Friday, August 28, 2026

July 2026 Cyberattacks Put U.S. Municipal Water And Wastewater Security In Focus – Analysis



August 28, 2026

the Congressional Research Service (CRS)

By Elena H. Humphreys


Key Takeaways:

After July 2026 cyber incidents at water systems in at least seven states, this CRS brief reviews EPA’s Safe Drinking Water Act tools: larger community systems must self-certify risk-and-resilience assessments and response plans that include electronic systems; small systems face only voluntary rules and technical help.

Implementation is uneven: EPA found high noncompliance with Section 1433, and a 2024 OIG review flagged critical or high cyber risks at 97 large systems serving about 26.6 million people; EPA later withdrew a 2023 attempt to force cybersecurity checks in state sanitary surveys after a legal challenge.

Congress is weighing more grants (including for wastewater), tighter assessment rules, or an independent standards body modeled on the electric sector—while weighing duplication, funding, small-system capacity, and the risk of centralizing vulnerability data.


Reports of cyberattacks on water systems in at least seven states in July 2026 have increased attention on the security of the nation’s municipal water infrastructure. These and other cyber incidents have raised questions about the effectiveness of existing approaches to address water sector cybersecurity. Municipal water systems and wastewater systems are paired together as a type of critical infrastructure (CI) covered by broader efforts to improve CI security. Executive Order 13636 designated the U.S. Environmental Protection Agency (EPA) as the sector risk management agency (SRMA) for water sector cybersecurity.

Federal efforts to address the cybersecurity of the water sector have primarily focused on drinking water systems rather than wastewater systems. Authorized through the Safe Drinking Water Act (SDWA), these federal efforts have generally involved specific vulnerability assessment requirements for larger drinking water systems and technical and financial assistance for smaller systems. This In Focus discusses EPA efforts under SDWA to address cybersecurity. It does not include information on Cybersecurity and Infrastructure Security Agency (CISA) authorities or EPA’s SRMA role.

Regulated Water Systems

SDWA applies to the nearly 144,000 privately and publicly owned public water systems, which provide piped water to at least 15 service connections or that regularly serve at least 25 people. Nearly 49,500 of these regulated public water systems (35%) are community water systems, which serve the same residences year-round. These systems provide water to more than 324 million people. EPA defines 81% of community water systems as “small,” serving 3,300 or fewer individuals. These systems provide water to 7% of the total population served by community water systems. Less than 10% of community water systems serve populations of 10,000 or more, but these larger systems provide water to 84% of community water system customers.

SDWA Assessments and Response Plans

In 2002, Congress amended SDWA to require community water systems serving more than 3,300 individuals to assess risks that could disrupt the provision of a safe and reliable water supply and prepare plans to address such risks. In 2018, the America’s Water Infrastructure Act (AWIA; P.L. 115-270) revised SDWA Section 1433 to require such systems to conduct risk-and-resilience assessments and to prepare emergency response plans. These water systems are required to assess their vulnerabilities to malevolent acts (and natural hazards). In their assessments, systems are required to evaluate the resilience of their infrastructure, including “electronic, computer, or other automated systems (including the security of such systems),” as well as their financial capacity to respond to these risks. Based on their assessments, community water systems must develop emergency response plans that address the risk-and-resilience issues their systems may face. Community water systems must self-certify their assessments and submit the certifications to EPA by deadlines determined by water system size. Every five years, SDWA requires water systems to review, and, if needed, revise their assessments, and resubmit their self-certifications to EPA. Risk-and-resilience assessments and emergency response plans are voluntary for small water systems.

SDWA Cybersecurity Assistance Programs

AWIA also added SDWA Section 1433(g), which authorizes technical assistance (TA) for community water systems of all sizes, and supports plans or projects to increase resiliency for small community water systems. In 2021, the Infrastructure Investment and Jobs Act (IIJA; P.L. 117-58) added SDWA Section 1459F, which directs EPA to establish a grant program for water systems serving 10,000 or more individuals to improve resilience to natural hazards and to reduce cybersecurity vulnerabilities. IIJA also reauthorized appropriations for SDWA Section 1442(b), which authorizes EPA to provide TA and make grants to states and public water systems to assist in responding to emergency situations. IIJA also amended SDWA Section 1442(b) to include cybersecurity events as an emergency situation. IIJA added SDWA Section 1459G, which authorizes a grant program for advanced technologies, including those that address cybersecurity. It also added SDWA Section 1420A, which requires EPA, with CISA, to develop a framework to identify water systems that, if degraded or rendered inoperable because of an incident, would lead to significant impacts. It requires EPA and CISA to develop a water system “Technical Cybersecurity Support Plan.”

Selected Implementation Issues

Reported cyberattacks on water systems have raised questions about the effectiveness of the sector’s approach to cybersecurity. SDWA Section 1433 requirements are targeted to systems serving a larger number of individuals because, if disrupted, the public health impact would be larger. Also, these larger systems benefit from economies of scale, resulting in greater capacity to update technology, adopt practices, or hire security specialists. SDWA assessments and plans are voluntary for smaller systems.

Some have raised concerns about SDWA Section 1433 compliance and the quality of larger systems’ vulnerability assessments and emergency response plans. A 2024 EPA enforcement notice indicated that larger systems were experiencing compliance challenges, stating that more than “70% of systems inspected by EPA since September 2023 are in violation of basic SDWA Section 1433 requirements.” Between 2020 and 2024, EPA conducted at least 100 enforcement actions due to violations of SDWA Section 1433. Also in 2024, EPA’s Office of Inspector General (OIG) conducted a cybersecurity assessment of 1,062 water systems that serve 50,000 or more individuals. Of the 1,062 systems, OIG “identified 97 … water systems serving approximately 26.6 million users as having either critical or high-risk cybersecurity vulnerabilities.”

Others have questioned EPA’s use of its SDWA authorities to address cybersecurity. For example, in March 2023, EPA issued an interpretive memorandum to require states, as a part of their SDWA primary enforcement responsibilities, to evaluate water system operational technology cybersecurity during triennial inspections, called “sanitary surveys.” Sanitary surveys are on-site inspections of a water system’s components (e.g., treatment technologies) and operational functions. Stakeholders filed a petition for judicial review, arguing that EPA did not follow the Administrative Procedure Act when issuing the memorandum and that EPA’s expansion of the sanitary survey exceeded its statutory authority under SDWA. In October 2023, EPA rescinded the interpretive memorandum and its requirements.

Legislation in the 119th Congress

In the 119th Congress, some Members have introduced legislation regarding water sector cybersecurity. The Water Resources Development Act of 2026 (S. 4949), for example, includes several cybersecurity provisions. S. 4949 wouldreauthorize appropriations for SDWA Section 1459F;
revise an existing SDWA small and disadvantaged communities grant program to make “reducing cybersecurity vulnerabilities” an eligible funding activity;
amend an existing water infrastructure workforce grant program to include support for cybersecurity training;
authorize a wastewater cybersecurity grant program;
authorize a digital infrastructure grant program; and
direct EPA to establish, subject to appropriations, a program to support participation in the Water Information Sharing and Analysis Center (WaterISAC), and to report on water sector cybersecurity within three years of enactment.


Other bills have water sector cybersecurity as their primary focus. These bills use different approaches, such as authorizing new grant programs (e.g., H.R. 2109/S. 1018, H.R. 9776/S. 3967, H.R. 2344/S. 1118);
reauthorizing appropriations for existing authorities (e.g., H.R. 10083, S. 1549);
reauthorizing appropriations for SDWA Section 1442(b) and authorizing a wastewater grant program (e.g., H.R. 9690/S. 4980);
revising SDWA Section 1433 vulnerability assessment requirements for water systems, expanding oversight of water system vulnerability assessments, and adding similar wastewater requirements (e.g., S. 5368); and
establishing a new framework to require systems to adopt cybersecurity standards developed and enforced by an independent organization (e.g., H.R. 2594).

Considerations for Congress

Members may consider several issues regarding water sector cybersecurity. In the 119th Congress, several bills propose to add cybersecurity grant programs for specific types of systems (e.g., rural) or to reauthorize appropriations for existing TA and/or grant programs. One consideration is whether new programs would be additive to or duplicative of existing ones. Another is whether existing programs are receiving appropriations. Congress has not specified appropriations for cybersecurity TA and grants under SDWA Section 1433(g) or the advanced technology grants under SDWA Section 1459G. Congress has provided appropriations for SDWA Section 1442(b)emergency assistance to address the Jackson, MS, water crisis and damage from Hurricanes Helene and Milton. In addition, Congress began funding resiliency grants for larger systems under SDWA Section 1459F in FY2023.

Other considerations may involve revising SDWA Section 1433 risk-and-resilience assessments and emergency response planning to include specific standards. In prior Congresses, some bills (e.g., H.R. 3258 in the 111th Congress) proposed a similar approach but were not enacted. Considerations for this approach could include how these standards would affect systems that face challenges in meeting the existing requirements. Another potential consideration involves EPA’s or a state’s ability to develop or oversee standards, as some have questioned whether water system expertise extends to cybersecurity expertise.

Another consideration relates to the risks of sharing water systems’ vulnerability information with entities tasked with overseeing or supporting cybersecurity. Proposals to require water systems to transmit vulnerability assessments to EPA, states, or an independent organization to check compliance with certain standards may risk creating a repository of water system vulnerabilities that could be targeted for a cyberattack. Similarly, ensuring the cybersecurity of third-party entities that provide TA to specific water systems may be another consideration for proposals to expand TA.

Policymakers are considering a proposal to establish an independent organization to set cybersecurity standards for adoption by water systems. Several waterassociations support this approach. Under this proposal, EPA would retain oversight of the standard-setting organization, similarly to how the Federal Energy Regulatory Commission (FERC) oversees cybersecurity standards developed by the North American Electric Reliability Corporation (NERC) in the electricity sector. Policymakers assessing this approach may consider the differences between the electricity and water sectors, such as interconnectedness. Local electricity distribution systems connect to a larger transmission network, so an attack on transmission could affect several states. NERC standards apply to the interconnected network. Water systems generally are not interconnected, so any disruption from an attack would be limited to a community rather than affecting water service in several states. Although water systems are not interconnected at the state level, the effect of an attack (e.g., water contamination) could be significant, as some systems serve millions of people.


About the author: Elena H. Humphreys, Specialist in Environmental Policy

Source: This article was published by the Congressional Research Service (CRS)


About CRS
The Congressional Research Service (CRS) works exclusively for the United States Congress, providing policy and legal analysis to committees and Members of both the House and Senate, regardless of party affiliation. As a legislative branch agency within the Library of Congress, CRS has been a valued and respected resource on Capitol Hill for nearly a century.
View all posts by CRS

 

Chile Exposes How Organized Crime Turns Stolen Copper Into Transnational Revenue – Analysis

A secondary tunnel at El Teniente, the world’s largest underground copper mine, located in the Andes Mountains of central Chile, is seen on November 20, 2025. (Photo: Chilean National Copper Corporation)

By Guillermo Saavedra


Key Takeaways:

  • Operation High Voltage in April 2026 produced Chile’s largest-ever copper seizure: 187 metric tons of stolen material, 25 arrests, and raids on 49 sites after a five-year scheme that trafficked nearly $917 million in stolen copper and fraudulently claimed over $55 million in export tax refunds.
  • The network infiltrated legitimate trade and tax systems—burning, stripping, and crushing copper before exporting it (mainly to China via Chilean and Peruvian routes)—and relied on lawyers, tax specialists, and transnational logistics to give illicit shipments the appearance of legality.
  • Copper theft has evolved into a sophisticated, supply-chain-wide threat driven by strong global (especially Chinese) demand; addressing it requires stronger legal classification of the crime, cross-border cooperation, financial oversight, and tighter export controls beyond isolated police actions.

Months of coordinated investigative work culminated in the largest seizure of stolen copper in Chile’s history. Operation High Voltage, carried out in April 2026 by the Investigative Police (PDI), the Public Prosecutor’s Office, the Internal Revenue Service, and the National Customs Service, led to simultaneous raids on 49 locations across seven regions of the country.

The operation resulted in the arrest of 25 people — including the organization’s leaders and key operatives — and the seizure of 187 metric tons of stolen copper, along with weapons and vehicles. “This is the largest seizure ever made in our country’s history for this type of crime,” then Undersecretary of Public Security Andrés Jouannet said.

A five-year scheme that exploited trade and tax systems

Between 2020 and 2025, the international criminal organization trafficked nearly $917 million worth of stolen copper, according to the PDI’s National Headquarters for Combating Theft and Criminal Hotspots. During the same period, it fraudulently obtained more than $55 million in export tax refunds. Rather than operating outside the system, the network infiltrated Chile’s legitimate commercial infrastructure, introducing stolen copper into legal supply chains while evading detection.

María Angélica de Miguel, acting regional prosecutor for the Los Lagos Region, described the method used to conceal the copper’s origin: The stolen material was burned, stripped, and crushed to eliminate any trace of its source before being exported to buyers in China through logistics networks that included northern Chilean ports. According to South China Morning Post, investigators also identified routes that passed through Peru, underscoring the network’s cross-border reach. The scheme illustrates a level of logistical, legal, and financial sophistication that extends far beyond conventional criminal activity.

Criminal sophistication: Lawyers, tax specialists, and transnational networks

International analyst Guillermo Holzmann told Diálogo that the Chilean case reflects a broader regional trend rather than an isolated incident. “We are currently witnessing an evolution of criminal gangs toward a level of sophistication that is frankly impressive in terms of how quickly their illegal businesses adapt to the characteristics of different markets,” he said. “The demand for natural resources is the most profitable source of income for these organizations.”

Holzmann said the sophistication of these networks lies not only in identifying the profitable markets but also in building supply chains capable of meeting demand while minimizing legal risk. To achieve this, criminal organizations rely on legitimate professional services — including law firms and tax specialists — to navigate regulatory requirements, exploit legal loopholes, and give illicit transactions the appearance of legitimacy.

Holzmann also pointed to the growing presence of Chinese criminal groups involved in these activities.

“There is a proliferation here of Chinese criminal groups and gangs carrying out most of these criminal activities. The question is whether they have backing or some kind of relationship with Beijing […],” Holzmann said. “These gangs subsequently sell these resources to the Chinese legal system, so there is a cover that allows this to happen.”

He added that legal shortcomings also contribute to the problem. “Copper theft thrives mainly because many of these operations are not adequately classified as crimes in the legal or criminal systems of these countries,” Holzmann added. “Establishing liability, filing charges, and, particularly, securing convictions is a very complicated process.”

Chile as the forefront of an expanding criminal threat

Operation High Voltage represents the largest case uncovered to date, but it is part of a broader pattern.

In December 2025, the PDI dismantled a criminal organization responsible for a series of violent copper thefts targeting mining operations in northern Chile. Earlier that year, Operation Oro Rojo dismantled another international network responsible for stealing more than 50 metric tons of copper cables and other materials, which were later exported to markets in India and Belgium.

The problem extends back several years. In 2023, armed criminals stole 12 containers of Codelco copper from the Port of San Antonio in one of the country’s largest copper heists. A year earlier, gangs repeatedly targeted freight trains carrying copper from northern mines to Pacific ports, forcing some mining companies to shift shipments from rail to road because of the security risk.

TT Club, a specialist insurer serving the global freight transport and logistics industry, warns that copper theft now affects every stage of the supply chain, extending well beyond cargo in transit to include storage yards, terminals, warehouses, and production facilities.

“Over the past decade, copper theft has evolved from an opportunistic crime to a persistent threat to supply chains, driven by the metal’s value, the involvement of organized crime, and vulnerabilities in transportation and storage controls,” the insurer states. “We are seeing a significant and accelerating increase in both the frequency of incidents and their financial impact, which reinforces the need to consider copper as a high-risk cargo.”

The economic incentives driving these crimes are unlikely to diminish. During the World Copper Conference in Santiago in April 2026, a researcher from the Chinese state-owned company Minmetals Corp projected that China’s copper consumption could grow by an average of 3.7 percent annually, reaching nearly 23 million metric tons by 2035 — a 43 percent increase from the 16 million recorded in 2025.

Operation High Voltage demonstrates that transnational organized crime no longer operates solely on the margins of the formal economy. Increasingly, it infiltrates legitimate commercial systems, by exploiting financial, tax and logistical mechanisms normally associated with lawful businesses. As copper becomes increasingly vital for electric vehicles, artificial intelligence, telecommunications, advanced manufacturing, and defense systems, protecting critical mineral supply chains is emerging as both an economic and national security priority for producing countries.

Strong global demand suggests these criminal incentives will persist. Addressing the threat will require more than isolated law enforcement operations. It will depend on stronger legal frameworks, cross-border judicial cooperation, enhanced financial oversight, and tighter export controls. Chile’s experience offers both a warning and a model of coordinated interagency action that other critical mineral-producing countries in the region would benefit from studying.

About Diálogo Américas

Diálogo Américas is a professional magazine published by U.S. Southern Command as an international forum for security issues in Latin America.

View all posts by Diálogo Américas →

GONE TO HELL

Ratko Mladic, Bosnian Serb Commander And Convicted War Criminal, Dies Aged 84


Ratko Mladic at his appeal hearing in The Hague in 2020. Photo: Flickr/IRMCT.

August 27, 2026
By RFE RL

Key Takeaways:

Ratko Mladić, the Bosnian Serb wartime commander convicted of genocide at Srebrenica, the siege of Sarajevo, and other crimes against humanity, has died at 84 in The Hague while serving a life sentence.

Arrested in Serbia in 2011 after 16 years as a fugitive, his life term was confirmed on appeal in 2021 after a lengthy ICTY trial; recent humanitarian-release requests after strokes were rejected days before his death.

Survivors and Bosnian officials said death does not erase the verdict or the victims; some Bosnian Serb politicians still framed him as a defe
nder of Serbs, underscoring a lasting political divide over the wartime record.


Bosnian Serb wartime military commander Ratko Mladic, known as the “Butcher of Bosnia,” has died aged 84 in The Hague, where he was serving a life sentence for genocide and crimes against humanity.

He was found guilty by an international court of genocide committed against around 8,000 Bosniaks in Srebrenica, a United Nations-protected area, in the summer of 1995, of terrorizing civilians during the siege of Sarajevo, and other war crimes during the 1992-95 war in Bosnia-Herzegovina.

Mladic “never expressed remorse in a single sentence in his cell,” Sahida Abdurahmanovic, who lost her husband in the Srebrenica massacre, told RFE/RL’s Balkan Service in response to the news of his death.

“The only thing we can regret now as victims of genocide is that he really stayed in The Hague all these years, that he wasn’t transferred…to a prison where he deserved to be. He had hotel accommodation in The Hague,” she added.

“Death does not bring forgiveness. Mass graves do not disappear. Murdered children do not return. Fathers, mothers, brothers, and sisters do not return. What remains is only shame, the verdict, and the bloody trail of crimes,” wrote Bosnian Defense Minister Zukan Helez on social media.

Mladic was arrested in Serbia on May 26, 2011. He had been the most wanted Hague fugitive, having evaded justice for almost 16 years, before he was finally detained and transferred to the International Criminal Tribunal for the former Yugoslavia (ICTY) in The Hague.

The Hague Tribunal confirmed his life sentence on June 8, 2021, rejecting an appeal by Mladic’s lawyers. It was the culmination of a marathon legal process that documented in shocking details some of the worst atrocities of the Bosnian war.

During the trial, which began on May 16, 2012, and lasted 530 days, 592 witnesses were called and around 10,000 pieces of evidence were presented.


Despite this, Mladic has continued to be supported by Serbian nationalists.

Responding to news of his death, longstanding Bosnian Serb political leader Milorad Dodik declared that Mladic had been fighting for the freedom of the Serbian people.

A statement by an association representing relatives of those killed at Srebrenica stated that “the memory of the victims must outlive both him and any policy that sought to justify or relativize what international courts established as facts.”
Ill Health

Mladic had suffered several strokes in recent months, leading to appeals for his release on humanitarian grounds by his family and also by Serbian officials. The Hague tribunal rejected those requests, the latest of which was filed on August 18.

“The interests of justice and general legal principles do not require release merely because imminent death is expected,” said Judge Graciela Gatti Santana, explaining the decision on August 26.

“The punishment, in addition to being a deterrent, should express the international community’s condemnation of the conduct in question and its unwillingness to tolerate serious violations of international humanitarian law and human rights,” she added.

In a statement confirming Mladic’s death, the Tribunal said an inquiry into the causes of Mladic’s death would begin in accordance with “the standard procedures and investigations required under Dutch national law.”




By Noor Nugali

Key Takeaways:

  • Saudi Arabia and France, in a joint statement after Crown Prince Mohammed bin Salman and President Macron met in Paris, called for a negotiated solution on Iran that ensures the peaceful nature of its nuclear program and full IAEA cooperation, while demanding restoration of unrestricted navigation through the Strait of Hormuz to pre-February 28, 2026 conditions.

  • On the Palestinian track, both sides welcomed a reported Hamas disarmament agreement, urged a sustainable ceasefire and unimpeded humanitarian access to Gaza, rejected moves undermining a two-state solution within 1967 borders, and called for an end to Israeli settlement expansion and settler violence.

  • Beyond regional diplomacy, the leaders marked a century of ties by expanding the strategic partnership—deepening defense cooperation, boosting trade and investment (including a major Qiddiya project in France), and advancing collaboration in AI, quantum technologies, culture, and Expo 2030—while addressing stability in Lebanon, Yemen, Sudan, and Syria.

Saudi Arabia and France called for a negotiated solution on Iran, the restoration of unrestricted navigation through the Strait of Hormuz and renewed efforts toward Palestinian statehood as Crown Prince Mohammed bin Salman and French President Emmanuel Macron laid out a broad joint vision for Middle East security and an expanded strategic partnership.

In a joint statement issued following their meeting in Paris on Monday, the two leaders emphasized that stability in the Middle East must be based on the sovereignty of states, respect for international law and the pursuit of political and diplomatic solutions to conflicts and security threats.

Iran featured prominently in the statement, with Riyadh and Paris stressing the need for a negotiated solution to prevent further escalation and ensure regional security.

The two sides reaffirmed their commitment to a diplomatic solution that guarantees the peaceful nature of Iran’s nuclear program and called on Tehran to resume full cooperation with the International Atomic Energy Agency.

They also condemned attacks on ships in the Strait of Hormuz and threats to the security of waterways, emphasizing the need to restore navigation through the strategic passage to the conditions that prevailed before Feb. 28, 2026.

The two countries called specifically for freedom of navigation, regular shipping traffic and the absence of direct or indirect tolls or restrictions on passage, in accordance with international law.

On the Palestinian issue, Saudi Arabia and France welcomed the announcement of an agreement on the disarmament of Hamas and called for its implementation.

They stressed the need to create conditions for a sustainable ceasefire and ensure the urgent, safe and unhindered delivery of humanitarian assistance to civilians in Gaza. They also rejected attempts to undermine the Palestinian people’s right to establish an independent state within the 1967 borders and emphasized the importance of preserving the unity of the Palestinian territories.

Riyadh and Paris also called for an end to Israeli settlement policy and settler violence, which they said threaten the two-state solution, and reiterated their commitment to the full implementation of the New York Declaration.

The two sides reaffirmed their support for the Palestinian Authority’s reform agenda and welcomed the announcement of legislative and presidential elections in Palestine.

The statement addressed several other regional flashpoints, including Lebanon, Yemen, Sudan and Syria.

On Lebanon, the two leaders agreed to intensify efforts toward a final resolution of the conflict through strengthening the Lebanese state and its institutions while safeguarding the country’s sovereignty and territorial integrity.

They commended President Joseph Aoun and the government of Prime Minister Nawaf Salam for steps taken to rebuild state institutions and extend state authority. Riyadh and Paris also reiterated support for the Lebanese Armed Forces and security forces, called for the full implementation of UN Security Council Resolution 1701 and stressed the need to complete the disarmament of all non-state armed groups. They also called for Israel to withdraw from all Lebanese territory.

On Yemen, the two countries reaffirmed support for the Presidential Council and UN efforts to reach an inclusive and comprehensive solution to the crisis.

They condemned Houthi attacks targeting civilian infrastructure and vital facilities in Saudi Arabia, as well as attacks on ships. France expressed its “solidarity and full support” for the Kingdom and rejected attacks on Saudi territory

On Sudan, both sides called for intensified efforts to end the crisis and halt foreign interference while preserving the country’s sovereignty, independence, territorial integrity and institutions.

Saudi Arabia and France also reaffirmed support for Syria’s unity, stability and economic recovery. They highlighted the potential to reposition Syria as a bridge connecting Europe, the Gulf and Asia through alternative routes and welcomed the establishment of a Saudi-Syrian-French business council.

Beyond regional diplomacy, the statement signaled a significant expansion of bilateral cooperation as the two leaders marked a century of political relations between Saudi Arabia and France and presided over the first meeting of the French-Saudi Strategic Partnership Council.

The two countries adopted a declaration strengthening their historic defense cooperation, including in armaments and training, while committing to greater coordination on global security and stability.

Economic ties were another major focus. Bilateral trade reached about $11.8 billion in 2025, while both countries agreed to strengthen cross-investment and cooperation between financial institutions.

The statement also welcomed Qiddiya Investment Company’s ambition to develop a major mixed-use destination in Cergy-Pontoise in the Île-de-France region, encompassing entertainment, leisure, hospitality, culture and sport. Current ambitions include investment of around €6 billion over the project’s development lifecycle.

Cooperation will also deepen in artificial intelligence, quantum computing and emerging technologies, while the countries agreed to extend their partnership on AlUla until 2035, building on cooperation in archaeology, heritage and culture.

France also confirmed its participation in Riyadh Expo 2030, with both leaders agreeing to make the event a highlight of Saudi-French relations.

The visit saw agreements and memorandums of understanding signed in defense, healthcare, AI, emerging technologies and entertainment, while the French-Saudi Investment Roundtable produced announcements of more than 22 agreements and MoUs across key sectors.

Together, the initiatives underscored a partnership that Riyadh and Paris are seeking to deepen not only around trade and investment, but also around some of the Middle East’s most consequential diplomatic and security challenges.