This achievement is impressive. But the sheer scale and speed of regulatory activity have created a new challenge: ensuring that this expanding rulebook remains coherent, effective and manageable for regulators, businesses and citizens. As the Draghi report made clear, simplification is no longer a technocratic nicety – it's a precondition for productivity and competitiveness.
This is why a CEPS Task Force convened more than 20 experts from industry, academia, civil society and the European institutions. They examined this landscape in-depth and the central message is clear: the EU's digital regulation has reached a point where coherence, capacity and coordination are now just as vital as new legislation.
The question isn't whether the EU should regulate the digital world – it already has. Rather, it's how well these rules work together and whether they can be effectively enforced. A rapid expansion of digital legislation
From 2012-24, the number of EU digital laws grew from 20 to 88. The DMA and the DSA have reshaped platform governance and competition. The AI Act introduced the world's first horizontal rules for AI. Cybersecurity legislation has expanded through NIS2, the Cyber Resilience Act , the Digital Operational Resilience Act and the forthcoming Digital Networks Act . The GDPR is rightly called Europe's regulatory gold standard. While gold is precious, it's also heavy.
Each of these laws responds to real needs. Yet taken together they form a complex and interconnected regulatory landscape that even the best experts struggle to navigate. This complexity isn't merely theoretical, it impacts enforcement, compliance and the functioning of the Single Market. A geopolitical backdrop that raises the stakes
Rethinking the EU's digital laws and regulation in an increasingly volatile world isn't easy. The US remains the EU's main tech supplier but it's no longer a predictable and reliable partner.
Now, the EU must focus on strengthening resilience and supply chain diversity, pursuing strategic autonomy in specific niches and cooperating with like-minded partners. How well the digital rulebook works is indispensable for achieving the EU's strategic autonomy ambitions. Institutional capacity under pressure
The rapid expansion of the EU's digital legislation has created major challenges for Member State authorities and regulated firms. Many digital laws require specialised technical expertise, continuous monitoring and coordination across multiple authorities and jurisdictions.
There are also big differences in enforcement models. The DMA is centralised at EU level, the DSA relies on a hybrid structure, the AI Act has introduced a new institutional actor (the AI Office ), cybersecurity rules involve multiple national authorities, and enforcing the GDPR depends on independent supervisors.
Consequently, enforcing the EU's digital rulebook in Member States is uneven and imposes substantial compliance burdens on firms – especially those operating cross-border.
The issue isn't that institutions lack commitment; it's that regulatory ambition has grown faster than firms' and Member States' ability to implement. Better regulation tools under strain
Impact assessments, evaluations and simplification are central to the EU's Better Regulation agenda. But the volume and speed of legislation have strained these processes.
Only around 40 % of legislative proposals come with impact assessments, often on unconvincing claims of urgency. Ex-post evaluation fares little better: many digital laws haven't yet been evaluated at all, and the data needed to do so properly is often not collected.
The Digital Omnibus illustrates both the promise and the risk. Simplification is needed – but it isn't simple. Any substantive legislative changes should be grounded in evidence and backed by proper impact assessments. Better Regulation tools require sufficient time, data and analytical capacity to function. Single Market tools are under-performing
The EU's digital regulation and the Single Market's functioning are deeply intertwined. And while digital regulation aims to strengthen the Single Market by reducing fragmentation and ensuring consistent rules across Member States, the tools designed to support cross-border implementation – notably the SOLVIT network and the Single Digital Gateway – haven't reached their full potential.
Varying national practices continue to create obstacles for businesses and citizens while enforcement differences affect the level playing field. Our Task Force report doesn't address the Single Market, but digital regulation and the Single Market's functioning are deeply intertwined. A condensed set of core recommendations
First , the numerous changes that this report puts forward for specific laws – DMA, DSA, AI Act, and GDPR – merit serious attention.
Second , the EU must strengthen coherence and coordination across digital laws to ensure overlapping regimes operate consistently and don't impose contradictory obligations, especially where they interact (e.g. data governance, algorithmic transparency, interoperability).
Third , the EU must provide firms with the guidance and legal certainty they need. This includes clear indicators of success for the DMA, verifiable outcome indicators and audit guidance under the DSA, harmonised standards and practical, example-based guidance under the AI Act.
Fourth , institutional capacity must be bolstered both qualitatively and quantitatively, both at EU and Member State level. Authorities must have the expertise needed to supervise complex digital systems.
Fifth , the European Parliament and the Council must step up to pull their weight in implementing the Better Regulation framework. Process improvements are needed for impact assessments, evaluations and burden reduction tools such as REFIT and the Omnibus.
Finally , unnecessary complexity in the acquis must be systematically reduced following good process. The goal isn't to deregulate, but rather to make regulation better and more streamlined. Substantive changes grounded in evidence – purported urgency simply cannot be an excuse for sloppy work. A moment for consolidation and coherence
For sure, Europe's digital regulatory framework is broad, ambitious and globally influential. But its effectiveness depends on its coherence across regimes, sufficient institutional capacity and consistent implementation across Member States. While the EU has built the foundations of digital regulation, the next step is to ensure these foundations support a system that's effective, coordinated and sustainable.
The challenge ahead isn't to regulate more but to regulate better, with clearer structures, stronger institutions and a much more coherent approach to the digital world. About the Author:
J. Scott Marcus is an economist, engineer and public policy analyst. He is an Associate Senior Research Fellow in the Global Governance, Regulation, Innovation and Digital Economy (GRID) Unit at the Centre for European Policy Studies (CEPS) and a Professor (part-time) and member of the Scientific Committee of the Centre for a Digital Society, European University Institute (EUI / RSCAS).
(0)Comments