A practical map of the EU digital-trust landscape.
Use this as an orientation layer for enterprise discovery. It highlights major frameworks and official sources; specialist legal advice remains necessary for regulated activity.
Markets in Crypto-Assets Regulation (MiCA)
MiCA creates a harmonised EU framework for crypto-asset issuers and crypto-asset service providers and has been fully applicable since December 2024. It does not replace the legal frameworks that can apply to tokenised securities, deposits or other regulated instruments.
Official context: European Commission — DLT and tokenisation: paving the way for an “internet of value”
DLT Pilot Regime
The DLT Pilot Regime enables testing of DLT market infrastructures for certain tokenised financial instruments under targeted exemptions from parts of existing securities-market rules. A feasibility study should therefore separate “token technology” from the regulated market activity around issuance, trading, custody and settlement.
Official context: European Commission / DG FISMA
European Digital Identity Wallets
The European Digital Identity Framework requires Member States to provide EUDI Wallets by the end of 2026. For blockchain programmes, this matters because identity, credentials, signatures, trust services and selective disclosure may be better solved through interoperable wallet standards than by putting identity data on-chain.
Official context: European Commission — European Digital Identity Regulation
AI Act and evidence architectures
The EU AI Act is in force. Where blockchain and AI intersect, the useful design question is not “put AI on blockchain”; it is which evidence, approvals, model artefacts, provenance events or accountability records should be tamper-evident and who is authorised to write or verify them.
Official law: EUR-Lex — Regulation (EU) 2024/1689
Regulation becomes a design input.
Perimeter
What activity is being performed, by whom, for which customer and asset?
Data
What can be public, permissioned, off-chain, encrypted or never recorded?
Identity
How are participants authenticated, authorised and credentialed?
Controls
Who can upgrade, pause, revoke, dispute, recover and audit?