A Commission staff working document published on 28 July 2026 reports the state of play of the 44-action Commission Anti-Fraud Strategy (CAFS) action plan as of 31 May 2026, detailing progress on fraud prevention, detection, and investigation tools. The document, accompanying the 37th Annual Report on the protection of the EU's financial interests, shows tangible advances in digital tools such as Arachne+, EDES, IMS, and GETI, with specific deadlines for deployment and compulsory data feeding.

The Arachne+ risk-scoring tool saw a 56.31% increase in users to 26,084, with 23 Member States using it voluntarily (18 for the Common Agricultural Policy, 19 for the Recovery and Resilience Facility). Service activation occurred on 28 April 2026, and migration to Arachne+ must be completed by 30 June 2026. Feeding data becomes compulsory from 1 January 2028, with full operational readiness for all management modes by the same date. The EDES database now allows case creation by importing a Business Partner number from SUMMA, and two-factor authentication will be required from October 2026 for external accounts. Connections to the ECFIN system have been improved, and eSubmission is now linked to the EDES search web service. Updated guidelines and a video capsule on EDES are under development for the second half of 2026.

In the SUMMA system, a Project Initiation Request for a Business Partner Compliance & Risk Intelligence Hub was submitted on 21 April 2026, with a Project Charter expected by end of 2026 and implementation planned for 2027–2028, subject to governance approval. The Irregularity Management System (IMS) saw improvements in July 2025 (automatic population of initiating authority field) and April 2026 (revised dropdown lists), and new competences were added for the Ukraine Facility (2025), Social Climate Fund (September 2025), and Reform and Growth Facility for Western Balkans (February 2026). The GETI analytical tool delivered six analytical reports flagging potential irregularities to investigative units by May 2026, and a pilot integrating risk indicators into a generative AI tool was conducted throughout 2025.

On IT security, the 4th quarterly 2025 IT Security and Risk Report was released in February 2026, a new Framework Agreement with the European Parliament was published in the Official Journal on 12 May 2026, and a new tool (SUE) was rolled out for secure classified information exchange with EU entities and Member States. Actions 6, 7b, 8, and 10 were completed by end of 2024.

The document impacts several stakeholders. EU taxpayers benefit from improved fraud detection and prevention, potentially reducing financial losses. National authorities of EU Member States face new compliance requirements, particularly the compulsory data feeding into Arachne+ from 2028, which may increase administrative burden. EU producers and beneficiaries of EU funds (e.g., CAP and RRF) may experience more rigorous scrutiny through risk-scoring tools, potentially slowing fund disbursement but also reducing fraud risks. EU regulatory bodies, such as OLAF and the Commission, gain enhanced analytical and investigative capabilities through tools like GETI and SUMMA, improving efficiency but requiring continued investment in IT security and training.

The institutional follow-up will involve the European Parliament and Council reviewing the annual report and the CAFS action plan implementation. The Commission will continue to monitor progress, with further updates expected in subsequent annual reports. The next milestones include the completion of Arachne+ migration by June 2026, two-factor authentication for EDES from October 2026, and the SUMMA project charter by end of 2026.

← Atlas › News › Budget & Administration