Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
On 23 April 2026, the Council of the European Union adopted the 20th package of restrictive measures against Russia, anchored by Council Regulation (EU) 2026/506 amending Regulation 833/2014 (sectoral sanctions) and Council Regulation (EU) 2026/511 amending Regulation 269/2014 (asset-freeze listings — 120 additional individuals and entities, the largest single tranche in two years). The package operationalises and extends the crypto-sanctions architecture introduced in the 19th package and constructs the legal scaffolding for a future full prohibition on maritime services to vessels carrying Russian crude/petroleum products. Headline measures: (i) full sectoral prohibition on transactions with crypto-asset service providers and exchange platforms established in Russia or Belarus, plus designation of the rouble-backed stablecoin RUBx and the digital rouble (CBDC) on Annex LIII — effective 24 May 2026, with EU support for the digital rouble's development banned outright; (ii) 36 new energy-sector listings spanning upstream extraction, refining and transportation; (iii) prohibition on providing technical, financial, brokering and insurance services to Russia-flagged, Russian-certified or Russian-managed LNG tankers and icebreakers effective 25 April 2026, extending to foreign-flagged vessels operating in Russian interests by January 2027 and culminating in a categorical ban on LNG terminal services to Russian-controlled entities on 1 January 2027; (iv) full transaction ban on 20 Russian banks plus four third-country banks listed for SPFS connectivity / sanctions circumvention; (v) 46 newly listed shadow-fleet vessels and new tanker sale-due-diligence obligations on EU shipping operators; (vi) 58 designations of companies and associated individuals in the Russian military-industrial complex including drone developers/manufacturers; (vii) further Annex IV third-country circumvention enabler listings (China, Hong Kong, Turkey, UAE); (viii) parallel measures against Belarus. Entry into force on 24 April 2026 (day following publication in OJ L_202600506), except for measures with explicit deferred application dates.
On 18 November 2025, the European Supervisory Authorities (EBA, ESMA, and EIOPA) jointly designated 19 Critical ICT Third-Party Providers (CTPPs) under DORA Article 31, with immediate effect — the first-ever exercise of direct EU financial-regulator supervision over hyperscale cloud and infrastructure providers. The designated entities include Amazon Web Services, Microsoft Azure, Google Cloud, Deutsche Telekom, Oracle, SAP, IBM, Bloomberg LP, London Stock Exchange Group (LSEG), Tata Consultancy Services, and Orange, among others. Designation triggers direct oversight by a lead ESA (EBA for banking-critical, ESMA for capital-markets-critical, EIOPA for insurance-critical) via Joint Examination Teams (JETs), with powers to conduct investigations, carry out on-site inspections, and impose fines of up to 1% of average daily worldwide turnover per day for non-compliance.
On 23 October 2025, the Council of the European Union adopted the 19th package of restrictive measures against Russia, anchored by Council Regulation (EU) 2025/2033 amending Regulation 833/2014 (sectoral sanctions), Council Implementing Regulation (EU) 2025/2035 amending Regulation 269/2014 (asset-freeze listings — 22 individuals + 42 entities, total 69 listings), and Council Regulation (EU) 2025/2041 (parallel Belarus measures). The package closes the Russian-LNG import loophole left open by the 18th package and establishes the architectural template for crypto-asset sanctions. Headline measures: (i) full prohibition on imports of Russian-origin LNG into the EU — short-term contracts banned six months from entry into force (effective 25 April 2026), long-term contracts (> 1 year, executed before 17 June 2025) phased out by 1 January 2027; (ii) full transaction ban on Rosneft and Gazprom Neft (tightening prior partial measures); (iii) five additional Russian banks added to Annex XIV transaction ban (Alfa-Bank, MTS Bank among them; effective 12 November 2025); (iv) full transaction bans on the Mir card payment system and the Faster Payments System (SBP), effective 25 January 2026; (v) first-ever EU sanctions on a stablecoin — the rouble-backed A7A5 (issuer + developer designated) — and a Paraguay-based cryptocurrency exchange used as a circumvention rail; (vi) prohibition on EU operators contracting with 11 listed Russian Special Economic Zones (Annex LII), with mandatory divestment from Alabuga (Tatarstan) and Technopolis Moscow effective 25 January 2026 — no five-year wind-down available; (vii) 45 entities added to Annex IV military end-user list (28 Russian + 17 third-country: 12 Chinese/Hong Kong, 3 Indian, 2 Thai); (viii) new export restrictions on electronic components, microelectronics, acyclic hydrocarbons, pneumatic rubber tires and propellant chemicals (~EUR 155 m of EU 2024 exports); (ix) prohibition on supply of AI, HPC, and quantum-computing services to Russian persons (effective 25 November 2025); (x) tourism-services ban (1 January 2026 wind-down); (xi) 117 additional shadow-fleet vessels listed (cumulative 557, exceeding the 18th package's 444); (xii) four Belarus + Kazakhstan banks listed for SPFS use (effective 2 December 2025); (xiii) binding ownership/control definitions added to Reg. 269/2014 (50 % proprietary-rights threshold + eight-criterion control test). Entry into force on 24 October 2025 (day following publication in OJ L_202502033), except for measures with explicit deferred application dates.
On 23 October 2025, the Council of the European Union adopted Council Regulation (EU) 2025/2041 (amending Regulation (EC) No 765/2006) and Council Decision (CFSP) 2025/2040 (amending Decision 2012/642/CFSP), widening the EU's Belarus restrictive-measures regime in lockstep with the 19th Russia sanctions package adopted the same day. The package widens the export ban to industrial goods (salts, ores, rubber articles, tyres, millstones, construction materials, electronic components, rangefinders, propellant chemicals, metals/oxides/alloys), extends the import ban to all acyclic hydrocarbons, introduces a new prior-licensing requirement for services supplied to Belarus, its government, or public bodies, and mirrors the Russia regime's space, AI, and high-performance/ quantum-computing service restrictions. A companion instrument, Council Implementing Regulation (EU) 2025/2039, adds 5 new asset-freeze listings (2 individuals + 3 entities, including JSC Holography Industry, Horizont Holding, and ICT Horizont). Entered into force 24 October 2025.
On 18 July 2025, the Council of the European Union adopted the 18th package of restrictive measures against Russia, anchored by Council Regulation (EU) 2025/1494 amending Regulation 833/2014 (sectoral measures), Council Implementing Regulation (EU) 2025/1476 implementing Regulation 269/2014 (asset-freeze listings), Council Decision (CFSP) 2025/1495 (vessel listings), and Council Regulation (EU) 2025/1472 (parallel Belarus measures). The package is the largest energy-sector escalation since 2022 and pivots from new-perimeter creation toward enforcement and circumvention closure. Headline measures: (i) the Russian-crude price cap is lowered from USD 60 to USD 47.6 per barrel with a new automatic dynamic mechanism re-indexing the cap to global oil prices every six months at a 15 % discount to the 22-week trailing average (effective 3 Sep 2025, with a transitional exemption to 18 Oct 2025 for pre-20 Jul 2025 contracts compliant with the prior cap); (ii) full transaction ban extended to 22 additional Russian banks, bringing the total cut off from the EU financial system to 45; transaction ban extended to third-country financial institutions and crypto-asset service providers facilitating circumvention; (iii) full transaction ban on Nord Stream 1 and Nord Stream 2 pipelines; (iv) import ban on refined oil products derived from Russian crude processed in third countries; (v) 105 additional vessels added to the shadow-fleet port-access ban (cumulative total 444); (vi) 26 new entities added to Annex IV military end-user list (15 Russian + 11 from China/Hong Kong/Turkey); (vii) Council Implementing Regulation 2025/1476 lists 14 individuals + 41 entities under asset-freeze, including a major Indian refinery (Nayara Energy, part-owned by Rosneft), three Chinese suppliers of battlefield goods, shadow-fleet operators, and entities involved in the deportation of Ukrainian children; (viii) parallel Belarus complementary measures via Regulation 2025/1472. Wind-down periods vary: 90 days for oil-price-cap contracts; banking-software wind-down to 30 Sep 2025; trade-goods wind-downs Oct 2025–Jan 2026 by category. Entry into force on 19 July 2025 (day following publication in the Official Journal), except for measures with explicit deferred application dates.
The Joint Committee of the European Supervisory Authorities (EBA, EIOPA, ESMA) published the Guide on DORA Oversight Activities (JC 2025 29) on 15 July 2025, the definitive operational description of how the ESAs will supervise Critical ICT Third-Party Providers (CTPPs) designated under DORA Art. 31. The guide establishes the governance of Joint Examination Teams (JETs), the oversight examination lifecycle (planning, risk assessment, binding recommendations, follow-up), penalty processes of up to 1% of average daily worldwide turnover per day of breach (DORA Art. 35(6)), and lead-overseer assignments (EBA for banking, ESMA for capital markets, EIOPA for insurance). It is authoritative ESA interpretive guidance, not legally binding per se, but constitutes the supervisory playbook CTPPs and their dependent financial entities must plan against.
On 18 June 2025 the European Investment Bank (EIB) and the BPCE banking group signed a EUR 300 million loan agreement to expand financing available to French small and medium-sized enterprises (SMEs) active in the security and defence supply chain, delivered through BPCE's Banque Populaire and Caisse d'Epargne networks. It is the first such operation the EIB has signed in France, and the second in Europe, under the EIB's Pan-EU Security & Defence Lending Envelope, which was expanded from EUR 1 billion to EUR 3 billion earlier in 2025 (a first tranche was signed with Deutsche Bank in Germany the preceding week). Funds are earmarked for SMEs investing in cybersecurity, surveillance, resilience, and defence technologies.
Commission Delegated Regulation (EU) 2025/532, adopted 24 March 2025 and published in the Official Journal on 2 July 2025, supplements DORA (Regulation (EU) 2022/2554) with binding Regulatory Technical Standards governing ICT subcontracting of critical or important functions. It requires all EU-regulated financial entities to establish a subcontracting policy, conduct due-diligence and concentration-risk assessments at each tier of the ICT supply chain (including nth-party providers), impose equivalent resilience standards on sub-ICT-providers, and maintain enforceable termination and information-access rights. The RTS entered into force on 22 July 2025, completing the second-batch DORA implementing acts on outsourcing chains.
Three Commission Delegated Regulations (CDR 2024/1772, 1773, 1774) adopted 13 March 2024 and published in the EU Official Journal on 25 June 2024 constitute the first batch of binding Level 2 implementing rules under DORA (Regulation (EU) 2022/2554). CDR 2024/1772 sets ICT incident classification criteria and materiality thresholds for mandatory reporting; CDR 2024/1773 specifies the required content of contractual policies for ICT third-party services supporting critical or important functions; CDR 2024/1774 defines the ICT risk management tools, methods, processes, and policies — including a simplified framework for smaller in-scope entities. All three apply from 17 January 2025 alongside the parent DORA regulation, covering approximately 22,000 EU regulated financial entities.
Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities, published OJ L 333, 27 December 2022, entered into force 16 January 2023, with Member State transposition deadline 17 October 2024 (rules applicable from 18 October 2024). The CER Directive repeals Council Directive 2008/114/EC on European Critical Infrastructures, extending the scope from two sectors (energy, transport) to eleven essential-service sectors: energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, public administration, space, and food. Member States must adopt national resilience strategies, conduct risk assessments at least every four years, identify "critical entities" providing essential services whose disruption would have significant cross-border impacts, and ensure those entities implement technical, security, and organisational resilience measures, business-continuity plans, incident-reporting obligations, and personnel-security background checks. The CER Directive is the physical and hybrid resilience twin to the NIS2 Directive (2022/2555) — the two instruments form the binding EU critical-infrastructure-protection architecture replacing the 2008/114/EC regime.
Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA) is the EU's first horizontal cyber- and ICT-resilience instrument for the financial sector. Adopted 14 December 2022 and published in the Official Journal on 27 December 2022, it entered into force on 16 January 2023 and applies from 17 January 2025. DORA covers approximately 22,000 EU regulated financial entities across ~20 entity types (credit institutions, insurers, investment firms, CCPs, trading venues, crypto-asset service providers, etc.) under five pillars: ICT risk management, ICT-incident reporting, digital operational resilience testing (including threat-led penetration testing for significant entities), ICT third-party risk management, and information sharing. Structurally novel, DORA establishes the Critical ICT Third-Party Provider (CTPP) oversight regime under which the European Supervisory Authorities (EBA, ESMA, EIOPA) acquire direct supervisory powers over hyperscale cloud providers (AWS, Azure, GCP, Oracle) servicing EU financial entities — the first EU mechanism for ESA direct oversight of non-financial cloud providers.
Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive), published OJ L 333, 27 December 2022, entered into force 16 January 2023. NIS2 repeals and substantially expands the 2016 NIS1 Directive (2016/1148), extending the scope from ~7 sectors to 18 enumerated essential and important sectors, imposing binding cybersecurity risk- management and incident-reporting obligations on covered entities, introducing board-level management accountability, and mandating Member State transposition by 17 October 2024. NIS2 is the structural EU statutory anchor for national cybersecurity frameworks across the bloc, operating alongside DORA (Reg 2022/2554) for financial-sector digital resilience and CRA (Reg 2024/2847) for product cybersecurity.