Screening the Screeners: The New EU Foreign Investment Regulation meets the old-generation investment treaties

Travellers are seen in a train station.

In August 2024, the Spanish government refused to authorize the takeover of the railway manufacturer Talgo by Ganz-Mávag Europe, a Hungarian investor partly owned by Hungary’s state investment fund. The stated ground was risk to national security and public order; the reasoning beyond that was classified. What followed is instructive in every direction. The investor litigated at home, and in January 2026 the Spanish Supreme Court upheld an order granting access to certain documents underpinning the decision while shielding intelligence material. In April 2025, Ganz-Mávag lodged an arbitration against Spain under the ECT and the SCC Rules, which it discontinued in April 2026, without prejudice to the underlying rights, after Spain raised the intra-EU objection. However, it is unknown what led the investor to discontinue the case.

Under the new Regulation (EU) 2026/1386 of June 2026 and applicable from January 17, 2028, every EU member state must be able to do precisely this. In fact, it must be equipped with even more powerful tools. The Regulation, which replaces the 2019 framework that merely encouraged screening, requires all member states to operate mandatory prior authorization regimes across a common minimum sectoral scope (Article 4(15) and Annex 1: dual-use and military items, semiconductors, quantum and certain AI technologies, strategic raw materials, critical transport, energy and digital infrastructure, financial market infrastructure, electoral systems), and equips screening authorities with ex post call-in powers over completed transactions for up to 5 years expressly contemplating the unwinding of investments as a screening outcome (Article 4(4)), and extends screening to acquisitions made through EU-incorporated vehicles controlled from third countries, closing the gap exposed by the Court of Justice in Xella.

The transposition commentary has so far treated all this as a story of EU law and transactional compliance. A second layer of law has drawn far less attention. A small but growing literature has begun to map the interface between screening and investment arbitration, prompted precisely by disputes such as Ganz-Mávag v Spain: on the procedural dynamics of parallel domestic and arbitral proceedings (Pei & Dahlquist, 2026), and on the menu of treaty-design techniques by which states might shield screening from challenge in future agreements (Paine, 2026). What remains largely unexamined is the prior question, and the urgent one: what exposure the Regulation’s tools create under the hundreds of investment treaties member states already have with third countries—treaties negotiated, for the most part, in an era whose animating premise was the protection of foreign capital against precisely the kinds of measures screening now mandates, and which cannot realistically be redrafted before January 2028. This piece maps that exposure, tests the available defences, and draws a conclusion that goes beyond defensive design.

What the Regulation Asks States to Do, Seen Through Treaty Eyes

Arranged in ascending order of treaty risk, the Regulation’s tools are as follows:

  • first, the prohibition of a proposed acquisition—for the mandatory sensitive sectors, screening occurs before completion, since authorization is a precondition of closing (Articles 4(15) and 4(9)), and prohibition is one of the defined outcomes of a screening decision (Article 2(14)), though, as noted below, a prohibition can also attach to a transaction already completed.
  • second, conditional clearance through mitigating measures, either behavioural or structural (Article 4(14) and Article 2(20));
  • third, the ex post call-in and unwinding of completed transactions—the Regulation creates two distinct call-in windows, for at least 15 months and up to 5 years for investments falling outside the prior authorization requirement which the authority reviews on its own initiative (Article 4(4)), and for at least 24 months where an investment subject to prior authorization was not filed, or filed only after completion (Article 4(5)); a call-in on either basis may result in a divestment or unwinding order.

Authorities are also empowered to impose penalties for non-filing or breach of conditions (Article 4(11)), though these raise distinct and generally lesser treaty questions. Cutting across all of these is an institutional architecture with its own treaty salience, as decisions are informed by the cooperation mechanism in which other member states’ comments and Commission opinions must be given due consideration by the deciding state (Article 12). A reviewed investor will see the classified core of the assessments, at best, in summary.

From a treaty perspective, one distinction carries crucial consequences. Prohibition typically operates at the moment of admission, whereas call-in and unwinding operate against an established investment. The line is not perfectly clean—a prohibition may attach to a transaction the investor completed without the required authorization (Article 4(5)), and the own-initiative call-in of Article 4(4) can reach a completed investment years after the fact—but as a first approximation, it holds.

Most European investment treaties are post-establishment instruments: their protections attach to investments made, admitted, or established in accordance with host state law. A refusal to admit therefore sits, in the ordinary case, outside the treaty’s substantive guarantees. However, Ganz-Mávag is a reminder that even a blocked bid can generate a treaty claim, and jurisdictional weakness of the claim may be cold comfort against years of defence costs. Newer agreements containing pre-establishment commitments have tended to anticipate the problem. Canadian treaty practice is the clearest illustration: CETA excludes decisions under the Investment Canada Act from both investor–state and state-to-state dispute settlement (Annex 8-C), and the recent Ecuador–Canada FTA extends the template in its most uncompromising form yet, (Article 15.19 and Annex 15-A), excluding screening decisions from ISDS as well as state-to-state dispute settlement, and adding a reciprocity mechanism under which analogous future Ecuadorian legislation may be inscribed into the carve-out. Where treaty drafters thought about screening, in other words, they excluded it—cleanly, by jurisdictional text. The older treaties, which are the vast majority, did not think about it at all.

The contrast with procurement sharpens the point. When Spain reportedly instructed the state-controlled companies in its SEPI (Sociedad Estatal de Participaciones Industriales) holding to stop signing new contracts with the U.S. firm Palantir on national security grounds this summer (here and here), it acted in a domain treaties have long left to state discretion. Government procurement has sat outside investment-treaty non-discrimination disciplines since those disciplines were first drafted (see, e.g., NAFTA Article 1108(7)(a); GATS Article XIII; and, in the same period, the ECT’s confinement of making-of-investment treatment to a non-binding “endeavour,” Article 10(2)). CETA houses procurement in a chapter of its own (Chapter 19), outside the investment guarantees. Screening enjoys no such immunity. To unwind or condition an established investment reaches into the treaties’ core protective standards in a way that excluding a vendor never has—even as the same security rationale now runs across every mode of foreign economic presence.

The Exposure: Expropriation and Fair and Equitable Treatment

A divestment order deprives the investor of its shareholding, typically through a forced sale under time pressure and at a discount. Whether framed as direct or indirect expropriation, this is the paradigm case for ISDS claims. The United Kingdom’s Nexperia/Newport Wafer Fab divestment order and the Ralls litigation in the United States preview the fact pattern. Neither produced an ISDS claim. There is no U.S.–China BIT behind Ralls, and the 1986 UK–China BIT‘s narrow arbitration clause reaches only the amount of compensation for expropriation. The Dutch chapter of the Nexperia story is different, however. In late 2025, the Netherlands invoked a dormant 1952 emergency law to seize control of Nexperia on economic security grounds, and its parent, Wingtech has since brought an ICSID claim under the China–Netherlands BIT, reportedly seeking some USD 8 billion, making it the most substantial live treaty claim from an EU security intervention in this wave, as Ganz-Mávag, brought earlier, has since been withdrawn.

The state’s natural doctrinal home to defend such claims is the police powers doctrine that holds that a bona fide, non-discriminatory exercise of regulatory power for public order does not, on the now-orthodox view, amount to compensable expropriation. But the doctrine’s edges are contested exactly where the Regulation applies pressure. A prohibition at the point of entry fits the police powers frame comfortably. An order unwinding a transaction the state could have reviewed years earlier, but did not, fits it far less well. It bears noting that the longest look-back the Regulation mandates, the 5-year window of Article 4(4), attaches precisely to investments the state never required to be notified in the first place. The later and more discretionary the intervention, the more it resembles a taking of vested rights rather than the policing of admission.

In addition, even where the power to expropriate for security reasons is undoubted, most treaties condition its lawful exercise on compensation. Screening statutes, as a rule, provide no compensation for the security-based interference itself, as the regimes are built on the premise that a security-grounded prohibition or divestment is a non-compensable exercise of regulatory power. Investment treaties do not share that premise. Arbitral practice on exceptions has, if anything, undermined the state’s defence. Tribunals have held that even an applicable general exceptions clause does not extinguish the obligation to compensate for the underlying breach. That gap will not stay unexamined once the first divestment order meets a request for arbitration.

FET raises a different order of problem. ITN readers will not need persuading that the doctrine of legitimate expectations rests on contestable foundations. I have argued elsewhere that its ascendance owes more to a particular historical conjuncture than to any doctrinal necessity. But an exposure analysis must take arbitral practice as it finds it, not as one might wish it to be. Tribunals now routinely treat the regulatory framework in force at the time of investment as capable of generating protected expectations, even absent any individualized assurance. The Spanish renewables saga is the paradigm. Across dozens of ECT claims, tribunals held that while investors could not expect the framework to be frozen in time, the general legislative regime, enacted to attract investment, itself founded legitimate expectations that its essential features would not be dismantled (e.g., Eiser v Spain; Cube Infrastructure v Spain). And an investor that closed lawfully—or obtained clearance—only to face later conditions or unwinding presents that argument in close to its strongest form.

Then there is the procedural limb of FET. The Regulation itself preserves formal safeguards—a right to be heard before any adverse decision (Article 4(14)), an effective judicial remedy (Article 4(7)) and the Charter of Fundamental Rights of the European Union demands as much. The vulnerability lies in the gap between formal process and substantive access. The investor is heard but cannot test the classified case against it. The Talgo domestic proceedings show national courts already straining against that gap, ordering disclosure of parts of the administrative file while shielding intelligence material. Transparency, the right to be heard, freedom from arbitrariness: this is the most winnable terrain for claimants.

The tribunal in Global Telecom Holding v Canada, the closest arbitral precedent arising from Canada’s national security review of a telecommunications investment, reviewed the security review on the merits under FET rather than treating it as shielded, and held that due process is satisfied where the investor is given “a fair opportunity to make its case in relation to readily identifiable issues” ahead of the decision. Canada prevailed because it had afforded that opportunity. The open question is whether the opportunity to be heard remains meaningful when the decisive assessment is classified and disclosed to the investor only in summary. That is the gap the Talgo proceedings expose: Spanish courts have ordered partial disclosure of the administrative file on equality-of-arms grounds while shielding intelligence material, testing exactly where the right to be heard meets the security interest in secrecy.

One further point deserves more attention than it has received: mitigating measures under the new regimes will typically be embodied in undertakings negotiated between investor and authority. Where the applicable treaty contains an umbrella clause, such undertakings are candidates for elevation into treaty-protected commitments. In such a case, a later tightening or enforcement dispute would arrive in arbitration dressed as a breach of the state’s own bargain. The officials who will draft these agreements over the coming 2 years are, for the most part, unaware that they may be drafting such commitments.

The Defences, and the Awkward Geography of the Treaty Network

The intuitive response is that security screening is what essential security exceptions are for. The difficulty is that the exceptions are distributed across the network with an almost perverse unevenness. Security clauses are creatures of particular treaty programs and particular decades, and a great many of the older European BITs—including, notably, treaties with China, with Gulf states, and with other capital-exporting partners whose investors the new screening wave most plainly has in view—contain no security exception at all. A systematic mapping remains to be done, but the pattern is not seriously in doubt. The newest instruments of economic security will operate against some of the oldest treaties in force, and the states most likely to need a security defence are, in many bilateral relationships, the least likely to have one.

The Canadian carve-out practice throws this gap into relief: a jurisdictional exclusion for screening is functioning, repeatedly deployed treaty technology, which makes its absence across the European network a structural exposure rather than an inevitability of the treaty form. So, from the opposite direction, does the intra-EU case law. Spain’s first line of defence in Ganz-Mávag was the intra-EU objection, and after Achmea, Komstroy, and the EU termination agreement, that door is closing. This concentrates, rather than dilutes, the exposure: the claims that survive will be those of third-country investors under exactly the older external treaties least likely to contain an exception.

Where an exception does exist, its coverage is narrow and contested (e.g., Alvarez & Khamsi, 2008; and Kabra, 2020). Customary necessity offers little comfort as a fallback: the cumulative conditions of Article 25 of the ILC Articles were not built for the routine administration of an authorization regime. Nor is EU law a defence. The Regulation deliberately leaves the screening decision with the member state. Recital 59, indeed, expressly directs that implementation be consistent with member states’ trade and investment agreements. This acknowledgement of the interface resolves nothing and, in any event, would not be binding on the tribunal. The member state holds the treaty risk, including for decisions shaped through the cooperation mechanism by institutions that hold none.

Transposing With Eyes Open—and the Question Behind the Question

In the 18-month window, three tasks suggest themselves. A treaty audit conducted alongside legislative drafting: mapping each regime’s tools, above all the call-in and unwinding powers, against the state’s extra-EU treaty network and identifying the relationships in which no exception exists. Procedural design as FET-proofing: reasoned decisions, defined timelines, declassified summaries, genuine hearings—the cheapest insurance against the most winnable claims, and largely what Article 47 of the Charter requires anyway, as the Talgo disclosure litigation suggests. Mitigation agreements need to be drafted in full awareness of umbrella clauses.

But defensive lawyering is the answer to the wrong question. The deeper lesson of this survey is not that states should learn to screen around their treaties; it is that the treaties themselves are the anomaly. For two decades, the central debate of this field was whether investment treaties left states sufficient regulatory space. Screening is the most muscular assertion of that space imaginable, mandated now by EU law itself. And what constrains it is a network of old-generation instruments whose protections and exceptions are distributed by the accident of when each was signed, and whose contribution to investment flows remains, after decades of study, unproven.

Member states have already drawn this conclusion once: they terminated their intra-EU BITs by agreement, and the Union and most of its members have walked out of the ECT. The same logic now applies to the external network. The transposition period should double as a treaty-reform period: renegotiate toward a new treaty agenda where partners engage and move deliberately toward terminating old-generation BITs where they will not, managing sunset clauses rather than being managed by them. Economic security policy is being constructed, at speed, on a legal substrate built for a different era. States can keep paying for that mismatch, award by award—or they can finally retire the substrate.


Author

Josef Ostransky, Senior Policy Advisor at IISD; Managing Editor, ITN.