Key data
| Regulation | Implementing Regulation (EU) 2026/1960 — 359th amendment to Regulation (EC) 881/2002 |
|---|---|
| Publication | August 21, 2026 |
| Entry into force | August 22, 2026 |
| Affected parties | Financial institutions, banks and EU companies obliged to apply counter-terrorism sanctions |
| Category | European Regulation |
| Updated records | 3 natural persons |
| Origin of changes | Decisions by the UN Security Council Sanctions Committee (August 13 and 14, 2026) |
Banks, insurance companies, fund managers and any company conducting international transactions must update their control lists from August 22, 2026. Implementing Regulation (EU) 2026/1960, published on August 21, amends for the 359th time Council Regulation (EC) 881/2002, incorporating changes in three records of persons subject to asset freezing due to their links with Daesh (ISIL) and Al-Qaeda.
The changes respond to decisions adopted on August 13 and 14, 2026 by the Sanctions Committee of the United Nations Security Council, and are directly applicable in all EU Member States without the need for national transposition.
What does this regulation establish?
Regulation (EC) 881/2002 is the European framework that imposes asset freezing and economic resources on persons and entities linked to Daesh and Al-Qaeda. Its Annex I contains the complete list of affected parties. This 359th amendment updates the identifying data of three persons already included in that list, which requires operators to refresh their control systems with the most current information.
The data updated in the records includes: new aliases, new addresses and new passport data. These changes are relevant because screening systems must recognize all possible identities of a sanctioned individual to block any transaction.
| Sanctioned person | Known alias | Updated data |
|---|---|---|
| Mohammed Salahaldin Abd El Halim Zidane | Sayf-Al Adl | New aliases, addresses and passport data |
| Adem Yilmaz | — | New aliases, addresses and passport data |
| Shafi Sultan Mohammed Al-Ajmi | — | New aliases, addresses and passport data |
The regulation is directly applicable in all Member States from August 22, 2026, with no room for adaptation or transitional period.
Economic and operational impact
The direct impact is not a new cost, but a compliance risk with serious economic and reputational consequences. Sanctions for operating with persons included on the EU list may include high administrative fines, license suspension and irreversible reputational damage.
The real operational cost falls on compliance teams: they must manually or through automatic integration update the data of the three modified records in their screening tools. For entities with automated systems connected to sanctions list providers (such as World-Check, Dow Jones Risk or equivalents), the update can be transparent. For operators with manual processes, the risk of lag is greater.
The volume of amendments to Regulation 881/2002 — already in its 359th amendment — reflects the frequency with which the EU reviews these lists. Companies that do not have automated update processes accumulate risk with each new amendment.
Who does it affect?
- Banks and credit institutions with screening obligations in payment operations, account opening and credit granting.
- Investment service companies and fund managers that must verify the identity of counterparties.
- Insurance companies with exposure to international clients or beneficiaries.
- Money transfer companies and fintech subject to AML/CFT regulations.
- Economic operators with international activity (exporters, importers, companies with subsidiaries in third countries) that must verify their commercial counterparties.
- Compliance departments and compliance officers in any company required by money laundering prevention and terrorist financing regulations.
Practical example
A Spanish bank receives an international transfer order in the name of a customer whose passport matches one of the documents updated in the record of Mohammed Salahaldin Abd El Halim Zidane (alias Sayf-Al Adl). If the bank's screening system has not incorporated the new passport data published on August 22, 2026, the transaction could pass automatic filters without being blocked.
The result: the bank would have executed an operation with a sanctioned individual, incurring a violation of Regulation (EC) 881/2002 regardless of whether there was intent or knowledge. Responsibility is objective: the operator must ensure that its systems are updated. That is why the immediate update of the records is not optional.
What should companies do now?
- Immediately update screening systems with the new aliases, addresses and passport data of the three modified records (Mohammed Salahaldin Abd El Halim Zidane, Adem Yilmaz and Shafi Sultan Mohammed Al-Ajmi).
- Verify if the sanctions list provider has already incorporated the changes: contact the provider (World-Check, Dow Jones, Refinitiv or others) to confirm that the August 22, 2026 update is reflected.
- Review pending or ongoing operations involving counterparties with names, aliases or documents that may match the updated data.
- Document the update in the compliance record, with date and responsible party, as evidence before a potential regulatory inspection.
- Alert onboarding and KYC teams to apply the new data in customer registration processes and periodic review of business relationships.
Frequently asked questions
Which persons have been updated on the EU sanctions list in August 2026?
The three updated records correspond to: Mohammed Salahaldin Abd El Halim Zidane (alias Sayf-Al Adl), Adem Yilmaz and Shafi Sultan Mohammed Al-Ajmi. In all cases, new aliases, new addresses and new passport data have been incorporated in Annex I of Regulation (EC) 881/2002.
When is it mandatory to apply the changes of Implementing Regulation (EU) 2026/1960?
The regulation entered into force on August 22, 2026, one day after its publication (August 21, 2026). It is directly applicable in all EU Member States without the need for transposition or transitional period. There is no room for adaptation.
What happens if my company conducts a transaction with a person included on the sanctions list?
Operating with persons included in Annex I of Regulation (EC) 881/2002 constitutes a violation of EU counter-terrorism sanctions, regardless of whether there was intent. The consequences may include administrative fines, license suspension and irreversible reputational damage. Responsibility is objective: the operator must ensure that its systems are updated.
Why is the list of sanctioned individuals linked to Daesh and Al-Qaeda updated so frequently?
The list is updated each time the UN Security Council Sanctions Committee adopts new decisions. This amendment — the 359th to Regulation (EC) 881/2002 — responds to decisions adopted on August 13 and 14, 2026. The frequency of changes makes it essential to have automated update systems.
Where can I consult the complete list of persons and entities sanctioned by the EU for links with Daesh and Al-Qaeda?
The complete list is found in Annex I of Regulation (EC) 881/2002 and its successive amendments, published in the Official Journal of the EU (EUR-Lex). The most up-to-date consolidated version includes all changes to date, including those introduced by Implementing Regulation (EU) 2026/1960.
Official source
Consult complete regulation in official source
Disclaimer: This article is for informational purposes only and does not constitute legal advice. For specific decisions, consult a qualified professional. Source: https://eur-lex.europa.eu/./legal-content/AUTO/?uri=CELEX:32026R1960