Regulatory Architecture and Its Discontents
A Contextual Analysis of the EU SMR Strategy
Regulatory Architecture and Its Discontents
A Contextual Analysis of the EU SMR Strategy

This is the third post in a series exploring the contextual dimensions of nuclear security and the institutional, political, and societal factors that shape whether technical security systems perform as intended. The second post established the analytical framework. This one applies it to a specific and consequential regulatory context.
Setting the Scene
The EU’s SMR Strategy (COM/2026/117), published in March 2026, is one of the more consequential documents framing the region’s nuclear policy direction. It sets the regulatory architecture for SMR deployment across Europe. What it includes, and importantly what it does not fully address, will shape nuclear security outcomes for decades.
The strategy does not operate alone. The Strategic Action Plan of the European Industrial Alliance on SMRs provides the most operationally detailed elaboration of how the strategy’s ambitions are being implemented. Through Technical Working Group 6 (TWG6) on Safety, Security, and Safeguards, the Action Plan promotes the Safety-Safeguards-Security (3S) by-design methodology as a cornerstone of SMR development. It frames the 3S approach as essential for ensuring that national differences in requirements do not hinder serial production or competitiveness. Together, these instruments constitute an ambitious policy environment that is of considerable analytical interest.
Before examining what the policy environment does not fully resolve, one structural feature of EU nuclear governance requires acknowledgement. Under Article 4(2) of the Treaty on European Union, essential national security remains the sole responsibility of each Member State. EU instruments can harmonise safety standards and promote design methodologies. Yet physical security requirements such as response force mandates, armed guard provisions, and command authority are determined entirely by national regulators. Bodies like the European Nuclear Safety Regulators Group (ENSREG), through its SMR Task Force, and the IAEA’s Nuclear Harmonization and Standardization Initiative are actively working on harmonisation challenges across this layered architecture. While that work is substantive and necessary, it does not eliminate the governance coordination gaps that a contextual analysis of the EU policy highlights.
Autonomous Security Dilemma
The EU’s SMR policy framework, emphasized through the Strategic Action Plan and COM/2026/117, promotes AI-driven anomaly detection and automated security responses as integral to the 3S by Design approach. The Strategic Action Plan explicitly frames AI and advanced digital technologies as enabling real-time monitoring, predictive maintenance, and anomaly detection for SMR operations. These are described as appropriate where implemented in compliance with 3S requirements.
However, the EU AI Act simultaneously classifies AI systems used in critical infrastructure security as ‘high-risk’, thereby mandating human oversight, algorithmic transparency, and explainability requirements before deployment. Passive safety and security systems that depend on millisecond response times cannot pause for an explainability protocol. A security response that requires human oversight at the point of automated intervention is, in operational terms, a different security architecture than one that does not.
This constitutes a governance gap between two regulatory frameworks developed without sufficient reference to each other. The SMR policy instruments promote a security methodology that the AI Act simultaneously constrains. Addressing this requires governance analysis that examines which institutional body owns the coordination gap, what incentive structures exist to resolve or defer it, and what regulatory independence looks like when two legislative frameworks are in tension simultaneously.
Insider Threat and Privacy Collision
Robust insider threat prevention increasingly relies on biometric monitoring and behavioural analytics. Continuous monitoring, anomaly flagging, and psychological profiling tools are being incorporated into security frameworks because personnel reliability programmes addressing individual motivational factors operate in a space that periodic checks alone do not.
Yet the EU’s General Data Protection Regulation (GDPR) classifies biometric data as special category data. It restricts automated profiling, requires explicit consent, and renders that consent legally ambiguous where there is an inherent power imbalance between employer and employee. In a nuclear facility context, security clearances are directly tied to employment, and employment to income. As such, the conditions for genuinely free and informed consent are structurally compromised.
The result is a security architecture that EU SMR policies support in principle while EU law simultaneously constrains in practice. An operator seeking to implement the insider threat monitoring that 3S by Design logically implies may find that the most effective tools are the ones most exposed to legal challenge. This is a political economy problem as much as a legal one. Understanding what organisational and regulatory conditions might resolve or entrench this tension, and what incentive structures shape whether operators and regulators treat it as a problem to solve or a risk to manage quietly, is precisely what contextual analysis is designed to bring to the forefront.
What Contextual Analysis Reveals
Both friction points share a common characteristic. They extend beyond the ‘fence line’, emerging from the intersection of governance frameworks, stakeholder incentive structures, and the broader regulatory environment driving SMR deployment decisions. A technical compliance review of a facility’s security architecture alone will not detect these points of friction. They require a different analytical frame.
Governance lens: which institutional body is responsible for resolving the coordination gap between the AI Act and the 3S by Design security mandate? Is the regulatory authority with oversight of nuclear security the same body with competence over AI Act compliance? If not, what coordination mechanism exists, and does it have the authority and incentive to act before deployment decisions are made?
Political economy perspective: what incentive structures shape how operators navigate the GDPR constraint on insider threat monitoring? Where compliance with one regulatory framework creates exposure under another, operators face a choice between security effectiveness and legal risk. How that choice is made is not determined by technical assessment. It is determined by the distribution of accountability, the costs of non-compliance, and the informal organisational cultures that shape how security and legal functions interact within operating organisations.
Societal resilience insights: what happens to public trust and institutional legitimacy when security systems presented to communities as protective are simultaneously operating in legal grey zones? Where communities adjacent to SMR facilities are already navigating low institutional trust, the discovery that security architecture is legally contested has impact. It is a condition that can amplify social licence erosion in ways that may not be anticipated.
A third illustration, drawn from the Strategic Action Plan itself, reinforces the point. The document promotes cybersecurity measures for SMR digital systems (firewalls, intrusion detection, and encryption) as essential to protecting operations from cyber threats. It does so while referencing the EU Digital Act framework, but does not address the AI Act constraints that apply to the AI-driven elements of those same systems. The gap is visible within a single policy instrument. That is not a criticism of the document’s authors. Rather, it is an illustration of what shortfalls in governance look like before becoming deployment issues.
Looking Forward
The EU’s SMR Strategy and its associated policy instruments represent a necessary and substantive effort to set the conditions for secure, safe, and competitive SMR deployment across Europe. The friction points identified in this post are not arguments against that ambition. They are structural features of the current regulatory environment that contextual analysis highlights and that technical compliance review may overlook.
These gaps can be addressed. Bodies like ENSREG, through its SMR Task Force, and mechanisms like the Net-Zero Industry Act (NZIA) regulatory sandboxes are beginning to provide the institutional space for resolving these kinds of deployment barriers. That work signals that the tension between regulatory ambition and governance coherence is recognised. Recognition, however, is not resolution.
What it has not yet fully produced is a systematic upstream methodology for mapping governance coordination gaps before deployment architecture is locked in and before capital commitments make course corrections expensive. That methodology is the focus of the next post in this series: what contextual analysis looks like as a structured practice, what questions it asks, and where in the deployment decision cycle it should be applied.
The fence line is necessary. It’s not always where security is determined.
메타데이터
- post_id
- 09dc3e5e07e8
- slug
- regulatory-architecture-and-its-discontents-09dc3e5e07e8
- url
- https://medium.com/@aofleming44/regulatory-architecture-and-its-discontents-09dc3e5e07e8
- canonical_url
- https://medium.com/@aofleming44/regulatory-architecture-and-its-discontents-09dc3e5e07e8
- author_url
- https://medium.com/@aofleming44
- status
- ok
- fetched_at
- 2026-06-28 04:42:08