On 17-18 September 2026, the Western Europe Business and Human Rights Forum convened at the Council of Europe in Strasbourg, delivered with the support of the UN Working Group on Business and Human Rights. Governments, companies, investors, academics and civil society gathered around a shared observation: human rights risks are intensifying on several fronts at once — artificial intelligence, climate, conflict, and a shrinking regulatory ambition — even as the legal framework meant to contain them is being scaled back. For companies, this combination creates a double bind: protecting their assets and reputation while staying compliant with the “respect” pillar of the UN Guiding Principles. Here is what was discussed in Strasbourg, and what it means in practice.
Human rights risks rising on every front
The forum’s throughline, set out in the opening plenary, could be summed up in one sentence: companies now operate in an environment where threats to human rights are no longer confined to isolated regions or sectors, but spread across them. The opening plenary made this point concrete from the outset. Carolina Rudnick, of the Libera Foundation (Chile), used her own country as an example to show that a regulatory vacuum does not free companies from risk — it merely relocates it: the absence of a binding framework on human trafficking and forced labour, she argued, directly worsened human rights abuses rather than creating room for businesses to manoeuvre. A similar thread ran through the exchanges with investors present in Strasbourg: their growing number of questions about companies’ exposure to human rights risk signals that mitigating these risks is now a shared interest between business and finance — a sign that human rights due diligence is no longer just a compliance matter, but increasingly a capital-allocation one too.
The session on artificial intelligence echoed the same logic. AI systems, panellists noted, can amplify bias in hiring and lending decisions, undermine data protection, and enable forms of surveillance that are hard to contest — while also opening real opportunities for inclusion and access to services. The OHCHR’s B-Tech project, which has spent several years helping technology companies apply the Guiding Principles to their business models, served as a reference point for these discussions, in line with the work Ksapa has documented on how human rights are becoming a new pillar of risk management for organisations.
Climate occupied an equally central place. The session “Integrating Climate Action and Human Rights” put a direct question to participants: should companies apply genuine human rights due diligence to the human impacts of climate change, on the same footing as other risks identified across their value chains? The consensus in Strasbourg was that climate change is no longer only an environmental issue, but a structural factor shaping livelihoods and community resilience — and therefore a human rights issue in its own right. This reading aligns with Ksapa’s earlier work on investors at the frontline of human rights, which already documented how climate and social vulnerability feed directly into financial portfolios.
That convergence between human rights and climate is no longer a theoretical debate for the regulators who were in Strasbourg. Professor Maria Gavouneli, of the Greek National Commission for Human Rights, summed up the view shared by many regulators in the room: integrating climate into human rights due diligence is now, in her words, a no-brainer — no longer up for debate. Private finance struck the same note. Lea Juliussen, of Danske Bank, pointed out that a private bank does not operate on a general-interest logic, yet sound risk management and the proper execution of its mandates now effectively require folding these climate and human rights risks into its risk-management framework — no longer an option, but a requirement. That convergence has a very concrete echo in recent case law. Sébastien Duyck, of the Center for International Environmental Law (CIEL), noted that courts in the UK, Germany, Switzerland, France and several other countries have, over the past 24 months, issued landmark rulings bringing scope 3 emissions within the scope of corporate responsibility and duty-of-care obligations — a development he called decisive. The 25 June 2026 ruling by the Paris Judicial Court against TotalEnergies, which brought scope 3 emissions within the scope of France’s duty-of-vigilance law for the first time, illustrates that trend, as does Germany’s Higher Regional Court of Hamm, which ruled in May 2025 that major emitters can, in principle, be held liable for climate-related harm.
The geopolitical dimension was not sidestepped either. A session on “Responsible Disengagement and Re-Engagement in Conflict-Affected Areas” examined the conditions under which a company can responsibly withdraw from — or re-enter — a conflict-affected market, accounting for the interests of local communities, the role of investors, and the need for heightened due diligence. These exchanges, echoed in OHCHR’s reference publication on the Guiding Principles, are a reminder that a deteriorating geopolitical context is no longer a peripheral risk but a core parameter of supply-chain management.
What set this year’s forum apart is that these dynamics — technological, climatic, geopolitical — were not presented as separate topics, but as risks that reinforce one another, to be addressed in an integrated way rather than in silos.
A regulatory framework retreating just as risks rise
The forum’s central paradox sat in its session on “The UNGPs in the current moment” and the panel on “Policy coherence”: just as risks intensify, European regulatory ambition is contracting. After more than a decade of expanding due-diligence legislation — the French duty of vigilance law adopted in 2017, followed by Germany’s LkSG, Norway’s Transparency Act and the UK’s Modern Slavery Act — that trend has reversed. The UN Guiding Principles, unanimously endorsed by the Human Rights Council in June 2011, established a three-pillar architecture — the state duty to protect, the corporate responsibility to respect, and access to remedy — that underpinned this legislative wave.
It is precisely that foundation the EU’s “Omnibus I” package has redrawn. Formally adopted on 24 February 2026 and published in the EU Official Journal on 26 February as Directive (EU) 2026/470, the text substantially amends both the Corporate Sustainability Due Diligence Directive (CSDDD) and the Corporate Sustainability Reporting Directive (CSRD). According to legal analyses, the CSDDD’s scope has narrowed — obligations now apply only to companies above significantly raised employee and turnover thresholds — while civil liability and penalties have been eased and application deadlines pushed back, a substantial simplification confirmed by several law firms that tracked the negotiation closely. EU institutions justify these revisions as necessary to cut administrative burden and strengthen the competitiveness of companies in the internal market.
That reading was not shared by every business voice at the opening plenary, however. Guillaume Schoebel, of Schneider Electric, made the opposite case: what companies need first is not fewer rules, but predictable, harmonised rules across jurisdictions. For a group operating in multiple countries, the regulatory fragmentation created by asymmetric revisions to the law often costs more — in uncertainty and compliance complexity — than keeping a single, stable framework would. It is an argument that complicates the assumption that lighter regulation automatically means lower risk for business.
The German government’s voice added another dimension to the debate. Dr Carsten Stender, of Germany’s Federal Ministry of Labour and Social Affairs, reminded the room that Germany, through its own history, knows better than most what it costs a country to install a regime that denies human rights. For him, respecting the Guiding Principles is not one constraint among others but the peaceful foundation on which lasting prosperity rests — a foundation that necessarily extends to supply chains: the comfort of some cannot rest on the child labour of others. He nonetheless confirmed that Germany’s own due-diligence law (LkSG) will also be revised, to refocus on a risk-based approach and on genuinely material issues rather than on an exhaustive list of documentary obligations.
Law firms that followed the negotiation stress that the text was not abandoned but simplified relative to its original ambition: the CSDDD still requires companies to identify, assess and address actual and potential harms to human rights and the environment across their operations and value chains, but for a much narrower set of companies and with compliance now due by 2029. Other observers note that the revision of the European reporting standards (ESRS) is still being finalised by EFRAG, leaving persistent uncertainty over companies’ concrete obligations in the coming months — an uncertainty several forum sessions flagged as a risk in its own right, distinct from human rights risk itself.
That was exactly the concern behind the “Policy coherence” panel: EU deregulatory initiatives risk fragmenting the global business-and-human-rights regulatory landscape, with consequences that extend beyond EU borders and reshape how responsible business conduct norms develop elsewhere. Ksapa had already made a similar point in its comparative analysis of European and US due-diligence practice: lighter regulation has never, in practice, translated into lower risk for companies — only into risk that is less well anticipated.
What this means for business
For legal, risk and sustainability functions, Strasbourg’s combination of rising risk and receding regulatory ambition should not be read as a signal to relax. If anything, the sessions on accountability and enforcement pointed to the opposite conclusion, for at least four reasons.
First, because narrowing the EU’s regulatory scope removes neither operational risk nor stakeholder expectations. The “Accountability and Enforcement” session noted that civil liability mechanisms, national supervisory authorities and extraterritorial liability regimes keep evolving independently of the EU’s own timeline, and that fragmented enforcement across countries is itself a source of legal uncertainty for multinationals. In other words, a company that falls outside the revised CSDDD’s direct scope remains exposed through other jurisdictions, its own voluntary commitments, or the expectations of its investors and customers. That is the case Ksapa has long made: human rights due diligence remains a manageable risk for companies, provided it is treated as a structured risk-management exercise rather than a box-ticking compliance one.
Second, because the gap between stated commitment and actual practice remains stark. Ingrid Elbertse, of Fair Wear, put it bluntly: companies today remain committed mainly on a voluntary basis — a state of affairs she called simply not serious given the scale of the risks at stake. Nadia Youds, of Unilever, offered a different lens to move past that impasse: stop measuring resources deployed or how much “more” is being done, and start reasoning in terms of effectiveness — the quality of decision-making processes, risk assessment and impact measurement. When regulators ask for paperwork, she warned, companies can produce it easily without that necessarily moving the needle on real effectiveness; but once the conversation shifts to measuring the relevance of the measures taken against actual risks, it becomes a different discussion entirely — and the one that actually matters.
Third, because the “respect” pillar of the Guiding Principles — the one that falls directly on companies, regardless of any legal obligation — remains fully applicable whatever happens to binding European texts. The corporate responsibility to respect human rights under the Guiding Principles does not depend on national or regional law: it is a standard of conduct expected everywhere a company operates, regardless of how strict the local legal framework is. Several speakers in Strasbourg stressed that lighter legal obligations do nothing to lower societal expectations — and therefore the reputational and operational risk — facing companies that neglect their due diligence. That is also the logic behind Ksapa’s work helping companies get ahead of regulatory compliance rather than waiting for the law to force their hand.
Fourth, because protecting a company’s assets — physical assets in conflict zones, brand assets exposed to AI controversies, financial assets exposed to climate risk — and complying with human rights frameworks are no longer separate concerns, but two faces of the same exposure. The forum devoted a full session to the role of external providers in due diligence, noting that the growing reliance on third parties to run this work requires clear competence criteria, or risks widening the gap between perceived and actual effectiveness. On this front, dialogue between companies and stakeholders — including mediation formats rather than systematic litigation — is gaining ground, as shown by Ksapa’s work with companies, unions and civil society organisations on alternatives to litigation.
The takeaway
Strasbourg did not settle the question of whether the 2011 Guiding Principles still meet today’s challenges — that was, after all, the explicit subject of “The UNGPs in the current moment” session. But it clarified one point: the retreat in European regulatory ambition embodied by Omnibus I coincides with a period in which human rights risks — AI, climate, conflict — are rising significantly. Companies that read this moment as an opening to relax expose themselves twice over: to asset losses in increasingly unstable contexts, and to a lasting compliance gap against a responsibility pillar that shows no sign of retreating. Those that instead keep their due diligence robust — irrespective of which regulatory threshold applies to them — turn a constraint into an advantage of stability and trust, which speakers closing the forum described as the one condition for sustainable business conduct in a more uncertain world.
Magnific Free License Visual
CEO and Co-Founder of Ksapa. Member of sustainability boards at major industrial groups and impact investment committees. Drawing on 25 years of experience working with multinationals, mid-size and small businesses across value chains, governments, and international organizations, Farid Baddache focuses on integrating human rights, climate, and ESG governance as drivers of business resilience and competitiveness. Author of several books on sustainability and responsible business. Connect on Bluesky @faridbaddache.bsky.social


