Part of 2026 May 19, 2026 ·
--- days
-- hrs
-- min
-- sec
Content Hub Debate Article
Debate Sep 8, 2026 · 9 min read

The Complexity Question Europe's Digital Rulebook Must Finally Answer

The Complexity Question Europe's Digital Rulebook Must Finally Answer

Four days ago, CEPS (Centre for European Policy Studies) released a report that asks a question European policymakers have been avoiding: has the EU's digital regulatory apparatus become so complex that it undermines its own goals?

The numbers are stark. According to the CEPS Task Force documentation, EU laws related to digitalisation have more than quadrupled in the past dozen years, from roughly 20 to 88. Their average length has doubled in two decades. This is not a complaint about regulation per se. It is a question about whether the regulatory architecture has become so dense that businesses, citizens, and even regulators themselves struggle to navigate it coherently.

The debate here is not "regulation versus deregulation." That framing obscures more than it reveals. The actual disagreement is about something more specific: can the EU maintain its protective ambitions while reducing the friction that complexity creates?

What the Task Force Actually Examined

The September 4th launch event in Brussels presented findings from four full-day workshops held between January and April 2026. The Task Force brought together industry stakeholders, academic experts, and NGO representatives to examine flagship instruments: the GDPR (General Data Protection Regulation), the DMA (Digital Markets Act), the DSA (Digital Services Act), the Data Act, the AI Act, and NIS2 (the Network and Information Security Directive).

The methodology matters. Rather than producing another position paper arguing for more or less regulation, the Task Force applied what it calls a "customer experience" lens. How do businesses and citizens actually experience regulatory obligations? Where do overlaps create confusion? Where do inconsistencies force companies to make contradictory compliance choices?

This framing shifts the conversation from ideology to mechanics. A startup trying to launch an AI-powered health application must navigate the AI Act, GDPR, the European Health Data Space (EHDS), potentially the Medical Device Regulation, and sector-specific requirements. The question is not whether each of these regulations serves a legitimate purpose. The question is whether their interaction creates compliance costs disproportionate to the risks being addressed.

Three Types of Disagreement Worth Naming

The debate about EU digital regulation typically conflates at least three distinct disagreements. Separating them clarifies what is actually at stake.

The facts disagreement: How much does regulatory complexity actually cost? Industry groups cite high compliance burdens; regulators point to the economic benefits of harmonised rules across 27 member states. Both claims contain truth. The Task Force's emphasis on ex-post evaluation, using actual data rather than projections, represents an attempt to ground this debate in evidence rather than competing anecdotes.

The values disagreement: How should the EU weigh innovation against protection? Some argue that Europe's regulatory approach reflects a legitimate choice to prioritise citizen rights over speed-to-market. Others contend that excessive caution cedes technological leadership to jurisdictions with lighter regulatory touch. This is not a disagreement that data alone can resolve. It requires explicit acknowledgment that different societies can reasonably make different choices.

The incentives disagreement: Who benefits from complexity? Large companies can absorb compliance costs that crush smaller competitors. Consultancies and law firms profit from regulatory opacity. Regulators expand their mandates. None of this implies bad faith, but it does suggest that simplification faces structural resistance from actors who have adapted to the current system.

The Task Force's focus on SME (small and medium enterprise) burden reduction acknowledges this dynamic. As the Task Force documentation notes, SMEs are often suppliers to larger firms, meaning that compliance requirements cascade down supply chains in ways that formal exemptions may not address.

The RegTech Proposition

One of the more interesting threads in the Task Force's work concerns RegTech, the use of regulatory technology including AI to streamline compliance. The proposition is that the same technologies creating regulatory challenges might also help manage them.

This deserves careful examination. RegTech can reduce compliance costs by automating documentation, monitoring, and reporting. It can help regulators process information more efficiently. But it also raises questions about access and equity. If sophisticated compliance tools become necessary to navigate the regulatory landscape, does this advantage well-resourced actors over smaller players?

The Task Force's interest in sandboxes, controlled environments where companies can test innovations under regulatory supervision, reflects a broader search for mechanisms that allow experimentation without abandoning oversight. The question is whether these mechanisms can scale beyond pilot projects.

What Would Have to Be True

The strongest version of the simplification argument holds that the EU can maintain its protective goals while significantly reducing compliance friction. This would require several things to be true: that current overlaps and inconsistencies are genuine inefficiencies rather than necessary redundancies; that simplification can be achieved without creating new loopholes; and that the political will exists to resist adding new requirements faster than old ones are streamlined.

The strongest version of the caution argument holds that complexity is the price of comprehensive protection in a rapidly evolving technological landscape. This would require accepting that some compliance burden is inherent to operating in a jurisdiction that takes rights seriously, and that the alternative, lighter regulation, would expose citizens to harms that the current framework prevents.

Both positions contain legitimate insights. The Task Force's contribution is to move beyond this binary by asking: where specifically can simplification occur without sacrificing protection? The answer likely varies by regulation, by sector, and by the size of the entity involved.

The Coherence Problem

Perhaps the most significant issue the Task Force addresses is coherence. The EU's digital acquis (the body of accumulated legislation) was not designed as an integrated system. Different regulations emerged from different directorates, responded to different political moments, and reflect different regulatory philosophies.

The result is what Kai Zenner's dataset work has documented: a regulatory landscape that even specialists struggle to map comprehensively. The July 2025 CEPS dataset tracking EU digital laws runs to dozens of pages and requires regular updates as new measures emerge.

Coherence is not merely an aesthetic concern. When regulations conflict or overlap, businesses must make judgment calls about which requirements take precedence. These judgment calls create legal uncertainty, which in turn creates risk that discourages investment and innovation.

The Task Force's call for better ex-ante impact assessments and more objective ex-post evaluations addresses this directly. If new regulations were systematically evaluated for their interaction with existing rules before adoption, and if existing rules were regularly assessed for their actual effects, the regulatory system might evolve more coherently.

The Question That Remains

The CEPS Task Force has produced a serious contribution to a debate that often generates more heat than light. Its emphasis on evidence, its acknowledgment of trade-offs, and its focus on practical mechanisms rather than ideological positions represent the kind of work that productive disagreement requires.

But one question remains underexplored: who decides what counts as "proportionate" compliance costs? The Task Force's framing assumes that proportionality can be assessed objectively. In practice, judgments about proportionality reflect prior assumptions about how much protection is worth how much friction.

This is not a criticism. It is an observation that even the most rigorous technical analysis eventually encounters value choices that cannot be resolved by data alone. The Task Force's work clarifies the trade-offs. The political system must still make the choices.

For those tracking how Europe navigates the tension between regulatory ambition and practical implementation, the CEPS report deserves close reading. The Human × AI Europe Content Hub continues to follow these developments as the debate moves from task force recommendations to legislative reality.

Frequently Asked Questions

Q: What is the CEPS Task Force on EU digital regulation?

A: The CEPS Task Force is a working group that convened industry stakeholders, academics, and NGO representatives across four workshops from January to April 2026 to examine how flagship EU digital laws can be simplified and made more coherent without sacrificing regulatory effectiveness.

Q: How many EU digital laws currently exist?

A: According to CEPS documentation, EU laws related to digitalisation have grown from roughly 20 to 88 over the past dozen years, with their average length doubling in two decades.

Q: Which regulations does the Task Force examine?

A: The Task Force focuses on the GDPR, Digital Markets Act, Digital Services Act, Data Act, AI Act, Cyber Resilience Act, NIS2, and related instruments including the European Health Data Space and Data Governance Act.

Q: What is RegTech in the context of EU compliance?

A: RegTech refers to regulatory technology, including AI-powered tools, that can automate compliance documentation, monitoring, and reporting to reduce the administrative burden of meeting regulatory requirements.

Q: When was the CEPS Task Force report released?

A: The report was publicly launched at a CEPS event in Brussels on September 4, 2026, following four full-day workshops held between January and April 2026.

Q: What is the main goal of the Task Force recommendations?

A: The Task Force seeks targeted reforms that achieve simplification and consistency improvements with minimal sacrifice of regulatory effectiveness, while reducing disproportionate compliance burdens particularly on SMEs.

Enjoyed this? Get the Daily Brief.

Curated AI insights for European leaders — straight to your inbox.

Created by People. Powered by AI. Enabled by Cities.

One day to shape
Europe's AI future

Secure your place at the most important AI convergence event in Central Europe.