The assumption worth naming
A UAE licence authorises the activity it names, in the jurisdiction that granted it. It does not travel.
This sounds obvious written down, and it is routinely assumed away. A licence appears on a website, a sales team is hired, and clients are onboarded from wherever they arrive — on an unexamined belief that a regulated firm is regulated everywhere.
There is no GCC passport
None of the Gulf states recognises another's licence. Not for virtual assets, not generally. A VARA licence confers nothing in Saudi Arabia, and a Saudi CMA authorisation confers nothing in Dubai.
This matters more than the EU question for most UAE businesses, because the Gulf is where their commercial instinct points first, and because the enforcement posture varies sharply between neighbours. Kuwait's position is markedly more restrictive than Bahrain's. Treating the region as one market is the error.
MiCA is the one passport in the picture
The European Union is the exception, in both directions. Since MiCA came into full application on 30 December 2024, a crypto-asset service provider authorised in one member state can serve the whole European Economic Area.
That is the opposite of the Gulf position, and it is the strongest argument for a dual structure: a UAE entity for the Gulf and the rest of the world, an EU entity — Cyprus being the common choice — for Europe.
It also means serving EU clients from Dubai is not a grey area. MiCA expects authorisation, and a UAE licence is not it.
What reverse solicitation is, and is not
It is a narrow doctrine that recognises a client who genuinely, without prompting, approached a firm abroad.
It is defeated by marketing into that country. By a relationship manager with a target. By a website that accepts registrations from there. By an affiliate paid per signup. By a conference stand. By a localised landing page.
Firms rely on it as though it were a licence category. It is not one, and the gap between the doctrine and the way it is used is where enforcement finds people.
What a defensible position looks like
A written analysis, per market, before the sales team is pointed at it. Not after. The document that matters is the one dated before the first client.
Controls that match it. If the position is that a country is not served, then onboarding refuses it, the website blocks it, and marketing does not target it. A disclaimer at the foot of a page is not a control.
A record of the decisions. A supervisor asking why a client in a given country was accepted wants to see that somebody decided, on a basis, on a date.
Review when the business changes. A new market, a new partner, a new affiliate channel — each reopens the question. Most breaches of this kind are drift, not decision.
The commercial reading
This looks like a constraint and is mostly an advantage. A firm that can demonstrate which markets it serves, on what basis, with controls that hold, is easier to bank, easier to partner with and considerably easier to sell.
The firms that struggle in diligence are not the ones with narrow permissions. They are the ones that cannot say which permissions they were relying on.
Regulators
Common questions
Our clients found us. Is that not enough?
Reverse solicitation is a narrow doctrine, not a business model. It survives a genuinely unsolicited approach. It does not survive marketing, an account manager with a target, or a website that accepts registrations from that country.
Can we just geo-block and carry on?
Controls are the right instinct, and blocking is one of them. Whether it is sufficient depends on what else the business does — a block undone by an affiliate programme or a regional sales hire is not a control.
Sources
- Markets in Crypto-Assets Regulation (MiCA), in full application since 30 December 2024 — EU regulation; confirm transitional arrangements before relying on them
- Capital Market Authority publications, Saudi Arabia, Oman and Kuwait