • intermediary;
  • individual.

Layer 4 — Control

Who has the ability to influence the system?

For example:

  • administrator keys;
  • upgrade mechanisms;
  • multisignature wallets;
  • governance voting;
  • control of the front end;
  • control of treasury funds.

Layer 5 — Jurisdiction

Where is the activity legally connected?

DeFi is globally accessible, so regulators must consider:

  • location of developers;
  • residence of users;
  • location of entities;
  • servers and interfaces;
  • financial effects in the jurisdiction;
  • solicitation of local customers.

4. Indian regulatory position

India presently does not have a single comprehensive DeFi statute establishing a dedicated DeFi regulator or licensing regime.

Instead, the regulatory perimeter is fragmented among existing laws and institutions.

The major areas include:

  • Prevention of Money Laundering Act, 2002 (PMLA);
  • Income-tax legislation;
  • Information Technology Act, 2000;
  • securities laws where a token/activity falls within the securities framework;
  • FEMA-related issues in appropriate cross-border transactions;
  • consumer and contract law;
  • corporate and insolvency law;
  • sectoral regulation by institutions such as RBI and SEBI where the activity falls within their respective mandates.

This produces an important distinction:

The absence of a comprehensive "DeFi Act" does not mean that DeFi activity is legally outside every regulatory framework.

5. PMLA and the Indian VDA perimeter

The most concrete Indian expansion of the crypto regulatory perimeter occurred in March 2023.

The Central Government notified specified activities involving Virtual Digital Assets (VDAs) under the PMLA framework.

The covered activities include:

  1. exchange between VDA and fiat currency;
  2. exchange between different forms of VDAs;
  3. transfer of VDAs;
  4. safekeeping or administration of VDAs or instruments enabling control over VDAs; and
  5. participation in and provision of financial services related to an issuer's offer and sale of a VDA. 

This is extremely important for DeFi.

The regulation is substantially activity-based rather than simply entity-based.

The Government has expressly stated that VDA service providers serving Indian users, whether offshore or onshore, and carrying out specified activities must register with FIU-IND and comply with PMLA obligations; the obligation is not contingent upon physical presence in India.

6. The major DeFi problem: Who is the "service provider"?

This is where the regulatory perimeter becomes difficult.

Consider a decentralised lending protocol.

There may be:

  • no incorporated company;
  • no conventional bank;
  • no central custody;
  • no employee approving loans;
  • autonomous smart contracts;
  • anonymous governance participants.

Who is the regulated entity?

Possible candidates could include:

A. Developer

If developers merely write immutable code and relinquish control, regulation is more difficult to attach.

But if developers retain significant administrative powers, the analysis changes.

B. DAO

A DAO may control protocol governance.

The question becomes whether the DAO has sufficient legal personality or whether liability can attach to identifiable participants.

C. Front-end operator

A supposedly decentralised protocol may have a website through which users access the protocol.

The entity controlling that interface may be more readily identifiable.

D. Governance participants

If a small group effectively controls protocol upgrades, treasury and transaction parameters, "decentralisation" may be largely formal rather than substantive.

E. Custodian

If an entity actually controls private keys or customer assets, it looks much more like a traditional financial intermediary.

7. Functional regulation versus formal decentralisation

This is perhaps the most important concept for a DeFi regulatory-perimeter answer.

Imagine two protocols.

Protocol A — genuinely decentralised

  • immutable smart contracts;
  • no administrator;
  • no central treasury;
  • no identifiable operator;
  • autonomous execution.

Protocol B — "decentralised" marketing

  • company owns the website;
  • company controls upgrade keys;
  • company controls treasury;
  • company can pause transactions;
  • company determines protocol parameters.

Technically, both may call themselves "DeFi."

Legally, however, Protocol B is much easier to place inside an existing regulatory perimeter.

Therefore:

The label "DeFi" should not determine regulatory treatment; actual control, economic function and risk should.

The FSB itself cautions that the actual level of decentralisation varies across DeFi arrangements.

8. Internet and Mobile Association of India v. Reserve Bank of India (2020)

Citation: (2020) 10 SCC 274 / 2020 SCC OnLine SC 275

This is the leading Indian Supreme Court authority concerning cryptocurrency and financial regulation.

The RBI had directed regulated entities not to provide services facilitating transactions involving virtual currencies.

The Supreme Court struck down the RBI circular on proportionality grounds.

The judgment is extremely significant for the DeFi regulatory perimeter because it demonstrates that:

Regulatory power over financial institutions does not automatically justify every restriction connected with crypto-assets.

The Court examined whether the RBI's measure was proportionate to the legitimate objective.

The case therefore provides a constitutional constraint on future attempts to regulate crypto or DeFi through executive action.

The Supreme Court's own case listing identifies Internet and Mobile Association of India v. RBI as a 2020 Supreme Court decision.

Importance for DeFi

If the State attempts to prohibit a DeFi-related activity through an existing regulatory power, the affected party could potentially argue:

  1. Is there statutory authority?
  2. Is the objective legitimate?
  3. Is the measure rationally connected to that objective?
  4. Is it necessary?
  5. Is it proportionate?
  6. Are less restrictive alternatives available?

Thus, regulatory perimeter does not mean unlimited regulatory discretion.

9. Internet and Mobile Association and the "banking nexus"

The case is particularly useful because the Supreme Court distinguished between:

  • the RBI's authority over regulated entities; and
  • the broader question of regulating cryptocurrency itself.

This distinction remains relevant to DeFi.

Suppose a DeFi protocol is not itself a bank or financial institution.

The State cannot necessarily assume that every activity connected with that protocol automatically falls within RBI's direct regulatory jurisdiction.

There must be an appropriate statutory and jurisdictional hook.

That is why the DeFi perimeter requires a careful analysis of:

activity + actor + statute + regulator + jurisdiction.

10. Shreya Singhal v. Union of India (2015)

Citation: (2015) 5 SCC 1

Although not a DeFi case, Shreya Singhal is relevant where regulation of DeFi uses broad technology-based prohibitions.

The Supreme Court struck down Section 66A of the Information Technology Act because of unconstitutional vagueness and overbreadth.

Its relevance is straightforward.

A law regulating DeFi should clearly identify:

  • prohibited activity;
  • regulated persons;
  • applicable obligations;
  • enforcement powers;
  • relevant jurisdiction.

A vague rule such as:

"No person shall operate an unsafe or harmful blockchain financial system"

could create serious constitutional problems because the regulated community may not know what conduct falls within the prohibition.

11. K.S. Puttaswamy v. Union of India (2017)

Citation: (2017) 10 SCC 1

DeFi transactions are frequently pseudonymous and recorded permanently on public blockchains.

That creates significant privacy questions.

Blockchain addresses may not initially identify a natural person, but information from exchanges, KYC systems, analytics providers or other datasets can potentially connect addresses with individuals.

Therefore, regulatory requirements involving:

  • wallet identification;
  • transaction monitoring;
  • blockchain analytics;
  • travel-rule-type information;
  • transaction histories;
  • user profiling

can engage the constitutional right to privacy.

Under Puttaswamy, State intrusion into privacy must satisfy constitutional requirements, including legality, legitimate purpose and proportionality.

This becomes particularly important when AML regulation is extended to decentralised protocols.

12. Justice K.S. Puttaswamy v. Union of India and DeFi anonymity

A major policy tension therefore emerges:

AML objective

The State wants to know:

Who owns the wallet?

DeFi design

The system is often designed around:

pseudonymous addresses + permissionless participation.

The regulatory perimeter therefore creates a fundamental technological conflict.

The law may require identification at a particular intermediary or gateway, while the underlying protocol may remain permissionless.

This suggests an important regulatory strategy:

Regulate identifiable points of control and access rather than attempting to regulate every line of smart-contract code.

13. Anuradha Bhasin v. Union of India (2020)

Citation: (2020) 3 SCC 637

This case concerned restrictions on internet access in Jammu & Kashmir.

Although not a financial case, it provides a useful constitutional principle for DeFi:

Digital infrastructure cannot be regulated without considering proportionality, transparency and judicial review.

DeFi depends upon internet access and blockchain infrastructure. A blanket blocking order against a DeFi interface or protocol could affect:

  • financial transactions;
  • speech;
  • legitimate commerce;
  • technological innovation.

Consequently, a regulatory response must consider whether targeted intervention would achieve the same objective with less collateral damage.

14. FATF and the "functional perimeter" problem

International AML policy has also moved toward looking at the persons who actually exercise control over DeFi arrangements rather than accepting decentralisation claims at face value.

The underlying regulatory problem is that a DeFi protocol can be:

  • technically decentralised;
  • economically centralised;
  • legally controlled by a small group.

This is why the concept of "effective control" becomes important.

For example:

If ten governance participants can collectively upgrade the protocol, change fees, freeze assets and control treasury funds, it may be difficult to argue that the system has no identifiable controlling actors.

15. DeFi and securities regulation

Another important perimeter question is:

When does a DeFi token or protocol become a securities-market activity?

This depends on the jurisdiction and the particular characteristics of the asset.

Potentially relevant features include:

  • rights attached to the token;
  • expectation of profit;
  • pooling of investor funds;
  • managerial efforts of identifiable persons;
  • representation of ownership;
  • revenue-sharing;
  • investment contracts;
  • derivatives characteristics.

In India, the analysis must be made under existing securities legislation and SEBI's statutory jurisdiction rather than assuming that every token is automatically a "security."

Thus:

Token ≠ automatically security

but equally:

Token ≠ automatically outside securities regulation.

The legal character depends upon the applicable statute and the substance of the arrangement.

16. DeFi lending

Consider:

User deposits ETH → protocol lends USDC → borrower pays interest → smart contract automatically distributes returns.

Potential regulatory issues include:

  • lending regulation;
  • securities/investment-product regulation;
  • AML;
  • consumer protection;
  • custody;
  • insolvency;
  • taxation;
  • systemic risk.

The key question is whether the activity is merely software execution or economically equivalent to a regulated financial service.

The FSB's analysis is particularly relevant because it finds that DeFi performs functions comparable to traditional finance and may reproduce traditional vulnerabilities, including leverage and liquidity mismatches.

17. DeFi derivatives

Derivatives present an even stronger regulatory case.

Suppose a protocol allows users to obtain leveraged exposure to:

  • Bitcoin;
  • Ether;
  • commodities;
  • equities;
  • foreign currencies.

The technological form may be a smart contract, but economically the product may resemble a conventional derivative.

Therefore, the regulator should examine:

What economic exposure does the instrument create?

rather than:

Is the contract written in Solidity?

This is the essence of substance-over-form regulation.

18. Stablecoins and the regulatory perimeter

Stablecoins are particularly important because they attempt to maintain a stable value relative to:

  • fiat currency;
  • commodities;
  • another asset;
  • or sometimes an algorithmic mechanism.

They can function as:

  • payment instruments;
  • settlement assets;
  • collateral;
  • liquidity instruments;
  • stores of value.

The FSB has warned that crypto-asset markets and their intermediaries can create financial-stability risks, particularly where crypto services combine multiple functions and become interconnected with traditional finance.

Consequently, a stablecoin used extensively inside DeFi may create a regulatory perimeter extending beyond the individual token.

19. DAOs and legal personality

Decentralised Autonomous Organisations (DAOs) create one of the most difficult questions.

Traditional regulation asks:

Who owns the company?

Who is the director?

Who is responsible?

A DAO may instead operate through:

  • token voting;
  • smart contracts;
  • anonymous participants;
  • multisignature wallets;
  • governance proposals.

This creates a liability gap.

A sophisticated regulatory framework therefore needs to determine:

  1. whether the DAO has legal personality;
  2. who exercises effective control;
  3. whether token holders have fiduciary obligations;
  4. whether developers can be liable;
  5. whether governance participants constitute an association;
  6. whether front-end operators can be regulated;
  7. whether a DAO treasury constitutes customer property.

20. Regulatory perimeter versus regulatory responsibility

These are not identical.

A protocol may fall within the policy concern of financial regulators without there being an immediately identifiable person upon whom existing legislation can impose obligations.

This creates three possible approaches.

Model 1 — Entity-based regulation

Regulate identifiable companies.

Advantage: easy to enforce.

Problem: truly decentralised protocols may have no company.

Model 2 — Activity-based regulation

Regulate the financial activity regardless of technology.

Advantage: technology-neutral.

Problem: difficult where nobody performs the activity conventionally.

Model 3 — Control-based regulation

Regulate persons who possess meaningful control.

Advantage: captures "decentralised" systems with concentrated control.

Problem: defining "control" can be difficult.

A mature DeFi regulatory framework will probably require a combination of all three.

21. Indian DeFi regulatory-perimeter matrix

DeFi activityPossible regulatory concernKey Indian legal area
Crypto–fiat exchangeAML/KYCPMLA
Crypto–crypto exchangeAMLPMLA
Transfer of VDAAML/reportingPMLA
CustodyAML + asset protectionPMLA/other applicable laws
LendingFinancial regulationActivity-dependent
BorrowingFinancial regulationActivity-dependent
StablecoinsMonetary/financial stabilityRBI/government policy
Token issuanceSecurities/AML/taxFacts and legal classification
DeFi derivativesSecurities/derivativesPotential SEBI jurisdiction
DAOGovernance/liabilityCompany/contract/common law questions
DEXAML/securities issuesDepends on activities and control
WalletCustody/AMLDepends on whether service is custodial
Protocol developerLiability/controlHighly fact-specific
Front-end operatorAccess/intermediationPotential regulatory nexus
Liquidity providerInvestment/AML/taxFact-specific

22. Cross-border dimension

DeFi is inherently cross-border.

An Indian user can interact with a protocol:

  • developed in the United States;
  • hosted through distributed infrastructure;
  • governed through a DAO;
  • using a token issued elsewhere;
  • interacting with an offshore liquidity pool.

Which country regulates it?

This creates a classic jurisdictional-arbitrage problem.

India has already demonstrated that its AML perimeter can extend to offshore VDA service providers serving Indian users. In 2025, FIU-IND announced enforcement notices against 25 offshore VDA service providers and reiterated that the relevant obligations are activity-based and not dependent upon physical presence in India.

That principle is highly relevant to DeFi.

23. The important distinction: DeFi protocol vs DeFi service provider

This distinction should be made very clearly in an examination.

DeFi protocol

The underlying software/smart-contract infrastructure.

DeFi service provider

A person or entity providing services around that protocol.

For example:

Smart contract: automated exchange mechanism.

Website: interface allowing users to access it.

Company: develops and controls the website.

DAO: controls governance.

Liquidity provider: supplies assets.

User: trades through the system.

These are legally different actors.

Therefore, regulating the service provider may be much easier and more constitutionally defensible than attempting to prohibit the underlying software itself.

24. Why "code is law" is not enough

A technological argument sometimes says:

"The smart contract executes automatically, therefore there is no legal intermediary."

That conclusion is too simplistic.

Law does not regulate only the mechanical execution of transactions.

It can regulate:

  • persons who develop software;
  • persons who market financial products;
  • persons who control assets;
  • persons who solicit customers;
  • persons who operate interfaces;
  • persons who profit from financial services;
  • persons who exercise governance;
  • persons who facilitate regulated transactions.

Thus:

Automation may remove an intermediary function technologically without necessarily eliminating legal responsibility.

25. Financial-stability perimeter

The regulatory perimeter should also expand according to systemic importance.

A small DeFi lending protocol with negligible assets presents a different risk from a protocol deeply connected to:

  • banks;
  • stablecoins;
  • exchanges;
  • payment systems;
  • institutional investors.

The FSB has emphasized that the financial-stability implications of DeFi depend substantially on its interconnections with traditional finance and the real economy.

This supports a risk-based regulatory perimeter.

26. Proportionality and the DeFi perimeter

The constitutional doctrine of proportionality is particularly relevant here.

A regulator should avoid:

"All crypto = high risk = prohibit everything."

Instead, it should assess:

Risk

What harm is being addressed?

Exposure

How many users and assets are involved?

Function

What financial function is being performed?

Control

Who can influence the system?

Alternative

Can the risk be addressed through disclosure, KYC at gateways, audits, reserve requirements or transaction monitoring instead of prohibition?

This is consistent with the Supreme Court's reasoning in Internet and Mobile Association of India.

27. A hypothetical case study

Suppose an Indian DAO operates a decentralised lending protocol.

It has:

  • ₹5,000 crore equivalent in assets;
  • 20 million users;
  • an Indian front-end;
  • Indian developers;
  • governance tokens;
  • no formal company;
  • a multisig wallet controlled by six developers;
  • the ability to freeze assets.

The DAO claims:

"We are completely decentralised, so Indian financial laws do not apply."

That claim would be difficult to accept automatically.

A regulator could investigate:

1. Economic function

Is the DAO effectively operating a lending business?

2. Control

Who controls the multisig?

3. Governance

Who can change the protocol?

4. Customer relationship

Who solicits Indian users?

5. Custody

Who controls user assets?

6. AML

Are regulated VDA activities being carried out?

7. Securities

Do governance tokens or products constitute securities or investment products?

8. Jurisdiction

Is there sufficient Indian territorial or economic nexus?

The result would depend upon the facts—not simply the label "DAO."

28. Current Indian position — the key takeaway

As of August 2026, India's position is best described as partial and activity-specific rather than a comprehensive DeFi regulatory regime.

The clearest perimeter is currently around specified VDA service activities under the AML framework. FIU-IND continues to enforce registration/compliance requirements against offshore VDA service providers serving Indian users.

At the same time, recent policy developments indicate that the broader legal status of private crypto-assets remains unsettled. Reporting in July 2026 indicated continuing RBI opposition to giving private cryptocurrencies legal status and concern about financial-stability and monetary-sovereignty risks.

Therefore, one should not state in an examination that "DeFi is illegal in India" or that "DeFi is completely unregulated." Both propositions are overbroad.

The more accurate formulation is:

Indian law currently regulates particular activities and service providers associated with virtual digital assets, especially for AML purposes, while a comprehensive activity-based regulatory framework specifically addressing decentralised finance remains undeveloped.

29. Major case-law principles to remember

CasePrincipleDeFi relevance
Internet & Mobile Association of India v. RBI (2020)Proportionality limits regulatory restrictions on crypto-related activityCore constitutional authority
K.S. Puttaswamy v. Union of India (2017)Privacy is a fundamental rightBlockchain analytics, KYC and surveillance
Shreya Singhal v. Union of India (2015)Vagueness/overbreadth unconstitutionalClear DeFi prohibitions required
Anuradha Bhasin v. Union of India (2020)Digital restrictions require constitutional justification and proportionalityInternet blocking of DeFi interfaces
PUCL v. Union of India (1997)Communication interception requires safeguardsBlockchain/transaction surveillance analogy
Modern Dental College v. State of M.P. (2016)Four-stage proportionalityRegulation must be necessary and balanced

30. Conclusion

The DeFi regulatory perimeter should not be determined merely by asking whether a platform calls itself "decentralised."

The legally stronger approach is:

Function → Activity → Actor → Control → Risk → Jurisdiction.

A DeFi protocol performing the economic function of a bank, exchange, broker, custodian or derivatives platform should not necessarily escape regulation merely because its functions are executed through smart contracts.

At the same time, regulation must respect constitutional limits. Internet and Mobile Association of India v. RBI demonstrates that even legitimate financial-regulatory objectives must be pursued through proportionate measures. Privacy principles from Puttaswamy and safeguards against vague or overbroad digital regulation from Shreya Singhal further constrain the State.

The future Indian approach is therefore likely to be strongest if it follows a technology-neutral, activity-based, risk-sensitive and control-oriented model rather than attempting either to prohibit DeFi wholesale or to treat all decentralised protocols as automatically outside the law.

Exam-ready proposition:

The regulatory perimeter of decentralised finance should be determined by the substance of the financial activity, the identity and degree of control of the actors involved, the risks generated and the applicable statutory jurisdiction, rather than by the technological label of decentralisation. In India, the PMLA's activity-based treatment of specified VDA services demonstrates an emerging functional perimeter, while Internet and Mobile Association of India v. RBI establishes that regulatory intervention remains subject to constitutional proportionality. Accordingly, genuine technological decentralisation may complicate enforcement, but it does not by itself create a legal immunity from financial regulation.

LEAVE A COMMENT