Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
BIS final rule (FR Doc 2024-19132, 89 FR 68539, published 27 August 2024) expanding the Russia/Belarus-Military End User (MEU) Foreign-Direct Product (FDP) rule under the Export Administration Regulations so that it also applies to transactions involving Entity List entries posing a significant diversion risk to Russia's and Belarus's defense industry or intelligence services — the rule is renamed accordingly. The rule also imposes new export, reexport, and in-country transfer controls on software for the operation of computer numerical control (CNC) machine tools destined for Russia or Belarus, and makes corrections eliminating obsolete cross- references introduced by the BIS 25 January 2024 and 18 June 2024 Russia/Belarus final rules. Effective 27 August 2024, except amendatory instruction 11 effective 16 September 2024.
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) issued a final rule amending three sanctions programs. The rule adds a new general license at 31 CFR § 525.512 to the Burma Sanctions Regulations authorizing the provision of agricultural commodities, medicine, medical devices, replacement parts and components for medical devices, and software updates for medical devices to individuals whose property and interests in property are blocked. It also updates the authorities section of the Burma Sanctions Regulations to reflect recent legislation, replaces "the Office of Foreign Assets Control" / "the Director of the Office of Foreign Assets Control" with the acronym "OFAC" in three sections of the Sudan Stabilization Sanctions Regulations, and corrects a cross-reference in the Ukraine-/Russia- Related Sanctions Regulations. The rule is effective on publication.
The U.S. Bureau of Industry and Security (BIS) published a final rule expanding the scope of the Iran Foreign Direct Product (FDP) rule in the Export Administration Regulations (EAR) to implement the "No Technology for Terror Act" (Public Law 118-50, Division N), signed by President Biden on April 24, 2024. The expanded rule extends EAR jurisdiction to additional foreign-produced items destined for Iran — including a broader set of items derived from U.S.-origin technology or software, or produced by plants/components that are themselves direct products of U.S.-origin technology — and requires a BIS license for their export, reexport, or in-country transfer to Iran. The rule also provides specified exclusions from the otherwise-applicable license requirements. The rule became effective on July 23, 2024 (publication July 26, 2024).
The Bureau of Industry and Security (BIS) issued an interim final rule (FR Doc. 2024-15810) amending the Export Administration Regulations (EAR) so that certain "releases" of technology and software during "standards-related activities" are no longer subject to the EAR. The rule revises 15 CFR §734.10 and consolidates the patchwork of prior carve-outs (May 2019 Huawei 5G TGL, June 2020 IFR, September 2022 Entity-List-wide IFR) into a single activity-based exclusion. The change enables US firms to participate in international standards bodies (IEEE, 3GPP, ITU, ISO, IEC) alongside Entity-Listed parties — most consequentially Huawei — without licence exposure. Comments were due September 16, 2024.
The European Union's Artificial Intelligence Act, Regulation (EU) 2024/1689, was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. It establishes the world's first horizontal, risk-tiered legal framework for the development, market placement, and use of AI systems — covering prohibited practices, high-risk systems, general-purpose AI models, and minimal-risk applications — with extraterritorial reach over any provider placing an AI system on the EU market or whose output is used in the EU. Penalties reach up to EUR 35 million or 7% of global annual turnover. Application is staged: prohibitions from 2 February 2025, GPAI and governance from 2 August 2025, the bulk of high-risk obligations from 2 August 2026, and product-safety-embedded high-risk systems from 2 August 2027.
The Bureau of Industry and Security (BIS) amended the Export Administration Regulations (EAR) by adding three Kaspersky entities to the Entity List under End-User Review Committee (ERC) determinations — AO Kaspersky Lab (Moscow), OOO Kaspersky Group (Moscow), and Kaspersky Labs Limited (London). All three are designated for cooperation with Russian military and intelligence authorities in support of Russian government cyber-intelligence objectives. Exports, reexports, and in-country transfers of all items subject to the EAR to the three entities now require a BIS licence reviewed under a policy of presumption of denial, with no licence exceptions available. The action is paired with a same-week Commerce ICTS final determination prohibiting Kaspersky cybersecurity and anti-virus software transactions in the United States.
BIS final rule (FR Doc 2024-13148, 89 FR 51644, RIN 0694-AJ87) expanding the Export Administration Regulations' Russia and Belarus sanctions architecture. Effective 12 June 2024 (most provisions) and 16 September 2024 (the EAR99 enterprise-software paragraph at §746.8(a)(8)), the rule introduces a new licence requirement for thirteen named categories of EAR99 enterprise software (ERP, CRM, BI, SCM, EDW, CMMS, project management, PLM, BIM, CAD, CAM, ETO) destined for Russia or Belarus; permits address-only Entity List designations to capture high-diversion addresses; adds eight Hong Kong addresses to the Entity List; and refines the Russia/Belarus Industry Sector Sanctions and Foreign Direct Product (FDP) rule. Released the day before the G7 Italy summit alongside coordinated OFAC, State, and Treasury actions that together designated 300+ persons and entities.
The U.S. Treasury's Office of Foreign Assets Control (OFAC) issued a final rule amending 31 CFR § 560.540 of the Iranian Transactions and Sanctions Regulations (ITSR) to incorporate, with amendments, General License (GL) D-2 — originally issued on OFAC's website on September 23, 2022 — which authorizes the export, reexport, and provision of certain services, software, and hardware incident to communications over the internet to persons in Iran. The codification preserves the GL D-2 expansion (cloud-based services; third-country importation of hardware/software previously exported to Iran; ex-Iran installation, repair and replacement services; case-by-case licensing for internet-freedom activities) and updates the § 560.540 List of Services, Software, and Hardware Incident to Communications. Effective June 17, 2024, the List is amended to exclude laptops, tablets, and personal computing devices with an Adjusted Peak Performance (APP) exceeding 1 Weighted TeraFLOP (WT) — narrowing the consumer-electronics authorization to lower-performance devices and aligning the carve-out with broader BIS-style compute thresholds. The rule does not relax primary ITSR prohibitions; it codifies a humanitarian / internet-freedom exception while inserting a narrow high-performance-compute carve-out.
The Bureau of Industry and Security (BIS), within the U.S. Department of Commerce, published an interim final rule (FR Doc 2024-08813) on April 30, 2024 amending the Export Administration Regulations (EAR) to restructure export controls on firearms, ammunition, parts, accessories, and related technology and software (EAR Categories 0 and 1). The rule created new Export Control Classification Numbers (ECCNs) for semi-automatic firearms, added Crime Control / Detection (CC) license requirements, narrowed license-exception eligibility, introduced a presumption of denial for many non-government end-users, and imposed a default 1-year license validity for semi-automatic firearms. Effective May 30, 2024; later rescinded (except for the new ECCNs) by FR Doc 2025-18992 on September 30, 2025.
Loi n° 2024-449 of 21 May 2024, known as the SREN law (Sécuriser et Réguler l'Espace Numérique), was definitively adopted by the French Parliament on 10 April 2024, validated in part by the Conseil Constitutionnel on 17 May 2024 (Decision n° 2024-866 DC), promulgated by the President on 21 May 2024, and published in the Journal Officiel on 22 May 2024. SREN is France's digital-sovereignty omnibus statute: it transposes parts of the EU Digital Services Act (Regulation 2022/2065), Digital Markets Act (Regulation 2022/1925), and Data Governance Act (Regulation 2022/868) into French law and layers national-level instruments on top — most consequentially a data-localisation hook for sensitive public-sector data tied to the ANSSI SecNumCloud sovereign-cloud certification scheme, an ARCOM-enforced age-verification regime for adult-content sites (with €250k or 2%-of-turnover fines and account-closure powers), an "anti-scam" cybersecurity filter requiring browsers and DNS resolvers to block ANSSI-designated fraudulent domains, a jeux-en-ligne (JONUM) regime for cryptoasset-adjacent gaming, and a coordination framework between CSA, CNIL, ARCOM, and the Autorité de la concurrence. SREN is one of the first EU member-state digital omnibus statutes anchoring national public-sector data-hosting rules to a sovereign-cloud certification scheme.
Three-year export-promotion policy issued by the Bangladesh Ministry of Commerce on 25 February 2024 covering FY2024-25 through FY2026-27. Sets a $110bn merchandise+services export target by FY2026-27 (vs. ~$56bn FY2023-24 base), restructures the cash-incentive regime, and designates "highest priority" and "special development" sectors including ready-made garments, leather, jute, ICT, pharmaceuticals, agro-processing, light engineering, and plastics. Explicitly designed as the transition framework for navigating Bangladesh's LDC graduation (effective 24 November 2026), at which point the country will lose EU Everything-But-Arms duty-free access and face an estimated 10% average MFN tariff on EU exports.
Ministerial order signed by the French Minister of Economy on 2 February 2024 and published in JORF n°0034 of 10 February 2024 establishing France's first national export-control list under Article 9 of EU Regulation 2021/821 on dual-use goods. The arrêté requires prior authorisation for exports to non-EU third countries of (i) quantum computers and their enabling technologies (qubit devices, control systems, measurement equipment) and (ii) equipment for the design, development, production, test and inspection of advanced electronic components, plus associated software and technology. The annex was substantively replaced by the Arrêté du 27 mars 2025 (explicit technical thresholds including ≥34-qubit systems with C-NOT error ≤10⁻⁴, HBM 6000+ processing performance, cryogenic cooling, dry-etch and EUV-mask tooling, and Si-28/Si-30/Ge isotopically-controlled materials) and is repealed by the Arrêté du 10 mars 2026 with entry into force 11 May 2026.
Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data — the "Data Act" — was published in the Official Journal on 22 December 2023, entered into force on 11 January 2024, and applies generally from 12 September 2025 (with longer transitional periods for IoT product-design obligations under Article 3(1), which apply to products placed on the market after 12 September 2026, and for the data-portability standardisation framework, applicable from 12 September 2027). The Data Act is the third pillar of the EU data-economy framework alongside the GDPR (personal data) and the Data Governance Act 2022/868 (data-intermediation services), and is the world's first horizontal statutory regime governing access to and portability of industrial / IoT / non-personal data — covering by-design data-availability obligations on connected-product manufacturers, a mandatory cloud- switching framework with progressive elimination of switching charges, B2G emergency data-sharing in exceptional needs, unfair-contract-terms protection for SMEs, and safeguards against unlawful international government access to non-personal data held in EU cloud.
BIS amended §§ 734.15 and 734.19 of the Export Administration Regulations (EAR) to clarify that a "release of software" for purposes of the transfer-of-access-information provision includes both source code and object code. A cross-reference was also added from § 734.15 to § 734.19. The practical effect is that providing a decryption key, password, or other access credential to a foreign person to unlock controlled software requires an export licence to the same degree as exporting the software itself would.
Bureau of Industry and Security final rule (88 FR 46071, Doc 2023-15343) adding four entities to the Entity List effective July 18, 2023. Intellexa S.A. (Greece) and Intellexa Limited (Ireland) — the corporate architecture behind the "Predator" commercial spyware platform — and Cytrox Holdings Zrt. (Hungary) and Cytrox AD (North Macedonia) — the developer of the underlying spyware technology — were listed for "trafficking in cyber exploits used to gain access to information systems, thereby threatening the privacy and security of individuals and organizations worldwide." All items subject to the EAR require a license with a presumption-of-denial review policy for all four entities, effectively cutting off access to US-origin hardware, software, and technology.
BIS issued a correcting amendment to the EAR Entity List to add China Aviation Development Harbin Bearing Co., Ltd. — an AVIC subsidiary and specialist precision-bearing manufacturer — that was included in the preamble of the June 14, 2023 final rule (88 FR 38739) but inadvertently omitted from the regulatory text. The entity was designated for acquiring and attempting to acquire US-origin items in support of China's military modernization, including hypersonic weapons development, air-to-air missiles, and weapon lifecycle management using Western software. All EAR-subject items require a licence with a presumption of denial; retroactive effective date of June 16, 2023.
On 20–21 December 2022 OFAC published two final rules (87 FR 78470 and 87 FR 78484) amending regulations across more than 30 sanctions programs to add general licenses (GLs) authorising four categories of humanitarian activity: (1) certain NGO transactions for disaster relief, health, democracy support, education, environmental protection, and peacebuilding; (2) provision of agricultural commodities, medicine, medical devices, replacement parts, and software updates for medical devices to blocked persons for personal, non-commercial use; (3) US government official-business transactions; and (4) official-business transactions of designated international organisations (e.g. UN, ICRC). The rules amended 29 CFR parts spanning Nicaragua, Iraq, Somalia, South Sudan, Yemen, and more than two dozen other sanctioned programs. The NGO GL excludes knowing fund transfers to blocked persons unless specified criteria are met, preserving the core blocking perimeter while lowering humanitarian-access friction.
The Bureau of Industry and Security (BIS) issued an interim final rule (IFR, 87 FR 55241, FR Doc. 2022-19415) amending the Export Administration Regulations (EAR) to authorize the release of specified items to all entities on the Entity List without a licence when such release occurs in the context of a "standards-related activity." The IFR expanded a narrower June 2020 predecessor that had applied only to Huawei and its affiliates; this 2022 rule extended equivalent authorization to the full Entity List. Authorized items include EAR99 technology and software, items controlled solely for anti-terrorism (AT) reasons, and certain cryptographic technology (ECCNs 5D002 and 5E002) used in standards development. The rule amended 15 CFR §§ 734.10, 744.11, 744.16, and Part 772 and was superseded by a broader 2024 IFR that recasted the carve-out as an activity-based exclusion from EAR jurisdiction entirely.
The Bureau of Industry and Security (BIS) amended the Commerce Control List (CCL) under the Export Administration Regulations (EAR) to implement four emerging and foundational technology decisions agreed at the December 2021 Wassenaar Arrangement Plenary meeting, pursuant to ECRA Section 1758. The rule adds new export controls on ultra-wide bandgap semiconductor substrates (gallium oxide Ga₂O₃ and diamond), ECAD software for Gate-All- Around Field-Effect Transistor (GAAFET) integrated circuit development, and Pressure Gain Combustion (PGC) technology for advanced gas turbine engines. Controls require a licence for items destined to countries listed in the NS:1 and AT:1 columns of the Commerce Country Chart; ECAD software controls (ECCN 3D006) have a delayed compliance date of October 14, 2022.
Bangladesh's Cabinet approved the National Industrial Policy 2022 on 11 August 2022, replacing the National Industrial Policy 2016 as the country's foundational umbrella industrial-policy statute; the Ministry of Industries gazetted it on 29 September 2022. The policy sets a target to raise industry's share of GDP to 40% by 2027 and introduces a sector taxonomy covering export-diversification, special-development (electronics, automotive assembly, semiconductors, renewable energy, defence-electronics), priority, reserved, and controlled categories. CMSMEs (Cottage, Micro, Small, and Medium Enterprises) are designated the "main driving force of industrialisation," with sector-specific concessional finance, tax holidays, and cluster-development frameworks, alongside FDI incentives including Bangladeshi citizenship for investors committing USD 1 million. The policy for the first time formally incorporates Bangladesh's informal sector within a national industrial-policy framework, mandating a National Informal Sector Database and a 2022–2027 implementation action plan.
BIS finalized changes to the Export Administration Regulations (EAR) governing controls on cybersecurity items — primarily intrusion software, command-and-control platforms, and surveillance tools capable of disrupting or monitoring information systems without authorization. The final rule, effective May 26 2022, revises License Exception ACE (Authorized Cybersecurity Exports) originally established by an October 2021 interim rule and narrows end-user carve-outs for government end users in Country Group D:5 and A:6 destinations. Exports of affected ECCNs (4A005, 4D001, 4D004, 4E001, 5A001.j, 5B001, 5D001, 5E001) to Country Groups E:1 and E:2 remain prohibited; D:1 through D:5 government-end-user transactions require a license.
BIS published an interim rule on January 12, 2022 delaying the effective date of its October 21, 2021 cybersecurity items interim final rule by 45 days, from January 19, 2022 to March 7, 2022. The underlying October 2021 rule establishes new Export Control Classification Numbers (ECCNs) for cybersecurity items — including intrusion software, command-and-control platforms, and surveillance tools — and introduces License Exception ACE (Authorized Cybersecurity Exports) for national security and anti-terrorism purposes. The delay was granted after twelve public comments highlighted significant compliance challenges, with BIS acknowledging the need for additional time for industry to update procedures and for BIS to issue supplemental guidance before the controls took effect.
The Bureau of Industry and Security (BIS) extended for a second time the temporary unilateral export control on software classified as ECCN 0D521 — "software specially designed for training a Deep Convolutional Neural Network to automate the analysis of geospatial imagery and point clouds" — adding a third year of control through January 6, 2023. The extension was required because COVID-19 prevented the Wassenaar Arrangement from formally convening in 2020 or holding sufficient deliberations in 2021 to consider the US multilateral control proposal submitted in 2020. Only License Exception GOV (§ 740.11(b)(2)(ii)) is available; all other exports require a specific license from BIS.
BIS published an interim final rule on October 21, 2021 establishing new Export Control Classification Numbers (ECCNs 4A005, 4D004, 4E001.c, and 5A001.j) for intrusion software systems, command-and-control platforms, and IP network surveillance tools, implementing the Wassenaar Arrangement 2017 cybersecurity decisions into the Export Administration Regulations (EAR). The rule simultaneously created License Exception ACE (Authorized Cybersecurity Exports), codified at § 740.22, to authorize exports to most destinations while imposing licence requirements — or outright prohibitions — for sales to Country Groups E:1/E:2 governments and certain D-group government end-users. Carve-outs for vulnerability disclosure and cyber-incident-response activities were included to protect legitimate security research. The effective date was subsequently delayed from January 19, 2022 to March 7, 2022 by a separate interim rule (FR 2022-00448), and the rule was finalized with revisions on May 26, 2022 (FR 2022-11282).
On 5 October 2021, Japan's Ministry of Economy, Trade and Industry, jointly with the Ministry of Finance, MEXT and MLIT, published amendments to the Regulatory Notices under the Foreign Exchange and Foreign Trade Act (FEFTA) adding two new categories to the "Core Business Sectors" subject to mandatory prior-notification FDI screening: metal mining (including mineral exploration vessels and land/underwater survey activity) and manufacturing, repair/maintenance or software for equipment used in metal mining (exploration vessels, marine equipment, excavators, drilling machines). The stated purpose is to secure the stable supply of critical mineral resources including rare earths. The amendment took effect 4 November 2021 after a 30-day transitional period; any inward direct investment of 1% or more in a covered business now requires case-by-case government pre-approval.
BIS amends the Export Administration Regulations (EAR) to implement the decision adopted at the Australia Group (AG) Virtual Implementation Meeting of May 2021, creating new ECCN 2D352 to control software designed for nucleic acid assemblers and synthesizers (ECCN 2B352.j) that is capable of designing and building functional genetic elements from digital sequence data. The rule also amends ECCN 2E001 to capture technology for the development of 2D352-controlled software. Exports to most non-allied destinations require a BIS licence under CB Column 2 and AT Column 1, and the classification of 2D352 software as a critical technology triggers mandatory CFIUS filing requirements for qualifying foreign investment.
On June 1, 2021, the Bureau of Industry and Security (BIS) published FR Doc 2021-11585 (86 FR 29189) notifying the public that, effective May 26, 2021, BIS had assumed jurisdiction over certain firearms-related "technology" and "software" — specifically digital files (CAD/AMF/G-code) for 3D-printed firearms and CNC milling instruction files — under ECCNs 0D501 and 0E501 of the Export Administration Regulations (EAR). The transfer was triggered by the Ninth Circuit's April 27, 2021 vacatur of a March 6, 2020 district-court preliminary injunction that had blocked the technology/software prong of the broader January 23, 2020 USML-to-CCL transfer rule. Internet posting of such files now requires a BIS license (review policy: denial), completing the full implementation of the January 2020 rule transferring USML Categories I–III (firearms, guns, and ammunition) from ITAR/State Department to EAR/Commerce jurisdiction.
The Bureau of Industry and Security (BIS) extended for one year the temporary unilateral export control on software classified as ECCN 0D521 — "software specially designed for training a Deep Convolutional Neural Network to automate the analysis of geospatial imagery and point clouds" — adding a second year of control through January 6, 2022. The extension was required because COVID-19 prevented the Wassenaar Arrangement from formally convening in 2020 to consider the US multilateral control proposal submitted that year. Only License Exception GOV (§ 740.11(b)(2)(ii)) is available; all other exports require a specific licence from BIS.
The Bureau of Industry and Security (BIS) amended the Export Administration Regulations (EAR) to establish new Export Control Classification Numbers (ECCNs) 0A977, 0D977, and 0E977 for water cannon systems designed for riot or crowd control, their software, and related technology. A Commerce Control List licence is now required for exports and reexports to most destinations worldwide, with NATO members and certain other close military allies exempt from the new requirement. The rule furthers US foreign policy interests by enabling human rights-based review of crowd-control equipment transfers globally.
BIS published an interim final rule on 5 October 2020 implementing multilateral export controls on six emerging technology categories agreed at the December 2019 Wassenaar Arrangement Plenary meeting, revising Commerce Control List ECCNs 2B001, 3D003, 3E004, 5A004, 5D001, and 9A004. The six technologies are: hybrid additive-manufacturing/CNC machine tools; computational lithography software for extreme-ultraviolet (EUV) mask fabrication; wafer-finishing technology for 5 nm-node production; digital forensics tools that circumvent device authentication to extract raw data; software for monitoring and analysis of communications acquired from a handover interface; and sub-orbital craft. As the first of two US implementing actions for the 2019 Wassenaar Plenary, this rule elevated nascent commercial technologies into permanent CCL classifications enforceable against all non-EAR99 destinations.
Effective 17 August 2020 (published in the Federal Register 20 August 2020, Vol. 85 No. 162, FR Doc 2020-18213), BIS implemented three simultaneous measures targeting Huawei's global supply chain. First, 38 non-U.S. affiliates of Huawei Technologies Co., Ltd. were added to the Entity List with the most restrictive license review policy (presumption of denial) and designated under footnote 1, extending the Huawei-specific Foreign-Produced Direct Product Rule (FDPR) to their operations. Second, the Temporary General License (TGL), which since May 2019 had authorized limited ongoing transactions with Huawei (network maintenance, software updates, standards participation), was allowed to expire on 13 August 2020 and replaced with a narrower authorization. Third, BIS expanded the scope of the Huawei FDPR (General Prohibition Three) to cover foreign-produced items when a footnote 1 entity is a party to any transaction or when the item will be used in the production or development of products for any footnote 1 entity, closing the design-house loophole that had allowed TSMC to supply HiSilicon/Kirin chips as long as Huawei was not the direct importer.