Regulatory Framework

The EU Spreadsheet Act

A comprehensive regulatory framework for spreadsheet systems, establishing tiered risk classifications and mandatory conformity assessments for high-risk tabular applications.

€35M
Maximum Fine
4
Risk Tiers
27
Member States
2025
Enforcement Date

Why We Need the EU Spreadsheet Act

Spreadsheets Already Determine Critical Outcomes

From credit decisions to healthcare allocations, from immigration determinations to criminal justice risk assessments—spreadsheets already make decisions that fundamentally shape human lives. Yet they operate with virtually no regulatory oversight.

The Error Rate Is Catastrophic

Studies consistently show that 88-94% of spreadsheets contain at least one error. The London Whale incident cost $6.2 billion. The Reinhart-Rogoff error influenced austerity policies affecting millions. The PHE COVID data loss delayed contact tracing for 15,841 cases.

AI Gets Regulated, Spreadsheets Don't

The EU AI Act establishes comprehensive oversight for AI systems. Yet a simple Excel spreadsheet making the same decisions with the same data faces no equivalent scrutiny. This regulatory gap is both arbitrary and dangerous.

The Four-Tier System

Following the precedent set by the EU AI Act, spreadsheet systems are classified by risk level. Non-compliance may result in fines up to 6% of global turnover or public embarrassment.

🚫

PROHIBITED — Unacceptable Risk

  • Spreadsheets with hidden formulas that manipulate users without their awareness
  • Social scoring systems ranking employees based on spreadsheet-tracked metrics
  • Real-time emotion detection via comment sentiment analysis
  • Spreadsheets exploiting cognitive vulnerabilities of less tech-savvy users
  • Any spreadsheet claiming to predict criminal behavior based on demographic data
⚠️

HIGH RISK — Requires Conformity Assessment

Must undergo third-party audit, maintain documentation, and establish human oversight mechanisms.

  • Credit scoring and loan eligibility determination
  • Employment decisions (hiring, firing, promotion)
  • Educational grading and outcomes
  • Healthcare resource allocation
  • Government benefit determination
  • Criminal justice risk assessment
  • Border control and immigration decisions
  • Economic policy modeling (see: Reinhart-Rogoff)
📋

LIMITED RISK — Transparency Required

  • AI-generated spreadsheets must disclose they were created by chatbots
  • Synthetic data in spreadsheets must be clearly labeled
  • Charts and visualizations must cite data sources
  • Users must be informed when interacting with spreadsheet-driven chatbots

MINIMAL RISK — Unregulated

  • Your personal budget (though errors here can also cause harm)
  • Fantasy football standings
  • Wedding seating charts (documented harm, but socially accepted)
  • Grocery lists
⚠️

Frontier Capabilities Warning

The following advanced spreadsheet techniques require additional governance consideration due to emergent capability risks.

Array Formulas (CTRL+SHIFT+ENTER)

Legacy array entry methods create undocumented compute dependencies.

Dynamic Arrays (SPILL Range)

Unpredictable output ranges that expand beyond intended boundaries.

Power Query / Get & Transform

External data connections with opaque transformation logic.

VBA Macros

Turing-complete and ungoverned. The spreadsheet singularity begins here.

Python in Excel (NEW)

Emergent existential threat. Full programming language embedded in cells.

LAMBDA Functions

User-defined functions without oversight. Creates recursive risk.

Capability Thresholds Requiring Notification

Spreadsheets exceeding 100,000 rowsFormulas with nesting depth > 7Any use of INDIRECT() or OFFSET()Cross-workbook referencesExternal data connectionsSpreadsheets determining policy for nations

Requirements for High-Risk Spreadsheets

Organizations deploying high-risk spreadsheets must meet the following requirements.

Risk Management System

Establish and maintain a risk management system throughout the spreadsheet lifecycle.

Data Governance

Implement data quality criteria for input data, including source validation and error detection.

Technical Documentation

Maintain comprehensive documentation including formula logic, dependencies, and version history.

Record-Keeping

Automatically generate logs of all spreadsheet operations and modifications.

Transparency

Provide clear information to deployers about spreadsheet capabilities and limitations.

Human Oversight

Design spreadsheets to allow effective oversight by qualified human operators.

Support the EU Spreadsheet Act

Join leading organizations in advocating for comprehensive spreadsheet governance. The time for action is now—before the next catastrophic spreadsheet error.

“The most dangerous spreadsheet is the one that appears to work correctly.”