What Europe is actually building, 2026 to 2034

You do not need to prove there is a secret plan in order to be worried.

Every argument about EU regulation gets stuck in the same place. People ask: is there a plan? Who decided this? Where is the document?

That is the wrong question, and nobody can answer it. There is a better question, and this one does have answers, because they are all published in the Official Journal.

The question is: what is actually being built, and what will it be able to do when it is finished?

If you answer that, you get one picture. The system is going up in five places at the same time.

1. The goods: one database for all EU trade

On 26 March 2026 the Council and the Parliament agreed the biggest customs reform since the customs union was created. It has three parts.

  • The EU Customs Data Hub. This is one platform that will hold the customs data of the whole Union. The Council’s own press release says it will give “a full overview of trade flows and supply chains.” It opens for e-commerce on 1 July 2028 and is fully running for all traders by 1 March 2034.
  • The EU Customs Authority. This is a new agency in Lille, France. It will run the hub, set the risk criteria, and decide which cargo gets checked.
  • Trust and Check. This is a new status for companies that are fully transparent. Their goods can clear with almost no active customs work at the border.

Until now, trade data sat with 27 separate national customs administrations. From 2028 it starts sitting in one place, with one body, and one search box.

That is not my reading of it. That is the product description.

2. The product: an ID number for every item

The Ecodesign Regulation, known as ESPR, brings in the Digital Product Passport. This is a data record attached to each unit, not only to the shipment as a whole.

Industrial and EV batteries over 2 kWh need it from 18 February 2027. Iron and steel are in the work plan for 2026. Textiles, tyres and aluminium follow around 2027. Furniture is around 2028.

At the same time the packaging regulation, PPWR, requires marking, QR codes and batch identifiers on the packaging itself. So the box and the product both start carrying a digital identity.

3. The person: biometrics at every border crossing

The Entry/Exit System went fully live in April 2026. Every third-country national now gives fingerprints and a facial image on every entry and every exit. The old passport stamp is gone.

ETIAS is meant to add a travel authorisation before departure. That date keeps moving, so I would not treat late 2026 as fixed. In parallel, the European Digital Identity Wallet under eIDAS 2.0 has to be issued by every member state by the end of 2026, and accepted across a wide range of sectors.

4. The money: from reporting to currency

CESOP has been running since 2024. Every payment service provider in the EU reports cross-border payments above a threshold to a central European database.

The digital euro moved forward again in 2026: a vote in the ECON committee, provider selection by the ECB, and a pilot talked about for 2027. Reporting is already there. A European digital currency is the next layer.

5. Carbon: not a tax first. A measurement layer

This is the part most people miss.

CBAM is not mainly a way of collecting money. It is a reporting system. It forces every shipment to be tied to a named producer and to the emissions built into the goods. Without that data, the goods do not sit cleanly in the system.

Maritime ETS, FuelEU and ETS2 then build a second measurement layer over the movement of the cargo itself. The money that comes out of this is a by-product. The data is the product.

The argument

Each of these five is defensible on its own. VAT fraud. Product safety. Border security. Climate. Every one of them was written honestly, by reasonable people, for good reasons.

But the result of putting them together is not the same as the reasons for each one.

What is being built, in practice, is a situation where every unit of goods, every cross-border payment, every border crossing and every supply chain becomes an identified record.

That record is held centrally. It can be queried. That is not a claim about a conspiracy. It is a claim about capability. And the capability is documented, funded and scheduled.

And here is the one rule of history you can rely on. Systems built to see things never stay limited to the job they were built for. SWIFT data was collected for banking and ended up used for terrorist finance tracking. Airline passenger data was collected to run flights and ended up used for law enforcement. The Covid certificate was not a surveillance system, but it proved something nobody knew before: that the EU can roll out a mandatory digital credential across 27 countries in a few months. That knowledge did not go away.

The difference between now and before is not the quality of the intention. It is that the infrastructure will exist, and in practice it will not be taken apart. Whoever inherits it in ten years will not have to build anything.

What this means for the small operator

This is the part that was left out of the press releases, and the part nobody is keen to talk about.

Once trade runs through a database, compliance stops being a document and becomes a data feed. Every one of these rules asks for more or less the same fields: who made it, where the material came from, country of production, emissions data, unit identifier.

If you can produce that feed, you trade. If you cannot, you do not always get fined. You are simply not visible to the system. And what is not visible does not get released. That is a new kind of entry barrier. Not a licence. Not capital. An information system. And an information system costs roughly the same whether you move 40 containers a year or 40,000.

So the outcome is arithmetic. Hundreds of thousands of small importers, retailers and forwarders will drop out. Not because anyone banned them from trading, but because they will not be able to feed the machine. The market that is left will have fewer players. It will be more concentrated. And it will therefore be far easier to supervise. That is not a sinister reading. It is what the design produces.

Fairness requires the other side too. This system is not moving smoothly. The Omnibus packages of 2025 and 2026 cut CSRD back, softened CSDDD, put a threshold into CBAM and delayed EUDR more than once. ETS2 slipped by a year. Timelines now run out to 2034. The EU is not a well-oiled machine. It is a fight between 27 governments, a court, and a data-protection regulation that is capable of cutting down capabilities that have already been built.

That is where the real argument is. Not who planned it, but the questions you can actually ask. Who audits the database? Who is allowed to query it, and for what? What is kept, and for how long? And what happens to the three hundred thousand small businesses that have no compliance department?

Anyone who runs this debate as a conspiracy loses it before it starts. Anyone who runs it on oversight, proportionality and access can still win it. But not for long.

After 2028 this is no longer a proposal. It is working infrastructure.

September 2026

Leave a comment