
Modern regulatory frameworks assume that the phenomena they govern are knowable: harms can be identified, probabilities estimated and risks balanced against benefits. This article argues that this assumption becomes unstable when applied to genuinely novel technologies. Drawing on Frank Knight's distinction between risk and uncertainty, it contends that contemporary EU digital regulation - particularly the EU AI Act, alongside the Digital Services Act and the GDPR - applies the form of risk-based analysis to domains where the necessary epistemic foundations are absent. These regimes borrow models developed for pharmaceuticals and environmental regulation and extend them to technologies whose future effects remain deeply uncertain. The article traces the historical development of risk-based regulation, examining both its virtues and structural limitations. It argues that such frameworks systematically marginalize diffuse, long-term and structural harms, while delegating assessment to regulated entities thus creating incentives for conservative self-evaluation. It then explores decision-making under deep uncertainty (DMDU) as a source of alternative regulatory approaches, including adaptive and precautionary techniques. Finally, the article argues that risk assessment is inherently political, embedding normative choices that risk-based methodologies often obscure rather than resolve.
This case note examines the landmark judgement in Case C-115/24 (DrSmile), the CJEU’s first ruling specifically addressing cross-border telemedicine. The dispute centred on a hybrid orthodontic model where physical dental acts in Austria were coupled with remote monitoring and treatment planning from Germany. The Court’s decision creates a significant “digital scalpel,” legally slicing the medical act into discrete components. By interpreting Article 3(d) of Directive 2011/24/EU strictly, the Court ruled that only services provided exclusively at a distance qualify as telemedicine. This triggers a legal fiction that anchors regulatory oversight in the provider’s country-of-origin, favouring market integration. However, any physical component remains tethered to the destination state’s regulations. While providing much-needed judicial scaffolding, the author argues that this formalist division creates a clinical-legal gap. By severing indivisible therapeutic processes, the ruling risks creating liability vacuums and professional fragmentation.
While the legislative text of the Digital Fairness Act (DFA) has not yet been published, it is already clear that its effectiveness will depend as much on its enforcement design as on the content of its substantive provisions. Experience with recent instruments - including the Digital Services Act, the Digital Markets Act, the Artificial Intelligence Act and the Data Act - reveals persistent difficulties in ensuring consistent and timely enforcement across Member States. Building on the findings of the Commission's Fitness Check of EU Consumer Law on Digital Fairness, this article examines how the enforcement design developed in these legal acts can inform the institutional and procedural design of the DFA. It argues that the challenges identified by the Digital Fitness Check reflect deeper patterns of procedural, institutional and epistemic fragmentation in EU enforcement. By analysing how different enforcement designs address these tensions through mechanisms of centralisation, coordination and capacity-building, the article identifies key design choices that may shape the emerging enforcement framework of the DFA.
This article argues that platform capitalism generates a distinct legal problem that existing regulatory frameworks, designed to address disinformation and censorship, structurally fail to recognise: attention fragmentation. The commodification of attention produces a form of distraction that undermines the preconditions legal accountability itself depends on. Platform capitalism’s business model rewards engagement, and the dominant architectures reward a fragmented modality of engagement in particular, producing subjects who have internalised the logic of self-optimisation that Han identifies as psychopolitics. Through a theoretical genealogy from Debord’s externally imposed spectacle to Han’s psychopolitical internalisation, this article explains why distraction resists conventional legal intervention. Turning to environmental governance as a particularly stark illustration, the article reveals four structural vulnerabilities that make environmental regulation systematically susceptible to attention collapse: temporal mismatch, monitoring dependency, breakdown of accountability chains and asymmetric harm distribution. The article identifies possible policy interventions but emphasises their structural limits; legal reform cannot guarantee attention when the economic system profits from its commodification and fragmentation. The effectiveness of law in the age of platform capitalism depends on confronting the alignment between extractive capital’s interest in deregulation and platform capital’s dependence on engagement-driven fragmentation.
EU laws remain structurally misaligned with how algorithmic systems generate harms. This paper identifies an “EU collective redress gap” for harms to algorithmic “groups of persons.” It uses doctrinal comparison of the GDPR, the Representative Actions Directive (RAD) and the Artificial Intelligence Act (AI Act), complemented by case studies of TPC v Oracle/Salesforce and the CJEU’s Meta Platforms Ireland (C-319/20) judgment, to showcase this gap. The analysis demonstrates that GDPR remedies are ultimately bound to identifiable data subjects and (optionally) their mandates, RAD ties redress to consumers, and the AI Act, while repeatedly referring to “persons or groups of persons” in its risk-based prohibitions and obligations, outsources collective enforcement to RAD and offers only individualised complaints. On that basis, the paper conceptualises three group categories, organised, inferred and legislatively “vulnerable” groups, and identifies inferred, risk-exposed groups constructed from anonymised data as the main harm-bearers currently left without meaningful access to compensation. To close this gap, this paper proposes a guide for “group-friendly” collective redress consisting in privileging opt-out models, lowering representativeness thresholds (including digital expressions of support), importing WAMCA-style categorisation of claimants, introducing an explicit AI-specific representation right for “persons or groups of persons,” and extending collective standing to non-consumer groups.
The integration of artificial intelligence (AI) agents into payment systems signals a profound shift in the architecture of financial transactions. Building on advances in large language models and autonomous systems, "agentic payments" refer to transactions initiated and completed by AI agents without direct human intervention. This article provides a conceptual and technical analysis of agent-enabled payment systems, examining their operational logic, defining features and emerging use cases across retail, e-commerce and decentralised finance. It distinguishes agentic payments from traditional automated systems by emphasising autonomy, contextual reasoning and adaptability. The article further identifies and categorises a range of technical, legal and societal risks, including cybersecurity vulnerabilities, liability gaps, regulatory non-compliance, and potential economic disruption. Through case studies and architectural illustrations, it highlights both the innovation potential and governance challenges posed by agentic systems. It argues that current regulatory frameworks - designed for human-intermediated payments - are ill-equipped to address the dynamic and decentralised nature of agent-led transactions. The article concludes by proposing a multi-layered governance framework combining core regulatory requirements with supporting ecosystem measures to ensure accountability, security, and transparency in the age of autonomous financial agency.
Recent advances in Artificial Intelligence (AI) reveal a mismatch between the EU's individual-centric data protection shell and automated systems' ability to affect entire groups of people, sealed within that shell. AI routinely processes data about groups, while the GDPR still allocates rights and remedies to identifiable individuals. This design produces a structural collective redress gap where injunctions may be obtained without individual mandates (GDPR Art. 80(2), RAD Art. 8), but compensation remains tied to identifiability. Here, I show how the GDPR's model (consent, data subjects' rights, Art. 80) fits in and why it fails against AI's capacity to de-anonymise and infer traits about persons whose data were never collected or volunteered. I then examine the AI Act 2024/1689. Although it repeatedly refers to "groups of persons," trilogue negotiations removed the Parliament's key collective remedy tools, leaving only ex-ante risk and transparency duties. The example of online behavioural advertising or affinity profiling illustrates how AI-designed groups fall outside the scope of meaningful GDPR or AI Act remedies. I argue for a right to group protection and propose four main revisions: a definition of groups, a mechanism for a group complaint and redress, group-level impact assessment requirements and group data protection by design.
Since February 2022, EU restrictive measures adopted under the Common Foreign and Security Policy have increasingly focused on targeting private wealth in response to Russia’s war against Ukraine. This paper analyses the Council’s strategies for maintaining, renewing, and expanding sanctions against Russian businesspersons (oligarchs) and their assets. It analyses the post-2022 amendments to the design and application of listing criteria, particularly the criterion (g), and the use of presumptions to secure the durability of listings decisions and the long-term imposition of asset freezes. These techniques enhance the resilience of listings to judicial review, limit opportunities for de-listing targets and unfreezing their assets, de facto immobilising private wealth within the EU. Nonetheless, they also raise broader questions about the purpose of sanctions, in particular whether asset freezes remain targeted, reversible and preventive tools to influence behaviour, or are increasingly used as instruments that aim at the long-term immobilisation of wealth.
Increasing water scarcity forced the European Union to investigate the possibility of supplementing natural water sources with reclaimed wastewater. Regulation (EU) 2020/741 sets minimum requirements for the safe reuse of treated urban wastewater in agricultural irrigation. The risks that wastewater reuse presents are further regulated in the numerous EU law instruments that concern the protection of human health, the environment and the European waters, including both laws and principles. This paper applies the widely applicable framework for risk governance that was developed by the International Risk Governance Council to the EU regulatory framework on wastewater reuse. The analysis identifies regulatory gaps - unclear pollutant regulation, incomplete division of responsibilities, and insufficient attention to the science-policy interface - and concrete means of improving the regulation of risks associated with wastewater reuse.
Energy dependence and rising pollution from the energy sector have compelled states to re-evaluate their energy policies and legal frameworks in favour of sustainable energy development. In this context, energy transition emerges as a strategy to achieve global climate goals while ensuring energy security. However, making the energy transition a “just transition” presents numerous challenges. These challenges are growing as innovation in the energy sector accelerates, with digitalisation presented as a tool to drive the energy transition and optimise current energy systems. This trend has been integrated into the EU’s policy objectives and regulated by the EU’s legal framework. However, this political decision has sparked ethical and legal debates about the digital transformation of the EU energy sector, particularly regarding energy justice. By analysing instruments in the EU’s policy and legal framework, this paper addresses the intersection of the twin transitions through the lens of energy justice. Therefore, this study assesses the EU policy and legal framework of twin transitions from an energy justice perspective. The geographical scope of this research covered the EU. The methodology includes doctrinal legal research. The conclusions of this research encompass an assessment of selected EU policy and legal instruments applicable to the twin transitions.
European policymakers have long sought to strike an appropriate balance between supporting EU-native cultural production and pursuing the objectives of internal market harmonisation. To this end, the 2018 reform of the Audiovisual Media Services Directive (AVMSD) introduced a set of measures for on-demand audiovisual media (VOD) providers, including catalogue quotas, prominence requirements and financial contributions. However, the coherence and effectiveness of these provisions remain highly contested. In particular, national implementations of financial obligations have produced adverse effects. They have intensified fragmentation among Member States and enabled them to prioritise domestic works over non-national European productions. Such fragmentation of the European audiovisual market will also preserve a heterogeneous ecosystem of producers, making it exceedingly difficult for a local service to scale and evolve into a pan-European platform. Consequently, despite the ambitions of EU policymakers, the emergence of European champions capable of competing with foreign players on an equal footing is likely to remain elusive. Moreover, the AVMSD rules on financial obligations create opportunities for regulatory gaming, insofar as Member States use the policy goal of fostering cultural and linguistic diversity as a convenient pretext for subsidising their local economies.
Hybrid threats represent a continued challenge to the European Union, combining disinformation campaigns with cyber-attacks as a means of destabilising the Union and its Member States, undermining legitimacy and public trust. With social media platforms at the centre of disinformation efforts, as well as potential sites for cyber-attack disruption, the ability to control narratives and disseminate content are essential to hybrid threat actors. Fake Activity Markets (FAMs) are websites offering services that can be used to generate fake engagement, in turn allowing for coordinated inauthentic behaviour online. These websites also constitute a cybersecurity threat in themselves, involved in distributing malware, harvesting user data or comprising information systems. This article seeks to explore the EU approach to hybrid threats and coordinated inauthentic behaviour using FAMs as a case study, highlighting the potential threats to the EU’s social and cyber resilience posed by these actors, the potential regulatory responses, and the ways in which the von der Leyen II Commission’s renewed emphasis on hybrid threats could provide for a more robust ecosystem for countering coordinated inauthentic behaviour.
A medicinal herbal tea classified as a traditional herbal medicinal product cannot, in principle, be marketed with the organic logo. The position may be otherwise where such an indication on the packaging has been approved by the competent authority on account of the beneficial effect of the organic production on the therapeutic characteristics of the medicinal product.
Under the notion of the twin transition, the green and digital transitions were conceptualised as a synergetic pair that should pave the way for a globally competitive green and digital Europe. But are European digital and environmental laws truly twins within the EU’s regulatory strategy, suggesting parallel approaches? In this article, we take a formal approach, focusing on regulatory instruments that are employed in both areas and their defining characteristics. While the twin transition in some respects blurs the boundaries between environmental and digital law, including through the integration of environmental considerations into digital regulations, we adopt an analytical distinction between the two domains. Through a series of steps, we identify key differences that set both regulatory approaches apart and help us understand the different trajectories the transitions have taken. Contrary to the often-invoked claim that form is substance, the analysis reveals that the choice of regulatory instruments does not inherently determine substantive policy choices, thereby underscoring the necessity of their comparative examination. Ultimately, the article argues that fostering dialogue between the two policy fields may yield valuable insights into how regulatory tools can be adapted and deployed across domains.
This paper analyses the General Court’s judgments of 25 June 2025 (RWE and Uniper) regarding the reviewability of ACER regulatory acts. The General Court endorsed a “hybrid approach,” excluding acts of general application from the jurisdiction of the Board of Appeal and subjecting them solely to judicial review under Article 263(4) TFEU. The study highlights how this interpretation creates significant procedural gaps and bureaucratic burdens for private parties. By contrasting these rulings with the more flexible standing criteria recently adopted by the Court of Justice (e.g., Nicoventures Case), the paper argues that the current framework fragments the EU system of judicial protection and undermines the principle of procedural economy in highly technical sectors.
Occupational accidents impose devastating human and economic costs worldwide, yet evidence on how judicial decisions affect workplace safety remains scarce. This study provides the first causal evidence on this relationship by examining Argentina's landmark Aquino ruling (2004), which eliminated employers' exemption from civil liability for workplace accidents. Using an event study design with provincial panel data (1997-2021), we exploit the differential impact of increased employer liability on workplace accidents versus commuting accidents (in itinere) as our identification strategy. Results show that workplace accidents decreased significantly by 16-27% following the judicial decision, with larger reductions in provinces with higher initial number of accidents. Importantly, we find no evidence of moral hazard effects when examining accidents that are difficult to detect and verify. The findings demonstrate that judicial decisions creating immediate economic liability can generate substantial behavioral responses even in developing country contexts with limited enforcement capacity, suggesting that liability-based approaches may effectively complement traditional regulatory strategies for improving workplace safety.
This paper examines the regulatory challenges and opportunities surrounding the introduction of autonomous inland shipping in Europe. As regulators navigate this shift, they must strike a balance between innovation, safety, legal certainty and private actors’ interests. Drawing on principles guiding innovation, such as outcome-based, risk-based and adaptive regulation, as well as the precautionary, proportionality and technological neutrality principles, the paper proposes a framework for developing regulatory responses. It also analyses the relevance of EU horizontal digital regulations, including the AI Act and the Data Act, in shaping the governance of autonomous systems in inland waterways. The paper explores how the existing divisions of regulatory competence between European institutions and river commissions may hinder harmonisation, and proposes mechanisms to improve regulatory and judicial coherence in a multilevel governance context.
This article presents a novel type of co-regulation under EU law: codes of practice under the AI Act. The introductory section offers an overview on how the AI Act combines general statutory obligations with various non-legislative instruments. Following a brief presentation of the legal basis for codes of practice in the AI Act, the third section provides a detailed account of how the European AI Office put this sketchy statutory framework into practice for the first General-Purpose AI Code of Practice, which was approved on 1 August 2025. Drawing upon this experience, the conclusion highlights two practical and normative issues associated with codes of practice: tech-induced acceleration and a diffusion of responsibility.
How do European Union (EU) fiscal allocations affect the electoral performance of corrupt incumbent governments? While existing research links EU funds to governance quality and corruption, less is known about how these resources interact with domestic political incentives to shape electoral outcomes. This article advances a theory of corruption compensation, arguing that EU transfers provide politically vulnerable incumbents with discretionary resources that can be redirected to consolidate electoral support. Using data on EU fiscal allocations and electoral outcomes in twenty-six member states between 2000 and 2015, the analysis shows that higher levels of EU funding are associated with larger electoral margins for governing parties in countries with high executive corruption. These effects are absent in less corrupt contexts. The findings suggest that, under weak domestic accountability and limited enforcement, EU fiscal instruments unintentionally reinforce illiberal governance and weaken the regulatory objectives of cohesion policy. The article highlights the need to integrate political risk considerations more systematically into the design and implementation of EU spending conditionality.
The efficacy of the “future-proof” Unfair Commercial Practices Directive against dark patterns is undermined by the fragmented regulatory landscape introduced by the Digital Services Act. Article 25 DSA creates four weaknesses: a general prohibition that is vague compared to the UCPD’s detailed framework; a narrow subjective scope that excludes many online traders; an exclusion clause in Article 25(2) that replaces cumulative application with an opaque hierarchy; and slow soft-law mechanisms for updating the law in response to new dark patterns. To resolve these contradictions, this article proposes four targeted reforms: first, repurposing Article 25(1) DSA as an institutional gateway for DSA authorities to apply substantive UCPD rules using the stronger DSA sanctions and enforcement regime; second, extending the prohibition’s scope to all intermediary service providers; third, the repeal of Article 25(2) DSA; and fourth, granting the Commission the power to update the UCPD blacklist via delegated acts for a swift response to emerging dark patterns. These reforms, particularly in combination, offer a coherent, future-proof regulatory framework that restores the centrality of the UCPD, preserves the innovations of the DSA, and equips EU law to address both current and emerging forms of dark patterns.