Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
Kenya's Senate introduced the Artificial Intelligence Bill, 2026 (Senate Bills No. 4 of 2025) on 19 February 2026, sponsored by Nominated Senator Karen Nyamu; the bill received its first reading on 2 April 2026 and was committed to the Senate Standing Committee on Information, Communication and Technology for public-input review. The bill establishes a risk-based AI regulatory framework explicitly modelled on the EU AI Act (Regulation 2024/1689), creating a four-tier classification (prohibited / high-risk / limited-risk / minimal-risk) with conformity- assessment, technical-documentation, and human-oversight obligations for high-risk AI systems. It creates the Office of the Artificial Intelligence Commissioner as a new statutory regulator with licensing, enforcement, and administrative-penalty powers, and bans social-scoring systems, real-time remote biometric identification in public spaces, emotion recognition in workplaces and education, and predictive policing based on profiling. The bill is the first comprehensive national AI regulatory instrument in Africa, closing a structural geographic gap in the global AI-governance architecture and positioning Kenya as the Brussels-effect template-recipient for the African continent.
Taiwan's Legislative Yuan passed the Artificial Intelligence Basic Act (人工智慧基本法) on third reading on 23 December 2025, and President Lai Ching-te promulgated the 20-article statute on 14 January 2026, bringing it into force immediately. The Act designates the National Science and Technology Council (NSTC) as the central AI-policy competent authority and codifies seven governance principles — sustainability and well-being, human autonomy, privacy protection and data governance, cybersecurity and safety, transparency and explainability, fairness and non-discrimination, and accountability — that apply to all public-sector AI procurement and high-risk sectoral applications. The statute establishes a statutory foundation for the Taiwan AI Action Plan 2.0, mandates an Executive Yuan National AI Strategy Committee, and provides authority for sector-specific implementing regulations by FSC, NCC, MOHW, and MOTC across finance, telecoms, medical, and autonomous-vehicle AI within a two-year window. As the first national AI governance statute in the Greater China region and the third globally after the EU AI Act and South Korea's AI Basic Act, it frames regulatory expectations for the companies at the heart of the global AI hardware supply chain — TSMC, NVIDIA ODM partners, and advanced-packaging incumbents — that are headquartered or operate substantially in Taiwan.
On 10 December 2025 the National Assembly of Vietnam adopted Law No. 134/2025/QH15 on Artificial Intelligence (8 chapters, 35 articles), Vietnam's first dedicated AI statutory framework and one of the first comprehensive horizontal AI laws in Southeast Asia. The law establishes a three-tier risk-based regulatory architecture (high / medium / low) for the research, development, provision, deployment, and use of AI systems; defines the rights and obligations of providers, deployers, importers, distributors, and users; and mandates state oversight via the Ministry of Information & Communications and Ministry of Science & Technology. Prohibited acts include systematic deception, manipulation of human perception, generation of fake content endangering national security, exploitation of vulnerable populations, and obstruction of human-supervision mechanisms. The law applies to Vietnamese agencies, organizations, and individuals as well as foreign organizations and individuals involved in AI-related activities in Vietnam, taking effect 1 March 2026 with 12-18 month transition windows for existing systems depending on sector.
Italy enacted Legge 23 settembre 2025, n. 132 — "Disposizioni e deleghe al Governo in materia di intelligenza artificiale" — published in Gazzetta Ufficiale Serie Generale n. 223 of 25 September 2025 (atto 25G00143) and entered into force on 10 October 2025. The statute makes Italy the first EU member state to enact a comprehensive national AI law complementing Regulation (EU) 2024/1689 (EU AI Act), designating AgID (Agency for Digital Italy) and ACN (National Cybersecurity Agency) as national oversight authorities under Presidency-of-the-Council-of-Ministers coordination. It sets sectoral rules for healthcare, labour, intellectual professions, public administration and the judiciary; authorises up to €1 billion in state-backed venture capital (via CDP Venture Capital) for AI, cybersecurity and telecoms; creates criminal penalties of up to five years' imprisonment for harmful deepfakes; mandates parental consent for under-14 users; and delegates secondary legislation to the Government across multiple domains.
The Mauritius Finance Act 2025 (Act No. 18 of 2025), assented to by Acting President Dharambeer Gokhool G.C.S.K. and gazetted in August 2025, is an omnibus financial-sector statute amending the Companies Act, Financial Services Act 2007, Income Tax Act, Bank of Mauritius Act, and FIAMLA. Its headline provisions are: (i) introduction of a Qualified Domestic Minimum Top-Up Tax (QDMTT) aligned with the OECD GloBE Pillar Two rules, imposing a 15% effective minimum tax on Mauritius profits of MNE groups with consolidated revenue ≥ EUR 750 million; (ii) new fiscal incentives for investments in AI infrastructure and Virtual Asset Service Provider (VASP) licensees; (iii) enhanced beneficial-ownership (UBO) identification and record-keeping requirements under the Companies Act, aligned with FATF Recommendation 24; (iv) tightened substance and economic-presence requirements for Global Business Companies (GBCs); and (v) an expanded AML/CFT administrative- penalty framework under FIAMLA.
The Republic of Korea's National Assembly passed the Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trustworthiness ("AI Basic Act") in plenary session on 26 December 2024, consolidating 19 separate AI bills tabled in the 22nd National Assembly. The statute was promulgated on 21 January 2025 and takes effect on 22 January 2026 after a one-year preparation period. Korea becomes the second jurisdiction worldwide — after the EU AI Act — to enact a comprehensive horizontal AI law, and the first in the Asia-Pacific. The Act establishes a risk-tiered regime targeting "high-impact" AI in healthcare, energy, public services, employment decisions, and generative-AI labelling, with extraterritorial reach over foreign providers whose systems affect the Korean market or users (mandatory local representative). It creates an AI Safety Institute, a national AI policy "control tower," and R&D / standardisation programmes under MSIT. Penalties are modest by international comparison — fines up to KRW 30 million plus a one-year grace period before full enforcement.
The European Union's Artificial Intelligence Act, Regulation (EU) 2024/1689, was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. It establishes the world's first horizontal, risk-tiered legal framework for the development, market placement, and use of AI systems — covering prohibited practices, high-risk systems, general-purpose AI models, and minimal-risk applications — with extraterritorial reach over any provider placing an AI system on the EU market or whose output is used in the EU. Penalties reach up to EUR 35 million or 7% of global annual turnover. Application is staged: prohibitions from 2 February 2025, GPAI and governance from 2 August 2025, the bulk of high-risk obligations from 2 August 2026, and product-safety-embedded high-risk systems from 2 August 2027.
Japan's National Diet enacted the Act on the Protection and Use of Critical Economic Security Information (重要経済安保情報の保護及び活用に関する法律, Act No. 27 of 2024) on 10 May 2024; it was promulgated on 17 May 2024 and came into full operation on 16 May 2025. The law establishes Japan's first peace-time economic-security clearance regime extending to private-sector employees. It designates "Critical Economic Security Information" (CESI) covering threat-intelligence on critical-infrastructure cyber attacks, regulatory-review information on essential infrastructure, and vulnerability data on critical-product supply chains; mandates Cabinet Office "適性評価" (suitability assessment) for cleared personnel; and imposes criminal penalties of up to five years' imprisonment for unauthorised disclosure. The CESI Act complements the 2022 Economic Security Promotion Act (ESPA), closing the information-protection gap and aligning Japan's framework with Five Eyes and EU partners for joint R&D and dual-use cooperation.
FinCEN published the Beneficial Ownership Information Access and Safeguards Final Rule (FR Doc 2023-27973, 88 FR 88732, December 22, 2023; effective February 20, 2024), implementing the access and disclosure provisions of Section 6403(c) of the Corporate Transparency Act (CTA) enacted as part of the Anti-Money Laundering Act of 2020. The rule defines six categories of authorized recipients permitted to access the FinCEN BOI database — US federal agencies engaged in national security/intelligence/law enforcement, state/local/tribal law enforcement, foreign law enforcement and competent authorities (via intermediary federal agency), financial institutions using BOI for customer due diligence (CDD), federal functional regulators assessing financial-institution CDD compliance, and Treasury officers/employees. Access is to be phased in, beginning with a 2024 pilot for key federal agencies before extending to financial institutions and their supervisors. The rule establishes data-security standards, re-disclosure prohibitions, and oversight mechanisms governing each recipient category.
Saudi Arabia's Personal Data Protection Law (PDPL), issued under Royal Decree M/19 (16 September 2021) and substantively amended by Royal Decree M/148 (27 March 2023), entered into force on 14 September 2023 with a one-year transition period that ended on 14 September 2024 — at which point the Saudi Data & Artificial Intelligence Authority (SDAIA) became the binding regulator with full enforcement powers. Alongside the Implementing Regulations and the Regulations on the Transfer of Personal Data Outside the Kingdom (both issued 7 September 2023), SDAIA published in 2024 a set of four pre-approved Standard Contractual Clauses templates (C2C, C2P, P2P, P2C) governing cross-border transfers. The regime establishes consent requirements, DPO appointment, a 72-hour breach notification duty, and prior-clearance / SCC-or-BCR-style conditions on personal-data exports out of Saudi Arabia.
The Bureau of Industry and Security (BIS) establishes procedures under 15 C.F.R. Part 764, Supplement No. 2, for submitting classified national security information ex parte and in camera to courts reviewing enforcement actions taken under the Export Administration Regulations (EAR). Implementing the judicial-review provision of the Export Control Reform Act of 2018 (ECRA § 1702(d)(4)), the rule enables BIS to present classified evidence to a reviewing court without public disclosure, protecting sensitive intelligence sources and methods while preserving respondents' due-process rights. The rule applies to any EAR enforcement action subject to judicial review and was effective upon publication.