Monthly Archives: September 2026

GOODBYE “GOLDEN POWER” LEGISLATION. IN COMES THE EU’S NEW FOREIGN INVESTMENT SCREENING REGULATION.

On June 17, 2026, the European Parliament and the Council adopted Regulation (EU) 2026/1386 on the screening of foreign investments in the European Union, repealing and replacing the previous framework under Regulation (EU) 2019/452. The new Regulation, which will enter into force in January 2028, marks a significant step forward in the EU’s approach to protecting its economic security and strategic interests.

Why a new Regulation?  The 2019 framework was the EU’s first attempt at coordinating foreign investment screening across Member States. However, it was widely seen as insufficient: it was voluntary in nature, covered only direct investments from third countries, and left significant gaps where Member States lacked any screening mechanism at all. Since then, escalating geopolitical tensions, and lessons learned from the pandemic and energy crises have prompted a fundamental rethink. The new Regulation responds to these challenges by making screening mandatory, extending its reach, and creating a more harmonized procedural framework across the EU.

KEY CHANGES AT A GLANCE

1. Intra-EU investments now in scope.  Under the previous regime, only direct investments by third-country investors were covered. The new Regulation captures investments made by foreign investors through an EU-based subsidiary. This means that, for example, a Chinese investor operating through a Dutch holding company will now fall within the screening perimeter of the target’s home Member State.

2. Mandatory prior authorization in sensitive sectors.  All Member States must require prior authorization for foreign investments in companies active in designated sensitive sectors. These include: dual-use items and military goods/technologies; semiconductors, quantum technologies, and certain AI technologies; strategic raw materials (exploration, extraction, processing, recycling, recovery, or stockpiling); systemically important financial market infrastructures and entities (central counterparties, central securities depositories, regulated market operators, payment systems, financial messaging providers); and electoral registration databases, voting systems, and election management IT systems. Transport, energy, and digital infrastructure are also included, but only where the target company has been designated as critical following a risk-based assessment by the relevant Member State. Greenfield investments are excluded from the prior authorization requirement, although they remain within the Regulation’s general scope.

3. Harmonized review timeline.  The initial screening period is now capped at 45 calendar days from the date on which the filing is deemed complete. This provides greater predictability for deal timetables, particularly in cross-border transactions involving multiple Member States. A second phase may be opened if the initial screening period does not close with clearance of the investment.

4. Ex officio powers for non-notifiable investments.  For investments that are not subject to mandatory prior authorization, authorities may act ex officio from 15 months up to a maximum of five years after the completion of the transaction.

Corruption in Healthcare: What ANAC’s New Catalogue Means for Life Sciences Compliance

Corruption in Healthcare. Corruption is a concrete, evolving compliance risk for life
sciences companies, not just a hypothetical risk. In my experience sitting on supervisory boards under Legislative Decree 231/2001 on corporate criminal liability, the risks in this space have grown more sophisticated and harder to detect over the years.

The numbers explain why. Italy’s National Anti-Corruption Authority (ANAC) recently noted
that roughly 25% of all public procurement spending in Italy flows to the healthcare sector, and
that 8% of whistleblowing reports concern that same sector. Those two figures alone justify
heightened scrutiny.

ANAC has been paying attention accordingly. It has adopted the “Catalogue of Corruption Risks
and Prevention Measures in the Healthcare Sector”
(Catalogo dei rischi corruttivi e delle misure
di prevenzione nel settore sanitario), approved by ANAC’s Board with Resolution No. 318 of 29
July 2026. The Catalogue is meant to support National Health Service entities in drafting the “corruption risks and transparency” sub-section of their Integrated Activity and Organization Plan (PIAO), and it is a document worth reading well beyond that immediate audience.

The idea behind it is straightforward: healthcare is complex, the stakes are high, and the web of
relationships within the system calls for extra scrutiny, especially when public health is on the
line.

What the Catalogue Covers. The Catalogue maps new risks and new prevention measures across a wide range of areas: healthcare system regulation, biomedical research, pharmaceutical and medical-device marketing and promotion, public procurement, product distribution and storage, financial resource management, human resource management, and the actual delivery of healthcare services, including relations with accredited providers, oversight and inspection activity, and private practice and waiting lists.

For life sciences companies, the marketing and promotion chapter is the most direct point of
relevance: it is the clearest line connecting the Catalogue’s healthcare-system focus back to
industry conduct rather than treating it as a purely public-sector document.


Why This Matters. Healthcare is a perfect storm for integrity risk: high-stakes decisions, significant economic interests, constant public-private interaction, and pronounced information asymmetries. That mix can easily breed mismanagement, conflicts of interest, and outright corruption. ANAC’s own conclusion is that preventing corruption in healthcare takes a model built on transparency and impartiality, digitalization, independent controls, accountability, and the capacity to monitor the most exposed processes on an ongoing basis.

A Basis to Stress Test the Risk Map. Both public entities and private companies active in healthcare should take note of these risks and move to adopt measures that prevent them. For life sciences companies operating a Legislative Decree 231/2001 compliance model, the Catalogue is more than a general awareness exercise: it is a ready-made checklist against which to stress-test the existing risk map, refine the questions asked of management, and confirm that prevention measures keep pace with how these risks.

A New 231? Italy’s Proposed Reform of Corporate Criminal Liability

On August 4, 2026, the Italian Council of Ministers has approved a draft bill overhauling the rules on the liability of legal entities under Legislative Decree No. 231 of 2001. Below is a summary of the main changes.

  • Organizational fault as the sole basis for liability
    • Organizational fault (“colpa in organizzazione”) becomes the exclusive subjective criterion for imputing liability to the entity. Crucially, this eliminates the current reversal of the burden of proof: the prosecutor, not the entity, must demonstrate organizational failings.
  • Unified liability test — no more “apical vs subordinate” distinction
    • The current two-track system — which treats offences committed by senior management differently from those committed by subordinates — is abolished. A single criterion applies: the entity is liable only where a causal link is established between the failure to adopt (or effectively implement) an adequate compliance model and the commission of the offence.
  • Presumption of corporate interest or benefit for offences based on negligence
    • For offences based on negligence, a rebuttable presumption of corporate interest or benefit is introduced where the breach of applicable rules has resulted in appreciable cost savings or increased output.
  • Clearer compliance model requirements
    • The reform defines the essential content, adoption procedure, and revision process for compliance models. Models that follow guidelines issued by representative trade associations are presumed adequate; a court departing from that presumption must give specific reasons. In the field of occupational health and safety, models based on the UNI ISO standard carry full exonerating effect.
  • Simplified procedures for SMEs
    • The Minister of Justice is tasked with issuing a decree setting out simplified procedures for small and medium-sized enterprises to adopt and implement effective compliance models.
  • Expanded grounds for extinguishing liability
    • A new ground to extinguish liability is added for entities that take post-offence remedial action to cure the compliance gaps identified by the public prosecutor. Specific extinction rules apply to environmental and tax offences (remediation and full payment, respectively). In addition, liability is extinguished where the entity eliminates the organizational failures identified in the certified assessment.
  • Strengthened procedural safeguards
    • The public prosecutor must specify the organizational failings both in applications for injunctive measures and when formally charging the entity; failure to do so renders the proceedings null. Pre-trial seizure is excluded where the entity offers adequate security. Plea-bargaining is now available to the entity regardless of the parallel proceedings against the individual. A time-bar mechanism is introduced: liability is extinguished five years after an injunctive sanction of up to one year (or two years after a pecuniary sanction only), provided no offence of the same kind is committed in the interim.
  • Government delegation on sanctions and crimes giving rise to liability
    • The Government is delegated to adopt, within 8 months of the law’s entry into force, a legislative decree revising the sanctions framework and the catalogue of crimes giving rise to 231 liability, which should limit such crimes to those with greater connection to corporate activities.

This reform represents a fundamental shift in Italy’s corporate liability regime: it places organizational fault at the center of the system, removes the burden-of-proof asymmetry that has long been criticized by practitioners, and introduces meaningful incentives for entities to invest in robust compliance programs. Businesses operating in Italy — or with Italian subsidiaries — should assess the impact on their existing 231 models as the bill progresses through Parliament.