Sept. 3, 2026

European Commission's Peter Kerstens | AI, Cyber Resilience, DORA Bank-Friendly Stablecoins and the MiCA Review

European Commission's Peter Kerstens | AI, Cyber Resilience, DORA Bank-Friendly Stablecoins and the MiCA Review
European Commission's Peter Kerstens | AI, Cyber Resilience, DORA Bank-Friendly Stablecoins and the MiCA Review
MetaMarkets
European Commission's Peter Kerstens | AI, Cyber Resilience, DORA Bank-Friendly Stablecoins and the MiCA Review

MetaMarkets hosted by Jan Philipp Fritsche, co-founder of Bermuda, a compliant privacy solution. Strategic Director at Oak Security, a Web3 cybersecurity firm pioneering research on economic and systemic risks in decentralized systems. https://www.linkedin.com/in/janf/

The Guest Peter Kerstens, Adviser for Technological Innovation, Digital Transformation and Cybersecurity at the European Commission's Directorate-General for Financial Stability, Financial Services and Capital Markets Union. He led the Commission's Fintech Action Plan and Digital Finance Strategy. In Brussels he is known as the father of MiCA and DORA. https://www.linkedin.com/in/pkerstens/

In August, attackers spent days inside the Berlin state network and left with six terabytes of data. Internal documents, personal records and reportedly a file full of passwords. Their price for silence was 30 Bitcoin, about 2 million euros. Berlin refused to pay. Peter Kerstens has heard this story many times before, and he finds a ransom demand in Bitcoin a strange choice for anyone who wants to stay hidden. In his words, "who says that criminals are smart?"

In this episode of MetaMarkets, Jan is joined by Peter Kerstens, the European Commission adviser behind both the Markets in Crypto-Assets Regulation and the Digital Operational Resilience Act. The conversation runs from cyber resilience and AI to the origin story of MiCA, the bank-friendly design of its stablecoin rules, the yield debate, DeFi and the MiCA consultation that is open until the end of September.

Kerstens opens with a cybersecurity truism. There are two kinds of organizations, those that have been breached and those that will be. Five or six days of undetected access in Berlin is fast by the standards of the data. Average detection times run 60 to 80 days, and the median is often 180. That is why DORA treats resilience as a life cycle of prevention, detection, isolation, recovery and repair. He also explains why finance got its own rulebook while everyone else, including public administration, got NIS2. Finance is the most attacked sector, the most cyber mature one and the most harmonized in its supervision. Applying DORA standards across the whole economy would overwhelm most other sectors. For crypto there is a catch that many firms miss. Anyone covered by MiCA is also covered by DORA, and Kerstens keeps meeting firms that celebrate MiCA compliance and forget the DORA half. Protocols outside MiCA sit outside DORA too, and that is exactly where the bridge and smart contract exploits keep happening. His message to builders is that what you build "should not only be cool, it should also be secure."

On AI, Kerstens is blunt. Attackers use the most capable models available and skip the question of authorization. Legitimate firms face restrictions. His personal view is that the best defense against an AI-enabled attack is AI, and that rules should never stop financial entities from using the best tools on the market. DORA already points in that direction. Jan pushes further and asks whether uncensored models should be legally available to everyone. Kerstens points to the AI Act and to geopolitics, since very few frontier models are built in Europe. He calls for serious European investment in models, compute and data centers, and he expects any attempt to shield European industry from foreign AI to fail.

Then comes the origin story. Kerstens first heard of Bitcoin in 2017, was fascinated by the technology and watched the ICO wave raise venture-scale money through token sales. Much of it was fraudulent. Some of it was a new way to fund innovation. The framework that later became MiCA started in 2018 as an attempt to enable that, at a time when most policymakers saw only money laundering and speculation. Libra arrived in 2019 as the catalyst. A basket currency backed by a company with billions of users turned crypto from too small to care about into something impossible to ignore, and the G20 declared that no global stablecoin should launch before a regulatory framework existed. The Commission took its existing market structure work, today's Titles 2, 5 and 6, and added two stablecoin chapters. Title 3 on asset-referenced tokens was written for Libra.

Jan puts the show's long-standing criticism on the table. MiCA is bank friendly and leaves stablecoins exposed to bank risk. Kerstens agrees, and adds that the banks never noticed. When MiCA was presented, traditional finance was indifferent and the crypto industry was disorganized, so the debate centered on a fear that stablecoins would drain bank deposits. Kerstens found that fear overstated, but it shaped the rules. Between 30 and 60 percent of reserves must sit in bank deposits, which channels money back to banks and opens a contagion channel. So far the contagion has run the other way. The failure of Silicon Valley Bank temporarily depegged a stablecoin that held more than 3 billion dollars there. Jan argues the case says more about the risk of bank deposits than about stablecoins, and Kerstens concedes the deposit slice may be the riskiest part of the reserve. He adds a twist. Basel liquidity rules treat those deposits as 100 percent outflow risk, so banks have to park them in liquid assets and the lending effect the rule was meant to create disappears.

The second bank-friendly feature is less known. Non-bank issuers need an e-money license and 100 percent collateral. Banks may issue e-money tokens directly against their balance sheet with no separate reserve. That was the Member States' decision in Council, and Kerstens notes that banks leave the privilege unused. His guess is that the market now expects a fully backed, separately reserved coin, which is why the Qivalis bank consortium is setting up its own e-money institution. Jan sees an arbitrage in both directions, full backing on the label with the deposits kept inside the consortium banks. Kerstens counts just under two dozen licensed issuers in Europe, most of them tiny, and expects network effects to leave a handful standing. Jan suggests the regulation itself may have produced that outcome.

On why dollar stablecoins dominate globally, Kerstens points to three uses. On and off ramps for crypto trading priced in dollars. Cross-border payments where banking rails are slow or expensive. Inflation hedging in countries with weak currencies. Dollar dominance predates the GENIUS Act, and the largest issuer operates outside the United States, so he attributes the outcome to demand for the currency itself. On yield he holds no dogmatic view, and the current MiCA consultation asks the question openly. The original prohibition grew out of the deposit fear and passed without debate. The fight over yield started in the United States and spilled over to Europe. Kerstens observes that 300 billion dollars in stablecoins has left bank deposits intact, recalls the money market fund scare of earlier decades, and adds that a bank fearing yield on stablecoins shows little confidence in its own product. He also warns that a debate as polarized as the American one tends to end in a standoff, and a standoff means the status quo.

A lot of what people call DeFi he calls DINO, decentralized in name only. Bitcoin is his example of real decentralization. Most other protocols come with a lab, licensed service providers and commercial incentives attached. Jan argues that permissionlessness is the better test. A solo developer can deploy a smart contract without ever taking custody of user funds, and regulators who obsess over decentralization risk pushing people into role-playing it. Kerstens calls the decentralization debate futile. His focus is the activity and who is behind it. His warning to users comes from 30 years at the Commission, many of them in consumer protection. A proposition that is too good to be true is exactly that, and high yield always comes with risk. He also hands the industry a responsibility of its own. Stop blowing yourselves up, because the political reaction after a blow-up is an overreaction.

Kerstens notes with some satisfaction that the SEC is now trying to bring ICOs back, six years after the Commission wrote what is internally still called the ICO chapter, Title 2 of MiCA. Jan jokes that reviving ICOs might finally deliver the capital markets union.

The episode closes with a call to action. MiCA was designed for spot crypto markets and stablecoins. The market has since moved to derivatives, perpetual futures and event markets, all of which sit outside MiCA's scope. The Commission's consultation runs until the end of September, and Kerstens wants responses from everyone, whether they love MiCA or hate it. The reasoning behind an opinion matters more to him than the opinion itself. The future of MiCA depends on two things, what the consultation returns and the political appetite for a European consensus.

The takeaway is a rare view from the inside. The man Brussels calls the father of MiCA describes the regulation as a product of its time, built on 2018 knowledge, shaped by Libra and by fears he himself found overstated. Now he is asking the market to help rewrite it.