The EU Anti-Corruption Directive Implications for Non-EU Companies
Directive (EU) 2026/1021 of the European Parliament and of the Council of 29 April 2026 on combating corruption (the “ACD”) was published in the Official Journal of the European Union on 11 May 2026 and enters into force on 31 May 2026. The Directive completes the EU’s first comprehensive criminal law framework on corruption applicable across all 27 Member States, with most substantive obligations applicable across Member States by mid-2028.
For non-EU companies, the question is no longer whether the EU has a binding anti-corruption regime. The question is which Member States’ implementing legislation will reach them, on what basis, and how quickly an existing compliance programme calibrated to the FCPA and the UKBA will need to be extended.
For Turkish corporates and other non-EU groups with EU exposure, the operational window to evidence a real programme is now measured in months.
1. The Legislative Background
Directive (EU) 2026/1021 of the European Parliament and of the Council of 29 April 2026 on combating corruption (the “ACD”) was published in the Official Journal of the European Union on 11 May 2026 and enters into force on 31 May 2026.
The European Parliament had endorsed the final text on 26 March 2026 by 581 votes to 21, with 42 abstentions. The Council gave its formal approval on 21 April 2026. Provisional agreement between the Commission, the Parliament and the Council had been reached on 2 December 2025.
The Directive completes the EU’s first comprehensive criminal law framework on corruption applicable across all 27 Member States, with most substantive obligations applicable across Member States by mid-2028.
Until the ACD, the EU’s anti-corruption architecture rested on a patchwork of partial instruments. The 1997 Convention on the fight against corruption involving EU officials and Council Framework Decision 2003/568/JHA on combating corruption in the private sector covered limited ground.
Directive (EU) 2017/1371 on the protection of the EU’s financial interests, the “PIF Directive,” by means of criminal law addressed corruption affecting the Union’s budget but not corruption more generally.
The Commission acknowledged in its 3 May 2023 proposal, COM(2023) 234 final, that significant discrepancies remained between Member States and that the existing instruments had failed to keep pace with cross-border corruption.
Articles 83(1), 83(2) and 82(1)(d) of the Treaty on the Functioning of the European Union (“TFEU”) serve as the legal basis. The ACD sets a minimum baseline, while Member States retain the discretion to adopt rules exceeding this baseline when transposing the ACD into their national law.
The approach taken by EU Member States while transposing the ACD into national law will bring the real change.
2. A Comparative Overview of the ACD with the FCPA and the UKBA
Any international compliance function has built its programme around the U.S. Foreign Corrupt Practices Act of 1977 (FCPA) and the UK Bribery Act of 2010 (UKBA). The ACD is the third major pillar in this architecture. It is not a translation of either.
Scope of offences
The FCPA is deliberately narrow. It prohibits U.S. persons, U.S.-listed companies and, with a U.S. nexus, non-U.S. persons from bribing foreign public officials to obtain or retain business. It does not address domestic bribery, private-sector bribery or passive bribery.
The UKBA is considerably broader, covering active and passive bribery in both the public and private sectors, including purely commercial corruption.
The ACD tracks the UKBA’s broad scope and exceeds it on certain points. The following are all mandatory offences:
- Public-sector bribery under Article 3
- Private-sector bribery under Article 4
- Misappropriation under Article 5
- Trading in influence under Article 6
- Unlawful exercise of public functions under Article 7
- Obstruction of justice under Article 8
- Enrichment from corruption under Article 9
- Concealment under Article 10
- Incitement, aiding, abetting and attempt under Article 11
The definitions of property in Article 2 expressly cover crypto-assets, bringing concealment enabled with such assets within the scope of the Directive in a way that neither the FCPA nor the UKBA does explicitly.
Corporate criminal liability
Article 13 adopts a functional approach to corporate criminal liability, but not a strict criminal liability standard.
A legal person is liable where an offence under Articles 3 to 6 and 8 to 11 is committed for that legal person’s benefit:
- By a person in a leading position based on representation, decision-making authority or control authority; or
- Where a lack of supervision by such a person has made the offence possible by a person acting under that person’s authority.
The Article 13 standard is narrower than Section 7 of the UKBA. The UKBA’s “associated person” concept captures employees, agents, subsidiaries, joint-venture partners and third-party intermediaries regardless of whether any senior person was aware of or involved in the conduct.
The ACD’s leading-position-or-failed-supervision test operates at a higher level inside the corporate structure and does not, on its face, reach third parties acting on the company’s behalf.
Mitigating factors
Section 7 of the UKBA, with its “adequate procedures” statutory defence, has shaped global anti-bribery compliance since its enactment. The strict-liability-plus-defence architecture creates a direct economic incentive to invest in real procedures.
The ACD does not replicate this structure. Under the ACD, compliance programmes operate as a mitigation factor at sentencing.
Article 16 provides a mitigating factor where a legal person is held liable for any of the offences referred to in Articles 3 to 6 and 8 to 11 and, unless it constitutes a ground for exclusion of liability, it has implemented effective internal controls, ethics awareness and compliance programmes to prevent corruption before or after the commission of the offence.
This means that unless a Member State already provides a full defence for the same circumstances, an effective compliance programme will apply, at minimum, as a mitigating factor.
The recitals warn that window-dressing programmes will not attract mitigation. Only genuine, effective and duly assessed internal controls, ethics and compliance programmes will qualify.
A further mitigating factor applies where a legal person, once the offence has been discovered, rapidly and voluntarily discloses it to the competent authorities and takes remedial measures.
These provisions are closer in character to the U.S. Sentencing Guidelines approach under the FCPA than to the UKBA model.
Penalties, measures and fines for legal persons
Article 14 sets minimum fine thresholds calibrated to worldwide turnover. The penalties must be proportionate to the gravity of the conduct and to the individual, financial and other circumstances of the legal person concerned.
For the most serious offences under Articles 3 to 5, covering public-sector bribery, private-sector bribery and misappropriation, the maximum fine must be no less than:
- 5% of total worldwide annual turnover; or
- Alternatively, EUR 40 million.
A second tier applies to trading in influence under Article 6, obstruction of justice under Article 8 and enrichment from corruption under Article 9. The maximum fine must be no less than:
- 3% of total worldwide annual turnover; or
- Alternatively, EUR 24 million.
Member States may transpose the obligation as either a turnover-based fine or a fixed-amount fine. They may also determine whether the fine takes the form of a criminal or administrative sanction. FCPA and UKBA fines remain unlimited in principle.
Beyond fines, Article 14 provides for additional sanctions on legal persons, which Member States may impose alongside or instead of criminal or non-criminal penalties. These include:
- Exclusion from entitlement to public benefits or aid
- Exclusion from access to public funding, including tender procedures and grants
- Temporary or permanent disqualification from commercial activities
- Withdrawal of permits and authorisations
- Placement under judicial supervision
- Judicial winding-up
- Temporary or permanent closure of establishments used for the offence
In specific circumstances, the non-financial sanctions can carry greater weight and consequences than the fine itself.
Jurisdiction
Article 18 sets out two mandatory jurisdictional bases that every Member State must adopt.
The first is territorial jurisdiction, including offences committed wholly or partly on the Member State’s territory and offences committed through an information system used on its territory, regardless of whether the technology itself is based in that territory.
The second is active nationality jurisdiction over offences committed by a Member State’s nationals.
Article 18 then offers four optional extensions that Member States may adopt and must notify to the Commission:
- Habitual residence on the Member State’s territory
- Victim nationality or habitual residence
- Benefit of a legal person established on the Member State’s territory
- Benefit of a legal person engaged wholly or partly in business on its territory
The fourth extension is the one that matters most for non-EU groups. It is structurally analogous to the UKBA’s “carrying on a business” test and produces comparable reach in the Member States that adopt it.
The ACD’s mandatory scope is narrower than either the FCPA or the UKBA. Its optional business-nexus extension can match the UKBA’s close-connection reach in the Member States that adopt it.
The exposure picture may therefore look materially different in a Member State that adopts the optional jurisdictional bases compared with one that declines them.
3. The Position of Non-EU Companies
The ACD is not formulated as a regime aimed at non-EU companies. However, its extraterritorial architecture, including the mandatory territorial and active-nationality bases under Article 18 and the optional business-nexus extension, means that any non-EU group with meaningful EU touchpoints is within potential reach.
This applies to U.S., UK, Swiss, Turkish, Gulf-based and other foreign multinationals alike.
Operational exposure points
A non-EU group should assume potential ACD exposure, and prepare for the resulting compliance obligations, wherever any of the following is true:
- It has a subsidiary, branch or permanent establishment in an EU Member State. Territorial jurisdiction under Article 18 attaches.
- It does meaningful business in an EU Member State that has adopted the optional business-nexus extension, even without local incorporation. In that Member State, a bribe paid by employees in a third country to a non-EU official for the benefit of the non-EU parent can, in principle, be prosecuted locally.
- It employs EU Member State nationals acting on its behalf. The Member State of nationality has active-nationality jurisdiction over its own nationals.
- It routes payments or communications through EU financial systems or EU-hosted IT infrastructure. Any transit through EU territory, including a correspondent bank, an EU-hosted email server or a data centre, can ground territorial jurisdiction.
- It participates in EU-funded procurement, EU public tenders or commercial relationships with EU officials or EU-regulated public-service functions.
- It is a counterparty, supplier, joint-venture partner or acquisition target of an EU-established legal person. Even without direct jurisdictional reach, the EU counterparty’s own compliance obligations cascade down through due diligence and contractual flow-downs.
4. The Turkish Lens
A detailed comparison between the ACD and Turkish law would be large enough to warrant a separate paper. Nevertheless, the principal points can be summarized briefly.
Bribery and foreign bribery are both criminalised under the Turkish Penal Code, Law No. 5237, although private bribery does not exist as a distinct offence.
Turkish criminal law does not provide for corporate criminal liability in the U.S. or UK sense. Sanctions against legal persons are administrative under the Law on Misdemeanours, Law No. 5326, and principally take the form of fines and security measures.
A Turkish parent’s ACD exposure therefore arises through its EU subsidiaries or EU business activity, not through Turkish criminal proceedings against the Türkiye-resident parent itself.
Three observations are critical for Turkish corporates.
First, the EU is Türkiye’s largest trading partner. Bilateral trade in goods is in the order of EUR 217 billion annually, and the EU-Türkiye Customs Union, in force since 1 January 1996, integrates Turkish industrial production with EU supply chains. Most sizeable Turkish multinationals will trigger at least one of the exposure points identified above.
Second, Turkish corporates with mature Anti-Bribery Anti-Corruption (“ABAC”) programmes built around the FCPA and the UKBA will already cover most of what the ACD substantively requires.
The OECD Working Group on Bribery’s Phase 4 monitoring report on Türkiye from June 2024 and GRECO’s compliance reporting identify structural gaps on the supply side of foreign bribery enforcement, including a low number of prosecutions of legal persons and limited corporate liability under Turkish law.
The ACD does not directly remedy these gaps. It changes the cross-border exposure picture for Turkish companies operating in the EU.
Third, specific attention is needed regarding the optional business-nexus extension. The UKBA’s “carrying on a business” test is well understood and reflected in most multinational programmes. The ACD’s equivalent will apply unevenly across the 27 Member States and will be defined in each jurisdiction by local transposing legislation.
Mapping EU operations against each Member State’s implementing law, as it emerges over the 24-month transposition window, is the immediate priority for any non-EU group with EU activity.
5. Timeline
The Directive was published in the Official Journal of the European Union on 11 May 2026 as Directive (EU) 2026/1021 and enters into force on 31 May 2026.
From that date:
- Member States have 24 months to transpose most substantive provisions into national criminal law, with the deadline falling at the end of May 2028.
- Prevention-related provisions, including national anti-corruption strategies and structured corruption risk assessments, have a longer 36-month transposition window, with the deadline falling at the end of May 2029.
- The Commission must report on the status of transposition within four years and on the Directive’s added value within six years.
Substantive criminalisation obligations will therefore take effect in most Member States by mid-2028. Prevention obligations follow in mid-2029.
Several Member States have signalled that drafting will begin immediately. The window to build or upgrade ABAC programmes before enforcement begins is months rather than years.
National variation will be material. The ACD is a minimum-harmonisation instrument. Member States may adopt stricter rules, and several are expected to do so. The optional jurisdictional bases under Article 18 will also be adopted unevenly.
Compliance teams should monitor national transposition in each Member State where the group has activity, rather than assuming uniformity across the Union.
ACD Implementation Timeline
Directive (EU) 2026/1021 of the European Parliament and of the Council of 29 April 2026
| Published | Entry into Force | Criminalisation | Prevention | Report I | Report II |
|---|---|---|---|---|---|
| 11 May 2026 | 31 May 2026 | 1 June 2028 | 1 June 2029 | 1 June 2030 | 1 June 2032 |
| Official Journal of the European Union | Directive binding; transposition clock starts | Substantive provisions due in national law, 24 months | National strategies and risk assessments due, 36 months | Commission transposition status report, 4 years | Commission added-value assessment, 6 years |
6. What Changes in Practice
The ACD promises to end two decades of EU corruption-law fragmentation. It puts corporate corruption financial exposure on a GDPR and competition-law scale.
It mandates a broad catalogue of offences, including trading in influence and concealment of virtual assets. Through its integration with Directive (EU) 2019/1937, the Whistleblower Directive, it builds a single reporting and protection architecture.
The Directive remains narrower than the UKBA in one structurally important respect: the absence of a failure-to-prevent offence and the corresponding adequate-procedures defence, although compliance programmes are considered as a mitigating factor.
The economic incentive for proactive compliance investment is therefore weaker in the EU than in the UK.
Companies already calibrated to UKBA and FCPA standards will, in most cases, already exceed the ACD’s substantive requirements. Companies calibrated only to ACD-based Member State regimes may not.
For Turkish corporates and other non-EU groups, the operational question has shifted. It is no longer whether the EU’s anti-corruption regime is relevant.
It is which Member States’ jurisdictional extensions reach the group, what each transposing law looks like in detail, and how quickly the group can evidence a programme that is real rather than cosmetic.
On current timelines, the third answer must arrive well before 2028.