Neither Reckless nor Over Layered — Anne Grace Kleczewski
ETH Belgrade Community·Tue, Oct 6, 2026, 12:00 AM
Transcript
Thank you very much for the introduction and mentioning the GitHub part because this presentation will also explain to you why I'm reading your GitHub and don't trust what you tell me. Um so first of all I mentioned over lawyered you hear lawyer but this is not a purely legal talk. I would say also jurisdiction agnostic. Um my goal is to make sure uh founders actually understand what the lawyers are telling them to do. One of the things I've observed in the space is that often people need to blindly trust their lawyer.
But the question is like does the lawyer have all the information to really assess what you need? Sometimes you just don't think about providing the right input and then we end up with uh sessions as I've heard for example yesterday where someone is asked about like the legal setup and their answer is my log my lawyer figured it out. But you don't even know what they figured out. So how can you make sure that you comply with the recommendations if you don't know what these recommendations were? So how to sorry Don't trust verify.
Don't trust verify. Exactly. And increasingly there's like a good trend because people now talk to AI. They ask cla. So they show up being like oh uh I've read that potentially Panama is good.
Yeah. But let's discuss it further. So how to be neither reckless and be the the person who just says I don't care what my lawyer says. I just want to scam me and push as many services as possible. No be over lawyered where you trust five lawyers at the same time and end up with expensive costs.
So let's start. Um well it was just after lunch break so I continue on the culinary um path. Uh it's all about dosage. You just want to know how much legal you need in your project not to feel too stiff where basically you end up spending months just discussing with lawyers and not launching the product because you just figured everything out and it just takes a very long time. But you also don't want to have too little of it and then do things that backfire.
And unfortunately lawyers we're a bit like chefs. We have like our favorite recipes like oh I like to do the BVI Cayman thing or I like to have a SPV for the token in Switzerland. Well this would be my issue for example or we have some templates that we like in terms of contracts that are not the same as someone else. Like how do you know whether it fits? Like when you go to a restaurant you order something and like damn this is too big this is not what I wanted or like this is too little.
It's the same with lawyers. Like how do you know how do you gain the skills to actually just critically assess what your lawyer is pushing at you? So this is the goal of the stock. And why the stock? Well, not just because of lawyers and how we operate because we're not that bad.
We're kind of friendly sometimes. Uh but also crypto regulation is very complex. Every now and then like even every month currently you hear, oh new regulation, new license for prediction markets and Gibraltar. Oo, Mika new aspect that got uncovered. This country uh does that.
The other one is having enforcement actions against this company. Like how do you navigate that? It's pretty complicated and it's very easy to end up being like a reckless founder because like there's too much crap. I don't want to handle that. I'm too small.
No one will bother to disturb me because there's not too much enough TVL for anyone to care. You never know. One user made an answer to some authorities just because they don't like something that happens. Um you can't just say I'm decentralized because there are so many understandings of it. So you just become reckless by doing that.
But you can also be over lawyered if you end up asking for five different legal opinions in all jurisdictions at once. although you're not even active there at first. So both extremes can kill. This is why we're having this talk. Why also we're having this talk?
Because it's just about being a good founder and basically doing triage. It's like you have a product road map, have a regulatory road map. What do you need to do at which stage? Which are the reversible choices you can just postpone for later? At which ones are the hind to unwind errors that will just follow you through.
For example, you published something on Twitter. You should have not said that. someone took a screenshot one year later they would just say hey guys you promised that on Twitter what happened in the meantime um so what is the triage how do you need to figure out this road map well there are five topics well know your product market team corporate partners it seems very basic it's like your business plan but unfortunately it turns out that these very basic questions are not always figured out so first of all the product seems obvious right you know your product you know what you're offering to users well when you start asking questions is Not that obvious, but then test net always buys your time. So in terms of like things when you're still experimental, you have a test net, no one can actually lose money. You just have test things.
Well, it buys your time because no one will go against you in principle. But there's always a but what you promise to people. What happens is the example of the Twitter post like on X. During test net phase, you promise things for domainet that never materialize in the way you announce them or you make some publications about a future token that will have some great acrruel of revenues and so on. It's very hard to undo that because always people take screenshots and there's always traces on the internet.
So it buys your time, but you need to be very cautious on how you advertise things. But if you don't want to reach a lawyer yet, you don't have the funds, you can more or less rest assured if you don't do uh tricky things. Then decentralized, is it a decentralized public good? You're offering like a super DeFi protocol or do will you have an operator? And this seems like an obvious question, right?
But then what turns out is that in many cases you retain a lot of admin functions and like oh centralized. Yeah, but if you can move all the user funds without asking the users, even if it's just for now because it's the V1. Well, if someone sees it in your open source code that's just public to anyone, maybe a bit tricky to maintain the narrative of decentralization. So, it's something that you should really be aware of. And one of the things I've heard is like, oh, but we'll never use that functionality.
Great. But the regulator doesn't know what's happening in your head and whether tomorrow you wake up and you go rogue. So, doesn't work. Now, what's the mean to do then for your product? And this is something I really hope for everyone to have because I need to ask for it when clients reach out to me.
just map your admin functions like what can you control? Why do you control it now? What is the rationality? Do you need to keep maintaining it as a control function once you launch mainet or is it just for the v1 because you still have some adjustment to do. Um can you actually relinquish it or can we adjust it and can we figure out something else?
Just be aware of it like any lawyer will thank you if you can have this data and reliable one. This is why I mentioned I'm going to go into your GitHub because sometimes I ask for it and I'm like are you sure? Because like when I ask the AI and analyzing your code, it tells me that actually you can do it and like oh yeah true it was maybe slightly misleading because it's easier for the users to understand that way doesn't work. So a very truthful reliable honest presentation of what you control is what any lawyer will need and it will also help you understand whether the advice you get is correct. So things moved a bit apparently on the slide or maybe it's just on my it's stuck.
Okay, what happened to my slides? And I also lost my slides here. Too much legal topics. Even the slides give up. Um they felt reckless and run away.
So we were at the product and we are here. Things shifted apparent. They don't appear up there. Well, anyways. So um another thing to take into account is just don't panic once you map all the controls because you also have like a difference in granularity on the extent of control.
If you just have like a general kill switch which most protocols have like I can pause everything if things go wrong you can kind of argue around it and make it work. But then the other extreme is people who have like very granular specific things. I can pause a specific account. I can block a specific transaction. I can do this.
If you have like very specific controls, it becomes harder and probably you should definitely call a lawyer to discuss it further. So targeted power tricky general power, we can figure it out. Um then it's still stuck. [snorts] Well, you will uncover those slides someday. I will publish them online, but I'm also stuck here.
[snorts] What comes next? Okay. Uh so what are the red flags? I already mentioned like this aspect of you have very specific powers. But what kind of powers?
Uh well the red flags or you definitely should discuss it with a lawyer just in a reasonable time before you launch mainet is three main things. If you hold somehow user assets if you contribute somehow to their transfers or you can cause a transfer without the users. Why do I say that? Because a lot of times I hear oh but it's not me it's a smart contract or it's not me is the AI agent. Well, you kind of control the smart contract based on your admin function mapping and you kind of deploy the AI agent and you are the one in charge of the server.
So, this is not a straightforward excuse. If you are really needed there's a dependency on you or basically tomorrow if I stop contributing this whole protocol just doesn't work anymore. Figure it out. If it can work because in some cases for example users can deploy their own instance of a software that is going to do exactly what you are doing then it's a bit better. But if really there's a dependency, better discuss it with your lawyer.
So after the product and those red flags, you have the market. And this is where things get tricky because you hear like, oh, let's get a license for prediction markets in Jibralta. It's going to be cool. Yeah, but you offer it in the EU or to the US market, so it doesn't make sense. There's a lot of hype about like oh there's a cool regulation there but what matters is not only where you are established as a project like the entity also where the team is based because a lot of jurisdictions also look at the substance and be like oh but your whole team is in Switzerland so basically you're operating from Switzerland and should have been established there but also which is the market you target best example the EU like if you don't exclude the EU and you have plenty of users in the EU even if you have an offshore entity well EU regulations apply So there's a problem.
So you really need to be aware of what are the markets you're targeting. Can you deal with the regulations there? Can you avoid it somehow by being elsewhere which often the answer is not? And do you need to go there? Like do I need to deal with the EU if I know most of my trading activity will come from Asia?
No. Do you want to take the risk then maybe just block the EU for now until you figure it out? This is how you also do like some sort of triage. What are my priority markets? what are the ones I can just postpone and where I want to minimize the risk or you can do some reverse solicitation things but this is very limited so awareness about your users um then after the market comes the team and my slides are still stuck so you need to listen to me and you don't see the super spicy uh image I've put of a hot sauce for the team because it's often forgotten like I asked is there a shareholder agreement do you have some agreements between founders for token allocations do you have clear agreements with your advisor service providers and you end up with templates with some very vague handshake deals and then things go wrong.
So for founders, I would say it depends on your team. If it's like a bunch of friends, you know each other for five years, there's some risk. But then if you have just three people who got to know each other a few months ago at a conference and have a product together, well maybe figure out some things in advance before things get sour and you start to hate each other because this is one of the things that doesn't always pop up in the press, but as a lawyer you see a lot of conflicts. Oh, they promised me tokens but now I leave. How much do I get?
This guy did that. Did he have the power to decide it on his own? Like it's a lot of very practical aspects that can actually ruin your business and then you end up in six months of a fight with your co-founder and then the product is stalling. Nothing happens because you're just doing this with lawyers and you spend a lot of money. So just figure out who gets equity, who gets token, who can decide on what, what you promise to different people.
Unless you really feel super like you're the best friend since high school and all of a sudden you work together, there's still a risk but maybe a smaller one. It really depends on your relationship. So feel the crowd that you're working with and know also just maybe this is the best cave yet. No investor wants to enter a startup where they know everyone is already fighting and they have no clue what they're doing. So they're going to often ask you have a shareholder agreement and like h we haven't figured it out.
Doesn't work. Uh the team is also the broader team like the people you hired your CTO and who are not necessarily part of the founding team. They are not on a shareholder agreement and so on but you want to know what they can do. What if your key asset all of a sudden tells you, "Oh, I'm leaving for the competition and you had no non-compete clause. You had nothing to really make sure that the IP they developed was assigned."
Like this is very important always like how crucial is this person for your team? Do you want to allow them to leave pretty easily or do you really need them to retain like and remain in place for a few months because I know they develop the key aspect of your protocol and if they leave from one day to another you may be stuck and there are very practical questions that you can just have in a policy which seems ridiculous said that way but same it end up creating issues like can your CTO fly business to token if you're early stage you don't have many funds and you end up with a 10k bill for a trip you're like maybe I should have planned ED events also can then trigger bigger issues or like who can reach out to the lawyer and ask questions. What if you get like an invoice from your lawyer for thousands and you're like but I never asked for that and you realize that actually your COO asked for plenty of questions that no one was aware of. So it seems very basic but it's actually important for you to know about it and know whether it was figured out. Is it in an agreement in a policy like what happens there?
So that's for the team. Now can AI or templates fix that? And I still don't have the slide. So you again miss a nice illustration. Um, of course they can, but it's not about having something in place.
Like a lot of people tell me, "Oh yeah, I have like I use this template. I have a shareholder agreement in place or I have like a basic agreement for my employees." It's about what you have in place and what's in it. Because if you use a AI generated template or any template, the question is, does it tackle the specific issues you have and the specific aspects you want it? And it's always like it's the same thing everywhere.
Wrong prompt, wrong output. So [clears throat] you ask for a basic shareholder agreement, you will get a basic shareholder agreement, but does it match what you need? No. And now we'll use AI as well for like corrections and stuff like that, but you'll have a completely different output just because it's about knowing what you need to ask about and this is the major issue. So use AI as much as you want, but you still need a lawyer to whisper to the AI to know what exactly you need um as an output.
Now the very important part the corporate structure like how many entities and where do you need them? Well I would say in general everyone is different. I've heard like things like uh the more entities the better because then you split risk. Yeah. But then you end up with founders who tell me I have five entities and I have this foundation and I don't even know what it's used for.
A bit annoying. It may result in situations with like entities that become abandoned. They forget to file taxes. They forget to do any corporate housekeeping and they just even forget it exists. and then someday it backfires.
So I would say if you're just building the product, the defa is what you need to start with. And then do you need thousands of questions to figure it out? Probably not. It's more about your situation. Where do you have substance?
You are you in a jurisdiction that is pretty uh stringent and will tell you that even if you incorporate it abroad actually you have substance in there. Like Switzerland for example, if you have nowhere in Panama and everything happens in Switzerland, they may kind of overlook what happens. But the defa usually the boring part. Just pick whatever works for you from your personal situation where the substances your tax situation whatever just make it easy for you. Don't overengineer it.
And then you have the actually a interesting part which is the operational company. It's the one that will be offering your product to the users or like if you have B2B partnerships, it's the one that may also collect some revenues if you have like a clear revenue stream and that's the one where all the regulatory questions occur. This is the one where you should really think it through with your lawyer and not be like I just put it wherever is the hype because this is where all the questions arise. So that's the one you need to spend a bit more time on and if you have like a test net phase it you have some time to figure it out properly and then what happens on top is like imagine you have a prediction market you go to some my slides are back awesome. So there you see the hot sauce for the upco because that's the hot topic.
um what comes on top often because end up you end up in Panama or like in biz or any of those random jurisdictions your investors may tell you if I preede it's fine but seed I don't really like it and then you need to restructure and what happens is like you would just say okay maybe let's find an entity that meets investor needs where you put the IP because investors don't want to have an empty shell like this is one of the things that happens oh can I just create a holdco yeah but the investor gets equity that is connected to nothing and then you can't sometimes connect it to the operational entity because it's regulatory tricky. So you want to split the risk. I would say the devco opco IP or holdco whatever you call it is like the sacred tree of entities that you potentially need. You may start with one go to two go to three over time. That's mostly the progression.
Um but you can't really avoid most of them. But you don't need six. But you still may end up with six. And then you end up as a lawyer like this cook being like, "Okay, I have too many pens. How do I handle it now?
Where is the the item I need?" Um, how do you end up with that? Well, if you have a clearly regulated arm, you need some custody or like you need something that's KY subject to KYC, you sometimes need to split activities into entities. You have a token issuer, you want a clear framework for the token issuance, so you end up in a different jurisdiction. That's where you have your OPC code.
uh you have licensing topics you want to optimize it from a licensing perspective or tax perspective but the only thing to always to keep in mind is the more boxes you add the more entity the more costs administrative overhead you need to think about it you may need local directors so it's like a whole chain that you expand and makes your whole activity complicated because every time you sign something you're like which entity is supposed to sign it and which person from that entity is supposed to sign it so just add them wisely over time fifth point partners that's often forgotten and I love this point because you have a lot of handshake deals with partners including partners that provide you technology that is really necessary for your product. It's like oh you really rely on this Oracle we really rely on this but the integration is like based on a template that the partner provided and we haven't discussed it all. Well, the issue is that even if you feel like you have zero negotiation power, if you just accept everything, could be that something doesn't match your situation. Maybe that part is suited for a regulated actor, but it's not suited for you. Um, I still remember uh an agreement that was provided by um an issuer of like a real world asset that was asking a DeFi protocol to say that they are operating the protocol.
If you sign that, you're basically slaying the opposite of the narrative you're selling to selling to everyone. So it's a kind of small details to be adjusted just to avoid that you sign whatever or the trickier part is like imagine you they have a super broad termination right or they can sue you for whatever happens like do you really want that sometimes you can't really say no because they have all the power and you're just a small actor but be aware of the risk and have for example backup strategies you know your main partner can terminate with a one month notice awesome but be aware of it because if you discover it afterwards and like, "Oh, damn. What do I do now? In one month, they're gone." It may be a whole um a whole mess for you.
Can AI fix that? Like, can I just submit the contract to AI and ask for comments? Sure, you can. AI will tell you what the clause is, whether it's market practice or not. But it's always the same.
Wrong pro like wrong prompt, wrong answer. You ask whether it's standard practice, they're going to base themselves on the wrong sector, the wrong jurisdiction or whatever. It happened a lot of times where a client's like super scared because AI told them it's bad, but then you look at their situation and actually it makes sense in their situation. Or the opposite, AI says like oh this is fine like uh for you guys it doesn't make sense at all. So it's always about thinking like what is the term in the agreement?
What does it mean for me and what are my operational needs? like um random um random example someone who needs to deploy cap capital constantly because they are providing a service to someone and then you have a clause in the agreement that says that you need approval from the client to deploy additional trenches of the capital seems normal right but what if there's no um duration for like how much they can wait to accept the deployment what if like they can just refuse deployment about any reason it seems like stupid as like a remark But actually it could mean that you prepared everything. You had costs and then they tell you oh no we don't want to deploy just because we changed our mind and then you bear all the cost because potentially there's nothing in agreement. So it's always about you know best your operations you know how your business works and you're supposed to kind of explain this to your lawyer so the lawyer can tell you whether the agreement matches those needs or not. And you could try it with AI but again you don't always know which aspects have legal implications.
So an AI whisperer is always useful I would say at that point. Now what are the all the wrong answers that I hear that you really should avoid is to say others do that so I'm going to be fine. The VC asked for it like recently someone told me oh they ask for a entity in that jurisdiction. Why? Because other projects do that.
Okay but why in your specific case? No answer. So definitely probably they haven't followed through and they just push the button like yeah this is trending now. Uh there is hype about the new license like everyone who was super excited about the US all of a sudden we need a US entity for this we need to do this because US is the future. Does it make sense for you?
Is it really figured out? Is it a new regulation that's already in place? You have practice or is it just a future draft that isn't there yet? It's all of this stuff to be taken into account and that not all entities take into account. Also saying oh because there's no tax.
Great. Maybe you have no tax but potentially you don't even have revenues yet but you have other risks that would be triggered in that jurisdiction. And also saying there's no actual control or enforcement. This is I also got that line once like yeah but no one cares in that jurisdiction. They don't care now but nothing guarantees you that they will not care in two years or there will be like a new regulation or like they will change enforcement practice.
So maybe it's like a good shortterm solution but it doesn't mean you can just safely operate there. So basically you can ask AI and I think it's a very good trend but ask a lawyer on top to actually understand whether AI provided the right answers and keep building peacefully while the lawyer is cooking for you. But I I would still say as a wrap-up like I wanted to explain why those things matters. Um so to be cautious like sometimes lawyers will push things at you and it's good for you to push back and say I'm not sure I need it. And sometimes it turns out that actually you didn't need it.
if you simply didn't mention the detail that makes it less necessary now. Um, but at other times when a lawyer tells you that this is really needed now, it actually is and you shouldn't take it as, oh, they're trying to get all the money out of me. No, you really have a major issue. So, have some critical thinking. Trust your lawyer enough.
Ask questions to understand what the lawyer is suggesting. Avoid being the founder who blindly trusts anyone and then cannot explain your own business actually to a VC or another founder. And then let the lawyer cook. And if you need a lawyer, well, you have one here. Thank you very much.
[applause]
Automatic transcript — names and jargon may be misspelled.