Hello and many thanks to the organiser for inviting me and giving me the chance to speak to you a little bit about what is happening in Brussels, to give you feedback what policymakers right now discussing, are trying to improve. And with my presentation, I want to do three things.
First of all, I want to push back a little bit against this assumption that is at the moment very strong in Brussels, but also in other, especially political capitals, so that there is over-regulation, which I think there is, at least partially, but that basically certain single laws are kind of holding our economy back, are the only problem that is out there restraining us and so on and so on.
In the title, you see the reference to the GDPR, and as many of you have probably read in the Draghi report and in many other reports, it's often the GDPR, but also the second law that I have worked on, the European AI Act, that are really singled out as, let's say, the legislative troublemakers. And as I said, so after working now for nine years in the European Parliament and being involved in the AI Act, also in liability law and GDPR, in e-privacy, in a lot of other digital laws, I do see the points that those people are making.
There is a lot of truth in it, and I would agree in a way that we definitely need to do a lot of fixes, that we should have a second look in many of our laws, but it should not be all. Maybe before I'm going more in an assessment or commenting mode, just to give you an overview, I think last time I was here two years ago, I showed you my so-called blue wall or green wall, with 101 pieces of applicable legislation, now a more, let's say, granular overview, which however shows that, again, we were quite busy in Brussels.
You could argue that the real start of digital policymaking happened in 2010 with the digital agenda from Commission President Barroso, and then it went further with Juncker's digital single market strategy, Fond Alliance, shaping Europe's future, making Europe fit for the digital age, and now it's all about our competitiveness also in the digital field. If you are looking deeper into what the Commission and the European institutions were working on, you see, however, that a lot of things are kind of popping up in every legislative term.
You are questioning yourself why is cybersecurity done in 2010, why again in 2015, why again in 2019? It could be that the, let's say, digital advances are so fast that we need to do constant updates, but it could also be the case that we kind of repeated certain mistakes that we had within the lawmaking machine, certain flaws that in the end led to a situation where our 101 laws maybe didn't work in practice as we have planned. And with those laws, and this is going back to the title of my presentation, there were also a lot of governance bodies popping up.
Almost every law has its own agency, its own advisory body, its own network, and according to Draghi, there are even more enforcement bodies when it comes to the member states. So definitely there is a lot of complexity. But now to my first point and concluding the first part of my presentation, to say again it's only one law, it's the digital laws from the European Union that are single-handedly fault for all of our problems is, I think, like so often in politics, too simplistic, is not really showing the bigger picture.
Because if you are checking those laws, so I added there basically, let's say, the most famous ones, well, at least the ones that I came across with and that were the household names in the Juncker term, but also in the von der Leyen 1 term, like the GDPR, like DSA, like Data Act, Cyber Resilience Act, and so on, you see that there were actually sound principles that many of the problems that those laws were trying to address are also that the, let's say, mechanisms that those laws have introduced make sense.
So the problem is not so much what is in those laws often, but more how the tons of digital laws are working together, how they are overlapping, interacting, and so on. And with all our focus on the number of laws and certain legal problems, there is actually a huge enforcement problem. And as you saw in the title of my keynote, that with all the new rules, we again created a huge number of entities that are taking care of those rules.
But it's, again, a rather fragmented system, very different capacities. It's often also unclear what exactly is the role of certain entities or certain bodies.
So, again, my key statement would be to blame the GDPR for all the problems is, again, two-one-sided. If you really want to put it down to a few core reasons, I would say it's in the end, yes, the unwillingness to improve certain concepts in the law. And you saw it now with the GDPR reforms that are currently ongoing, where finally some longstanding problems are discussed and maybe fixed.
But another huge problem that so far is not really on the agenda is the incoherence of laws that I have already mentioned, all the overlaps, all the contradictions, and so on, that is currently not really on the agenda. And the third point, this significant enforcement gap, so that we have strong words in the laws on paper, but that are not really enforced in practice. Max Schrems, I think, is shortly after me on the panel.
Neub, so his organization, came up with this shocking number. I think it's a bit older now.
Nowadays, it's maybe a bit better. But I think two, three years ago, it was 99.93% that the Irish DPA was rejecting. There are also other numbers coming from the EDPD, so from the European Data Protection Board, where you see the differences between member states when it comes to enforcement. Those three numbers coming from national DPAs that are actually quite active, compared to many, many others that have often a single number of cases.
And you have also in the laws, but also in enforcement, often the problem with safe declaration, with non-binding rules, where, yeah, the legislator, but also the enforcer, doesn't really have a clear idea how to engage with it. Again, bringing me back to the point that just blaming a law is probably too easy.
I want, because I cannot speak for one hour whatsoever, now really focus on the enforcement part, because I feel it's not something that in Brussels many people talk about. You see it now also in the simplification strategy of the Commission, that enforcement is basically completely overlooked. It's all about certain compliance burdens.
Again, I do think that they exist and that we should reduce it, but the question of governments and so on are not addressed at all. Why this is a problem?
Well, you see here an overview of issues that currently are leading to those numbers, but also other problems that you are aware of. We have a geopolitical trap, so there are certain cases where the European Union, but maybe also other member states that are responsible to enforce a certain case, are thinking about Ukraine, are thinking about trade agreements, are thinking about other geopolitical points, which then leads to pressure on the enforcement authorities to maybe not start with a case or sanctionize a certain company.
We have in general a very politicized enforcement, especially in the European Union, where party politics is playing quite a role when it comes again to the identification of certain cases to the final enforcement. I talked a lot already about the fragmentation. I slightly mentioned also the capacity issue when I was talking about the different numbers. It's still the case that now going to data protections that certain authorities basically almost do not have any funding.
They are struggling to prepare cases, to even establish a well-functioning office with IT and infrastructure and so on and so on. And we have, of course, also cases where national protectionism is leading to no enforcement or to enforcement that we can rather be confident to not say is neutral or objective enough. And what the European Commission and the European Union did in the past years, especially with the DMA and the DSA, was actually a first reaction to what I was now outlining, which is an issue since 2010, so the real beginning of digital policymaking in Europe.
And the Commission in particular proposed to centralize enforcement powers. You see it now with the first DMA fines against Apple, 500 million. You also see in European Court of Justice, who now approved certain cases, so the Commission didn't lose all the cases again, apparently prepared the case better. Evidence that was collected was better, so there are definitely improvements.
However, if you are now on the downside looking at how big those fines are, especially when it comes to US tech companies, but also Chinese tech companies or even our own companies, often those fines are rather small. You feel like this will not really hurt them. There's one fine from X with 120 million. There are sometimes also caps, like in Italy, when it comes to fines. And I talked in particular about the capacity issues. The good news is why the centralization approach happened in the last legislative term under von der Leyen.
In this legislative term, there is even more movement and even more parts of those three issues that I mentioned at the beginning are now being addressed in Brussels. Already in the end of last term, as many of you know, there was the GDPR procedure regulation. I don't know if Max will talk about it, but there are definitely very different opinions about this file, if it's working or if it's not. What I can say as someone who was involved also in this legislative file, the amount of evidence collection was rather slim. It was another law that was pushed through the system as fast as possible.
And now no one really knows if those new rules are really working in practice. But at least there was commitment to change something. And the Data Act, with all the new interoperability rules and so on, is another, let's say, initiative from the last term, which, however, now is being implemented. Set back to our first questions that you saw on the first slide, if law and especially the GDPR is harmful for our AI development, is at least an attempt to solve it.
And I mentioned the digital omnibus as a package that is doing legislative fixes, that is trying finally to overcome known issues legislatively in the GDPR. But going back to what I said before, I do not really feel that it's an overall clear concept that is solving most of the critical issues.
And again, in terms of enforcement, governance, one of the key factors why we have problems, you don't really find anything in all those initiatives. And in terms of time, I'm jumping one slide further to come to my third point. And with that, I really want to present you three concrete and more and more ambitious proposals how we could really solve the enforcement and governance problems in Europe, per se, in Brussels, but also specifically in the member states. Because based on the academic literature, also work from think tanks, from NGOs and so on, there are a lot of good proposals.
And we also don't need to look that far to see certain structures that are actually working quite well in practice. In the UK, something very similar we can see in the Netherlands, in France and so on. There's something called Digital Regulation Coordination Forum. We could actually replicate it in the European Union, bring together all those different enforcers that we have on a European level and use basically existing structures. The EDPS has already offered to provide a kind of secretariat for such a structure.
And again, going to my overlaps and contradictions point, such a forum would really help to bring together different regulators, different enforcers. It would fix, at least to a certain extent, the policy silo issues that is leading to many of those problems and could force different entities to work together on horizontal issues like anonymization, like copyright and so on.
This, of course, would be a first step. Even further would be the idea to, at least for the big cases, in order to support especially smaller member states that don't have the capacities to use all those agencies that we have in Brussels.
Again, 82 governance structures and use one, which is called Hadir, which is already doing digital, to take over the huge enforcement cases, which are right now here and they are working, as you saw with the DMA or some DMA and DSA cases. But in other cases, the role of the politicized commission is constantly leading to problems. A more independent external agency, like an improved Hadir, could solve it. There are actually best practices for such a move, especially in the finance sector, when it comes to anti-money laundering. There is a new agency called Amler.
So all of that could happen without, let's say, huge changes, also without huge investments. And again, what I show you here in terms of numbers is going back to preparation by think tanks like ZEPS, like Bruegel and so on. There is a rather clear field of topics that such a new agency could cover.
Again, it's a rather small amount of large companies, similar to the DMA, DSA that would fall in. And there is, on the right side, there is also the point that you could probably use the staffing that is right now in the commission and don't need to hire 500 completely new people. So also that is a rather easy solution, the hard solution. But I would say in the more midterm future, we would need to think about is really to think about treaty level reforms, to think about how we want to create independent entities in Brussels that could support member states.
Because going back to the beginning of my presentation, the enforcement issue that we have right now, the big gap that we have right now, we will not solve with the status quo. We need to do some broader changes. And maybe in the end we see that, similar to the United States, we need really fully independent agencies to finally make sure, again, that our rules that we created so much are really enforced and are not only there on paper. And I will jump over just to the last slide and then I would end because I'm already a bit over time.
The big issue, and now going back also to the first point, to the large amount of laws that we, however, often accept that they exist and we are unwilling to improve existing laws or old laws for a variety of reasons. But also the second point that there are so many overlaps and contradictions, in my opinion, and again, it's going back to the work of many think tanks in Brussels, but also here in Berlin or in Paris, is that the European Union policy cycle is, especially with all the crises of the past decade, kind of overheated. I would even say broken.
And that in many of those different areas of the policy cycle, how a law is being drafted or even before, how foresight is being done or later how it's being implemented and enforced, that in each of those stages are really core problems that we need to fix.
Because otherwise, this is my opinion, we will never really close this delivery gap in terms of policies that you see here in Germany, but also in Brussels, that the policy level is constantly making new initiatives, but all of them are not really, or most of them are not really working on the ground and are achieving our policy goals that we had with those. I would stop here and hope that I gave a kind of overview in this topic that, again, is often very much overlooked.
Well, great. Thank you so much for the Brussels perspective. We have a question here, which is more a comment than a question, I think. But there seems to be a great deal of feeling behind it because it's been voted up quite a few times.
It says, with the focus on enforcement, why do you not ask the question whether regulations are actually desired by the population? What indicates that citizens actually want this heavy level of legislation? Yeah.
No, it's a good question. I think this goes back to the last slide that I saw, that I showed, because it's also my impression that there's a real disconnect here in Berlin, but even more in Brussels when it comes to the policymakers and the citizens, but also companies and so on and so on. We had some initiatives like the Conference for the Future of Europe, where especially Macron tried to bring closer citizens.
But, yeah, even that initiative didn't really work out as planned. So, yeah, I can just completely agree. It's something that we need to fix because I think in all member states and within or across the union, we see really very, let's say, citizens that are not really thinking that policy understands their need and so on. And maybe the last point to that, why I think the machine is a bit of a problem, the policy machine in Brussels functions to create laws. So this is what it's doing. So when it's about the question, why do we need those laws? This is exactly the right question.
But this means we need to change the machine because the machine only knows how to produce new laws and updates of laws, but it's not so much about reducing laws, making them more effective using other policy methods and so on. So this question is completely on spot.
Well, that's great. But I know we're running a bit long, but there also seems to be quite a bit of sentiment behind this question. Are you not afraid that all those laws are actually creating entry barriers for EU startups or vendors that ultimately only the big US groups are able to cope with them by passing all they can? Yeah. Also regarding this question, I completely support with the indications that you hear when you're reading it out.
And again, it's my first point that I made. I've focused now on enforcement, but indeed this big series of laws that we have there that are, again, not really coherent, that we are drafted in policy silos are creating a huge barrier, especially for our European SMEs and startups. I want to praise now the EU institutions because at least there is now better understanding. They are trying to push back, but so far there's not really a convincing strategy that would help exactly against what you are saying, that for huge companies in relative terms, it's always easier to comply.
But for a small one where it's really about the committer behind these global income, it's becoming almost impossible to invest in AI without involving a large law firm or big four accounting firms and so on. So we are not really helping our industry with what we are doing so far, is my personal opinion. So there's a frank one for you. Thank you very much, Kyle Zeller. Thank you.