Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
The Department of Commerce's International Trade Administration published a Federal Register notice on 10 April 2026 (91 FR 18412, doc 2026-06952) opening the inaugural Call for Proposals for the American AI Exports Program established under Executive Order 14320. Proposals are accepted from 1 April 2026 through 5:00 pm EDT on 30 June 2026 from US industry-led "pre-set" consortia offering full-stack American AI export packages — AI-optimised hardware, data pipelines, AI models and systems, security and cybersecurity measures, and sector-specific applications — for presentation by the US government to foreign public- and private-sector buyers. Designated consortia receive priority US-government advocacy, priority consideration for export-control licence engagement, interagency coordination, and federal-financing referrals (EXIM, DFC), with a 14-business-day completeness review and 60-calendar-day designation decision once a proposal is deemed complete.
Vietnam's National Assembly passed Law on Cybersecurity No. 116/2025/QH15 on 10 December 2025 (434 of 443 deputies in favour), effective 1 July 2026. The law supersedes both the 2018 Cybersecurity Law (Law 24/2018/QH14) and the 2015 Law on Cyber Information Security, consolidating cybersecurity, cyber-information-security, and network-information-security into a unified Ministry of Public Security-led framework. It retains data-localization obligations for foreign digital-service providers handling personal data, user-generated content, and relationship graphs of Vietnamese users (minimum 24-month retention), introduces 6-hour urgent / 24-hour standard content take-down windows on MPS request, expressly prohibits AI/deepfake forgery of images, voices, and videos for illegal purposes, and mandates child-safety platform measures.
On 20 November 2025 the White House and US Department of Commerce / Bureau of Industry and Security (BIS) authorised Abu Dhabi AI holding company G42 to import advanced computing chips — equivalent to approximately 35,000 Nvidia GB300 Blackwell processors — under the UAE-pioneered Regulated Technology Environment (RTE) compliance framework. The RTE is an Emirati-designed technology governance and audit architecture, developed by G42 and approved under BIS guidelines, with binding UAE-side controls to prevent onward diversion to foreign adversary nations. The authorisation accelerates the Stargate UAE project — a 1 GW AI compute cluster being built by G42 for OpenAI in partnership with Oracle, Cisco, NVIDIA, and SoftBank Group — and represents the first concluded major country-level advanced-compute authorisation following the May 2025 rescission of the Biden-era AI Diffusion Rule.
On 18 November 2025, the European Supervisory Authorities (EBA, ESMA, and EIOPA) jointly designated 19 Critical ICT Third-Party Providers (CTPPs) under DORA Article 31, with immediate effect — the first-ever exercise of direct EU financial-regulator supervision over hyperscale cloud and infrastructure providers. The designated entities include Amazon Web Services, Microsoft Azure, Google Cloud, Deutsche Telekom, Oracle, SAP, IBM, Bloomberg LP, London Stock Exchange Group (LSEG), Tata Consultancy Services, and Orange, among others. Designation triggers direct oversight by a lead ESA (EBA for banking-critical, ESMA for capital-markets-critical, EIOPA for insurance-critical) via Joint Examination Teams (JETs), with powers to conduct investigations, carry out on-site inspections, and impose fines of up to 1% of average daily worldwide turnover per day for non-compliance.
The Joint Committee of the European Supervisory Authorities (EBA, EIOPA, ESMA) published the Guide on DORA Oversight Activities (JC 2025 29) on 15 July 2025, the definitive operational description of how the ESAs will supervise Critical ICT Third-Party Providers (CTPPs) designated under DORA Art. 31. The guide establishes the governance of Joint Examination Teams (JETs), the oversight examination lifecycle (planning, risk assessment, binding recommendations, follow-up), penalty processes of up to 1% of average daily worldwide turnover per day of breach (DORA Art. 35(6)), and lead-overseer assignments (EBA for banking, ESMA for capital markets, EIOPA for insurance). It is authoritative ESA interpretive guidance, not legally binding per se, but constitutes the supervisory playbook CTPPs and their dependent financial entities must plan against.
On 14 June 2025 Vietnam's 15th National Assembly adopted Law No. 71/2025/QH15 on the Digital Technology Industry (DTI Law) at its 9th session. The Law enters into force on 1 January 2026 (with certain provisions phased) and is the world's first standalone primary statute dedicated to the digital technology industry, covering digital-tech production and services, semiconductor manufacturing, artificial-intelligence systems, digital assets (legally recognised as property under the Civil Code), and Concentrated Digital Technology Zones. It codifies sector-specific incentives — multi-year corporate income tax reductions, R&D-cost deductions, preferential public procurement, five-year personal income tax exemption for high-quality digital professionals, five-year visa and work-permit exemptions for foreign experts, and 50% subsidy for SME advanced-technology acquisition — and sets headline targets of 150,000 digital-tech enterprises and USD 74bn digital-economy contribution by 2030/2035 (with USD 43bn / USD 74bn variants in different government summaries).
On 13 May 2025, two days before the AI Diffusion Rule's primary 15 May 2025 compliance date, the Trump administration's BIS announced it would rescind the Biden-era Framework for AI Diffusion (90 FR 4544) and simultaneously issued three guidance documents that re-routed US AI export policy through existing EAR authorities. The package comprises (1) GP10 guidance asserting that all ECCN 3A090 ICs designed by PRC-headquartered firms are presumptively EAR-violative, with Huawei Ascend 910B/910C/910D processors named explicitly — making US- and non-US-person use, transfer, financing, or servicing of those chips anywhere in the world a presumptive General Prohibition 10 violation; (2) a policy statement warning industry that supplying US advanced computing ICs for training or inference of Chinese AI models risks EAR enforcement; and (3) industry guidance on diversion-prevention diligence. BIS stated a formal Federal Register rescission and replacement rule would follow.
President Trump signed Executive Order 14179 on 23 January 2025 (published in the Federal Register on 31 January 2025 as 90 FR 8741, doc 2025-02172). The order revokes Biden-era Executive Order 14110 of 30 October 2023 ("Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence") and directs federal agencies to identify and rescind, revise, or suspend any policies, regulations, memoranda, or guidance documents adopted pursuant to the revoked Biden order. It mandates that the Assistant to the President for Science and Technology, the Assistant to the President for National Security Affairs, the Special Advisor for AI and Crypto, and the Assistant to the President for Economic Policy develop an AI Action Plan within 180 days to "sustain and enhance America's global AI dominance." The plan was released on 23 July 2025. EO 14179 reframes US AI industrial-policy posture from safety-first regulation to deregulation, infrastructure investment, and export-competitiveness.
Bolivia's Decreto Supremo 5309, signed by President Luis Arce on 8 January 2025, mandates that all public-sector entities migrate their information systems to Free Software and Open Standards by 12 January 2030. The decree includes a data-localization provision barring storage of non-public state data on servers outside Bolivian territory; government cloud workloads must run either on public-entity infrastructure or on state-operated cloud services within the country. AGETIC (Bolivia's ICT agency) is responsible for overseeing compliance and developing the implementation plan (approved via the companion Decreto Supremo 5322 on 23 January 2025).
The U.S. Treasury's Office of Foreign Assets Control (OFAC) issued a final rule amending 31 CFR § 560.540 of the Iranian Transactions and Sanctions Regulations (ITSR) to incorporate, with amendments, General License (GL) D-2 — originally issued on OFAC's website on September 23, 2022 — which authorizes the export, reexport, and provision of certain services, software, and hardware incident to communications over the internet to persons in Iran. The codification preserves the GL D-2 expansion (cloud-based services; third-country importation of hardware/software previously exported to Iran; ex-Iran installation, repair and replacement services; case-by-case licensing for internet-freedom activities) and updates the § 560.540 List of Services, Software, and Hardware Incident to Communications. Effective June 17, 2024, the List is amended to exclude laptops, tablets, and personal computing devices with an Adjusted Peak Performance (APP) exceeding 1 Weighted TeraFLOP (WT) — narrowing the consumer-electronics authorization to lower-performance devices and aligning the carve-out with broader BIS-style compute thresholds. The rule does not relax primary ITSR prohibitions; it codifies a humanitarian / internet-freedom exception while inserting a narrow high-performance-compute carve-out.
On April 4, 2024, the Bureau of Industry and Security published an interim final rule (89 FR 23876) providing corrections, clarifications, and targeted revisions to the October 2023 advanced-computing and semiconductor manufacturing equipment rules. The most substantive change splits the former License Exception NAC (Notified Advanced Computing) into two separate exceptions: NAC (retaining the 25-day prior notification requirement) and a new ACA (Advanced Computing Authorized) exception that permits certain shipments without advance notification. The rule also adds ECCN 4A090.b covering computers and assemblies containing advanced ICs, restores national-security controls to several ECCNs, and addresses various technical drafting errors from the October 2023 rules.
Three Commission Delegated Regulations (CDR 2024/1772, 1773, 1774) adopted 13 March 2024 and published in the EU Official Journal on 25 June 2024 constitute the first batch of binding Level 2 implementing rules under DORA (Regulation (EU) 2022/2554). CDR 2024/1772 sets ICT incident classification criteria and materiality thresholds for mandatory reporting; CDR 2024/1773 specifies the required content of contractual policies for ICT third-party services supporting critical or important functions; CDR 2024/1774 defines the ICT risk management tools, methods, processes, and policies — including a simplified framework for smaller in-scope entities. All three apply from 17 January 2025 alongside the parent DORA regulation, covering approximately 22,000 EU regulated financial entities.
On 25 October 2023 the Bureau of Industry and Security published an interim final rule (88 FR 73424; FR Doc 2023-23055) making substantive revisions to the October 7 2022 advanced-computing IFR, incorporating 43 public comments covering 78 topics. The rule replaced the prior TOPS-based performance metric with a new "Total Processing Performance" (TPP) / performance-density dual-threshold structure for ECCN 3A090, splitting the control into tiers 3A090.a (full licence requirement for highest-capability datacenter AI chips) and 3A090.b (new License Exception NAC with 25-day prior notification for the intermediate tier). Geographic scope was expanded from China-and-Macau to Country Groups D:1/D:4/D:5 to block diversion via third-country intermediaries and offshore datacenters.
The US Bureau of Industry and Security issued an interim final rule on 17 October 2023 that substantially expanded the advanced-computing and semiconductor manufacturing controls first imposed in October 2022. The rule closed the performance-threshold workaround that NVIDIA had used to ship China-specific A800/H800 GPUs, replacing it with a "performance density" metric and adding a new "Notified Advanced Computing" licence category. It expanded controls on chipmaking equipment (additional ECCNs covering deposition, etch, metrology), pulled 21 additional countries (mostly Middle East / Central Asia) into a regional licensing scheme to prevent transshipment, and added 13 Chinese entities to the Entity List including AI-chip designers.
Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA) is the EU's first horizontal cyber- and ICT-resilience instrument for the financial sector. Adopted 14 December 2022 and published in the Official Journal on 27 December 2022, it entered into force on 16 January 2023 and applies from 17 January 2025. DORA covers approximately 22,000 EU regulated financial entities across ~20 entity types (credit institutions, insurers, investment firms, CCPs, trading venues, crypto-asset service providers, etc.) under five pillars: ICT risk management, ICT-incident reporting, digital operational resilience testing (including threat-led penetration testing for significant entities), ICT third-party risk management, and information sharing. Structurally novel, DORA establishes the Critical ICT Third-Party Provider (CTPP) oversight regime under which the European Supervisory Authorities (EBA, ESMA, EIOPA) acquire direct supervisory powers over hyperscale cloud providers (AWS, Azure, GCP, Oracle) servicing EU financial entities — the first EU mechanism for ESA direct oversight of non-financial cloud providers.
Government Decree 53/2022/ND-CP, signed 15 August 2022 and effective 1 October 2022, implements Article 26 of Vietnam's 2018 Law on Cybersecurity. It mandates in-country storage of three categories of data — personal data of users in Vietnam, user-generated data, and user-relationship data — for both domestic and foreign cyberspace- service providers, with a minimum 24-month retention period. Foreign enterprises providing telecoms, data storage, domain names, e-commerce, online payments, social networks, online video games, or messaging services to users in Vietnam must establish a Vietnamese branch or representative office within 12 months of a Minister of Public Security written request. The decree closes a four-year implementation gap on the 2018 Cybersecurity Law and is the principal Vietnamese digital-trade barrier alongside Decree 13/2023/ND-CP (Personal Data Protection).