Twenty-five years since Sept. 11, 2001, much of the legal and institutional architecture erected in response to the terrorist attacks still stands. The Department of Homeland Security, which was created to fill the intelligence and law enforcement gaps the attacks had exposed, has become one of the largest federal agencies in the country. The 2001 Authorization for the Use of Military Force, which Congress passed to bless a military response to the attacks, remains on the books and has been used as legal justification for operations in various countries. Guantanamo Bay, which opened in 2002 to house “the worst of the worst” terrorists responsible for the attacks, has been home to more than 800 detainees over the years, 15 of whom remain there today, and none of whom have been tried for perpetrating the attacks. And law enforcement powers expanded in the name of counterterrorism, including expanded surveillance authorities and broadened material support statutes, have largely outlasted the initial threats that inspired them and have been repurposed for new circumstances.

Rather than focusing on the well-documented debates over whether the response to 9/11 was good or bad, or on the day’s enormity, Lawfare editors and contributors examine how 9/11 remains—or doesn’t—embedded in current legal and policy frameworks. Twenty-five years later, our editors and contributors set out to answer the question: What aren’t people seeing about that legacy?


Foreign Relations & International Law Intelligence Terrorism & Extremism

The Unexpected Emergence of the EU as a U.S. Counterterrorism Partner

Kenneth Propp
Friday, September 11, 2026, 4:55 AM

How the U.S. and the EU built law enforcement and counterterrorism information sharing in the wake of 9/11

Romano Prodi, President of the EU, delivers an address following the 9/11 attacks (Christian Lambiotte, https://tinyurl.com/eek9xu84, CC BY 4.0, https://creativecommons.org/licenses/by/4.0/deed.en)

[Editor's note: This piece is part of Lawfare's collection "9/11 at 25: The Legal Architecture of the War on Terror, Twenty-Five Years On," examining how 9/11 remains—or doesn't—embedded in current legal and policy frameworks, a quarter century after the attacks. Read the full collection here.]

***

Soon after the Sept. 11, 2001, terrorist attacks, the ensuing U.S. criminal investigation took on a transatlantic dimension as it emerged that several of the attackers had lived in Hamburg, Germany, and organized elements of the plot there. U.S. law enforcement turned for help to German law enforcement through long-established bilateral extradition and mutual legal assistance relationships.

But within months, the United States government made an unprecedented decision to go beyond bilateralism in its European law enforcement relationships, choosing to supplement them with multilateral law enforcement and security links to the European Union. The choice was unusual because the EU at the time had no criminal investigators or prosecutors and little operative responsibility for criminal justice. Indeed, the EU’s governing treaties make clear that law enforcement is primarily a matter of member state competence.

During the years that followed, the United States reached four important agreements with the EU. The first two were on extradition and on mutual legal assistance. These were followed by accords granting U.S. counterterrorism authorities access to two important sources of data with links to Europe. One was information collected by airlines’ Passenger Name Records (PNR) on transatlantic air travel, and the other was data collected by the Society for Worldwide Interbank Financial Telecommunication (SWIFT), a Belgian company that routes international banking transactions. Through these agreements, the new Department of Homeland Security obtained the ability to use PNR data for advance screening of passengers on transatlantic flights, and the Department of the Treasury was able to utilize SWIFT data for its Terrorist Finance Tracking Program (TFTP).

These agreements have proven to be an enduring and valuable part of the strong transatlantic law enforcement and security relationship. But what explains the initial U.S. decision to engage with the European Union, an international organization that until that point had never concluded international agreements in these areas? Why did Washington look to Brussels, and what benefits did the EU and its member states see for themselves?

EU-U.S. Extradition and Mutual Legal Assistance Agreements

The initial impetus for establishing a formal U.S. law enforcement relationship with the EU came from Brussels, not Washington. In the weeks following 9/11, the EU’s senior career official for Justice and Home Affairs, Gilles de Kerchove, and the Department of Justice’s representative in Brussels, Mark Richard, floated the idea of an agreement on counterterrorism cooperation. There ensued, from late 2001 until early the following year, “a period of intensive consultation between the United States and officials of the European Union and its then-Belgian and Spanish Presidencies … on ways of improving trans-Atlantic cooperation against terrorism,” the George W. Bush administration later explained to the Senate.

These exploratory discussions soon evolved toward consideration of extradition and mutual legal assistance agreements, essential tools for securing, respectively, fugitives and the evidence needed to convict them. The initial response in Washington to this proposal was bafflement. What would be the point of entering into formal relationships with the European Union when the United States had mutual legal assistance treaties (MLATs) in place with the major EU member states, as well as a comprehensive network of bilateral extradition treaties?

However, it was a moment when policymakers in Washington were open to creative law enforcement initiatives. U.S. officials soon came to realize, as detailed to the Senate, that “by concluding agreements with the European Union, the United States could achieve uniform improvements and expansions in coverage across much of Europe,” by amending existing bilateral MLATs and by creating legal assistance relationships with newer EU members with which it had no existing relations.

In other words, through single agreements with the EU, the United States could efficiently modernize its entire network of existing extradition treaties and MLATs with the EU’s member states. It could also swiftly establish such relations with the countries that had come into the EU after the Soviet Union’s demise. “This is particularly important in light of the counterterrorism challenges we have faced since September 11, 2001,” the White House explained to the Senate.

The twin agreements had novel dimensions under U.S. and EU external relations law, as well as international law. The United States had not previously reached a law enforcement agreement with the European Union as an entity. Nor did the European Union at the time enjoy international legal personality, usually considered indispensable for treaty capacity. (This defect would not be remedied until the Treaty of Lisbon in 2009.) However, EU lawyers identified several international agreements that the union had concluded with the successor states of ex-Yugoslavia in the late 1990s as evidence of its already-extant ‘effective’ legal personality. Ultimately, State Department treaty lawyers accepted this argument and concluded that the union was an appropriate actor under international law.

The 2010 EU-U.S. extradition agreement made one major substantive advance. Many older bilateral extradition treaties between the United States and EU member states in force at the time contained exhaustive lists of extraditable offenses that had become dated and outmoded. Newer offenses—such as those relating to terrorism, cybercrime, money-laundering, and sexual exploitation—were simply not covered, allowing numerous international fugitives to escape justice. The new EU-U.S. extradition agreement replaced these lists with the modern ‘dual criminality’ approach, which allowed for broader coverage and flexibility over time. 

The 2010 EU-U.S. mutual legal assistance agreement contained a similarly important technical advance. The agreement provided legal authority for U.S. and European prosecutors to conduct video depositions of witnesses located in the other’s jurisdiction in a manner that enabled the resulting evidence to be admissible in the prosecutor’s home state courts. Prior to the EU-U.S. agreement, some EU member states had been unable to offer this type of assistance to U.S. prosecutors. As a result of the EU-U.S. MLA agreement, U.S. prosecutors began to use video depositions taken in Europe with “increasing frequency and effectiveness,” according to an EU study. Video depositions became particularly important for law enforcement during the coronavirus pandemic.

The EU saw these twin agreements as a way of making Brussels more relevant in the transatlantic policy conversation on law enforcement and counterterrorism issues. The United States government agreed with this ambition, as was noted to the Senate: “[T]he U.S.-EU Agreements will enable the strengthening of an emerging institutional relationship on law enforcement matters between the United States and the European Union, during a period when the EU is actively harmonizing national criminal law procedures and methods of international cooperation.”

Through periodic joint reviews of the agreements, the United States, EU institutions and EU member states jointly assess past performance and discuss common implementation problems. While criminal law in Europe remains largely a member state affair, the EU over the years has come to play a genuine role in addressing transatlantic law enforcement challenges including terrorism.

Counterterrorism Data Transfer Agreements

The events of 9/11 generated not only U.S. criminal investigations into the attackers, but also stimulated efforts by other parts of the U.S. government to develop systematic counterterrorism data collection programs. One, undertaken by the Department of Homeland Security under the authority of the 2001 PATRIOT Act, requires airlines to collect PNR data on all international flights to and from the United States. A second major program, the TFTP, began to analyze the global flow of banking transactions believed to be connected to the financing of terrorism relying on data collected by SWIFT.

But the U.S. government could not unilaterally compel private companies collecting these types of personal data in Europe to turn it over to Washington; European privacy laws stood in the way. European cooperation would have to be secured through international agreements containing privacy safeguards and consenting to U.S. collection of personal data in Europe. Here, too, the United States found itself negotiating with the European Union, because privacy law in Europe is largely made in Brussels.

EU-U.S. PNR Agreements

PNR consists of the data a traveler provides to an airline electronic reservation system, including their address, telephone, and credit card numbers, as well as potentially sensitive information, such as meal preferences or special needs. The Department of Homeland Security (DHS) reviews this data before departure of an international flight to assess whether anyone on board might be involved in terrorist or other criminal activity, and deny them permission to travel or arrange for detention upon arrival in cases of suspected criminal activity.

Airlines flying between Europe and the United States welcomed this additional security measure but also realized that complying with the U.S. legal requirement could violate European privacy law. European civil libertarians objected that the U.S. program required transfer of data on large numbers of innocent travelers, with the goal of finding a few previously unidentified criminals. Airlines therefore urgently petitioned Brussels to address this potential conflict of laws with the United States.

Negotiating a sustainable U.S.-EU PNR agreement proved difficult. A first agreement was reached in 2004, but the Court of Justice of the European Union overturned the agreement, and it had to be renegotiated. That successor agreement itself succumbed several years later to political pressure from the European Parliament, and a durable agreement was only reached in 2012. It remains in place today.

The crux of the agreement is a set of data protection safeguards derived from EU law that DHS agreed to accord PNR data supplied by the airlines. In return, the EU agreed that the airlines should supply this data to DHS. The airlines thereby received assurance that complying with U.S. law would not expose them to potential liability under EU data protection law.

Both the U.S. and EU regard the PNR agreement as having yielded useful law enforcement information, according to the first joint review of its implementation. A subsequent report from the European Commission noted that the agreement had been especially valuable in preventing the return of foreign Islamic fighters to EU territory and in child exploitation and drug crime cases.

Although DHS has not released a detailed overview about the agreement’s successes, it disclosed a number of examples over the years. One notable case involved a failed 2010 terrorist bombing in New York City’s Times Square, where quick police work yielded the phone number of a suspect who had fled the scene. By comparing that phone number to the PNR database, police were able to arrest Faisal Shahzad as he sat on a plane awaiting takeoff from New York’s John F. Kennedy International Airport that same day. Shahzad pleaded guilty to planting the explosives and is serving a life sentence.

Terrorist Finance Tracking Program Agreements

TFTP negotiations with the European Union followed a similar trajectory to deliberations about PNR: political and legal controversy yielding eventual stability and concrete results.

After 9/11, SWIFT began to quietly supply swathes of financial transaction data to the Treasury Department, pursuant to administrative subpoenas issued under the authority of the International Emergency Economic Powers Act (IEEPA) and served on the company’s U.S.-located facility. However, in 2006, the New York Times revealed the existence of the (then-) classified program, causing a political reaction in Europe because some of the transferred data could relate to persons covered by EU data protection law. In response, SWIFT announced plans to close its U.S. offices, depriving the Treasury Department’s subpoenas of jurisdictional effect. The Treasury Department realized it needed an agreement with the EU to ensure data transfers from SWIFT’s Belgium headquarters.

Late in 2009, the Council of the European Union reached an agreement with the United States permitting transfer of SWIFT data to the Treasury Department for counterterrorism analysis purposes. The transfers would be subject to U.S. commitments to afford a set of privacy protections modelled on EU law and similar to those used for PNR. However, early in 2010, the European Parliament shocked Washington by refusing to consent to the agreement—the first time it had ever so acted with respect to a proposed EU international agreement. Later that year, the commission and the United States concluded an adjusted second agreement that barely survived European Parliament scrutiny. 

The EU assumed an unusual dual role in implementing the TFTP agreement. Each request from the Treasury Department for SWIFT data would be first reviewed by Europol, the EU police agency, to verify that it properly fell within the agreement’s counterterrorism scope. Additionally, the EU, as party to the agreement, would take steps to “ensure” that SWIFT complied with requests, lending its sovereign weight to a private company’s compliance with a foreign governmental request.

The Treasury Department in turn agreed to put its analytical capabilities at the disposal of European agencies seeking their own insights into terrorist finance trends. The agreement has since proved its worth for the EU, according to an analysis by the U.S. Privacy and Civil Liberties Oversight Board. More than 40 percent of the database searches over the three-year period studied were performed by the Treasury Department on behalf of EU member states or Europol. The EU and its members accounted for nearly 75 percent of all TFTP leads disseminated to foreign governments.

The 80,000 individual leads shared with Europe related to some of the most notorious terrorist attacks on the continent in recent years, including the 2015 attacks in Paris and 2017 ones in Barcelona. After the 2011 attack in Norway by Anders Breivik, TFTP information on the assailant’s funding sources assisted authorities in neighboring Finland in averting a similar planned attack.

TFTP thus not only benefits U.S. counterterrorism analytical efforts but also assists counterpart European ones. It “resembles an outsourcing arrangement, with the Treasury Department effectively serving as an offshore service provider for the EU and European governments,” Adam Klein, the former chairman of the U.S. Privacy and Civil Liberties Oversight Board, observed. Klein added that the EU and its members have “effectively deputized” the Treasury Department to perform counterterrorism searches on their behalf.

*          *          *         

Efforts to build law enforcement cooperation between the United States and the European Union began soon after Sept. 11, 2001, in a spirit of remarkable solidarity, and yielded the extradition and MLA agreements relatively quickly and harmoniously. In the years that followed, U.S. officials came to see Brussels as the key to unlock continent-wide access to data collected by private companies and sought for counterterrorism purposes. Although the series of negotiations on PNR and TFTP were lengthy and contentious, due to European unease about providing U.S. authorities with personal data on a bulk basis, they eventually led to durable agreements and strengthened transatlantic security against terrorist attacks.

All four of these agreements are still actively applied. Extradition and mutual legal assistance are staples of transatlantic cooperation on criminal matters. The PNR and TFTP agreements are prominent early examples of the U.S. government obtaining access for security purposes to personal data not within U.S. control, a practice which continues to expand today.  


Kenneth Propp is senior fellow at the Europe Center of the Atlantic Council, senior fellow at the Cross-Border Data Forum, and adjunct professor of European Union Law at Georgetown Law. He also advises companies on transatlantic digital policy. From 2011-2015 he served as Legal Counselor at the U.S. Mission to the European Union in Brussels, Belgium.
}