Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
The Bureau of Industry and Security (BIS) amended the Export Administration Regulations (EAR) by adding three Kaspersky entities to the Entity List under End-User Review Committee (ERC) determinations — AO Kaspersky Lab (Moscow), OOO Kaspersky Group (Moscow), and Kaspersky Labs Limited (London). All three are designated for cooperation with Russian military and intelligence authorities in support of Russian government cyber-intelligence objectives. Exports, reexports, and in-country transfers of all items subject to the EAR to the three entities now require a BIS licence reviewed under a policy of presumption of denial, with no licence exceptions available. The action is paired with a same-week Commerce ICTS final determination prohibiting Kaspersky cybersecurity and anti-virus software transactions in the United States.
Bureau of Industry and Security final rule (88 FR 46071, Doc 2023-15343) adding four entities to the Entity List effective July 18, 2023. Intellexa S.A. (Greece) and Intellexa Limited (Ireland) — the corporate architecture behind the "Predator" commercial spyware platform — and Cytrox Holdings Zrt. (Hungary) and Cytrox AD (North Macedonia) — the developer of the underlying spyware technology — were listed for "trafficking in cyber exploits used to gain access to information systems, thereby threatening the privacy and security of individuals and organizations worldwide." All items subject to the EAR require a license with a presumption-of-denial review policy for all four entities, effectively cutting off access to US-origin hardware, software, and technology.
BIS finalized changes to the Export Administration Regulations (EAR) governing controls on cybersecurity items — primarily intrusion software, command-and-control platforms, and surveillance tools capable of disrupting or monitoring information systems without authorization. The final rule, effective May 26 2022, revises License Exception ACE (Authorized Cybersecurity Exports) originally established by an October 2021 interim rule and narrows end-user carve-outs for government end users in Country Group D:5 and A:6 destinations. Exports of affected ECCNs (4A005, 4D001, 4D004, 4E001, 5A001.j, 5B001, 5D001, 5E001) to Country Groups E:1 and E:2 remain prohibited; D:1 through D:5 government-end-user transactions require a license.
On November 4, 2021, BIS added four entities to the Entity List under a policy of denial: NSO Group and Candiru (Israel), Positive Technologies (Russia), and Computer Security Initiative Consultancy PTE (Singapore). NSO Group and Candiru were designated for supplying commercial spyware to foreign governments used to maliciously surveil government officials, journalists, activists, and academics; Positive Technologies and CSIC for trafficking cyber tools enabling unauthorized access to information systems. All four entities now require BIS licenses for any export, re-export, or in-country transfer of EAR-controlled items, with a presumption of denial.
BIS published an interim final rule on October 21, 2021 establishing new Export Control Classification Numbers (ECCNs 4A005, 4D004, 4E001.c, and 5A001.j) for intrusion software systems, command-and-control platforms, and IP network surveillance tools, implementing the Wassenaar Arrangement 2017 cybersecurity decisions into the Export Administration Regulations (EAR). The rule simultaneously created License Exception ACE (Authorized Cybersecurity Exports), codified at § 740.22, to authorize exports to most destinations while imposing licence requirements — or outright prohibitions — for sales to Country Groups E:1/E:2 governments and certain D-group government end-users. Carve-outs for vulnerability disclosure and cyber-incident-response activities were included to protect legitimate security research. The effective date was subsequently delayed from January 19, 2022 to March 7, 2022 by a separate interim rule (FR 2022-00448), and the rule was finalized with revisions on May 26, 2022 (FR 2022-11282).
The Bureau of Industry and Security amended the Export Administration Regulations by adding six Russian technology entities to the Entity List, all designated consistent with Executive Order 14024 on blocking property associated with harmful foreign activities of the Russian government. The designated entities operate in Russia's technology sector and have been determined to support Russian intelligence services, including notable cybersecurity firms and defense-innovation institutions. All items subject to the EAR require a BIS licence for export, reexport, or transfer to these parties, subject to a presumption-of-denial review policy with no licence exceptions available. The rule also corrects an existing FSB entry to reference updated General Licence No. 1B.
BIS published an interim final rule on 5 October 2020 implementing multilateral export controls on six emerging technology categories agreed at the December 2019 Wassenaar Arrangement Plenary meeting, revising Commerce Control List ECCNs 2B001, 3D003, 3E004, 5A004, 5D001, and 9A004. The six technologies are: hybrid additive-manufacturing/CNC machine tools; computational lithography software for extreme-ultraviolet (EUV) mask fabrication; wafer-finishing technology for 5 nm-node production; digital forensics tools that circumvent device authentication to extract raw data; software for monitoring and analysis of communications acquired from a handover interface; and sub-orbital craft. As the first of two US implementing actions for the 2019 Wassenaar Plenary, this rule elevated nascent commercial technologies into permanent CCL classifications enforceable against all non-EAR99 destinations.