Article 345 TFEU: The Ceiling on Tokenised-Securities Harmonisation
Why there will be no MiCA for security tokens: Article 345 TFEU reserves property law to Member States, so what a token is, who owns it, and how rights transfer stay national. A structural read for issuers.

Executive Summary
There will be no single EU rulebook for security tokens, and the reason is structural, not political. Article 345 TFEU provides that the Treaties shall in no way prejudice the rules in Member States governing the system of property ownership. Property law is reserved to national legislators. That means the three questions that decide what a tokenised security actually is (what the asset is, who owns it, and how rights transfer and are enforced) remain answered at Member-State level, even after MiCA harmonised the crypto-asset market. The recent Rome/UNIDROIT work weighed three ways around the ceiling: a sector-specific EU instrument on the Financial Collateral Directive model, soft law via the UNIDROIT Principles, and mutual recognition of national characterisations. None removes the ceiling. For issuers, the lesson is that the legal wrapper is the product. Get it right per jurisdiction, and the token works. Get it wrong, and no smart contract saves you.
Key Takeaways
- Article 345 TFEU reserves the system of property ownership to EU Member States, which is the structural reason a MiCA-style single rulebook for security tokens cannot exist.
- MiCA governs market conduct for crypto-assets, but it deliberately excludes financial instruments; the private law of who owns a security token and how it transfers stays national.
- The UNIDROIT Principles on Digital Assets and Private Law are soft law, drafted so a country can enact them as domestic law, not as directly binding EU rules.
- The "control" concept, borrowed from the Financial Collateral Directive, is the functional equivalent of possession and is the most promising bridge between blockchain settlement and national property law.
- The live decision that matters for issuers is the DLT Pilot Regime: ESMA reported to the Commission by 24 March 2026, and the regime may now be extended, amended, or made permanent.
The question every tokenisation project eventually hits
RWA tokenization has stopped being a pitch and become a number. On-chain, freely tradable RWA value, excluding stablecoins, reached approximately $33.5 billion as of early July 2026, according to RWA.xyz, up from roughly $11.8 to $14.1 billion a year earlier. The infrastructure exists. The demand exists. What still breaks projects is the law underneath the token, and in the EU that law has a hard ceiling. If you are structuring a digital securities offering across Member States, the ceiling is the first thing worth understanding, and it is where a compliance-first infrastructure partner like Stobox earns its keep.
Executives who followed the MiCA rollout tend to assume a parallel regime is coming for security tokens. It is not. MiCA handled crypto-assets that are not financial instruments. Security tokens are financial instruments, and financial instruments are property. Property is where EU competence stops.
This is not a gap waiting to be filled. It is a design feature of the Treaties. Understanding why changes how you build.
Why Article 345 TFEU sets the ceiling
Article 345 TFEU is short and absolute. "The Treaties shall in no way prejudice the rules in Member States governing the system of property ownership." In plain terms: the EU does not harmonise property law. It never has.
The provision, formerly Article 295 EC and before that Article 222 EEC, traces its origin to the Schuman Declaration and the founding coal-and-steel treaty. Its wording is settled; its scope is not. The Court of Justice treats Article 345 TFEU as an expression of the principle of the neutrality of the Treaties in relation to the rules in Member States governing the system of property ownership.
Two points sharpen what this means for tokenised securities.
First, neutrality is not immunity. Article 345 TFEU does not mean that rules governing the system of property ownership current in the Member States are not subject to the fundamental rules of the FEU Treaty, which include the prohibition of discrimination, freedom of establishment and the free movement of capital. A Member State cannot use its property law to escape the internal market's fundamental freedoms.
Second, the reservation is real where it counts. National law decides the core proprietary questions: is the token itself the asset or a claim on it, does registration on a ledger create a right good against third parties, and how does that right survive insolvency. The EU can regulate how these instruments trade. It cannot dictate what they are as a matter of ownership.
That division is why there is no MiCA for security tokens. MiCA could set common conduct rules. It could not, without breaching Article 345, tell Germany, France and Italy that a token confers the same property right in each.
Definition: what a security token actually is in EU law
A tokenised security is a financial instrument whose ownership and transfer are recorded on a distributed ledger, but whose proprietary characterisation (what right it confers, and against whom) is determined by the national property law of the relevant Member State, not by EU regulation.
That definition is the whole problem in one sentence. The token is uniform. The legal effect of holding it is not. Tokenised assets are expected to transform finance, yet their legal treatment remains a source of uncertainty; the analytical work in this area categorises legal structures based on the legal relationship between tokens and their underlying assets. In some structures the token embodies the right directly; in others it points to an asset held through an intermediary. Which one you have is a national-law question, and the answer can differ across the border.
The three routes around the ceiling, and why each stops short
The Rome/UNIDROIT work weighed three responses to the property-law reservation. Each is a genuine option. None dissolves Article 345. Here is how they compare.
| Route | Legal form | What it fixes | What it leaves national |
|---|---|---|---|
| Sector-specific EU instrument (FCD model) | Directive, functional and system-neutral | Perfection, enforceability, priority for a defined use | Underlying ownership characterisation |
| Soft law (UNIDROIT Principles) | Model rules a state enacts domestically | Common vocabulary, control concept, innocent-acquirer rule | Everything, until each state adopts it |
| Mutual recognition | Conflict-of-laws coordination | Which national law applies cross-border | The substance of every national law |
Route one: a sector-specific instrument on the Financial Collateral Directive model
The most concrete precedent is the Financial Collateral Directive. It works precisely because it does not try to harmonise property law. It defines legal effects functionally. The FCD introduced the concept of "control" into European law as a functional equivalent to the traditional legal term of "possession," in line with modern legal developments such as the Uniform Commercial Code and the UNCITRAL Legislative Guide on Secured Transactions.
Critically, the FCD is deliberately agnostic about the underlying property regime. It applies irrespective of the legal construction chosen by the parties as provided by national property law regimes, whether a limited right in rem or a transfer of full ownership; the decisive factor is solely the economic purpose of securing credit. That is the trick: regulate the function, leave the ownership doctrine to Member States.
A digital-securities instrument built on this model could give tokenised transfers cross-border legal certainty for a defined purpose without ever telling a Member State what ownership means. Recent academic work argues for exactly this, proposing a unified regime that would establish definitions that track economic function rather than national labels. The limit is visible in the design: it fixes perfection and enforceability for a slice of activity. It does not make ownership uniform.
Route two: soft law via the UNIDROIT Principles
The second route is the one already furthest advanced. UNIDROIT adopted its Principles on Digital Assets and Private Law in 2023. They are soft law by construction. The Principles were drafted as an instrument that could be enacted by a country as domestic law; thus, they could only include property rules capable of being adopted at national level.
The Principles do real work on the hardest questions. UNIDROIT steers clear of prescribing the conditions for a valid transfer, but it proposes that innocent acquirers who have "control" of a digital asset and meet certain requirements should take it free of proprietary claims. They also anchor insolvency protection. Principle 19 allows a person with a proprietary right in a digital asset to assert that right against a third party in an insolvency proceeding if that right has been made effective against third parties.
But the strength is also the ceiling. The Principles attempt to harmonise private-law fundamentals regarding digital assets across jurisdictions; adopted in May 2023, they serve as a guide for legislators, judges, arbitrators and parties. A guide is not a regulation. Until each Member State enacts them, they bind no one. Soft law respects Article 345 by leaving the choice to national parliaments, which is exactly why it cannot deliver a single EU answer on its own.
Route three: mutual recognition of national characterisations
The third route accepts fragmentation and manages it through conflict-of-laws rules: agree which Member State's law governs a given token, and recognise that characterisation elsewhere. This is the domain of the HCCH-UNIDROIT joint project, which is examining international law issues in the tokenised economy, in particular the law applicable to digital tokens in decentralised finance and the tokenisation of real-world objects.
Mutual recognition is honest about the ceiling: it does not pretend to remove it. It coordinates around twenty-seven substantive regimes rather than replacing them. That is useful for cross-border certainty. It is not harmonisation, and it should not be sold as such.
The control concept: possession, rebuilt for the ledger
Control is the functional equivalent of possession, and it is the single most important bridge between blockchain settlement and national property law. This is why the FCD model matters beyond collateral.
Possession is a physical idea. You cannot possess a book-entry security or a token the way you possess a bearer note. The FCD solved this by shifting to control. Control is usually obtained when the intermediary administering the asset undertakes to execute disposal instructions issued solely by the creditor. On a distributed ledger, control maps naturally onto who holds the private key or who can direct transfers.
The catch is that the EU never nailed the definition. The terms possession and control are not well defined in the FCD and have caused problems of legal interpretation within certain jurisdictions, including the UK. The Commission itself has recognised this. In February 2021, the Commission published a consultation on the functioning of the FCD, asking whether the concepts of "possession" and "control" are sufficiently clear or might need further clarification.
For tokenisation, this is the frontier. Get a clean, technology-neutral definition of control, and you have a functional handle on the proprietary question that Article 345 keeps national, without touching the ownership doctrine itself. It is the reason the FCD keeps reappearing in every serious proposal for a security-token instrument.
What actually governs your token today
The honest current answer: national law, plus one live EU pathway. The rights attached to a security token are governed by national law and are unevenly enforceable across the EU, with the DLT Pilot Regime as the main EU-level route for a functioning digital-securities market.
And the Pilot Regime is at a decision point right now. On 25 June 2025, ESMA published its report on the functioning and review of the DLT Pilot Regime, and under Article 14 of the Regulation ESMA was required to present a report to the Commission by 24 March 2026 covering the functioning of DLT market infrastructures, the number and value of instruments and transactions, costs and benefits, and a recommendation on whether to continue the regime. The next move sits with Brussels. The Commission is expected to present its own report to the European Parliament and Council within three months of receiving ESMA's report, which may cause the DLT pilot regime to be extended, amended or converted into a permanent regulation.
ESMA has been direct about the shortcomings. It is positive about the regime despite limited uptake, with only three authorised infrastructures and minimal live trading activity since it entered into force on 23 June 2022; the limited market interest has been a structural problem. Its fixes are pragmatic. The report recommends short-term measures such as tiered or adjustable thresholds tailored to each entity's risk profile, and long-term measures such as removing regulatory thresholds once an infrastructure reaches a set level of activity and establishing a pathway toward a permanent framework.
None of this repeals Article 345. It works within it: harmonised market-infrastructure rules sitting on top of national property law. That is the shape of everything the EU can realistically build here.
How to act on this
The property-law ceiling is not an obstacle to route around. It is the terrain you build on. What that means depends on who you are.
For the CEO or founder issuing tokenised securities. Treat the legal wrapper as the product, not the paperwork. Your token confers whatever right your chosen Member State's law says it confers, and no more. Decide the governing jurisdiction first, structure the instrument to that law, and only then design the token. This is where Stobox Compass, the tokenization infrastructure layer for compliant digital assets, is built around the reality that professional tokenization is asset structuring, legal framework and lifecycle management, not minting a token. Compass issues security tokens primarily on Base, with Arbitrum and Canton also supported.
For the asset owner. Your enforceability is only as strong as the weakest link in the national characterisation. Ask, before issuance: does registration on the ledger create a right good against third parties in this jurisdiction, and does it survive insolvency. If the answer is uncertain, fix the structure, not the marketing. Our EU tokenisation guide walks through the jurisdiction-by-jurisdiction questions that decide this.
For the investor. Read the wrapper before the whitepaper. Two tokens that look identical on-chain can carry different proprietary rights in different Member States. The DLT Pilot Regime status is your near-term signal for how much regulated infrastructure will exist to hold and trade these instruments. The broader three-stage framework for becoming an investment-ready, tokenisation-ready company sets out where legal preparation sits in the sequence: intelligence, then digital transformation, then legal structuring, then capital strategy, then tokenisation.
Stobox has structured and supported over $305M in assets across more than 100 clients in over 20 jurisdictions since 2018, and participated in the SEC Crypto Task Force roundtable on tokenised securities in 2025. That vantage produces one consistent finding: most tokenisation projects fail not on the blockchain but on what is underneath it. Article 345 TFEU is the reason that "underneath" is, and will remain, national.
For a deeper read on how this fracture runs through the whole market, see the companion essay The Tokenization Fault Line.
FAQ
What is Article 345 TFEU? Article 345 TFEU is a Treaty provision stating that the Treaties shall in no way prejudice the rules in Member States governing the system of property ownership. It reserves property law to national legislators. It is the structural reason the EU does not harmonise who owns what.
Why is there no MiCA for security tokens? Because MiCA governs crypto-assets that are not financial instruments, while security tokens are financial instruments, which are property. Article 345 TFEU reserves property law to Member States. The EU can harmonise how these instruments trade, but not what ownership they confer.
How does Article 345 TFEU affect tokenised securities specifically? It keeps the core proprietary questions national: whether the token is the asset or a claim on it, whether ledger registration creates a right good against third parties, and how that right survives insolvency. These answers can differ across Member States even for identical tokens.
What is the control concept and why does it matter? Control is the functional equivalent of possession, introduced by the Financial Collateral Directive because you cannot physically possess a book-entry security or a token. Control maps onto who can direct transfers, which on a ledger is who holds the key. It is the most promising bridge between blockchain settlement and national property law.
What are the UNIDROIT Principles on Digital Assets and Private Law? They are soft-law model rules adopted in 2023 to guide legislators, judges and parties on the private-law treatment of digital assets. They were drafted so a country can enact them as domestic law. They are not directly binding EU rules and take effect only as each state adopts them.
Can the EU pass a single instrument for tokenised securities? It can pass a sector-specific instrument on the Financial Collateral Directive model that harmonises functional legal effects like perfection and enforceability for a defined purpose. It cannot harmonise the underlying ownership characterisation without breaching Article 345 TFEU.
Why does the DLT Pilot Regime matter right now? Because its future is a live decision. ESMA reported to the Commission under Article 14 by 24 March 2026, and within three months the Commission must report to Parliament and Council, at which point the regime may be extended, amended or made permanent. That decision shapes the EU's main pathway for regulated digital-securities markets.
What should a company do before issuing a security token in the EU? Choose the governing Member State first, structure the instrument to that jurisdiction's property and securities law, then design the token to match. Confirm that ledger registration creates a third-party-effective right there and that it survives insolvency. The legal wrapper determines what the token is, so it must be built before the token, not after.
