Berlin is in mourning after a van rammed into the city's Pride parade, killing one woman and injuring 29 others. The suspect, 21-year-old Abdul Ballout, a German citizen of Lebanese descent, had been on the radar of German intelligence services for years due to his involvement in Islamist extremist networks. The attack has reopened a difficult conversation about whether Europe's patchwork of national surveillance systems and cross-border intelligence sharing is adequate to prevent such tragedies.
A suspect known to authorities
Ballout had a history of extremist activity. He had previous convictions for assault and robbery and had repeatedly tried to travel to Syria via Turkey and Lebanon to join the so-called Islamic State group. In May 2026, a Berlin juvenile court sentenced him to one year and ten months in youth custody for preparing a serious act of violence and attempting to join a jihadist organization. Prosecutors appealed, arguing the sentence was too lenient, but during the appeal process a court ruled there were no longer sufficient grounds to detain him and ordered his release. He was also required to undergo a deradicalisation programme.
German Chancellor Friedrich Merz called the attack “heinous” and vowed to defend freedom. The case has drawn attention to the fact that Ballout had traveled outside the Schengen Area — to Turkey, where he sought to enter Syria — and then returned to the EU without being stopped.
The limits of the Schengen Information System
The Schengen Information System (SIS) is the EU's most widely used security database, consulted billions of times each year. Since its upgrade in 2023, member states can issue alerts on individuals suspected of involvement in terrorist activities, allowing authorities in other Schengen countries to carry out discreet checks. According to the European Commission, the system has helped identify dozens of terrorist suspects. But as the Berlin attack shows, the SIS has clear limits.
“The SIS is a powerful tool, but it was designed to identify individuals as they cross borders,” said Christian Kaunert, Professor of International Security at Dublin City University. He noted that counterterrorism intelligence sharing across the EU still relies largely on voluntary cooperation between member states.
The Commission insists that counterterrorism remains primarily the responsibility of individual member states, and that the SIS is a key tool for cross-border tracking. But experts argue that the system cannot compensate for the lack of a unified EU-wide intelligence register. There is no central database showing how many people are under surveillance for suspected involvement in Islamist extremist networks across the continent.
A patchwork of national watchlists
European countries use different systems to monitor suspected extremists, each with its own legal definitions, surveillance thresholds and threat classifications. Germany estimates its Islamist extremist scene at around 28,000 people, including roughly 450 individuals classified as potential violent offenders, or Gefährder. France's FSPRT watchlist contains several thousand people considered at risk of violent radicalisation. Belgium's GGB T.E.R. database lists 529 priority entities, 446 of them linked to Islamist extremism. In the UK, MI5 says it manages around 43,000 “subjects of interest” across all terrorism investigations.
Europol does not maintain its own EU-wide intelligence watchlist. The agency supports cross-border investigations through intelligence analysis and operational coordination, but counterterrorism remains a national responsibility. The result is a layered European security framework: the SIS allows countries to trace terrorism suspects across borders, while national intelligence agencies decide who should be monitored and what action should be taken.
The Berlin attack has raised fresh questions about whether this system is sufficient to identify individuals who may progress from extremist sympathies to acts of violence. As our analysis of the EU's lack of a unified terror watchlist shows, the gaps are significant. The attack also underscores the challenge of monitoring individuals who travel outside the Schengen Area and then return.
In the aftermath, German authorities have faced scrutiny over why Ballout was not detained despite his known links to extremism. The case has also sparked debate about the effectiveness of deradicalisation programmes and the judicial decisions that led to his release. For many Europeans, the attack is a stark reminder that the continent's security architecture, while robust in many respects, still has vulnerabilities that can be exploited.


