ESMA Says Major Prediction Platforms Lack Required EU Authorization
ESMA said the marketing and sale of event contracts in the EU generally requires authorization and raised concerns about partial geographic restrictions, market integrity, contract resolution, data sources, and smart-contract execution.
The European Securities and Markets Authority said the marketing and sale of event contracts in the European Union generally requires EU authorization, which it said the largest prediction-market platforms do not hold. The regulator also questioned the geographic restrictions used by Polymarket and Kalshi, saying both restrict users in some EU countries but not all, and that users can bypass geographic blocks with virtual private networks. The assessment appears in ESMA's Risk Monitor report, as reported by The Block.
ESMA's position does not place every event contract in a single legal category. Its report says the applicable regime depends on a contract's characteristics. A contract may qualify as a financial instrument under MiFID II; a blockchain-based contract that is not a financial instrument may fall under the Markets in Crypto-Assets Regulation, or MiCA; and a contract may instead be treated as a gambling product under national law. That means the label "prediction market" does not settle its regulatory treatment in the EU, according to the report.
The regulator's conclusion on authorization follows that classification analysis. ESMA wrote that marketing and selling event contracts in the EU generally requires an EU authorization and said the largest platforms currently do not have one. The statement is about the conditions under which these products are offered in the EU. It is not a published finding in the report that every contract offered by every platform has the same legal status, or that a single rule applies to every member state in the same way.
The report arrives after ESMA issued a separate public statement in July on the application of national product-intervention measures on binary options to event contracts. In that statement, ESMA defined event contracts as products whose outcome is binary: a fixed payout or no payout, depending on the answer to a yes-or-no question about a future event. It said the question underlying the contract is relevant to whether it qualifies as a financial instrument, and that event contracts may also qualify as bets under national gambling legislation. The July statement therefore provides the narrower product description behind the broader risk-monitor discussion.
Classification comes before the rulebook
MiFID II, MiCA, and national gambling law are not interchangeable labels for the same product. ESMA's account is conditional: the regulatory regime depends on the contract's characteristics and, in the case of financial-instrument status, on the event question. The report does not say that a platform can determine its position solely by calling a product a prediction, a bet, a token, or an event contract. It directs attention to the actual product and the law that applies to it.
For contracts that qualify as financial instruments, ESMA said they would generally be classified as derivatives. That classification is important because the contracts have binary outcomes. Under the national product-intervention measures on binary options cited by ESMA, marketing, distribution, and sale to retail clients are prohibited. The regulator made the same point in its July public statement: where an event contract is a financial instrument, it is a derivative and falls within the existing national binary-option measures because of its binary outcome.
The retail restriction is not described by ESMA as a general ban on every discussion of an event or on every form of forecasting. It concerns the marketing, distribution, or sale of financial-instrument event contracts to retail clients under the national measures. The distinction matters because ESMA says event contracts exist across a wide variety of event questions, and because it does not presume a uniform legal classification for all of them. The source materials support a product-by-product inquiry, rather than a conclusion drawn only from a platform's name or technology.
ESMA also said in July that distributing event contracts that qualify as financial instruments in the EU requires authorization as an investment firm, even when the contracts are distributed only to non-retail clients. The subsequent Risk Monitor's broader statement that the marketing and sale of event contracts generally requires EU authorization sits alongside that earlier explanation. Neither document, as cited here, provides an authorization decision for an individual contract or a complete compliance assessment for a particular platform.
MiCA enters the analysis on a different condition. The Risk Monitor says blockchain-based contracts that do not qualify as financial instruments may fall under MiCA. This is not a conclusion that every contract recorded or traded using distributed-ledger technology is regulated by MiCA, and it is not a conclusion that using a blockchain takes a contract outside financial-markets rules. ESMA's formulation turns on whether the contract qualifies as a financial instrument.
National gambling legislation is the third route ESMA identifies. In its July statement, the regulator said event contracts may also qualify as bets under national gambling law. That reference keeps national law in the analysis rather than treating EU financial-services rules as the only possible framework. The report does not set out a member-state-by-member-state list of gambling-law outcomes, licenses, or enforcement actions. It says that national law may be relevant depending on the product.
This structure leaves a practical limit on broad claims about an entire market category. A statement that an event contract is onchain, trades through a prediction-market interface, or pays according to a future outcome does not by itself establish which regime applies. ESMA's published account identifies the possible routes and the conditions it considers relevant, but it does not publish a universal classification table for all existing contracts.
Retail binary-option measures
ESMA's July statement was a reminder to firms, not an announcement of a newly written EU-wide binary-option prohibition. It said firms must assess whether newly offered products fall within the scope of existing national product-intervention measures on binary options. The regulator tied the warning to the growing popularity of prediction markets, also called event contracts, and to increasing retail participation globally.
The existing measures are relevant where the event contract is a financial instrument. ESMA says those contracts are derivatives and, because their outcome is binary, are within the scope of national measures adopted by national competent authorities. The effect described by ESMA is a prohibition on marketing, distribution, and sale to retail clients. The source does not support treating that outcome as a judgment that all event contracts are financial instruments or that the same conclusion applies without examining the contract.
The distinction between retail and non-retail clients also should not be used to erase the authorization issue. ESMA's July statement says investment-firm authorization is required for the distribution in the EU of event contracts that qualify as financial instruments, including when they are distributed only to non-retail clients. The binary-option product-intervention measures and the authorization requirement address different parts of the regulator's account: one concerns retail marketing, distribution, and sale; the other concerns the authorization needed to distribute qualifying financial instruments.
The Risk Monitor's wording is broader because it also addresses contracts that may be governed by MiCA or national gambling law. It says the marketing and sale of event contracts in the EU generally requires EU authorization. The report does not identify a single authorization that covers every possible classification, and it does not say that a financial-services authorization is necessarily the relevant authorization for a contract treated under national gambling legislation. Its point is that the market category can trigger regulated activity under more than one legal route.
Partial geographic restrictions
ESMA specifically addressed Polymarket and Kalshi's country restrictions. The regulator said both platforms prohibit users in some EU countries from placing orders, but not in all EU countries. It questioned why the restricted-jurisdiction lists do not cover every EU member state, according to The Block's report on the Risk Monitor.
The report also says geographic restrictions do not prevent users from reaching the platforms through VPNs. ESMA's point is about the limits of location-based access controls as described in the report. It does not state that every user of either platform is in the EU, that every attempted VPN connection succeeds, or that either platform has no compliance controls beyond the geographic restrictions discussed. The stated concern is that a location block can be circumvented.
That concern bears on access, not on an automatic classification of every contract. A country restriction can affect who is able to place an order through a service, while ESMA's legal analysis asks what the contract is and which regulatory regime follows from its characteristics. The report treats those as related questions: the nature of the product can determine the relevant rules, and partial country restrictions may not prevent access from jurisdictions where those rules apply.
ESMA's reference to some, rather than all, EU countries is also narrow. The report does not publish the full list of countries restricted by each platform in the cited passage, specify when each restriction was introduced, or attribute a reason for every country included or excluded. The regulator instead raises the question of why the restrictions do not cover all member states. No additional country-by-country conclusion should be read into that observation.
Market-integrity risks
ESMA also raised market-integrity concerns about prediction markets. The Risk Monitor highlighted insider trading and market manipulation risks, particularly on distributed-ledger-technology-based platforms such as Polymarket. According to The Block's account of the report, ESMA said limited identity verification and pseudonymous participation can make suspicious activity harder to detect.
The report identifies a difficulty in detecting suspicious activity; it does not establish that a specific trader committed insider trading or market manipulation. It also does not convert pseudonymous participation into proof of misconduct. The risk identified by ESMA concerns supervision and detection where the people behind activity may be harder to identify and where identity checks are limited.
ESMA described platform measures aimed at suspicious trading as largely reactive, The Block reported. The point is not that such measures do nothing. It is that, in the regulator's assessment, they respond after suspicious activity has become an issue rather than supplying the same form of preventative oversight the report considers necessary. The report's concern is framed as a market-integrity risk, not a finding that a named platform has failed a specified legal test.
The integrity question is especially direct for contracts tied to events where some participants may know relevant facts before those facts are broadly public. ESMA does not need to identify a particular event contract for the risk to arise in its analysis. A market whose price changes as traders buy and sell claims about an outcome can be affected when a participant acts on information others do not have. The report's stated focus is on how limited identity verification and pseudonymous participation can complicate the detection of that activity.
The report also flags risks around contract resolution, data sources, and smart-contract execution. Those are distinct concerns. Resolution concerns the process of determining whether the contract's stated outcome has occurred. Data-source concerns address the information used for that determination. Smart-contract-execution concerns address the code-driven process through which a contract is carried out. ESMA lists all three as areas of risk; it does not, in the cited reporting, provide a detailed technical assessment of a particular contract's resolution rules, data feed, or code.
These risks are connected without being identical. A clear event question does not by itself disclose how a platform will settle a disputed outcome. A named data source does not by itself answer whether the source will be available or how conflicting information will be handled. A smart contract can set out execution logic without resolving every question about the information supplied to it or the outcome that should trigger payment. ESMA's report identifies the categories of exposure, while the available report does not set out a platform-specific control framework for each one.
What ESMA did and did not conclude
ESMA's account is a warning about existing regulatory obligations and identified risks, rather than a claim that all prediction markets are legally identical. The regulator says event contracts can be financial instruments under MiFID II, may fall under MiCA when blockchain-based and not financial instruments, or may be treated as gambling products under national law. Where the contracts are financial instruments, ESMA says they are generally derivatives and the national binary-option measures prohibit their retail marketing, distribution, and sale.
The authorization conclusion is equally qualified but direct. ESMA said the marketing and sale of event contracts in the EU generally requires authorization, which the largest platforms currently do not hold. That statement does not identify an authorization held by a particular firm, adjudicate every contract offered by Polymarket or Kalshi, or publish a final enforcement action. It describes the regulator's position on the requirements that generally apply to the products and activity it examined.
For the two named platforms, the report records partial country restrictions and the possibility of VPN circumvention. It does not say that geographic restrictions resolve the EU authorization question. For market operations, ESMA identifies risks involving suspicious trading, contract resolution, data sources, and smart-contract execution. The report does not attach a public finding of misconduct to a particular user or platform in the cited discussion. Its confirmed message is that classification, authorization, access controls, and market-integrity safeguards all remain live issues for event-contract offerings in the EU.