Skip to content
VibeFormer
44 min

The Four of Them, and What Is Live Right Now

Each panellist's actual research in plain words, then what is happening in their field this month — the cases, the fines, the pending statutes — and the one thing to say to each. Written to be read in a single sitting.

Listen

0. Read this last, the night before

The earlier panel chapter gives you questions and answers. This one gives you context: what each of them actually studies, in plain language, and what is in the news in their area as of now. Being current is cheap and it is noticed.

1. Thibault Schrepel — the chair

What he actually does, stripped of jargon:

  • He studies competition law in digital markets — the law about whether firms are competing properly — and he does it using complexity science, which is the study of systems made of many interacting parts whose behaviour you cannot predict by examining the parts separately.
  • His own summary of his position: he treats markets as systems that evolve rather than settle. Most economics assumes markets reach a resting point and you can measure them there. He thinks they never rest, so a measurement taken at one moment describes something that has already moved.
  • He founded Stanford Computational Antitrust, a project connecting academics with over eighty competition agencies worldwide on using computational tools in enforcement. This is the single most relevant thing about him for your application — your position exists because he believes this work needs doing.
  • He built a knowledge graph of every European Commission competition decision from 1977 to 2025 — a database of decisions linked by their relationships, so you can ask questions across them rather than reading them one at a time.
  • He is critical of both mainstream economics and its loudest critics. He describes both the neoclassical account of markets and the neo-Brandeisian critique of it as reductionist — too simple. So do not arrive in a camp.
  • He writes with Alex 'Sandy' Pentland at MIT on competition between AI foundation models, and with Jason Pott on measuring how *open* an AI model really is.
  • He co-founded the Dynamic Competition Initiative with Nicolas Petit — the research programme arguing that what matters is competition over time through innovation, not price rivalry in a fixed market.
  • He hosts two podcasts, Scaling Theory and Stanford Computational Antitrust. Episode 40 of the latter covers language models colluding in a simulated duopoly, with some learning to hide the evidence.
  • His LinkedIn names three current specialisms: agentic workflows, MCP and graphs. That is a statement of what he is building with right now.

What is live in his field as of now:

What happenedThe detailWhy it matters to you
The record DMA fine against Google — 16 July 2026Two non-compliance decisions. Self-preferencing on Google Search under Article 6(5) — fined €460 million. Anti-steering on Google Play, blocking businesses from pointing users to cheaper channels elsewhere — fined €430 million. €890 million total, the largest DMA penalty so far. The full non-confidential text of the self-preferencing decision only became public in September 2026This is the single most useful current reference you have. It is the DMA actually working rather than the DMA as a design. And the delay between the July fine and the September publication is itself a point: the reasoning was unavailable for two months, which is an interesting fact about transparency in ex ante enforcement
Two specification decisions, same dayAlso 16 July 2026, the Commission issued binding specification decisions to Alphabet — one on interoperability with Android, one on access to Google Search data under Article 6(11). Published 10 September 2026Specification decisions are the DMA's most interesting instrument and almost nobody discusses them. Rather than fining after the fact, the Commission tells a gatekeeper precisely what compliance looks like. That is regulation by iterative specification, and it is the closest thing in EU law to the adaptive machinery Schrepel says the Digital Acts lack
Earlier enforcement, for contextApril 2025 — Apple found in breach of anti-steering; Meta found in breach of the obligation to offer a service using less personal data. Maximum DMA penalties are 10 percent of worldwide turnover, rising to 20 percent for repeat breaches, plus daily periodic penaltiesShows the pattern: the Commission is enforcing the DMA steadily rather than symbolically
The Digital Omnibus — in force 27 July 2026Moved the AI Act's high-risk timetable: Annex III to 2 December 2027, Annex I to 2 August 2028. Also proposes amendments to the Data ActHis own argument, demonstrated. He says the Digital Acts lack internal adaptive machinery, so adaptation has to happen through amendment. The Omnibus is adaptation through amendment, eleven months after he published that claim
The GenAI layer argumentHis public position: analysing the AI stack layer by layer misleads. Nvidia holding roughly 90 percent of chips looks alarming until you notice DeepSeek reportedly trained on around 2,000 chips for about $5.6 million against tens of thousands of chips and hundreds of millions for comparable modelsHe insists this cuts both ways — interactions dissolve false alarms *and* reveal real concerns, such as compute-for-equity partnerships that escape merger control. Do not use it only as a deregulatory argument

2. Georgiana Mirza

What her field is about, in plain words:

  • Digital ecosystems means groups of connected products and services run by one firm, where each part makes the others more valuable and harder to leave — a phone, its app store, its payment system, its cloud, its assistant. The competition problem is that the firm may compete across *several* markets at once, so analysing any one market in isolation misses the point.
  • Market regulation here means *ex ante* rules — obligations imposed in advance on designated firms — rather than *ex post* enforcement after an infringement. The DMA is the flagship example. The underlying idea is that if proving a case takes five years and the market moves in two, you must regulate before rather than punish after.
  • EU Data Spaces are the Commission's project to create shared, sectoral pools of data — health, mobility, agriculture, energy — that organisations can access under common rules. The animating hope is that pooling data breaks the data advantage of the largest firms.
  • The live question in her panel's framing: will data spaces genuinely open access, or entrench the firms that already hold the data? That question has no settled answer and it is a good one to be able to discuss rather than resolve.
  • The data-protection and competition convergence is the other half of this field. Data is both a competition asset and personal information, so two bodies of law with different logics now bear on the same facts. The landmark is Meta Platforms v Bundeskartellamt, where the Court of Justice accepted that a competition authority may take GDPR compliance into account in assessing an abuse — which merged two regimes that had been kept apart.

What is live in her field as of now:

What is happeningThe detailWhat to know
The EU Data Act is now bitingGeneral application began 12 September 2025. The next hard deadline is 12 September 2026 — new connected products placed on the EU market must be built for access by design, so the data a device generates is directly and securely available to its user in a structured, machine-readable formatThis is the most concrete thing in her area and it just landed. It is a legal mandate for machine-readable data access — which is precisely what Schrepel says the Digital Acts lack for oversight. The Data Act mandates it for devices and not for regulators, and that asymmetry is a real observation
Cloud switchingThe Data Act requires cloud providers to let customers move to a competitor, with switching charges fully banned from 2027. The Digital Omnibus proposes clarifying when early-termination penalties are permittedThis is interoperability as a competition remedy, imposed by regulation rather than won by litigation — the same move as DMA Articles 6(4) and 6(7), in a different sector
The Data Act reaches IoTIt applies to manufacturers and users of connected devices, data holders, cloud providers and in some cases public bodiesNote the overlap with Wisman. A connected device generating data the user can now demand access to is simultaneously a competition instrument and a surveillance object. Being able to see both at once is exactly the cross-project perspective your position is for
Ecosystem theories of harmAgencies increasingly frame cases around ecosystems rather than single markets, and the Commission revised its Market Definition Notice in 2024 partly to handle digital markets, zero prices and multi-sided platformsMarket definition is the step on which everything else rests, and it is being rewritten because the inherited tools broke. Your HHI point lands here: the index measures your market definition more than it measures concentration

3. Tijmen Wisman — and this is the section to study hardest

What he works on, in plain words:

  • Privacy and surveillance law — in particular when state monitoring of people is lawful. He teaches the two-stage test: is the interference legal (does it have a proper basis in law), and is it proportionate (the statutory phrase is *necessary in a democratic society*).
  • Proportionality is the concept to understand. It does not ask whether a measure works. It asks whether the intrusion is justified by what is achieved, whether a less intrusive option existed, and whether safeguards exist. A system can be accurate and still fail proportionality.
  • He has a long publication record on the Internet of Things — connected devices — including RFID tags, consumer privacy in smart devices, and the privacy implications of smart electricity meters and the smart grid. That is roughly fifteen years on the same theme: ordinary objects quietly generating personal data.
  • He is connected to the civil-rights platform that brought SyRI, the case that struck down a Dutch state fraud-detection system. Read the next table before anything else.

And the Dutch record since then, which is remarkable and ongoing:

CaseWhat happenedWhy it is useful to you
The childcare benefits scandal (*toeslagenaffaire*)Revealed from 2019: the Dutch tax authority used a self-learning algorithm to build fraud risk profiles for childcare benefit claims. Thousands of families were wrongly accused and financially ruined. Amnesty International's 2021 report *Xenophobic Machines* documented discrimination and nationality-based profiling built into the design. The scandal brought down the Dutch government in January 2021The most consequential algorithmic governance failure in Europe. It is why Dutch scholars treat automated risk scoring as a civil-rights question rather than a technical one, and it explains the register Wisman will use
DUO student grantsBetween 2012 and 2023 a rule-based risk-profiling algorithm at the Dutch education agency contributed to indirect discrimination when checking whether students had wrongly received grants. Reported to the Dutch Parliament in 2024Note: rule-based, not machine learning. No neural network, no training data — and it still discriminated. This defeats the assumption that transparency alone fixes the problem, and it is a genuinely important qualification on your own symbolic-layer enthusiasm
Dutch police abandoned CAS — February 2026The police discontinued the Crime Anticipation System, a crime-prediction tool. They had already discontinued RTI-G, an instrument predicting individual risk of violence, in September 2023 — criticised as vulnerable to ethnic profiling and as lacking scientific supportEight months ago, and the most current item in his field. Note the second ground: not illegal, *unsupported*. A tool withdrawn because nobody could show it worked. That is the validation gap, and it is your argument
Supervisory pressure is continuousThe Dutch Data Protection Authority and the Netherlands Institute for Human Rights have repeatedly flagged unlawful and discriminatory data processing by government bodies, and a May 2026 academic contribution argued that without principled measures the risk of discrimination and harm remains too greatThe issue is live rather than historical, and *proportionality* and *discrimination* are the operative words rather than *accuracy*

4. Catalina Goanta — and her field is becoming legislation right now

What she does, in plain words:

  • Associate Professor of Private Law and Technology at Utrecht University. Private law is the law between individuals and companies — contracts, consumer rights — as opposed to public law, which governs the state.
  • She holds an ERC Starting Grant called HUMANads, studying the impact of content monetisation on social media and rethinking fairness in private law in the context of platform governance. *Content monetisation* means the ways people earn money from posting — sponsorship, ad revenue, affiliate links, tips, subscriptions.
  • She previously ran the Maastricht Law and Tech Lab, which was unusual for having computer scientists resident inside a law school. This is the most important fact about her for your purposes: she does the engineering herself, at scale.
  • Her empirical work is large. One study covers 292,315 posts by Dutch influencers across Instagram, YouTube and TikTok, in two languages. Another covers on the order of a million Instagram posts by 400 creators across four countries.
  • Her findings, which you should actually know: influencer marketing is generally underdisclosed, and — counterintuitively — bigger influencers are not necessarily more compliant with disclosure rules. And in the multi-country study, although sponsored posts get lower engagement on average, properly disclosing an ad does not reduce engagement any further. *(Paraphrased from the papers' own abstracts.)*
  • Why that last finding matters: the industry's standing excuse for not labelling ads is that labels kill reach. Her data says the label is not what costs you. That is an empirical finding that removes a legal defence, and it is a very good example of what computational legal research is for.
  • She has also proposed a legal compliance API for enforcing the DSA on social platforms — a machine-readable interface through which compliance could be checked automatically rather than by reading reports.
  • And a study of 85 TikTok policy documents examining how influencers are classified — including as *independent contractors* — and how hard that documentation is to navigate.

What is live in her field as of now:

What is happeningThe detailWhat to know
The Digital Fairness ActA European Commission legislative initiative, led from the justice and consumer protection side under Commissioner Michael McGrath. It is expected to tackle dark patterns, influencer marketing, addictive design of digital products, unfair personalisation exploiting consumer vulnerabilities, and fake or misleading reviews. Expected around Q4 2026 after repeated slippage, and senior Commission figures are reported to be split over how far it should reachHer research subject is turning into a statute, right now. If you know one current thing in her area, know this. And the honest observation: the DSA already prohibits dark patterns and has been fully in force since 2024, so the DFA is partly an admission that a prohibition without measurement does not change behaviour — which is precisely what her 292,315-post study demonstrates
DSA enforcement is runningThe DSA has applied fully since February 2024, with Article 25 prohibiting interface designs that distort user choices, and Article 40 compelling very large platforms to give vetted researchers data accessArticle 40 is her structural interest and yours. It is the only place in EU law compelling a private firm to open its data to outside researchers — and it is the template for the argument that agencies should open their screens to audit
The creator economy as a labour questionHer TikTok work examines influencers classified as independent contractors, and platform documentation that is formally available and practically unnavigableFormal compliance against effective compliance. **The same gap as *a human signed the decision* against *the human actually reviewed it***, which is your Article 14 point in a different domain

5. The thing all four have in common

PanellistTheir live headlineYour single best line
SchrepelGoogle fined €890m under the DMA on 16 July 2026, plus two specification decisions; Digital Omnibus in force 27 JulyLayer interaction applies to the agency's own instruments — a screen's error rate has a shelf life nobody states
MirzaData Act access-by-design deadline 12 September 2026; cloud switching charges banned from 2027We mandate machine-readable data access for devices and not for the regulators supervising them
WismanDutch police abandoned the CAS crime-prediction tool in February 2026 — the earlier instrument was dropped partly for lacking scientific supportSyRI failed on opacity, not accuracy — and the defect is unaddressed for undertakings, though DUO shows rule-based systems discriminate too
GoantaDigital Fairness Act expected Q4 2026, targeting dark patterns, influencer marketing and addictive design — Commission split on scopeThe DSA already banned dark patterns and the behaviour did not change; a rule without an instrument is unenforceable in practice

6. If you remember ten things

  1. Google, 16 July 2026: €460m for self-preferencing on Search, €430m for anti-steering on Play — €890m, the biggest DMA fine yet. Full reasoning only published in September.
  2. Specification decisions are the DMA's most interesting tool — the Commission telling a gatekeeper what compliance looks like, rather than fining afterwards. Two were issued to Alphabet the same day.
  3. The Digital Omnibus came into force 27 July 2026 and moved the AI Act high-risk dates to December 2027 and August 2028. That is Schrepel's adaptivity argument proving itself.
  4. Data Act: access-by-design for new connected products from 12 September 2026, cloud switching charges banned from 2027. Machine-readable access mandated for devices, not for regulators.
  5. SyRI, February 2020, The Hague: struck down under Article 8 ECHR for opacity about the risk indicators and the model — not for inaccuracy. Learn this one properly.
  6. The childcare benefits scandal brought down the Dutch government in January 2021. It is why Dutch scholars treat risk scoring as a civil-rights question.
  7. DUO: a rule-based algorithm produced indirect discrimination over 2012–2023. No machine learning involved. Transparency is necessary and not sufficient — and this qualifies your own symbolic-layer argument.
  8. Dutch police dropped CAS in February 2026, having earlier dropped a violence-prediction tool partly for lacking scientific support. A tool withdrawn because nobody could show it worked.
  9. The Digital Fairness Act is expected Q4 2026 — dark patterns, influencer marketing, addictive design, unfair personalisation. Goanta's research area becoming law, with the Commission split on scope.
  10. All four fields have a rule without an instrument. Say that, and say the accuracy strand is what the other two rest on rather than a technical annexe.