Disclaimers are explicitly worth nothing. There is exactly one measure the regulator recognises, and it is built, not written.MiCA and design, part two of two. Written with Serhii Barinov of SBLC.The previous issue ended on an uncomfortable note. A long list of ordinary growth decisions, domains, language versions, SEO targeting, affiliates, creators, educational content with a link back, all of it now reads to a European supervisor as evidence that a firm outside the EU is soliciting clients inside it.The question that follows is obvious. So what actually works.In most rooms the first answer is a banner. We will put a line on the homepage saying we do not serve EU residents, and a checkbox at signup confirming the user is not an EU resident. Everyone relaxes.That is the one answer the guidelines rule out by name.Facts over wordingThe ESMA guidelines say the assessment is factual, and that contractual provisions or disclaimers cannot override facts to the contrary.Read that against a real site. A banner saying the firm does not serve the EU, sitting on a site that has a Polish version, runs European retargeting and prices in euro, does not change what the site is doing. It only records that someone knew the rule existed.This is the part that tends to land badly with founders, because the disclaimer is cheap, fast and visible, and it feels like an action. It is the compliance equivalent of a cookie banner. Present, acknowledged, and not doing the work anyone thinks it is doing.The one thing that countsIn the whole document there is exactly one protective measure ESMA itself puts forward. A firm that may be seen as soliciting EU clients can avoid breaching the authorisation requirement by not onboarding new EU clients, or by geo-blocking access to its services.And it defines what a real geo-block is, in a footnote. Access to the website blocked for clients with an IP address originating in the EU, and the mobile app unavailable in EU app stores.Notice the shape of this. One recognised defence, and it lives in infrastructure and product configuration. Everything textual is expressly devalued. For a studio that means the deliverable is not a page of legal copy, it is a routing rule, a store distribution setting, and an onboarding gate.Where this becomes a branding problemThere is a second half to the guidelines that gets less attention, and it lands directly on the work I do.Many crypto groups run a structure where an EU-regulated entity sits at the front and a third-country firm does the rest. The guidelines address that directly. Providing crypto services after solicitation on behalf of a third-country firm by an entity regulated in the EU is still a breach of MiCA. An EU credit institution, investment firm or payment institution should not redirect clients, including through its website, to the crypto services of a third-country firm, and that applies within the same group.The annex adds a related circumstance: a group using strategies that do not sufficiently allow a client to distinguish between the offer of the EU-regulated entity and the third-country firm.That is a brand architecture requirement. Whether a user can tell which legal entity they are dealing with is decided by naming, by logo usage, by navigation, by which domain a button leads to, by whether the footer changes when the entity changes. None of that is copy. It is the part of the system a brand studio owns, and it is now being read as evidence.Two more things that shape productTwo smaller points, both with design consequences.The burden of proof sits with the firm. Firms have to be able to provide records tracking the client relationship, including whether it was the client who took the initiative regarding a new product. If the product does not capture that, the exemption is unprovable. That is an event logging requirement landing in a product backlog, not a legal filing, and it sits alongside every other product decision crypto teams already struggle with.And there is a clock. The exemption covers the transaction the client initiated, not the relationship that follows. The guidelines give a push notification two days after the initial transaction, listing trending assets, as an example of a breach, and a push two months later with a limited-time promotion as another. Anyone who has ever set up a lifecycle campaign will recognise exactly what has just been ruled out.I asked Serhii BarinovSerhii Barinov is a lawyer at SBLC, which works on software, blockchain and licensing. The answers below are translated from his own written analysis of the guidelines.Is a banner saying we do not serve EU residents worth anything?"The guidelines state directly that the assessment is factual, and contractual provisions or disclaimers cannot override facts to the contrary. A banner saying we do not serve EU residents has no independent meaning if the site in fact indicates otherwise, for example if it has a version in Polish. I would add one more signal that is not in the ESMA list but inevitably matters in this context: the use of the euro as a currency on the site."So what does ESMA actually accept?"ESMA itself names a measure it considers effective: not onboarding new clients from the EU, or geo-blocking the means of access. In a footnote it defines a real geo-block, access to the site is blocked for IP addresses originating in the EU, and the mobile application is not available in the app stores of EU countries. Note the symmetry. In the whole document there is exactly one defence that ESMA expressly recognises as workable, and it is technical and architectural. Disclaimers, on the contrary, are devalued."What about the common structure, an EU-licensed entity at the front and a global one behind it?"Providing crypto services after solicitation on behalf of a third-country firm by a person regulated in the EU is still a breach of MiCA. A credit institution, investment firm or payment institution from the EU must not redirect clients, including through its own website, to the crypto services of a third-country firm, and this applies where that firm belongs to the same group. This closes the most common workaround, a licensed European storefront with an unlicensed global back end."What does a firm have to be able to show if it is asked?"Firms must be able to provide records tracking the relationship with the client, in particular whether it was the client who took the initiative regarding a new product. The obligation to maintain the evidence base for its own position lies with the firm. No logs, no exemption."What I take from thisDesign cannot create legal protection here. That is the honest summary, and it is worth saying plainly to any client who arrives asking for a site that solves this.What design does decide is whether the real structure is legible. Which entity a person is dealing with, which service belongs to whom, where a button actually takes them, whether the product records how a relationship started. Those are naming, navigation, information architecture and product decisions, and they are being assessed.Crypto became a regulated field. What is regulated is not how the service looks but how it behaves, which means product, infrastructure and distribution decisions need a legal read at the design stage rather than after launch. This is brand strategy work before it is design work.SourcesThe legal analysis in this issue comes from Serhii Barinov, lawyer at SBLC, who works on licensing and compliance for software and blockchain companies. The quoted answers are translated from his written analysis and published with his approval.Primary sources: Regulation (EU) 2023/1114 (MiCA), articles 61 and 66. ESMA Guidelines on reverse solicitation under MiCA, ESMA35-1872330276-2030, 26 February 2025, in particular paragraphs 16, 22, 24, 25 to 28, and the annex. ESMA register of authorised CASPs.Earlier in this series: MiCA Is Forcing Crypto Brands to Grow Up, A Brand Is Never Finished, Your Hardest Reader Is Not a User, and MiCA Just Turned Crypto Website Design Into a Compliance Issue, which is part one of this pair.