Europe makes the rules. The CEO makes the decisions.
I once asked the chief executive of a manufacturing company what he saw as the biggest change over the past decade.
I expected him to speak about energy costs, the shortage of skilled staff or competition from Asia.
He paused for a few seconds and answered simply:
— I can no longer finish.
I asked him to explain.
He showed me his diary.
On Monday morning there was a cyber-security discussion. On Tuesday he had a meeting on the roll-out of a new AI-driven system. On Wednesday he had to approve the sustainability-reporting procedures. On Thursday there was a data-protection review. On Friday an internal-audit meeting was scheduled.
None of these meetings had any direct connection with what the company actually produced.
And yet every one of them was essential to the company.
At one point he said something that, I admit, stayed with me for a long time.
— I have ended up running less of the business and more of the obligations the business itself generates.
I do not think he was exaggerating.
Europe is living through a period in which the pace of regulation is unprecedented. Artificial intelligence, operational resilience, cyber-security, data protection, sustainability reporting and many other fields are creating new obligations at a rate that few organisations can absorb without difficulty.
The problem is not that these rules exist.
Most of them are necessary.
The problem is that, inside a company, they all land on the same people’s desks.
The chief executive does not simply read a European regulation and move on.
He has to decide who is accountable, what it will cost to implement, which processes must change, which IT systems must be adapted, who will train the staff, who will check compliance with the new rules and—above all—what happens to the day-to-day work while the organisation tries to do all of this at once.
From the outside it looks as though we are talking about the law.
Inside the company we are talking about time.
About people.
About priorities.
About resources that are, almost always, insufficient.
Here, I believe, lies the greatest misunderstanding between the legal world and the business world.
The lawyer sees a regulation.
The manager sees another project.
The chief financial officer sees another budget.
The human-resources director sees another training programme.
The IT manager sees another system that must be modified.
Each is right.
And each sees only one part of the same reality.
After nearly twenty years spent in companies, across industries and roles—eleven of them in consultancy—I have reached the conclusion that the big problems do not arise when organisations refuse to comply with the law.
They arise when organisations can no longer keep up with change.
Organisational fatigue is a risk that is talked about too little.
People no longer reject the rules.
They postpone them.
They break them into fragments.
They shift them from one quarter to the next.
They tell themselves they will return to them when things are less busy.
Yet that moment never comes.
That is how non-compliance begins in earnest.
Not out of bad faith.
But out of overload.
Out of the impression that there is still time.
Out of the belief that today’s problem can be solved tomorrow.
Perhaps the role of the legal counsel is changing precisely here.
No longer the person who reads the first European regulation.
Now the person who tells the chief executive which three things must be done now and which seven can wait.
In a world where rules keep multiplying, the most valuable skill is no longer knowing them all.
It is knowing where to start.