Important Note: This article presents an independent analysis and has not been reviewed or endorsed by any regulatory authority, including the Central Bank of the United Arab Emirates (CBUAE). It not dues constitute legal advice and is exclusively informative in nature, intended for entrepreneurs, executives, legal professionals, and technology specialists seeking to understand how the regulatory framework established by Federal Decree-Law No. (6) of 2025 applies to companies operating in the financial and digital asset sector in the United Arab Emirates.
The enactment of Federal Decree-Law No. (6) of 2025 by the President of the United Arab Emirates was a significant milestone in the evolution of the country’s financial, banking and currency regulatory architecture. Among the most relevant provisions are Articles (61) and (62), which together define the scope of licensed financial activities subject to the Central Bank’s supervision, regardless of the form, model, or technology through which those activities are conducted.
Understanding the application of these two provisions is essential for every company that operates or intends to operate in the UAE’s financial ecosystem, whether through traditional infrastructure or through digital and decentralized models.
Article (61) establishes the foundational list of activities that the Central Bank of the UAE considers to be licensed financial activities, meaning activities that may only be lawfully conducted upon obtaining the related authorization from the CBUAE.
These activities are comprehensive in scope and include:
- The taking of deposits of all types, whether conventional or Shari’ah-compliant;
- the provision of credit and funding facilities in all their forms, including Islamic finance structures;
- the provision of open finance services;
- currency exchange and money transfer services, including instant transfer mechanisms;
- the provision of payment services using virtual assets;
- the operation of stored value services, retail payments, and digital money services;
- the arrangement, promotion, and marketing of licensed financial activities;
- acting as a principal in financial products such as derivatives, foreign exchange, bonds, sukuk, equities, and commodities; and
- the conduct of insurance, reinsurance, Takaful, and Re-Takaful business and services.
In addition to setting out the list of activities subject to authorization, Article (61) also grants the Board of Directors of the CBUAE the authority to classify and define the activities on that list, as well as to add, remove, or amend entries following consultation with the Financial Stability Board of the State.
Furthermore, the article also provides that any Licensed Financial Institution wishing to conduct activities regulated by other authorities, whether within the UAE, in financial free zones, or abroad, must first obtain the Central Bank’s approval before seeking authorization from the relevant authority, thereby reinforcing the CBUAE’s primacy in supervising entities within its scope.
In turn, Article (62) builds directly upon the foundation established by Article (61) and addresses a question of growing urgency in an era of decentralized finance, tokenized instruments, and blockchain-based infrastructure:
Does the obligation to obtain Central Bank authorization depend on the technology or model through which the financial service is delivered?
Under the terms of Article (62):
“Without prejudice to the Licensed Financial Activities referred to in item (1) of Article (61) of this decree-law, any Person carrying on, offering, issuing, or facilitating, whether directly or indirectly, any Licensed Financial Activity – regardless of the medium, technology, or form employed – shall be subject to the licensing, regulatory, and oversight jurisdiction of the Central Bank. This includes the following:
1. Virtual Assets payment tokens, decentralized finance (DeFi), other emerging technology, or other digital or physical instruments used in connection with the Licensed Financial Activities; and
2. Offering or operation of platforms, decentralized applications (dApps), protocols, or technological infrastructure that facilitate, intermediate, or enable the provision of financial services, such as payments, credit, deposits, money exchange, remittances, or investment services”.
As extracted from the wording above, any person who carries on, offers, issues, or facilitates, directly or indirectly, any licensed financial activity is subject to the licensing, regulatory, and supervisory jurisdiction of the CBUAE, regardless of the medium, technology, or form employed.
For businesses operating in the development of technology and blockchain-based solutions, a thorough and detailed assessment in light of the aforementioned legal guidelines is required, given that blockchain architecture possesses attributes that often reorganize supply chains and traditional business flows, representing an additional compliance challenge.
This is because smart contracts — a form of self-executable “contract” generally written in Solidity — are endowed, beyond their self-executing nature, with characteristics such as immutability and auditability, meaning that, as a general rule, transactions or information recorded on the network cannot be deleted and are accessible to anyone. This is stated as a general rule because these characteristics are not absolute and may be mitigated depending on the type of blockchain used to deploy the smart contract and the conditions established in the code.
With regard to self-execution, it is in this attribute that the most sensitive point lies from a legal and regulatory perspective, since once deployed, these contracts perform their coded functions without ongoing human intervention.
This characteristic raises a structural regulatory question that Article (62) implicitly addresses:
When the activity is carried out in an automated manner, without human intervention or action, who is the “Person carrying on, offering, issuing, or facilitating” the licensed financial activity within the meaning of the decree-law?
In such cases, the applicability of the rule may fall upon companies or individuals who exercise control over the protocol, derive economic benefits from its operation, operate the user-facing interface, hold keys enabling specific functions, or participate in governance mechanisms, regardless of how they present themselves to the market.
Equally relevant is the composability inherent to decentralized finance, through which protocols are routinely combined and integrated in a manner that aggregates regulated functions across multiple smart contract systems.
By way of example, a yield aggregator that routes capital through a lending protocol, a liquidity pool, and a synthetic asset platform may, in its entirety, replicate the economic profile of a collective investment scheme or a leveraged credit facility, even though each component, individually considered, may appear to be purely technical in nature.
Therefore, companies developing solutions within this ecosystem must assess their products and their full architecture holistically, rather than in isolation with respect to individual smart contracts or other tools.
This conclusion is further reinforced by the interpretative guidelines recently published by the CBUAE in FAQ format, which address the implications of Article (62) for businesses based on two main pillars.
The first concerns activity-based regulation, as opposed to technology-based regulation, under which the criterion that determines whether an entity requires a Central Bank license is not the nature of the technological infrastructure it uses, but rather the nature of the underlying financial activity it performs or enables.
Therefore, a protocol built on a public blockchain that allows users to lend, borrow, exchange, or hold digital assets in a manner functionally equivalent to traditional financial services would be subject to the same obligations as a conventional bank or payment institution performing those same services through centralized infrastructure. The decentralized character of the technology is legally irrelevant to the classification of the activity as regulated and subject to the requirement of authorization.
This interpretation has significant implications for companies in the Web3 market, since decentralized applications, automated market makers, token-based lending protocols, and other forms of smart contract infrastructure that allow users to conduct transactions traditionally classified as deposits, credit, payments, foreign exchange, or investment management would, under Articles (61) and (62), be subject to CBUAE licensing requirements if they operate within the UAE or offer their services there.
The second pillar regarding Article (62) seeks to exclude purely technical service providers from the CBUAE’s jurisdictional scope, given that entities that supply, for example, software, cloud infrastructure, development tools, or other technological solutions, and do so exclusively in support of institutions already licensed by the CBUAE, are not considered regulated entities.
This distinction is fundamental to preserving the development of the innovation and technology sectors, which provide services and solutions that are critically needed by the financial and Web3 markets, without compromising market integrity and investor protection.
Accordingly, a software company developing a core banking system, a cloud provider hosting the servers of a licensed payment institution, or a smart contract developer building infrastructure for a regulated virtual asset service provider would not be required to obtain their own CBUAE authorization to operate.
However, caution is necessary, as the threshold between a regulated activity and a purely technical service can be thin, and the reality of the operation must be considered over its form.
Thus, the predominant factor of analysis is whether the entity in question is, in practice, performing, enabling, or presenting itself to the market as a provider of a financial service directly to end users, or exclusively as a provider of technological services, tools, or infrastructure.
When a technology provider begins to offer financial services such as payments, custody, credit, or foreign exchange, whether directly to clients or indirectly through structures designed to attempt to circumvent the licensing requirement, it will be treated as carrying on a regulated financial activity and will be subject to the obligation of obtaining CBUAE authorization.
On the basis of these provisions, companies operating in the UAE financial services, fintech, or virtual asset market must therefore conduct a rigorous assessment of whether their activities fall within the CBUAE’s regulatory scope and, if so, obtain authorization prior to commencing operations.
The stakes of failing to conduct that assessment are considerable. Under Article (170) of Federal Decree-Law No. (6) of 2025, any person who engages in licensed financial activities without the requisite authorization is subject to imprisonment and a fine of not less than AED 50,000 and not exceeding AED 500,000,000, or either of those two penalties.
In parallel, Article (168) empowers the CBUAE to impose administrative sanctions at its own discretion, including a fine of not less than AED 1,000,000 on any person carrying on or promoting financial activities without a license, and fines ranging from AED 1,000,000 to AED 20,000,000 on any person operating a financial market infrastructure without authorization.
Beyond monetary penalties, the Central Bank holds broad investigative and enforcement powers under Article (133), including the authority to inspect premises, requisition documents, and seize records from any person suspected of conducting unlicensed financial activities. Companies and individuals who present themselves to the public as licensed financial institutions without holding the requisite authorization face additional criminal exposure under Article (174), which provides for imprisonment of up to six months and a fine of not less than AED 100,000.
Taken together, these provisions signal a clear legislative intent to treat unauthorized financial activity as a serious offense, one that carries both reputational and material consequences capable of threatening the operational and commercial viability of a firm. It is against this enforcement backdrop that the full significance of Articles (61) and (62) becomes apparent.
In light of the foregoing, it is evident that Articles (61) and (62) of Federal Decree-Law No. (6) of 2025 establish a regulatory model that is simultaneously broad in its reach and precise in its delineation, given that the CBUAE’s jurisdiction attaches to the financial activity, and not to the instrument, technology, or model through which it is conducted.
This approach establishes a relevant regulatory framework that promotes innovation in a manner consistent and harmonious with financial stability, consumer protection, and market integrity.
As a consequence, companies operating in this market should thoroughly assess their structures, operations, and products in order to verify alignment with the applicable legal and regulatory requirements, so as to avoid unwanted penalties or the interruption of their activities due to irregular conduct.
Should you wish to explore in greater depth how these provisions may affect your firm’s structure, licensing strategy, product design, or market approach, our team remains available to discuss these matters and assist in developing practices consistent with CBUAE expectations and with the broader regulated environment of the United Arab Emirates.
Contact Details
Email: admin@bankslegal.com
WhatsApp: +971 55 655 2447