The legacy of 9/11: intrusive financial surveillance and violations of fundamental rights under US economic pressure

The attacks of 11 September 2001 were an enormous turning point. They exposed an unexpected vulnerability of the United States and triggered a powerful political response: the war on terror. What followed was not only military and security policy. A far-reaching regulatory and surveillance infrastructure was built in the physical world and, crucially, throughout the financial system. The US was the main driver behind it, both formally and informally.

Twenty-five years later, Europe should take stock.

Many of the current excessive monitoring practices carried out by banks and financial institution and so-called obliged entities, are based on intrusive anti-money-laundering rules. The resulting financial discrimination, automated risk classification and the gradual erosion of the presumption of innocence in everyday financial life can be traced back to the security paradigm that was boosted after 9/11.

HRIF.EU was set up to counter this blind copy-paste mechanism, and ensure that the human rights are properly weighed in advance (EX ANTE) by regulators, supervisors and institutions all involved in the surveillance and monitoring work.

How did we get here?

A useful starting point for understanding how Europe arrived at today’s system of intensive financial monitoring is Ben Coates’ Legalist Empire, which shows how the United States has long used law, legal institutions and international rule-making not merely as neutral frameworks, but also as instruments through which political and economic power can be projected beyond its borders.

That longer historical perspective helps explain the significance of the post-9/11 shift described from a rule-of-law perspective by Ybo Buruma in De onvoltooide rechtsstaat: from the late 1990s onwards, and with much greater force after the attacks of 11 September 2001, security considerations increasingly came to outweigh traditional safeguards for individual rights.

Mara Wesseling’s The European Fight against Terrorism Financing then documents how that security paradigm was translated into the financial sphere, in particular through the rapid expansion of the FATF mandate after 9/11 and the subsequent incorporation of FATF standards into European AML/CFT regulation. It also discusses the 2006 disclosure of US access to SWIFT financial messaging data, taking place immediately after 9/11. Wesseling also documents that prior to the 9/11 attack, there was no momentum at all for the intrusion of human rights.

Carolin Kaiser’s 2018 doctoral thesis, Privacy and Identity Issues in Financial Transactions: The Proportionality of the European Anti-Money Laundering Legislation, provides the crucial European fundamental-rights analysis of what this regulatory development means once translated into Union law.

Kaiser observes that AML legislation subjects essentially the entire population using financial services to identification, transaction monitoring, reporting and long-term data retention, including people who have never been suspected of any offence and transactions revealing highly intimate aspects of private life. She therefore compares the breadth of European AML surveillance with the indiscriminate data-retention regime struck down by the Court of Justice and argues that the AML framework raises similarly fundamental questions of necessity and proportionality.

Where is the place for human rights assessments?

The tension of all those intrusive rules becomes apparent in local rulings such as the Dutch SyRI-case: intrusive monitoring considered disproportional and void under EU-rules, despite the existence of a formal law. But there are also numerous CJEU rulings that make the relation to fundamental rights more clear: (Kadi and Al Barakaat -Joined Cases C-402/05 P and C-415/05 P), Digital Rights Ireland (Joined Cases C-293/12 and C-594/12), Tele2 Sverige and Watson (Joined Cases C-203/15 and C-698/15), Privacy International and La Quadrature du Net (C-623/17 and Joined Cases C-511/18, C-512/18 and C-520/18), Schrems II (C-311/18), Luxembourg Business Registers/Sovim (Joined Cases C-37/20 and C-601/20).

Taken together, these judgments point to a principle of considerable importance for contemporary AML/CFT and financial-surveillance policy: neither national security, the fight against terrorism, sanctions enforcement nor the prevention of money laundering reverses the constitutional order of analysis. The legitimacy of the objective does not establish the legality of the means. Under EU law, large-scale monitoring, data sharing, financial blacklisting and restrictions on economic participation must still satisfy the Charter requirements of legality, necessity, proportionality, independent scrutiny and effective judicial redress.

Despite these rulings, most policymakers view the EU-rules on anti-money laundering as a free pass to invade human rights and let the Court of Justice deal with the unintended consequences. HRIF.EU does not support this approach and our objective is to ensure EX-ANTE consideration of human rights impact in regulatory, supervisory and monitoring/KYC processes. Weighing the charter rules should be a part of the monitoring process, not merely an afterthought.

HRIFEU’s European fundamental-rights agenda for financial regulation

The next stage of rules and legislation should therefore not consist of another layer of compliance rules on top of an already enormous compliance infrastructure. Europe needs a different architecture. We need to accept that the EU-US link must be severed and we must stop copy-pasting FATF-rules (and step out of the FATF – see article here on the impact of the new geopolitical course of the US).

Our response to the AMLA Consultation on KYC and monitoring can be read here. In essence we outline the following:

  • The Charter must come first. AMLA, the European Commission, national supervisors, FIUs and financial institutions should treat the Charter of Fundamental Rights as an operational framework, not as an afterthought.
  • Fundamental-rights impact assessments must become part of AML/CFT design. Necessity, proportionality and subsidiarity should be demonstrated before intrusive monitoring systems are introduced, not reconstructed afterwards.
  • Financial risk indicators must be contestable, verifiable and correctable. Individuals need to know when significant financial decisions are based on adverse indicators, subject to narrowly defined lawful exceptions, and must have realistic possibilities to challenge errors.
  • Redress must restore the person, not merely correct a database. Where unfounded indicators lead to financial exclusion, remedies should include correction across recipient systems and, where appropriate, restoration of banking access and compensation.
  • Privacy-enhancing behaviour must not be equated with criminal risk. Encryption, privacy tools and legitimate efforts to minimise unnecessary data exposure are part of European fundamental rights.
  • EU and third-country law must be clearly separated. European institutions and businesses should not automatically reproduce foreign sanctions, watchlists or risk classifications that have no basis in Union law.
  • Europe should actively pursue fundamental-rights reform and reconsider aliging with the FATF.
  • Critical financial infrastructure must become more European and more resilient. Payments, cloud infrastructure, public-sector financial services and access to cash should not depend unnecessarily on jurisdictions whose legal priorities diverge from those of the Union.

The Hague Declaration: protecting human rights and preventing financial repression is explicitly on the international agenda

The analysis of HRIF.EU aligns with that of many concerned other observers, members of Parliament and NGO’s such as the Open Diaologue Foundation. Thanks to this international community in Juy 2026, the OSCE Parliamentary Assembly adopted the Hague Declaration. This declaration marks an important shift in the international debate: financial surveillance is no longer viewed solely as a technical instrument of enforcement, but also as a potential source of fundamental-rights violations requiring independent safeguards and legal redress.

One of the resolutions is on Countering Transnational Financial Repression and the Weaponization of INTERPOL Executive Management, Anti-Money Laundering and Countering the Financing of Terrorism, and Cybersecurity. This resolution recognises explicitly that mechanisms originally designed to combat crime and terrorism — including AML/CFT frameworks, mutual legal assistance, international police co-operation, cybersecurity rules and cross-border financial data exchange — can themselves be misused to surveil, intimidate, financially exclude or otherwise exert pressure on individuals and organisations across borders.

While technically there may be all kinds of flavours in terms of precise changes that can be made, HRIF.EU seeks to clear away from changing the FATF itself. EU must leave and do away with the FATF-structure, which in itself is still a project instead of a formal international organisation. The reason is that behind the FATF-structure there is always US coercion taking place and the era of US coercion via the FATF must stop, in order for EU institutions and EU obliged entities to take up their own responsibility in protecting human rights.

HRIF.EU calls upon each organisation to take its responsibility under EU rules

HRIF.EU understands the technicalities of sanctions rules well enough to see that the blind copy-pasting of US rules is not a necessity but a self-inflicted and chosen commercial position to protect economic interests. In essence EU companies use the US-rules or US-inspired rules to inflict human rights infringements upon their customers, while their own EU Charter of fundamental rights can form a fine backbone to not do so. EU companies, governments and privacy supervisors clearly lack the will to act and the will to stand up against injustice.

HRIFEU is not open for compromising on the EU ideals. Each company, supervisor and regulator has an independent moral and legal obligation to respect the Charter of fundamental rights and the balancing of oblogations that it requires. We have seen the impact of 25 years of neglecting human rights. It doesn’t work. The Dutch Court of Audit clearly outlines this in its March 2026 report on the suspicious reporting systems used by the Dutch banks/government/FIUs.

Europe makes Europe Europe

We must wake up to reality. There is no more alignment with the US as the US does not back the rule of law any more but merely used the rule of power. The behind the scenes coercion of the US now becomes visible in a unjustified abuse of sanction rules and unlawful pressuring of governments and companies around the world. So Europe needs to stand on its own feets.

Europe has a range of challenges ahead. We need to stand firm, act and become independent and move towards a robust economic and legal infrastructure that is resilient enough on its own and is not dependent on trade partners or countries that do not share the same values as Europe. We need to cherish and protect our fundamental rights.

In the area of economic/financial transactions this means: we need to step back from a long lasting error of judgment. Using financial infrastructure to crackdown on a war of terror does not work. There are no provable results. Targeted investigations by educated police teams needs to be the way forward and financial institutions and obliged entities should be relieved of their task to monitor everything and everyone because – in essence – the US wants us to.