CASP: how to obtain a MiFID license?

Keywords. CASP, MiFID II, investment services provider, tokenized financial instruments.

Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA) established a harmonized European framework applicable to crypto-asset service providers (CASPs). That framework does not, however, cover all crypto-assets: where a crypto-asset qualifies as a financial instrument, it is excluded from MiCA’s scope and falls in particular under Directive 2014/65/EU (MiFID II) (MiCA, art. 2(4)(a)).

For a CASP, this boundary may be strategic. Obtaining a MiFID authorization may make it possible to broaden its offering to activities that go beyond MiCA’s scope alone.

It should be emphasized, however, that while MiCA provides certain already authorized financial entities with a notification procedure allowing them to provide certain crypto-asset services (MiCA, art. 60), no equivalent mechanism is provided for a CASP wishing to obtain a MiFID II authorization. It must follow the ordinary authorization procedure applicable in France.

Why might a CASP have an interest in obtaining a MiFID license?

The use of blockchain technology does not, in itself, determine the regulatory regime applicable to an asset. In its guidelines of March 19, 2025 on the qualification of crypto-assets as financial instruments, ESMA recalls the principle of technological neutrality: the tokenization of a financial instrument does not affect its legal qualification.

A share, a bond or a unit in a collective investment undertaking (CIU) therefore does not cease to be a financial instrument because it is issued or represented in the form of a token. A CASP wishing to offer its clients tokenized shares or bonds must therefore determine whether the envisaged services fall under MiFID II.

The same reasoning applies to derivatives. The qualification of the derivative is distinct from that of its underlying: a crypto-asset falling under MiCA may thus serve as the underlying of a derivative instrument falling under MiFID II. Certain futures, options, swaps or perpetual contracts on crypto-assets may thus require a MiFID authorization, irrespective of the regime applicable to the underlying crypto-asset.

For a CASP, the interest is therefore very concrete: offering tokenized shares or bonds, or certain derivatives on crypto-assets, may bring all or part of the activity within the scope of MiFID II. Depending on the services actually provided, the player will then have to hold the corresponding authorizations.

What does a MiFID authorization application contain?

In France, the MiFID II license corresponds, for the players concerned, to the authorization as an investment firm, which confers the status of investment services provider (PSI) for the authorized services.

This authorization is granted by the Autorité de contrôle prudentiel et de résolution (ACPR), after approval of the programme of operations by the Autorité des marchés financiers (AMF) (CMF, art. L. 532-1 and L. 532-4).

The authorization application must in particular set out the shareholding structure, the governance, the senior managers and key function holders, the resources devoted to the project and the organization planned for carrying out the investment services applied for (CMF, art. L. 532-2).

Particular attention must be paid to the programme of operations, which must cover each of the investment services for which authorization is sought. It describes the activities envisaged, their organization and the manner in which they will be provided. Its content and the arrangements for its review by the AMF are set out in AMF instruction DOC-2014-01.

In practice, the application must therefore consistently reflect the product offered, the clients targeted, the services applied for and the organization put in place to provide them.

How does the MiFID authorization procedure work?

Once the file has been assembled, the authorization procedure can be summarized in several steps.

  • Filing of the application – Completeness check.

The authorization application is submitted to the ACPR (CMF, art. R. 532-1). The ACPR verifies that the file contains the required information and requests any missing items where applicable.

  • Complete file – Review of the programme of operations by the AMF.

Where the file is complete, the ACPR forwards it to the AMF within five business days. The AMF then has three months to decide on the approval of the programme of operations (CMF, art. R. 532-3; AMF instruction DOC-2014-01).

  • Review – Exchanges with the authorities.

The review is not limited to the examination of the documents initially filed. The ACPR, on its own initiative or at the AMF’s request, may seek the additional information necessary to analyze the file (CMF, art. R. 532-3). These exchanges may relate in particular to the business model, the organization or the arrangements presented.

  • Decision on the authorization.

The ACPR decides on the application within a maximum period of six months from receipt of a complete file (CMF, art. R. 532-3).

That period does not, however, correspond to the total duration of an authorization project. The preparation of the file, which may itself take several months, as well as the exchanges needed to reach completeness must also be anticipated.

In practice, an overall timeline of around nine to twelve months can reasonably be envisaged to obtain a MiFID II authorization, depending in particular on the maturity of the project, the quality of the initial file and the exchanges with the authorities in the course of its review.

Thus, for certain crypto players, this second regulatory building block may nevertheless open up very concrete prospects: offering tokenized financial instruments, developing derivatives on crypto-assets or, more broadly, building an offering at the boundary between traditional finance and crypto. The interaction between MiCA and MiFID II may therefore be worth anticipating as early as the structuring of the project.


The information contained in this article is provided for general information purposes only and does not constitute legal advice. It does not purport to be exhaustive and must be assessed in the light of the circumstances specific to each situation, in particular the business model, the services envisaged and the applicable regulatory framework. It is recommended to seek appropriate legal advice before taking any decision based on the elements presented in this article.

MiCA license in 40 days: who can benefit from the Article 60 fast-track procedure?

Keywords. MiCA, CASP, MiCA Article 60, MiCA fast-track procedure, CASP notification.

Since December 30, 2024, the provision of crypto-asset services in the European Union requires authorization as a crypto-asset service provider (CASP) under Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA).

For certain already regulated financial players, Article 60 of MiCA nevertheless provides for a faster route: certain crypto-asset services may be provided upon completion of a notification procedure, in principle 40 working days after it is filed, without going through the full CASP authorization procedure.

Strictly speaking, this is therefore not a “fast-track MiCA license”, but a mechanism that relies on an existing financial authorization.

Are you eligible for the MiCA fast-track procedure?

    The Article 60 procedure is not open to all regulated undertakings.

    Only six categories of entities are eligible:

    • credit institutions, for all crypto-asset services;
    • central securities depositories, solely for the custody and administration of crypto-assets;
    • investment firms, for services equivalent to those covered by their MiFID II authorization;
    • electronic money institutions, solely for the custody and administration, as well as the transfer, of electronic money tokens (EMTs) that they issue;
    • market operators, for the operation of a trading platform;
    • UCITS management companies and authorized AIFMs, for portfolio management, investment advice, and the reception and transmission of orders.

    A payment institution that holds none of the statuses referred to in Article 60 will therefore have to follow the ordinary CASP authorization procedure.

    What must be prepared for an Article 60 notification?

    The procedure is streamlined, but an Article 60 notification remains a substantial regulatory filing.

    The entity must demonstrate that it is ready to provide the envisaged services and has an appropriate organization. The notification includes, in particular, a programme of operations, information relating to internal control and AML/CFT, a business continuity plan and information on IT systems and their security (MiCA, art. 60(7)).

    Additional documents are required depending on the services concerned. For example, a custody service entails documenting the custody policy and the segregation of clients’ crypto-assets, while an order execution service implies an execution policy.

    Commission Delegated Regulation (EU) 2025/303 specifies the level of detail expected, in particular regarding the program of operations for the three years following the notification, the categories of clients targeted, the jurisdictions targeted, and the human, financial, and IT resources allocated to the project.

    The challenge is therefore to prepare upstream a file sufficiently advanced to be considered complete as soon as it is filed. Information already provided to the competent authority does not, however, have to be resubmitted where it is identical and still up to date (MiCA, art. 60(9)).

    Can crypto services really be launched in 40 days?

    Compliance with this timeline depends directly on the completeness of the file.

    • Day 0 – Filing of the notification.

    It must be sent to the competent authority at least 40 working days before the first provision of the services concerned (MiCA, art. 60(1) to (6)).

    In France, it is filed with the ACPR for credit institutions, investment firms and electronic money institutions, and with the AMF for central securities depositories, market operators and management companies falling within its remit (CMF, art. L. 54-10-7, II and III).

    The competent authority verifies that the required information has been provided.

    • If the file is incomplete – Suspension of the time limit.

    The competent authority requests the missing information and sets a deadline that may not exceed 20 working days. The 40-working-day period is suspended until the expiry of that deadline. Any subsequent requests for additional information or clarification do not further suspend that period, but the services may not commence for as long as the notification remains incomplete (MiCA, Article 60(8)).

    • On expiry of the time limit – Launch.

    Unlike the standard CASP authorization, MiCA does not provide for a formal decision granting a new authorization at the end of the notification. Once the notification is complete and the applicable time limit has expired, the entity may begin providing the notified services.

    However, the right to provide the notified services ceases upon withdrawal of the authorization on which that right is based (MiCA, Article 60(11)).

    An advantageous mechanism within a precisely defined framework

    Article 60 offers a twofold advantage: it speeds up market access and avoids certain requirements specific to the ordinary CASP authorization.

    Beyond its value for players that are already eligible, Article 60 may constitute a genuine regulatory structuring lever for a crypto project.

    Depending on the business model and the services envisaged, various strategies may be considered: using an existing regulated entity within a group, having certain services carried by an eligible regulated partner, acquiring an entity that holds the relevant authorizations or, where this is more consistent with the project as a whole, obtaining a financial authorization that then allows the Article 60 procedure to be used.

    The question is therefore not necessarily whether to choose between a “CASP authorization” and an “Article 60 notification” once the project has been built. The existence of this procedure can be factored in from the outset when choosing the regulatory structure and the entity called upon to carry the crypto activities.

    For certain players, in particular those whose model sits at the intersection of traditional financial services and crypto-assets, Article 60 thus opens up several possible routes to access the European market, the relevance of which will depend on the intended scope of activities, the timeline and the overall regulatory strategy.

    The information contained in this article is provided for general information purposes only and does not constitute legal advice. It does not purport to be exhaustive and must be assessed in the light of the circumstances specific to each situation, in particular the business model, the services envisaged and the applicable regulatory framework. It is recommended to seek appropriate legal advice before taking any decision based on the elements presented in this article.

    Crypto-asset advice: what the AMF’s new guidance changes for Financial Investment Advisors (CIF) ?

    Keywords: CIF, crypto-asset advice, MiCA, CASP, AMF DOC-2006-23

    More and more clients are asking their adviser whether they should invest in crypto-assets. Until recently, a Financial Investment Adviser (Conseiller en investissements financiers – CIF) could, in certain cases, provide guidance in this area with relative flexibility. That is no longer the case.

    On 27 July 2026, the French Financial Markets Authority (Autorité des marchés financiers – AMF) updated its position-recommendation DOC-2006-23 (the document setting out its answers to recurring questions on the CIF regime) to clarify the scope of crypto-asset advice.

    This update comes as the MiCA Regulation, which harmonizes the regulation of crypto-assets at the European level, is now fully applicable, and as the transitional period available to former Digital Asset Service Providers (DASP) ended on 1 July 2026.

    From now on, as soon as a CIF crosses the line into personalized crypto-asset advice, it must hold authorization as a Crypto-Asset Service Provider (CASP). The question of exactly where that line falls is precisely what the AMF’s new guidance addresses.

    A CIF status that does not cover crypto-assets

    CIF status, governed by Articles L. 541-1 et seq. of the French Monetary and Financial Code (Code monétaire et financier – CMF), authorizes its holder to provide an investment advisory service. This service consists of giving a client a personalized recommendation (that is, advice presented as suited to the client’s situation) concerning one or more transactions relating to financial instruments (Article D. 321-1, 5° of the same Code).

    The concept of a financial instrument is decisive here: it covers, in particular, shares, bonds and units in collective investment undertakings (OPC), but not crypto-assets. The AMF expressly confirms this in its new question-and-answer 2.5 of DOC-2006-23: a CIF’s advisory service covers neither crypto-assets nor services relating to them.

    In practice, however, this limit was more a matter of principle than of actual practice, since DASP status offered another route. The DASP regime (Digital Asset Service Provider, corresponding to the former French PSAN status) was the French framework that regulated these players before MiCA, at a time when the term used was “digital assets” rather than “crypto-assets.” In its 2022 guidance, the AMF distinguished between two situations:

    • where the CIF was itself approved as a DASP for advising subscribers of digital assets, it carried out that activity under the rules specific to that service;

    • otherwise, that advice fell under the “other wealth management advisory activities” that a CIF may carry out, and was then subject only to the organizational and conduct-of-business rules of the CIF regime.

    In both cases, the CIF could, in practice, advise its clients on digital assets.

    This arrangement, however, rested on a temporary regime. DASPs registered or authorized in France before 30 December 2024, or providing advisory services to subscribers of digital assets before that date, could continue their activity until a MiCA authorization was granted or refused, and at the latest until 1 July 2026.

    That deadline having now passed, the benchmarks set in 2022 are obsolete.

    Crypto-asset advice now falls solely under the CASP regime established by MiCA. In other words, what was permitted yesterday under DASP status or under wealth management activities is no longer permitted today on that basis alone.

    A broader scope of advice under MiCA

    The difficulty lies not only in the authorization requirement: it also lies in MiCA’s very definition of advice, which is broader than it first appears.

    Under Article 3(1)(24) of the MiCA Regulation, the provision of crypto-asset advice means offering, giving, or agreeing to give personalized recommendations to a client, whether at the client’s request or on the CASP’s own initiative, concerning one or more transactions relating to crypto-assets or the use of crypto-asset services.

    This definition goes beyond investment advice as defined under MiFID II, which is limited to transactions in financial instruments: it also covers advice on the use of crypto-asset services, such as custody or portfolio management. The European Securities and Markets Authority (ESMA) confirmed this in its question-and-answer of 18 June 2026 (ESMA_QA_2882): a mere introductory service that recommends a service or a CASP without targeting a specific transaction may already constitute advice, provided the recommendation is personalized, is not addressed exclusively to the public, and is directed at an investor or the investor’s representative. The only exception is a simple reference to a CASP that is accessible in the same way to all potential investors.

    In this context, the AMF warns of a risk specific to CIFs that direct their clients toward a CASP. The very fact of being a CIF may lead the client to believe that this referral stems from a personalized recommendation based on a review of the client’s situation, particularly where the adviser has already gathered information about the client’s assets in connection with an investment advisory service. The risk is then one of reclassification as crypto-asset advice, an activity for which the CIF is not authorized.

    Clarification the profession had been waiting for

    The entry into application of MiCA and the obsolescence of the 2022 benchmarks left CIFs without up-to-date guidance, at a time when the scope of crypto-asset advice, broader than that of investment advice, creates a risk of reclassification in the event of poorly controlled communications.

    By adding a new question-and-answer to DOC-2006-23, which relays ESMA’s position and illustrates it with non-exhaustive examples, the AMF addresses this need for legal certainty and identifies certain situations in which CASP authorization is, or is not, required.

    What the AMF’s position actually changes

    To draw this line, the AMF reasons on the basis of a simple distinction between two categories of communications.

    General communications fall outside the scope of crypto-asset advice. This is the case for educational information, marketing communications addressed to an undifferentiated public, or directing a client to the AMF’s published whitelist of authorized CASPs. Their common feature is that they do not target any particular person.

    Individual communications, addressed to a specific client, call for greater caution. They remain permitted, but subject to two conditions: no personalized recommendation may be made, and the CIF must inform the client that it is not authorized to recommend crypto-assets, while referring the client to the AMF’s whitelist. Subject to this reservation, the following are notably permitted:

    • simply informing a prospect, whether for payment or free of charge, of the existence of a CASP, before any wealth review or collection of information on the prospect’s personal situation;
    • simply informing a client, whether for payment or free of charge, of the existence of a CASP belonging to the same group as the CIF, provided the client is duly and clearly informed of the nature of that relationship;
    • a diversified asset allocation that may include crypto-assets, without any recommendation concerning a specific crypto-asset or a specific service;
    • recommendations relating directly to financial instruments, even where those instruments are backed by crypto-assets (AIFs exposed to crypto-assets, index-linked debt securities), which then fall under investment advice covered by CIF status.

    The options available to CIFs

    To go beyond these regulated communications and deliver an actual personalized recommendation on crypto-assets or crypto-asset services, only one option remains: obtaining a CASP authorization.

    Unlike investment services providers (Prestataire de services d’investissement – PSI), CIFs cannot obtain this through simple notification; they must file an authorization application and would be well advised to approach the AMF beforehand.

    The requirement is, however, calibrated: the AMF specifies that authorization limited to the advisory service alone carries proportionate requirements, substantially less extensive than those attached to an application also covering, for example, the custody and administration of crypto-assets on behalf of clients.

    Conclusion

    The AMF’s position does not change the applicable law: it clarifies its implementation, now that the transitional period has ended. The point requiring vigilance is clear: absent CASP authorization, only a general communication, or an individual communication accompanied by the required clarifications, protects the CIF from reclassification. The dividing line between permitted communication and advice subject to authorization nonetheless remains a fine one and must be assessed on a case-by-case basis.

    CIFs whose activity is moving toward recurring support on crypto-assets therefore have an interest in assessing, as of now, the merits of obtaining CASP authorization limited to the advisory service, the formalities for which remain proportionate.

    AI Act: New Obligations for Employers as of 2 August 2026

    In this article, Allison BENICHOU CORCHIA analyses the new obligations imposed on employers by Regulation (EU) 2024/1689 of 13 June 2024 on Artificial Intelligence (the “AI Act”). Although the deadline of 2 August 2026, initially set for the compliance of high-risk AI systems, has been postponed to 2 December 2027 under the “Digital Omnibus” package — the formal adoption of which by the Council is still pending — the date of 2 August 2026 nevertheless remains decisive.

    Keywords. Artificial Intelligence, AI Act, AI systems, penalties.

    Introduction

    In this article, Allison BENICHOU CORCHIA, Partner in the Employment Law department of the law firm d&a partners, highlights some of the new obligations placed on companies following the adoption of the first European legal framework dedicated to AI.

    AI is now embedded in many tools used in the workplace: automated recruitment, performance evaluation, data analysis and monitoring of employees’ activity. While these technologies can greatly increase productivity and deliver considerable time savings, they also raise major legal issues, particularly with regard to the protection of fundamental rights.

    To address these new challenges, on 13 March 2024 the Members of the European Parliament adopted Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonized rules on artificial intelligence (hereinafter the “AI Act”), thereby establishing the first harmonized legal framework on AI within the EUROPEAN UNION.

    The AI Act, which entered into force on 1 August 2024, pursues a central objective: to improve “the functioning of the internal market and promote the uptake of human-centric and trustworthy artificial intelligence”. Its application is gradual: phased in since 2025, it will continue until 2027, and even 2028 for certain high-risk systems.

    This text marks an important milestone: it now imposes new — and sometimes little-known — obligations on companies whenever they use AI systems within their organization.

    Pursuant to Article 3 of the Regulation, its rules apply to “any natural or legal person, public authority, agency or other body using an AI system under its authority”. The European Regulation on AI imposes several specific obligations on employers in their capacity as deployers of AI systems.

    Employers, as deployers of AI systems, are thus subject to several specific obligations, in particular where they use these technologies in the context of recruitment, performance evaluation, decision-making concerning employees or the monitoring of employees’ activity.

    This article will successively address the classification of AI systems adopted by the Regulation (I) and the obligations it imposes on employers (II), before considering the risks in the event of non-compliance (III).

    I/ A Risk-Based Approach: Classification of AI Systems

    The European Regulation is based on a graduated approach: the more the use of an AI system is likely to affect fundamental rights, the more demanding the resulting obligations.

    The AI Act thus distinguishes four levels of risk, each entailing specific requirements for employers, which should not be overlooked and should be anticipated as of now.

    1/ Prohibited AI Systems

    Since 2 February 2025, practices deemed unacceptable by the AI Act have been prohibited. Eight practices are thus banned, including social scoring systems and emotion recognition in the workplace (except for medical or safety reasons).

    2/ High-Risk AI Systems

    These include, in particular, employee evaluation tools, automated recruitment systems, algorithmic work management systems, and systems likely to affect an employee’s career or employment contract.

    3/ Limited-Risk AI Systems

    These are subject to transparency obligations, owing to the risks of manipulation or deception they present. They include chatbots, AI-generated content and deepfakes: users must be informed that they are interacting with an AI or that content has been artificially generated.

    4/ Minimal-Risk AI Systems

    Most AI systems fall into this category, such as recommendation systems, spam filters or video games. They are not subject to any specific obligation under the Regulation.

    II/ Enhanced Obligations for Employers

    Beyond the classification of systems, the AI Act imposes on employers a set of cross-cutting obligations, some of which are already applicable.

    The first obligation, in force since 2 February 2025, consists of ensuring a sufficient level of AI literacy. Article 4 of the Regulation on Artificial Intelligence, entitled “AI literacy”, thus establishes a general training obligation for providers and deployers of AI systems. As a result, companies are required to train users in the AI tools deployed within their organization.

    The text provides that “Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used”.

    The objective is to ensure that everyone involved with AI systems within the company has the skills and knowledge required to make informed decisions and use these systems responsibly.

    The AI Act lays down new obligations for employers, depending on the risk level of the AI system.

    Limited-risk systems must comply with a principle of transparency and a principle of information, which consists in particular of notifying users that they are interacting with an AI and providing users with clear information about AI-generated content.

    The following have been classified as high-risk systems under the AI Act: automated recruitment tools, employee evaluation or scoring systems, algorithmic work management tools, and decision-making tools affecting an employee’s career or employment contract. Consequently, these systems will have to meet strict requirements. Initially set for 2 August 2026, the entry into application of these obligations is in the process of being postponed to 2 December 2027 under the “Digital Omnibus” package, the formal adoption of which by the Council is still pending to date.

    These systems will have to be subject to effective human oversight: designed by the provider to enable human control (Article 14 of the Regulation), they will have to be overseen, on the employer’s side, by people who have the necessary competence, training and authority (Article 26 of the Regulation). This requirement operates alongside Article 22 of the GDPR, which already governs fully automated decisions producing legal effects with regard to employees.

    Article 26 of the Regulation further requires the employer-deployer to inform workers and their representatives before putting a high-risk AI system into service in the workplace (paragraph 7), as well as the persons subject to a decision involving such a system (paragraph 11).

    These requirements are accompanied by obligations relating to the traceability of the system’s operation and of the data used, documentation, and the provision of information to employees and their representatives.

    III/ Risks in the Event of Non-Compliance with the AI Act

    The AI Act does not merely establish a theoretical framework. It also provides for particularly significant financial penalties in the event of non-compliance with the obligations it lays under.

    Companies and other economic operators that develop, market or use prohibited AI systems are exposed to particularly severe financial penalties.

    The AI Act provides for administrative fines of up to EUR 35 million or where the offender is a company, up to 7% of its total worldwide annual turnover, whichever is higher.

    Non-compliance with the other obligations established by the Regulation is also subject to substantial financial penalties: Article 99 of the Regulation provides for a fine of up to EUR 15 million or, for a company, up to 3% of total worldwide annual turnover, whichever is again higher.

    For SMEs and start-ups, however — and this is good news — it is the lower of the two amounts that applies.

    In light of these new requirements introduced by the AI Act, companies must therefore adopt a resolutely proactive approach in order to secure their practices.

    The first step is to carry out a precise audit of the tools in use, in order to identify the AI systems, present within the company and to assess the scope of the resulting obligations.

    It is then up to employers to assess the risks associated with their use, in light of the classification adopted by the Regulation and the potential impact on employees’ rights.

    When labor law meets criminal law

    Abstract. Through an analysis of the main offenses under the Labor Code and the Criminal Code, Allison BENICHOU CORCHIA highlights situations in which an employer’s violations go beyond the scope of labor law to give rise to criminal liability. Occupational health and safety, illegal employment, offense of obstruction, and workplace harassment: these are all behaviors that may expose the company, its executives, or its agents to severe criminal penalties, within a constantly evolving legal landscape.

    Keywords. Employer’s criminal liability, criminal labor law, workplace safety, illegal employment, workplace harassment.

    Introduction

    The Court of Cassation recently reaffirmed its new interpretation of the non bis in idem principle, which prohibits convicting a person twice for the same acts. It notes that it is possible to prosecute, concurrently for identical acts, offenses under the Labor Code and those under the Criminal Code when they occur concurrently (Court of Cassation, Criminal Division, January 23, 2024, No. 23-81.091), such that concurrent prosecution is permitted unless (1) the characterization of the elements constituting one of the offenses precludes that of the other, (2) one of the classifications corresponds to an element or an aggravating circumstance of the other, or (3) one of the classifications, known as a special classification, criminalizes a specific form of the reprehensible act already punishable under the general offense.

    In this article, Allison BENICHOU CORCHIA, Partner in the labor law department at d&a partners, highlights situations in which an employer’s practices may go beyond the scope of labor law and fall within the realm of criminal offenses.

    The article will address, in turn, offenses related to occupational health and safety (I), illegal employment (II), the offense of obstruction (III), as well as recent developments in case law regarding harassment (IV).

    I/ Occupational health and safety: when criminal law comes into play

    The violations set forth in the Labor Code in this area are primarily intended to be preventive, but they can result in criminal liability for the employer, even in the absence of an accident.

    Article L.4741-1 of the Labor Code establishes a general liability and provides for a civil fine of €10,000.

    This includes, in particular, obligations regarding the provision of information and training to workers, as well as obligations related to protective equipment and measures.

    When the violation involves the life or physical integrity of an employee, the Criminal Code applies: the main offenses are involuntary manslaughter, involuntary assault, and endangering the life of another person.

    Article 221-6 punishes causing the death of another person “through clumsiness, imprudence, inattention, or negligence” with up to 3 years’ imprisonment and a fine of €45,000. The penalty is increased in cases of “a manifestly deliberate violation of a specific duty of care or safety imposed by law or regulation”.  

    Recent events tragically illustrate these issues. On July 26, 2023, a young worker died while cleaning a machine that had been shut down, which then restarted. A few months earlier, another employee had been the victim of the same accident on the same machine.

    The company was found guilty of involuntary manslaughter as a legal entity and fined €225,000, with the requirement to display the judgment for 2 months (fines for legal entities can indeed be up to five times higher than those imposed on individuals).

    These tragedies serve as a reminder that safety violations are never merely theoretical. According to the National Health Insurance, 810 people died on the job in 2023. The 2024 report from the Labor Inspectorate highlights that in 55% of companies inspected following a workplace accident, risks are not reassessed or are poorly reassessed, and that in half of all cases, no action is taken.

    II/ llegal Employment: a criminal risk that is often underestimated

    Article L.8211-1 of the Labor Code lists 6 forms of illegal employment, including undeclared work and the employment of a foreign national without a work permit.

    Hidden employment through the concealment of salaried employment occurs when an employer intentionally evades certain legal obligations, particularly by failing to report wages and social security contributions to the relevant authorities (Article L.8221‑5).

    Many employers underestimate the risks associated with failing to report overtime, which must, however, be included on the pay stub (up to 3 years’ imprisonment and a fine of 45,000 euros— Article L.8224‑1). Furthermore, when an employer intentionally reports a number of hours lower than those actually worked, the employee is entitled, in the event of termination of the contract, to a lump-sum compensation equal to 6 months’ salary (Article L.8223‑1).

    III/ Offense of obstruction: when hindering social dialogue becomes a criminal offense

    The offense of obstruction occurs when there is a deliberate attempt to undermine the establishment or proper functioning of employee representative bodies (CSE).

    The employer must organize CSE elections once the company has at least 11 employees for 12 consecutive months (Article L.2311-2 of the Labor Code). It is common, particularly in small businesses, for the business owner to fail to meet this obligation. This failure exposes the offender to 1 year of imprisonment and a fine of €7,500 (Article L.2317-1). The employer may also be ordered to pay damages to employees without the employees having to prove the existence of harm (Court of Cassation, Social Chamber, June 28, 2023, No. 22-11.699).

    In the event of collective layoffs for economic reasons, consultation with the CSE is mandatory. Failure to do so exposes the employer to a fine of €3,750 (Article L.1238-2).

    The legislature also punishes any obstruction of the exercise of trade union rights with 1 year of imprisonment and a fine of €3,750 (Article L.2146-1).

    IV/ Harassment in the workplace: what recent rulings mean

    Recent case law reflects a broadening of the definition of harassment, while also relaxing certain obligations imposed on employers.

    Sexual harassment is defined by Article 222-33 of the Criminal Code and Article L.1153-1 of the Labor Code as any serious pressure, even if not repeated, exerted with the actual or apparent intent of obtaining a sexual act.

    Under labor law, it is not necessary to prove that the harasser was aware of harassing the victim, unlike under criminal law, which requires the presence of a legal element, a material element, and an intentional element: the perpetrator must therefore have had the intent to commit the acts, which are punishable by 2 years’ imprisonment and a fine of €30,000.

    The employer is required to take “all necessary measures to prevent, stop, and punish acts of sexual harassment” (Article L.1153-5 of the Labor Code). The employer is liable for acts of harassment committed by their employees, unless they can demonstrate that they took all necessary preventive measures (Court of Cassation, Social Chamber, June 1, 2016, No. 14-19.702).

    With regard to workplace bullying, which is considered a form of workplace violence, Article 222-33-2 of the Criminal Code defines it as repeated acts intended to, or having the effect of, degrading working conditions in a manner likely to infringe upon the victim’s rights and dignity, impair their physical or mental health, or jeopardize their professional future (Article L.1152-1 of the Labor Code).

    The Court of Cassation recently affirmed that management practices that degrade an employee’s working conditions and are likely to impair their health constitute psychological harassment, even if the employee is not personally targeted by such acts (Court of Cassation, Social Chamber, December 10, 2025, No. 24 15.412).

    This case law has since been confirmed, establishing the concept of “institutional psychological harassment” (Court of Cassation, Social Chamber, Jan. 7, 2026, No. 24-18.865). Managers may also be sanctioned for “institutional psychological harassment” when a company policy knowingly leads to the deterioration of employees’ working conditions ( Court of Cassation, Criminal Division, January. 21, 2025, No. 22-87.145).

    However, while broadening the definition of harassment, the Court of Cassation has eased employers’ obligations regarding internal investigations, breaking with earlier rulings that penalized “employers who had not conducted any serious investigation and allowed the situation to deteriorate” (Court of Cassation, Social Chamber, July 9, 2014, No. 13-16.797). In a ruling from January 2026, the Labor Chamber of the Court of Cassation reiterated that “no provision of the Labor Code requires the employer to conduct an internal investigation in the event of a report of sexual harassment” (Court of Cassation, Social Chamber, January. 14, 2026, No. 24-19.544).

    Through several themes, the analysis demonstrated how certain behaviors can expose the employer, its executives, or its delegates to criminal liability.

    The list of applicable offenses is particularly extensive: offenses related to specific contracts, the drafting of internal regulations, discrimination, unequal treatment, parental rights, young workers, foreign workers, wage portage, or even traffic violations committed by an employee. This list, far from being exhaustive, illustrates the extent of the criminal risk a company may face.

    AI-generated code and vibe coding: copyright, licensing, and legal risks

    Keywords: Vibe coding, artificial intelligence, intellectual property, GitHub Copilot, AI-generated code, AI Act, open source.

    Legal analysis by Matthieu Quiniou, Partner IP/IT Lawyer at D&A Partners

    Vibe coding refers to the use of generative artificial intelligence tools to produce computer code from natural language instructions.

    AI code generation tools such as GitHub Copilot, ChatGPT or Claude now make it possible to rapidly generate functional code. Their use raises significant legal issues relating to the intellectual property of the generated code, open-source licensing, liability in the event of bugs, and compliance with the European Artificial Intelligence Act.

    This guide answers the main legal questions surrounding vibe coding and AI-generated code.

    Key takeaways

    • AI-generated code may be protected by copyright if creative human input can be demonstrated.
    • The use of vibe coding may expose developers to open-source license contamination risks (such as GNU General Public License or GNU Affero General Public License).
    • Liability for software generally remains with the company that deploys the software into production, even when AI tools were used during development.
    • Companies should implement code and license audits before any production deployment.

    1. Understanding vibe coding

    What is vibe coding and how does it work?

    Vibe coding is a programming practice made possible by generative artificial intelligence models, which allows computer code to be created from instructions formulated as prompts.

    Large language models (LLMs), trained on large volumes of data and digital content, may have been trained on corpora including code from public repositories such as GitHub or GitLab, as well as other data sources.

    Although vibe coding can be used by experienced developers as a programming assistance tool, this practice also helps to democratize access to software development. It allows people with little or no programming knowledge to generate code from instructions formulated in natural language.

    2. Training AI models used for vibe coding

    Can you object to your code being used to train AI models?

    Theoretically, yes, but in practice it’s more complicated.

    The European AI Regulation (EU) 2024/1689 of June 13, 2024 refers to the Copyright Directive 2019/790 of April 17, 2019, which provides in Articles 3 and 4 for an exception to copyright for text and data mining (known as the “TDM exception”).

    This exception allows the reproduction and extraction of lawfully accessible works for the purposes of text and data mining, except where rights holders have expressly objected to this using a machine-readable process, for example with devices such as robots.txt.

    In practice, the effectiveness of this right to object remains limited. Opt-out mechanisms are still imperfectly standardized, and it is often difficult to verify whether these reservations are actually respected when training model databases are created. This difficulty also exists for computer code. License files, readme files, or comments in repositories are rarely taken into account during automated data collection and the creation of AI model training databases.

    The European AI Regulation, through the work of the AI Office, provides for certain transparency obligations for providers of general-purpose AI models, including the obligation to implement a copyright compliance policy and to document the training data used. However, the technical opacity of model training systems, often described as black boxes and covered by trade secrets and business secrets, does not in practice allow rights holders to assert their opposition to training based on their creations.

    Are developers compensated when their code is used to train AI?

    This is still quite rare, but the issue is being debated, as code is, under certain conditions, eligible for copyright protection, raising the question of value sharing or collective remuneration. Several lawsuits have already been filed concerning the use of open source code to train AI systems without attribution to the original developers, notably in the GitHub Copilot case (J. DOE 1 v. GitHub Inc., Northern District of California, Case 3:22-cv-06823, Nov. 3, 2022).

    3. Intellectual property of AI-generated code

    Is computer code protected by copyright?

    Computer code is indeed protected by copyright, the essential criterion for assessment being originality.

    It is settled case law (Court of Cassation, Plenary Assembly, March 7, 1986, 83-10.477, Babolat case) that originality in computer code is assessed on the basis of the mark of intellectual contribution characterized by the fact that the author of the code has “demonstrated a personalized effort going beyond the simple implementation of an automatic and restrictive logic.”

    Article L 112-2 (13°) of the Intellectual Property Code (CPI) explicitly states that software is a work of the mind.

    Is code generated with vibe coding protectable?

    Although it is difficult to give a definitive opinion at this stage on the protection of code generated with vibe coding, in the absence of specific case law on the subject, it seems reasonable to consider that the protection of code generated with vibe coding depends mainly on the degree of human intervention in the creation process.

    In copyright law, only a creation that reflects the author’s own intellectual contribution can be protected. If the developer uses an AI tool to design the program architecture, formulate precise instructions, and then select, modify, and integrate the generated code, the result should be considered an original work eligible for copyright protection.

    Conversely, if the code has been generated in a largely automated manner by an AI system without significant human intervention, protection is more uncertain.

    In practice, vibe coding is most often part of a co-creation process between the developer and the AI tool, which leads to the originality being assessed in terms of the choices and decisions made by the developer in the design and structuring of the software.

    In summary, the use of an AI system to generate code does not therefore exclude copyright protection, but leads to the analysis of originality being oriented towards the creative choices made by the developer.

    Who owns the code created with vibe coding?

    Code created with vibe coding belongs in principle to its author, provided that it constitutes a work of the mind that can be protected by copyright. In French law, as in most legal systems, the rights to software belong to the person who made the intellectual contribution that gave rise to the code.

    When vibe coding is used as a programming assistance tool, the author will therefore generally be the developer who designs the program architecture, formulates the instructions, and selects or modifies the generated code.

    However, two important factors must be taken into account. Firstly, under French law, according to Article L113-9 of the CPI, the economic rights to software created by employees in the course of their duties are transferred to the employer. Secondly, the user licenses or general terms and conditions of use for the AI tools used for vibe coding may include certain rules concerning the use or reuse of the generated code.

    It is therefore recommended that these contractual terms and conditions, as well as the framework of the employment or service relationship, be carefully reviewed.

    How can human intervention in AI-generated code be proven?

    In copyright law, the protection of software presupposes the existence of human intellectual input that characterizes the originality of the work. When code is generated with the help of an AI system, it may therefore be useful to document the developer’s intervention in order to demonstrate that the code is indeed the result of human creative choices.

    Documenting the developer’s intervention is an important step in facilitating the recognition of copyright ownership of the generated code.

    Several elements can help establish this intervention, for example:

    • keeping prompts and exchanges with the AI tool;
    • successive versions of the code (Git history, commits, modifications);
    • documentation of the software architecture and technical choices made by the developer;
    • traces of editing, integration, and adaptation of the generated code.

    In this context, implementing best practices for traceability in the development process becomes an important issue in securing ownership rights to software developed with the help of artificial intelligence tools.

    Can AI-generated code violate open source licenses?

    Yes, this risk exists and is currently the subject of much legal debate.

    The AI systems used for vibe coding are trained on vast corpora of computer code, including open source repositories, for example under the GNU GPL license. In some cases, the generated code may reproduce or be inspired by existing code fragments. If these code snippets come from projects subject to copyleft licenses, their integration into software may create certain contractual obligations, including the obligation to publish the source code under the same license as the original code. These licenses are often referred to as contaminating licenses.

    Two legal interpretations are currently being discussed.

    The first, and most widespread, considers that the contaminating effect only applies if the generated code actually reproduces identifiable fragments of code subject to a copyleft license. In this case, it is recommended that the generated code be audited, similar to a plagiarism check, in order to detect any matches with open source repositories.

    A second, more extensive and currently marginal interpretation is that once an AI model has been trained on code subject to copyleft licenses, the generated code should itself be subject to these licenses. Such an approach would have significant consequences, as it would call into question the possibility of protecting or exploiting AI-generated code in a proprietary manner.

    The use of AI-generated code may therefore expose companies to constraints related to open source licenses or the unintentional introduction of problematic dependencies.

    What license should be adopted for code developed with the help of AI?

    The choice of license for code developed with the help of an artificial intelligence tool depends above all on the strategy of the software project and the legal framework applicable to the generated code. If the code is copyrightable and the developer or company is the copyright holder, it can be distributed under either a proprietary license or a fully or partially open source license (MIT, Apache 2.0, GPL, etc.).

    In practice, it is in companies’ interests to implement procedures for auditing the generated code and verifying licenses, similar to those used for managing open source dependencies in traditional software projects.

    Can the prompts used to generate code be protected by copyright?

    Yes, if these prompts are original, there is no reason why they cannot be protected by copyright as intellectual works.

    4. Legal risks of vibe coding

    Who is liable in the event of a bug or flaw in AI-generated code?

    Liability lies with the person or company that develops, integrates, or makes the software available to users or the public. The use of an artificial intelligence tool to generate code does not transfer liability to the AI provider.

    Furthermore, AI code generation systems often include clauses in their terms and conditions of use stating that no guarantee is provided regarding the output.

    It is therefore up to developers and companies to carry out the necessary tests, security audits, and code reviews before putting anything into production. Given the current state of the art in technology, it seems inappropriate to require AI systems to guarantee that the generated code is free of bugs or vulnerabilities. AI is a development aid tool, but the ultimate responsibility for software quality and security remains with humans.

    What are the risks of confidentiality or information leaks with vibe coding tools?

    The use of AI tools to generate code may present confidentiality risks, particularly when developers transmit sensitive code elements or technical information to the system.

    These risks are particularly significant when the AI tool is operated via an online service and not deployed locally. Prompts, code snippets, or architecture descriptions submitted to the system may be processed on third-party servers and, depending on the terms of use of the service, may be stored, analyzed, or used to improve the models.

    In this context, there is a risk of disclosure of information covered by trade secrets, particularly when a developer submits proprietary code, internal algorithms, or sensitive software architecture elements.

    To limit these risks, companies can, in particular:

    • regulate the use of AI tools through internal policies,
    • avoid submitting confidential or strategic code,
    • favor solutions deployed locally or in secure environments,
    • verify the contractual terms and conditions and data processing policies of AI providers.

    The use of vibe coding tools must therefore be compatible with trade secret protection obligations and, where applicable, with the company’s internal information security policies.

    Can code generated with vibe coding be reused by AI providers to train their models?

    There is no absolute answer to this question, as it is generally governed by the licenses and terms of use of generative AI systems. Some AI systems allow users to choose whether their prompts and generated content can be used to improve the model.

    5. Best practices for vibe coding in companies

    Can AI-generated code be used in commercial software?

    In most cases, AI-generated code can be used in commercial software. Several legal precautions must be taken, in particular to verify that the generated code does not reproduce fragments subject to restrictive open source licenses and that the terms of use of the AI tool allow commercial exploitation of the generated code.

    What best practices should be adopted before vibe coding or publishing or deploying AI-generated code?

    Before going live, it is recommended to:

    • avoid disclosing confidential information or proprietary code when prompting
    • check the terms of use of the AI tool and the rules applicable to the generated outputs
    • conduct a human review of the code and thorough technical testing
    • verify the absence of security vulnerabilities and the robustness of the software
    • perform a license and similarity audit to detect any fragments from software subject to restrictive open source licenses
    • document human intervention in the development process (prompts, modifications, Git history) to secure ownership of rights.

    In general, code generated with the help of AI should be considered as code to be verified and audited, rather than code that is ready to be used without control.

    Companies using vibe coding tools must therefore integrate these legal issues into their software development practices, particularly with regard to intellectual property, open source licenses, and risk management.

    Legal support

    D&A Partners advises companies, startups, and developers on legal issues related to artificial intelligence, software intellectual property, and compliance with the European AI regulatory framework.

    Last updated: March 2026.

    By Matthieu Quiniou – Partner, Lawyer

    𝐃𝐢𝐬𝐭𝐚𝐧𝐜𝐞 𝐬𝐞𝐥𝐥𝐢𝐧𝐠 𝐨𝐟 𝐟𝐢𝐧𝐚𝐧𝐜𝐢𝐚𝐥 𝐬𝐞𝐫𝐯𝐢𝐜𝐞𝐬: 𝐰𝐡𝐚𝐭’𝐬 𝐜𝐡𝐚𝐧𝐠𝐢𝐧𝐠

    Ordinance No. 2026-2 of 5 January 2026 on the Distance Marketing of Financial Services to Consumers

    Ordinance No. 2026-2 of 5 January 2026 was adopted pursuant to Law No. 2025-391 of 30 April 2025 (DDADUE)and transposes Directive (EU) 2023/2673 of 22 November 2023 on the distance selling of financial services. It also aligns the applicable legal framework with Law No. 2025-594 of 30 June 2025 on combating fraud involving public subsidies (the “Cazenave Law”), in particular with respect to telephone solicitation.

    The purpose of this Ordinance is to strengthen consumer protection in the context of the distance marketing of financial services, taking into account the rapid development of online sales and the repeal of Directive 2002/65/EC, now integrated into Directive 2011/83/EU on consumer rights.

    First, the Ordinance enhances the right of withdrawal by facilitating its exercise. Where a contract is concluded electronically, professionals are required to provide a dedicated withdrawal functionality, enabling consumers to exercise this right easily.

    Second, it strengthens pre-contractual information obligations. Prior to the conclusion of the contract, professionals must provide consumers with clear and detailed information, including in particular:

    • complaint handling procedures,
    • the consequences of late or non-payment, and
    • the possible use of automated decision-making mechanisms influencing the price or contractual terms.

    Third, the Ordinance imposes stricter requirements on digital interfaces used for distance marketing. Professionals must provide clear and appropriate explanations and must ensure that consumers are able to contact a human representative when digital tools are used.

    Fourth, the Ordinance updates the sanctions regime. It extends the supervisory powers of the DGCCRF to all provisions governing the distance selling of financial services, including in the insurance sector, and introduces a system of administrative (decriminalised) sanctions, aligned with the general regime of the Consumer Code, without affecting the sanctioning powers of the ACPR.

    In addition, where contracts are concluded via voice telephony, the Ordinance introduces a “two-step sales process”, requiring professionals to send consumers a prior confirmation of the offer before any binding commitment is made.

    Finally, in line with the Cazenave Law, the Ordinance largely repeals Article L.112-2-2 of the Insurance Code, which has become obsolete following the ban on unsolicited telephone solicitation as of 11 August 2026.

    The Ordinance is structured into seven titles, amending in particular the Consumer Code, the Insurance Code, the Mutuality Code, the Social Security Code and the Monetary and Financial Code.
    It will enter into force on 19 June 2026, with the exception of Article 18 (11 August 2026) and Article 9 relating to telephone sales (1 January 2027).

    By Margaux FRISQUE – Partner – Contracts & Litigation Expert

    Integrating Crypto Services Without MiCA License, What Options Are Available?

    With the entry into force of the “MiCA” regulation, the provision of crypto-asset services within the European Union is strictly reserved for duly authorized providers.

    For many market participants, obtaining a CASP (“Crypto-Asset Service Provider”) license  entails significant organizational, technical and regulatory investments, sometimes amounting to several hundred thousand euros per year.

    In this context, a key question arises: is it possible to offer a coherent crypto experience without holding a license?

    MiCA does not provide for any “agent” status for CASPs. An unauthorized actor can therefore neither act on behalf of a provider nor deliver a crypto-asset service under the provider’s responsibility.

    Nevertheless, market practice demonstrates that certain configurations remain viable. The partnerships established by Bitpanda with non-licensed actors illustrate this possibility, provided the framework is structured with sufficient rigor.


    1. The Business Introducer Model

    The business introducer model is the most accessible non-regulated option.

    It is based on a simple requirement: limiting one’s role to putting a user in contact with a licensed CASP, without intervening in the service itself.

    This implies:

    • a purely functional redirection with no incentive;
    • no collection or processing of customer information;
    • no access to orders or transactional data;
    • no promotional or value-driven communication.

    Any deviation, even minor, may lead to regulatory requalification.

    For actors looking to test a market or structure an initial step toward a crypto strategy, this model remains the simplest and fastest option.


    2. The “Grey-Label” Distribution Model

    The grey-label model is currently the most balanced solution for offering an integrated crypto experience without necessarily requiring a CASP license.

    Under this model, the user accesses the CASP’s interface from within the partner’s environment (typically via webview), while maintaining a strict separation of roles.

    Its effectiveness relies in particular on three cumulative requirements.

    Transparency: the user must clearly identify the licensed provider. The interface may be co-branded, but the CASP’s identity must appear explicitly at every stage. Nothing should suggest that the service is provided by the facilitating entity.

    Technical segregation: sensitive flows – orders, amounts, transactional data – must be handled exclusively by the CASP. The webview must remain a visual entry point only, with no operational capacity.

    Neutrality: the partner’s role is limited to providing access. It does not present the service as its own, does not promote it, and does not intervene at any stage in its operation.

    When these conditions are met, the grey-label model can deliver smooth user experience, realistic integration, and – importantly – no licensing requirement. It is now the most widely used distribution model in crypto partnerships across Europe.

    Integrating CASP services via API represents the most ambitious variation of this model, but also the most exposed. If the partner interacts with an order, transforms an instruction, accesses transactional data or contributes to operational processing – even marginally – it may be requalified as providing a reception-transmission or execution service. These services are reserved for licensed CASPs.

    Any consideration of such an integration should, as a strong recommendation, be preceded by consultation with the regulator (in France, the Autorité des marchés financiers) to assess compliance.


    3. Becoming a CASP – The Structural Option

    Some actors will choose to obtain a CASP licence themselves. This option provides independence, full control of the service, the ability to build a complete business model, and significantly greater flexibility in structuring and delivering the offering.

    For regulated financial institutions, certain shortcuts exist, such as the accelerated licensing procedure available to credit institutions. These do not, however, reduce the level of substance expected.


    4. Choosing the Appropriate Model

    The decision rests fundamentally on three criteria:

    • the level of integration sought in the user journey;
    • the degree of responsibility the actor is prepared to assume;
    • the strategic orientation selected, whether partnership-based, a progressive ramp-up, or full internalization of the service.

    Actors able to structure a compliant model from the outset gain a clear advantage: offering a credible crypto experience without exposing the organization to disproportionate regulatory risks.

    To explore how to structure a crypto model in compliance with MiCA, you may contact Daniel Arroche using the form at the bottom of this page.

    The information in this article is provided for general informational purposes only and does not constitute legal advice or investment guidance; it must be assessed in light of each actor’s specific circumstances and cannot create any liability for d&a partners or its attorneys, who recommend seeking professional advice before making any decisions related to the implementation of a crypto offering or the interpretation of the MiCA regulation.

    Guide juridique d’une « tokenisation » immobilière en France – Comment structurer une telle opération ?

    C’est la question que se posent de nombreux acteurs de l’immobilier qui envisagent de recourir à un dispositif d’enregistrement électronique partagé (DEEP ou blockchain) pour réaliser des opérations immobilières. L’objectif recherché est le plus souvent de démocratiser l’accès à l’investissement immobilier ainsi que de simplifier et sécuriser les transactions grâce à un registre transparent et présumé infalsifiable.

    Les réponses ne sont pas évidentes puisqu’elles se trouvent au croisement de plusieurs droits. Dans le présent article, nous apporterons quelques pistes de réflexion sur ce sujet passionnant.

    Retrouvez l’intégralité de l’article publié dans Cryptoast par nos Associés Stéphane Daniel et Daniel Arroche en cliquant ici.