ESMA's latest Risk Monitor and July statement say the treatment of event contracts in the EU turns on the contract and can involve financial-services, crypto-asset, or national gambling rules.

European Commission representation office with EU flags in Paris. Photo: Richardprins via Wikimedia Commons (CC0). Source
The European Securities and Markets Authority has used its latest risk report to put prediction markets, also called event-contract markets, alongside a July reminder on the EU rules that can apply to them. The two publications do not create a single new prediction-market regime or announce an action against a named operator. Instead, they describe a classification exercise with different possible results: an event contract can be a financial instrument, a crypto-asset arrangement within the scope of the Markets in Crypto-Assets Regulation, or a product governed by national gambling law. The result depends on the contract's characteristics and, in ESMA's July statement, on the question the contract asks. ESMA's September Risk Monitor and its 3 July public statement address the issue from different angles: the former is a risk assessment and market overview; the latter reminds firms of existing obligations.
That difference frames what ESMA has, and has not, said. The Risk Monitor is a twice-yearly publication intended to identify market developments and risks to investor protection, orderly markets, and financial stability, according to ESMA's description of the series. Its event-contract chapter makes observations about market growth, platforms' published geographic restrictions, retail-risk concerns, and technical and integrity risks. The July statement makes legal points about event contracts that qualify as financial instruments. Neither publication is presented as a decision imposing a penalty, an authorisation decision, or a public finding that a particular platform has breached a specific rule.
ESMA describes prediction markets as platforms on which participants trade contracts tied to future events. An event contract normally pays either a fixed amount or nothing, depending on whether the answer to a defined question is yes or no, the authority said in its July statement. The subjects can range widely. In the Risk Monitor, ESMA groups activity on Kalshi and Polymarket into categories including sports, politics, crypto-assets, weather, entertainment, finance, science and technology, media, and other subjects. The report's platform data put sports at 73% of identified Kalshi activity, while Polymarket's reported mix was led by politics at 29%, followed by sports at 19% and crypto-related markets at 15%.
The market has expanded quickly in the data ESMA reviewed, though the authority cautions that the available data mainly show global activity and cannot measure EU retail participation. Drawing on public Kalshi and Polymarket application-programming interfaces, ESMA reported quarterly volume of about $8.8 billion on Kalshi and $12 billion on Polymarket in the fourth quarter of 2025. The Kalshi data were current to 25 November 2025 and the Polymarket data to 31 January 2026, as stated in the report's chart notes. ESMA's Risk Monitor says the 2024 US presidential election coincided with a sharp increase in trading and that activity continued to grow into 2026.
ESMA also says prediction markets have drawn attention because of rising retail participation globally, a wider variety of questions, and links to crypto-assets, decentralised finance, artificial intelligence, and social-media ecosystems. Those are observations about the market's development, not a claim that each platform shares the same design or legal treatment. The report contrasts Polymarket, which it calls partially decentralised because trading and settlement occur on-chain while market governance and administration are centralised, with Kalshi, which it describes as fully centralised and regulated in the United States by the Commodity Futures Trading Commission as a designated contract market. The Risk Monitor identifies both among the major platforms but also names PredictIt, Robinhood, Pariflow, DraftKings, and FanDuel as operators active in the market and based outside the EU.
That global growth is context, rather than an answer to the EU legal question. ESMA says prediction markets do not appear to have gained significant traction in the EU compared with the US, while adding that its available data do not permit an assessment of EU retail participation. The report suggests that the EU regulatory approach, which it says significantly restricts the marketing and sale of event contracts, may help explain the difference. Its wording is conditional in the key respect: the applicable legal perimeter depends on the contract.
The first route is financial-services law. ESMA's July statement says that whether an event contract is a financial instrument depends on the event question. The Risk Monitor adds a more specific formulation: only event contracts whose question relates to an underlying listed in Section C(4) through C(10) of Annex I to the Markets in Financial Instruments Directive II, or MiFID II, qualify as financial instruments. The report therefore does not treat every contract that pays out on a future event as a MiFID II instrument.
When an event contract does qualify as a financial instrument, ESMA says it is a derivative. Because the payout is binary, the authority says it falls within existing national product-intervention measures on binary options. Those national measures prohibit the marketing, distribution, and sale of the relevant products to retail clients, according to ESMA's July statement. This is a legal consequence for contracts that meet the classification, rather than a blanket retail prohibition that ESMA says applies to every prediction-market contract.
ESMA's statement makes a second point about that financial-instrument route: distributing event contracts that qualify as financial instruments in the EU requires authorisation as an investment firm, including when they are distributed only to non-retail clients. The authority's public statement describes this as an existing obligation. It does not say that a US designation, an on-chain settlement mechanism, or the name used for a market settles the MiFID II classification. The relevant question remains what the particular contract is and what activity is being provided in the EU.
The Risk Monitor identifies a second possible route for a blockchain-based product. Where a contract is based on distributed-ledger technology and does not qualify as a financial instrument, it may fall within MiCA, ESMA says. The report does not say that every on-chain event contract is within MiCA, nor does it identify a particular MiCA authorisation held or not held by a named platform. MiCA itself excludes crypto-assets that qualify as financial instruments, preserving the existing financial-services framework for those products. The regulation's recitals set out that division.
The third route is national gambling law. An event contract may also qualify as a bet under a Member State's gambling legislation, ESMA said in the July statement. The Risk Monitor similarly says a contract can be treated as a gambling product under national law. That qualification is necessarily less uniform than a single EU-wide authorisation test because the relevant gambling legislation is national. The ESMA publications do not set out a Member State-by-Member State analysis, and they do not resolve how each jurisdiction would classify a particular contract.
Taken together, those routes mean that an event contract cannot be classified solely by calling it a prediction, a wager, a token, or a derivative. The public materials identify the characteristics of the contract, its event question, its technology, the service being provided, the client category, and potentially the Member State as relevant features. That is why the July statement is framed as a reminder that firms must assess whether newly offered products are within the binary-option measures, rather than as a finding about one standard product across the sector. ESMA's announcement explicitly says the statement responded to the growing popularity of prediction markets and retail participation globally.
The Risk Monitor says that marketing and selling event contracts in the EU generally requires EU authorisation and that the largest prediction-market platforms do not currently hold one. That sentence appears amid the report's description of the alternative MiFID II, MiCA, and national-gambling-law routes. Read in that context, it is an ESMA risk-report observation about the market and the relevant regimes, not a published enforcement decision or a list of final authorisation determinations for each platform and product.
The report does not name the legal entities behind "the largest" platforms in that sentence, identify the Member State or legal regime applicable to each contract, specify an application for authorisation, or cite a decision by a national competent authority denying one. It also does not say that every service offered by a platform has been determined to be unlawful in every Member State. Those unresolved points matter because the same report says legal treatment turns on a contract's characteristics, and because the July statement limits its binary-options analysis to contracts that qualify as financial instruments. The Risk Monitor and the statement support the legal framework and the report's general observation; they do not establish platform-specific enforcement outcomes.
ESMA does report a narrower, verifiable platform fact: Polymarket and Kalshi say on their own websites that users in some, though not all, EU countries cannot place orders. The authority says it is unclear why the lists do not include all Member States, given risks it identifies under MiFID II, MiCA, national gambling legislation, and the national binary-options measures. The Risk Monitor also says the platforms prohibit VPN use and may block users if it is detected.
ESMA does not present those geographic controls as a proven solution. Its report says a VPN can allow a user located in the EU to access prediction-market services and that the practical effectiveness of the platforms' restrictions remains uncertain. That is an observation about the limits of location controls, not evidence that every EU-based user has evaded one or that either named platform has knowingly served a particular person in breach of a rule. The authority's language preserves both limits.
Malta is the one Member State the report identifies as publicly exploring a dedicated framework. ESMA says the Maltese government described the sector in March 2026 as moving quickly globally and as offering room for innovation subject to an appropriate legislative framework. The Risk Monitor does not say Malta has adopted such a regime, nor does it treat that exploration as a replacement for the existing classification questions elsewhere in the EU.
The Risk Monitor devotes substantial space to risks that can arise in the design and operation of prediction markets. It says platforms can offer retail participants speculative gambling environments without the investor-protection measures ordinarily associated with regulated financial products when those platforms are not authorised in the EU. ESMA also points to gamified presentation, emotionally charged participation, and social-media promotion as factors that can expose inexperienced retail users to losses, addictive behaviour, and traders with informational or technological advantages. Those are the report's risk assessments, not findings that a named platform has caused those outcomes in a particular case.
Market integrity is another concern. ESMA says pseudonymous participation on distributed-ledger-based platforms can complicate detection and prevention of insider dealing, wash trading, and coordinated manipulation, particularly where participants can hold multiple accounts and a platform may have limited identity information. The report says the EU Market Abuse Regulation may help address such risks only when the contracts are within the financial regulatory perimeter. That condition is material: the report does not apply the market-abuse regime indiscriminately to all event contracts.
ESMA separately identifies the risk of resolving a contract after trading ends. Prediction markets depend on definitions of the event, the process for determining whether it occurred, and the quality of data used in that process, the report says. Ambiguous wording, compromised or failed data sources, opaque or discretionary resolution, and delayed or failed settlement can adversely affect participants. The Risk Monitor describes these as possible weaknesses of event-contract design and operation; it does not make a public determination that a particular market was resolved incorrectly.
The report also flags operational limits associated with decentralised settings. It says decentralised prediction markets without identifiable intermediaries or central governance can limit accountability and supervisory oversight. Smart-contract transactions are irreversible, including in a dispute, and the underlying code can contain errors or be manipulated, compromised, or unreliable, according to ESMA's analysis. That is an assessment of possible operational risk, not an assertion that any named smart contract has failed.
Finally, ESMA says AI-generated signals, algorithmic strategies, and automated bots may deepen information asymmetries, increase volatility, and make coordinated trading easier. The Risk Monitor cites outside analyses concerning the concentration of profits and user losses on Polymarket, but it presents those as evidence informing a broader risk discussion rather than as an enforcement case. Its concluding observations on the issue add that AI-generated misinformation, misleading viral content, and coordinated online campaigns may affect sentiment, prices, and perceived probabilities. The report does not identify a completed ESMA investigation, a sanction, or a final authorisation finding arising from those risks.