TIMEWELL
Solutions
Free ConsultationContact Us
TIMEWELL

Unleashing organizational potential with AI

ISO/IEC 27001 (ISMS) certification mark (SGS / ISMS-AC)

ISO/IEC 27001:2022 certified Certificate No. JP26/00000255 Scope: Planning, development and operation of SaaS products utilizing AI technology

Services

  • ZEROCK
  • TRAFEED (formerly ZEROCK ExCHECK)
  • TIMEWELL BASE
  • WARP
  • └ WARP 1Day
  • └ WARP NEXT Corporate
  • └ WARP BASIC
  • └ WARP ENTRE
  • └ Alumni Salon
  • └ WARP for Schools
  • AI Consulting
  • ZEROCK Buddy

Company

  • About Us
  • Team
  • Why TIMEWELL
  • News
  • Contact
  • Free Consultation

Content

  • Insights
  • Knowledge Base
  • Case Studies
  • Whitepapers
  • Events
  • Solutions
  • AI Readiness Check
  • ROI Calculator

Legal

  • Privacy Policy
  • Manual Creator Extension
  • WARP Terms of Service
  • WARP NEXT School Rules
  • Legal Notice
  • Security
  • Anti-Social Policy
  • ZEROCK Terms of Service
  • TIMEWELL BASE Terms of Service

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

© 2026 株式会社TIMEWELL All rights reserved.

Contact Us
HomeColumnsTRAFEEDEU Dual-Use Regulation 2026–2028 Evaluation Explained: Article 26 and What Japanese Companies Should Prepare
TRAFEED

EU Dual-Use Regulation 2026–2028 Evaluation Explained: Article 26 and What Japanese Companies Should Prepare

Published2026-05-20Updated2026-07-06Ryuta Hamamoto
export controlEU Dual-Use RegulationArticle 26500 seriesWhite PaperCyber-surveillanceTRAFEED

The EU Dual-Use Regulation (Regulation 2021/821) enters a formal Article 26 evaluation window from September 2026 through September 2028.

EU Dual-Use Regulation 2026–2028 Evaluation Explained: Article 26 and What Japanese Companies Should Prepare
Share

Hello, this is Ryuta Hamamoto from TIMEWELL. The EU’s core dual-use export-control law, the Dual-Use Regulation (Regulation 2021/821), will enter a formal evaluation phase from 10 September 2026 to 10 September 2028. The timeline is written into Article 26 of the regulation itself. Depending on findings, the process can lead to a later recast or targeted amendment. People often ask “what changes in 2028?” The short answer: not on that day. Below is the structure, the likely issues, and what Japanese companies can start now, written for practitioners on an export-control desk.

What you will learn

  • Structure of Article 26 and the September 2026–September 2028 schedule
  • Five evaluation domains (effectiveness, divergence, emerging tech, Article 5, transparency)
  • The typical 5–7 year EU cycle from evaluation to recast entry into force
  • Reform directions suggested by the January 2024 White Paper on Export Controls
  • Human-rights NGO criticism of Article 5 cyber-surveillance controls
  • Fragmentation created by national lists in 11 member states
  • Three impacts for Japanese companies and five practical steps

Three terms to know first

Term 1: Article 26 (evaluation clause)

Article 26 of Regulation 2021/821 obliges the Commission to review how the regulation is working and how far its objectives are met. It requires a full evaluation five to seven years after application, with a report to the European Parliament, the Council, and the European Economic and Social Committee (EESC). The legal calendar is already fixed: evaluation starts 10 September 2026; report due by 10 September 2028.

Importantly, this is not only a retrospective review. Article 26(3) contemplates legislative proposals where results warrant them. Evaluation is the starting line for possible reform.

Term 2: 500 series

After the Wassenaar Arrangement stalled under Russian veto, the EU created the 500 series, an EU-autonomous control category for emerging technologies, via Commission Delegated Regulation (EU) 2025/2003 (in force 15 November 2025). It covers quantum computing, advanced semiconductor manufacturing equipment, advanced computing, 3D printing, life-science tools, and more.

In the evaluation, a major question will be whether the EU should hard-code autonomous emerging-tech controls into the main regulation, based on 500-series operating experience. See also EU Dual-Use Regulation 2025 update (2025/2003) overview.

Term 3: White Paper on Export Controls

The Commission’s January 2024 policy paper (COM(2024) 25 final) maps operational issues and reform topics for Regulation 2021/821. Many evaluation themes already appear there: a permanent Political Coordination Forum, stronger notification of national control lists, and better emerging-tech response.

It is a discussion starter for member states, Parliament, and stakeholders, not a final Commission proposal.

Article 26 structure (September 2026–September 2028)

Clause Subject Start Due Output
Related to Article 5(7) Effectiveness of cyber-surveillance catch-all (Art. 5) From 10 Sep 2024 Ongoing Reports to EP / Council / EESC
Article 26 main evaluation Regulation as a whole 10 Sep 2026 10 Sep 2028 Evaluation report
Article 26(2) Annual transparency reporting Annual Annual Public annual reports

The regulation was adopted 20 May 2021 and applied from 9 September 2021. Design intent: full evaluation at year five; report by year seven.

Procedural flow (Better Regulation Guidelines)

  1. Roadmap — scope and methods published
  2. Public consultation — typically ~12 weeks (Japanese companies and associations can submit)
  3. Staff Working Document (SWD) — interim evaluation analysis
  4. Evaluation Report — formal submission to EP and Council
  5. Legislative proposal if needed — recast or targeted amendment

For the predecessor regulation (EC) 428/2009, evaluation began in 2014, a White Paper followed in 2016, and recast completed in 2021. Five to seven years from evaluation start to new rules in force is normal. For a September 2026 start, entry into force of any recast around 2031–2033 is a realistic planning range.

As of May 2026, no formal evaluation Roadmap has been published. Expert commentary (e.g., gamingtechlaw.com, March 2026) expects Q3–Q4 2026 (unconfirmed; reporting/expert views).

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

Download Product CatalogContact About TRAFEED

Five domains under review

Domain 1: Effectiveness

Licensing and enforcement quality, whether penalties are “effective, proportionate and dissuasive,” and information sharing via the Dual-Use Coordination Group (DUCG). Directive 2024/1226 is introducing minimum penalty standards, but member-state practice still varies widely. The same violation can face very different outcomes.

Domain 2: Divergence

Often the most watched theme:

  • 11 member states impose licensing on intra-EU movements of items outside Annex IV
  • A majority extend military end-use controls to non-listed items in national practice
  • Penalty and interpretation gaps create forum shopping risk

Moving a product from member state A to B can be license-free in one and licensed in the other. Japanese groups with multi-country EU footprints feel this as real admin cost.

Domain 3: Emerging-technology response

Operating results of the 500 series (from 15 November 2025) will be central: quantum, advanced semiconductor equipment, advanced computing, 3D printing, life-science tools.

The policy question: if Wassenaar remains impaired, should the EU keep regulating alone, and institutionalize that approach in the main regulation? Expert commentary mostly expects Article-level codification of 500-series mechanisms (medium confidence; multiple sources).

Domain 4: Article 5 (cyber-surveillance)

Article 5 is a catch-all for non-Annex I cyber-surveillance items (facial recognition, location tracking, interception tech, etc.). Licenses are required when the exporter “knows” or “has reason to suspect” misuse risk for human-rights harm.

Review points:

  • Effect of Commission Recommendation (EU) 2024/2659 (October 2024 Article 5 guidelines)
  • SIPRI and others note very few Article 5 triggers in practice
  • Amnesty International, Human Rights Watch, and other NGOs argue effectiveness is insufficient

Human Rights Watch’s 12 May 2026 report argued that EU member states still sell surveillance tech to rights-abusing destinations and that transparency duties are reinterpreted in ways that undercut the regulation’s intent. Evaluation may push clearer trigger criteria and stronger human-rights due diligence (medium confidence).

Domain 5: Transparency (Article 26(2))

Article 26(2) requires annual transparency reporting on licenses and destinations. HRW’s May 2026 critique says report granularity is weak and member-state-level data is often undisclosed.

Evaluation may push finer reporting (including customer/end-use data). Industry will push back on trade secrets and admin burden—expect difficult trade-offs.

Past evaluation cycles (5–7 years is normal)

Article 26 fixes the evaluation report deadline, not the date of new law. Past timing:

Phase Old Reg. 428/2009 Outlook for Reg. 2021/821
Evaluation start 2014 September 2026
White Paper etc. 2016 January 2024 (already published)
Legislative proposal September 2016 2027–2028 (estimate)
Adoption May 2021 2030–2031 (estimate)
Entry into force September 2021 2031–2033 (estimate)

Current rules do not automatically change during 2026–2028 evaluation. Separately, Annex I annual updates via Delegated Regulation continue—so 500-series-style additions can keep coming during the evaluation window.

White Paper (Jan 2024) reform directions

COM(2024) 25 final organizes reform ideas in layers. It is a discussion paper, not the Commission’s final position. Combining it with expert commentary:

Higher confidence (multiple sources)

  • Institutionalizing the 500 series — autonomous emerging-tech controls at main-regulation level even without Wassenaar
  • Permanent Political Coordination Forum among member states
  • Stronger national control-list notification — elevating the April 2025 Council/Commission Recommendation toward legal duty

Medium confidence

  • Stronger cyber-surveillance controls — clearer Article 5 triggers; mandatory HRDD
  • Minimum penalty standards to reduce divergence
  • Reintroducing circumvention prohibition dropped from the 2016 draft

Lower confidence / watch list

  • Integrating AI Act (Reg. 2024/1689) with export control
  • Integrating outbound investment screening (currently separate)
  • Technology transfer via cloud/SaaS

Again: these are expert/media projections, not official Commission conclusions. Update after the Roadmap (expected Q3–Q4 2026).

Article 5 criticism and open issues

SIPRI

SIPRI’s 2024 commentary: Article 5 is powerful on paper but member-state interpretation is cautious, so triggers are rare. The “know or suspect” bar is high, and authorities do not always push.

Human-rights NGOs

Amnesty and HRW track EU-origin facial recognition and location-tracking exports to authoritarian destinations and criticize “operation that undercuts intent.” The 12 May 2026 HRW report claimed de facto non-application in several member states.

Evaluation issues

  • Objectify and codify “know or suspect”
  • Introduce enforceable human-rights due diligence (OECD Guidelines / UNGPs)
  • Clarify item scope (currently broad catch-all)

If your EU subsidiaries deal in cyber-surveillance-adjacent items, document Article 5 applicability criteria internally now. Waiting for the evaluation report is too late for process design.

Fragmentation: national lists in 11 member states

Group Examples Stance
Hardliners Netherlands, Germany, France Tighter controls; U.S. coordination
Cautious Some Southern/Eastern members Industrial competitiveness; caution on going beyond Wassenaar
Neutral broker EP INTA Committee Transparency + human rights

The Netherlands coordinates with the U.S. on advanced ASML-related controls; Germany’s BAFA engaged heavily on Article 5 guidance; France leads outbound-investment screening debates. Harmonization will take time.

Three impacts on Japanese companies

Impact 1: 500-series expansion and triangular trade

Risk: Japan HQ → EU subsidiary → third country trades may newly need licenses as 500 series expands without waiting for Wassenaar.

Actions:

  • Annual classification refresh
  • Continuous monitoring of re-export license need from EU entities
  • Yearly refresh of item masters for quantum, SME, advanced computing, AM, bio

Impact 2: ICP becoming a de facto—and possibly legal—obligation

Risk: Global Export Authorisations (EU009, EU010, etc.) already effectively assume an Internal Compliance Programme. Evaluation may push ICP from de facto to legal duty.

Actions:

  • Audit ICP status; start gaps in 2026 if missing
  • Align with METI CP (internal compliance programme) practice
  • Map eight ICP elements (commitment, organization, classification, screening, training, audit, records, violation handling) to Commission guidance

Impact 3: Documenting Article 5 criteria

Risk: Objectified triggers can recharacterize past “we did not know/suspect” cases.

Actions:

  • Inventory facial recognition, location tracking, interception-related offerings
  • Manualize destination human-rights risk assessment
  • Reflect OECD Guidelines / UNGPs in ICP
Topic Risk Recommended action
500-series expansion New triangular-trade controls Annual classification cycle
Stronger cyber-surveillance Objectified Art. 5 triggers Internal applicability manuals
ICP de facto obligation Loss of Global Authorisation use ICP review; METI CP alignment
Finer transparency reporting Customer/end-use data demands Record retention and granularity
Harmonization Strictest member practice becomes common floor Watch DE/NL/FR practice

Five practical steps now

Step 1: Share the regulation and White Paper internally

Export control, legal, and leadership should share Articles 5 and 26 plus the January 2024 White Paper so priorities do not stall on misaligned assumptions.

Step 2: Reclassify against Annex I including 500 series

Use the 2025/2003 Annex I replacement. Document technical reasoning for audits and authority queries.

Step 3: ICP health check

Map against member-state ICP guidance (CDIU, BAFA, DGE, etc.) and the eight standard elements.

Step 4: Self-assess Article 5 exposure

Use BAFA’s Article 5 leaflet and similar materials to decide process, then write it into manuals.

Step 5: Prepare for Public Consultation

Build a flow for information gathering → draft → management approval so you can respond within a ~12-week consultation window (via Keidanren, JEITA, JMA, or as a company).

FAQ

Q1. Will the regulation be amended on 10 September 2028?

No. That date is the evaluation report deadline. Past cycles take 5–7 years from evaluation start to new rules in force. Treat September 2028 as report publication timing, not new-law day.

Q2. Can Japanese HQ engage in the evaluation process?

Yes. Public Consultation under Better Regulation Guidelines is open to Japanese companies and associations. English submissions are standard.

Q3. Do current rules freeze during evaluation?

No. Annex I Delegated Regulation updates continue annually. 500-series-style additions can arrive during 2026–2028.

Q4. What if Article 5 is strengthened?

Triggers may move from exporter knowledge/suspicion toward mandatory human-rights due diligence. Firms exporting surveillance-adjacent items should embed HR risk assessment now.

Q5. Relationship with U.S. EAR?

Coordination with EAR will be a theme—especially semiconductor equipment (Netherlands/ASML alignment) and AI chips. See EAR + China extraterritorial rules + EU 2025/2003 simultaneous impact.

Q6. Biggest risks for Japanese companies?

  1. ICP gaps blocking Global Authorisations — every deal becomes individual licensing
  2. Missed 500-series classifications after annual Annex I updates
  3. Overlooked triangular re-export via EU subsidiaries

Do not wait for evaluation results to strengthen internal systems. If I had to start one workstream in 2026, it would be ICP gap-closing before any Global Authorisation dependency bites.

Q7. When is the evaluation Roadmap published?

No formal announcement as of May 2026. Expert views point to Q3–Q4 2026 (unconfirmed). Share promptly once published.

Latest developments as of July 2026

While EU evaluation may take years to become new law, Japan’s economic-security framework is already moving. At the 16th Japan–India annual summit on 2 July 2026, the two sides issued a joint declaration on economic-security cooperation covering semiconductors, critical minerals (rare earths), clean energy, ICT (submarine cables), and pharmaceuticals, with roughly ¥2 trillion of investment indicated (Japan–India summit joint press conference (Prime Minister’s Office, July 2026)). EU 500-series autonomous controls on advanced semiconductors and emerging tech and Japan’s supply-chain diversification push point in related directions. EU sites of Japanese companies should track bilateral supply-chain redesign alongside EU rulemaking (Japan–India summit and economic security).

If you want to improve export-control operations or classification efficiency, review the TRAFEED service catalog (PDF) or contact us.

Summary

  • Regulation 2021/821 enters an Article 26 evaluation window from 10 September 2026 to 10 September 2028
  • Historical pattern: new rules in force around 2031–2033 (about 5–7 years from evaluation start)
  • Five domains: effectiveness, divergence, emerging tech, Article 5, transparency
  • White Paper (Jan 2024) points to 500-series institutionalization, a permanent Political Coordination Forum, and stronger national-list notification (not official final positions)
  • Article 5 is criticized for few real-world triggers; objectifying criteria is a live issue
  • Fragmentation from national lists in 11 member states will take time to harmonize
  • Japanese companies should start ICP build-out, triangular-trade control, and Article 5 documentation without waiting

My practical stance: treat 2026–2028 as a monitoring window, not a freeze. Annex I will keep moving. Build the ICP and reclassification muscle while Brussels debates the recast.

Related articles

  • EU Dual-Use Regulation 2025 update (2025/2003) overview
  • EU export regulation 2026
  • EAR + China extraterritorial rules + EU 2025/2003 simultaneous impact
  • Wassenaar Arrangement dysfunction and national responses
  • List controls vs catch-all controls, practical guide

If you are unsure whether you can handle this in-house

2026–2028 will run new controls (Annex I updates, 500-series expansion) in parallel with debate on main-regulation reform (Article 5, harmonization, ICP duties). Information volume rises, but recast timing is multi-year. Priority now: continuous monitoring and ICP baseline uplift.

TRAFEED (formerly ZEROCK ExCHECK) cross-searches EU, U.S., Chinese, and Japanese controls and uses a knowledge graph of 200+ million nodes (papers, patents, researchers, entities, lists) to surface classification and counterparty checks in seconds. AI agents absorb ongoing load from Annex I updates, 500-series additions, and Article 5 exposure signals—on AWS Tokyo Region infrastructure.

▶ Explore TRAFEED ▶ Book a 30-minute consultation

References

  • EUR-Lex: Regulation (EU) 2021/821
  • EUR-Lex: Consolidated version (2025-11-15)
  • White Paper on Export Controls (COM(2024) 25 final)
  • Commission Recommendation (EU) 2024/2659 (Article 5 guidelines)
  • DG Trade dual-use page
  • BAFA Article 5 leaflet
  • EPRS Briefing "Dual-use export controls as tools of EU economic security" (2025)
  • European Parliament Legislative Train (Review of dual-use export controls)
  • SIPRI "Making the most of the EU catch-all control on cyber-surveillance exports" (2024)
  • Human Rights Watch "European Union: Surveillance Technology Sold to Rights Violators" (2026-05-12)
  • TEPSA "Assessing the role of human rights in the Recast EU Regulation on dual-use items"
  • gamingtechlaw.com "EU Dual-Use Technologies Regulation" (2026-03)
  • AmCham EU "Position White Paper on Export Controls"

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Contact About TRAFEED
Contact About TRAFEEDContact form (about 3 min)TRAFEED product briefFeatures & rollout in PDF

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Free download

Recommended materials

Economic Security Management Guidelines (1st Edition): 44-Item Self-Check Worksheet (2026)

A fill-in worksheet built from the appendix checklist of the Economic Security Management Guidelines (1st Edition), published by METI's Trade and Economic Security Bureau on 23 January 2026. All 44 items are transcribed from the original text and laid out in its three-column form: check item, Y/N, and the structures (organisation, internal rules) and track record behind your answer. The breakdown follows the original: 5 items on principles executives should keep in mind, 13 on securing autonomy, 13 on securing indispensability, and 13 on strengthening governance, with the 8 items the original phrases as "it is also useful to" badged separately. Opens with a plain-language primer on what economic security, autonomy, indispensability, governance and duty of care actually mean. Includes METI-published survey data showing that 70.7% of 3,007 manufacturers had heard the term but had no concrete image of it, and that the share expecting lost revenue to outweigh the cost of action rises from 22.3% over one to three years to 31.9% over four to ten. As METI states explicitly, the guidelines are not an obligation imposed on companies and are not premised on transactions with any specific country, company, or person. This worksheet was produced by TIMEWELL and was not prepared or endorsed by METI. Final decisions should rest with your legal and compliance leadership and the latest publications of the relevant authorities.

Event Organiser's Migration & Data-Rescue Checklist (fill-in, 2026)

A fill-in worksheet for event organisers whose ticketing service has shut down. PassMarket closed on June 30, 2026, and its ticket management tool is announced as available until August 31, 2026 (planned). The sheet covers what to rescue before that deadline (attendee records, survey responses, revenue and payout records, event page copy, ticket configuration), an inventory of the channels through which you can still reach attendees, a formula and worksheet for calculating the effective cost of a new platform yourself, and the steps to launch a first event on it. Anything the official announcement does not state — when in-service messaging stops, the export specification for attendee lists and survey data, the timing of payouts — is marked "to be confirmed" rather than asserted. It does not rank providers; it supplies the formula and the checklist.

China-Related Transactions Export-Control Screening Sheet (fill-in / Export Control Law & Dual-Use Regulations, critical minerals, Control List, 2026)

A fill-in working sheet for companies trading with China: screen a single transaction against China's export-control regime (the Export Control Law and the Dual-Use Items Export Control Regulations), the controls on critical minerals (gallium/germanium/graphite/antimony/tungsten etc./rare earths/helium), and the four counterparty-list systems (Control List, Watch List, Unreliable Entity List, countermeasure lists). A procedure for "what to check before the deal," not a roster of "who is listed." With a plain-language intro, based on MOFCOM announcements. Listing is a regulatory category, not a judgment about any company (including the Japanese firms on the Japan-directed lists); controls change continually, so verify current announcements and consult your officer. Match counterparties using the original simplified-Chinese wording.

See all materials

Related Knowledge Base

Export Control Guide

Solutions

Strengthen Export ComplianceStreamline compliance with complex export regulations

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Contact UsDownload Catalog

Related Articles

Complete Guide: EU Dual-Use Regulation 2025 Amendment (2025/2003) — New 500 Series and What Japan’s EU Subsidiaries Must Check

Complete Guide: EU Dual-Use Regulation 2025 Amendment (2025/2003) — New 500 Series and What Japan’s EU Subsidiaries Must Check

A beginner-friendly guide to the EU Dual-Use Regulation amendment that took effect November 15, 2025 (Delegated Regulation 2025/2003).

2026-05-20
EU 500-Series Controls Explained: Quantum, Semiconductor Equipment, and Advanced Computing

EU 500-Series Controls Explained: Quantum, Semiconductor Equipment, and Advanced Computing

A practical guide to the EU Dual-Use Regulation update (Delegated Regulation 2025/2003) that created the 500 series on 15 November 2025.

2026-05-20
Complete Guide: Fundamentals of EU Dual-Use Regulation 2021/821 — Annex I 10 Categories, GEAs, and Three Catch-All Articles

Complete Guide: Fundamentals of EU Dual-Use Regulation 2021/821 — Annex I 10 Categories, GEAs, and Three Catch-All Articles

Complete Guide: Fundamentals of EU Dual-Use Regulation 2021/821 — Annex I 10 Categories, GEAs, and Three Catch-All Articles.

2026-05-20
Complete Guide: EU-Autonomous Export Controls Under Wassenaar Stalemate — White Paper 2024 and a Three-Stage Path to the 500 Series

Complete Guide: EU-Autonomous Export Controls Under Wassenaar Stalemate — White Paper 2024 and a Three-Stage Path to the 500 Series

Complete Guide: EU-Autonomous Export Controls Under Wassenaar Stalemate — White Paper 2024 and a Three-Stage Path to the 500 Series.

2026-05-20
Washington Pushes Back on Apple Buying Chinese Memory: Section 5949 and the Supplier Fallout

Washington Pushes Back on Apple Buying Chinese Memory: Section 5949 and the Supplier Fallout

In August 2026, Commerce Secretary Lutnick said the administration opposes Apple sourcing Chinese memory. Here are the Senate and House letters, where CXMT and YMTC actually sit in US regulation, and what Section 5949 and the pending FAR rule mean for component suppliers in Japan and elsewhere.

2026-08-15
What Japan's Foreign Interference Prevention Act and Foreign Intelligence Collection Act Would Change

What Japan's Foreign Interference Prevention Act and Foreign Intelligence Collection Act Would Change

On August 5, 2026, the LDP's Intelligence Strategy Headquarters released its second set of recommendations on strengthening Japan's "information defense capability." Here is what the three pillars of deterrence, collection, and oversight actually contain, read against the statutory text.

2026-08-15