# Frontend providers for DeFi as operators under MiCA - Ilija Rilaković | Rilaković Law Firm

- Channel: [ETH Belgrade Community](https://streameth.org/eth-belgrade-community)
- Date: 2024-10-07
- Duration: 28:24
- Topics: People & Blogs
- Watch: https://streameth.org/watch/yt-tKqvsk6AzS4
- YouTube: https://www.youtube.com/watch?v=tKqvsk6AzS4

## Transcript

hello guys uh it seems that uh the US market is uh more interesting to the general public than uh MAA um we'll see whether is it because of uh speaker or the regulatory framework so um yeah um as an said I'm lovic uh I do Logistics uh picking up collecting people from the airport uh sending merch and uh when not doing that I'm uh lawyer and I do corporate law tax FLW and some crypto assets uh besides I'm the one of the co organizers of e Belgrade so that's why I'm wearing this um this red shirt and uh I have to cons reconsider um this this format of being both organizer and uh speaker because it's a hell um whoever uh saw this this movie scarf so uh don't get high on your own Supply um because it's just does not add up so um briefly about uh MAA regulation uh as yes all good thank you as this is predominantly Builder conference uh I wanted to shed some light to to people who develop protocols mainly in defi so uh as you know we have MAA that is into Force since last year almost a year ago um certain parts concerning uh e-money tokens and asset reference tokens um just uh began to to apply but uh what is also expected is that um uh so as with uh l1's l2s l3s in in blockchain we have uh different levels of Regulation um in this field as well so uh European authorities are expected to uh provide technical standards many bylaws that um develop framework in more details because me is just a general framework that sets principles and technical details should be should be done by these level two and level three uh three measures U this is brief Outlook of um um application of of M so uh first first uh first part title three and title four asset reference tokens and the money tokens started to apply why the rest of it should be in application by the end of uh this year so pursuant to the uh pursuant to the uh definition of MAA um operation of trading platform is basically management one or more uh systems that um facilitate trading of different cryptocurrencies tokens and so on and so forth I not going to read the entire um the entire definition this is just for the referance because of the the later part uh yeah yes one uh one more uh picture of how how the application going to going to look like so um uh this is also definition of what is um custody and administration of crypto assets according to Mika uh why the access is uh underlined it's because it is important for the front end of uh the centralized protocols we'll see why so basically custody uh provides access to to uh crypto assets of holders and uh we are coming to the main point so uh when we talk about uh decentralized protocols it's it's basically a piece of software that runs on a blockchain and once it's deployed uh you uh somehow have to interact with it how do you interact with the blockchain protocol um it's usually through uh another piece of uh code let's say website or maybe a mobile application that allows you to to interact with it and use all the features that it offers uh and then there is a question whether such a uh access point can be characterized as a operator of trading platform under under MAA maybe it's obvious maybe it's not uh I would say it it's it's not clear enough and it's open to discussion that and that's uh that's uh what I wanted to uh to do later to open the discussion on on this because we have some devs in in the audience and the and the lawyers to give us their um uh their opinion because why this is uh of importance for the defi industry is because there are serious uh serious of liabilities and obligations of operators of um uh trading platforms so uh this is just one one excerpt and what is commonly seen in terms and conditions of uh different service providers is that uh they try to limit their liability so disclaimers uh which can be seen under MAA are not going to uh prevent uh from prevent you from being sued so uh terms and and conditions of those websites and mobile applications should be adjusted and uh this is kind of call to action to to discuss with your lawyers advisers uh your terms and conditions and the way you operate your uh front end especially if you work with uh uh decentralized protocols because your website or uh application is second please um is the access point to to that protocol and what are the consequences apart from civil liability so being sued and asked for money or damages uh you can be uh prosecuted in your national jurisdiction uh under criminal law so uh that's the that's the nuclear uh nuclear scenario and uh you can be prosecuted but under what grounds so you can claim that you are not uh uh not operator of a trading platform but um do you want to be part of the ordeal of criminal proceedings um what might be uh defense strategy hope that it's not going to be the case is that you cannot you can plead that uh law was not sufficiently clear and that you are not part of uh that you are not operator of a trading platform so um I would like to hear yeah you you had questions question about prac terms okay so any contract uh contractual exclusion or limitation of civil liability shall be deprived of legal effect so basically uh if I write if it's written in a contract that I will not be liable for anything whatsoever irres uh well as an operator yeah and and in general um I would not be liable for anything whatsoever it's all to up to you as a client or customer uh that will not have a legal effect so uh it's limitation of contractual uh freedom of uh Contracting is it good enough more clear so there are principles of um of criminal law that should be uh observed at any criminal case one is that uh there is no sanction without uh um prescribed um prescribed crime so uh it's difficult to apply uh the rule um to to prosecute somebody if the rule is not clear enough so um there is a risk that uh certain frontend uh websites or might be characterized as a operators but this is this is up to the uh up to discussion whether that uh that would be the case um so um I can open the floor for for discussion now yeah V pretty loud as well but not that much related to uh m in particular um because there are a lot of uncertainty there but um I'm part of a an of an advocacy organization uh and we're in Brussels quite a lot so during a conversation I had with a representative from the European Commission last year related to the product liability directive um for those of you that don't uh know it's one of the eldest oldest dire uh directives in the European Union so now they're kind of redefining the concept of a product to also fit software product so that there would be also liability for programmers um so the way that it it was written basically brought up this question okay what who is going to be responsible like who is going to be liable and the person that is one of the people responsible for writing the like the um product liability directives uh new version basically said well it's going to be uh the front end operators because it's obviously that it's going to be there because they're we are looking for an like person entity that is bringing the faulty product in this case to the market so obviously like in their um way of thinking it's obviously the front end So based on that logic I wouldn't be surprised that with the next version of mik like with whatever is going to happen now with defi uh this might be followed as a as a concept like even though we currently have RTO 22 of Mika where fully decentralized is out of the scope a we don't know what fully decentralized is and B that's only until the revision that will come uh in the next few like months top and year tops so yeah if that helps I hope that helps the discussion of basic it's always uh the regulator and then the uh judicial system and the overall system is looking for someone and that's usually the one that is the most obvious um person like bringing the front end and yeah the fact is that um front end provides access to the to the protocol and if you are gatekeeper in a way although you don't have custody over that effectively you can prevent somebody from accessing the their funds if your software is broken I mean front end software pav what do you think okay uh so what would help maybe frame this discussion a little bit is liability in in in certain cases because for me at least as a um so the first thing which was quite surprising to me is this idea that you have product liability as a as a developer because I understand liability if you are uh H how can you divest liability from or or like how can you have liability that's direct without having some kind of chamber or licensure or something which does not exist for software Engineers or developers at all so you can be like personally reli personally like liable what if it's an open- Source contribution built by like thousands of people that are not in the same jurisdiction do you just pick someone and throw them under the bus how's that even like how is that okay I guess it it meets some legal goals but it's not very productive so I guess it's still a bit of a mess but if we're talking liability here like my main question is like of course if you are operating a frontend and there is no access to a protocol without a frontend cont even if you run it on your own computer somehow uh the question is like what is it that you're doing that you're liable for are you liable because you're for example not censoring people are you liable because people are trading and gambling and losing money like like what is the problem here are we like setting the standard for general liability or is there some specific like categories that we are trying to to to determine that frontend operators should guard against and I guess the most important one is like do we does the frontend need to identify its uh its users and how deep does this identification have to go I'm not sure that uh we don't talk about identifying the users immediately it's um how the that service provider that frontend developer is responsible and where limits of his liability and responsibility for the uh for the code it it provided to to Dex yes M so when it comes to front ends so with unop it's clear that like you have the unop front end but you can also interact with unisoft through ITR scan and you can also send transactions via an RPC via curl so is it clear what classifies as a front end where is the line drawn uh for the purpose of this presentation what I had in mind are um websites and mobile apps not not either skin so I try try to well I try to narrow a little bit down the the scope you had a question yeah um actually I was curious about like the Practical implementation like what is considered to be the loss of funds because for instance let's uh Envision some practical examples like I'm trading on Unis swap for instance and I uh I buy a token a custom token which I add manually there it's not in the white list and this token is uh pumped and dumped and all the money are gone like I spent like $1,000 to buy 1 billion of paye meme coins or whatever and now they cost nothing is this considered to be a loss of funds no I think it's just your poor investment decision not uh not uh the the loss of funds or or liability of uh either Dex or or front end so it's only about like exploiting the contract or if the Unis swap contract is exploited and for instance like all the pool money are gone and I'm the investor in this case um no as I explained once the the smart contract is deployed on on blockchain you basically can't do anything but uh you provide a gate uh through which you access that smart contract so that's uh that's the question so are you as U access point so front end developer for for that de um liable for for um customers not being uh able to access the blockchain or potentially losing the funds due to some exploit of your uh of your your not mine in general I don't have clear answer that's the that's the the reason I I why it was uh this was interesting to to me to to discuss and to present because although it might be clear that uh frontend provider is not uh offering custody Services fundament I mean effectual in in effect the it's access point through which you can either have access to your funds or no and the last last bit of a question like are there any practical cases some one got prosecuted or like sued under the I don't know to be honest and this uh this is new piece of legislation so it might happen in the following years we'll see yeah because yeah madin of question so thank you for the great presentation I have a question because we are now living in the decentralized world this means that the front end can also be centralized for example through ipfs now is it is the provider the developer or because who is then liable for I'm I'm not sure so that's a good question uh since this is new I'm I'm not sure that I can answer it but it's it's good one yeah and uh in essence then as a backend developer I can write anything and I'm not reliable and put it on the blockchain or is there some piece of legislation that is uh working with the smart contract developers I don't think that you can uh escape the the liability just because of you are in in backend there are few cases that I know uh Ida case uh in the US and of course tornado cash they were just providing a smart contract so they did not launder the money but but have a non-legal question um which projects are doing the best job having decentralized front ends built in their ecosystem like for example I've seen it with liquidy I'm just curious if there are others that have done a good job of completely independent teams building the front end to interact with the smart contracts do you know of any no to be honest does anyone in the room know any so um unfortunately there's no such thing as a from what we're seeing like we're not talking about any kind of exotic way in which you're interacting directly with with onchain services and sort of assembling everything in your own house there's no such thing as a decentralized access point to a web Tree application because it's going over the internet and the internet has an IP address that you're you're you're targeting a server whoever holds that server in this understanding will be liable even if you're following this kakimi logic which is like you were a contributor on GitHub like the law will find somebody whose head it will chop off it doesn't matter if it makes sense they'll just do it because that's that's the way the law operates so liability has to be found be for for for this for this legislation now as far as I understand there is it's a little bit more clear to me sorry when I asked the first question I was totally confused now I'm a little less confused but I'm still confused the the thing is essentially you're if the fact that you're talking to a piece of decentralized technology that's like hum mutable and so so on and so forth doesn't mean anything because the app that you're doing interacting with can tell you anything your wallet can lie to you your app can lie to you everything can lie to you and I guess this is where liability sits now this is a big problem because there have been even in web tree and outside of web tree there have been like attacks supply chain attacks where the the the app will show you bad data and you will make a decision based on bad data and you will incur a loss so this is actually a good thing that that the EU is targeting because in the end you should be liable for operating something like this it is something that that that can be looked at and can be mitigated potentially through security practices and so on and so forth this is something to begin with uh as I said it's a new new piece of legislation and it remains to be seen how the technical standards will be finally developed and rolled out and uh how the front-end operative operators service providers will be perceived and this is what lawyers do discussion discuss different scenarios and I I would just like to ask you specifically a question like what what do you see as the overarching goal of of of this legislation is it is it basically just bringing crypto in line for for for it to be tracked for tax purposes is is it is it that or is it something else I always found M difficult to pin down as a as a lay uh it's uh it's tough one because um it so okay um MAA should be good uh because it finally puts together all critical parts of um crypto industry under one Chapo let's say and aims to unify the European uh crypto markets because and that's why this is regulation and it applies directly unlike directive when it sets minimum standards and National jurisdictions should uh develop it further so set minimum standard in order to unify the the market with regulation it applies directly and um I guess that's the Europe that's why European legislator uh opted for for uh this this format of uh of law so direct application last question I guess to be on time yeah all right so with Serbia kind of wanting to join the European Union do you see Serbia following M bit like how it did with gdpr and how compatible is it with current Serbian regulations um so um Serbia is on accession path to the EU and our law on digital assets um generally follows the logic of MAA although different different terms different conditions but um in some parts it's um it's more appealing to the projects who want which want to um not to say Escape but to uh mitigate the regulatory burden uh that uh MAA will introduce um for that reason we already I mean already in my legal practice few leads on uh crypto asset service providers who wanted to open a branch in Serbia in order to be able to operate in Europe without entirely complying with MAA that means that uh which does not mean actually that you can avoid it entirely there are some reverse solicitation Clauses which prevent you incorporating for example in Serbia or Macedonia or Albania and targeting actively European market that's uh that's not allow that's targeted by by uh by this regulation so um I think that in near future we will uh have to adjust our regulatory framework and our law with ma but um it's long long way to to that point so uh like with gdpr uh I think we will we will at some point have to to uh adjust our lit with this regulation yes or no are they going to kyc everyone yes or no I guess no yes thank you [Applause]
