1. The rule, and the 111 billion behind it
The Commission buys staff time, people and the hours they work.
When the European Union funds a project, most of what it pays for is staff time. And “staff” means everyone whose hours are charged to a grant: the researcher, yes, but also the person who builds the project website, the one who designs the brochure, the manager who organises the conference, the officer who sends email campaigns, the director who runs the budget. All of them are personnel, their hours are billed when their time is declared to a grant.
The Commission says how much this costs, in its own guidance presentation on PERSONNEL UNIT COST for HORIZON EUROPE:
“Personnel costs represent: approximately two thirds of the budget in a project; the largest single source of financial errors in Horizon 2020.
Two thirds pay for human time. The Commission goes even further in its Communication to Horizon 2020 beneficiaries ARES(2022)907396-08/02/2022 and states
The Commission’s own figures for the research programmes are at least 74.3 billion euros for Horizon 2020, and at least 93.5 billion for Horizon Europe. Two thirds of the two programmes together represent more than 111 billion euros of staff time. The count is only for these two research programmes, on their smallest official numbers, and leaves out every other EU programme that pays people against a timesheet.
The rule for proving those hours is the same across the Union.
Every hour must be recorded. In practice that is a timesheet, or a signed monthly declaration of the days worked, signed and dated. It is the only document that proves a real person spent real time on the project the public paid for.
The same funding contract sets a limit, and it is the limit at the centre of this investigation. Under the Annotated Grant Agreement the Commission lists 37 programmes, page 49, “the total number of day-equivalents declared in EU grants, for a person for a year, cannot be higher than 215”. Not 215 days per project, but 215 days in total, across every EU grant one person holds, because one person has only one working year to give.
2
2. The timesheet and who checks it
Now the part that matters. The record must exist, but the record stays with the funding beneficiary.
The agencies that pay for the hours never receive it. In a written reply in November 2025, the European Research Executive Agency, REA, which manages a large share of EU research funding, told me: “REA does not receive working hours per person but only aggregated tables for the total of efforts or working hours.” CINEA, the agency that funds climate, infrastructure and environment projects, confirmed the same in January 2026.

So the timesheet is real, and required, and signed. But it lives in a filing cabinet at the organisation that received the public money. What travels up to Brussels is a total.
And a total cannot catch the one thing the 215-day limit was written to catch. In a small organizational team, one person can be charged at 60% of their time to one European project, and at 70% to another. Both grants are real, both charges are allowed. But 60%+70% is 130%, and no one has 130% of a working year. To see it, someone would have to take that one person and add up every day they declared, across every grant they are on.
So I asked the European Commission, in writing, in April 2026 and again in June:
“is there any system, anywhere in the Union, that adds up one person’s declared time across all their concurrent EU grants?”
The reply came from the cabinet of the Commissioner for Budget, Anti-Fraud and Public Administration – Piotr Serafin.
He is also the one tasked with leading the work to prepare the next long-term EU budget. Fifteen pages. It described the checks on paper that stop the same project being funded twice, the eligibility rules, the internal database of excluded companies, the audits carried out after payment, ARACHNE the data-mining tool. It listed a great deal.
The cabinet did not name a single system that adds up one person’s hours across parallel grants. The question went unanswered, and it stays unanswered to this day.
Above the Commission sits its own external auditor, the European Court of Auditors, whose job is to check that EU money was spent as the rules require. I asked the Court whether it verifies personnel costs – the hours behind the money. It told me its transparency audit “did not include verification of personnel cost declarations”, and that when personnel costs do fall into its sample, it examines them only “occasionally”, never “to express an opinion on the revenue and/or spending of one or more specific beneficiaries”. Its purpose is a global estimate of error across the whole budget – not a single beneficiary, and not a single person’s hours.
The rest of this investigation is what I found when I went looking myself for the last person paid for EU-funded work.
3
3. I went looking for the people paid for the EU-funded work.
To follow public money to the people paid for it, I did the one thing the EU does not do. I followed the money trail, from the grant in the EU’s own Financial Transparency System until the last person paid disappeared. I did so at scale, not by sampling, for the entire period of 2014-2024.
I chose Belgium: home to the institutions that award the money, and to the organisations that live closest to them.
I traced 7.29 billion euros to 758 Belgian organisations that the Commission’s own database files under one label: “non-profit, non-governmental”. It is a label the Commission stretches to cover almost anything, charities and advocacy groups, universities, research institutes, and even consultancies, all counted together as one sector. Those 758 entities hold 92% of every euro the EU records going to that sector in Belgium.
Then, for each of the 758, I went looking for the people. The work is real, grants run, reports are filed, money is paid. The people should show up twice. First in the employer register, which sorts every Belgian employer into a band by size: 1 to 4 staff, 5 to 9, 10 to 19, and up. Then again in the annual accounts, under Code 62, the payroll line, and in the declared FTE, full-time equivalents, the number of people working a full year. Read together, the two records should have answered a simple question: how many people did the EU-funded work, and what were they paid.
Here is what I found, and for Belgium it is a pattern.
Funding concentration: the money is heavily concentrated at the top. Just 30 organisations hold 4.13 billion euros, 56.7% of the total sector verified funding. The top 100 hold 5.45 billion, 74.8% of the funding. These are the main serial grantees. The remaining 658 organizations, the overwhelming majority, share what is left, 1.84 billion euros – 25.2%.
Verified EU funding by employment band: 298 organizations, holding 1.2 billion euros, show 4 workers or fewer, against millions in EU-funded work. Of them, 126 organisations, holding 680 million euros, have no registered employees at all. Not few. None.
Fiscal transparency: 285 organizations, holding 1.74 billion euros, file no financial accounts a citizen can verify.
Parallel grants: 251 were running 10 to 889 EU-funded actions at the same time, each one watched individually by the agency that awarded it, no institution seeing the whole.
Large sums of public money, almost no visible staff, no readable books, stacks of parallel funding no single authority oversees as a whole.
This is not how anti-fraud reads data. It does not take one chart at a time. It scores every organisation against several red flags, then looks for the organizations showing more than one. A single red flag means nothing. Plenty of organisations have few staff, or many grants, or file only what the law requires for their size.
So I put the three together. 44 of the 758 show all three at once: 4 workers or fewer, 10 or more EU-funded actions running at the same time, and no public financial accounts a citizen can read. Between them they hold 360 million euros. 20 of them have no employees at all.
A red flag is not proof of anything, and I accuse none of them. It is where someone is supposed to start looking. So I did.
4
4. The people are invisible, lumped in Code 61, “services and miscellaneous goods”
In Belgium, the people are not on the payroll – Code 62, where employees are counted in the employer register and the money paid is visible. The people are paid as consultants, have their own individual companies and are lumped into Code 61, “services and miscellaneous goods”, the same line that carries the rent, the electricity and the office supplies. Paid as a consultant through a company, a worker is counted nowhere publicly: no name, no rate, no hours.
So the two records that should show the workforce come up empty, because in Belgium what you must file depends on your size, and size is set by two things: how many people you employ and how much money you manage. Keep the headcount low with contractors, spread the money as income deferred across several years, and an organisation handling millions stays small on paper, and out of sight for good.
The organisations that file financial accounts in full give it away: a small percentage goes on payroll, the rest on Code 61.
For the sharpest test, I wrote to five of them, among the largest. Each received the exact figures drawn from its own public filings, and one question: who did the EU-funded work, and where can a citizen verify it? Not one found an error in the figures. Every one explained where the workforce was. Here is what they said.
Go back to the rule. No person may declare more than 215 days a year across all their EU grants. One person, one working year.
The organisation is the only place that person exists. The beneficiary holds the contracts and it holds the timesheets. What it sends to the agency that pays is a total: months of work, on a project. What it shows the public is Code 61: a sum of money, no name, no hours.
So the rule exists and is written about a person nobody outside the organisation can see. From outside, nobody can test it. So I went to the ones whose job it is to look inside.
5
5. The watchdogs that do not see the whole chain
The money is public, the people are not. So who is meant to catch a gap like this? The Union has five safeguards, and each is built to reveal part of the risk: the Commission’s own auditors, a data tool, an anti-fraud office, a prosecutor, and an external auditor. I tested all five and not one can see the whole chain, from the grant to the last person paid.
The first is the Commission itself. It pays the money, and it checks the money. Its auditors can open a beneficiary’s files after payment and test what was declared. For Belgian non-profits they did it 45 times between 2017 and 2024, testing 29.27 million euros of staff costs. Those audits, the Commission wrote, “concern H2020 only, as for Horizon Europe no audit exist yet”. Horizon Europe is the current programme, it is the 93.5 billion euros this investigation started with.
So I asked the same cabinet for the total across all programmes and all departments. It replied that the Commission “does not hold a single consolidated figure for audits related to personnel costs completed across all programmes, all DGs, and all management modes”, and that “the added value of a consolidated dataset is therefore questionable”.
The second is a tool. When I asked the Commission how it screens this money for fraud risk, it pointed me to Arachne. In plain terms, Arachne takes the EU’s data on projects and recipients, checks it against company registries and other databases, and flags the ones that carry the warning signs, potential fraud, conflict of interest, or funding piling up on the same few names. But Arachne runs on the money the Commission shares with national governments – shared management, and the recovery fund – RRF. The EU’s tool has never run on the 111 billion euros, or on the Belgian sector I tested. And even where Arachne applies, using it is voluntary. The Court of Auditors reported this year that many member states are not making full use of data-mining tools to detect fraud. The Commission’s own 2025 report records that six member states are unlikely to use Arachne at all, preferring national systems.
The third is OLAF, the European Anti-Fraud Office. It removed two tables from its annual reports. Belgium was first in both. The first table: received fraud suspicions worth investigating, per country. Belgium had 975 between 2019 and 2024, more than any other member state. Concluded investigations by OLAF in the same years: 6. Only I have that table, I obtained it through an access to documents request. The second table: cases OLAF sends to the European Public Prosecutor’s Office, again, per country. Belgium was first again, had 81 cases between 2021 and 2024.
The data shows again a pattern. I asked OLAF why the countries at the top of its investigations are always Romania, Bulgaria, Hungary, and Belgium is near the bottom when it comes to incoming versus concluded cases conversion rate. In a document it signed, OLAF titled the 975 Belgian fraud suspicions “incoming information deemed to be of investigative interest”, and stated in the same document that information not deemed of investigative interest is never recorded in its system at all. Two weeks later, replying to me, it described the same 975 as covering, among other things, “preliminary, unverified allegations that do not lead to an investigation”. Its explanation for the high count: Belgium hosts many EU bodies, so the signals are noise. But sending a case to the EPPO is OLAF saying it may be a crime. It did that 81 times for Belgium.
One question remains unanswered since 1 June 2026: how many OLAF investigations ever touched money under direct management, the channel that carries the 7.29 billion euros in this investigation?
The fourth is the EPPO – the European Public Prosecutor’s Office, the only body competent to assess whether an allegation contains criminal conduct. It told me, in writing, what it is: “not competent to audit, prevent or detect potential structural conditions and irregularities in the granting process”, and it “does not act based on a risk-oriented approach”. It opens a case when a report reaches it with grounds for a crime.
The fifth is ECA, the European Court of Auditors, the EU’s external auditor. This year it audited the Commission’s whole anti-fraud strategy and called it “comprehensive yet insufficiently ambitious”: the Commission measures its own effort rather than results, and reports its progress more brightly than the audit found. In an earlier report it found the Commission had never asked why some countries report far more fraud than others, and recommended the Commission find out by the end of 2026. The Commission accepted. In that same report it counted 2,252 fraud allegations OLAF had dismissed that the Court could not trace any further, because OLAF’s and EPPO’s case systems are not connected. And it told me, in writing: “in absence of an efficient information exchange system, the current legal framework does not ensure that all fraud allegations reach EPPO”.
Five safeguards: the body that pays checking itself one file at a time, a tool that has not reached this money, an anti-fraud office that stopped publishing revealing data and will not reconcile its own record, a prosecutor that acts only when handed a crime, an external auditor that finds the system cannot yet prove itself. Each sees a piece, none follows the money from the grant to the last person paid.
Article 317 of the Treaty binds the Commission to spend the Union’s budget “having regard to the principles of sound financial management”. It is the promise owed to every citizen who funds it. On this money, it is the one thing no one can show.
6
6. The last person paid
I am not an auditor, but I was the last person paid.
For five and a half years I worked inside a Brussels organisation that runs on parallel EU grants. Later I checked the project timesheets filed in my name and found inconsistencies. In 2024 I reported it to OLAF and to the European Public Prosecutor’s Office. Belgium also formally recognised me as a whistleblower under the law of 28 November 2022. My former employer asked a Belgian court to order me to stop publishing anything connected to them about my own lived experience, and to fine me 5,000 euros for every publication, for every day it stayed online. It took five months for the court to declare the application unfounded.
That case is mine, it is where the question came from, and it is why I knew what to look for. Nobody writes about a timesheet, it is the most boring document in the European budget. It is also the only one that proves a person was there.
So I stopped asking about my own hours and started asking about everyone’s.
I worked alone for almost two years, on public records, with no EU funding and no institution behind me. What I found is a system that runs sound financial management on trust. The European Union buys human time on a scale of at least 111 billion euros. It requires a signed record for every hour and it wrote one limit to protect it: one person, one working year. It built nothing that can test it.
The fix is not a new bureaucracy, it is a design choice. Those days are already written down, person by person, inside every organisation that receives the money. They are simply never sent anywhere. Reporting them under a pseudonymous identifier, no names and no personal data, into the single gateway the Commission is already building for the next budget, would make the 215-day limit checkable for the first time since it was written.
The method and the dataset are deposited and open. Any journalist, any auditor, any citizen can run this for their own country. I hope they do.
Designs get rewritten, and this one is being rewritten right now, for close to 2 trillion euros. The only thing missing from it is the person.









