International Legal Highlights | Winter 2025 | McDermott

REPORT

International Legal Highlights | Winter 2025

Winter, 2025

Read time: 2 min

Überblick

xxx

MCDERMOTT JAPAN PRACTICE: LAWYERS’ HIGHLIGHT WITH SIMON ROBERTS AND JASON LEONARD

By Simon Roberts, Jason Leonard

BACKGROUND 

Simon Roberts and Jason Leonard are nationally recognized patent litigation trial lawyers who have more than 50 years of combined experience and serve as lead counsel in dozens of cases in which they represent brand pharmaceutical companies. While they are based in McDermott’s New York office, their practices are national so they appear in federal courts across the United Sates and assist clients with enforcing patents to ensure consistent and effective cross-border litigation strategies. Over the course of their careers, they have represented several innovators from the pharmaceutical industry, including some of the largest Japanese companies in the sector. Simon and Jason particularly enjoy representing Japanese companies and have substantial experience guiding their Japanese clients through complex litigation and formulating strategies to maximize the chances of successful outcomes.

Over the past year, Simon and Jason represented a major Japanese pharmaceutical company as lead trial counsel in several high-profile patent litigations that included bench trials, Markman hearings, preliminary injunction proceedings, and appeals and are scheduled to argue jury trials worth billions of dollars throughout the upcoming year. Given their proven track record, they are undoubtedly considered one of the best trial teams in the US.

INSIGHTS AND ADVICE

  1.  What are the common legal issues Japanese companies face when operating internationally, and how do you assist them in navigating these challenges?

Patent defenses built on Section 112 of the Patent Act, including lack of written description and lack of enablement, are becoming more prevalent because of recent Supreme Court of the United States jurisprudence. Since context is so important to ensure accurate Japanese to English translations, many US patents that are based on Japanese language priority documents may have susceptibilities that otherwise may not exist. Thanks to our deep experience handling litigations for Japanese-based companies, we’re able to provide valuable foresight and strategies that can be used to minimize the potential for such defenses.

2. What current trends or changes in the global intellectual property landscape should Japanese companies be aware of?

Given the competitive nature of the generic drug industry and harsher economic environment, we have seen more companies willing to launch their generic products at-risk, which was a rarity not that long ago. It is now more important than ever to have litigation strategies ready well before litigation is contemplated to ensure successful patent enforcement before generic US Food and Drug Administration approval can be obtained or to mitigate such risks by demonstrating that it would be too risky for companies to launch their generic products even absent a preliminary injunction.

ON A PERSONAL NOTE

3. Can you share a personal anecdote or experience that highlights your connection to Japan or Japanese culture?

Simon: When my first child was born, she was a terrible sleeper and often stayed awake throughout the night. My wife and I travelled with our then nine-week-old to Japan for a vacation. That first night, our daughter slept through the night for the first time and has slept well ever since! She is now 16 years old and remains a very good sleeper thanks to Japan.

マクダーモット日本プラクティス -Lawyers’ Highlight with Simon Roberts and Jason Leonard (サイモン・ロバーツ/ジェイソン・レオナード)

By Simon Roberts, Jason Leonard

経歴と専門(BACKGROUND)

サイモン・ロバーツとジェイソン・レオナードは、米国で特許訴訟の弁護士として知られており、合わせて50年以上の経験を有し、名立たる製薬会社の代理人として多数の訴訟で主任代理人を務めています。McDermottのニューヨークオフィスを拠点としていますが、業務は全米を対象としているため、米国中の連邦裁判所に出廷し、クライアントの特許権行使を支援し、一貫性のある効果的な国際訴訟戦略を確保しています。また、日本の大手製薬会社を含む、世界中の名立たる製薬会社の代理人を務めています。サイモンとジェイソンは、特に日本企業を代理することを好み、複雑な訴訟において日本企業を導き、勝訴の可能性を最大限に高める戦略を策定する豊富な経験を有しています。

過去1年間に、サイモンとジェイソンは、複数の注目度の高い特許訴訟において主任代理人として日本の大手製薬会社を代理しました。これらの訴訟には、裁判官による審理、クレーム解釈、仮処分手続、上訴手続が含まれ、今後1年間では、数十億ドル規模の陪審裁判において弁論を行う予定です。これらの実績を踏まえると、彼らは米国で最も優れた訴訟チームの一つであるといえます。

見識と助言(INSIGHTS AND ADVICE)

1. 日本企業がグローバルに事業を展開する際に直面する典型的な法律問題として、どのようなものがあるでしょうか?また、それらの問題に対処するにあたり、どのようなサポートを提供しているのでしょうか?

米国特許法第112条に基づく明細書の欠如や実施可能要件の欠缺などの抗弁は、近年の米国最高裁の判例法により、より一般的になってきています。日本語を正確に英語に翻訳するためには文脈を捉えることが極めて重要ですが、日本語の優先権書類に基づく多くの米国特許には、日本語で記載されていなければ存在しなかったであろう漸弱性を含んでいる可能性があります。日本企業を代理した訴訟対応の豊富な経験により、このような防御の可能性を最小限に抑えるために役立つ予測と戦略を提供することができます。

2. グローバルな知的財産権に関して日本企業が注意すべき動向や変化として、どのようなものがあるでしょうか?

従来はほとんど事例がありませんでしたが、ジェネリック医薬品業界における競争の激化や経済環境の厳しさから、リスクを覚悟でジェネリック医薬品を発売する企業が増えています。ジェネリック医薬品が米国食品医薬品局(FDA)の承認を受ける前に特許権を確実に行使できるようにするため、あるいは、仮差止命令が下されなかったとしてもジェネリック医薬品を発売するのは企業にとってあまりにもリスクが大きいこと理解した上で、そのようなリスクを低減するために、訴訟が想定される前から訴訟戦略を練っておくことが、これまでになく重要になっています。

ON A PERSONAL NOTE

3. 日本や日本文化に関する個人的な思い出や経験を教えてください。

サイモン:長女が生まれたとき、彼女はなかなか寝付かず、夜通し起きていることがよくありました。妻と私は、生後9週間の娘を連れて休暇で日本を訪れました。日本での最初の夜、娘は初めて夜通し眠り、それ以来ずっとよく眠るようになりました。娘は16歳になりましたが、日本のおかげで今でもよく眠ります。

THE IMPACT OF THE NEW EU AI ACT ON THE MEDTECH AND LIFE SCIENCES SECTOR

By Sharon Lamb

As technology continues to advance almost every aspect of healthcare, so the use of AI has become an increasing focus for developers and the regulators who are racing to keep pace with rapid advancements in technology.

Software (including AI) with a medical purpose is already regulated in Europe and the United Kingdom as a medical device and requires comprehensive assessment before it can be placed on the market under EU Medical Device Regulations 2017 (MDR) and the EU In Vitro Diagnostic Medical Devices Regulation (IVDR).

Despite the existing comprehensive regulatory requirements, there has been concern that the current framework does not fully address the ethical and transparency risks associated with AI. The European parliament is leading the way with the Act, which applies to all sectors but will have significant implications in the life sciences sector, particularly for AI medical device manufacturers. Click here for our general overview of the Act.

Like the General Data Protection Regulation, the Act has global reach; it will apply to providers wherever they are in the world if they place, or put into service, an AI system in the European Union. The Act is also only one piece in the puzzle of new AI-related legislation and will need to be read in the context of changes proposed on product liability and AI liability.
Defining an AI System

Over the last few years, it has become popular to describe technologies as artificial intelligence, even where the software may be a fixed or locked algorithm with no adaptiveness.

It will now be important for manufacturers to determine whether their software are truly AI systems with the scope of the Act, which defines an AI system as

“A machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.”

The key term here, “infer” is not precise, but the recitals to the Act give helpful context about how it should be interpreted, stating that AI does not include systems based on rules defined solely by natural persons to automatically execute operations. In other words, the Act does not appear to apply to software comprised of rules-based fixed algorithms. Systems that go beyond basic data processing and enable learning, reasoning, or modelling are, however, likely to be caught.

The line here may not always be clear cut, and it appears that the Act will not apply to many current “AI” solutions, which operate using fixed diagnostic algorithms rather than independent or self-learning capabilities, although stabilised systems with incremental learning may be caught.

HIGH RISK AI SYSTEMS

Under the Act, any AI system that is a Class IIa (or higher) medical device, or uses an AI system as a safety component, is designated as “high risk”.

The Act also specifies certain types of healthcare AI systems as high risk, whether or not they are medical devices, such as AI systems used by public authorities to evaluate the eligibility of people for essential public services, and AI systems that are emergency healthcare patient triage systems.

WHAT AI MEDICAL DEVICE PROVIDERS NEED TO KNOW

Under the AI Act, high-risk AI systems will need to comply with a raft of additional requirements, many of which overlap with the current rigorous requirements of conformity assessment under the MDR and IVDR.

These entirely new requirements include a conformity assessment by a notified body that the AI system meets the requirements under the AI Act, including with respect to the technical documentation and risk management system. During the development of the legislation, there was concern that this “double certification” would lead to significant delay of market entry and double running cost for device manufacturers. The legislators have accommodated these concerns, in part. For medical devices, the Act states that the conformity assessment procedure in the MDR and IVDR must be followed, and that the requirements of the Act will be part of that assessment.

The Act also allows medical device notified bodies to carry out AI conformity assessments, provided that their AI competence has been assessed under the MDR and IVDR. In other words, a single declaration of conformity is proposed, although the precise mechanics for this remain unclear.

Given the well-publicised lack of notified body capacity in the run-up to the implementation of the MDR and IVDR, medical device manufacturers will naturally be concerned to ensure that their existing notified body has been assessed as competent to conformity assess AI systems. If two notified bodies are required, that may risk divergent views on how the same or similar requirements are to be met.

Many of the requirements in the Act also replicate existing requirements in the EU MDR and EU IVDR. For example, the requirements to have a quality management system, technical documentation, and instructions for use.

The AI Act contemplates a single set of technical documentation to include all the requirements, both under the EU MDR and the EU AI Act. However, medical device manufacturers that have already certified their devices under the EU MDR, may need to amend their technical documentation to reflect the additional requirements of the EU AI Act.

Additional requirements for AI systems that are not already in the EU MDR and the EU IVDR, include

  • Governance and data management requirements for training and testing data sets
  • New record-keeping requirements, including the automatic recording of events (logs) over the system’s lifetime
  • Transparent design requirements so deployers can interpret the output and use it appropriately
  • Human oversight design requirements
  • Accuracy and cybersecurity requirements.

Where medical device manufacturers are providers or deployers of general-purpose AI models or systems, they will also need to comply with these requirements.

Although legislators have made efforts to attempt to streamline overlap between regulatory frameworks, many questions remain. For example, it is not clear how the substantial modification framework under the AI Act will interact with the MDR and IVDR modification rules. Likewise, it is not clear whether devices undergoing a trial (performance evaluation or clinical investigation) will need to be AI Act certified prior to use in the trial.

The Act proposes harmonised standards, but it is not currently clear whether these will overlap or differ from current harmonised standards, such as ISO 13485.

The industry will be keen to see the guidance on these points, and to understand whether the costs and time of a second certification present a barrier to market entry of the most innovative products.

THE IMPACT ON DEPLOYERS OF HIGH RISK SYSTEMS

Unlike the MDR and IVDR, which place responsibilities on economic operators in the supply chain, the AI Act also puts responsibilities onto the deployers of AI systems, being any person using an AI system in the course of a business or professional activity, such as hospitals or clinicians. These deployers will have new obligations, including

  • Taking appropriate technical and organisational measures to ensure that AI systems are used in accordance with their instructions for use
  • Assigning human oversight to competent, trained people
  • Monitoring and surveillance
  • Maintaining system logs when these are under their control
  • Undertaking, where applicable, data protection impact assessments.

Impact on the Use of AI Systems in the Wider Life Sciences Sector

There is increasing use of AI systems across the medicine product lifecycle, from drug discovery through to post market vigilance activities. You can read more about the impact on the wider life sciences sector in our longer On The Subject.

IMPLEMENTATION TIMELINE

The AI Act is likely to enter into force later this year, with a phased implementation period, followed by a phased transition period, before becoming enforceable. Obligations for high-risk AI systems already covered by other EU regulation, such as medical devices, will only come into force 36 months after the Act enters into force.

Whilst this is a relatively generous period, it is worth bearing in mind that the MDR and IVDR had longer implementation periods, and in both cases, these have now been extended.

新しいEU AI法が医療テクノロジー及びライフサイエンス業界にもたらす影響について

By Sharon Lamb

テクノロジーの進化により、ヘルスケア産業のほぼすべての側面が変化し続けるなか、AIの利用は、急速な技術進歩に追いつこうと努力する開発者や規制当局にとって、ますます注目される問題となっています。

医療目的のソフトウェア(AIを含む)は、EUと英国ではすでに医療機器として規制されており、EU医療機器規則2017(MDR)及びEU体外診断用医療機器規則(IVDR)に基づき、上市前に包括的な評価が必要とされています。

包括的な規制がすでに存在しているにもかかわらず、現行の枠組みではAIに関連する倫理的リスクや透明性リスクに十分に対処できていないことが懸念されてきました。欧州議会は、新しいAI法によってこの問題を主導しています。この法律は、すべてのセクターに適用されますが、生命科学業界、特にAIを活用した医療機器のメーカーにとって重要な意味を持つことになります。同法の概要はこちらをご覧ください。

一般データ保護規則(GDPR)と同様に、この法律は世界中の事業者に適用されうるものです。AI法は、EU域内にAIシステムを配置又は稼働させる場合、そのプロバイダーが世界中のどこに所在していても、適用されます。この法律はまた、新たなAI関連の新しい法律のパズルの1ピースに過ぎません。したがって、製造物責任やAI責任に関する変更の提案との関連性も考慮する必要があります。

AIシステムの定義について

ここ数年、適応性のない固定されたアルゴリズムやロックされたアルゴリズムであっても、技術を人工知能と表現することが一般的になってきました。

製造業者にとって、自社のソフトウェアが法律で定義されているAIシステムに該当するかどうかを判断することが今後重要になります。AIシステムは、

さまざまなレベルの自律性を備え、導入後に適応性を示す可能性があり、明示的又は暗黙的な目的のために、受け取った入力から予測、コンテンツ、推奨、又は物理的若しくは仮想環境に影響を与える意思決定などの出力を生成する方法を推論する機械ベースのシステムである。」と定義されています。

ここで重要な用語である「推論」は正確ではありませんが、同法の前文には、AIが自然人によってのみ定義されたルールに基づくシステムで、自動的に操作を実行するものは含まれないと述べられており、解釈の参考となる文脈が示されています。言い換えれば、この法律は、一定のルールに基づく固定アルゴリズムで構成されるソフトウェアには適用されないようです。しかし、基本的なデータ処理にとどまらず、学習、推論、モデリングを可能にするシステムは対象となる可能性が高いでしょう。

この線引きは常に明確であるとは限らず、独立した機能や自己学習機能ではなく、固定された診断アルゴリズムを使用して動作する現在の「AI」ソリューションの多くにはこの法律は適用されないように思われます。一方で、漸進的な学習を伴う安定的なシステムには、同法が適用される可能性があります。

高リスクAIシステム

同法の下では、クラスⅡa(若しくはそれ以上)の医療機器に用いられるAIシステム、又は安全装置としてAIシステムを使用するAIシステムは、「高リスク」に指定されます。

同法はまた、医療機器であるか否かにかかわらず、特定の種類のヘルスケアAIシステムを高リスクAIシステムとして指定しています。例えば、公的機関が重要な公共サービスを受ける人々の適格性を評価するために使用するAIシステムや、緊急時の医療患者トリアージシステムであるAIシステムなど、特定の種類のヘルスケアAIシステムを高リスクAIシステムに指定しています。

AI医療機器プロバイダーが知っておくべきこと

AI法では、高リスクAIシステムは多くの追加要件に準拠する必要があり、それらの要件の多くはMDR及びIVDRに基づく、現行の厳格な適合性評価要件と重複しています。

これらの全く新しい要求事項には、技術文書やリスク管理システムを含め、AIシステムがAI法に基づく要求事項を満たしているかどうかのノーティファイドボディ(notified body) による適合性評価が含まれます。法制化の過程では、この「二重認証」が市場参入の大幅な遅れや機器メーカーの二重のランニングコストにつながるという懸念がありました。立法者は、こうした懸念に一部対応しました。医療機器については、MDR及びIVDRの適合性評価手順に従わなければならず、この法律の要件は適合性評価の一部となることが規定されています。

また、MDRとIVDRに基づいてAIの能力が評価されることを条件に、医療機器ノーティファイドボディがAIの適合性評価を実施することが認められています。言い換えれば、単一の適合性評価が提案されていますが、その具体的な仕組みは依然として不明確です。

MDRとIVDRの施行を目前にして、ノーティファイドボディの能力不足が広く報じられていることを踏まえると、医療機器メーカーは当然、既存のノーティファイドボディがAIシステムの適合性評価を行う能力があると評価されているかどうかを懸念することでしょう。ノーティファイドボディが2つ必要とされる場合、同じ又は類似の要件を満たす方法について、見解が分かれるリスクがあるかもしれません。

また、AI法の要件の多くは、MDR及びIVDRの既存の要件を踏襲したものです。例えば、品質管理システム、技術文書、取扱説明書などの要件です。

AI法は、MDRとAI法の両方に基づくすべての要件を含む、単一の技術文書一式を想定しています。しかし、すでにMDRの下で認証を受けている医療機器メーカーは、AI法の追加要件を反映させるために技術文書を修正する必要があるかもしれません。

MDR及びIVDRにはまだ記載されていないAIシステムに対する追加要件は以下の通りです。

  • トレーニング及びテスト用データセットのガバナンス及びデータ管理要件
  • システムのライフタイムにわたるイベント(ログ)の自動記録を含む、新たな記録保持要件
  • AIの実装者が、アウトプットを解釈し、それを適切に使用できるようにするための透明性設計要件
  • 人間による監視設計要件
  • 正確性とサイバーセキュリティの要件

医療機器メーカーが、汎用AIモデルやシステムの提供者又は実装者である場合には、上記の要件にも準拠する必要があります。

立法者は規制の枠組み間の重複を合理化しようと努力していますが、多くの疑問が残っています。例えば、AI法に基づく実質的な変更の枠組みが、MDR及びIVDRの修正規則とどのように相互作用するかは明らかではありません。同様に、試験(性能評価又は臨床試験)を受ける機器が、当該試験内で使用する前にAI法の認証を受ける必要があるかどうかも明らかではありません。

AI法では整合規格の採用が提案されていますが、それらがISO 13485のような現行の整合規格と重複するのか、それとも異なるのかは現在のところ明らかではありません。業界では、これらの点に関するガイダンスを待ち望んでおり、2度目の認証にかかる費用と時間が、最も革新的な製品の市場参入の障壁となるかどうかを理解したいと考えています。

高リスクAIシステムの実装者への影響

サプライチェーンから恩恵を受ける事業者に責任を課すMDRやIVDRとは異なり、AI法は、病院や臨床医など、事業または専門的活動の一環としてAIシステムを使用するあらゆる人々であるAIシステムの展開者にも責任を課しています。これらの展開者は、以下を含む新たな義務を負うことになります。

  • AIシステムが取扱説明書に従って使用されることを保証するために、適切な技術的及び組織的措置を講じること
  • 訓練を受けた能力を有する担当者に監視させること
  • 監視と調査
  • システムログが管理下にある場合は、これを維持すること
  • 該当する場合は、データ保護影響評価を実施すること

ライフサイエンス分野におけるAIシステム利用への影響

創薬から臨床試験の被験者募集、上市後の調査活動に至るまで、医薬品のライフサイクル全体でAIシステム及びAIモデルの活用と開発が増加しています。これらのAIシステムの多くは、医療目的で使用されるものではない、もしくはAI法の下で高リスクとして指定されていないため、医療機器には該当しない可能性が高いとされています。同法は、これらのシステムの提供者に対して、従業員等に十分なAIリテラシー(研修を含む)を確保することや、一定の透明性に関する要件など、比較的軽い義務しか課していません。

また、純粋に科学的な目的のAIアプリケーションの多くも、AI法の適用除外の対象となる可能性があります。欧州議会は、AI法の意図がイノベーションの支援にあることを示唆しており、同法は、科学的研究開発のみを唯一の目的として開発され、実用化されたAIシステム(そのアウトプットを含む)を適用除外としています。

この適用除外は、研究の初期段階にあるライフサイエンス企業にとって有用かもしれませんが、「科学的研究」という用語がどのように解釈されるのか、またこの適用除外が、商業研究ではなく学術研究にのみ適用されるのかどうかはまだ明らかではありません。

ライフサイエンス企業は、AI法の緩やかなアプローチを歓迎するかもしれませんが、医薬品開発で使用されるAIシステムに関する議論はこれで終わりというわけではありません。

2023年12月、EMAはAIに関する戦略の主要な作業の流れを定めた5年間の作業計画を発表しました。この作業計画は、2023年に発表された、医薬品のライフサイクルにおけるAIの利用についてのリフレクション・ペーパーの草案に基づいています。このリフレクション・ペーパーの草案では、医薬品の開発をサポートするために使用されるAIが、GxP(Good Practice)や欧州医薬品庁の科学的ガイドラインなどの既存の要件に適合していることを保証する責任は、市場販売承認者及び申請者が負うことが強調されています。また、このリフレクション・ペーパーでは、製品ライフサイクルにおけるAIの様々な使用例を概説し、様々な段階で使用されるAIのリスクを示しています。

作業計画によれば、AIについてのさらなるガイダンスとリフレクション・ペーパーは2024年と2025年に発表される予定です。

施行スケジュール

AI法は今年後半に発効される見込みで、段階的な実施準備期間と移行期間を経た後に執行可能となります。医療機器など、すでに他のEU規制でカバーされている高リスクのAIシステムに対する義務は、AI法の発効から36ヵ月後に初めて発効します。

これは比較的余裕のある期間設定ではありますが、MDRやIVDRではより長い実施準備期間が設けられており、いずれも現在では当該期間が延長されていることを念頭に置く価値があります。

QUARTERLY SANCTIONS UPDATE | Q2 2024

By Sabine Naugès, Raminta Dereskeviciute, Michal Chajdukowski

On June 24, 2024, the European Union adopted its 14th sanctions package (implemented by EU Regulations 2024/1745 and 2024/1739). While the focus of this package was to curb the violation and circumvention of sanctions through the introduction of due diligence obligations for non-EU subsidiaries, or the expansion of “no re-export to Russia” clause requirement, ample other amendments were also introduced, such as those relating to transfer of IP rights, or divestment. The list of restricted goods has also been significantly expanded and additional persons and entities have been added to the list of sanctioned persons in EU Regulation 269/2014.

On June 29, 2024, the EU also fundamentally expanded its sanctions against Belarus (implemented by EU Regulation 2024/1865) in order to align with the goals of the 14th sanctions package. Additional sanctions under the Hamas and Palestinian Islamic Jihad and Sudan regimes were also published.

In this Quarterly Sanctions Update, we summarise the most recent and significant amendments introduced, or proposed, by the EU and the United Kingdom between April and July 2024.*

IN DEPTH

DUE DILIGENCE, CIRCUMVENTION & ENFORCEMENT 

  • Liability for the actions of subsidiaries: New Article 8a of EU Regulation 833/2014 imposed a ‘best efforts’ obligation on EU companies which are now required to ensure that their non-EU subsidiaries do not participate in activities undermining EU sanctions. As explained by Recital 29 to EU Regulation 2024/1745 such activities are “those resulting in an effect that EU sanctions seek to prevent, for example, that a recipient in Russia obtains goods, technology, financing or services of a type that is subject to prohibitions under EU Regulation 833/2014”. EU sanctions against Belarus now contain the equivalent provision.
  • “No re-export to Russia” and “no re-export to Belarus clauses: Two exemptions from the “no re-export to Russia clause” obligation of Article 12g of EU Regulation 833/2014 have been introduced. Those relate to: (i) contracts relating to machining centres, horizontal lathes and other related goods and (ii) public contracts concluded with a public authority in a third country or with an international organisation. In addition, the new Article 12ga of EU Regulation 833/2014 included within the scope of the “no re-export to Russia” clause a requirement for the transfer of intellectual property in connection with common high priority items. Finally, EU exporters of common high priority items are now required to (i) implement sanctions due diligence and compliance policies, and (ii) ensure that such policies are implemented by their non-EU subsidiaries. This requirement will apply as of December 26, 2024. An equivalent “no re-export to Belarus” clause requirement has been introduced to EU sanctions against Belarus. Note that this requirement does not, however, extend to intellectual property relating to the common high priority items.
  • Definition of circumvention: The existing anti-circumvention provision of Article 12 of EU Regulation 833/2014 has been amended to specifically prohibit participation in arrangements aimed at circumventing EU sanctions, without deliberately seeking such circumvention but being aware of it and accepting the possibility. Recital 37 to EU Regulation 2024/1745 further explains that the amendment reflects the interpretation of ‘circumvention’ provided by the Court of Justice of the European Union in Case C-72/11. EU sanctions against Belarus now contain the same prohibition.
  • Voluntary self-disclosure: The 14th package amended Article 8 of EU Regulation 833/2014 relating to penalties for sanctions violation to expressly provide that voluntary self-disclosure may be taken into account as a mitigating factor. Recital 26 to EU Regulation 2024/1745 clarified in this respect that: “Where a natural or legal person voluntarily, completely and in due time discloses a violation of the restrictive measures, it should be possible for national competent authorities to take that self-disclosure into account when applying penalties, as appropriate, in accordance with national administrative law or with other relevant national law or rules.” In addition, the 14th package imposed a new requirement on EU Member States and the European Commission to share information on sanctions violations and enforcement issues, penalties for breach and judgments handed down by national courts. Click here to access our alert on sanctions violation criminalisation at the EU level. EU sanctions against Belarus have been amended accordingly.
  • List of entities involved in circumvention: 28 Russian and 31 third-country entities were added to the list of entities associated with Russia’s military-industrial complex of Annex IV to EU Regulation 833/2014 (which are subject to authorisation requirements with limited grounds). This list now contains 649 entities incorporated in, among other countries, Russia, China, Türkiye, Thailand, Kazakhstan, India or Singapore.
  • United Kingdom: On May 16, 2024, the UK Office of Financial Sanctions Implementation issued its Guidance on financial sanctions enforcement and monetary penalties. The guidance sets out, among other things, (i) a summary of the UK Office of Financial Sanctions Implementation compliance and enforcement approach, (ii) an overview of how it will assess whether to apply a monetary penalty, and what will be taken into account, (iii) an overview of the process that will decide the amount of the monetary penalty and (iv) an explanation of how it will impose a monetary penalty, including timescales at each stage and rights of review and appeal.

BUSINESS SERVICES AND SOFTWARE

  • “Partner countries” subsidiaries’ exemption: The existing exemption for the provision of business services and software for the exclusive use of Russian subsidiaries that are owned or controlled by an entity established in the EU or ‘partner countries’ (including the UK, US, Australia, Canada, Japan, New Zealand, Norway, Switzerland and South Korea) has been extended until September 30, 2024. The list of ‘partner countries’ has been additionally expanded to include Iceland and Lichtenstein. Further, under a new exemption, EU nationals currently residing Russia, and were in residence before February 24, 2022 are allowed to provide business services to their Russian employers if these employers are owned or controlled by an entity established in the EU or partner countries.
  • Belarus: EU sanctions against Belarus prohibits provision of certain business services and software to (i) the Republic of Belarus, its Government, public bodies, corporations or agencies or (ii) any natural or legal person, entity or body acting on their behalf or their direction. This prohibition is narrower in scope as compared to EU sanctions against Russia as it does not apply to Belarussian entities that are not controlled by the Belarussian State. Two exemptions have been provided, relating to (i) the provision of services that are strictly necessary for the termination by October 2, 2024 of contracts concluded before July 1, 2024 and (ii) the provision of services intended for the exclusive use of Belarussian subsidiaries of EU, UK, US or “partner countries” entities (applicable until January 2, 2025).

DIVESTMENT

  • Divestment licences: Powers of national authorities to authorise a number of activities prohibited under EU sanctions in relation to divestment from Russia or the wind-down of business activities in Russia have been extended until December 31, 2024. In addition, national authorities have been granted the power to authorise the satisfaction of a claim made by a Russian entity that would otherwise be affected by EU sanctions, to the extent such satisfaction is strictly necessary for the divestment from Russia or the wind-down of business activities in Russia.
  • Damages for expropriation: EU companies have been granted powers to recover, in judicial proceedings before the competent courts of EU Member States, any damages, including legal costs, caused by Russian entities that benefited from the expropriation of EU companies in Russia. Further, Member States shall not be liable for judicial decisions rendered in accordance with [the Russian Expropriation Decree] or for the enforcement of such decisions. Member States shall not comply with judgments, arbitral awards, including investor-State arbitral awards, or other judicial decisions which hold them liable”.

ENERGY

New restrictions on Russian LNG: For the first time, the EU has introduced prohibitions on the provision of goods, technologies and services to LNG projects under construction in Russia. In addition, the transshipment of LNG via EU ports and related technical services will be gradually phased-out over the next 9 months. The import of Russian LNG into terminals which are not connected to the EU gas pipeline network has also been prohibited.

EXPORTS & IMPORTS

  • Advanced technology and industrial goods: The 14th Sanctions Package extended export restrictions to include quadbikes, microwaves and aerial amplifiers, and digital flight data recorders, as well as certain chemicals, plastics, vehicle parts (including replacement parts for trucks) and machinery (e.g. boring/excavating machinery, appliances for pipes, electrical equipment, monitors, radios, video/audio equipment). EU sanctions against Belarus have been updated accordingly to include the advanced technology, industrial and common high priority items included in EU Regulation 833/2014.
  • Helium: The 14th sanctions package introduced a new prohibition on the import into the EU of helium originating in Russia or exported from Russia. This prohibition also covers any transfer of helium and the provision of technical assistance and financing in relation to any such import or transfer.

FINANCIAL SECTOR

  • Russian SPFS Financial Messaging System: From June 25, 2024, EU banks outside Russia are prohibited from connecting into, and carrying out transactions using, the SPFS (equivalent to SWIFT). In addition, EU operators to engage with third-country banks listed in EU Regulation 833/2014 that are using SPFS.
  • Transactions with banks and crypto asset providers: Any transactions with banks and asset providers established in Russia and third countries listed in EU Regulation 833/2014, which facilitate transactions supporting Russia’s defence-industrial base are now prohibited.

TRANSPORT

  • Aviation: Subject to a number of exemptions, non-scheduled flights (the origin or destination of which is decided by a Russian individual or company, regardless of the aircraft’s ownership) have been prohibited.
  • Road transport: The existing prohibition relating to transport of goods by road in the EU has been expanded to also cover EU companies with an ownership share of 25% or more by Russian companies or individuals. In addition, companies with an ownership of 25% or more by such persons will no longer be allowed to become ‘EU road transport undertakings’ within the meaning of the relevant EU legislation.
  • Maritime: For the first time, the EU has sanctioned 27 vessels for their contribution to Russian warfare in various sectors (e.g. the transport of military equipment for Russia, the transport of stolen Ukrainian grain, or the participation in the dark fleet transporting Russian oil). These vessels are now prohibited from accessing EU ports and related services.

ASSET FREEZE

  • Persons and entities subject to asset freeze: A further 69 individuals and 47 entities were added to the list of persons subject to asset freeze restrictions. The listings touch upon various sectors of the Russian economy, including military companies, companies active in the engineering, chemical or explosives sectors, the leading Russian energy companies as well as companies involved in disinformation activities. In the same vein, the UK introduced 50 new designations targeting Russian shadow fleet, Russian financial institutions as well as companies which supply Russia’s military production.

OTHER SANCTIONS REGIMES

  • Hamas and Palestinian Islamic Jihad sanctions: On June 28, 2024, 6 individuals and 3 entities were added to the list of sanctioned persons under EU Regulation 2024/385 for participating in the financing of Hamas and Palestinian Islamic Jihad. The UK imposed similar sanctions on January 22, 2024 and March 27, 2024.
  • Sudan sanctions: On June 28, 2024, 6 individuals were added to the list of sanctioned political persons under EU Regulation 2023/2147 for participating in activities undermining the stability and transition of Sudan. The UK updated its Sudan (Sanctions) (EU Exit) Regulations 2020 with 3 entities on April 15, 2024.

*Trainees David Amar and Marine Bahaderian also contributed to this update.

EXPLORE FURTHER INSIGHTS

  • Export Controls in the Aeronautics, Space and Defence Sector’ Conference: Sabine Naugès participated as panellist in this conference organised by the French Compliance Society, in partnership with “Risques et Vous” and McDermott Will & Emery. Raminta Dereskeviciute, Benoit Feroldi and Michal Chajdukowski were also involved. Read our summary here.
  • Global Investigation Review ‘How the United Kingdom Approaches Export Controls’: Raminta Dereskeviciute, Ludovica Rabitti and Michal Chajdukowski authored a chapter on UK export controls in The Guide to Sanctions published by the Global Investigations Review. Read the publication here.
  • Law360 ‘EU Sanctions Against Russia Get Tighter as “Partner Countries” Subsidiaries’ Exemption Expires’: Raminta Dereskeviciute, Sabine Naugès and Michal Chajdukowski authored an article on the amendments of the 14th sanctions package published by Law360.
  • Recent sanctions-related posts on our Regulatory and International Trade Blog:
    • Spotlight on the “Partner Countries” Exemption from Sanctions against Russia. Read here.
    • German Authorities Take Action to Accelerate Export Control Procedures. Read here.

European Union Criminalizes Violations of Sanctions. Read here.

制裁措置についての四半期アップデート|2024年第2四半期

By Sabine Naugès, Raminta Dereskeviciute, Michal Chajdukowski

2024年6月24日、欧州連合(EU)は対ロシア制裁第14次パッケージ( EU規則2024/1745及び2024/1739により実施)を採択しました。この一連の制裁パッケージの焦点は、非EU子会社に対するデューデリジェンス義務の導入や、「ロシアへの再輸出禁止」条項要件の拡大を通じて、制裁違反や回避を抑制することに置かれていましたが、知的財産権の取引や事業売却に関するものなど、その他の改正も数多く導入されました。制限品目リストも大幅に拡大され、EU規則269/2014の制裁対象者リストには、新たな個人及び事業体が追加されました。

2024年6月29日、EUはまた、対ロシア制裁第14次パッケージの目標に沿って、ベラルーシに対する制裁を抜本的に拡大しました(EU規則2024/1865により実施)。また、ハマス及びパレスチナ・イスラミック・ジハード(PIJ)、スーダン政権に対する追加制裁も発表しました。

この制裁措置についての四半期アップデートでは、2024年4月から7月までの間にEUと英国により導入又は提案された、最新の重要な改正について要約します。

デューデリジェンス、迂回行為と法執行について

  • 子会社の行為に対する責任 :EU規則833/2014の新第8条aは、EU企業に「最善の努力」義務を課し、EU企業は、EU域外の子会社がEU制裁を弱体化する活動に参加しないことを確保することが求められています。EU規則2024/1745の序文29で説明されているように、そのような活動とは、「EU制裁が阻止しようとする効果をもたらすもの、例えば、ロシアの受取人がEU規則833/2014で禁止されている種類の商品、技術、資金、サービスを入手すること」を指します。現在、EUの対ベラルーシ制裁にも、これと同等の規定が含まれています。
  • 「ロシアへの再輸出禁止」と「ベラルーシへの再輸出禁止」条項:EU規則833/2014の第12g条に定められた「ロシアへの再輸出禁止条項」の義務について、2つの適用除外が導入されました。これらは (i)マシニングセンター、汎用旋盤及びその他の関連商品に関する契約、(ii)第三国の公的機関又は国際組織と締結された公的契約に関するものです。さらに、EU規則833/2014の新しい第12ga条には、「ロシアへの再輸出禁止」条項の範囲内に、Common High Priority Itemsに関連する知的財産の移転に関する要件が含まれました。最後に、Common High Priority ItemsのEU圏内の輸出業者は現在、(i)制裁措置に関するデューデリジェンス及びコンプライアンス方針を実施し、(ii)そのような方針がEU域外の子会社でも実施されていることを確保することが求められるようになりました。この要件は2024年12月26日から適用されます。EUの対ベラルーシ制裁には、同等の「ベラルーシへの再輸出禁止」条項要件が導入されています。ただし、この要件は、Common High Priority Itemsに関連する知的財産の取引には適用されません。
  • 迂回行為の定義:EU規則833/2014の第12条に定められた既存の迂回行為防止規定が改正され、EU制裁の迂回行為を目的とする取組みへの参加が特に禁止されるようになりました。意図的に回避を目的としたものではなくとも、そのような効果を認識し、受容している場合も対象となります。EU規則2024/1745の序文37は、この改正について、C-72/11事件において欧州連合司法裁判所(the Court of Justice of the European Union)が示した「迂回行為」の解釈を反映したものであると説明されています。現在、EUの対ベラルーシ制裁措置にも、同様の禁止規定が含まれています。
  • 自発的な自己開示:第14次パッケージでは、制裁違反の罰則に関するEU規則833/2014の第8条が改正され、自発的な自己開示が緩和要素として考慮される可能性があることが明示的に規定されました。EU規則2024/1745の序文26では、この点について以下のように明確に規定されています。 「自然人又は法人が自発的に、完全に、かつ期限内に制限措置違反を開示した場合、各国の管轄当局は、国内行政法又は他の関連する国内法若しくは規則に従って、適切な場合、罰則を適用する際に、その自己開示を考慮することが可能であるべきである」。さらに、第14次パッケージでは、EU加盟国と欧州委員会(European Commission)に、制裁措置の違反や執行に関する問題、違反に対する罰則、国内裁判所が下した判決に関する情報を共有するよう新たに義務付けました。EUレベルでの制裁措置違反の刑事罰化に関するアラートは、こちらをクリックしてご覧ください。EUの対ベラルーシ制裁は、これに応じて修正されました。
  • 迂回行為に関与している組織のリスト:EU規則833/2014の付属書Ⅳに記載されたロシアの軍産複合体に関連する組織リスト(限定的な理由による認可要件の対象となります。)に、ロシアの28組織と第三者国の31組織が追加されました。このリストには、現在、ロシア、中国、トルコ、タイ、カザフスタン、インド、シンガポールなどで設立された649の組織が含まれます。
  • 英国: 2024年5月16日、英国金融制裁実施局は、金融制裁の執行と金銭的罰則に関する指針を公表しました。同ガイダンスでは、特に(i)英国金融制裁実施局のコンプライアンス及び執行アプローチの概要、(ii)金銭的罰則を適用するかどうかの評価方法の概要及び考慮される要素、(iii)金銭的罰則の金額を決定する手続の概要、(iv)金銭的罰則の適用方法の説明(各段階のスケジュール、審査及び上訴の権利を含む)が規定されています。

ビジネスサービスとソフトウェア

  • 「パートナー国」子会社の適用除外:EU又は「パートナー国」(英国、米国、オーストラリア、カナダ、日本、ニュージーランド、ノルウェー、スイス、韓国を含む。)に設立された企業が所有又は支配するロシアの子会社が独占的に使用するビジネスサービスとソフトウェアの提供に関する現行の適用除外措置が、2024年9月30日まで延長されました。さらに、「パートナー国」のリストにアイスランドとリヒテンシュタインが追加されました。さらに、新しい適用除外措置により、現在ロシアに居住するEU国籍保有者で、2022年2月24日以前からロシアに居住していた者は、そのロシアの雇用主がEU又はパートナー国に設立された組織によって所有又は管理されている場合、その雇用主に役務を提供することが認められるようになりました。
  • ベラルーシ:EUの対ベラルーシ制裁は、(i)ベラルーシ共和国、その政府、公共団体、企業若しくは機関、又は(ii)それらの代理若しくは指示により行動する自然人若しくは法人、団体に対して、特定の役務の提供とソフトウェアの提供を禁止しています。この禁止措置は、EUの対ロシア制裁と比べると範囲が狭くなっています。ベラルーシ国家によって管理されていないベラルーシの組織には適用されません。(i)2024年7月1日以前に締結された契約を2024年10月2日までに終了させるために厳密に必要なサービスの提供、及び、(ii)EU、英国、米国、又は「パートナー国」にある組織の、ベラルーシ子会社が独占的に使用することを目的とした、サービスの提供(2025年1月2日まで適用)という、2つの適用除外が設けられています。

エネルギー

ロシアのLNGに対する新たな規制:EUは初めて、ロシアで進行中のLNGプロジェクトに対する商品、技術、役務の提供を禁止する措置を導入しました。さらに、EUの港を経由するLNGの積み替えとこれに関連する技術的なサービスは、今後9か月かけて段階的に廃止されます。EUのガスパイプライン網に接続されていない港湾へのロシア産LNGの運び込みも禁止されました。

輸出入

  • 先端技術と工業製品:対ロシア制裁第14次パッケージでは、輸出規制が拡大され、四輪バイク、電子レンジ、空中増幅器、デジタル・フライト・データ・レコーダーに加え、特定の化学品、プラスチック、車両部品(トラックの交換部品を含みます。)、機械類(ボーリング/掘削機械、配管用器具、電気機器、モニター、ラジオ、ビデオ/オーディオ機器など)が含まれるようになりました。EUの対ベラルーシ制裁は、EU規則833/2014に含まれる先端技術、工業製品、Common High Priority Itemsを対象に、併せて更新されました。
  • ヘリウム:対ロシア制裁第14次パッケージでは、ロシア産又はロシアから輸出されたヘリウムについて、EUへの輸入禁止が新たに導入されました。この禁止措置は、ヘリウムの譲渡、及び輸入や譲渡に関連する技術支援や融資の提供も対象となっています。

金融業界

  • ロシアのSPFS金融メッセージ転送システム: 2024年6月25日以降、ロシア国外のEU域内銀行はSPFS(SWIFTに相当)への接続とSPFSを使用した取引が禁止されます。さらに、規則833/2014に記載されている第三者国の銀行でSPFSを使用しているEU銀行と取引を行うEU事業者も対象となります。
  • 銀行及び暗号資産プロバイダーとの取引: ロシアとEU規則833/2014に記載された第三者国に設立された銀行及び資産プロバイダーとの取引で、ロシアの防衛産業基盤を支援する取引を促進するものは、現在禁止されています。

交通

  • 航空:いくつかの例外を除き、非定期便(航空機の所有権に関係なく、ロシアの個人又は企業が出発地又は目的地を決定するもの)は禁止されています。
  • 道路輸送: EU域内の道路を利用する貨物輸送に関する従来の禁止事項が拡大され、ロシアの企業又は個人が25%以上の株式を保有するEU企業もその対象となりました。さらに、このような人物が25%以上の株式を保有する企業は、EU関連法上の「EU道路運輸事業者」になることができなくなりました。
  • 海事:EUは、今回初めて、さまざまな分野でロシアの戦争に貢献しているという理由で、27隻の船舶に制裁を科しました(例えば、ロシアへの軍事装備の輸送、盗まれたウクライナの穀物の輸送、ロシアの石油を輸送する暗黒船団への参加などが理由として挙げられています。)。これらの船舶は、現在、EU域内の港湾や関連サービスへのアクセスを禁止されています。

資産凍結

  • 資産凍結の対象となる人物と団体:資産凍結の対象者リストに、さらに69人の個人と47の法人が追加されました。このリストには、軍需企業、エンジニアリング、化学、爆発物分野で活躍する企業、ロシアの大手エネルギー企業、偽情報活動に関与する企業など、ロシア経済のさまざまな部門が含まれています。同様に、英国はロシアの「影の船団」、金融機関、及び軍事生産に供給する企業を対象とした50の新たな指定を行いました。

その他の経済制裁

  • ハマスとパレスチナ・イスラミック・ジハード(PIJ)への制裁: 2024年6月28日、ハマスとパレスチナ・イスラミック・ジハード(PIJ)の資金調達に関与したとして、6人の個人と3つの法人がEU規則2024/385に基づく制裁対象者リストに追加されました。英国は2024年1月22日と3月27日に同様の制裁を科しています。
  • スーダンへの制裁: 2024年6月28日、スーダンの安定と移行を損なう活動に参加したとして、EU規則2023/2147に基づく制裁対象政治家リストに、6人の個人が追加されました。英国は2024年4月15日、スーダン(制裁)(EUは離脱)規則2020を更新して、3つの法人を追加しました。

*このアップデートの執筆に際して、トレーニーのDavid AmarMarine Bahaderianの協力を得ました。

より深く

  • 「航空・宇宙・防衛分野における輸出管理」会議: Sabine Naugèsは、フランス・コンプライアンス協会が「Risques et Vous 」とMcDermott Will & Emeryと共同で主催した会議にパネリストとして参加しました。Raminta Dereskeviciute、Benoit Feroldi、Michal Chajdukowskiも参加しました。会議の概要はこちらからご覧いただけます。
  • グローバル・インベスティゲーション・レビュー「英国の輸出規制へのアプローチ」:Raminta Dereskeviciute、Ludovica Rabitti、Michal Chajdukowskiは、Global Investigations Review発行の「The Guide to Sanctions」において、英国の輸出管理に関する章を執筆しました。出版物はこちらからご覧いただけます。
  • Law360 「EUの対ロシア制裁が強化される中、「パートナー国」子会社に対する適用除外が終了」:Raminta Dereskeviciute、Sabine Naugès、Michal Chajdukowskiが執筆した第14次制裁パッケージの改正に関する記事がLaw360に掲載されました。
  • 規制・国際貿易ブログの最近の制裁に関連した記事:
    • 対ロシア制裁の「パートナー国」適用除外にスポットライト。こちらをお読みください。
    • ドイツ当局、輸出管理手続きの迅速化に向けた措置。こちらをお読みください。
    • 欧州連合(EU)、制裁違反の刑事罰化。こちらをお読みください。
ANTITRUST M&A SNAPSHOT | Q2 2024

By Mary Hecht, Jon B. Dubrow, Joel R. Grosberg, Stéphane Dionnet, Graham J. Hyman, Max Küttner

UNITED STATES

Agencies Revisiting Consummated Mergers

What’s old is new again, as agencies are increasingly scrutinizing consummated mergers from years past. In May 2024, the US Department of Justice (DOJ), Antitrust Division, together with 30 states and the District of Columbia, sued Live Nation, alleging monopolization and other claims. If successful, the lawsuit could result in Live Nation being forced to sell Ticketmaster despite regulators clearing the combination in 2010. This is not the first time regulators have revisited Live Nation’s purchase of Ticketmaster. The 2010 deal involved a consent decree with the DOJ requiring Live Nation to sell off certain assets and license software to competitors as well as prohibiting, for 10 years, retaliation against venues for considering working with ticketing services other than Ticketmaster. In 2019, the DOJ found that Live Nation violated the agreement; the DOJ subsequently extended the consent decree and imposed additional costs and fees on Live Nation. At the time, the DOJ advertised the extension as “the most significant enforcement action of an existing antitrust decree by the Department in 20 years.”

This lawsuit aligns with recent agency rhetoric and the recent enforcement trend of re-opening investigations into closed deals. The DOJ’s 2023 lawsuit alleging Google monopolized digital advertising technologies – including through “serial acquisitions” – is set for trial this fall. Additionally, in June 2024 the Federal Trade Commission (FTC) asserted, in its ongoing lawsuit against Meta challenging its acquisitions of Instagram in 2012 and WhatsApp in 2014, that the company withheld documents as part of the earlier Hart-Scott-Rodino (HSR) reviews of those acquisitions. The agency represented, in June, that if it had access to the pre-acquisition documents it now has, the outcome of the initial review could have come out differently.

The agencies also have signaled, through their recent public requests for information (RFIs), that they will make other inquiries into past acquisitions. The FTC, DOJ, and US Department of Health and Human Services (HHS) issued an RFI in March 2024 asking the public to comment on deals by “health systems, private payors, private equity funds, and other alternative asset managers” in the healthcare space. The FTC and DOJ followed in May with a second RFI specifically soliciting information on serial acquisitions and roll-up strategies across all sectors. These extensive fact-gathering efforts indicate that the agencies are eager to evaluate deals with a retrospective lens. The Live Nation, Google and Meta lawsuits may therefore function as test cases for later actions.

Less Enforcement, More Abandonment

Recent reports indicate that, over the past three years, companies have abandoned 37 deals in the face of FTC pressure. Some were abandoned prior to formal enforcement actions and others were post-complaint. These abandonments spanned industries including pharma, defense, healthcare, energy and technology. Among them, in May 2024, Atlus Group abandoned its purchase of Situs Group’s real estate valuation business.

Assistant Attorney General Jonathan Kanter has separately stated that 21 deals were abandoned following merger investigations by the DOJ, indicating an even stronger link between regulatory action generally and further expanding the count of abandonments.

Because many deals require review by multiple agencies and countries, it can be difficult to know which pressure points or combination thereof led to the abandonment of deals. Some firms, though, announce their reasoning outright. For example, Amazon and iRobot publicly stated earlier this year that “[u]ndue and disproportionate regulatory hurdles” led to the mutual termination of their deal, specifically noting that European authorities disapproved of the deal. Amazon-iRobot also faced FTC scrutiny. Regardless of the definitive reasons, these reports confirm that merger abandonment is in a historic upswing, making breakup fees more important than ever in evaluating and allocating risk.

Oil and Gas Deals Flowing

Merger activity in oil and gas markets remains high. Although agencies are scrutinizing the deals, they have engaged in little enforcement activity this quarter. On April 29, 2024, Diamondback Energy received a second request from the FTC looking into its $26 billion acquisition of its privately held competitor Endeavor Energy Resources. Diamondback announced to stockholders that it still anticipated a fourth-quarter closing as originally planned. The combined entity would be the third-largest oil and gas producer in the Permian Basin, located primarily in Texas and partly in New Mexico, but the US gasoline market generally is highly fragmented. This second request follows four others in the oil and gas sector in recent months:

  • Occidental and Crownrock reported that they received a second request in January that just received FTC clearance on July 18, 2024.
  • Chesapeake Energy and Southwest Energy received a second request in April that is ongoing.
  • Chevron-Hess received a second request in January that is ongoing, and Hess is party to an arbitration with Exxon related to ownership rights implicated by the deal.
  • Exxon Mobil-Pioneer Natural Resources was cleared with conditions following a second request, as explained further below.

Exxon Mobil closed its $64.5 billion acquisition of oil producer Pioneer Natural Resources on May 3, 2024, following a second request. In public documents explaining the clearance, the FTC did not allege concerns about the actual merits of the transaction despite the acquisition doubling Exxon’s footprint in the Permian Basin, as described by Exxon’s press release on the acquisition. The FTC complaint stated the geographic market for analyzing crude oil was global, and therefore combined firm’s share presumably falls well below the 2023 Merger Guidelines’ presumption of unlawfulness (30% combined market share). Nevertheless, the FTC filed a complaint focused on alleged collusive conduct by Pioneer’s CEO.  The settlement required the parties to enter into a consent decree, prohibiting Exxon from appointing Pioneer’s CEO to the Exxon board and limiting which other Pioneer employees Exxon could appoint to its Board. Similar to the FTC’s recent consent decree for EQT’s acquisition of Quantum Energy’s Tug Hill entity, the FTC’s action in Pioneer is another example of a FTC settlement focused on Clayton Act Section 8 interlocking directorate issues in the energy space.

EUROPEAN UNION

The (Possible) End of the Notorious Article 22 Referral of the European Merger Control Regulation

On March 21, 2024, Advocate General Nicholas Emiliou issued his opinion in the Illumina/Grail case and concluded that Article 22 of the EU Merger Regulation (EUMR) is not the European solution for dealing with “killer acquisitions.” In particular, he stated his view that Article 22 EUMR does not permit national competition authorities (NCAs) to ask the European Commission (EC) to examine a concentration that does not have a community dimension under the EUMR and where the NCAs have no competence to review such a concentration under national law.

As a reminder, the EC reviewed and blocked Illumina’s acquisition of Grail, a US biotechnology company, that develops blood tests for early detection of cancer, despite Grail not having any European revenue. Therefore, the parties did not submit a notification to the EC or any European competition authority, as no revenue threshold was triggered.

Historically, Article 22 EUMR was introduced to address a perceived gap where EU member states did not yet have their own merger control rules. The EC interpreted this provision more broadly to allow it to review mergers not meeting the revenue thresholds in Member States (as opposed to a country not having merger control rules in the first place).

In April 2021, the EC accepted a referral request from France, joined by Belgium, Greece, Iceland, the Netherlands and Norway. This eventually led to the EC prohibiting the proposed acquisition in September 2022, and Illumina was compelled to divest Grail in October 2023. The EC recently (April 2024) approved Illumina’s plan to divest GRAIL following the restorative measures requiring Illumina to unwind its completed acquisition of GRAIL. On June 24, Illumina announced the completion of the spinoff of GRAIL.

The lower General Court (GC) previously upheld the EC’s position. The higher EU Court of Justice is now required to assess whether Article 22 of the Merger Regulation enables the EC to review a merger referred to it by national competition authorities who lack jurisdiction to review it, since the merger falls below the thresholds of the national legislation.

The purpose of the Advocate General’s opinion to propose an independent legal analysis to the Court of Justice. The judges will generally take the opinion into account in making a final ruling. Advocate General Emiliou concluded that the GC erred in its interpretation and application of Article 22 of the EUMR. In this regard, he considered the wording, origin, context and purpose of Article 22 and considered the logic of the EU merger control system to conclude that Article 22 cannot be used where the Member States have no jurisdiction to review a concentration under its national law.

The actual position of the EC continues to raise substantial uncertainty for merging parties, as this interpretation of Article 22 EUMR gives the EC the power to review pre- or post-closing almost any concentration, occurring anywhere in the world, regardless of an undertakings’ turnover and presence in the European Union or the value of the transaction. As a reminder, the Advocate General’s opinion is not binding, and thus we await to see the decision of the Court of Justice to evaluate (or not!) the risk of an Article 22 referral when drafting transactional agreements.

The EC Often Considers Non-Price Competition Parameters When Assessing Transactions Under EU Merger Control Regulation

In April 2024, the EC issued a competition policy brief on the topic of non-price competition in EU merger control, citing case practice examples. The EC reported that it is increasingly evaluating non-price competition parameters such as innovation, quality, data protection, sustainability and supply reliability alongside traditional price effects for its merger reviews. While price effects remain significant, assessing non-price captures broader effects on consumer welfare, as endorsed by the Horizontal Merger Guidelines and permitted under the EUMR. These factors are considered on a case-by-case basis throughout the merger assessment process, including market definition, competitive assessment, potential efficiencies and remedies. Their importance varies by industry and the specific transaction but has grown due to digital and green transitions and other evolving market dynamics.

Non-price competition parameters to be considered include the following:

  • Innovation: Vital for economic progress, evaluated through R&D expenditure, industry trends, IP protection and ongoing innovation requirements, especially in pharmaceuticals, agrochemicals and high-tech sectors.
  • Quality and Product Differentiation: Critical in markets with differentiated products and limited price competition; quality aspects like durability, reliability, functionality and brand perception are critical in industries such as steel manufacturing and medical devices.
  • Data Protection and Privacy: Crucial in digital and tech industries, where data control is a competitive advantage, with data protection and privacy seen as quality and differentiation factors.

In May 2024, the EC published another policy brief on antitrust in labor markets. Helpfully, the brief underscores that as part of a non-problematic transaction, as long as a restriction on employees is directly related, objectively necessary and proportionate, companies will be able to justify no-poach agreements in transaction documents. However, the policy brief does note that when agreeing to such a restriction, companies should consider whether a confidentiality or nondisclosure agreement would not be sufficient and limit the clause to key personnel.

(Not So) Kind Reminder from the EC to Provide Correct Information When It Comes to the Review of a Transaction Under EUMR

The EC suspects Kingspan to have intentionally, or negligently, provided incorrect, incomplete and misleading information while the EC investigated Kingspan’s planned acquisition of Trimo in 2021 under the EUMR. The information concerns basic facts related to Kingspan’s internal organization, as well as basic facts aimed at assessing (i) the scope of the relevant product and geographic market, (ii) the existence of barriers to entry and expansion, (iii) the importance of innovation, and (iv) the closeness of competition between Kingspan and Trimo, and vis-à-vis their competitors.

Kingspan ultimately abandoned the transaction in April 2022 If the EC were to conclude that Kingspan intentionally, or negligently, provided incorrect, incomplete or misleading information, it could impose a fine for each violation of up to 1% of the company’s annual worldwide turnover.

UNITED KINGDOM

Focus on the M&A Aspects of the Digital Markets, Competition and Consumers (DMCC) Act to Come Into Force

The DMCC Act will grant the Competition & Markets Authority (CMA) with powers to enforce the new digital markets competition regime and will apply to firms that are designated as having strategic market status (SMS). The SMS designation will be applied to firms that have substantial and entrenched market power and a position of strategic significance in at least one digital activity linked to the UK. The threshold for SMS will include having a global turnover exceeding £25 billion, or a UK turnover exceeding £1 billion.

Along with the other two pillars of the new Digital Markets Competition regime (conduct requirements and pro-competition interventions to address adverse effects on competition), this SMS designation comes with new merger reporting requirements: SMS firms will have to report to the CMA prior to closing on intended transaction, where they have a value of £25 million or more and a UK connection.

Aside from this new merger control regime, the DMCC Act also includes a new merger control review jurisdictional threshold applicable to all sectors, where the parties’ activities do not overlap – namely, to address “killer acquisitions.” The CMA will be able to review deals when one of the parties to the transaction (i) supplies or purchases 33% of goods or services in the UK/a substantial part of the UK and (ii) has UK turnover exceeding £350 million; and (iii) another party to the transaction has a UK nexus (carries on activities in the UK, including through supplying goods or services into the UK).

The DMCC Act received royal assent on May 24, 2024, but is expected to come into force in autumn 2024 (depending in part on the prioritization of any new government). The CMA opened at the same time as the royal assent, a consultation on the Digital Markets Competition regime guidance and on the specific guidance for merger reporting requirements for SMS firms.

For more info on this topic, please visit Antitrust M&A Snapshot | Q2 2024 (mwe.com).

競争法M&Aスナップショット | 2024年第2四半期

By Mary Hecht, Jon B. Dubrow, Joel R. Grosberg, Stéphane Dionnet, Graham J. Hyman, Max Küttner

米国

競争当局による実施済み合併事案の再検討

競争当局が過去に実施済みの合併を精査するケースが増えているため、過去のことが再び注目されるようになっています。2024年5月、米国司法省(DOJ)反トラスト部門は、30州とコロンビア特別区と共に、Live Nationを独占行為などの容疑で訴えました。この訴訟が成功すれば、2010年に規制当局がTicket Masterの合併を承認していたにもかかわらず、Live NationはTicket Masterの売却を余儀なくされる可能性があります。規制当局がLive NationによるTicket Masterの買収を再検討するのは、今回が初めてではありません。2010年の買収では、DOJの同意判決により、Live Nationは特定の資産を売却し、競合他社にソフトウェアをライセンスすることを義務付けられ、また10年間にわたり、Ticket Master以外のチケットサービス事業者との提携を検討している会場に対して不利益措置を取ることを禁止されました。2019年に、DOJはLive Nationが同意判決に違反したと判断して、同意判決を延長し、追加の費用と課徴金の支払い義務を課しました。当時、DOJはこの同意判決の延長を「過去20年間で、同省が現行の反トラスト判決を執行した中で、最も重要な執行である」と評価しました。

この訴訟は、既に実施済みの合併事案を再検討する、最近の競争当局の姿勢や傾向に沿ったものといえます。DOJがGoogleに対して提起した2023年の訴訟では、同社がデジタル広告技術を、「連続的買収」その他の方法で独占化したと主張しており、今年の秋に審理が予定されています。さらに、2024年6月には、連邦取引委員会(FTC)が、2012年のInstagramの買収と2014年のWhatsAppの買収をめぐり、現在係争中のMetaに対する訴訟において、Metaがこれらの買収におけるハート・スコット・ロディノ(HSR)法の審査に際して、文書を隠蔽していたと主張しました。FTCは、現在入手している買収前の文書にアクセスできていれば、初期審査の結果は異なっていた可能性があると主張しています。

当局は、近年の情報提供依頼(RFI)を通じて、過去の買収事案に関して他にも調査を行う意向を示唆しています。FTC、DOJ、保健福祉省(HHS)は、2024年3月に、ヘルスケア業界における「医療機関、民間保険会社、プライベート・エクイティ・ファンド、その他の資産運用会社」による買収に関するコメントを求める情報提供依頼を行いました。5月には、FTCとDOJが、あらゆる業界における、連続的買収とロールアップ戦略に関する情報を特に募集する2回目の情報公開請求を行いました。このような広範な情報収集の取り組みは、当局が過去に実施済みの買収案件について積極的に精査しようとしていることを示唆しています。そのため、Live Nation、Google、Metaの訴訟は、今後の活動の試金石となる可能性があります。

執行活動の減少、買収断念の増加

最近の報告によると、過去3年間で、企業がFTCの圧力に直面して買収案件を断念した事案が37件あることが明らかになっています。正式な執行活動がなされる前に断念した事案もあれば、訴訟提起後に断念した事案もあります。これらの買収の断念は、製薬、防衛、医療、エネルギー、テクノロジーなど様々な業界で生じています。例えば、Atlus Groupは、2024年5月にSitus Groupの不動産評価事業の買収を断念しました。

DOJのジョナサン・カンター補佐官は、DOJによる合併審査の後に21件の取引が中止されたと述べており、執行活動の強化と買収断念の件数増加との間には相関関係があることを示唆しています。

多くの買収案件は、複数の当局と国による審査を必要とするため、どのような圧力が買収案件の断念に至ったのかを特定することは困難です。しかし、一部の企業はその理由を率直に公表しています。たとえば、AmazonとiRobotは、今年初めに「過度で不均衡な規制上のハードル」が両社の取引解消に繋がったと公表し、特に欧州当局が取引を承認しなかったことを指摘しました。AmazonとiRobotはFTCの圧力にも直面しました。決定的な理由が何であれ、これらのレポートは、買収事案の中止件数が歴史的な上昇傾向にあること、そして、リスクの評価と配分においてブレークアップ・フィーがこれまで以上に重要であることを示しています。

石油・ガス業界の動向

石油ガス業界においては、合併が依然として活発です。当局は買収案件を精査していますが、この四半期はほとんど執行活動を行っていません。2024年4月29日、Diamondback Energyは、非公開会社である競業他社のEndeavor Energy Resourcesを260億ドルで買収する事案について、FTCから2回目の調査要請を受けました。Diamondback Energyは、株主に対し、当初の計画通り、第4四半期中に買収事案を完了する見込みであると発表しました。買収が実現すると、テキサス州を中心に、ニューメキシコ州の一部を含むパーミアン盆地で3番目に大きな石油とガスの生産者となりますが、米国のガソリン市場は非常に細分化されています。この2回目の要請は、ここ数か月の石油・ガス業界における以下の4事例に続くものです。

  • OccidentalとCrownrock は、1月に2回目の要請を受け、2024年7月18日にFTCからクリアランスを取得。
  • Chesapeake EnergyとSouthwest Energyは、4月に2回目の要請を受け、現在も進行中。
  • ChevronとHessは、1月に2回目の要請を受け、現在も進行中であり、Hessは買収案件に関連する所有権を巡ってExxonと係争中。
  • Exxon MobilとPioneer Natural Resources は、以下で詳細するように、2回目の要請の後、条件付きのクリアランスを取得。

Exxon Mobilは、2024年5月3日に、石油生産事業者であるPioneer Natural Resources を645億ドルで買収する事案を、2回目の要請を経て完了しました。FTCは、買収に関するクリアランスを説明する文書において、買収によりパーミアン盆地におけるExxonの市場シェアが倍増するとExxon自身がプレスリリースで公表していたにもかかわらず、買収による実際の利益については特に懸念を示しませんでした。FTCは、原油の分析対象となる地理的市場は世界規模であり、したがって、両者の市場シェアの合計は、2023年合併ガイドラインにおける違法性の推定(併せて30%の市場シェア)を大幅に下回るとしたものの、PioneerのCEOが談合を行ったとして、申し立てを行いました。和解では、当事者が同意判決に従うことが求められ、これによりExxonはPioneerのCEOを自社の取締役に任命することを禁じられ、Pioneerの従業員をExxonの取締役に任命することも制限されました。本件は、EQTによるQuantum Energy傘下のTug Hillの買収に関するFTCの同意判決とも類似しており、エネルギー業界におけるクレイトン法第8条の役員兼任の問題に焦点を当てた事例の一つです。

EU

不評であった欧州合併規制第22条の終焉の可能性

2024年3月21日、ニコラス・エミリウ法務官は、Illumina/Grail事件に関する見解を発表し、EU合併規制(EUMR)第22条は「キラー買収」に対処するための手段として適切ではないと指摘しました。特に、エミリウ法務官は、加盟国競争当局が国内法の下で買収計画を審査する権限を持たない場合に、欧州市場に影響を及ぼさないような企業結合を、加盟国競争当局がEU合併規則第22条に基づいて、欧州委員会(EC)に対して審査するよう付託することは認められないという見解を述べました。

そもそも、欧州委員会は、癌の早期発見のための血液検査を開発している米国のバイオテクノロジー企業であるGrailの買収計画について、Grailには欧州市場での売上がなかったにも関わらず、買収計画を審査し、これを阻止しました。そのため、当事者は、売上高が基準値に満たないものとして、欧州委員会や加盟国競争当局に対して届出をしていませんでした。

EU合併規則第22条は、歴史的には、EU加盟国がまだ独自の合併規制ルールを持っていない場合の抜け穴に対処するために導入された規定でした。欧州委員会は、この規定をより広く解釈し、(そもそも加盟国自身が合併規制を設けていない場合とは異なり)加盟国で売上高が基準値に満たない合併も審査対象としてきました。

2021年4月、欧州委員会は、フランスからの付託要請を受け入れ、これにベルギー、ギリシャ、アイスランド、オランダ、ノルウェーも参加しました。最終的に、欧州委員会は2022年9月に買収計画を禁止し、Illuminaは2023年10月にGrailを売却することを余儀なくされました。欧州委員会は、2024年4月になって、Illuminaにより実施済みのGrailの買収の解除に基づく原状回復措置に従い、IlluminaがGrailを分離する計画を承認しました。同年6月24日、IlluminaはGrailのスピンオフの完了を発表しました。

欧州一般裁判所(GC)は、これまで欧州委員会の立場を支持していました。上級裁判所に当たる欧州司法裁判所は、合併が国内法の基準値を下回るため、管轄権を持たない加盟国競争当局が、欧州委員会に付託した合併計画を、EU合併規則第22条に基づいて審査することが可能であるかを判断する必要があります。

エミリウ法務官の見解は、欧州司法裁判所に対して、独立した法的見解を提供することを目的としています。通常、欧州司法裁判所の判事は、最終判決を下す際にかかる見解を考慮に入れます。エミリウ法務官は、第22条の文言、背景、文脈、目的を考慮し、EU合併規制の論理を検討した上で、同条は加盟国が国内法の下で買収計画を審査する管轄権を持たない場合には適用できないと結論付けました。

欧州委員会によるEU合併規則第22条の解釈に基づくと、欧州委員会は、企業の売上高やEU市場内におけるプレゼンス、取引額の大きさに関係なく、世界中のほぼ全ての買収案件を事前ないし事後に審査する権限を持つことになり、合併当事者が大きな不確実性に直面することになります。エミリウ法務官の見解は法的拘束力がないため、買収計画を考案する際に第22条に基づく付託のリスクをどのように評価するかについては、欧州司法裁判所の判断を待つ必要があります。

EU合併規制に基づく審査における価格以外の指標の考慮

2024年4月、欧州委員会は、事例を挙げつつ、EU合併規制における価格以外の競争に関する競争政策の概要を発表しました。欧州委員会は、合併審査において、従来の価格効果に加えて、イノベーション、品質、データ保護、持続可能性、供給の安定性など、価格以外の競争指標も重視していると報告しました。価格効果は依然として重要ですが、水平的合併ガイドラインで規定され、EU合併規則でも認められているように、価格以外の要素も評価することによって、消費者の福祉に対する影響をより広範に把握することができます。これらの指標は、市場の定義、競争の評価、潜在的な効率性、問題解消措置とともに、合併審査プロセス全体においてケースバイケースで考慮されています。これらの重要性は、業界や取引によって異なりますが、デジタル社会とグリーン社会への移行や、その他の市場の動向により、その重要性は高まっています。

価格以外で考慮される競争指標としては以下のものがあります。

  • イノベーション特に医薬品、農薬、ハイテク業界においては、研究開発費、業界の動向、知的財産権の保護、継続的なイノベーションを通じて評価される経済的発展が重要とされます。
  • 品質と製品の差別化:差別化され価格競争が乏しい市場で重要となり、鉄鋼業や医療機器などの業界においては、耐久性、信頼性、機能性、ブランド認知などの品質面が重要とされます。
  • データ保護とプライバシー:データの管理は、競争上の優位性につながるデジタル業界とハイテク業界において重要であり、データ保護とプライバシーは品質と差別化を図るものと評価されています。

2024年5月、欧州委員会は、労働市場における競争法上の政策概要を発表しました。この政策概要では、有益なことに、問題のない取引の一例として、従業員に対する制限が直接関連し、客観的に必要であって相当な範囲にとどまる限り、企業は契約書においてノーポーチ協定(企業が互いに従業員を雇用したり勧誘したりしないことの合意)を規定することを正当化できると強調しています。ただし、政策概要では、そのような制約に同意する際には、機密保持ないし守秘義務契約が十分であるかどうかを企業側が検討し、適用対象を主要な従業員に限定する必要があることを指摘しています。

EU合併規則に基づく審査に際して正確な情報を提供するように求める欧州委員会からの注意喚起

欧州委員会は、2021年のKingspanによるTrimoの買収計画を、EU合併規則に基づいて審査していた際に、Kingspanが故意又は過失により、不正確、不完全、誤解を招く情報を提供したのではないかと疑っています。当該情報は、Kingspanの内部組織に関連する基本的な事実をはじめ、(i) 製品と地理的市場の範囲、(ii) 参入及び拡大に対する障壁の存在、(iii) イノベーションの重要性、(iv) KingspanとTrimo及び競合他社との競争の緊密性を評価するための基本的な事実に関するものでした。

最終的にKingspanは、2022年4月に買収計画を断念しました。もしも、Kingspanが故意又は過失により不正確、不完全、誤解を招く情報を提供したと欧州委員会が結論付けた場合、欧州委員会はKingspanに対して、違反1件につき、最大で同社の全世界における年間売上高の1%に相当する額の罰金を科すことができます。

英国

デジタル市場・競争・消費者法(DMCC)の施行に伴うM&A上の問題について

DMCC法は、競争・市場庁(CMA)に、新しいデジタル市場競争体制を施行する権限を付与し、戦略的市場地位(SMS)を持つと指定された企業に対して適用されます。SMSの指定は、英国に関連する少なくとも1つのデジタル活動において、実質的かつ確立された市場影響力と戦略的重要性を持つ企業に対して適用されます。SMSの基準値としては、世界全体での売上高が250億ポンドを超えるか、英国での売上高が10億ポンドを超えることが規定されています。

新しいデジタル市場競争体制の他の2つの柱(行動要件と競争への悪影響に対処するための競争促進的な介入)とともに、今回のSMS指定において、新たな合併届出要件が課されることになりました。SMSに指定された企業は、取引額が2500万ポンド以上で、英国市場との関連性がある買収計画について、取引完了前にCMAに報告しなければなりません。

この新たな合併規制体制とは別に、DMCC法では「キラー買収」に対処するために、合併当事者の事業が重複しない場合における、全業界に適用される合併規制審査の管轄権に関する基準値も新たに設定されました。CMAは、買収案件の一方の当事者が(i)英国全体又はその大部分において、商品又はサービスの33%を供給又は購入している場合、(ii)英国での売上高が3億5000万ポンドを超える場合、及び(iii)買収の他方の当事者が、英国に商品又はサービスを供給するなど英国市場との関係性を有する場合に、買収計画を審査することができます。

DMCC法は2024年5月24日に国王の裁可を受け、(新政権の優先事項によっては時期が前後する可能性もあるが)2024年秋に施行される予定です。CMAは、国王の裁可と同時に、デジタル市場競争制度のガイダンスとSMS企業を対象とする合併報告要件に関する具体的なガイダンスに関する協議を開始しました。

 

For more info on this topic, please visit Antitrust M&A Snapshot | Q2 2024 (mwe.com).

DOJ MAKES KEY REVISIONS TO CORPORATE COMPLIANCE PROGRAM GUIDANCE

By Ashley Hoff, William W. Hameline

On September 23, 2024, the US Department of Justice (DOJ) updated its Evaluation of Corporate Compliance Programs guidance (ECCP). Changes to the ECCP build on themes that the DOJ has been emphasizing for some time, including risk assessment, compliance empowerment, effective reporting structures, and continuous improvement. The most recent updates encourage companies to:

  • Manage evolving risks associated with technology, including artificial intelligence (AI);
  • Empower compliance with data and resources;
  • Ensure the organization has a speak-up culture and whistleblower protections; and
  • Learn from others, reevaluate risks, and make compliance enhancements.

WHAT’S NEW

Managing Evolving Risks Associated With Technology, Including AI

The DOJ has long expected companies to review and update their compliance programs to account for emerging risks. With this latest version of the ECCP, the department expands this concept to risks associated with the use of new and emerging technologies, including AI. The revised guidance instructs prosecutors to scrutinize how companies use AI, assess related risks, and take proactive measures to prevent AI-enabled criminal schemes.

What type of compliance risks might companies encounter when using AI and other emerging technologies? In recent remarks, Principal Deputy Assistant Attorney General Nicole M. Argentieri suggested that “false approvals and documentation generated by AI” could be used to facilitate criminal activity. Companies also risk relying on inaccurate data leveraged from untested or unreliable technologies. To protect against such risks, the DOJ expects companies to:

  • Assess and mitigate risks associated with the use of new or emerging technologies, including AI;
  • Develop and implement a governance strategy regarding the use of new technologies;
  • Implement controls to monitor and ensure that AI and similar technologies are being used for their intended purpose in compliance with applicable laws and the company’s code of conduct, and to confirm the accuracy and reliability of the data leveraged from such technologies;
  • Consider an appropriate baseline of human decision-making when using AI; and
  • Train employees on the use of AI and other emerging technologies.

While the DOJ intensifies its focus on AI, companies should consider these updates to the ECCP when implementing any novel technology solution for business or compliance purposes. This is particularly important given that the DOJ has increasingly encouraged companies to leverage data and technology in their compliance programs, as discussed below.

Empowering Compliance With Data and Resources

The DOJ views data as a powerful tool to prevent and detect misconduct. Prior versions of the ECCP encouraged the use of data to monitor and test policies, controls, and transactions. The revised ECCP heightens this focus, asking:

  • Whether compliance personnel have timely access to relevant data sources;
  • Whether the company is leveraging data analytics to create efficiencies in compliance operations and measure compliance program effectiveness; and
  • How the company is managing data quality and measuring the accuracy, precision, and recall of data analytics models.

Data is critical to facilitating testing of the compliance program, which is another focus area of the revised ECCP. For instance, the updated guidance suggests that companies should:

  • Confirm that employees know how to access relevant policies (which may involve tracking policy access or testing knowledge through surveys or other means);
  • Evaluate employees’ engagement with training content (which may involve collecting data on completion rates and comprehension);
  • Leverage data to evaluate third-party risk during the relationship; and
  • Take steps to measure the success and effectiveness of their compliance programs.

The revised ECCP also newly emphasizes “proportionate resource allocation,” which suggests that companies should empower compliance and risk management functions with the same level of technology and resources available to commercial teams.

Protecting Whistleblowers and Promoting a Speak-Up Culture

Whistleblowers are having more than a moment. Companies have raced to amend policies and procedures as the patchwork of European whistleblower laws grows and evolves in the wake of the European Union Whistleblower Directive. On this side of the pond, US government agencies continue to have success with whistleblower programs. In 2023 alone, the Securities and Exchange Commission’s whistleblower program generated more than 18,000 whistleblower tips and nearly $600 million in awards. It is, therefore, no surprise that the DOJ implemented its own Corporate Whistleblower Awards Pilot Program earlier this year to incentivize information sharing with the department. Despite being in place for less than a month, the program has already garnered tips from over 100 individuals.

Against this backdrop, the revised ECCP includes a new section titled “Commitment to Whistleblower Protection and Anti-Retaliation,” which reinforces the need to invest in a speak-up culture. Receiving internal reports of potential misconduct enables companies to investigate and stop misconduct, consider disclosure, and make compliance program enhancements. To facilitate reports, companies must establish internal reporting channels and an anti-retaliation policy. Training on internal reporting options and requirements is paramount. The revised ECCP goes further, asking:

  • Whether companies are training not just on internal reporting avenues but also on external whistleblower protection laws, whistleblower programs, and regulatory regimes;
  • Whether companies’ practices “tend to chill” reporting;
  • Whether employees involved in misconduct are treated differently based on whether they internally reported misconduct;
  • How companies “assess employees’ willingness to report misconduct”; and
  • Whether companies “incentivize reporting of potential misconduct.”

Companies should think creatively about internal reporting. If you review any company’s code of conduct, you will likely encounter a section requiring employees to report potential violations of the law, code, or policy. The DOJ’s recent updates to the ECCP call for companies to go even further.

Taking a Broad View of Lessons Learned

Companies must learn from both their own issues and those of others. The DOJ’s updates to the ECCP illustrate that companies cannot afford to have tunnel vision when determining their risk profile. Both internal and external circumstances should inform compliance programs. The revised ECCP emphasizes the importance of considering lessons learned by “other companies operating in the same industry and/or geographic region” when conducting risk assessments, designing and updating policies and procedures, and delivering tailored training.

Other Updates

  • Post-M&A integration: Compliance and risk management personnel should be involved in post-transaction integration planning. The revised ECCP asks, “Does the company account for migrating or combining critical enterprise source planning systems as part of the integration process?”
  • Third-party management: The revised ECCP instructs prosecutors to consider whether a company’s third-party management process allows for the review of vendors in a timely manner, emphasizing the need for efficiency in the process.
  • Training and communications: Echoing existing guidance, the revised ECCP emphasizes that training and communications should be tailored to the particular needs, interests, and values of relevant employees.
米司法省、企業コンプライアンス・プログラムの指針に重要な改訂を追加

By Ashley Hoff, William W. Hameline

2024年9月23日、米司法省(DOJ)は、企業コンプライアンス・プログラム評価ガイダンス (Evaluation of Corporate Compliance Programs guidance、「ECCP」)を改訂しました。 このECCPの改訂は、リスク評価、コンプライアンスの強化、効果的な報告体制、継続的な改善など、DOJが以前から強調してきたテーマに基づいています。 最新の改訂では、企業に対して以下のことを推奨しています。

  • 人工知能(AI)を含む技術に関連する進化するリスクを管理する
  • データとリソースを活用してコンプライアンスを強化する
  • 組織内に問題提起を奨励する文化と内部告発者保護を確保する
  • 他社から学び、リスクを再評価し、コンプライアンスを強化する

より深く

改訂の内容

AIを含む技術に関連する進化するリスクを管理する

DOJはかねてより、企業が新たなリスクを考慮してコンプライアンスプログラムを見直し、アップデートすることを期待してきました。ECCPの最新版では、この概念をAIを含む新技術や新興の技術の利用に伴うリスクにまで拡大しています。改訂版指針では、検察官に対して、企業によるAIの利用方法を精査し、関連リスクを評価し、AIを利用した犯罪計画を防止するための積極的な措置を講じるよう指示しています。

 

企業がAIその他の新興の技術を使用する際に直面する可能性のあるコンプライアンス上のリスクには、どのようなものがあるでしょうか。最近の発言として、ニコール・アルジェンティエリ司法次官補代理は、「AIによって生成された偽の承認や文書」が犯罪行為を容易にするために使用される可能性があると指摘しました。また、企業は、テストが済んでいない技術又は信頼できない技術から生成された不正確なデータに依存するリスクも有しています。このようなリスクから身を守るために、DOJは企業に対して、以下のことを期待しています。

  • AIを含む新技術や新興の技術の使用に関連するリスクを評価し、軽減すること
  • 新技術の利用に関するガバナンス戦略を策定し、実施すること
  • AI及び類似のテクノロジーが、適用される法律及び企業の行動規範に準拠して、意図された目的で使用されることを監視し、確保するために管理すること。また、そのようなテクノロジーから生成されるデータの正確性と信頼性を確認すること
  • AIを使用する際には、人間による意思決定の適切な基準を検討すること
  • 従業員にAIその他の新興技術の使用に関するトレーニングを実施すること

DOJがAIに焦点を絞る中、企業がビジネス目的やコンプライアンス目的で新しいテクノロジーソリューションを導入する際には、ECCPのこれらの改訂ポイントを考慮する必要があります。特に、DOJが、企業に対して、コンプライアンスプログラムにおいてデータとテクノロジーを活用するよう企業に促す傾向が強まっていることを踏まえると、この点は重要です。

データとリソースを活用したコンプライアンスの強化

DOJは、データを不正行為の防止と発見に役立つ強力なツールと見なしています。ECCPの旧バージョンでは、方針、統制、取引の監視と試験にデータを活用することが推奨されていました。改訂版ECCPでは、この点がさらに強調され、以下のことが問われています。

  • コンプライアンス担当者が関連データソースにタイムリーにアクセスできるか
  • 企業がデータ分析を活用してコンプライアンス業務の効率化とコンプライアンスプログラムの有効性の測定を行っているか
  • 企業がデータの質をどのように管理し、データ分析モデルの正確性、精度、再現性をどのように測定しているか

データはコンプライアンスプログラムのテストを円滑に進める上で極めて重要であり、改訂版ECCPのもう一つの重点分野となっています。例えば、改訂版指針では、企業は以下を行うべきであると提案しています。

  • 従業員が関連する方針にアクセスする方法を知っていることを確認する(方針へのアクセスを追跡したり、アンケートその他の手段で知識をテストしたりすることが考えられます。)
  • 従業員の研修コンテンツへの取り組みを評価する(研修修了率や理解度に関するデータを収集することが考えられます。)
  • 第三者との関係が継続している間、データを活用して第三者のリスクを評価する
  • コンプライアンスプログラムの成功と有効性を測定するための措置を講じる

改訂版ECCPでは、新たに「適切なリソースの割り当て」も強調されており、企業は、営業部署が利用できるものと同レベルのテクノロジーやリソースをコンプライアンス及びリスク管理機能を担う部署に提供すべきであると示唆しています。

内部告発者の保護と「スピークアップ」文化の促進

内部告発者は注目を集めています。EU内部告発者保護指令を受けて、欧州の内部告発者保護に関する法律が急増し、進化する中、企業は方針や手続の改訂を急いでいます。一方、米国では政府機関が内部告発者保護プログラムで引き続き成果を上げています。2023年だけでも、証券取引委員会の内部告発プログラムには18,000件以上の内部告発による通報があり、報奨金は6億ドル近くに上りました。そのため、DOJが今年初めに、同省への情報共有を奨励するための独自の企業内部告発報奨金パイロットプログラムを実施したことは驚くことではありません。 開始から1か月も経っていないにもかかわらず、このプログラムにはすでに100人以上の個人から通報がありました。

 

こうした背景から、改訂版ECCPには「内部告発者保護と報復禁止への取り組み」と題された新しいセクションが追加され、内部告発を奨励する企業文化への投資の必要性が強調されています。 企業は、不正行為の可能性に関して内部報告を受けることによって、不正行為の調査と阻止、情報開示の検討、コンプライアンスプログラムの改善を行うことができます。 報告を促進するために、企業は内部報告ルートと報復禁止方針を確立する必要があります。 内部報告の選択肢と要件に関する研修は最も重要です。改訂版ECCPでは、さらに踏み込んで、以下のことが問われています。

  • 企業が内部報告経路だけでなく、外部の内部告発者保護法、内部告発者プログラム、規制体制についても研修を行っているかどうか。
  • 企業の慣行が「報告を抑制する傾向」があるかどうか。
  • 不正行為に関与した従業員が、内部報告を行ったかどうかによって異なる扱いを受けているかどうか。
  • 企業が「従業員の不正行為を報告する意思」をどのように評価しているか。
  • 企業が「不正行為の可能性を報告することを奨励している」かどうか。

企業は内部報告について創造的に考える必要があります。 企業の行動規範を調べると、多くの場合、法律、規範、方針の違反の可能性を報告するよう従業員に義務付ける条項が記載されています。 DOJによる最近のECCPの改訂では、企業に対してさらに踏み込んだ対応が求められています。

幅広い観点から教訓を学ぶ

企業は、自社の問題だけでなく他社の問題からも学ぶ必要があります。DOJによるECCPの改訂は、企業がリスクプロファイルを判断する際に、視野を狭めてはならないことを示しています。社内及び社外の状況の両方を考慮してコンプライアンスプログラムを策定する必要があります。改訂版ECCPでは、リスク評価の実施、方針及び手続の策定と更新、カスタマイズされた研修の実施にあたり、「同じ業界又は地域で事業を展開する他社」の教訓を考慮することが重要であることが強調されています。

その他の改訂

  • M&A後の統合:コンプライアンス及びリスク管理担当者は、取引後の統合計画に関与する必要があります。改訂版ECCPでは、「企業は、統合プロセスの一環として、重要なエンタープライズ・ソース・プランニング・システムの移行又は統合を考慮しているか」が問われています。
  • サードパーティの管理:改訂版ECCPでは、企業のサードパーティ管理プロセスがベンダーの適時の見直しを可能にするものであるかを考慮するよう、検察官に指示しています。

トレーニングとコミュニケーション:改訂版ECCPでは、既存の指針を踏襲し、トレーニングとコミュニケーションは、関連する従業員の特定のニーズ、関心、価値観に合わせて行うべきであることを強調しています。

Autoren

Simon Roberts

Partner

New York — One Vanderbilt Avenue

Jason Leonard

Partner

New York — One Vanderbilt Avenue

Sharon Lamb

Partnerin

London – 22 Bishopsgate

Sabine Naugès

Partnerin

Paris

Raminta Dereskeviciute

Partnerin

London – 22 Bishopsgate

Michal Chajdukowski

Rechtsanwalt

London – 22 Bishopsgate

Mary Hecht

Rechtsanwältin

Paris

Jon B. Dubrow

Partner

Washington, DC

Joel R. Grosberg

Partner

Washington, DC

Stéphane Dionnet

Partner

Brüssel

Graham J. Hyman

Law Clerk

New York — One Vanderbilt Avenue

Max Küttner

Rechtsanwalt

Düsseldorf

Ashley Hoff

Counsel

Austin

William W. Hameline

Rechtsanwalt

Chicago

Aktuelles