The European Securities and Markets Authority published a risk report on Thursday naming Polymarket and Kalshi directly — not as examples of a regulatory grey area, but as platforms that "currently do not hold" the authorisation generally required to serve EU users. That is a specific finding about specific companies, and it matters more than the paragraph of framework analysis that surrounds it.
ESMA's core observation is that the two platforms restrict some EU member states from trading but not others, and that no clear rationale has been offered for the inconsistency. The regulator raised an additional problem that the platforms may not be able to solve even if they wanted to: VPN enforcement. If you cannot reliably verify where your user is sitting, a jurisdiction-based access policy is less a compliance measure than a statement of intent.
The framework question underneath this is genuinely complicated, and ESMA laid it out plainly. The same contract can fall under EU securities rules, under MiCA if it runs on distributed ledger technology, or under national gambling law — and those three regimes carry different obligations, different supervisors, and different consequences for a breach. A platform that has correctly determined it does not need MiCA authorisation may still have the wrong answer on securities rules, or vice versa. This is the kind of structural ambiguity that looks like an opportunity until a regulator decides to treat it as a violation.
What the reporting does not tell us is whether ESMA has referred either platform to national supervisors for enforcement, or whether this report is the early signal before that action. In my experience of how regulators sequence these things, a named warning in a published risk document is not the same as an enforcement referral — but it is the document you cite when you make one. The gap between the two can close faster than the named parties expect.
The domestic picture in the US already shows what happens when regulators move from observation to action: courts in Iowa, Nevada, and Ohio have all handed platforms losses in recent weeks, and the preemption theory that was supposed to resolve the state-by-state problem has so far survived in zero of the jurisdictions that have ruled. Europe is not running the same legal argument — ESMA's framework is about authorisation, not federal preemption — but the underlying dynamic is the same. Platforms that grew faster than the regulatory perimeter are now inside the perimeter, and the perimeter is being enforced.
The consensus view appears to be that US legal risk is the dominant story for prediction markets right now. The ESMA report suggests that reading underweights what is happening simultaneously in Europe, where the question is not which legal theory wins in federal court but whether the platforms are licensed to operate at all. Those are different problems with different timelines, and the European one does not require a Supreme Court ruling to resolve.
A single prediction market contract can fall under EU securities regulation, under MiCA if it uses distributed ledger technology, or under national gambling law—each carrying different supervisory requirements and enforcement consequences. This structural ambiguity means a platform correctly authorized under one regime may lack required authorization under another, creating compliance risk even for good-faith operators attempting to map their obligations.
ESMA found that Polymarket and Kalshi restrict trading access inconsistently across EU member states without offering clear justification for which countries are blocked and which are not. The regulator also noted the platforms cannot reliably enforce geography-based restrictions because VPN use makes it difficult to verify user location, undermining any compliance measure based on jurisdiction.
A named warning in an ESMA published risk document precedes enforcement referral to national supervisors but is not itself that referral. The report functions as the citation document regulators use when escalating to formal enforcement action, and the interval between publication and that escalation can compress faster than the named platforms anticipate.
US courts in Iowa, Nevada, and Ohio have recently ruled against platforms on state-level grounds, and federal preemption defenses have so far failed in zero jurisdictions that have decided cases. Europe presents a different timeline and mechanism—the question is licensing authorization rather than legal preemption—but the dynamic is identical: platforms that expanded beyond the regulatory perimeter are now subject to enforcement inside it.