Documents: EU prosecutors are probing how Atos' Moscow office helped build the EU's border system, which will establish the EU's largest personal info database
www.ft.com/content/1541... @financialtimes.com Mastodon: Tim Mak / @timkmak@journa.host : The Moscow office of a French IT group is that helped create the new electronic #EU border system is being investigated. — The Russian branch bought software to collect vast amounts of PI data for the project and is believed to have a license granting the FSB access to it's work. — https://www.ft.com/... Ricardo Carvalho / @rabc@hachyderm.io : Atos got the contract to build the border system for EU then routed it to be built by cheap labor in Moscow. — Software industry in the EU is so fucked up sometimes. — https://archive.is/...
Context & Ripple Effects
The probe sharpens questions around Atos after related reporting tied the company to delays in the biometric Entry/Exit system’s rollout. Because the system is intended to consolidate personal information at exceptional scale, the development environment and access controls are as consequential as the delivered software.
It also sits in a longer EU record of disputes over law-enforcement data governance, including the watchdog’s order for Europol to delete unlawfully held personal data. The issue here is whether sensitive public infrastructure can be governed safely when work is distributed across jurisdictions.
First-order effects
- Atos faces prosecutorial scrutiny over the role of its Moscow office and reported access to work connected to the EU border system.
- EU authorities operating or overseeing the project are likely to examine development provenance, software procurement, and access permissions associated with the Russian branch.
Second-order effects
- Other suppliers to security-sensitive EU systems face stronger pressure to document subcontracting chains, developer access, and where personal-data tooling is built or maintained.
- The case raises the compliance cost of using lower-cost offshore development for public-sector systems holding sensitive data, potentially narrowing procurement options for incumbents and contractors.
Third-order effects
- If investigations repeatedly uncover cross-border access risks in sensitive government systems, EU procurement is likely to place more weight on operational control and auditable delivery locations alongside price and technical capability.
- The broader structural question is whether privacy and security oversight can keep pace with large shared databases whose vendors rely on globally distributed engineering; the answer will shape future public-IT contracting.
The trend: This is one data point in the shift from cost-led public IT outsourcing toward sovereignty- and access-led procurement for sensitive digital infrastructure.