SYSTEM AUDIT · EUROPEAN CONTROL ARCHITECTURE · ACCOUNTABILITY 2026

Who Ordered This System? Europe’s Control Architecture Has No Single Architect

Europe is not building a secret central brain. It is building something politically more convenient: separate registries, wallets, authorities and platform duties that can produce combined effects through standards, identities, queries and private gatekeepers. Precisely because nobody ordered the whole system, nobody feels responsible for the whole system.

30 min read
Share article
Founder overlooking a European city architecture of separate institutions and connected access points
EUROPE 2026 · SEPARATE SYSTEMS, COMBINED EFFECTS, DISTRIBUTED RESPONSIBILITY
Operational statusESP & CIR operational since June 12, 2026 · full implementation expected by 2027
No single databaseEUDI · EES · AMLA · DSA · digital euro remain separate legal regimes
Real connective powerIdentifiers · query portals · biometrics · risk models · private gatekeepers
NBF testWho can stop, correct and practically bridge a false decision?

Europe’s control architecture is not emerging from one secret master plan. It is emerging from the addition of legitimate individual purposes. The Commission, Parliament, Council, member states, agencies, supervisors and private providers each control only part of the chain. Shared identifiers, interoperable queries, technical standards and obligated gatekeepers can nevertheless turn those parts into an effective access architecture. Its most dangerous property is not central omniscience. It is responsibility without an owner of the whole outcome.

What is real

In the border, visa, migration and security domain, the EU already connects separate systems through a search portal, identity repository, biometric matching service and multiple-identity detector. One authorized query can reach several systems.

What is not established

There is no single 2026 EU database covering every citizen, no enacted universal asset register and no general social-scoring system. EUDI, AMLA, DSA, the digital euro and chat-control proposals must not be relabelled as an already integrated super-system.

Why it still matters

Power does not require full integration. It arises when the same person is recognized across identity, account, device, platform and border events, several actors contribute results, and a public or private interface decides access.

In this analysis01 · Who ordered this system? The honest answer is more uncomfortable than a conspiracy02 · Who actually decides in the EU? ‘Brussels decided’ is an excuse, not an accountability map03 · The connective layer is no longer a theory: one input, multiple systems04 · EU Digital Identity in 2026: voluntary use, mandatory acceptance—and a new identity node05 · AMLA, bank-account registers and the asset-register claim: precision makes the warning harder06 · DSA and AI Act: control, protection and counter-control occupy the same framework07 · What is not connected in 2026—and why that boundary must be defended08 · Why distributed power can be harder to stop than central power09 · The NBF Accountability & Access Audit: govern dependency rather than disappear10 · The false reassurance is that nobody planned the whole system
01

Who ordered this system? The honest answer is more uncomfortable than a conspiracy

Nobody ordered the whole system. That is the governance problem.

Monday, 8:12 a.m. An identity is checked at a border, a bank account enters enhanced review, a platform reduces reach, and a digital credential must be confirmed again. Four events, four legal bases, four responsible bodies. To the person affected, this is one loss of decision capacity. To each institution, it is merely its properly administered segment.

The old political reflex looks for an architect behind a closed door. Europe rarely works that way. The Commission develops proposals. Parliament and Council—including member-state governments—amend and adopt them. National authorities implement them. EU agencies operate technical systems. Banks, platforms, wallet providers and identity services translate rules into acceptance, rejection, suspension, reporting or additional review. Nobody owns the whole structure. Everybody builds part of it.

Distributed creation is democratically preferable to a secret order. It is not reassurance. When each project has a plausible purpose—fraud prevention, security, convenience, child protection or anti-money laundering—the combined effect rarely receives its own vote. Europe approves components while almost nobody approves the finished building as a whole.

The NBF diagnosis is falsifiable. A control architecture exists where several actors can jointly influence whether a person remains identifiable, bankable, visible, mobile and capable of effective appeal through rules, data and interfaces. If interoperability remains narrow, alternatives stay strong and correction works within the relevant deadline, the thesis weakens. Those are the points that must be tested.

No single authority sees everything. Several authorities can see enough to reorder access, scrutiny and decision. That is less cinematic than a central register—and institutionally far more credible.

Europe votes on components. Almost nobody votes on the effect of the finished building.

Alexander Erber
02

Who actually decides in the EU? ‘Brussels decided’ is an excuse, not an accountability map

Responsibility begins by separating proposal, political consent, technical standard and national execution.

Under the ordinary legislative procedure, the Commission normally holds the right of initiative. Its proposal becomes law only when the European Parliament and the Council adopt the same text. Member-state governments sit in the Council; working parties of national experts and COREPER prepare positions. Parliamentary committees and rapporteurs shape the Parliament’s position. Trilogues can strongly influence compromise, but their agreements still require formal approval.

Then a second architecture begins. Regulations, delegated and implementing acts, technical standards, guidelines, procurement, certification and national procedures translate political language into operational reality. This is where a mandatory field, error duration, accepted document, escalation threshold and reachable correction desk are determined.

Politics prefers abstract safeguards: voluntary, proportionate, purpose-limited, respectful of fundamental rights. Technology needs hard yes-or-no decisions. Is the document valid? Does the biometric match? May the transfer proceed? Must the content be removed? Once an open legal standard becomes a digital gate, the human discretion behind the interface contracts.

Every critical function therefore needs six named roles: initiator, legislator, operator, standard setter, user and correction authority. If one is missing, the map is incomplete. If all six point to one another, the citizen is not poorly informed; the architecture is poorly accountable.

Evidence baseCouncil of the EU · Ordinary legislative procedure (opens in a new tab)Architectural conclusions are identified as NBF analysis.
NBF Control-Architecture Equation

Cumulative control power rises as connection becomes easier and correction becomes harder.

01Identifiability

02Data query

03Decision automation

04Gatekeeper power

05Dependency

06Correction latency

The more critical functions share identity and review chains, the less a central order is needed to produce centrally felt outcomes.
03

The connective layer is no longer a theory: one input, multiple systems

A capability once dismissed as exaggerated future anxiety became operational in June 2026.

The border, visa, asylum, migration and security databases operated by eu-LISA were built for different purposes and remain legally separate. The official objective of interoperability is nevertheless to make them work together within their legal limits. The European Search Portal and Common Identity Repository entered operations on June 12, 2026; full operational capacity is expected by 2027.

The European Search Portal is a distributed search engine and message router. An authorized officer enters data once; the portal can query EES, VIS, ETIAS, Eurodac, SIS and ECRIS-TCN alongside Europol and Interpol databases. User profiles are meant to restrict which results a border guard, migration officer or other official may see. The portal does not, according to eu-LISA, store the retrieved personal data. It still changes access fundamentally: separate logins become a shared query surface.

The Common Identity Repository extracts selected biographic and travel-document data relating to third-country nationals from separate silos into a shared identity file. The shared biometric matching service works with fingerprint and facial templates. The Multiple-Identity Detector links results and flags potential multiple identities; a yellow link requires manual verification.

This is not proof of a total database covering every EU citizen. It is proof of connective power. Asking whether every raw record sits in one physical store misses the decisive question: can one interface query several systems, link identities and delay or escalate a real-world event?

Role profiles, purpose limits, hit/no-hit procedures, logging and manual review belong in the balance. They must be tested as functions. A yellow link is benign only when correction is fast, evidenced and reachable. A right to rectification that works after the missed flight exists in law and fails in operation.

Separate databases do not produce separate effects once a common query brings them into the same decision.

Operator at a role-based query across separate European information systems
INTEROPERABILITY · ONE INPUT CAN REACH MULTIPLE SYSTEMS
04

EU Digital Identity in 2026: voluntary use, mandatory acceptance—and a new identity node

‘Voluntary’ answers the legal question. It does not settle practical dependency.

The European Digital Identity Regulation requires member states to provide at least one European Digital Identity Wallet. Use by natural persons remains voluntary; non-users may not be disadvantaged, and alternative identification methods must generally remain available. Describing the framework as an enacted wallet mandate for every citizen is legally wrong.

Acceptance duties are nevertheless being created. Public bodies and specified private relying parties must accept the wallet on the statutory timetable when the user requests it. The individual may choose, while a growing range of counterparties must prepare around the same standardized identity channel. Voluntary use can become attractive and ultimately infrastructurally dominant.

A wallet may communicate identity attributes and digital credentials more selectively and securely than sending full document copies. It can reduce unnecessary disclosure. The same wallet can also become the common vestibule to public services, signatures, onboarding, age verification, contracts and later services. The risk lever is not ownership of the app; it is the number of critical doors standing behind it.

The hard test is whether the alternative remains functional in practice. Are in-person, paper or other digital routes genuinely available? How is a compromised wallet suspended and restored? Who acts for a child, parent or incapacitated founder? Can a false identity result be corrected without freezing several areas of life at once?

Evidence baseEUR-Lex · Regulation (EU) 2024/1183 · European Digital Identity (opens in a new tab)Architectural conclusions are identified as NBF analysis.

What is in force, what operates—and which shortcut exceeds the evidence

ComponentDefensible findingUnsupported shortcut
EU interoperability
ESP and CIR operational since June 12, 2026; full implementation expected by 2027
One EU database contains everything about every citizen
EUDI Wallet
Member-state provision duty, voluntary citizen use, expanding acceptance duties
Every EU citizen must hold a wallet in 2026
EES
Biometric entry/exit system for covered third-country nationals
Every movement of every EU citizen is stored in EES
AMLA & account registers
Coordination, standards, FIU cooperation and national account lookup
AMLA runs a real-time register of all private wealth
DSA & AI Act
Platform duties, supervision, user rights and limits on high-risk AI
A general EU opinion or social score has been enacted
Combined effect
Separate systems can accumulate effects through identity, standards and gatekeepers
Only one physical database can produce control
05

AMLA, bank-account registers and the asset-register claim: precision makes the warning harder

The EU has expanded financial query capacity. That does not make a universal asset register an enacted fact.

Anti-money-laundering control already operates through private gatekeepers. Banks and other obliged entities identify customers, verify beneficial owners, monitor transactions and report suspicious activity to national Financial Intelligence Units. National central bank-account registers or retrieval systems allow competent authorities to identify holders of certain accounts. This infrastructure is real, and it affects access before any court establishes wrongdoing.

AMLA centralises part of the supervisory architecture in Frankfurt. It develops standards and guidelines, coordinates national authorities and FIUs, supports cross-border analysis and manages FIU.net. Direct supervision of selected high-risk cross-border financial entities is scheduled to begin in 2028, with 40 obliged entities selected in 2027. AMLA expressly says it does not contact citizens, intervene in individual citizen transfers or fine individual citizens.

The customer can still experience the power effect. A European authority sets standards, a national supervisor examines the institution, the institution translates risk into controls and an automated model produces a hit. The client sees a request, delay or rejection—not the institutional division of labor. Private compliance becomes an execution layer for public rules, amplified by liability and reputation incentives.

The cited framework does not establish a 2026 central EU register combining every citizen’s property, securities, precious metals, art, vehicles and cryptoassets in real time. Presenting one as fact destroys the credibility of valid criticism. The precise conclusion is strong enough: identity, account, ownership, transaction and reporting data are becoming more structured, standardized and queryable within several legal regimes.

The response for internationally mobile founders is not invisibility. It is evidence-chain integrity. Source of wealth, economic purpose, tax status, ownership, authority and transaction logic must tell the same story across jurisdictions and institutions. In a risk-based architecture, poor documentation is not privacy. It is a self-built access failure.

The EU does not need a universal asset register to make an unexplained asset practically immobile.

Alexander Erber
Advisers around an architectural model of separate institutions, data routes and correction authorities
ACCOUNTABILITY MAP · WHO SETS THE RULE, WHO DECIDES, WHO CORRECTS?
06

DSA and AI Act: control, protection and counter-control occupy the same framework

Anyone who sees only censorship or only protection has not mapped the mechanism.

The Digital Services Act imposes procedures against illegal content and systemic-risk duties on platforms. Very large platforms must assess and mitigate risks including effects on fundamental rights, media pluralism, elections and minors. The Commission and national Digital Services Coordinators enforce the rules. Regulatory pressure therefore reaches the private systems that govern reach, advertising, account access and moderation.

The DSA does not order universal scanning of private messages and does not create a government opinion score. It does require platforms to define, measure and address risks at scale. The governance question follows: which content, users and behavioral patterns enter risk models, and who can detect when over-compliance, error or political pressure has moved the threshold?

The DSA also creates counter-rights: reasons for moderation decisions, internal appeals, out-of-court dispute settlement, advertising transparency and, on major platforms, a non-personalised feed option. These are not decorative. They are the correction layer that determines whether platform power is merely regulated or made accountable.

The AI Act is not a blanket license for automated control either. It prohibits specified practices including covered forms of social scoring and subjects high-risk uses in essential services, law enforcement, migration and borders to duties around risk, documentation, logging and human oversight. A protection in legislation is only as strong as classification, audit and enforcement. Architecture asks whether the safeguard constrains an actual decision path.

07

What is not connected in 2026—and why that boundary must be defended

Strong criticism carries a map of its own limits.

The EUDI Wallet, EES, digital euro, AMLA, DSA, AI Act and chat-control debate are not modules in one operating platform. They have different legal bases, purposes, controllers, affected populations and timelines. The digital euro has not been issued. Any permanent CSAR regime must be described according to its actual legislative status. AMLA supervises obliged entities, not every citizen’s private life.

This distinction is not institutional courtesy. It protects the analysis. Mixing proposal, operation, technical possibility and potential future linkage lets every valid concern be dismissed through one factual error. Alarmism is not brave. It makes life easier for anyone who prefers opacity.

It would be equally weak to infer separate life effects from separate legal acts. The same person meets several systems. The same identity, device, address, company and beneficial owner can appear in different review chains. Connection arises not only through an API. It can arise through common identifiers, standardized evidence and decisions used as inputs to later decisions.

The 4.0 line is therefore clear: we do not allege a connection we cannot show. We do not ignore a documented function because it is described in reassuring language. Where an authority can query, a provider can review, a model can flag or a gatekeeper can refuse, we identify actor, legal basis, mechanism and correction route.

Precision does not remove the edge. Precision makes the edge defensible.

08

Why distributed power can be harder to stop than central power

A monopoly has an address. A chain of responsibilities has excuses.

Centralised systems are visible. Parliament, courts, media and the public can target an operator, database and decision. In a federated architecture, the legal basis sits with institution A, the standard with B, operation with C, risk assessment with D and the rejection with E. Each can correctly explain why it is not solely responsible.

Fragmentation may constrain power because no actor may do everything. It may also harden power because correction has to cross several organizations. A bad record becomes a false match, the match becomes enhanced review, review becomes delay, and delay becomes a lost transaction. No stage expropriates the owner. The chain can still remove the economic value of the right.

Private providers intensify the asymmetry. Banks, platforms and identity services carry fine, liability and reputation exposure. When uncertain, they may review longer, report more or reject conservatively. The state needs no secret blocking order. An incentive system in which a false acceptance is more dangerous than a false rejection generates over-compliance on its own.

Privacy law alone is therefore insufficient. The architecture needs functional protection, decision deadlines, intelligible reasons, evidence preservation, human escalation and an independent route during the dispute. Asking only whether data processing was lawful can miss a lawful architecture that leaves the person practically unable to act.

09

The NBF Accountability & Access Audit: govern dependency rather than disappear

Sovereignty comes from correctable identity, coherent evidence and independent routes—not invisibility.

First, map functions. Which actions preserve payment, mobility, communications, signature, corporate authority, asset access and family decision capacity? For each function, name the primary route, operator, legal basis, identity evidence, data source and rejection triggers. A product inventory is not enough. The question is what must execute under pressure.

Second, mark shared nodes. Do the bank, wallet, government service and signature use the same phone, number, email or identity source? Do personal and company payments depend on the same individual? Are identical translated records used in several countries? Redundancy that fails at the same node is merely a duplicate interface.

Third, prove correction. Who accepts the case? Which reference numbers, logs and records exist? What deadline applies? Which human authority can override an automated hit? What remains operational during review? The test does not end with a right to complain. It ends when the function is restored.

Fourth, keep alternatives real. A second bank must know the profile. An alternative identity path must actually be accepted. Powers of attorney must be current and usable across borders. Critical records need accessible copies and named owners. Family and corporate representatives must know how to act, not merely that they theoretically may.

Fifth, monitor change signals. Implementing acts, technical standards, data fields, acceptance duties, supervisory guidance and provider terms can change the equation without a major political headline. Architecture is never built once. It is versioned, tested and re-approved after every material rule change.

If you must hide your identity, you do not have sovereignty. If you cannot correct a false identity result, you do not have it either.

Alexander Erber
10

The false reassurance is that nobody planned the whole system

Unplanned cumulative effect is still cumulative effect.

Europe needs digital identity, secure borders, anti-money-laundering controls, platform accountability and rules for high-risk AI. A modern legal order cannot operate these functions through paper files and goodwill. The question is not whether systems may exist. It is what power their connection creates and who limits that power when the chain is wrong.

‘These are separate systems’ is often factually correct and strategically incomplete. Separate systems can examine the same person in sequence. They can use the same identifiers. They can transmit effects through query portals, standards, gatekeepers or later decisions. The issue is not only where data sits. It is where one decision becomes a precondition for the next.

‘Use is voluntary’ can likewise be true and practically weak. Voluntariness loses substance when the alternative is slower, costlier or barely accepted. Rights lose substance when correction arrives after the economic deadline. Ownership loses substance when no payment or disposal route works. Architecture translates formal rights into executable capacity—or its opposite.

Who ordered this system? Not one actor. It emerged from many individually approved components. That is precisely why somebody must now audit the whole picture. Not to portray Europe as darker than it is, but to prevent a technically capable legal order from sending citizens through a chain whose combined effect nobody wants to own.

The decisive democratic question is not only who approved a system. It is who owns its cumulative effect.

Four findings that would materially narrow our diagnosis

A defensible system critique must state when it would be wrong or too severe.

Durably independent alternatives

Non-digital and alternative digital routes remain fast, affordable and practically equivalent.

FALSIFIER · DEPENDENCY FALLS

Strict non-linkability

Law and technology effectively prevent new identity, finance, platform and border systems from being linked across functions.

FALSIFIER · CUMULATION FALLS

Fast effective correction

Errors are resolved within the economically relevant deadline with human ownership and functional continuity.

BOUNDARY · ACCESS RISK FALLS

Visible change paths

Material functional expansion requires transparent political approval rather than a quiet standard or provider change.

BOUNDARY · DRIFT IS CONSTRAINED

What specialists must validate separately

No Borders Founder maps the system. Legal, privacy, security and case-specific conclusions remain with the accountable professionals.

EU & administrative law

Legal bases, competence, purpose limitation, access, rectification, remedy and national implementation.

Privacy & cybersecurity

Data flows, identifiers, linkability, user profiles, logs, device binding, recovery and attack surfaces.

Banking & compliance

KYC, beneficial ownership, account registers, monitoring, reporting, provider incentives and escalation.

Family & corporate governance

Authority, representation, record ownership, independent access and incident exercises.

Not individual legal, tax, investment or privacy advice. Case review and implementation belong with appropriately qualified professionals.

01

Name the actors

Document initiator, legislator, operator, standard setter, user and correction authority for every critical function.

02

Expose shared nodes

Compare identity, device, provider, account, data source and authorized person across personal and business functions.

03

Test correction and fallback

Count the deadline, accountable desk, evidence and functioning alternate route—not the abstract right to appeal.

18-point system audit

Can your architecture survive a false match?

  1. Which seven functions must remain executable?
  2. Which identity opens each function?
  3. Which systems use the same identifiers?
  4. Which functions depend on the same phone?
  5. Who created the source data?
  6. Who may query it?
  7. Who makes the operational decision?
  8. Is the decision automated, supported or human?
  9. Which reasons are disclosed?
  10. Which logs and evidence are retained?
  11. Who can override a hit?
  12. Which correction deadline is economically tolerable?
  13. What works while appeal is pending?
  14. Which alternative identity route has been tested?
  15. Which second bank or platform knows the profile?
  16. Who acts if the founder cannot?
  17. Which rule change triggers review?
  18. When was the entire chain last rehearsed?

Reassess after new interoperability components, EUDI rollout, AMLA standards, DSA or AI Act case law, provider changes, and every identity, access or data incident.

EU control systems in 2026: the questions people actually search

Is there a central EU control system in 2026?

Not as one universal database or authority. Multiple systems and regimes can nevertheless produce combined effects through common identifiers, standards, queries and gatekeepers. Formal interoperability is already operating in the border and security domain.

Is the EU Digital Identity Wallet mandatory in 2026?

Member states must provide wallets, while citizen use is voluntary under the EUDI Regulation. Alternative identification must remain available. Specified public and private relying parties do face acceptance duties.

Does the EU have an asset register?

No enacted universal real-time register of every citizen’s assets is established by the cited framework. National bank-account registers, beneficial-ownership and reporting systems are real, and standardisation and query capacity are increasing within specific regimes.

Can an EU authority search several databases at once?

The European Search Portal allows authorized users to enter data once and query several border, visa, migration and security systems. Role profiles and each system’s legal basis are intended to limit what a specific user may see.

Who makes EU laws?

The Commission normally proposes. The European Parliament and Council must adopt the same text under the ordinary legislative procedure. Implementation, standards, agencies, national authorities and private providers then shape practical effect.

Is social scoring legal in the EU?

The AI Act prohibits social scoring in the forms it defines and restricts other high-risk uses. Banks, platforms and authorities may still use lawful risk models for narrower purposes; these should not be mislabeled as a single government citizen score.

Does AMLA control private bank accounts?

AMLA coordinates supervision and FIUs, sets standards and will directly supervise selected obliged entities. It says it does not contact citizens or process their individual transfers. Front-line customer controls remain primarily with obliged institutions and national bodies.

Are EUDI, EES, the digital euro and chat control connected?

Not as an already integrated system. They have different laws, purposes and operators. The strategic issue is shared identity, device, provider and decision dependencies—not an unsupported claim of total integration.

How can founders protect digital sovereignty?

Through coherent evidence chains, independent payment and identity routes, current authority documents, separated device and provider dependencies, documented correction paths and repeated incident tests—not illegal concealment.

Primary sources current through September 10, 2026. The analysis separates law in force, operational systems, scheduled buildout, technical capability and possible cumulative effect.

  1. eu-LISA · Interoperability of EU information systems (opens in a new tab)Official operational status for ESP, CIR, shared BMS and MID, including role-based queries across separate border, visa, migration and security databases.
  2. EUR-Lex · Regulation (EU) 2019/817 (opens in a new tab)Legal basis for interoperability between EU information systems in the fields of borders and visas.
  3. European Union · Entry/Exit System (opens in a new tab)Official description of EES functions, biometric enrolment and operational status.
  4. EUR-Lex · Regulation (EU) 2024/1183 · European Digital Identity (opens in a new tab)Binding legal framework for European wallets, voluntary use, alternative identification, trust services and acceptance obligations.
  5. AMLA · Mission, responsibilities and timeline (opens in a new tab)Official boundary around AMLA, FIU coordination, standards, direct supervision of selected obliged entities from 2028 and the absence of direct citizen contact.
  6. European Commission · AML/CFT at EU level (opens in a new tab)EU framework for due diligence, transaction monitoring, suspicious-transaction reporting and national bank-account registers.
  7. Council of the EU · Ordinary legislative procedure (opens in a new tab)Official account: the Commission proposes; Parliament and Council negotiate and adopt; informal trilogue agreements require formal approval.
  8. European Commission · Digital Services Act (opens in a new tab)Platform duties, enforcement by the Commission and national coordinators, and user rights against moderation decisions.
  9. European Commission · AI Act (opens in a new tab)Risk-based framework, prohibitions including social scoring, and requirements for high-risk applications.
Alexander Erber, founder of No Borders Founder
ALEXANDER ERBER · FOUNDER · NO BORDERS FOUNDER

The problem is not that one architect controls Europe. It is that many architects can add power without owning the combined outcome.

I have no use for the comfortable story of a secret switch in Brussels. It is too simple and therefore too easy to disprove. The real architecture is more demanding: a parliament legitimizes a rule, an agency builds an interface, a standard defines the record, a bank or platform sets the threshold, and a person loses time, access or visibility. Every stage may be lawful, reasonable and limited on its own. Together they can still create power nobody owns as a whole. Our job is not to call these systems demonic. It is to expose their handoffs—and make sure ownership, mobility, communication and decision do not depend on one uncorrectable chain.

ACCOUNTABILITY & ACCESS · FOUNDERS, FAMILIES & BUSINESS

Map the control points before a false match explains your architecture.

No Borders Founder connects identity, banking, mobility, communications, authority and asset access in one decision map—with named gatekeepers, correction paths and independent second lines.

Check mandate fitExplore private-client capabilities