
When Legal Mobility Becomes a Security Risk: The EU Posted Workers System
A legal channel turned into a migration and labour-routing system
Recent investigations in Belgium and the Netherlands show that the EU’s posted-workers regime has evolved into a powerful and largely ungoverned channel for labour mobility and de facto migration. What was designed to support the free movement of services now functions as a transnational labour-routing system allowing tens of thousands of workers (many of them from outside the EU) to circulate across borders through opaque corporate structures that evade effective state control.
Under EU law (Directive 2018 on posted workers), a company in one Member State may temporarily deploy its workers in another while they remain insured in the sending state. This status is certified through the A1 form, which should anchor legal responsibility. In practice, the A1 system has become one of the regime’s main points of abuse. Workers are recruited in countries such as Poland, Latvia, Slovenia, Bulgaria, Romania or Portugal and immediately redirected elsewhere, often without ever setting foot in the state that formally employs them. Many arrive without valid A1 certificates or with manipulated professional documents, while host-state inspectors have no real-time way to verify them. There is no EU-wide A1 database, no standardised format, and no rapid cross-border validation mechanism—allowing jurisdictional responsibility to be systematically blurred.
Belgium: a case study in invisible labour mobility
Belgium illustrates how this operates on the ground. Journalists (VRT/PANO) have documented entire holiday parks, such as Kastelree in the Kempen region, converted into labour compounds housing up to eight workers per bungalow, in conditions linked to organised exploitation and trafficking networks. Workers may be formally “posted” by foreign companies, yet Belgian authorities often cannot determine who actually employs them, who insures them, or which state is legally responsible.
The scale is substantial. Around two million posted workers operate across the EU, including roughly 205,000 in Belgium alone. In construction, transport, agriculture, meat processing and food production, they form a critical share of the workforce. The most significant shift is the surge in posted third-country nationals (TCNs): over the past nine years their numbers have increased by more than 300%, creating a form of mobility that sits between legal migration and informal labour markets.
Mobility without traceability
This evolution has created major enforcement blind spots. Workers from Bosnia, Serbia, Brazil, North Macedonia, Ukraine or Belarus enter the EU legally through Member States with permissive admission regimes and are then circulated across the Union through posting arrangements backed by A1 certificates issued or claimed by companies with little or no real economic activity in the sending state. When shell companies collapse or disappear, workers are left without contracts, insurance, or any enforceable link to the country that authorised their entry. The situation is particularly dramatic in the event of an accident, when posted workers cannot obtain medical care and, in the event of disability, the necessary insurance assistance.
Slovenia has become a central hub of this system. Hundreds of “postbox companies” registered at single addresses generate up to 95 % of their turnover abroad, rotating workers on paper between entities to simulate compliance while preventing any authority from exercising effective control.
The Netherlands has formally acknowledged these risks. In a 2024 report, the Dutch Advisory Council on Migration warned that posting creates opaque legal situations in which it becomes nearly impossible to determine workers’ rights or which state is responsible for enforcement—especially for non-EU nationals whose residence and housing depend on their employer.
Similar dynamics exist across all Europe. Germany relies heavily on posted workers in construction, logistics and meat processing; Italy and Spain in agriculture and food production; and Austria and the Scandinavian states in construction and infrastructure.
From a border-security perspective, this constitutes an EU-internal facilitation phenomenon: a network-based form of organised exploitation that relies on lawful entry, legal mobility and fragmented enforcement. Non-EU nationals are not the perpetrators but the facilitated population. Their lawful status is weaponised by networks operating through legitimate corporate structures, i.e using letterbox firms, rotational posting, document manipulation, and dependency-based control through housing, transport and residence permits.
The legal contradiction at the heart of the system
At the core lies a structural legal contradiction. EU law guarantees free movement of services, while immigration law remains national. An Ukrainian can legally work in Poland, be posted to Germany, and yet never receive a German work permit—creating a grey zone in which the worker is formally legal but effectively unprotected. For third-country nationals, whose residence depends on their employer, this produces coercive conditions resembling forced labour: losing a job means losing legal status.
From a border-security perspective, this crime is “clean” at entry. There are no forged passports, no illegal crossings, and no false visas. Everything appears legal at the border. The abuse materialises only after movement inside the EU, making it invisible to classic border-risk models and detectable only through post-entry intelligence and cross-border cooperation.
Mutual trust as an exploitation vector
A defining feature of abusive posting schemes is the exploitation of mutual trust between Member States. The system assumes that the sending state has verified a worker’s status, that the host state will enforce labour standards, and that certificates issued by one authority reflect reality. In practice, this trust is rarely audited in real time. Verification requests are slow, resource-intensive and often inconclusive, especially when postings are short or workers rotate frequently.
This creates a perverse incentive structure: paper compliance is rewarded, substantive abuse remains low-risk, and detection depends on exceptional triggers rather than routine control. From a security standpoint, this mirrors how trust-based border regimes have long been exploited by organised facilitators in other migration contexts.
A structurally EU-specific facilitation model – pure EU crime
The term “pure EU crime” does not criminalise EU law. It describes a form of exploitation that depends entirely on the EU’s integration architecture. This model requires:
- supranational market freedoms,
- nationally fragmented migration control,
- the absence of internal border checks, and
- mutual recognition without shared verification and enforcement capacity.
Remove any one of these elements and the system collapses. Outside the EU, a Brazilian hired in one country cannot simply appear on a construction site in another without host-state authorisation. Inside the EU, legal status is portable via posting, allowing facilitation chains to operate entirely within the internal market.
Why most abuse remains invisible
Cross-border enforcement is usually triggered only by exceptional events: document inconsistencies, residence-threshold breaches, liability for a main contractor, accidents, or media exposure. Routine exploitation as short postings, clean paperwork and worker’s silence remains largely invisible.
This means that the most sophisticated operators are also the least visible, a familiar pattern in facilitation-based crime.
Legality as camouflage
The exploitation of third-country nationals through posting is not an accident of integration. It is a predictable misuse of a legal mobility system designed for trust rather than adversarial control. Lawful status becomes a tool of coercion, genuine documents mask fictitious employment, and jurisdictional fragmentation prevents effective intervention by responsible agencies.
For border-security practitioners, this case illustrates a broader lesson: in highly integrated legal spaces, the most consequential threats may not cross borders illegally at all. They may move entirely within the law until the law itself becomes the instrument of abuse.
Prevention by design failure
This case illustrates a recurring failure in EU regulatory design: large-scale mobility systems are created for economic efficiency and political trust, but not for adversarial use by organised networks.
The posted-workers regime was never designed to operate in a hostile environment where shell companies, document manipulation and dependency-based control would be used to move and bind third-country nationals across borders. As a result, it lacks built-in safeguards for traceability, enforcement and cross-border responsibility.
In practice, the system enables a form of administrative disappearance: workers remain formally legal, but no authority can reliably determine who is responsible for them, where they are insured, or which state must intervene when abuse occurs. This is not a technical oversight—it is a structural vulnerability created by separating free movement of services from immigration control and enforcement capacity.
What is missing is a prevention by design approach: the systematic modelling of how legal mobility schemes can be misused, how they interact with organised facilitation networks, and how enforcement responsibilities degrade once movement begins inside the EU. Without this, economic mobility tools become de facto migration and exploitation channels.
What makes this system particularly dangerous today is the rapid increase in posted third-country nationals. In less than a decade their numbers have more than tripled, turning what was once a labour-law mechanism into a large-scale internal migration channel operating almost entirely outside traditional border-control visibility.
Conclusion
The misuse of the EU’s posted-workers regime shows how contemporary migration and border-security risks increasingly arise inside legal mobility systems rather than at the physical border. What appears economically as labour flexibility has, in security terms, evolved into a parallel movement architecture—one that enables the large-scale circulation of third-country nationals without effective traceability, accountability, or control.
For border-security authorities, this requires a fundamental shift in risk perception. Entry control alone is no longer sufficient when legal status can be engineered, transferred, and exploited through corporate and administrative mechanisms after arrival. The critical vulnerabilities now lie in post-entry mobility, document integrity, and the gaps between national responsibility regimes.
Unless the A1 system, posting rules, and migration control are integrated into a single operational risk framework, facilitation networks will continue to weaponise legal mobility as a low-risk, high-profit channel for organised exploitation. In an integrated legal space like the European Union, the most dangerous movements are not those that violate the law but those that operate entirely within it.
By Lina Kolesnikova, Author. Security and Crisis Management Expert.
Lina is regular Speaker and Chairperson at UNOCT, OSCE and World Border Security Congress and many others, as well as being a regular contributor for ALERT, Crisis Response Journal, Journal of International Security, Counter Terror Business, ISJ, Counter-Terrorist Journal publications
