From agencies to algorithms? Ten years of asking whether EU law actually works

By Miroslava Scholten, Zlatina Georgieva, Laura Zoboli, and Kelly Blount (Co-editors)

In September 2026, our blog – eulawenforcement.com – marks its 10th anniversary. We take this milestone to look back to assess what knowledge the blog has brought about and to look forward to outline directions for relevant research and for the EU law enforcement practice. Given the rise of AI technology in assisting research and enforcement practice, we experiment with it in this blogpost. More specifically, we have created the same prompt asking AI ten questions about eulawenforcement.com and have run it through five different AI programmes, then we have compared the results and aligned them with our own ideas on the mentioned questions (our methodological note is at the end of the blog post).

All in all, we witness an evolution of our blog from mapping new institutions to evaluating systems of enforcement, and finally to designing enforcement when legislation is made. One of the most exciting questions for the future of research on enforcement practice suggested by AI is: to what extent will enforcement be able to transform from agencies to algorithms given EU constitutional, political and economic realities?

Picture 1: Future of enforcement? (generated with Copilot)

Founded in September 2016 by Dr. (Mira) Scholten at Utrecht University, the eulawenforcement.com blog platform was originally established to support two NWO-funded research projects at RENFORCE (Utrecht Centre for Regulation and Enforcement in Europe): Scholten’s own Veni project on ‘Shared enforcement but separated controls in the EU’ and Michiel Luchtman’s Vidi project on ‘The rise of EU law enforcement authorities’. The blog subsequently became the communication platform of the Jean Monnet Network on enforcement of EU law (EULEN), a consortium of nine European universities funded from 2019 to 2023, and has continued ever since to stimulate discussion and enhance knowledge on how to enforce EU law.

Five recurring questions organise much of the decade on eulawenforcement.com.
  1. Who enforces EU law? The Commission, EU agencies, national regulators, networks, courts, prosecutors, private claimants or some combination of them?
  2. At what level should enforcement power sit? Should enforcement remain decentralised, become centralised in Brussels, or be allocated selectively according to the actor or risk concerned?
  3. Who controls the enforcers? The blog repeatedly considers accountability, judicial review, transparency, defence rights, fundamental rights and the problem of responsibility in composite procedures.
  4. What makes enforcement effective? Is success a matter of formal powers, inspections and fines, actual compliance, prevention of harm, or achievement of the policy’s underlying objectives?
  5. How can enforcement cross borders without losing legality and legitimacy? This question appears across fields such as competition law, banking, migration, criminal cooperation, data protection, platform regulation and environmental law.
The most important change in approach over the years is a movement from mapping new institutions to evaluating systems of enforcement, and finally to designing enforcement when legislation is made. The blog has evolved over time through, roughly speaking, 3 stages.

Phase 1 (2016–2018): Mapping the landscape/verticalization stage/discovery

Early posts were often agency-specific case studies (EASA, ECHA, EIOPA, ESMA) or conceptual pieces introducing the “verticalization” thesis, whereby it was observed that the EU is taking on increasingly more enforcement functions in the shared EU administrative order. Posts like “Effective and accountable enforcement in EU aviation safety?” (Schmidt & Coman-Kund, April 2017) and “Problems of informal supranational enforcement: The case of chemical substance registration in the REACH regulation” (Klika, November 2018) exemplify this empirical mapping approach.

Phase 2 (2019–2023): Deepening and network-building/consolidation

The launch of the Jean Monnet Network on EU Law Enforcement (EULEN) in September 2019 marked a turning point. The focus shifted to examining four EU policy pillars (competition, financial services, PIF, migration/asylum) and three horizontal themes (rule of law, uniformity vs differentiation, technology). Posts became more comparative and theoretical, engaging with constitutional questions about delegation, soft law and judicial protection. The 50th post (October 2020) took stock of progress and challenges.

Phase 3 (2024–2026): New regulatory frontiers/design

After the EULEN project funded by the EU Commission formally ended in 2023, the blog continued thanks to the collaboration of EULEN universities with posts on emerging regulatory regimes: the Digital Services Act, Digital Markets Act, AI Act, Corporate Sustainability Due Diligence Directive (CSDDD), and the Anti-Money Laundering Authority (AMLA). Posts increasingly focus on “enforcement design” – how to build enforcement architectures that are effective, legitimate and fair from the outset.

Seven principal insights can be highlighted over the ‘lifecycle’ of the blog.
  1. Enforcement architecture determines substantive outcomes. A right or prohibition is only as effective as the institution, procedure, information and remedy attached to it.
  2. Centralisation solves some cross-border problems but creates constitutional ones. It can produce consistency and expertise, while simultaneously increasing concerns about legal basis, political independence and judicial protection.
  3. Shared enforcement requires shared control. National and EU authorities perform integrated tasks, but parliamentary, judicial and administrative controls often remain divided by jurisdiction. Scholten formulated this problem particularly clearly in “Shared Tasks, but Separated Controls” (Scholten, July 2019).
  4. Effectiveness and fundamental rights are not simple opposites. Procedural fairness, transparency and review can strengthen legitimacy and compliance. But complex safeguards and divided remedies can also delay or weaken enforcement. The real question is institutional design, not a crude choice between efficiency and rights.
  5. Under-enforcement is frequently systemic. It can result from fragmented authority, unequal national capacity, opaque informal procedures, political reluctance and the inability of regulators to obtain or understand evidence—not merely from insufficient maximum fines.
  6. Enforcement is becoming preventive and collaborative. Guidance, compliance systems, risk-based supervision and design duties are increasingly treated as part of enforcement itself.
  7. The field still lacks an agreed measure of success. Case numbers and fines are inadequate, but outcome-based measurement is difficult. How do you prove that prevention has worked? The blog’s 100th-post reflection (by co-editors, October 2024) expressly calls for conceptual clarity and more empirical work on when enforcement succeeds.
Blind spots of the blog entries and invitation for contributions to ‘fill the gaps’:

The editors very much welcome future contributions on the below topics, which were identified as opportunities for the blog platform to further grow and expand:

  1. Specific sectoral domains, like consumer protection, intellectual property rights, tax, public procurement, and environmental acquis (even though the blog does feature blog posts in those areas).
  2. Geographical perspectives from different parts of Europe and globally, and national practices and laws.
  3. Enforcement operational challenges and good practices: costs, resources, optimal fines, nudging, compliance.
  4. Empirical studies and different disciplinary and methodological approaches to the abovementioned topics.

Looking forward: what’s next in research and enforcement practice?

The following predictions for the coming decade have been made by the AI programmes used:

  • By 2036, EU law enforcement will be significantly more centralized, though possibly selectively (per sector) rather than comprehensively, with at least three new EU-level enforcement agencies (building on AMLA, possibly a digital enforcement authority, and a sustainability enforcement body).
  • Enforcement will be increasingly automated, with AI systems conducting real-time monitoring and risk assessment across Single Market rules. However, this will provoke a constitutional backlash: the CJEU will have issued landmark rulings clarifying the limits of delegation to algorithms and agencies, and a new “EU Enforcement Code” will have been proposed to harmonise procedural safeguards across all centralised enforcement regimes.
  • The main constitutional litigation will concern not only sanctions, but the legitimacy and reviewability of algorithmic risk selection, supervisory guidance and decisions produced across several authorities before any formal infringement proceeding begins.

In this light, it will be interesting to investigate these predicted directions as well as emerging questions such as the following (proposed by the AI programmes):

  1. How should enforcement be designed for “regulatory ecosystems” rather than single instruments? The blog’s most recent posts (Digital Fairness Act, CSDDD, AI + AML + Space Law) all concern situations where multiple overlapping EU regulations must be enforced simultaneously, often by different authorities. The next decade’s challenge is enforcement coherence across the regulatory stack — not just within single instruments but across them.
  2. What institutional form should AI enforcement take, and who enforces the enforcers’ algorithms? The blog has documented both the promise (efficiency, detection) and peril (bias, opacity, rights violations) of algorithmic enforcement. As AI systems are embedded deeper in supervisory processes — from AML screening to border surveillance — the question of how to govern enforcement technology itself becomes paramount.
  3. Can the EU enforce its green and sustainability commitments, or will the “enforcement gap” swallow the Green Deal? With the CSDDD, the CSRD, the Taxonomy Regulation, deforestation-free supply chains, and CBAM all requiring enforcement, the next decade will test whether the EU has the institutional capacity to match its climate ambition.
  4. What is the appropriate enforcement relationship between the EU and third countries in an era of strategic competition? The EU-China trade post by Li Guangqi (July 2026) opens this question. As the EU asserts regulatory power extraterritorially (GDPR, AI Act, CBAM, deforestation), it must develop enforcement mechanisms that work beyond its borders — through trade conditionality, mutual recognition, or coercion.
  5. How should enforcement be governed democratically in a multi-level system? The 100th blog post asked: “What should be the enforcement power of the EU and who should establish this — representative organs, the demos directly via the European Parliament and/or courts?” This constitutional question becomes more pressing as enforcement centralises and agencies acquire quasi-executive power.

Concluding remarks and a note on methodology

All in all, the eulawenforcement.com editors have found it a thought-provoking exercise to use AI to analyse the 10 years’ development of blog posts on our blog. From the substantive perspective, all the knowledge that has been generated seems relevant and supportive to the ongoing development in society and EU law.  From a methodological perspective, it could be an interesting idea for academic journals and official reports to do a similar exercise once in a while to take a pause and evaluate their fields, efforts, progress in knowledge accumulation and impact, and to sketch possible directions for future activities. Of course, this all should happen with a critical mindset and openness to the opportunities and limitations of AI use.

Picture 2: a comic image of the co-editors (generated with Copilot)

Methodological note

We submitted the same five-question prompt to five general-purpose AI models: Gemini 3.1 Pro, Perplexity, ChatGPT 5.6 SOL Extra High, Claude Opus 4.6 and the professional version of Copilot. The broad convergence among their accounts was striking, but so were some of their differences and errors.

Since the prompt itself prescribed a set of ten questions, the similarity of the structure tells us little. More revealing were the themes that the models emphasised, omitted or interpreted differently. These variations appear to reflect, among other things, differences in retrieval and in the weight assigned to particular posts. They may also have been influenced by the organisation of the website: the sortable archive is not fully up to date, many recent posts are categorised simply as “Uncategorized”, and student contributions are collected separately.

We therefore treated the five outputs as material for reflection rather than as authoritative accounts. Their claims were checked against the blog, and the selection, interpretation and conclusions presented here are those of the editors. The prompt and the complete outputs are available here.

Disclaimer: While the structure and some parts of the blog post have been designed and written by the editors, a few passages that the editors found interesting and thought-provoking, have been taken from the five reports that we have generated with AI. The pictures have been generated with the help of Copilot.

 

 

 

Leave a Reply

Your email address will not be published. Required fields are marked *