María José Ruiz de Olano on DeFi Regulation and DAO Governance

August 26, 2026
44
CRYPTOMEGAPHONE IN YOUR SOCIAL FEED

María José Ruiz de Olano is the founder of Etherea Legal, a legal consultancy firm advising Web3 ventures, decentralised organisations and digital asset projects. Her work focuses on international legal structures, DAO governance, token frameworks, regulatory compliance and commercial agreements. Before founding Etherea Legal, she was Legal and Compliance Manager at kpk (formerly karpatkey), supporting its growth from an early-stage DAO service provider into a global organisation. Her previous experience includes in-house legal advice, contract management, public-sector compliance and private practice, giving her a practical perspective on the legal and governance challenges created by decentralised technologies.

In this interview with CryptoMegaphone, Ruiz de Olano discusses the evolving regulatory landscape for DeFi, the legal structures surrounding DAOs, common governance and compliance mistakes made by Web3 founders, different jurisdictional approaches to digital asset regulation, and the emerging accountability challenges posed by artificial intelligence and increasingly autonomous on-chain systems.

Over the past few years, regulators have shifted from simply observing decentralized finance to actively developing legal and policy frameworks that could shape its future. From your perspective, what do you see as the most significant regulatory trends defining the next chapter of DeFi, and where do you believe policymakers and the industry still misunderstand one another?

In the first stage of crypto regulation, policymakers understandably focused on the activities that were easiest to identify and regulate: centralised exchanges, custodians, token issuers and stablecoin providers, where there is usually a legal entity or individual who can be licensed, supervised and held accountable.

This approach has brought greater certainty to parts of the digital asset market. However, the most difficult questions remain unresolved, particularly in relation to DeFi and DAOs. Existing financial regulation is generally built on the presence of an intermediary or a central decision-maker, and genuinely decentralised systems challenge this model, since there may be no single operator, no clear jurisdiction and no one person capable of complying with traditional regulatory obligations.

To date, no regulator has found a complete, widely accepted method of regulating genuine decentralisation. The current trend is therefore to look behind the label and examine the reality of each project: who controls the admin keys, who can modify the protocol, how concentrated governance power actually is and who benefits financially. This helps to distinguish genuine decentralisation from projects that use the term merely as a marketing claim.

The misunderstanding runs in both directions. Policymakers sometimes try to apply rules designed for traditional intermediaries to systems that simply have no central operator. The industry, for its part, sometimes assumes that decentralisation automatically removes legal responsibility, which is rarely the case in practice. The next chapter of regulation should be built on proportionate, risk-based rules that identify where effective control genuinely lies, while recognising that truly decentralised protocols may need a new regulatory approach altogether, rather than a simple extension of existing financial law.

DAOs were originally envisioned as organizations capable of operating without traditional corporate structures, yet many are now exploring legal wrappers and formal recognition. Do you believe truly decentralized governance can coexist with existing legal systems, or is the future more likely to belong to hybrid models that balance decentralization with legal certainty?

I believe the future belongs to hybrid models, and I would go further: I think it is useful to separate what we mean by “DAO” into different layers, because conflating them is where most of the confusion comes from.

At the protocol layer, a DAO can remain genuinely decentralised. Smart contracts execute automatically, and no jurisdiction can claim exclusive authority over code that runs on a permissionless, global network. This layer is, in a sense, ajurisdictional, and it can coexist with legal systems simply by remaining outside their direct reach.

The tension arises at the entity layer, and in practice it shows up in the most mundane ways. Decentralisation is very much a value tied to the ideology of the industry, but the reality is that every DAO, at some point, needs to interact with the traditional world. Someone has to contract a hosting provider, subscribe to Notion or pay for a messaging service, and all of these require a registered address and a credit card.

This is precisely where legal wrappers come in, and it is worth being clear about what they actually do. A wrapper is not really about giving the DAO operational capacity; any ordinary company could sign a hosting contract. Its real purpose is to limit the liability of the people behind the DAO — founders, token holders and decision-makers — who could otherwise face personal liability for the DAO’s actions under applicable legal frameworks. Without a wrapper, active participation in governance can, in some jurisdictions and depending on the circumstances, create risks associated with unincorporated organisational structures, potentially exposing participants to liability for the organisation’s obligations.

The real bottleneck, then, is not technical but jurisdictional: very few jurisdictions have developed legal structures specifically designed to accommodate DAOs on terms that reflect how they operate on-chain, rather than simply repackaging them inside conventional corporate structures. Interestingly, some of the most useful frameworks still use a familiar corporate form, but the difference lies in how that form is adapted. The Marshall Islands, for example, built a statutory regime that allows token holders to be recognised as members and the smart contract itself to function as part of the operating agreement, rather than simply requiring the DAO to convert into a generic LLC designed for traditional businesses.

The Cayman Islands, in turn, takes a different route: it allows a DAO to be structured as a Foundation Company, which can pursue commercial or non-profit purposes depending on the DAO’s actual activity, while remaining subject to the specific rules governing distributions to members. This offers a degree of flexibility that a standard corporate vehicle typically does not. That distinction — adapting the form to fit on-chain governance, rather than forcing the DAO into an unmodified traditional structure — is what separates a genuine wrapper from a purely conventional entity. Most jurisdictions still offer no comprehensive answer, and several of the solutions that do exist — however well-intentioned — can end up functioning as traditional entities in substance, with decentralisation preserved in name only.

So my view is that “coexistence” is not really the right framing. It is more accurate to say that decentralised governance and legal systems will continue to operate side by side, with the legal wrapper acting not simply as an operational vehicle but as a liability shield. The scarcity of jurisdictions capable of offering that shield while accommodating decentralised governance remains one of the biggest unresolved gaps in the space.

Having advised Web3 companies on legal and compliance matters, you’ve seen how projects evolve from early-stage ideas into established businesses. What are the most common legal or governance mistakes founders continue to make, and how can they build compliance into their organizations without sacrificing innovation or decentralization?

The most common mistake I see is founders treating legal structuring as an afterthought, something to be dealt with once the protocol is already live and generating traction. In reality, the very first decision a founder needs to make, before writing a single line of code, is whether the protocol is genuinely intended to become decentralised or not. That decision should shape everything that follows: how the treasury is funded, how tokens are distributed, who holds admin keys and how governance actually operates in practice.

This matters because, once those choices have been made, they are extremely difficult, if not impossible, to reverse, even on a blockchain that is often assumed to offer a clean slate. Every transaction, every wallet used to fund the project and every early governance decision leaves a trace. It is a bit like the story of Hansel and Gretel: founders leave a trail of breadcrumbs along the way, and if a regulator or a court later decides to follow that trail, it can lead directly back to a person, however carefully the project was later dressed up as decentralised. Founders often assume that decentralisation, once achieved, retroactively protects the decisions made before it. It does not.

This is closely linked to a second mistake: poor wallet hygiene and unclear funding structures from day one. I always advise founders to be extremely disciplined from the outset: document how the organisation is funded, keep wallets clearly separated by function — for example, treasury, operations, team compensation and grants — and avoid mixing personal and organisational funds under any circumstances. This is not bureaucratic box-ticking; it is often a critical factor in determining whether a founder can later demonstrate genuine separation between themselves and the protocol, or whether they remain personally exposed.

A third mistake is confusing decentralisation as a narrative with decentralisation as a fact. Many projects describe themselves as decentralised while a small founding team still controls the multisig, the treasury or the ability to upgrade the protocol. Regulators are increasingly looking behind the label, so this gap tends to catch up with founders sooner or later.

In terms of building compliance without sacrificing decentralisation, I always recommend the same approach: separate the layers early, and be honest from day one about which layer you are actually building. Keep the protocol layer as decentralised as the project genuinely intends it to be, and use the entity layer for what it is meant to do: interacting with the traditional world and limiting the liability of the people involved. Compliance does not need to compromise decentralisation if it is applied at the right layer and decided at the right moment, rather than imposed retroactively on a structure that has already left its breadcrumbs behind.

Digital asset regulation is evolving at different speeds across jurisdictions, with approaches ranging from comprehensive frameworks to more fragmented or enforcement-driven models. Which jurisdictions do you believe are currently setting the strongest example for responsible innovation, and what lessons can regulators elsewhere draw from their experiences?

I approach this question from a jurisdiction-agnostic perspective, which is actually central to how I work with clients. I don’t believe there is a single “best” jurisdiction for Web3 projects in general; the right fit always depends on the specific circumstances of the project, its activities, its stage, its risk profile and its actual level of decentralisation. What I can point to are jurisdictions that are doing something genuinely useful, each for different reasons and for different types of projects.

The European Union, through MiCA, deserves credit for producing a comprehensive, harmonised framework covering crypto-asset issuers, service providers and stablecoins across an entire economic bloc. Its main strength is legal certainty and the ability of authorised crypto-asset service providers, subject to MiCA’s requirements, to provide services across the EU single market. Its main weakness is that it was largely designed around centralised or semi-centralised activities, and fully decentralised crypto-asset services provided without an intermediary fall outside its scope, leaving some of the hardest questions around genuine DeFi and DAOs unresolved.

Switzerland offers a different lesson. Rather than relying exclusively on an entirely new regulatory regime, it has applied a principle-based, technology-neutral approach while also making targeted legislative changes where necessary. This has made it attractive for blockchain and infrastructure projects and shows that clarity does not always require entirely new legislation; sometimes it requires a regulator willing to provide consistent, predictable guidance under existing rules while adapting the legal framework where genuine gaps emerge.

The UAE, and Dubai in particular through VARA, is an interesting case of a jurisdiction establishing a dedicated regulatory authority for virtual assets, with rulebooks covering different regulated activities. It demonstrates the advantages of developing a framework specifically for the sector, while the regulatory model continues to evolve as it is applied in practice.

Then there are smaller, more specialised jurisdictions such as the Marshall Islands, which chose to address a particular unresolved problem by establishing a statutory framework under which DAOs can be organised as domestic limited liability companies. This is a useful lesson in itself: sometimes the most responsible approach to innovation is not to build a comprehensive framework immediately, but to identify a specific legal gap causing significant uncertainty and address that first.

So rather than ranking jurisdictions against one another, I tend to map them against what a specific project actually needs: legal certainty and market access, a flexible principle-based regulator, a bespoke framework built for the sector, or a narrow but precise solution to a particular legal gap. If there is a common lesson for regulators elsewhere, I would say it is this: responsible innovation does not require choosing between strict regulation and no regulation at all. The jurisdictions getting it right are the ones treating regulation as an iterative process, engaging directly with the industry and being willing to say clearly what they do not yet have an answer for, rather than forcing new activities into frameworks that were never designed for them.

Looking ahead, technologies such as tokenization, decentralized identity, artificial intelligence, programmable compliance and increasingly autonomous on-chain systems are reshaping the digital asset ecosystem. Which developments do you believe will create the most significant legal and regulatory challenges over the next five years, and how should both policymakers and industry participants begin preparing today?

Of all these developments, I think the convergence of artificial intelligence and autonomous on-chain systems will create the most difficult legal challenges, precisely because it challenges the same assumption that already makes DeFi and DAOs hard to regulate: the presence of an identifiable person responsible for a decision.

Today, even in a decentralised protocol, there is usually still a human, or a group of humans, behind each governance vote or parameter change, however difficult they may be to identify. Autonomous agents change that. When an AI system can independently manage a treasury, execute trades or vote in governance based on its own evolving logic, the traditional questions regulators ask — who controls this, who benefits and who can be held accountable — start to lose a clear answer. This is not a distant, speculative scenario; early forms of autonomous agents capable of interacting with DeFi and other on-chain systems already exist today.

Tokenisation of real-world assets raises a different, though related, challenge. It brings enormous benefits in terms of liquidity and access, but it also imports the legal complexity of the underlying asset directly onto the blockchain. A tokenised bond, a tokenised piece of real estate or a tokenised private fund does not stop being subject to applicable securities, property or fund regulation simply because it is represented by a token. The next five years will likely see regulators focus heavily on this intersection, making sure that tokenisation does not become an unintentional route around existing investor protection rules.

Decentralised identity and programmable compliance are, in some ways, part of the solution rather than the problem, but they raise their own questions. Embedding compliance logic directly into smart contracts and verifying identity or accreditation on-chain can help provide greater visibility and enforceability in systems that may otherwise be difficult to supervise. The challenge will be standardisation: for programmable compliance to work across borders, regulators will need greater interoperability in data standards and approaches to recognition; otherwise, we risk ending up with as many fragmented compliance systems as there are jurisdictions.

My advice to both policymakers and industry is to start now, rather than waiting for autonomous systems to become mainstream before addressing the accountability gap. For industry, this means building traceability and appropriate human oversight into autonomous systems from the design stage, not as an afterthought once something goes wrong. For regulators, it means starting to think today about how existing concepts such as control, decision-making and beneficial ownership should be interpreted when the decision-maker is, in whole or in part, an algorithm rather than a person.

Throughout your career, you’ve worked across government, corporate compliance and Web3 legal advisory, giving you a unique perspective on how regulation and innovation intersect. If you could recommend one meaningful change that would strengthen trust between regulators and the digital asset industry while encouraging responsible innovation, what would it be, and why?

If I had to choose one change, it would be shifting the nature of the dialogue that already exists between regulators and industry from a largely academic exercise to a genuinely practical one.

Regulators do meet with industry associations, and those conversations happen regularly in most active jurisdictions. But in my experience, they tend to stay at a conceptual level: discussing principles, risks and general frameworks without getting into how a rule is actually meant to be complied with on a day-to-day basis. The result is regulation that can sound coherent in theory but becomes very difficult to apply in practice, because nobody has worked through the operational detail of what compliance actually looks like for a specific type of protocol or activity.

This is where the real problem shows up, and it is one I see constantly with clients. A law without clear implementing rules on how it should be complied with becomes, in practice, a beautiful piece of legislative history that nobody can actually follow. Founders are left trying to build a compliance programme against a standard that technically exists but has never been translated into anything actionable. The real difficulty only becomes visible later, when a founder is asked by a regulator, an auditor or a court to demonstrate that they complied to the best of their ability. At that point, “we tried to follow the spirit of the law” is rarely a sufficient answer, because there was no operational standard to follow in the first place.

What I would recommend, then, is not more dialogue, but a different kind of it: opening a channel between policymakers and the people actually implementing compliance on the ground — legal and compliance teams, developers and operators — rather than relying solely on industry associations engaging at a policy level. Associations play an important role in representing the sector’s interests, but they are rarely the ones who can explain exactly how a specific technical requirement would need to be met in a live protocol, or where a rule that sounds reasonable on paper simply cannot be executed in practice.

Ultimately, I believe trust between regulators and industry will come from rules that are not only well-intentioned but genuinely implementable. That requires bringing pragmatic, hands-on expertise into the room alongside the policy conversation, so that regulation is shaped with an understanding of how it will actually be complied with, not just how it is meant to be understood.