Sovereignty by proxy? EU technological capacity and the first Portuguese Open Large Language Model

Ana Filipa Ribeiro (master’s student in European Union Law at the School of Law of University of Minho and ENDE Research Grant Holder – ref. UMINHO/BIM/2026/33) and Renan Bendel Vaughan (master’s student in European Union Law at the School of Law of University of Minho and ENDE Research Grant Holder – ref. UMINHO/BIM/2026/40)

Setting the scene: a small model in a large problem

On 1 July 2026, the Portuguese Government presented AMALIA,[1] the first open large language model (LLM) developed in European Portuguese, developed by a consortium of national universities and research institutions with an investment of 5.5 million euros funded under the Recovery and Resilience Plan.[2] The Minister of State and Administrative Reform framed the launch as a deliberate choice for digital sovereignty and the country’s technological autonomy.[3]

The moment is politically charged. On 3 June 2026, the European Commission adopted its Communication on European Tech Sovereignty, acknowledging that the European Union (EU) remains structurally dependent on external suppliers for more than 80% of its products, services, infrastructures, and intellectual property in the digital domain.[4] On 7 July 2026, the Action Plan on Cybersecurity and Artificial Intelligence acknowledged, more explicitly, that “frontier capabilities are mainly developed outside of the EU, and their availability is often determined by non-transparent, foreign-led processes”.[5]

The strategic salience of this moment is not contained within the Union’s normative framework. The NATO summit held in Ankara on 7 and 8 July 2026, although its official programme scarcely mentioned the issue, was shaped by access to frontier artificial intelligence (AI) models as an unofficial undercurrent of the discussions: the United States controls access to the most advanced AI capabilities and determines unilaterally which allies may obtain them, leaving European allies dependent on technology they do not govern and whose availability may be curtailed by an external political decision.[6]

AMALIA emerges at this juncture, positioned explicitly against the dependence described in both instruments. The model builds on EuroLLM-9B, subsequently expanded and optimised for European Portuguese,[7] and was trained within the EuroHPC network, including the MareNostrum 5 supercomputer and the national supercomputer Deucalion.[8] Conceived to preserve European Portuguese, to safeguard citizens’ national data from the reach of third-country jurisdictions, and to be progressively integrated into the public administration,[9] the Portuguese Government classifies AMALIA, in the light of Regulation (EU) 2024/1689 (the AI Act), as a general-purpose AI model without systemic risk.[10] A project of this profile becomes fully legible only against the Union’s own acknowledgement of structural dependence.

Technological dependencies and new vulnerabilities 

European technological sovereignty[11] is articulated across several layers, with computational capacity operating as a decisive constraint. EuroLLM-9B, the base on which AMALIA was developed, was pretrained on 400 NVIDIA H100 graphics processing units (GPUs) on the MareNostrum 5 supercomputer.[12] The subsequent training of AMALIA used 256 NVIDIA H100 GPUs. Council Regulation (EU) 2026/150, adopted in January 2026 to enable the AI Gigafactories, states that the next generation of frontier models will require “at least, three to four times the number of the most advanced AI processors currently available in the most powerful AI factories” and that “the existing mechanisms currently provided for under Council Regulation (EU) 2021/1173 are not sufficient”.[13] The insufficiency of European infrastructure is thus recorded in the very normative text that seeks to expand it.

A second layer is added to this one: energy. Data-centre electricity consumption in the Union accounts for around 3% of total demand and is projected to more than double by 2030.[14] In advanced economies, the construction of a transmission line takes between four and eight years, while grid-connection queues range from three to ten years.[15] The physical constraint precedes industrial-policy choices.

The Draghi Report documents the scale differential. 73% of the foundation models developed since 2017 are United States-based and 15% Chinese-based; in 2023, venture capital invested in AI in the Union amounted to eight billion dollars, against 68 billion dollars in the United States and 15 billion dollars in China.[16] The dependence is structural, and it extends to the critical infrastructures into which AI will be progressively integrated.

The Union’s cybersecurity framework confronts this landscape through instruments that only partially overlap. The Action Plan on Cybersecurity and Artificial Intelligence identifies a precise set of risks specific to AI systems integrated into critical infrastructures: “data and model poisoning, adversarial attacks, and prompt injection”.[17] The AI Act imposes obligations of robustness, accuracy, and cybersecurity on providers of high-risk AI systems, including resilience against adversarial attacks.[18] Those obligations fall on the provider of the system; Directive (EU) 2022/2555 (NIS2) regulates the entity operating the infrastructure into which the system is integrated.[19] The normative articulation between the two regimes has not been constructed.

The integration of AI into critical infrastructures generates a further tension that the existing framework is structurally unable to resolve at the external level: where the source of the threat is a State actor, the response shifts into the domain of the CFSP, where decision-making requires unanimity in the Council and where the Union’s capacity to respond depends on a political attribution decision that the existing mechanisms are not designed to deliver at the speed the nature of the threat demands.[20] The instruments available were conceived for a threat typology that the Commission itself acknowledges to have been overtaken.

From research excellence to technological capacity

The development of AMALIA represents a significant achievement for Portugal’s artificial intelligence ecosystem and contributes to the European Union’s broader objective of strengthening technological capacity in strategically important sectors.[21] More broadly, the project brings into focus a recurring weakness in the European innovation ecosystem, namely the limited capacity to transform publicly supported research into technological assets capable of sustained development and sustained operational deployment.[22]

This difficulty is particularly pronounced in AI. Indeed, a large language model does not become a mature technological asset simply because the research objectives associated with its initial development have been achieved.[23]Rather, its continued relevance depends on access to adequate computing resources, the retention of specialised technical expertise and the ability to adapt the model as technologies and user requirements evolve.[24] Accordingly, maintenance, refinement and deployment form part of the continuing development of the technology.

Against this background, AMALIA also illustrates the institutional consequences of this requirement. As a publicly funded research initiative, its initial development was financed under the Recovery and Resilience Plan and organised within a defined funding period.[25] Although this model is consistent with the requirements of research financing, it does not necessarily provide the organisational continuity required for long-term technological development. Accordingly, a research project may conclude once its contractual obligations have been fulfilled, whereas an AI system intended for continued operation requires ongoing monitoring, maintenance and institutional support throughout its lifecycle.[26] A further phase extending until 2027 has since been announced, with additional funding for the evolution of the model and the development of sovereign infrastructure. Nevertheless, the longer-term organisational framework supporting AMALIA beyond that phase remains to be determined.

The central difficulty therefore concerns the transition from research to sustained technological activity. In practice, public investment may establish the scientific foundations of a project without securing the expertise, infrastructure and financing required after the research phase has ended.[27] As a result, a project may retain considerable scientific value without becoming a durable technological capability.

In this context, AMALIA exemplifies the broader difficulty of converting publicly supported research into durable technological capacity. Although its development confirms the availability of scientific expertise, its long-term significance will depend on whether the model can be maintained and integrated into productive activity beyond successive funding cycles. This question is also relevant to technological sovereignty. In particular, such sovereignty depends on the existence of structures capable of retaining strategic expertise and sustaining the development of critical technologies.[28] Where advanced research is produced without the capacity to support its subsequent deployment, dependence on external providers may therefore persist even when the underlying knowledge originates within Europe. Accordingly, European competitiveness depends on the conditions under which research outputs can develop into stable technological activity.[29]

This assessment does not call into question the value of publicly funded research. Rather, it requires greater precision concerning the objectives assigned to different forms of public intervention. Finite project structures may be appropriate where the principal objective is scientific advancement or experimental development. Where public policy also seeks to establish strategic technological capacity, additional institutional arrangements are required. The applicable legal framework must therefore address both the allocation of research funding and the conditions under which the resulting technologies can be maintained, developed and deployed within the European economy.

The Union’s institutional response

The structural weaknesses identified above consequently raise a constitutional question concerning the role that Union law can realistically perform in strengthening European technological capacity. This question becomes particularly important where Europe’s competitiveness deficit cannot be addressed through research funding and public investment alone.

At first sight, the Treaties provide no direct answer. As noted above, they confer no autonomous horizontal competence allowing the Union to pursue technological sovereignty, industrial autonomy or strategic resilience as independent legal objectives.[30] Moreover, under Article 4(2) TEU, national security remains the sole responsibility of the Member States. Accordingly, the strategic importance of AI cannot, by itself, justify Union action outside the system of competences established by the Treaties.[31]

Nevertheless, the absence of an express competence does not render the Union institutionally irrelevant. Union action may be founded on another Treaty competence where the aim and content of the measure fall within its scope, even if the measure also produces effects in other policy fields.[32] This dynamic is particularly relevant to artificial intelligence because the same technological capabilities may support both civilian and security-related uses. Consequently, a measure adopted on the basis of Article 114 TFEU may also shape the technological environment on which strategically important capabilities depend.[33]

Within this constitutional framework, the internal market assumes particular significance, since it provides a central legal mechanism through which the Union may establish common conditions for the development and circulation of emerging technologies.[34] The relevant constitutional objective remains the prevention of regulatory fragmentation capable of impairing the functioning of the internal market. Even so, the practical effects of harmonisation may extend to the broader conditions governing technological development.[35]

In this regard, Article 114 TFEU provides the principal legal basis for this form of harmonising action. According to settled case law, that provision permits the approximation of national rules where existing differences obstruct the fundamental freedoms or directly affect the functioning of the internal market.[36] Furthermore, it may support preventive harmonisation where future obstacles resulting from regulatory divergence are sufficiently likely and the measure is designed to prevent them.[37] Its constitutional rationale therefore remains closely connected to market integration.

The Artificial Intelligence Act exemplifies this institutional model. Adopted under Articles 16 and 114 TFEU, it establishes harmonised rules intended to improve the functioning of the internal market while ensuring a high level of protection of health, safety and fundamental rights. In relation to high-risk AI systems, its requirements influence organisational and technical choices throughout the system’s lifecycle, thereby shaping the conditions under which artificial intelligence is designed and deployed in the Union.[38]

However, this broader effect remains subject to the constitutional limits imposed by the Treaties. In particular, Article 2(3) of the Artificial Intelligence Act preserves Member State competences concerning national security and excludes systems placed on the market, put into service or used exclusively for military, defence or national security purposes. Furthermore, recital 24 clarifies that systems serving both excluded and non-excluded purposes fall within the scope of the Regulation.

Even within those limits, the boundary between civilian and strategic technological capacity may be difficult to maintain during the development phase. Indeed, foundation models, computing infrastructure and specialised expertise may support several forms of subsequent deployment.[39] Consequently, legislation governing civilian artificial intelligence may indirectly (but inevitably) affect capabilities that also possess strategic relevance. Such effects nevertheless arise from the lawful exercise of internal market competences and do not alter the constitutional allocation of powers.

From this perspective, the internal market may contribute to technological capacity by reducing legal fragmentation, improving legal certainty and enabling technological activities to develop across national borders. However, harmonisation cannot replace the financing, infrastructure and industrial organisation required to sustain technological development. Its function is therefore to establish the legal conditions within which such capacity may emerge and expand.

Against this background, the simplification agenda raises a further question concerning the effect of regulatory reform on the common legal conditions established through internal market harmonisation. This question provides the basis for the following section.

Competitiveness, simplification, and the legal conditions of strategic autonomy 

The Commission’s diagnosis of Europe’s competitiveness deficit identifies three transformational imperatives: “closing the innovation gap”, “a joint roadmap for decarbonisation and competitiveness”, and “reducing excessive dependencies and increasing security”.[40] None of them primarily attributes the problem to regulation. The Competitiveness Compass locates the root cause in Europe’s difficulty in converting scientific discoveries into marketable technologies and in integrating them into its industrial base.[41] AMALIA illustrates the pattern: a high-quality scientific project whose deliverables-driven model keeps it at a distance from the industrial scale the Union identifies as strategically decisive.

The institutional response to this diagnosis is nevertheless structured around a different hypothesis: that regulatory agility is, in itself, an instrument of competitiveness. The April 2026 Better Regulation Communication formalises urgency as an autonomous procedural category, with differentiated procedures that dispense with impact assessment and public consultation where “the political context creating a need for urgent action” justifies it.[42] In 2024, 85% of the legislative proposals were presented without an impact assessment – the highest figure recorded since 2014 and nearly double the average for the three preceding years.[43] Although not every proposal legally required an impact assessment, the figure reflects a structural shift in the Commission’s approach to procedural obligations. Alemanno argues that the constitutional reach of the operation extends further still: Treaty obligations in relation to proportionality, participatory democracy, and the protection of fundamental rights are reclassified as instruments of discretionary management, adjustable to the political moment.[44]

That displacement is constitutionally significant. Article 11(3) TEU imposes on the Commission an obligation to conduct “broad consultations with parties concerned”, a requirement that the Commission’s own Better Regulation guidelines acknowledge as binding.[45] As regards Article 5(4) TEU, the Court clarified in Czech Republic v Parliament and Council that the absence of an impact assessment “cannot be regarded as a breach of the principle of proportionality” only where the EU legislature “is in a particular situation requiring it to be dispensed with and has sufficient information enabling it to assess the proportionality of an adopted measure”.[46] In the Mobility Package judgments, the Grand Chamber partially annulled Regulation (EU) 2020/1055 precisely on the ground that the EU legislature had not demonstrated that it possessed sufficient information to assess the proportionality of the measures adopted.[47] In a recommendation of November 2025, the European Ombudsman found maladministration in the preparation of the Omnibus packages, on the ground that the urgency invoked was not adequately reasoned, that the public consultation was inadequate, and that the necessary climate assessments had not been documented.[48] In June 2026, the Ombudsman closed the inquiries following the Commission’s overall agreement to implement the recommendations, while noting that the effectiveness of the resulting measures remained to be assessed.[49]

The question raised by this architecture is whether the institutional route chosen to pursue regulatory simplification is compatible with the procedural guarantees that Articles 5(4) and 11(3) TEU, read in the light of the Court’s case-law, render binding irrespective of the urgency claimed. The technological sovereignty that the Commission professes to pursue depends, in legal terms, on the very procedural guarantees that the simplification agenda is designed to attenuate.

Against this background, the simplification agenda, including the Omnibus packages, must be assessed in light of the institutional function of internal market legislation. Although the Commission presents simplification as a means of reducing burdens and strengthening legal certainty,[50] reforms that narrow harmonised requirements or create unevenly applied exemptions may recreate regulatory fragmentation. For projects such as AMALIA, long-term development depends on predictable regulatory conditions capable of supporting deployment beyond the national context. Simplification should therefore be assessed according to whether it facilitates deployment across the internal market without weakening the coherence of the common regulatory framework.

The limits of the legal answer 

AMALIA reveals that European technological capacity depends on continuity between publicly supported research and deployment across the internal market, a transition sustained by the predictable legal conditions created through harmonisation. Accordingly, simplification must be assessed through its effects on that common framework, since procedural acceleration acquires strategic value only where it preserves the coherence required for technological activity to reach European scale. That assessment must account for what law cannot resolve on its own. The scale differential documented by the Draghi Report – in computing infrastructure, energy access, and venture capital – precedes legal choices and conditions their effects, rather than being a regulatory problem. The NATO summit in Ankara confirmed that access to frontier AI capabilities has become a dimension of transatlantic security architecture, with European allies dependent on technology they neither govern nor can replicate at the required speed. Technological sovereignty requires the material conditions – infrastructure, investment, and industrial organisation – that harmonisation alone cannot supply. The question ultimately left to the Union is whether technological sovereignty can be constructed through a legal order whose foundations are increasingly perceived as obstacles to speed.


[1] AMALIA is the acronym for Agente Multimodal Automático de Linguagem com Inteligência Artificial, which may be translated as “Automatic Multimodal Language Agent powered by Artificial Intelligence.”. The scientific coordination of the AMALIA Project at the University of Minho is entrusted to Professor Paulo Novais, from the Department of Informatics of the School of Engineering, where he coordinates LASI (Associated Laboratory of Intelligent Systems), the largest associated laboratory dedicated to Artificial Intelligence in Portugal. He is also a Key Staff Member of the Jean Monnet Centre of Excellence “Digital citizenship and technological sustainability: achieving CFREU effectiveness in the digital decade” (CitDig), funded under the ERASMUS+ Programme.

[2] Ministério do Ambiente e Reforma do Estado (MARE) and Ministério da Educação, Ciência e Inovação (MECI), Portugal apresenta o AMALIA, o primeiro modelo de linguagem aberto desenvolvido em português europeu, Comunicado (Lisbon, 1 July 2026), 1–4, accessed July 17, 2026, https://portugal.gov.pt/gc25/comunicacao/comunicados/portugal-apresenta-o-amalia-o-primeiro-modelo-de-linguagem-aberto-desenvolvido-em-portugues-europeu

[3] Gonçalo Matias, Minister of State and Administrative Reform, quoted in MARE and MECI, Portugal apresenta o AMALIA, 2.

[4] European Commission, Communication on European tech sovereignty, COM(2026) 503 final, 3 June 2026, 1, https://digital-strategy.ec.europa.eu/en/library/communication-european-tech-sovereignty-accompanied-eu-open-source-strategy.

[5] European Commission, Action plan on cybersecurity and artificial intelligence, COM(2026) 577 final, 7 July 2026, 2, https://digital-strategy.ec.europa.eu/en/library/eu-action-plan-cybersecurity-and-artificial-intelligence.

[6] NATO, The Ankara Summit declaration, 8 July 2026, accessed July 17, 2026, https://www.nato.int/en/about-us/official-texts-and-resources/official-texts/2026/07/08/the-ankara-summit-declaration. On AI capabilities as a priority at the summit, see LeAnne Noelani Howard, “Allies committed to $50 billion in defense industry deals”, in Atlantic Council, Eleven Takeaways from the NATO Summit in Ankara, 9 July 2026, accessed July 17, 2026, https://www.atlanticcouncil.org/dispatches/eleven-takeaways-from-the-nato-summit-in-ankara/.

[7] MARE and MECI, Portugal apresenta o AMALIA, 9 (Q&A no. 29).

[8] MARE and MECI, Portugal apresenta o AMALIA, 3.

[9] MARE and MECI, Portugal apresenta o AMALIA, 2.

[10] MARE and MECI, Portugal apresenta o AMALIA, 5 (Q&A no. 9). Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L 2024/1689, 12 July 2024, http://data.europa.eu/eli/reg/2024/1689/oj.

[11] See European Commission, Communication on European tech sovereignty, defining technological sovereignty by reference to Europe’s ability to develop and control key technologies while reducing external dependence. The concept of technological capacity is used in this article as an analytical category describing the institutional conditions required for sustained technological development and deployment. See also European Commission, “State of the digital decade 2026”, accessed July 19, 2026, https://digital-strategy.ec.europa.eu/en/policies/2026-state-digital-decade-package, emphasising funding continuity and Europe’s capacity to develop and deploy critical technologies. 

[12] Pedro Henrique Martins et al., “EuroLLM: Multilingual Language Models for Europe”, arXiv, 2024, 5, accessed July 17, 2026, https://doi.org/10.48550/arXiv.2409.16235.

[13] Council Regulation (EU) 2026/150 of 16 January 2026 amending Regulation (EU) 2021/1173 on establishing the European High Performance Computing Joint Undertaking, OJ L 2026/150, 19 January 2026, recital 6, http://data.europa.eu/eli/reg/2026/150/oj.

[14] Agnieszka Widuto, AI and the energy sector, EPRS Briefing PE 775.859 (Brussels: European Parliamentary Research Service, July 2025), 1–3, accessed July 17, 2026, https://www.europarl.europa.eu/thinktank/en/document/EPRS_BRI(2025)775859.

[15] Widuto, AI and the energy sector, 5.

[16] Mario Draghi, The future of European competitiveness: a competitiveness strategy for Europe, Part B (Brussels: European Commission, 2024), 79, https://commission.europa.eu/topics/competitiveness/draghi-report_en.

[17] European Commission, Action plan on cybersecurity and artificial intelligence, 7.

[18] Regulation (EU) 2024/1689, Article 15.

[19] Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS2), OJ L 333, 27 December 2022, Article 21, http://data.europa.eu/eli/dir/2022/2555/2022-12-27.

[20] Articles 24(1) and 31(1) TEU (unanimity requirement for CFSP decisions); Article 215 TFEU (restrictive measures). See also Council Decision (CFSP) 2019/797 of 17 May 2019 concerning restrictive measures against cyber-attacks threatening the Union or its Member States, OJ L 129I, 17 May 2019, http://data.europa.eu/eli/dec/2019/797/2026-05-13; Council Regulation (EU) 2019/796 of 17 May 2019 concerning restrictive measures against cyber-attacks threatening the Union or its Member States, OJ L 129I, 17 May 2019, http://data.europa.eu/eli/reg/2019/796/2026-05-13.

[21] This objective is also reflected in the Commission’s Frontier AI Grand Challenge, won in June 2026 by the EUROPA consortium, led by Domyn. The consortium was selected to develop an openly available European frontier AI model covering all 24 official EU languages and exceeding 400 billion parameters. The initiative was presented as part of the Union’s ambition to develop advanced AI capabilities on European terms. See European Commission, Commission Selects EUROPA consortium as the winner of the Frontier AI Grand Challenge (19 June 2026), accessed July 19, 2026, https://digital-strategy.ec.europa.eu/en/news/commission-selects-europa-consortium-winner-frontier-ai-grand-challenge-project-build-european-open. See Pedro Madeira Froufe, “Ter ou não ter ‘fome’”, Correio do Minho (18 July 2026), accessed July 19, 2026, https://www.correiodominho.pt/cronicas/ter-ou-nao-ter-fome/18260

[22] Draghi identifies the need to improve “the pipeline from innovation to commercialisation” and to remove the barriers preventing innovative companies from growing and attracting finance. Mario Draghi, The future of European competitiveness: a competitiveness strategy for Europe, Part A (Brussels: European Commission, 2024), 18, https://commission.europa.eu/topics/competitiveness/draghi-report_en.

[23] As Bommasani et al. observe, foundation models are “unfinished intermediate objects” that require subsequent adaptation for downstream applications, underscoring that their initial development does not exhaust their technological lifecycle. Rishi Bommasani et al., On the opportunities and risks of foundation models (Stanford, CA: Stanford University, Center for Research on Foundation Models, 2021), 5, accessed July 17, 2026, https://crfm.stanford.edu/report.html.

[24] Ping Song, Adegboyega Ojo, and Edward Curry, “Trustworthy requirements for foundation models—A comprehensive survey and roadmap”, Engineering Applications of Artificial Intelligence (2025): 5, accessed July 17, 2026, https://doi.org/10.1016/j.engappai.2025.113111.

[25] Portuguese Government states that AMALIA was financed through the Recovery and Resilience Plan, developed by public entities and implemented according to an 18-month timetable providing for successive beta, base and multimodal versions. See Portuguese Government, “Modelo de Linguagem em Grande Escala para a língua portuguesa” (29 November 2024), accessed July 17, 2026, https://portugal.gov.pt/gc24/comunicacao/noticias/modelo-de-linguagem-em-grande-escala-para-a-lingua-portuguesa.

[26] EU-funded research projects operate within grant agreements that define their duration and contractual obligations. By contrast, OECD and NIST guidance treats monitoring and maintenance as continuing aspects of the AI-system lifecycle. See European Research Executive Agency, “Horizon Europe – Grants & Reporting”, accessed July 17, 2026, https://rea.ec.europa.eu/horizon-europe-grants-reporting_en?prefLang=en; OECD, Recommendation of the Council on Artificial Intelligence, OECD/LEGAL/0449 (2019 and amended on 2024), 8, accessed July 17, 2026, https://legalinstruments.oecd.org/en/instruments/oecd-legal-0449; NIST, Artificial Intelligence Risk Management Framework 1.0 (2023), 38, accessed July, 17, 2026, https://www.nist.gov/itl/ai-risk-management-framework

[27] Randolph Beard et al., “A valley of death in the innovation sequence: an economic investigation” (2009), in Research Evaluation 343, “executive summary”, accessed July 18, 2026, http://dx.doi.org/10.2139/ssrn.1093006, arguing that a gap may arise where public expenditure supports early-stage research without sufficient regard to the investment decisions required during the subsequent stages of innovation.

[28] See Francesco Crespi et al., “European technological sovereignty: an emerging framework for policy strategy” (2021), Intereconomics(Springer, Heidelberg, Vol. 56, Issue 6), 349 and 353, accessed July 17, 2026, https://doi.org/10.1007/s10272-021-1013-6, arguing that scientific and technological capacities require corresponding capabilities for their economic exploitation and that technological sovereignty depends on consistent investment in critical technologies. The reference to institutional structures capable of retaining strategic expertise is the authors’ analysis.

[29] Draghi, The future of European competitiveness, Part A, 7.

[30] Articles 2 to 6 TFEU (a contrario).

[31] However, it is important to note that Article 4(2) TEU does not establish a general exclusion from the scope of Union law for measures connected with national security. The European Court of Justice has held that “the mere fact that a decision taken by a competent national authority concerns State security cannot result in European Union law being inapplicable”. See Judgment CJEU ZZ v Secretary of State for the Home Department, 4 June 2013, case C-300/11, ECLI:EU:C:2013:363, para. 38; see also Judgment CJEU Privacy International, 6 October 2020, case C-623/17, ECLI:EU:C:2020:790, para. 44.

[32] See Judgment CJEU European Parliament v Council, case C-490/10, 6 September 2012, ECLI:EU:C:2012:525, paras. 44-46, confirming that the appropriate legal basis must be determined by reference to the aim and content of the measure and that an incidental objective does not alter the legal basis required by its predominant purpose. See also Judgment CJEU Philip Morris Brands and Others, 4 May 2016, case C-547/14, ECLI:EU:C:2016:325, para. 60, holding that Article 114 TFEU may be relied upon where its conditions are satisfied even when the protection of public health is a decisive factor in the legislative choices made. These judgments support the proposition that the lawful exercise of a conferred competence may produce effects extending beyond its principal regulatory field.

[33] See European Commission, White paper on options for enhancing support for research and development involving technologies with dual-use potential (24 January 2024), COM(2024) 27 final, 1, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:52024DC0027, defining dual-use research by reference to software and technology capable of being used for both civil and military purposes. See also Regulation (EU) 2024/1689, recital 24, which recognises that the same AI system may serve both excluded security-related purposes and civilian uses.

[34] See Articles 26(2) and 114(1) TFEU. In the field of artificial intelligence, recital 1 of Regulation (EU) 2024/1689 expressly refers to “a uniform legal framework” for the development and marketing of AI systems, while recital 8 links harmonised rules to their free movement within the internal market.

[35] Regulation (EU) 2024/1689, recitals 1, 3 and 8, which link the prevention of regulatory fragmentation to a uniform framework governing the development and use of AI systems. 

[36] See Judgment Philip Morris Brands, paras. 57–58. The Court held that Article 114(1) TFEU authorises measures approximating national provisions whose object is the establishment and functioning of the internal market. Although the mere existence of disparities between national rules is insufficient, recourse to Article 114 TFEU is justified where those differences obstruct the fundamental freedoms and thereby directly affect the functioning of the internal market.

[37] See Judgment CJEU Poland v European Parliament and Council, 4 May 2016, case C-358/14, ECLI:EU:C:2016:323, para. 33, holding that Article 114 TFEU may be used to prevent future obstacles to trade resulting from divergences in national laws, provided that the emergence of those obstacles is likely and the measure is designed to prevent them.

[38] See Regulation (EU) 2024/1689, Articles 1(1)–(2), 9 and 72, and Annex IV.

[39] This corresponds to the concept of dual use, which refers to technologies capable of serving both civilian and military purposes. See Regulation (EU) 2021/821, Article 2(1); and Jane Vaynman and Tristan A Volpe, “Dual use deception: how technology shapes cooperation in international relations”, International Organization, 77(3) (2023): 599, accessed July 17, 2026, https://doi.org/10.1017/S0020818323000140. The concept is used here in an analytical sense and does not imply that every technology mentioned falls within the product scope of Regulation (EU) 2021/821.

[40] European Commission, A competitiveness compass for the EU: Communication from the Commission to the European Parliament, the European Council, the Council, the European Economic and Social Committee and the Committee of the Regions, COM(2025) 30 final (Brussels: European Commission, 29 January 2025), https://commission.europa.eu/topics/competitiveness/competitiveness-compass_en, 3.

[41] European Commission, A competitiveness compass for the EU, 1.

[42] European Commission, A simpler, clearer and better enforced EU Rulebook, COM(2026) 380 final, 28 April 2026, https://commission.europa.eu/publications/simpler-clearer-and-better-enforced-eu-rulebook_en; Alberto Alemanno, “Deregulating better regulation: the constitutional stakes of the Commission’s 2026 reform”, Verfassungsblog, 29 April 2026, accessed July 17, 2026, https://doi.org/10.59704/640336d7bff5903b.

[43] Council of the European Union, Handling of impact assessments within the Council – Annual report covering the period January-December 2024, IA 13/MERTENS 2/POLGEN 16/BETREGS 7, Brussels, 8 April 2025, 14, accessed July 18, 2026, https://www.parlament.gv.at/gegenstand/XXVIII/EU/17052; Alberto Alemanno, “Codifying better regulation: constitutional requirements and reform proposals”Submission to the European Commission Call for Evidence on the Communication on Better Regulation, HEC Paris Research Paper No. LAW-2026-1591, February 2026, 7, accessed July 17, 2026, http://dx.doi.org/10.2139/ssrn.6168211.

[44] Alemanno, “Deregulating better regulation”.

[45] Treaty on European Union, Article 11(3); European Commission, A simpler, clearer and better enforced EU Rulebook, 6–10; Alemanno, “Codifying better regulation”, 4–5, 10; Alemanno, “Deregulating better regulation”.

[46] Judgment CJEU, Czech Republic v European Parliament and Council, 3 December 2019, case C-482/17, ECLI:EU:C:2019:1035, para. 85.

[47] Judgment CJEU, Republic of Lithuania and Others v European Parliament and Council (“Mobility Package”), 4 October 2024, joined cases C-541/20 to C-555/20, ECLI:EU:C:2024:818, paras. 150–153.

[48] European Ombudsman (Teresa Anjinho), Recommendation on the European Commission’s compliance with ‘Better Regulation’ rules and other procedural requirements in preparing legislative proposals that it considered to be urgent, cases 983/2025/MAS (“Omnibus”), 2031/2024/VB (“migration”) and 1379/2024/MIK (“CAP”), 25 November 2025, conclusion, accessed July 17, 2026, https://www.ombudsman.europa.eu/en/recommendation/en/215920.

[49] European Ombudsman (Teresa Anjinho), Decision on the European Commission’s compliance with Its ‘Better Regulation’ rules and other procedural requirements in preparing legislative proposals that it considered to be urgent, cases 983/2025/MIK (“Omnibus”), 2031/2024/VB (“migration”) and 1379/2024/MIK (‘CAP’), 23 June 2026, conclusion, accessed July 19, 2026, https://www.ombudsman.europa.eu/en/decision/en/228151. The Ombudsman closed the inquiries following the Commission’s overall agreement to implement the recommendations, while noting that the effectiveness of the measures adopted remained to be assessed.

[50] European Commission, A simpler, clearer and better enforced EU Rulebook, 2, linking streamlined procedures to greater legal certainty and identifying enforcement of the single market rulebook as a strategic priority. 


Picture credit: by http://www.kaboompics.com on pexels.com.

Leave a comment