Twenty-one of the 27 member states have declared that they do not use artificial intelligence tools in their anti-fraud strategies, although fraud against the European budget increasingly employs digital technologies. Only the Czech Republic, Italy, and Portugal have integrated AI into their national strategies, and adoption remains primarily experimental and limited to certain sectors.
In short, the Czech Republic, Italy, and Portugal have included the use of artificial intelligence in their national anti-fraud strategies. Belgium, Spain, France, Italy, Hungary, and Slovenia use AI in other frameworks or anti-fraud activities. The tools are mainly used for anomaly detection, predictive risk analysis, automatic invoice verification, supporting audits, and identifying links between individuals and companies. Only the Czech Republic, Luxembourg, and Sweden conducted a comprehensive assessment of cyber threats and the risks associated with artificial intelligence for the EU budget in 2025. Fifteen states had not conducted such an assessment and had no plans to start one. Eight others had only conducted a partial analysis, while one state was preparing the assessment. The most common obstacles are the lack of interoperability between systems, mentioned by 19 states, budget constraints, indicated by 16, and legal issues or data protection concerns, reported by 12 states.
Artificial intelligence is used by some authorities to analyze data volumes that cannot be effectively verified through manual checks alone. The systems can compare beneficiaries, contracts, invoices, payments, suppliers, and project histories to identify transactions that deviate from normal patterns.
However, the Commission shows that this use has not yet become a common component of national systems for protecting EU funds. Most states have reported that AI is not included in their anti-fraud strategy, and existing examples are often pilot projects or tools used in a single domain.
The Czech Republic, Italy, and Portugal are the only states that have confirmed the integration of artificial intelligence into their national anti-fraud strategy. Inclusion in a strategy means that the technology appears in the overall planning regarding the prevention and detection of irregularities, without demonstrating that it is used in all programs and by all authorities.
Six other states, Belgium, Spain, France, Italy, Hungary, and Slovenia, use AI in other anti-fraud frameworks. Italy appears in both categories, so eight member states use such tools in some form, according to the responses analyzed by the Commission.
The initial uses are focused on prevention and detection. A system can assign a risk score to a funding request, can flag an invoice with an unusual value, or can identify links between beneficiaries and suppliers that are not evident from separate document analysis.
In agriculture and customs, some authorities use automatic learning for anomaly detection and risk analysis. Historical data can be compared with new declarations to identify values, quantities, origins, or beneficiaries that require further verification.
Other tools support audits and attempt to anticipate where irregularities may arise. They do not independently establish the existence of fraud but help inspectors select the projects or transactions that need to be checked.
Automated text processing can be used for document analysis, transcription of materials, and searching for relevant terms or patterns in bulky files. Invoice verification can automatically compare declared information with other databases and can flag discrepancies.
Network analysis tracks relationships between companies, administrators, beneficiaries, subcontractors, and individuals participating in multiple projects. This can help identify structures created to disguise the real beneficiary, conflicts of interest, or repeated funding.
A risk indicator does not represent a finding of fraud. The signal must be verified through documents, administrative checks, inspections, or investigations and cannot replace the assessment made by responsible individuals.
The Commission recommends combining the results of digital tools with human analysis and operational monitoring. A system that produces alerts without the authority having personnel to examine them does not automatically improve detection.
The quality of the results depends on the data entered. Incomplete, outdated, or differently recorded information by institutions can produce unnecessary alerts or omit important cases.
National systems have been developed in different periods and for distinct administrative objectives. Databases regarding projects, beneficiaries, procurements, taxes, company owners, and investigations cannot always communicate automatically with each other.
Nineteen states indicated system incompatibility and interoperability difficulties as a significant obstacle to the digitalization of fraud prevention. In many cases, data is still transferred manually, through exported files or through periodic uploads.
The lack of an automatic link delays analysis and can hinder the rapid identification of a beneficiary appearing in multiple programs, regions, or states. It also increases the risk of incompatible formats or the repeated entry of the same information.
Sixteen states mentioned budget constraints. Developing a tool does not only involve acquiring software, as authorities must prepare the data, connect the systems, ensure security, and train personnel.
Old systems can be costly to modify and were not designed for automatic data exchange or real-time analysis. Replacing them can affect the daily operations of institutions managing payments and checks.
Another 12 states indicated data protection and legal uncertainties. Anti-fraud tools may use information about individuals, company ownership, contracts, payments, location, and business relationships.
Authorities must establish the legal basis for processing, the categories of individuals who can access the information, the duration of data retention, and the possibility of contesting a decision. The use of an algorithmic result without sufficient explanation can affect the rights of beneficiaries.
The Commission recommends applying AI in a targeted, secure, and risk-based manner. Technology should be used for clearly defined issues, with accuracy verification, human oversight, and procedures for correcting errors.
States were asked whether they assessed cyber threats and risks related to artificial intelligence for protecting the EU budget. Only the Czech Republic, Luxembourg, and Sweden conducted a comprehensive assessment in 2025.
Belgium, Estonia, Ireland, Spain, Latvia, Malta, Austria, and Slovakia conducted partial assessments. These may cover only certain institutions, funds, types of attacks, or technologies.
Fifteen states reported that they had not conducted an assessment and did not intend to do so. One other state indicated that it was preparing the analysis.
Assessing threats is not identical to using AI for fraud detection. A state may use an analysis tool without having fully examined the risks that new technologies create for its own systems.
Artificial intelligence can assist authorities, but it can also be used by criminal networks. The automatic generation of texts and images allows for the rapid production of identities, certificates, invoices, photographs, and false supporting documents with a high level of credibility.
Systems can be used for the repeated adaptation of a funding request, imitating documents of an authority, or creating companies and transactions that appear legitimate upon superficial inspection.
Networks involved in cross-border fraud already use complex company structures to hide the links between participants. Digital tools can make these structures easier to manage and can reduce the cost of producing false documents.
The lack of an assessment does not demonstrate that a state is unprepared for any cyber attack. Institutions may have general security strategies or procedures in other areas, but responses show that specific risks for EU funds have not been systematically analyzed in most countries.
The Commission also monitors the use of Arachne, the European tool that helps authorities identify projects, beneficiaries, and contracts with risk factors. The number of states using it increased from 22 in 2024 to 23 in 2025.
Declared use does not mean complete integration. Some states send data only for certain funds, enter information manually, or provide only the minimum required set.
Eight states cited technical limitations for partial implementation, seven strategically decided to provide only the minimum data, and six reported legal constraints.
Interoperability between Arachne and national tools remains low. In many administrations, data is exported in XML format, processed separately, and manually uploaded into the European system.
The Commission is preparing the development of Arachne+, which should provide authorities with a more modern tool for risk analysis, preventing irregularities, and selecting controls.
States are encouraged to use more risk-based analysis and IT tools, including for checks conducted after transactions are made. These verifications can identify patterns that become visible only after comparing multiple projects and payments.
The report shows that risk analysis still plays a limited role in detecting certain frauds. In agriculture and cohesion policy, many cases continue to be discovered through regular checks, administrative verifications, or information received from third parties.
A digital tool cannot compensate for the lack of information exchange between institutions. Administrative authorities need data from police, prosecutors, courts, the European Public Prosecutor's Office, and the European Anti-Fraud Office to update the status of cases.
Several states reported difficulties in obtaining information about criminal procedures, penalties, recoveries, and final court outcomes. The confidentiality of investigations can delay the transmission of data to the institutions managing the funds.
Effective digitalization depends, according to the Commission, on five elements: usable and quality data, interoperable systems, clear legal rules, qualified personnel, and the integration of tools into the regular control activity.
Member states reported 72 measures to improve the protection of EU funds in 2025. Most focused on prevention and detection, including the early identification of high-risk operators, staff training, information exchange, and database development.
About a quarter of the projects submitted for funding under the European anti-fraud program in 2025 targeted data analysis technologies and IT tools. The total funding request exceeded the available budget by more than four times.
The program received 151 applications from 16 member states and two from Ukraine. The interest shown indicates that authorities are seeking to expand digital capabilities even though AI does not yet appear in most national strategies.
The Commission's report analyzes the measures adopted by states to protect European revenues and expenditures in 2025. Information regarding the use of artificial intelligence comes from responses provided by national authorities.
The figures describe the integration of AI into the declared anti-fraud strategies and frameworks, not every tool used by all public institutions in a country. Some tax, customs, or judicial authorities may use digital technologies that have not been reported in this category.
The Commission is preparing a review of the European anti-fraud architecture, which will also analyze the use of modern technologies, data exchange, and cooperation between national authorities, OLAF, and the European Public Prosecutor's Office.
Fraud detected against the EU budget involved 274.3 million euros in cases reported by states and institutions for 2025. Other investigations regarding VAT and the Recovery and Resilience Facility are not fully included in the same statistical systems.
The expansion of artificial intelligence in anti-fraud controls will depend on the ability of states to connect databases, define legal guarantees, and transform algorithmic alerts into checks and investigations conducted by authorities.
In short, the Czech Republic, Italy, and Portugal have included the use of artificial intelligence in their national anti-fraud strategies. Belgium, Spain, France, Italy, Hungary, and Slovenia use AI in other frameworks or anti-fraud activities. The tools are mainly used for anomaly detection, predictive risk analysis, automatic invoice verification, supporting audits, and identifying links between individuals and companies. Only the Czech Republic, Luxembourg, and Sweden conducted a comprehensive assessment of cyber threats and the risks associated with artificial intelligence for the EU budget in 2025. Fifteen states had not conducted such an assessment and had no plans to start one. Eight others had only conducted a partial analysis, while one state was preparing the assessment. The most common obstacles are the lack of interoperability between systems, mentioned by 19 states, budget constraints, indicated by 16, and legal issues or data protection concerns, reported by 12 states.
Artificial intelligence is used by some authorities to analyze data volumes that cannot be effectively verified through manual checks alone. The systems can compare beneficiaries, contracts, invoices, payments, suppliers, and project histories to identify transactions that deviate from normal patterns.
However, the Commission shows that this use has not yet become a common component of national systems for protecting EU funds. Most states have reported that AI is not included in their anti-fraud strategy, and existing examples are often pilot projects or tools used in a single domain.
The Czech Republic, Italy, and Portugal are the only states that have confirmed the integration of artificial intelligence into their national anti-fraud strategy. Inclusion in a strategy means that the technology appears in the overall planning regarding the prevention and detection of irregularities, without demonstrating that it is used in all programs and by all authorities.
Six other states, Belgium, Spain, France, Italy, Hungary, and Slovenia, use AI in other anti-fraud frameworks. Italy appears in both categories, so eight member states use such tools in some form, according to the responses analyzed by the Commission.
The initial uses are focused on prevention and detection. A system can assign a risk score to a funding request, can flag an invoice with an unusual value, or can identify links between beneficiaries and suppliers that are not evident from separate document analysis.
In agriculture and customs, some authorities use automatic learning for anomaly detection and risk analysis. Historical data can be compared with new declarations to identify values, quantities, origins, or beneficiaries that require further verification.
Other tools support audits and attempt to anticipate where irregularities may arise. They do not independently establish the existence of fraud but help inspectors select the projects or transactions that need to be checked.
Automated text processing can be used for document analysis, transcription of materials, and searching for relevant terms or patterns in bulky files. Invoice verification can automatically compare declared information with other databases and can flag discrepancies.
Network analysis tracks relationships between companies, administrators, beneficiaries, subcontractors, and individuals participating in multiple projects. This can help identify structures created to disguise the real beneficiary, conflicts of interest, or repeated funding.
A risk indicator does not represent a finding of fraud. The signal must be verified through documents, administrative checks, inspections, or investigations and cannot replace the assessment made by responsible individuals.
The Commission recommends combining the results of digital tools with human analysis and operational monitoring. A system that produces alerts without the authority having personnel to examine them does not automatically improve detection.
The quality of the results depends on the data entered. Incomplete, outdated, or differently recorded information by institutions can produce unnecessary alerts or omit important cases.
National systems have been developed in different periods and for distinct administrative objectives. Databases regarding projects, beneficiaries, procurements, taxes, company owners, and investigations cannot always communicate automatically with each other.
Nineteen states indicated system incompatibility and interoperability difficulties as a significant obstacle to the digitalization of fraud prevention. In many cases, data is still transferred manually, through exported files or through periodic uploads.
The lack of an automatic link delays analysis and can hinder the rapid identification of a beneficiary appearing in multiple programs, regions, or states. It also increases the risk of incompatible formats or the repeated entry of the same information.
Sixteen states mentioned budget constraints. Developing a tool does not only involve acquiring software, as authorities must prepare the data, connect the systems, ensure security, and train personnel.
Old systems can be costly to modify and were not designed for automatic data exchange or real-time analysis. Replacing them can affect the daily operations of institutions managing payments and checks.
Another 12 states indicated data protection and legal uncertainties. Anti-fraud tools may use information about individuals, company ownership, contracts, payments, location, and business relationships.
Authorities must establish the legal basis for processing, the categories of individuals who can access the information, the duration of data retention, and the possibility of contesting a decision. The use of an algorithmic result without sufficient explanation can affect the rights of beneficiaries.
The Commission recommends applying AI in a targeted, secure, and risk-based manner. Technology should be used for clearly defined issues, with accuracy verification, human oversight, and procedures for correcting errors.
States were asked whether they assessed cyber threats and risks related to artificial intelligence for protecting the EU budget. Only the Czech Republic, Luxembourg, and Sweden conducted a comprehensive assessment in 2025.
Belgium, Estonia, Ireland, Spain, Latvia, Malta, Austria, and Slovakia conducted partial assessments. These may cover only certain institutions, funds, types of attacks, or technologies.
Fifteen states reported that they had not conducted an assessment and did not intend to do so. One other state indicated that it was preparing the analysis.
Assessing threats is not identical to using AI for fraud detection. A state may use an analysis tool without having fully examined the risks that new technologies create for its own systems.
Artificial intelligence can assist authorities, but it can also be used by criminal networks. The automatic generation of texts and images allows for the rapid production of identities, certificates, invoices, photographs, and false supporting documents with a high level of credibility.
Systems can be used for the repeated adaptation of a funding request, imitating documents of an authority, or creating companies and transactions that appear legitimate upon superficial inspection.
Networks involved in cross-border fraud already use complex company structures to hide the links between participants. Digital tools can make these structures easier to manage and can reduce the cost of producing false documents.
The lack of an assessment does not demonstrate that a state is unprepared for any cyber attack. Institutions may have general security strategies or procedures in other areas, but responses show that specific risks for EU funds have not been systematically analyzed in most countries.
The Commission also monitors the use of Arachne, the European tool that helps authorities identify projects, beneficiaries, and contracts with risk factors. The number of states using it increased from 22 in 2024 to 23 in 2025.
Declared use does not mean complete integration. Some states send data only for certain funds, enter information manually, or provide only the minimum required set.
Eight states cited technical limitations for partial implementation, seven strategically decided to provide only the minimum data, and six reported legal constraints.
Interoperability between Arachne and national tools remains low. In many administrations, data is exported in XML format, processed separately, and manually uploaded into the European system.
The Commission is preparing the development of Arachne+, which should provide authorities with a more modern tool for risk analysis, preventing irregularities, and selecting controls.
States are encouraged to use more risk-based analysis and IT tools, including for checks conducted after transactions are made. These verifications can identify patterns that become visible only after comparing multiple projects and payments.
The report shows that risk analysis still plays a limited role in detecting certain frauds. In agriculture and cohesion policy, many cases continue to be discovered through regular checks, administrative verifications, or information received from third parties.
A digital tool cannot compensate for the lack of information exchange between institutions. Administrative authorities need data from police, prosecutors, courts, the European Public Prosecutor's Office, and the European Anti-Fraud Office to update the status of cases.
Several states reported difficulties in obtaining information about criminal procedures, penalties, recoveries, and final court outcomes. The confidentiality of investigations can delay the transmission of data to the institutions managing the funds.
Effective digitalization depends, according to the Commission, on five elements: usable and quality data, interoperable systems, clear legal rules, qualified personnel, and the integration of tools into the regular control activity.
Member states reported 72 measures to improve the protection of EU funds in 2025. Most focused on prevention and detection, including the early identification of high-risk operators, staff training, information exchange, and database development.
About a quarter of the projects submitted for funding under the European anti-fraud program in 2025 targeted data analysis technologies and IT tools. The total funding request exceeded the available budget by more than four times.
The program received 151 applications from 16 member states and two from Ukraine. The interest shown indicates that authorities are seeking to expand digital capabilities even though AI does not yet appear in most national strategies.
The Commission's report analyzes the measures adopted by states to protect European revenues and expenditures in 2025. Information regarding the use of artificial intelligence comes from responses provided by national authorities.
The figures describe the integration of AI into the declared anti-fraud strategies and frameworks, not every tool used by all public institutions in a country. Some tax, customs, or judicial authorities may use digital technologies that have not been reported in this category.
The Commission is preparing a review of the European anti-fraud architecture, which will also analyze the use of modern technologies, data exchange, and cooperation between national authorities, OLAF, and the European Public Prosecutor's Office.
Fraud detected against the EU budget involved 274.3 million euros in cases reported by states and institutions for 2025. Other investigations regarding VAT and the Recovery and Resilience Facility are not fully included in the same statistical systems.
The expansion of artificial intelligence in anti-fraud controls will depend on the ability of states to connect databases, define legal guarantees, and transform algorithmic alerts into checks and investigations conducted by authorities.
Sources
Latest News
23:00
NASA has published images of the crater formed on the Moon after the Falcon 9 rocket stage crashed on August 5.
22:53
ECB: Europe cannot afford to miss the opportunities offered by artificial intelligence
22:49
Energy consumption is on the rise. When is the peak consumption expected this year?
22:45
The assessment of the buildings affected by the explosion in Rahova has begun. The operation will conclude on September 9.
22:35
Bogdan Ivan responds to Ilie Bolojan, asking him to confirm that large energy consumers will not be affected by power cuts.
See more news