Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
President Trump signed Executive Order 14420 on 26 August 2026, declaring a national emergency under IEEPA and the National Emergencies Act over foreign threats to the US bulk-power system. The order generally prohibits the acquisition, import, transfer, or installation of foreign-produced bulk-power system electric equipment — transformers, inverters, battery storage, generators, circuit breakers, turbines, and industrial control systems, including associated software and remote-access capabilities — where a transaction involves a "Covered Foreign Entity" and poses a risk of sabotage, unauthorized access, or catastrophic disruption to critical infrastructure. Local electric distribution facilities are excluded. No countries or companies are named in the order itself; DOE must publish implementing rules within 120 days (by 24 December 2026) identifying covered equipment and entities, and submit recommended Federal Acquisition Regulation revisions within 180 days.
Prime Minister Phạm Minh Chính issued Directive 38/CĐ-TTg on 5 May 2026, mobilising a cross-ministerial enforcement campaign against intellectual property infringement running 7–30 May 2026 with a 31 May reporting deadline. The directive explicitly responds to the USTR 2026 Special 301 designation of Vietnam as a Priority Foreign Country — the first such designation in eleven years — which triggers a statutory 30-day window for USTR to decide whether to open a Section 301 investigation. Ministries of Public Security, Industry and Trade (Market Surveillance), Information and Communications, and Culture are mobilised for coordinated raids targeting counterfeit-goods exporters, pirated-content platforms, and software-copyright violators, with the Prime Minister signalling enforcement will be permanent rather than a one-off campaign.
Taiwan's Legislative Yuan passed the Artificial Intelligence Basic Act (人工智慧基本法) on third reading on 23 December 2025, and President Lai Ching-te promulgated the 20-article statute on 14 January 2026, bringing it into force immediately. The Act designates the National Science and Technology Council (NSTC) as the central AI-policy competent authority and codifies seven governance principles — sustainability and well-being, human autonomy, privacy protection and data governance, cybersecurity and safety, transparency and explainability, fairness and non-discrimination, and accountability — that apply to all public-sector AI procurement and high-risk sectoral applications. The statute establishes a statutory foundation for the Taiwan AI Action Plan 2.0, mandates an Executive Yuan National AI Strategy Committee, and provides authority for sector-specific implementing regulations by FSC, NCC, MOHW, and MOTC across finance, telecoms, medical, and autonomous-vehicle AI within a two-year window. As the first national AI governance statute in the Greater China region and the third globally after the EU AI Act and South Korea's AI Basic Act, it frames regulatory expectations for the companies at the heart of the global AI hardware supply chain — TSMC, NVIDIA ODM partners, and advanced-packaging incumbents — that are headquartered or operate substantially in Taiwan.
On 10 December 2025 the National Assembly of Vietnam adopted Law No. 134/2025/QH15 on Artificial Intelligence (8 chapters, 35 articles), Vietnam's first dedicated AI statutory framework and one of the first comprehensive horizontal AI laws in Southeast Asia. The law establishes a three-tier risk-based regulatory architecture (high / medium / low) for the research, development, provision, deployment, and use of AI systems; defines the rights and obligations of providers, deployers, importers, distributors, and users; and mandates state oversight via the Ministry of Information & Communications and Ministry of Science & Technology. Prohibited acts include systematic deception, manipulation of human perception, generation of fake content endangering national security, exploitation of vulnerable populations, and obstruction of human-supervision mechanisms. The law applies to Vietnamese agencies, organizations, and individuals as well as foreign organizations and individuals involved in AI-related activities in Vietnam, taking effect 1 March 2026 with 12-18 month transition windows for existing systems depending on sector.
India's Ministry of Electronics and Information Technology (MeitY) notified the Digital Personal Data Protection Rules, 2025 via Gazette notification G.S.R. 846(E) on 13 November 2025, operationalising the 2023 DPDP Act. The Rules introduce a "negative list" cross-border personal-data transfer regime under Rule 14, verifiable parental consent, breach-notification windows, and tiered penalties up to INR 250 crore. Implementation is phased: Data Protection Board provisions in force on notification, Consent Manager rules from 13 Nov 2026, and core data-fiduciary / cross-border-transfer obligations from 13 May 2027.
The National Assembly of Vietnam passed the Personal Data Protection Law (Luật Bảo vệ dữ liệu cá nhân), Law No. 91/2025/QH15, on 26 June 2025; it enters into force on 1 January 2026. The PDPL is Vietnam's first statutory (rather than decree-level) personal-data-protection framework, elevating the prior Decree 13/2023/ND-CP (PDPD) regime into a 5-chapter, 39-article primary statute and adding revenue-based administrative penalties of up to 5% of prior-year annual revenue for cross-border data-transfer violations and up to 10x illegal gains for unlawful data trading. The law is implemented by Decree 356/2025/ND-CP (issued 31 December 2025, effective 1 January 2026) and applies extraterritorially to foreign organisations offering services to or processing the personal data of Vietnam residents.
BIS (acting through its Office of Information and Communications Technology and Services, OICTS) published a final rule under Executive Order 13873's ICTS authority prohibiting certain connected-vehicle (CV) transactions involving hardware and software designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction of the People's Republic of China or the Russian Federation. The rule reaches the Vehicle Connectivity System (VCS — hardware/software enabling external RF connectivity above 450 MHz) and the Automated Driving System (ADS) software stack. Effective 17 March 2025, with phased prohibitions: import/sale of CVs incorporating covered software prohibited from model year 2027; import of covered VCS hardware prohibited from model year 2030 (or 1 January 2029 for hardware not associated with a model year). Importers and connected-vehicle manufacturers must file annual Declarations of Conformity.
Bolivia's Decreto Supremo 5309, signed by President Luis Arce on 8 January 2025, mandates that all public-sector entities migrate their information systems to Free Software and Open Standards by 12 January 2030. The decree includes a data-localization provision barring storage of non-public state data on servers outside Bolivian territory; government cloud workloads must run either on public-entity infrastructure or on state-operated cloud services within the country. AGETIC (Bolivia's ICT agency) is responsible for overseeing compliance and developing the implementation plan (approved via the companion Decreto Supremo 5322 on 23 January 2025).
The Republic of Korea's National Assembly passed the Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trustworthiness ("AI Basic Act") in plenary session on 26 December 2024, consolidating 19 separate AI bills tabled in the 22nd National Assembly. The statute was promulgated on 21 January 2025 and takes effect on 22 January 2026 after a one-year preparation period. Korea becomes the second jurisdiction worldwide — after the EU AI Act — to enact a comprehensive horizontal AI law, and the first in the Asia-Pacific. The Act establishes a risk-tiered regime targeting "high-impact" AI in healthcare, energy, public services, employment decisions, and generative-AI labelling, with extraterritorial reach over foreign providers whose systems affect the Korean market or users (mandatory local representative). It creates an AI Safety Institute, a national AI policy "control tower," and R&D / standardisation programmes under MSIT. Penalties are modest by international comparison — fines up to KRW 30 million plus a one-year grace period before full enforcement.
The National Assembly of Vietnam passed the Law on Data (Luật Dữ liệu), No. 60/2024/QH15, on 30 November 2024; it enters into force on 1 July 2025. The Law is Vietnam's first comprehensive horizontal data-governance statute, extending regulation beyond personal data (already covered by Decree 13/2023/ND-CP) to all digital data — public, private, and sectoral. It introduces statutory categories of "important data" (dữ liệu quan trọng) and "core data" (dữ liệu cốt lõi) tied to national-defence and national-security review for cross-border transfer, and establishes the National Data Centre under the Ministry of Public Security plus a statutory data-broker / data-services licensing framework.
Regulation (EU) 2024/2847 of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, signed 23 October 2024 and entering into force 10 December 2024. The CRA is the first EU statutory cybersecurity regime covering all hardware and software products with a direct or indirect data connection placed on the EU market, imposing essential cybersecurity requirements, conformity assessment with CE marking, mandatory vulnerability handling, and 24-hour early-warning notification of actively-exploited vulnerabilities to ENISA. Main manufacturer obligations apply from 11 December 2027; conformity-assessment-body notification provisions apply from 11 June 2026 and reporting obligations from 11 September 2026. Penalties reach EUR 15M or 2.5% of global annual turnover.
The U.S. Treasury's Office of Foreign Assets Control (OFAC) published in the Federal Register (89 FR 84472–84474, FR Doc 2024-24524) three general licenses issued under the Western Balkans Stabilization Regulations (31 CFR Part 588): GL 3A, GL 4, and GL 5. All three were originally issued on 18 June 2024 concurrent with OFAC's expansion of Republika Srpska / Dodik-network designations; the 23 October 2024 Federal Register notice formalises them per the Administrative Procedure Act notice requirements. GL 3A (which superseded GL 3 of 16 November 2023) authorises transactions involving certain WBSR-blocked entities that are ordinarily incident and necessary to the exportation or re-exportation of agricultural commodities, medicine, medical devices, replacement parts and components, software updates, or activities involving medical prevention, diagnosis, treatment, or clinical trials. GL 4 authorises wind-down transactions with entities blocked on 18 June 2024 through a defined cutoff. GL 5 authorises transactions ordinarily incident and necessary to the manufacture, distribution, operation, installation, or maintenance/repair of drinking-water pumps manufactured or distributed by the WBSR-blocked Bosnian Serb entity Kaldera Company EL PGP d.o.o. (and 50%-or-more-owned subsidiaries), preserving municipal water supply continuity.
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) issued a final rule amending three sanctions programs. The rule adds a new general license at 31 CFR § 525.512 to the Burma Sanctions Regulations authorizing the provision of agricultural commodities, medicine, medical devices, replacement parts and components for medical devices, and software updates for medical devices to individuals whose property and interests in property are blocked. It also updates the authorities section of the Burma Sanctions Regulations to reflect recent legislation, replaces "the Office of Foreign Assets Control" / "the Director of the Office of Foreign Assets Control" with the acronym "OFAC" in three sections of the Sudan Stabilization Sanctions Regulations, and corrects a cross-reference in the Ukraine-/Russia- Related Sanctions Regulations. The rule is effective on publication.
The Bureau of Industry and Security (BIS) issued an interim final rule (FR Doc. 2024-15810) amending the Export Administration Regulations (EAR) so that certain "releases" of technology and software during "standards-related activities" are no longer subject to the EAR. The rule revises 15 CFR §734.10 and consolidates the patchwork of prior carve-outs (May 2019 Huawei 5G TGL, June 2020 IFR, September 2022 Entity-List-wide IFR) into a single activity-based exclusion. The change enables US firms to participate in international standards bodies (IEEE, 3GPP, ITU, ISO, IEC) alongside Entity-Listed parties — most consequentially Huawei — without licence exposure. Comments were due September 16, 2024.
The European Union's Artificial Intelligence Act, Regulation (EU) 2024/1689, was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. It establishes the world's first horizontal, risk-tiered legal framework for the development, market placement, and use of AI systems — covering prohibited practices, high-risk systems, general-purpose AI models, and minimal-risk applications — with extraterritorial reach over any provider placing an AI system on the EU market or whose output is used in the EU. Penalties reach up to EUR 35 million or 7% of global annual turnover. Application is staged: prohibitions from 2 February 2025, GPAI and governance from 2 August 2025, the bulk of high-risk obligations from 2 August 2026, and product-safety-embedded high-risk systems from 2 August 2027.
Loi n° 2024-449 of 21 May 2024, known as the SREN law (Sécuriser et Réguler l'Espace Numérique), was definitively adopted by the French Parliament on 10 April 2024, validated in part by the Conseil Constitutionnel on 17 May 2024 (Decision n° 2024-866 DC), promulgated by the President on 21 May 2024, and published in the Journal Officiel on 22 May 2024. SREN is France's digital-sovereignty omnibus statute: it transposes parts of the EU Digital Services Act (Regulation 2022/2065), Digital Markets Act (Regulation 2022/1925), and Data Governance Act (Regulation 2022/868) into French law and layers national-level instruments on top — most consequentially a data-localisation hook for sensitive public-sector data tied to the ANSSI SecNumCloud sovereign-cloud certification scheme, an ARCOM-enforced age-verification regime for adult-content sites (with €250k or 2%-of-turnover fines and account-closure powers), an "anti-scam" cybersecurity filter requiring browsers and DNS resolvers to block ANSSI-designated fraudulent domains, a jeux-en-ligne (JONUM) regime for cryptoasset-adjacent gaming, and a coordination framework between CSA, CNIL, ARCOM, and the Autorité de la concurrence. SREN is one of the first EU member-state digital omnibus statutes anchoring national public-sector data-hosting rules to a sovereign-cloud certification scheme.
Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data — the "Data Act" — was published in the Official Journal on 22 December 2023, entered into force on 11 January 2024, and applies generally from 12 September 2025 (with longer transitional periods for IoT product-design obligations under Article 3(1), which apply to products placed on the market after 12 September 2026, and for the data-portability standardisation framework, applicable from 12 September 2027). The Data Act is the third pillar of the EU data-economy framework alongside the GDPR (personal data) and the Data Governance Act 2022/868 (data-intermediation services), and is the world's first horizontal statutory regime governing access to and portability of industrial / IoT / non-personal data — covering by-design data-availability obligations on connected-product manufacturers, a mandatory cloud- switching framework with progressive elimination of switching charges, B2G emergency data-sharing in exceptional needs, unfair-contract-terms protection for SMEs, and safeguards against unlawful international government access to non-personal data held in EU cloud.
BIS amended §§ 734.15 and 734.19 of the Export Administration Regulations (EAR) to clarify that a "release of software" for purposes of the transfer-of-access-information provision includes both source code and object code. A cross-reference was also added from § 734.15 to § 734.19. The practical effect is that providing a decryption key, password, or other access credential to a foreign person to unlock controlled software requires an export licence to the same degree as exporting the software itself would.
The Bureau of Industry and Security (BIS) issued an interim final rule (IFR, 87 FR 55241, FR Doc. 2022-19415) amending the Export Administration Regulations (EAR) to authorize the release of specified items to all entities on the Entity List without a licence when such release occurs in the context of a "standards-related activity." The IFR expanded a narrower June 2020 predecessor that had applied only to Huawei and its affiliates; this 2022 rule extended equivalent authorization to the full Entity List. Authorized items include EAR99 technology and software, items controlled solely for anti-terrorism (AT) reasons, and certain cryptographic technology (ECCNs 5D002 and 5E002) used in standards development. The rule amended 15 CFR §§ 734.10, 744.11, 744.16, and Part 772 and was superseded by a broader 2024 IFR that recasted the carve-out as an activity-based exclusion from EAR jurisdiction entirely.
BIS published an interim rule on January 12, 2022 delaying the effective date of its October 21, 2021 cybersecurity items interim final rule by 45 days, from January 19, 2022 to March 7, 2022. The underlying October 2021 rule establishes new Export Control Classification Numbers (ECCNs) for cybersecurity items — including intrusion software, command-and-control platforms, and surveillance tools — and introduces License Exception ACE (Authorized Cybersecurity Exports) for national security and anti-terrorism purposes. The delay was granted after twelve public comments highlighted significant compliance challenges, with BIS acknowledging the need for additional time for industry to update procedures and for BIS to issue supplemental guidance before the controls took effect.
On June 1, 2021, the Bureau of Industry and Security (BIS) published FR Doc 2021-11585 (86 FR 29189) notifying the public that, effective May 26, 2021, BIS had assumed jurisdiction over certain firearms-related "technology" and "software" — specifically digital files (CAD/AMF/G-code) for 3D-printed firearms and CNC milling instruction files — under ECCNs 0D501 and 0E501 of the Export Administration Regulations (EAR). The transfer was triggered by the Ninth Circuit's April 27, 2021 vacatur of a March 6, 2020 district-court preliminary injunction that had blocked the technology/software prong of the broader January 23, 2020 USML-to-CCL transfer rule. Internet posting of such files now requires a BIS license (review policy: denial), completing the full implementation of the January 2020 rule transferring USML Categories I–III (firearms, guns, and ammunition) from ITAR/State Department to EAR/Commerce jurisdiction.