The NSI Act annual report 2025-26: what it means for data infrastructure and telecoms deals

NSI Act annual report 2025-26: data infrastructure and telecoms deal screening

In short: The NSI Act annual report 2025-26, published 14 July 2026, shows national security screening still concentrated in defence, government supply and dual-use activity, with data infrastructure the one commercial-technology sector to feature heavily: it drew three of the nine final orders. Notifications rose 15% to 1,324, with 60 call-in notices in total. Digital-infrastructure and telecoms buyers should treat screening as an active planning risk on every deal.

By Rob Bratby, Managing Partner, Bratby Law. Chambers UK Band 2 (Telecommunications). Legal 500 Leading UK Telecoms Partner. 30+ years in telecoms regulation, including Oftel and senior operator roles.

Anyone buying a data centre, a cloud business, a fibre network or a telecoms operator has to ask whether the deal needs clearance on national security grounds before it can complete. The government’s latest figures show that for most deals the answer is a quick clearance, but that the interventions, when they come, now reach data infrastructure alongside the expected defence and dual-use deals. The NSI Act annual report 2025-26, covering the year to 31 March 2026, records more notifications than ever and confirms where the Investment Security Unit is actually intervening. For dealmakers in telecoms and digital infrastructure, the sector split is what should shape how they plan a filing.

Key findings from the NSI Act annual report 2025-26

  • The Investment Security Unit received 1,324 notifications, up 15% on the prior year and 46% on 2023-24. Source: NSI Act Annual Report 2025-26.
  • Of 1,220 notified acquisitions reviewed, 54 (4.4%) were called in and 1,166 (95.6%) were cleared with no further action. Source: NSI Act Annual Report 2025-26.
  • The government made nine final orders: eight allowing the deal subject to conditions, one blocking it. Source: NSI Act Annual Report 2025-26.
  • Data infrastructure drew three of the nine final orders, second only to advanced materials, and 27% of the 44 final notifications. Source: NSI Act Annual Report 2025-26.
  • The government identified 42 deals completed without the required approval, taking assurances rather than imposing any penalty. Source: NSI Act Annual Report 2025-26.
Indicator2025-26 figurePrior year
Notifications received1,3241,143
Call-in notices issued6056
Final orders made9 (8 conditional, 1 blocked)17
Final orders in data infrastructure3Not reported separately
Median days to accept a mandatory notification117
Deals completed without approval42Not reported

Where the interventions fell: defence, dual-use and data infrastructure

National security screening fell where it has always fallen. Defence led the notifications at 58%, ahead of military and dual-use activity and critical suppliers to government, and defence and critical suppliers again led the 60 call-in notices. The sector worth flagging to buyers in telecoms and digital infrastructure is the one that appeared alongside them. Data infrastructure, which the Notifiable Acquisitions Regulations 2021 (SI 2021/1264) define as data centres and cloud computing services above set capacity thresholds, drew three of the nine final orders, second only to advanced materials, and 27% of the 44 final notifications. It was the only commercial-technology sector to feature that heavily. Given the volume of capital moving into UK data centres and AI compute, a data-infrastructure buyer should assume the deal will be reviewed, and should plan for conditions rather than a clean clearance.

Communications appeared among the sectors that attracted call-in notices, which reached 16 of the 17 mandatory sectors, but it did not lead any category this year. The concentration of interventions in data infrastructure, advanced materials and defence tells telecoms and digital-infrastructure buyers where the sharp end of the regime currently sits. Eight of the nine final orders cleared the deal subject to conditions. The single prohibition, published on the register, blocked the transfer of graphene production know-how held by Versarien Plc to a China-linked joint venture, a reminder that the outright block is reserved for dual-use technology going to an acquirer of concern.

The final orders made in 2025-26

The public register of final orders shows what the regime does at the sharp end. Each order below is taken from the gov.uk register, which names the parties and states the outcome. The register does not classify an order by sector, so the report’s count of three data-infrastructure orders cannot be matched to named deals.

TargetAcquirer (as named on the register)Order dateRegister actionOutcome stated in the notice
Versarien Plc (graphene assets)Joint venture with Anhui Boundary Innovative Materials Technology Co Ltd20 Aug 2025Final order and revocationBlocked. Transfer of the assets prohibited; order revoked 19 Feb 2026 when the joint venture was abandoned
Paragraf LimitedMIC UAE Investments 2 RSC Limited (12.8%)19 Jun 2025Final orderCleared with information-security and governance conditions
RETN LimitedLaviks Limited and Astern GmbH24 Jul 2025Final orderCleared with a condition to notify the ISU of possible public-authority contracts
Oxford Ionics LimitedIonQ Inc11 Sep 2025Final orderCleared with conditions to keep the hardware and functions in the UK
Oxford Nanoscience LimitedQD Oxford UK Limited15 Dec 2025Final orderCleared with conditions to maintain UK capability and supply to UK Government
Investigo LimitedCareer International AP (Hong Kong) Limited16 Dec 2025Final orderCleared with data-handling and security conditions
Agile Analog LimitedDelin Ventures Limited17 Dec 2025Final order and variationCleared with conditions; the conditions are not set out in the notice
Pinggao-Liverpool institute (energy research joint venture)University of Liverpool and Pinggao Group LtdOrder 20 Jun 2024Revoked 25 Nov 2025Earlier order revoked when the joint venture would not proceed
FireAngel Safety Technology Group PlcIntelligent Safety Electronics Pte LtdOrder 16 May 2024Varied 13 Feb 2026Earlier order amended by a definitional change following a change of address

Source: gov.uk, Notices of final orders under the National Security and Investment Act 2021 (Cabinet Office), read 19 July 2026, and the individual final-order notices. The annual report separately records nine final orders made, three varied and two revoked in the period; the register does not publish that split order by order, so the seven fresh 2025 orders and the two actions on 2024 orders above are the register’s own record of the year.

What the screening regime actually catches

For most deals, screening under the National Security and Investment Act 2021 is a short clearance. In 2025-26 the government cleared 95.6% of the acquisitions it reviewed with no further action, all within the statutory 30 working days of the review period. Mandatory notification applies only where the target carries out one of the activities listed for the 17 sensitive sectors in SI 2021/1264, and the thresholds matter. A public electronic communications network or service provider is caught only where the turnover of its relevant UK business reaches at least £50 million. Holding a network, a service or a spectrum licence does not, by itself, make a deal notifiable, and there is no general Ofcom change-of-control approval that applies simply because the target holds one. The practical task on any telecoms or data deal is to test the target’s specific activities against the Schedule.

The clearance timetable has lengthened

Acceptance is taking longer. The median time from receipt of a mandatory notification to acceptance rose to 11 working days, up from 7 the year before. Acceptance is the point at which the statutory 30-day review clock starts, so a slower acceptance stage pushes back the whole timetable. Where a deal is called in, the report records a median of 24 statutory working days from call-in to a final notification, and 69 statutory working days from call-in to a final order. A conditions-precedent longstop drafted on the assumption of the historic minimum will now be too tight. On any deal that needs a mandatory filing, the sensible planning assumption is a longer runway to acceptance and a genuine possibility of the assessment period running its course.

The risk of completing without approval

Completing a notifiable acquisition without clearance makes it void under section 13 of the National Security and Investment Act 2021, and is a criminal offence carrying civil penalties on top. The report records no penalties and no prosecutions this year, but it also records 42 deals where the government identified a completed acquisition that should have been notified and was not. In each case the government required the parties to give assurances about future compliance rather than impose a penalty. That is 42 void transactions in a single year. The pattern most likely to catch a buyer is a lower-profile deal, often UK-on-UK, where the parties did not appreciate that the target fell within a mandatory sector. The lesson is to run the mandatory-sector analysis early, and to keep a written record of why a deal was or was not notifiable.

Viewpoint

The headline in the NSI Act annual report 2025-26 is reassuring for investors: the great majority of deals clear quickly and the government kept to the statutory clock on every call-in decision. The detail is where the value sits. In advising on transactions in regulated sectors, I find the harder question is rarely whether a deal will ultimately clear, but whether it falls within the mandatory net at all, and the report shows why that judgment matters: the interventions cluster in data infrastructure and advanced materials, and 42 buyers this year completed a deal they should have notified. The government has signalled legislation to change which sectors are notifiable and to exempt some acquisitions, so the scope questions that catch deals today may move. The concentration of final orders on China-linked acquirers has also held, even though the United Kingdom is the largest single origin of notifications, which tells you where the substantive risk still lies.

Frequently asked questions

Does every telecoms or data centre acquisition need clearance under the NSI Act?

No. Mandatory notification applies only where the target carries out an activity listed for one of the 17 sensitive sectors in SI 2021/1264 and the relevant thresholds are met. A communications provider is caught only where its relevant UK business turnover reaches at least £50 million. Test the target’s specific activities and the level of control being acquired against the Schedule.

What happens if a deal completes without the required NSI Act approval?

Completing a notifiable acquisition without clearance makes it void under section 13 and is a criminal offence with civil penalties available. In 2025-26 the government identified 42 such deals and required assurances rather than imposing penalties, but the acquisition remains legally void until validated, so the risk is real for any buyer that misjudged whether a filing was needed.

How long does NSI Act clearance take?

In 2025-26 the median time to accept a mandatory notification was 11 working days, up from 7. The statutory review period is 30 working days from acceptance. Where a deal is called in, the median from call-in to a final order was 69 statutory working days. Deal timetables and longstop dates should allow for the longer acceptance stage.

How Bratby Law can help

If you are assessing whether a telecoms, data-infrastructure or technology acquisition needs clearance, Bratby Law advises acquirers and targets on NSI Act notification, mandatory-sector analysis and deal-timetable planning. For advice on a specific transaction, contact Rob Bratby at Bratby Law.

Select topics of interest

Similar Posts