Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
President Trump signed a Section 232 proclamation on 13 August 2026 (published in the Federal Register 19 August 2026, FR doc 2026-16979) imposing tariffs on unmanned aircraft systems (UAS/drones) and components, following a Commerce Department finding that US reliance on foreign-produced (chiefly Chinese, e.g. DJI/Autel) drones and critical components creates supply-chain and cybersecurity national- security risk. A 100% ad valorem tariff applies to Annex I items (drones with maximum takeoff weight over 25kg, thermal-imaging drones, docking stations, and listed critical components); a 25% ad valorem tariff applies to Annex II items (other listed UAS). Qualifying-origin content from the EU, Japan, Korea, Switzerland, Taiwan and Liechtenstein is capped at 15%; UK-origin content is capped at 10%. UAS duties take effect 3 September 2026; component duties take effect 9 February 2027. The proclamation also authorizes Commerce to set up an onshoring program giving temporary relief to firms committing to build or expand US production of covered drones and components.
The Department of Commerce's International Trade Administration published a Federal Register notice on 10 April 2026 (91 FR 18412, doc 2026-06952) opening the inaugural Call for Proposals for the American AI Exports Program established under Executive Order 14320. Proposals are accepted from 1 April 2026 through 5:00 pm EDT on 30 June 2026 from US industry-led "pre-set" consortia offering full-stack American AI export packages — AI-optimised hardware, data pipelines, AI models and systems, security and cybersecurity measures, and sector-specific applications — for presentation by the US government to foreign public- and private-sector buyers. Designated consortia receive priority US-government advocacy, priority consideration for export-control licence engagement, interagency coordination, and federal-financing referrals (EXIM, DFC), with a 14-business-day completeness review and 60-calendar-day designation decision once a proposal is deemed complete.
On 19 November 2025, the U.S. Treasury's Office of Foreign Assets Control (OFAC), in a coordinated action with Australia's Department of Foreign Affairs and Trade and the UK's Foreign, Commonwealth and Development Office, designated 5 individuals and 7 companies linked to two Russia-based "bulletproof hosting" (BPH) providers, Media Land and Aeza Group, under Executive Order 13694. Media Land and its subsidiaries (Media Land Technology, Data Center Kirishi, ML Cloud) supplied server infrastructure to ransomware groups including LockBit, BlackSuit and Play. The designations also targeted three companies Aeza Group used to evade its July 2025 OFAC designation and rebrand its infrastructure: Hypercore Ltd. (United Kingdom), Smart Digital Ideas DOO (Serbia), and Datavice MCHJ (Uzbekistan). All designated persons' U.S.-nexus assets are blocked and U.S. persons are prohibited from transacting with them.
FinCEN issued a final rule under Section 311 of the USA PATRIOT Act (31 U.S.C. § 5318A) prohibiting US covered financial institutions from opening or maintaining a correspondent account for, or on behalf of, Cambodia-based Huione Group, a foreign financial institution found to be of primary money-laundering concern. Treasury determined that Huione Group and its subsidiaries — including Haowang Guarantee, Huione Pay PLC, and Huione Crypto — laundered at least $4 billion of illicit proceeds between August 2021 and January 2025, including funds tied to North Korean cyber-heist actors and Southeast Asian "pig-butchering" investment-scam compounds. The rule also imposes a special-due-diligence requirement on US covered institutions to guard against indirect access via foreign correspondent accounts. Effective November 17, 2025.
On 8 September 2025, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated 19 targets — companies and individuals based in Burma (Myanmar) and Cambodia — for operating or supporting networks of scam compounds that defraud Americans through virtual-currency investment fraud ("pig butchering") schemes. Nine targets operate out of Shwe Kokko, Burma, a scam-compound hub under the protection of the OFAC-designated Karen National Army (KNA), and ten targets are based in Cambodia, including Heng He Bavet's casino-linked complex in Bavet. Designations were made pursuant to Executive Order 13581 (transnational criminal organizations) and, for the Burma-based Shwe Myint Thaung Yinn Industry & Manufacturing Company, also under Executive Order 14014 (Burma sanctions program) as an entity acting on behalf of designated individual Tin Win. Treasury cited a U.S. government estimate that Americans lost over $10 billion in 2024 to Southeast Asia-based scam operations, a 66% increase over the prior year. All U.S.-nexus property of designated persons is blocked and U.S. persons are prohibited from transacting with them.
On 14 August 2025 OFAC re-designated the cryptocurrency exchange Garantex Europe OU under its cyber authority (E.O. 13694, as amended) for processing over USD 100 million in transactions tied to ransomware and darknet-market actors since 2019, and designated its successor exchange Grinex — created by former Garantex staff to move customer deposits and continue operations after a March 2025 US Secret Service-led takedown of Garantex's infrastructure. OFAC also designated three Garantex executives, the A7A5 ruble-backed stablecoin issuer Old Vector (Kyrgyzstan), and Russian settlement-platform firm A7 and its subsidiaries A71 and A7 Agent — entities linked to sanctioned Moldovan oligarch Ilan Shor and sanctioned Promsvyazbank — for supplying the A7A5 token used to compensate Garantex customers and route funds through Grinex.
The FCC adopted a Report and Order (FCC 25-49) on 7 August 2025 — the first comprehensive overhaul of submarine cable landing license rules since 2001 — effective 26 November 2025. The order prohibits Indefeasible Right of Use (IRU) agreements that would give entities from designated foreign adversary countries (China including Hong Kong and Macau, Cuba, Iran, DPRK, Russia, and Venezuela) control over Submarine Line Terminal Equipment (SLTE) on US cable landings, and mandates new annual reporting plus certification/disclosure requirements covering ownership, cybersecurity and physical security plans, and FCC Covered List compliance. The order operationalises the FCC's bifurcated policy package: accelerating legitimate commercial cable buildout while hardening national-security review for foreign-adversary-connected infrastructure.
On 1 July 2025, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated Aeza Group, a St. Petersburg, Russia-based "bulletproof hosting" (BPH) provider, along with two affiliated companies and four Aeza Group leaders (Arsenii Penzev, Yuri Bozoyan, Vladimir Gast, Igor Knyazev), for supplying server infrastructure that shielded ransomware operators, infostealer groups, and darknet drug marketplaces from law-enforcement takedown. In coordination with the UK's National Crime Agency, OFAC also designated Aeza International Ltd., a UK front company Aeza used to lease IP addresses to cybercriminals. The action was taken under Executive Order 13694 (as amended by E.O. 14144 and E.O. 14306) and builds on OFAC's February 2025 designation of BPH provider ZServers.
The Bureau of Industry and Security (BIS) amended the Export Administration Regulations (EAR) by adding three Kaspersky entities to the Entity List under End-User Review Committee (ERC) determinations — AO Kaspersky Lab (Moscow), OOO Kaspersky Group (Moscow), and Kaspersky Labs Limited (London). All three are designated for cooperation with Russian military and intelligence authorities in support of Russian government cyber-intelligence objectives. Exports, reexports, and in-country transfers of all items subject to the EAR to the three entities now require a BIS licence reviewed under a policy of presumption of denial, with no licence exceptions available. The action is paired with a same-week Commerce ICTS final determination prohibiting Kaspersky cybersecurity and anti-virus software transactions in the United States.
Bureau of Industry and Security final rule (88 FR 46071, Doc 2023-15343) adding four entities to the Entity List effective July 18, 2023. Intellexa S.A. (Greece) and Intellexa Limited (Ireland) — the corporate architecture behind the "Predator" commercial spyware platform — and Cytrox Holdings Zrt. (Hungary) and Cytrox AD (North Macedonia) — the developer of the underlying spyware technology — were listed for "trafficking in cyber exploits used to gain access to information systems, thereby threatening the privacy and security of individuals and organizations worldwide." All items subject to the EAR require a license with a presumption-of-denial review policy for all four entities, effectively cutting off access to US-origin hardware, software, and technology.
OFAC reissued the Cyber-Related Sanctions Regulations (31 CFR Part 578) in their entirety on 6 September 2022, replacing the abbreviated placeholder framework first published on 31 December 2015. The reissuance implements Executive Order 13694 (1 April 2015, blocking property of persons engaging in significant malicious cyber-enabled activities) and Executive Order 13757 (28 December 2016, expanding that authority to include election interference). The full-form regulations add interpretive definitions, general licences, and civil-penalties provisions — providing compliance clarity for US financial institutions and technology companies without expanding the underlying sanctions perimeter.
BIS finalized changes to the Export Administration Regulations (EAR) governing controls on cybersecurity items — primarily intrusion software, command-and-control platforms, and surveillance tools capable of disrupting or monitoring information systems without authorization. The final rule, effective May 26 2022, revises License Exception ACE (Authorized Cybersecurity Exports) originally established by an October 2021 interim rule and narrows end-user carve-outs for government end users in Country Group D:5 and A:6 destinations. Exports of affected ECCNs (4A005, 4D001, 4D004, 4E001, 5A001.j, 5B001, 5D001, 5E001) to Country Groups E:1 and E:2 remain prohibited; D:1 through D:5 government-end-user transactions require a license.
BIS published an interim rule on January 12, 2022 delaying the effective date of its October 21, 2021 cybersecurity items interim final rule by 45 days, from January 19, 2022 to March 7, 2022. The underlying October 2021 rule establishes new Export Control Classification Numbers (ECCNs) for cybersecurity items — including intrusion software, command-and-control platforms, and surveillance tools — and introduces License Exception ACE (Authorized Cybersecurity Exports) for national security and anti-terrorism purposes. The delay was granted after twelve public comments highlighted significant compliance challenges, with BIS acknowledging the need for additional time for industry to update procedures and for BIS to issue supplemental guidance before the controls took effect.
On November 4, 2021, BIS added four entities to the Entity List under a policy of denial: NSO Group and Candiru (Israel), Positive Technologies (Russia), and Computer Security Initiative Consultancy PTE (Singapore). NSO Group and Candiru were designated for supplying commercial spyware to foreign governments used to maliciously surveil government officials, journalists, activists, and academics; Positive Technologies and CSIC for trafficking cyber tools enabling unauthorized access to information systems. All four entities now require BIS licenses for any export, re-export, or in-country transfer of EAR-controlled items, with a presumption of denial.
BIS published an interim final rule on October 21, 2021 establishing new Export Control Classification Numbers (ECCNs 4A005, 4D004, 4E001.c, and 5A001.j) for intrusion software systems, command-and-control platforms, and IP network surveillance tools, implementing the Wassenaar Arrangement 2017 cybersecurity decisions into the Export Administration Regulations (EAR). The rule simultaneously created License Exception ACE (Authorized Cybersecurity Exports), codified at § 740.22, to authorize exports to most destinations while imposing licence requirements — or outright prohibitions — for sales to Country Groups E:1/E:2 governments and certain D-group government end-users. Carve-outs for vulnerability disclosure and cyber-incident-response activities were included to protect legitimate security research. The effective date was subsequently delayed from January 19, 2022 to March 7, 2022 by a separate interim rule (FR 2022-00448), and the rule was finalized with revisions on May 26, 2022 (FR 2022-11282).
The Bureau of Industry and Security amended the Export Administration Regulations by adding six Russian technology entities to the Entity List, all designated consistent with Executive Order 14024 on blocking property associated with harmful foreign activities of the Russian government. The designated entities operate in Russia's technology sector and have been determined to support Russian intelligence services, including notable cybersecurity firms and defense-innovation institutions. All items subject to the EAR require a BIS licence for export, reexport, or transfer to these parties, subject to a presumption-of-denial review policy with no licence exceptions available. The rule also corrects an existing FSB entry to reference updated General Licence No. 1B.
BIS published an interim final rule on 5 October 2020 implementing multilateral export controls on six emerging technology categories agreed at the December 2019 Wassenaar Arrangement Plenary meeting, revising Commerce Control List ECCNs 2B001, 3D003, 3E004, 5A004, 5D001, and 9A004. The six technologies are: hybrid additive-manufacturing/CNC machine tools; computational lithography software for extreme-ultraviolet (EUV) mask fabrication; wafer-finishing technology for 5 nm-node production; digital forensics tools that circumvent device authentication to extract raw data; software for monitoring and analysis of communications acquired from a handover interface; and sub-orbital craft. As the first of two US implementing actions for the 2019 Wassenaar Plenary, this rule elevated nascent commercial technologies into permanent CCL classifications enforceable against all non-EAR99 destinations.
The International Emergency Economic Powers Act of 1977 (IEEPA, Title II of Pub. L. 95-223, 91 Stat. 1626, codified at 50 U.S.C. §§ 1701–1708) was signed by President Carter on 28 December 1977 and grants the President sweeping authority to declare a national emergency with respect to "any unusual and extraordinary threat, which has its source in whole or substantial part outside the United States, to the national security, foreign policy, or economy of the United States" — and then to investigate, regulate, direct, compel, nullify, void, prevent, or prohibit any transaction in, or involving, foreign exchange, banking transfers, importing, exporting, or dealings in property by persons subject to US jurisdiction. IEEPA is the parent enabling statute for every OFAC-administered autonomous sanctions program (Russia, Iran, DPRK, Venezuela, Cuba, Syria, Belarus, Myanmar, cyber, Global Magnitsky, Hong Kong, ICC, and others) as well as the legal basis for the entire Trump-era IEEPA-tariff regime (EO 14193–14195 fentanyl tariffs, Canada/Mexico/China; EO 14257 reciprocal-tariff framework; EO 14323 Brazil; EO 14380 Cuba; EO 14382 Iran; and the US-India interim tariff agreement). Between 1977 and 2025 Presidents invoked IEEPA in 77 national-emergency declarations; of these, 7+ directly parent IPTM-filed implementing actions, with ~dozens of OFAC SDN designation actions tracing their legal root to this statute.