l0grisk intelligence · english

// analysis

Digital euro, 4/6: programmable money, the legal boundary

The texts prohibit expiring or earmarked euros, allow conditional payments, and do not erase freezes or seizures. An investigation into where the rule actually lives.

dated revision: August 14, 2026French originalprimary sourcesno tracker

This is the fourth part of our six-part investigation into the digital euro. The first article followed money from one balance sheet to another. The second reconstructed the €699 billion bank stress test. The third followed data through PSPs, central infrastructure, aliases and the fraud engine. This fourth part follows another invisible object: the rule deciding whether value can move.

Status of the file as of 14 August 2026. The Commission presented its proposal in June 2023. The Council adopted its negotiating mandate in December 2025. Parliament authorised interinstitutional negotiations on 9 July 2026. The final regulation has not been adopted. Draft rulebook v0.91, published on 2 July 2026, remains preliminary and non-binding.

You order a computer.

Six hundred euros are reserved in your account. The seller receives them only after delivery is confirmed.

A fraud-detection false positive then flags you. A second payment is refused.

Elsewhere, the assets of a person subject to an EU sanction are frozen. In another case, a court prevents a debtor from moving a sum of money.

Four situations produce the same immediate symptom: the money cannot move freely.

None of those examples, on its own, proves that the euro is programmable.

Programmable money begins when the restriction belongs to value itself: this euro can buy food only, this euro stops working on Friday, this euro can circulate only among certain beneficiaries. The rule follows the unit after transfer and makes it different from other euros.

The European project draws a narrower boundary than public debate. It prohibits that intrinsic logic while allowing conditional payments and reservations, without removing instrument limits or the law governing sanctions, fraud and judicial enforcement.

The right question is therefore not:

“Can a payment be blocked?”

The answer is already yes in today’s banking system.

The useful question is:

Where does the rule live, who chooses it, does it end at settlement, and what remedy can challenge it?

Nine things to remember

  • The Commission, Council and Parliament use the same prohibition: the digital euro must not be programmable money.
  • Their definition targets intrinsic logic limiting the full fungibility of each unit.
  • An expiry date or general product restriction would fall within that category.
  • Pay-on-delivery acts on the payment instruction, not on the euros received.
  • A pre-authorisation temporarily blocks an amount, as cards already do in some uses.
  • A PSP can refuse a transaction for fraud without turning the balance into specialised vouchers.
  • A sanction or seizure targets a person, account or property under law.
  • The most credible risk lies at the edge: an app can reproduce a highly restrictive experience around legally fungible euros.
  • The ECB could not activate expiry on its own under the current framework. Future legislation could change the rule.

Six mechanisms hidden behind one word

“Programmable” is now used for almost anything that automates or prevents a payment.

That expansion erases the distinction the law is trying to protect.

A rule can target:

  1. the monetary unit;
  2. the payment instruction;
  3. an amount reserved before settlement;
  4. the payment instrument;
  5. the account;
  6. a person or their property.
Six different places where a rule can act on a paymentA rule may target the monetary unit, payment instruction, reservation, instrument, account, or a person and their property. Only the first category directly constitutes programmable money.WHERE DOES THE RULE LIVE?Same apparent result, six different legal objects.1. MONETARY UNIT“This euro expires Friday”“food only”The restriction follows the value.PROGRAMMABLE MONEYProhibited by Article 24.2. PAYMENT INSTRUCTION“pay after delivery”“pay every month”The condition ends at settlement.CONDITIONAL PAYMENTAllowed and explored.3. RESERVATIONhotel, rental, usageamount blocked before paymentThe amount is unavailable,not specialised.PRE-AUTHORISATION4. INSTRUMENTlimit, contactless, cardsecurity blockThe instrument is limited.ACCESS CONTROLThe euros remain ordinary.5. ACCOUNTholding limitautomatic transfer of excessThe quantity or availabilityis constrained.ARCHITECTURE RULE6. PERSON / PROPERTYsanction, freeze, seizureauthority or court decisionLaw blocks disposal.LEGAL RESTRICTIONThe money remains fungible.Decisive test: does the restriction follow the euros after transfer?WHERE DOES THE RULE LIVE?Only a restriction following the unit is programmable money.UNITexpiry, restricted goodsThe restriction follows value: programmable money.INSTRUCTIONafter deliveryThe condition ends at settlement.RESERVATIONblocked amountUnavailable before payment, free afterwards.INSTRUMENTcard or appThe access tool is limited.ACCOUNTholding capThe quantity or availability is constrained.PERSON / PROPERTYfreeze or seizureLaw blocks the power to dispose of assets.Test: does the rule survive transfer?
Programmability becomes intelligible once the object targeted by the rule is identified.

The first case is what the texts call programmable money. The other five can produce a very real block without changing the nature of the euro.

The simplest test is to look at what remains after settlement.

If the merchant receives euros that can be transferred freely, the condition governed the payment. If the restriction continues to follow value, the money itself has lost part of its fungibility.

Article 24 closes the door in all three texts

The Commission proposal drew the distinction in 2023.

It defines programmable money as units carrying intrinsic logic that limits each unit’s full fungibility. Recital 55 gives two concrete examples: units that can be used only for certain goods or services, or that are subject to a time limit after which they are no longer usable.

Conditional payment follows a different logic. Software triggers an operation once predefined and agreed conditions are met. The Commission cites standing orders, machine-to-machine payments, insurance, leasing and usage-based maintenance.

The Council mandate repeats those definitions. Article 24 allows the ECB to publish interoperable standards and provide settlement functions, including reservation of funds. It ends with an unqualified sentence:

The digital euro shall not be programmable money.

Parliament’s A10-0185/2026 report reproduces the same structure. Article 2 separates the automatic instruction from intrinsic logic. Article 24 allows standards and reservation, then repeats the same prohibition. Parliament confirmed the mandate to negotiate on 9 July 2026.

At the start of trilogue, the three institutions therefore converge on the legal core:

Element Commission Council Parliament
Condition attached to instruction allowed allowed allowed
Reservation of funds possible provided for provided for
Intrinsic restriction of the unit prohibited prohibited prohibited
Expiry or imposed goods examples of prohibition incompatible with fungibility examples of prohibition

Negotiations can still change many provisions. They do not begin from institutional disagreement on this specific point.

Why fungibility is the boundary

Two units are fungible when one can replace the other at equal value.

A €20 banknote normally contains no information saying it may buy fuel only or will stop being valid at month-end. A €20 bank deposit can be blocked with the account, but it remains expressed in the same unit as other deposits and banknotes.

“Food until Friday” value works differently. It resembles a voucher, coupon or special-purpose claim. Its practical value depends on the merchant, product and calendar.

The ECB’s 2023 legal opinion takes this reasoning to the Treaties. A restriction on where, when or whom a user may pay would, in its view, make the instrument tantamount to a voucher, inconsistent with legal tender, face value and conversion at par. The ECB adds that it has no mandate to issue vouchers. Our CBDC reading guide explains how legal tender and programmability fit into the wider design.

That position is strong. It sits on top of the proposed legislative prohibition.

It remains an ECB legal opinion, not a Court of Justice judgment on a digital euro already in circulation.

The strongest legal conclusion therefore has two parts:

  • secondary law would explicitly prohibit programmable money;
  • the ECB also considers such issuance beyond its mandate even without that sentence.
Difference between conditional payment and programmable money before and after settlementIn a conditional payment, ordinary euros are reserved and become unrestricted at the beneficiary. With programmable money, the restriction remains attached to value after transfer.BEFORE AND AFTER SETTLEMENTThe boundary appears when the beneficiary receives the funds.CONDITIONAL PAYMENT€600 ordinaryavailable balancethen reserveddeliveryconfirmedsettlementcondition endson transfer€600 FREEat thebeneficiaryPROGRAMMABLE MONEY€600 marked“energy only”until 31 Decembertransfercompletedrule persistsit follows valueafter settlement€600 LIMITEDeven at thebeneficiaryThe post-settlement state determines fungibility.BEFORE AND AFTER SETTLEMENTDoes the beneficiary receive unrestricted euros?CONDITIONAL PAYMENT€600 of ordinary money is reserved.Delivery confirmed: the condition ends.The beneficiary receives unrestricted €600.PROGRAMMABLE MONEY€600 carries “energy only”.The transfer occurs; the rule remains attached.The beneficiary receives restricted €600.Legal test: does the rule survive transfer?
A payment can be automated without passing a restriction to the euros received.

The fate of euros after a conditional payment

The ECB’s innovation platform tested this separation in 2025 with around 70 participants from payments, banking, technology, commerce and research.

The environment was simulated, simplified and used no real euros. It was not the final product.

Its value lies in the chosen architecture.

The Eurosystem supplied the core:

  • settlement;
  • reservation of funds;
  • standards;
  • a common technical environment.

PSPs defined the conditionality layer:

  • delivery confirmed;
  • milestone completed;
  • duration consumed;
  • fare calculated;
  • triggering event.

The report explicitly describes a separation between settlement and conditionality. Private actors are expected to develop value-added services, while the Eurosystem supplies common infrastructure.

That separation has an obvious institutional advantage: the ECB does not need to decide whether your parcel arrived or a construction project reached 40% completion.

It creates a new centre of power: the actor certifying the fact.

Pay on delivery

The amount is reserved.

The carrier or customer confirms delivery.

The merchant receives ordinary euros.

The condition determined the time of transfer. It does not determine the future use of the money received.

Milestone payment

A provider receives part of the price after each accepted stage.

The mechanism automates a contract. Every settled instalment becomes an ordinary holding.

Pay per use

The amount depends on duration, consumption or passage.

The system may calculate a transport fare, electricity charge or rental duration. The main risk shifts to data quality and the cap accepted by the user.

Automatic refund

A delayed train, cancelled service or insurance condition can trigger a payment to the customer.

The rule automates an obligation. It does not mark the refunded euros.

Reservation of funds already exists in another form

Draft rulebook v0.91 describes pre-authorisation when the payable amount or time is unknown at checkout.

In the central infrastructure, that pre-authorisation corresponds to a reservation of holdings.

The draft allows:

  • full settlement;
  • partial settlement;
  • multiple partial settlements;
  • cancellation;
  • expiry;
  • modification of the amount or duration.

Two protections are already written into this draft.

Settlement above the reserved amount requires authorisation for the difference. Increasing the reservation or extending its duration also requires payer authorisation. The unused amount is released when the reservation is cancelled, fails or expires.

Reserved amounts continue to count towards the holding limit. A user could not bypass that limit by stacking reservations.

These are draft scheme rules rather than a finished implementation. The settlement annex defines the reservation transaction but states in a footnote that its detailed coverage will be added in a later rulebook version.

This mechanism looks less like programmed money than the familiar hotel or car-rental hold.

The consolidated PSD2 already allows funds to be blocked when a card payment is initiated and the final amount is unknown, provided the payer has agreed to the exact amount to be blocked. The funds must then be released without undue delay once the final amount is known.

A blocked amount does not become a new kind of euro.

The oracle becomes the sensitive component

“Pay after delivery” sounds simple until someone must decide what delivered means.

A parcel may be:

  • left outside a door;
  • declared delivered by the carrier;
  • received empty;
  • damaged;
  • sent to the wrong address;
  • disputed by the customer.

The condition needs an oracle, meaning an actor or system authorised to declare that the event occurred.

It may be the customer, merchant, carrier, sensor, public authority, insurer, arbitrator or several sources combined.

The conditionality layer therefore shifts part of the economic power.

The dispute is no longer only about payment. It is about the truth of the fact triggering it.

Three safeguards become central:

  1. identifying the data used;
  2. being able to challenge the event;
  3. allocating liability when the oracle is wrong or unavailable.

The public corpus does not yet provide a complete liability architecture for all such services. The innovation platform identifies arbitration as a possible need. The rulebook covers technical and fraud disputes, not a universal court for commercial conditions.

The child wallet reveals the true grey area

The innovation platform discusses supervised wallets for children with spending controls. These are participant ideas, not adopted features.

Three versions would produce three different classifications.

A daily limit

The parent limits the daily amount or disables online shopping.

The rule targets the instrument. It resembles parental controls already offered by some cards.

An authorised category list

The app refuses alcohol, gambling or certain merchants.

The euros may remain unrestricted in central infrastructure, but the account or interface limits their use. Classification then depends on whether the restriction is voluntary, revocable, portable and avoidable through another instrument.

Units that remain marked

The funds received can never leave the authorised categories, even after transfer.

The restriction follows value and impairs fungibility. It directly approaches the programmable money prohibited by Article 24.

The child-wallet case shows why a purely technical definition is insufficient. A restriction can live in the app and reproduce almost the same practical result as a rule inside the unit.

A separate layer for conditional social benefits

The prohibition does not make conditional public policy impossible.

A public authority can already distribute:

  • meal vouchers;
  • energy vouchers;
  • social cards;
  • targeted discounts;
  • refunds after evidence;
  • direct payments to suppliers.

PSD2 itself recognises instruments usable within a limited network or for a very limited range of goods and services.

The boundary lies between two models.

In the first, a benefit is paid once eligibility is verified. The beneficiary then receives ordinary euros.

In the second, the value remains limited to particular products, merchants or a period of time.

The second model can exist as a voucher or specialised instrument. It should not be presented as the general, fully fungible digital euro if Article 24 is respected.

That architecture creates an important political consequence:

The prohibition does not eliminate earmarked purchasing power. It forces the layer doing the earmarking to remain visible.

Programmability can move to the edge

The most credible risk may not look like the ECB writing “food” into every euro.

It can take a more ordinary form:

  • the user receives legally fungible euros;
  • the app refuses some merchants;
  • a public authority or provider controls the settings;
  • there is no simple alternative;
  • the restriction is difficult to remove;
  • conversion into cash or bank money becomes cumbersome.

The unit remains free in theory. Purchasing power becomes conditional in practice.

Commission and Parliament recital 55 contains a useful formula: conditional payments must not have the object or effect of turning the digital euro into programmable money.

That clause should prevent an obvious circumvention through the interface.

It does not yet provide a complete test for peripheral services.

A serious audit must ask at least six questions:

Question Sign of an optional service Sign of peripheral programmability
Does the user genuinely choose? separate consent imposed condition
Can basic services be used without it? yes no or only with difficulty
Can the user switch PSP or interface? easily captive restriction
Can funds be converted or transferred? at par exit prevented
Does the rule end at settlement? yes follows balance or transfers
Is there a clear remedy? contract and challenge opaque or irreversible decision

Parliament provides another clue. Its report states that during emergency switching from an unavailable PSP, some additional services, including conditional payments, may need to be re-established with the new provider. The account and holdings may survive while the conditional logic does not follow automatically.

Classifying a blocked payment

PSD2 Article 68 already permits agreed spending limits and blocking an instrument for objectively justified security reasons, suspected unauthorised or fraudulent use and, in some cases, a risk of non-payment.

The PSP must inform the payer where possible, then unblock or replace the instrument when the reason no longer exists.

The future digital euro would add a cross-provider fraud mechanism, examined in the previous part. A score could lead the PSP to refuse a transaction.

The legal distinction does not make that power harmless.

A false positive can prevent someone from paying rent or buying a ticket. An opaque model can reproduce a systematic block around perfectly fungible euros.

Correct classification merely prevents choosing the wrong remedy.

For a fraud refusal, the questions are:

  • what reason?
  • what data?
  • what deadline?
  • what remedy?
  • what liability?

For programmable money, the questions would be:

  • what intrinsic restriction?
  • who attached it to the unit?
  • does it survive transfer?
  • does value remain convertible at par?
Four different legal reasons why a payment may be impossibleA pre-authorisation, fraud refusal, sanctions freeze and judicial seizure can all stop a payment. Each targets a different object and relies on a different authority.FOUR LEGAL PATHS TO A BLOCKED PAYMENTThe same symptom can come from four different legal regimes.PRE-AUTHORISATIONAn amount is reserved.It still counts towards the cap.Decision: payer and merchantObject: amount before settlementOutcome: settlement, cancellation or expiryFRAUD REFUSALThe PSP refuses an instruction.The balance remains general-purpose.Decision: PSP under payments lawObject: transaction or instrumentOutcome: reason, challenge, unblockingSANCTIONS FREEZEA person or entity is targeted.Their assets become unavailable.Decision: Union, executed by PSPObject: person, account and assetsOutcome: unfreezing or legal challengeSEIZURE OR JUDICIAL FREEZEA court or authority actson property or a claim.Decision: competent authorityObject: holder’s propertyOutcome: procedure, exemptions and remediesNone of these mechanisms requires euros carrying a spending category or expiry date.“PAYMENT IMPOSSIBLE”: WHICH LAW?The legal basis locates the power.PRE-AUTHORISATIONamount reservedCommercial agreement before settlement, then release.FRAUD CONTROLinstruction refusedPSP decision, reason and remedy under law.SANCTIONStargeted personAsset freeze under EU law.SEIZURE / FREEZEproperty or claimAuthority or court, procedure and exemptions.Same practical block, four different legal bases.
A real block can arise from contract, fraud, sanctions or judicial procedure without programming the monetary unit.

Sanctions target a person and their assets

The Council mandate provides a specific control for persons and entities subject to Union targeted financial restrictive measures.

PSPs would verify users immediately after a new measure or amendment, then at least once a day. For these specific targeted sanctions, the text seeks to avoid another name screening of every instant transaction, reducing false positives and unnecessary rejection.

The logic is:

  1. a person or entity appears on a list;
  2. the PSP identifies its customer;
  3. assets are frozen or funds cannot be made available.

The logic is not:

every unit contains a blacklist.

The freeze can produce a total block. It nevertheless rests on a targeted legal measure that can be amended, lifted or challenged under applicable procedures.

The money remains denominated in the same unit. The person’s ability to dispose of it disappears.

Criminal freezing and confiscation belong to another body of law

Directive 2024/1260 defines property broadly: corporeal or incorporeal, movable or immovable, including crypto-assets and instruments evidencing title or interest.

It defines freezing as temporarily prohibiting transfer, destruction, conversion, movement or disposal of property, or temporarily assuming custody or control.

Council and Parliament also want digital euros to be classified as intangible assets belonging to their users.

Together, these provisions support a robust inference: digital euro holdings could, in principle, be subject to criminal freezing or confiscation where legal conditions are met.

The available text does not yet describe the button or API that would execute that decision.

The route will depend on:

  • national law;
  • the competent authority;
  • the PSP’s role;
  • final DESP architecture;
  • treatment of offline holdings;
  • third-party rights and remedies.

It would therefore be excessive to write that the ECB could confiscate funds at discretion. It would be equally wrong to present the digital euro as inherently immune from seizure.

Civil seizure remains a real blind spot

Regulation 655/2014 allows a creditor to obtain a European order preventing transfer or withdrawal of funds from a bank account in certain cross-border disputes.

Its scope relies on two precise categories:

  • an account containing funds;
  • held with a credit institution.

It also excludes accounts held by or with central banks when they act as monetary authorities.

The digital euro would form a hybrid object:

  • a Eurosystem liability;
  • an asset belonging to the user;
  • an account and service administered by a PSP;
  • a PSP that may not be a bank.

The public law corpus does not support a conclusion that the current European order would apply automatically, or that application would be impossible.

The operational question remains: to whom would a court send the order?

To the PSP managing the customer relationship? To central infrastructure? To both? How would an active reservation, joint account, legally protected amount or offline holding be treated?

This gap deserves more than a binary answer.

The proposed property protection clearly concerns the PSP’s creditors. If the intermediary fails, its creditors should not reach customer digital euros.

It does not create general immunity against the user’s own creditors, tax authority, criminal law or sanctions.

Central bank money does not mean property outside the law.

Who actually holds the switch?

Public debate often concentrates every power at the ECB.

The texts distribute decisions among several actors.

Allocation of powers around the digital euroThe legislature defines the money and its limits, the ECB supplies infrastructure within the law, PSPs develop services, users consent, and authorities or courts apply legal restrictions.WHO CAN DECIDE WHAT?Decision-making is split among several actors.PARLIAMENT + COUNCILdefine the money, prohibitionand allocation of powersECB / EUROSYSTEMstandards, settlement, reservationand possible issuance decisionwithin the regulationPSPs / PROVIDERSbusiness logic, interface, oracleand additional servicessubject to payments lawUSERaccepts a condition, mandateor pre-authorisationconsent and revocationCOMMISSIONdelegated or implementing actswithin delegated matterscannot overturn the law aloneAUTHORITIES / COURTSsanctions, AML, freeze, seizureand confiscationunder a targeted legal basisARTICLE 24 BINDS THE ECB’S TECHNICAL POWERSA substantive change would require a new legislative process.WHO CAN DECIDE WHAT?Power is split among several authorities.PARLIAMENT + COUNCILThey define the money, prohibition and allocation of powers.ECB / EUROSYSTEMStandards, settlement and reservation within the law.PSPs / PROVIDERSServices, interface, oracle and business logic.USERConsent, modification and revocation by service.COMMISSIONBounded acts.AUTHORITIES / COURTSFreeze, seizure, sanctions.Expiry would require a new legislative procedure.
The future regulation distributes powers among the legislature, ECB, intermediaries, users and authorities applying the law.

Parliament and Council can prohibit or authorise a monetary architecture. They can also amend the law later.

The Commission may receive delegated or implementing powers for matters assigned by the regulation. It cannot turn a legislative prohibition into general authorisation by itself.

The ECB can provide standards, reservation, settlement and infrastructure, then possibly decide to issue after adoption of the law. Its measures must remain within the regulation and its competences.

PSPs can develop conditional services, select some oracles, manage interfaces and apply fraud controls. They remain subject to payments law, GDPR, consumer protection and competition.

The user accepts a pre-authorisation, recurring instruction or condition. Consent does not make every restriction lawful. It must be understandable and, depending on the service, modifiable or revocable.

Authorities and courts apply sanctions, AML, freezing, confiscation, seizure or tax rules under their own legal basis.

That distribution matters because it determines the remedy. A delivery error, fraud false positive and EU sanction are not challenged before the same actor or under the same law.

Could the ECB activate expiry through a software update?

Under the framework currently being negotiated, no.

Article 24 prohibits programmable money. Article 5 confines ECB measures, rules and standards to the regulation and its competences. Article 24a in the Council and Parliament mandates allows it to monitor and integrate new technologies after assessing maturity, dependencies and risks.

Article 24a permits technical evolution.

It does not permit Article 24 to be reversed.

Turning the general digital euro into expiring or use-restricted units would require at least a major legal change. It would pass through a new political procedure involving Parliament and Council, possible judicial review, legal tender and fungibility.

Legislative protection is never eternal.

A future legislature can amend a regulation. Saying expiry will arrive automatically because the infrastructure is digital is false. Saying no future majority could ever change the law is also false.

The accurate formulation is less spectacular and more robust:

The ECB could not activate prohibited programmability on its own under the current framework. A substantive change would have to become a visible legislative decision.

Nine myths, nine verdicts

Claim Verdict as of 14 August 2026
“The ECB can make your euros expire through a setting” False under the current framework. Intrinsic expiry is an example of what is prohibited and Article 24 binds the ECB.
“Pay on delivery is programmable money” False. The condition governs execution and ends at settlement.
“A reserved amount proves the euro is programmable” False. Reservation temporarily blocks an amount before payment.
“A holding limit restricts what you can buy” Category error. It limits the stock, not the destination of each unit.
“A sanctions freeze programs the money” No. It targets a person or entity and their assets under law.
“The prohibition makes every seizure impossible” False. Criminal law and national enforcement law continue to apply.
“Digital euros are protected from every creditor” False. The explicit protection concerns PSP creditors, not every creditor of the holder.
“A child wallet blocking categories is necessarily lawful” Not demonstrated. A peripheral restriction must pass tests of fungibility, choice and exit.
“Today’s law guarantees the future forever” False. It creates a serious lock that a future legislative process can amend.

Evidence status and open questions

Proposition State of evidence
All three institutions prohibit programmable money established in their negotiating positions
Intrinsic expiry and product restrictions are covered established by recitals and definitions
Conditional payments are allowed established
The ECB could provide standards and reservation established in all three texts
The market would mainly provide conditional logic documented by the innovation platform and texts
Pre-authorisation allows partial settlement and requires new consent for increases documented in draft rulebook v0.91
Additional services will always be portable without friction not established
An app restriction reproducing a voucher would automatically be prohibited object-or-effect principle is relevant, final test unpublished
Sanctions and fraud refusals will remain possible established in mandates and payments law
Digital holdings can in principle fall within criminal freezing strong legal inference, technical execution undocumented
European civil seizure will apply automatically not established
The ECB can remove the prohibition on its own incompatible with the current framework

The European project does not provide for expiring, geofenced or purchase-specific euros.

That statement rests on a written prohibition in the Commission, Council and Parliament positions, reinforced by the ECB’s legal analysis of legal tender and fungibility.

The conclusion does not remove the real powers surrounding the money.

A payment may be reserved by contract, refused for fraud, blocked by sanctions, frozen in criminal proceedings or seized under applicable law. A private or public app may also try to build highly restrictive services around legally free euros.

The point of scrutiny therefore moves.

It is not enough to verify that the word programmable is absent from the monetary core. Auditors must examine:

  • interfaces;
  • oracles;
  • consent;
  • exit rules;
  • portability;
  • false positives;
  • freezing orders;
  • remedies.

The most useful question in this fourth part fits in one sentence:

Does the restriction belong to the euros, or to power exercised around them?

The current project answers clearly for the unit: it must remain fungible.

What remains is to document, service by service, how peripheral powers will be constrained.

Next: the price of payment sovereignty

The fifth part leaves law and follows costs.

The ECB is building central infrastructure. Banks and PSPs must integrate the account, app, offline mode, fraud controls, support and acceptance terminals. Basic services would be free for individuals while merchant charges would be capped.

The investigation looks for the real payer: Eurosystem, banks, merchants, taxpayers or customers through other channels. It includes a simulator for testing adoption, fees and the distribution between PSPs.

Sources and method

This article relies primarily on:

The evidence method separates adopted law, negotiating positions, technical drafts, experiments and legal inference. Parliament’s report was extracted and checked article by article. Civil seizure remains deliberately open because the available corpus does not yet describe a complete route for the hybrid object a digital euro account would create.

This analysis is not investment advice.

// cite this analysis

l0g, “Digital euro, 4/6: programmable money, the legal boundary”, l0g.fr, published August 14, 2026, updated August 14, 2026, https://l0g.fr/en/analysis/digital-euro-4-programmable-money-legal-boundary/


$ cd ../analysis