MiCA reverse solicitation after 1 July 2026: what a non-EU exchange can still do, and what ends it
Can a Dubai or Indian crypto exchange serve EU customers without MiCA? Not since 1 July 2026. ESMA said on 23 June 2026 that CASPs outside the EU cannot provide MiCA services to EU clients or solicit them, business-to-business included, preserving only reverse solicitation: services a client requested at its own exclusive initiative under Article 61. That carve-out is per client and per product; no disclaimer creates it and any promotion in the Union defeats it. Read this as a wind-down review, not a way to keep serving the EU.
The rule ESMA restated on 23 June 2026
Article 59(1) of Regulation (EU) 2023/1114 bars anyone from providing crypto-asset services within the Union unless authorised as a CASP under Article 63 or permitted as a financial entity listed in Article 60. A client under Article 3(1)(39) is any natural or legal person, and ESMA’s final report records that guidelines cannot create a professional-client carve-out.
Article 61 is the only door for a third-country firm. Where an EU client initiates a crypto-asset service at its own exclusive initiative, authorisation is not required for that service and a relationship specifically relating to it. Where the firm, or anyone acting on its behalf or with close links to it, solicits clients or prospective clients in the Union by any means, the service is not on the client’s own initiative, notwithstanding any contractual clause or disclaimer, and Article 61(2) gives the firm no right to market new types of crypto-assets or services to that client.
ESMA’s guidelines under Article 61(3) were finalised on 17 December 2024, published in all official EU languages on 26 February 2025 and apply 60 calendar days later, which works out to 27 April 2025. They call genuine reverse-solicitation situations very limited and very narrowly framed, not to be assumed nor exploited to circumvent MiCA. The 23 June 2026 statement (ESMA75-113276571-1710) then restated the rule: CASPs outside the EU cannot provide MiCA services to EU clients or solicit them, business-to-business included, with footnote 3 preserving only services strictly at the client’s own exclusive initiative under the guidelines. Unauthorised firms are to stop onboarding EU clients immediately, cease marketing and limit services to selling, transferring, reallocating or closing. MiCA vs VARA covers how the transitional period closed; this page covers what Article 61 leaves and how to evidence it.
Schedule A: conduct that ends the carve-out
The airdrop row is Infinilex’s application of the guidelines, not a stated ESMA position.
| Conduct | What Article 61 and the ESMA guidelines say | Where it leaves an Article 61 argument |
|---|---|---|
| EU-language site, EU-targeted SEO, geo-targeted or brand ads | Annex: EU country-code domains or subdirectories, geographic SEO targeting and geo-targeted ads are likely solicitation, as is a site in an EU language not customary in international finance unless it serves a non-EU market. Paragraph 13: broad-reach brand advertising may also count. | Defeated for every EU client the content could reach. |
| App listed in EU app stores | Footnote 20 names keeping the app out of EU app stores as a precaution. Annex: a push notification to an EU client promoting different-type assets two days after a first purchase, or a promotion two months later, is likely solicitation. | Removal is an ESMA-named precaution; a listing is a fact the regulator weighs. In-app marketing defeats it. |
| Influencers, affiliates and promotional deals | Guideline 1 lists affiliation campaigns as solicitation. Guideline 2 reaches any person acting for the firm or with close links, expressly including influencers; promotional deals or the firm’s logo are indications, and any remuneration or benefit is a strong one. | Defeated where the creator or affiliate is paid, briefed or facilitated; unprompted reviews the firm knew nothing of stay outside. |
| Airdrops and giveaways aimed at EU wallets (Infinilex application) | Not named in the guidelines. Guideline 1 covers the promotion, advertisement or offer of services by any means, and offers of a general nature to the public with broad reach. | Assume defeated where the airdrop draws EU recipients to the platform or to an account they must open to claim it. |
| Follow-on products to an existing EU client | Article 61(2) and Guideline 3: further same-type assets or services only in the context of the original transaction; marketing similar assets a month later is not permitted. Guideline 4 lists the pairs that differ in type. | Each new product needs its own client-initiated request. |
| EU events, sponsorships and training | Guideline 1: education and industry events are not solicitation until the audience is directed to the firm’s website, given the means of access or invited to complete a client profile; sponsoring an international sporting competition with EU teams or athletes makes the firm a soliciting firm. | Education survives; a link, a sign-up desk or sponsorship reaching EU audiences ends it. |
| EU group company or EU-regulated firm redirecting clients | Guideline 2: an EU credit institution, investment firm or payment service provider should not redirect clients to a third-country firm’s crypto-asset services, same group or not; group branding that blurs the two entities is likely solicitation. | Defeated. MiCA protections attach only to the specific authorised EU entity. |
Sources: Regulation (EU) 2023/1114; ESMA guidelines and final report; ESMA statements of 23 June 2026, 17 April 2026 and 4 December 2025, as at 19 September 2026. The right-hand column is Infinilex’s reading, not a regulator’s statement.
What a client-initiated relationship still allows
The first subparagraph of Article 61 is a per-client, per-service exception that exists only where the facts show the EU client came unprompted. Guideline 3 construes the client’s own exclusive initiative narrowly, treats it as a factual assessment and says contractual arrangements or disclaimers cannot supersede contrary facts. A legacy EU client who found a Dubai or Indian exchange unaided, before any EU-facing marketing existed, and asked for a specific service can sit inside the carve-out for that service, subject to the all-facts assessment Guideline 1 leaves to the national regulator.
The carve-out does not grow. ESMA’s final report confirms that the Guideline 3 time limit governs marketing of new same-type products rather than ending the relationship, but each new product needs the client’s own initiative afresh; ESMA declined to fix a number of days, and its only illustration is that a month later is too late. Paragraph 28 then expects records tracking the relationship and whether the client took the initiative for each new product; without them the firm cannot show a regulator that it is in one, and ESMA says such situations are not to be assumed.
The eight-step exposure review
The sequence Infinilex runs for a non-EU exchange with EU users on its books ends in a file, not an opinion that the business can carry on.
- Map the EU book and the contracting entity. Every client established or situated in the Union, natural and legal persons alike, and the group entity contracting with each.
- Pull the EU marketing record from 27 April 2025. Website languages and subdirectories, SEO and ad geo-targeting, app-store availability by country, events, sponsorships and messaging campaigns; ESMA’s supervision guidelines tell national regulators to monitor exactly this.
- Trace third parties. A register of influencers, content creators, affiliates, EU group companies and EU-regulated partners, with what each was paid or given and what they were asked to do.
- Test each EU relationship, client by client and product by product. How first contact happened and what was asked for; then, for each later product, whether the client asked or the firm offered, applying Guideline 4’s same-type pairs. Sort clients into own-initiative with evidence, own-initiative without, and solicited.
- Build the evidence file. For each client in the first category: the first-contact record with channel and timestamp, the service requested, every later request in the client’s own words, the EU marketing-suppression log and the third-party register entry showing nobody was asked or paid to reach that client.
- Cut the conduct that defeats the carve-out. Stop onboarding EU clients, geo-block EU access and withdraw the app from EU stores (the precautions paragraph 16 and footnote 20 name), then end EU-facing campaigns, affiliate payments and sponsorships and instruct group entities to stop redirecting. None of this cures past solicitation.
- Wind down everyone else. For the second and third categories, the exit ESMA describes: clear, prompt and repeated communications, a deadline after which residual positions close automatically, transfers to an authorised CASP or a self-hosted wallet, and services limited to selling, transferring, reallocating or closing. AML and CFT controls run throughout, so the crypto AML programme must be live; custody continues only for the period strictly necessary, and a receiving authorised CASP cannot delegate custody back to an unauthorised entity (Article 75(9)).
- Decide the road. Either CASP authorisation through an EU entity, or an exit from the EU. For the first, the MiCA CASP readiness checklist is the pre-application pass and the MiCA authorisation programme is the engagement: Infinilex quarterbacks, EU local counsel files. For the second, the country-by-country licence map shows what each remaining market requires, and the home-market rules are in crypto marketing rules by market.
What is at stake if the review is skipped
Article 110 requires ESMA to keep a public register of entities providing crypto-asset services in violation of Article 59 or 61, naming at least the commercial name or website; ESMA publishes it beside the register of authorised CASPs, last updated 16 September 2026 when checked on 19 September 2026. Article 111 requires member states to equip regulators with at least a public statement naming the person and the infringement, a cease-and-desist order, fines of at least twice the profit gained or loss avoided, and maximum fines of at least EUR 5,000,000 or 5% of total annual turnover for legal persons and EUR 700,000 for natural persons, without prejudice to national criminal penalties (as at 19 September 2026). ESMA’s June 2026 statement says national regulators may take coordinated action.
Infinilex’s response to the MiCA review consultation, which closes on 30 September 2026, asks for a defined re-entry path for formerly registered firms with clean supervisory records and for clear, narrow guidance on reverse solicitation.
Who signs what on an EU exposure review
Infinilex scopes the review, builds the fact record and the evidence file, and briefs the EU local counsel who sign any opinion on EU law or regulator-facing filing; those counsel are brought into the engagement explicitly and named to the client before they act. Where the review reaches the home regulator, the UAE leg is signed by Infinilex counsel qualified for the relevant UAE regulator and the India leg by an advocate enrolled in India at Infinilex.
Frequently asked questions
Is a pending CASP application enough to keep serving EU clients?
No. Article 143(3) cover ended on 1 July 2026 and only ever applied to firms operating lawfully under national law before 30 December 2024; a pending application creates no cover of its own. ESMA's statement of 4 December 2025 told national regulators to treat late applications with considerable caution, even where the applicant must wind down while the application is assessed. Until authorisation is granted, EU clients are served within the narrow Article 61 carve-out or not at all.
Does a disclaimer or a client declaration save reverse solicitation?
No. Article 61(1) says the solicitation rule applies notwithstanding any contractual clause or disclaimer purporting to state otherwise, including a clause deeming the service to be on the client's own exclusive initiative. ESMA's Guideline 3 adds that whether the client initiated the contact is a factual assessment and that disclaimers cannot supersede contrary facts. A tick-box declaration proves nothing if the firm's marketing reached the client first; a record of how the client actually arrived is what counts.
Does an EU-targeted airdrop count as solicitation under MiCA?
ESMA's guidelines do not mention airdrops, so this applies what they do say. Guideline 1 defines solicitation as the promotion, advertisement or offer of crypto-asset services to clients or prospective clients in the Union by any means, and adds that offers of a general nature addressed to the public with a broad reach may also be solicitation. An airdrop aimed at EU wallets that draws recipients to the platform, or to an account they must open to claim it, fits that description.
What goes in a reverse solicitation evidence file?
ESMA's Guideline 3 says third-country firms should be able to provide records tracking the relationship with each client and whether the client took the initiative for each new product. Per EU client that means the first-contact record with channel and timestamp, showing it was inbound and unprompted; the service asked for; every later product with the client's own request attached; the EU marketing-suppression log; and the third-party register showing no influencer, affiliate or group entity was paid or asked to reach that client.
What happens to EU users after the MiCA transitional period ended?
They lose MiCA's safeguards, including client-asset protections, and ESMA has told them to check its register and move their assets to an authorised CASP or a self-hosted wallet. The provider is expected to tell them clearly, promptly and repeatedly about safeguarding and the wind-down plan, including a deadline by which residual positions close automatically. Transfers to an authorised CASP trigger full customer due diligence at the receiving end, and business users are treated the same as retail.
EU users on a Dubai or Indian exchange’s books?
Send us the shape of the EU book, the marketing channels used since April 2025 and the contracting entity. We map the exposure and name the lawful road.
Further reading
MiCA vs VARA · MiCA authorisation programme · MiCA review consultation response · Crypto licence requirements by country · MiCA CASP readiness checklist · Crypto marketing rules by market
This article is general information, not legal advice on any firm’s EU book. MiCA provisions and ESMA positions are stated as at 19 September 2026 and the page is re-verified quarterly; whether a relationship falls within Article 61 turns on facts a national regulator will assess.