European compliance is not one conversation. It is four simultaneous conversations happening in four different regulatory languages, each with its own enforcement body, its own penalty regime, and its own specific implications for Australian and New Zealand firms operating in the EU. The food company faces the General Food Law, the Farm to Fork Strategy, and the weight of EFSA certification. The tech company faces GDPR, the AI Act, NIS2, and the Cyber Resilience Act. The innovation organisation faces the transformed landscape of Horizon Europe — a landscape that has changed fundamentally for ANZ entities in the past two years. And the defence contractor faces the new EDIP architecture, with its 65% EU-origin component rule and its explicit preference for entities established and managed within EU borders. This handbook covers all four. Not as a legal treatise — as an operational guide for ANZ executives who need to know what applies to them, what the deadlines are, and where the real risks sit.
The Four Compliance Domains at a Glance
Food Safety
Digital
Horizon Europe
EDIP
Chapter 1: Alimentary — What the EU Actually Requires from ANZ Food Companies
The EU food safety framework is the most complete and demanding food regulatory system in the world, and it applies to every product placed on the EU market — regardless of where it was manufactured. For ANZ food and agrifood companies selling into Europe through a Spanish or other EU entity, compliance is not optional and it is not negotiable. The key is understanding that the EU framework is risk-based, outcome-oriented, and enforced at the point of sale rather than exclusively at the border.
Every food business operator (FBO) placing food on the EU market is legally responsible for the safety of that food. The General Food Law establishes the principle of primary responsibility at the FBO level — not at the customs level, not at the retailer level. This means that an ANZ company selling food products through a Spanish distribution entity must ensure that those products comply with EU safety standards across their entire supply chain, from primary production to final sale. The regulation requires full traceability (one step back, one step forward), mandatory recall systems, and immediate notification to competent authorities for products that may present a risk to public health.
All food sold in the EU must carry labels in the official language(s) of the member state(s) where it is sold. For Spain, this means Spanish. Required information includes: product name, ingredients list in descending order of weight, allergen highlighting (14 major allergens must appear in bold or contrasted typography), net quantity, best-before or use-by date, storage conditions, name and address of the EU food business operator responsible for the product, country of origin for meat, poultry, fish, honey, olive oil, and fresh fruit and vegetables, nutritional declaration (per 100g/100ml), and alcohol content for beverages above 1.2% ABV. Non-compliance at the labelling level is the most common and most avoidable EU food compliance failure for non-EU companies.
Any food or food ingredient without a significant history of safe consumption in the EU before 15 May 1997 is classified as a novel food and requires pre-market authorisation from EFSA (European Food Safety Authority) before it can be sold in the EU. For ANZ agrifood innovators — particularly in plant-based proteins, functional ingredients, insect protein, precision fermentation products, and novel bioactive compounds — this is the most commercially significant regulatory hurdle. The novel food authorisation process typically takes 18–36 months and requires a comprehensive dossier demonstrating safety. Spain’s AgriFoodtech Regulatory Sandbox, however, provides a testing and validation environment where novel food technologies can be piloted under regulatory supervision before the full EFSA authorisation process, significantly reducing time-to-market risk.
The AU–EU FTA concluded in March 2026 eliminates import duties on 97.8% of Australian goods at entry into force. For ANZ food exporters, this removes the tariff barriers that previously made some product categories commercially unviable in the EU market. Combined with the NZ–EU FTA (in force since May 2024), both ANZ countries now enjoy preferential tariff access to the EU market that materially improves the landed cost competitiveness of their food products relative to non-FTA suppliers.
Chapter 2: Tech — The EU Digital Regulatory Stack Every ANZ Company Must Navigate
The EU has built the world’s most comprehensive digital regulatory framework. By mid-2026, tech companies operating in or targeting EU markets face an interconnected web of compliance obligations that is not a single law but a layered system. For ANZ tech companies operating through a Spanish entity, these obligations apply in full from day one of EU operations — there is no grace period for foreign companies, no phased application for SMEs, and no geographic exemption for companies headquartered outside the EU. The extraterritorial reach of every regulation in the stack is explicit.
The General Data Protection Regulation has been in full force since May 2018 and remains the foundation of EU data compliance. For ANZ tech companies, the critical principle is extraterritoriality: any company offering goods or services to EU residents, or monitoring their behaviour, is in scope regardless of where the company is headquartered. Operating through a Spanish SL makes GDPR obligations immediate, direct, and enforced by the Spanish Data Protection Authority (AEPD). Core obligations include: lawful basis for every processing activity, privacy-by-design and privacy-by-default in product architecture, data subject rights (access, rectification, erasure, portability), mandatory Data Protection Impact Assessments for high-risk processing, 72-hour breach notification to the AEPD, and Data Processing Agreements with all third-party processors. Fines reach €20M or 4% of global annual turnover, whichever is higher. Between May 2018 and December 2025, EU data protection authorities imposed 2,086 fines totalling over €4.5 billion.
The EU AI Act (Regulation EU 2024/1689) entered into force on 1 August 2024 and phases in obligations through 2027. For ANZ tech companies, three deadlines are operationally critical. Since 2 February 2025: prohibited AI practices are banned — social scoring by public authorities, emotion recognition in workplaces, and subliminal manipulation are already illegal across the EU. Since 2 August 2025: General Purpose AI (GPAI) model obligations are live — providers of foundation models must meet transparency, copyright, and documentation requirements immediately. For high-risk AI systems (recruitment tools, credit scoring, medical devices, law enforcement, education): the original deadline of 2 August 2026 has been deferred to 2 December 2027 under the EU AI Act Omnibus political agreement of 7 May 2026 — but until formal adoption, the original date remains legally binding. Maximum penalties: €35M or 7% of global annual turnover for prohibited practice violations — exceeding GDPR’s 4% cap. The AI Act applies to any organisation whose AI systems affect EU users, regardless of location.
The NIS2 Directive, in effect since 18 October 2024, covers an estimated 160,000 entities across 18 sectors and imposes mandatory obligations on cybersecurity risk management, incident reporting, supply chain security, and senior management accountability. For ANZ tech companies operating in or serving critical sectors — energy, transport, health, financial services, digital infrastructure, and manufacturing — NIS2 compliance is not optional. Senior management can be held personally liable for non-compliance. Incident reporting to national authorities is required within 24 hours for significant incidents and 72 hours for full reports. Spain’s NIS2 implementing legislation designates INCIBE (National Cybersecurity Institute) as the primary competent authority for private sector entities.
The Cyber Resilience Act entered into force in December 2024 and imposes mandatory cybersecurity standards for all software and hardware products with digital elements sold in the EU. Reporting obligations apply from 11 September 2026, with full compliance required by 11 December 2027. For ANZ companies in IoT, connected devices, industrial software, and any hardware product sold to EU customers, this means mandatory vulnerability management programmes, security-by-design requirements, and mandatory reporting of actively exploited vulnerabilities to ENISA within 24 hours of discovery.
Chapter 3: Innovation — The Horizon Europe Window That Changes Everything for ANZ
This is the chapter that most ANZ research organisations, universities, and deep tech companies have not yet fully processed — because the change happened quietly and its commercial implications are profound. Horizon Europe, the EU’s flagship research and innovation programme with a total budget of €93.5 billion for 2021–2027, has historically been the exclusive domain of EU member states and a small number of associated countries. That exclusivity is ending for ANZ organisations — and the timeline matters enormously.
Since July 2023, New Zealand has been formally associated with Pillar 2 of Horizon Europe — the Global Challenges and European Industrial Competitiveness pillar, which covers the vast majority of collaborative research funding including health, digital, industrial, climate, energy, mobility, food, and security themes. This association means that New Zealand researchers and organisations participate in Horizon Europe on terms virtually identical to EU member state organisations. They can apply for funding independently, lead research consortia, receive EU grant money directly, and count toward the minimum consortium composition requirements. This is not a preferential access arrangement — it is full operational parity with EU partners. New Zealand organisations that have not yet integrated Horizon Europe into their European expansion strategy are leaving a material funding opportunity on the table.
Australia concluded its negotiations for Horizon Europe Pillar 2 association in 2026. From January 2027, Australian entities will transition from “third country” status — where participation was possible but limited and required host country approval — to full associated country status with direct, equal-terms access to EU research funding. Crucially, Australian organisations will gain the ability to lead Horizon Europe consortia from January 2027, a right previously reserved for EU member states and associated countries. This changes the strategic calculus for Australian universities, research organisations, and deep tech companies planning European operations: a Spanish entity established in 2026 will be fully positioned to lead Horizon Europe applications from January 2027, accessing EU grant funding that was structurally unavailable six months earlier.
Participation in Horizon Europe grants carries specific compliance obligations that ANZ organisations must understand before applying. All grant beneficiaries must: register in the EU Participant Register and obtain a Participant Identification Code (PIC); comply with open access requirements for publications and, where applicable, research data; adhere to research integrity standards including the European Code of Conduct for Research Integrity; manage intellectual property in accordance with the grant agreement’s IP chapter, which governs ownership, protection, and access rights for results; and report financial and scientific progress according to the Commission’s monitoring and reporting framework. For ANZ organisations with no prior EU grant experience, these obligations are manageable but require proper administrative infrastructure — typically a dedicated grants management function or an experienced European research partner.
The strategic window for ANZ organisations: An Australian deep tech company or university that establishes a Spanish entity in 2026, builds its Horizon Europe consortium relationships during the second half of 2026, and submits its first Horizon Europe consortium application in January 2027 as a newly associated country organisation will be positioned to access EU research funding that was structurally unavailable 12 months earlier. This is a first-mover window with a measurable opening date. The organisations that act before January 2027 will have the relationship infrastructure in place when the door opens. Those that wait will find that the best consortium slots are already taken.
Chapter 4: Defence — What EDIP Means for ANZ Contractors and the 65% Rule
The European Defence Industry Programme (EDIP), formally adopted on 8 December 2025 and in force with a €1.5 billion budget for 2025–2027, represents the most significant restructuring of EU defence procurement since the Lisbon Treaty. For ANZ defence contractors evaluating European market entry, EDIP is simultaneously the largest opportunity in European defence for a generation and the most carefully bounded programme they will encounter. Understanding its eligibility rules is not optional — it is the difference between accessing EU defence procurement and being structurally excluded from it.
For a defence product to be eligible for EDIP funding, at least 65% of the total cost of its components must originate from EU member states or associated countries (members of the European Economic Area). This rule applies at the product level, not the company level. An ANZ defence company that manufactures products with significant non-EU supply chain content — Australian-sourced materials, New Zealand-manufactured components, or components from any non-EEA third country — must restructure its supply chain to meet the 65% threshold before its products qualify for EDIP-funded procurement. This is not an administrative hurdle: it is a structural supply chain redesign challenge that requires lead time, investment, and often partnership with EU-based Tier 1 and Tier 2 suppliers. ANZ contractors that start this process in 2026 will be positioned for EDIP’s first major procurement calls closing in October 2026 and February 2027.
Companies benefitting from EDIP financial support must be established in the EU and have their executive management structures in the EU. They must also use infrastructure, facilities, assets, and resources located in the EU. This rule has a direct structural implication for ANZ defence contractors: participation in EDIP as a prime contractor or direct grant beneficiary requires a genuine EU entity — not a mailbox company, not a representative office, not a branch with nominal local staff. A Spanish SL with a real management team, genuine operational infrastructure, and EU-based decision-making authority is the minimum threshold. This requirement simultaneously explains why the softlanding sequence matters: the entity established for EDIP eligibility must be operationally genuine, which requires the correct incorporation, staffing, and governance structure from day one.
EDIP includes the Fund Accelerating Defence Supply Chains Transformation (FAST), which specifically targets SMEs and mid-sized companies using blended financial instruments including loans, equity, and guarantees. FAST is designed to accelerate the investment that SMEs and scale-ups need to participate in EU defence supply chains — production capacity expansion, technology certification, interoperability upgrades, and manufacturing capability development. For ANZ defence SMEs with relevant capabilities in autonomous systems, cybersecurity, sensor technology, counter-drone systems, or maritime domain awareness, FAST provides a financing pathway that does not require the scale of a Tier 1 prime contractor. The first FAST calls are expected in Q4 2026.
The EU–Australia Security and Defence Partnership, signed simultaneously with the AU–EU FTA in March 2026, creates a formal framework for defence industrial cooperation that goes beyond standard third-country arrangements. While EDIP’s 65% rule and EU establishment requirement still apply to direct funding eligibility, the Partnership creates structured pathways for Australian defence technology to enter EU supply chains as subcontractors to EU prime contractors — a route that does not require the same level of EU establishment as direct EDIP grant participation. For ANZ defence companies with specialised capabilities that EU primes need but currently source outside the EU, the Partnership provides the diplomatic and commercial framework for these subcontracting relationships to be formalised and expanded.
The Cross-Cutting Compliance Principle: Establish First, Then Navigate
Across all four compliance domains, a single structural principle emerges: the EU regulatory framework is designed for entities established within the EU. It can apply extraterritorially — and it does — but its benefits, funding programmes, regulatory sandboxes, and preferential treatment mechanisms are structured around EU-based operators. An ANZ company attempting to navigate EU food safety certification, AI Act compliance, Horizon Europe participation, and EDIP eligibility from an offshore base without an EU entity will find that every pathway is harder, slower, and more expensive than the same journey made from a genuine EU presence.
The Spanish entity is not merely the operational base for selling into the EU market. It is the compliance infrastructure that makes the full range of EU regulatory participation possible: the food business operator registration that enables EU market access, the data controller registration with the AEPD that anchors GDPR compliance, the Participant Identification Code that enables Horizon Europe applications, and the EU establishment that satisfies EDIP’s management structure requirement. These four compliance anchors are not separate infrastructure items. They are four functions of a single, correctly structured Spanish entity.
Related reading: The Strategic Fortress: Why ANZ Tech, Food and Defence Firms Choose Spain as Their European Base | The 2026 Spain Softlanding Blueprint for ANZ Scale-Ups and Defence Contractors | Germany Economy 2026: Europe’s Most Underrated Consumer Market | Japan Economy 2026: The Ageing Economy and Irreversible Demand
Four compliance domains. One conversation.
Let’s map yours.
Gedeth Network helps ANZ firms navigate EU regulatory requirements across food safety, digital compliance, Horizon Europe participation, and EDIP defence procurement. Book a free 45-minute session and walk away knowing exactly which regulations apply to your company, what your deadlines are, and what your Spanish entity needs to look like to access the full EU compliance infrastructure.
📅 Book Your Free Compliance Session Tailored to your sector and ANZ company profile. Response within 24 hours.