Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
The Defence Trade Controls Amendment Act 2024 (C2024A00021) received Royal Assent on 8 April 2024 and created three new criminal offences in the Defence Trade Controls Act 2012: section 10A (supply of Defence and Strategic Goods List technology in Australia to a non-exempt foreign person); section 10B (secondary supply of DSGL Part 1 Munitions or Part 2 Dual-Use Sensitive/Very Sensitive goods or technology outside Australia when originally exported from Australia); and section 10C (provision of DSGL Part 1 services to foreign nationals outside Australia). All three offences carry maximum penalties of 10 years imprisonment or 2,500 penalty units (~A$782,500), or both. The offence framework commenced 1 September 2024 with a six-month compliance-transition period; criminal liability attached from 1 March 2025. The Act also codifies AUKUS-partnership exemptions, carving out supplies to and from citizens and permanent residents of the United Kingdom and United States, underpinning the licence-free trilateral technology-transfer environment sought under AUKUS Pillar 2.
The Cyberspace Administration of China (CAC) issued the Provisions on Promoting and Regulating Cross-Border Data Flows (《促进和规范数据跨境流动规定》) on 22 March 2024, effective immediately. The rules substantially raise the thresholds at which CAC security assessment, Standard Contractual Clauses (SCC), or Personal Information Protection Certification are required for outbound data transfers, and create categorical exemptions for contract performance, HR management, intra-group transfers below a volume threshold, and transit data processed in China with no domestic personal information introduced. A Free Trade Zone pilot mechanism allows designated FTZs (Shanghai Lingang, Tianjin, Beijing) to publish their own negative lists defining which data categories still require prior approval, easing conditions for multinationals with operations in those zones.
Ministerial order signed by the French Minister of Economy on 2 February 2024 and published in JORF n°0034 of 10 February 2024 establishing France's first national export-control list under Article 9 of EU Regulation 2021/821 on dual-use goods. The arrêté requires prior authorisation for exports to non-EU third countries of (i) quantum computers and their enabling technologies (qubit devices, control systems, measurement equipment) and (ii) equipment for the design, development, production, test and inspection of advanced electronic components, plus associated software and technology. The annex was substantively replaced by the Arrêté du 27 mars 2025 (explicit technical thresholds including ≥34-qubit systems with C-NOT error ≤10⁻⁴, HBM 6000+ processing performance, cryogenic cooling, dry-etch and EUV-mask tooling, and Si-28/Si-30/Ge isotopically-controlled materials) and is repealed by the Arrêté du 10 mars 2026 with entry into force 11 May 2026.
On 25 October 2023 the Bureau of Industry and Security published an interim final rule (88 FR 73424; FR Doc 2023-23055) making substantive revisions to the October 7 2022 advanced-computing IFR, incorporating 43 public comments covering 78 topics. The rule replaced the prior TOPS-based performance metric with a new "Total Processing Performance" (TPP) / performance-density dual-threshold structure for ECCN 3A090, splitting the control into tiers 3A090.a (full licence requirement for highest-capability datacenter AI chips) and 3A090.b (new License Exception NAC with 25-day prior notification for the intermediate tier). Geographic scope was expanded from China-and-Macau to Country Groups D:1/D:4/D:5 to block diversion via third-country intermediaries and offshore datacenters.
The US Bureau of Industry and Security issued an interim final rule on 17 October 2023 that substantially expanded the advanced-computing and semiconductor manufacturing controls first imposed in October 2022. The rule closed the performance-threshold workaround that NVIDIA had used to ship China-specific A800/H800 GPUs, replacing it with a "performance density" metric and adding a new "Notified Advanced Computing" licence category. It expanded controls on chipmaking equipment (additional ECCNs covering deposition, etch, metrology), pulled 21 additional countries (mostly Middle East / Central Asia) into a regional licensing scheme to prevent transshipment, and added 13 Chinese entities to the Entity List including AI-chip designers.
BIS published a final rule adding 43 entities under 50 entries to the EAR Entity List and removing one entity (Fiber Optic Solutions, Latvia), effective June 12, 2023. The additions span ten countries — China (31 entities), UAE (5), Pakistan (4), South Africa (3), UK (2), and one each in Kenya, Laos, Malaysia, Singapore, and Thailand — targeting four principal threat clusters: China's military modernization and hypersonic-weapons supply chain, an international network of flight-training academies (TFASA and affiliates) providing Western pilot training to Chinese military personnel, Pakistan-linked procurement for unsafeguarded ballistic-missile programs, and UAE/South Africa-based dual-use diversion networks. All listed entities require a BIS licence, with most subject to a presumption of denial.
MOTIE finalised the 31st amendment of the Public Notice on Trade of Strategic Items on 24 April 2023, effective 28 April 2023, adding 741 items to the Russia/Belarus situational-licence (상황허가) list. The added items span industrial machinery, petroleum and gas refining equipment, steel, chemicals, automotive goods and quantum computers judged to have high military-diversion potential. MOTIE stated the amendment brings Korea's export-control coverage of Russia/Belarus closer to that of the US, EU and Japan, incorporating 2022 international export-control-regime agreements and reflecting the US's 2nd-6th Russia sanctions rounds and a substantial part of the EU's measures.
The Bureau of Industry and Security (BIS) added 37 entities under 38 entries to the Entity List, effective March 2, 2023, spanning six destinations: China (28), Pakistan (4), Burma (3), Russia (1), Belarus (1), and Taiwan (1). The China tranche — the largest — targets entities supporting the People's Liberation Army's military modernization, including BGI Research and Forensic Genomics International (genomic surveillance/data risk), Inspur Group Co. Ltd. (cloud servers supplied to Chinese military), and Loongson Technology (domestic CPU developer). Three Burmese entities, including the Ministry of Transport and Communications, are designated for providing surveillance equipment enabling the military junta's tracking and targeting of civilians. Pakistani entities Abdul Razaq Asim, Add-On Technology, and Dynamic Engineers are added for contributing to Pakistan's ballistic missile programs; Russian DMT Electronics and Belarusian DMT Trading LLC for export-control evasion. All listed entities are subject to a license requirement for all items subject to the EAR, with the review policy being presumption of denial for the majority of Chinese entries.
BIS amended the Commerce Control List (CCL) under the Export Administration Regulations (EAR) to implement decisions agreed at the December 2021 Wassenaar Arrangement Plenary meeting, revising 16 ECCNs across computing, electronics, lasers, sensors, and aerospace domains. The most operationally significant change raised the Adjusted Peak Performance (APP) threshold for digital computers under ECCN 4A003.b from 29 to 70 Weighted TeraFLOPS (WT), reducing the licensing burden for high-performance computing exports to Wassenaar partner countries while preserving controls to non-partners. Corresponding revisions to License Exception APP (15 CFR Part 740) and License Exception Strategic Trade Authorization (STA) align the broader EAR framework with the updated multilateral thresholds.
BIS published an interim final rule on January 18, 2023 (88 FR 2821, FR Doc 2023-00888) extending to Macau the same advanced computing and semiconductor manufacturing controls originally imposed on China by the October 7, 2022 rule. The extension closes a diversion loophole created by Macau's status as a Special Administrative Region of China, applying equivalent license requirements for advanced computing ICs, equipment used in ≤14 nm logic and advanced NAND/DRAM fabrication, and supercomputer end-use restrictions. The rule also includes entity list modifications and took effect one day before Federal Register publication (January 17, 2023).
The US Bureau of Industry and Security imposed broad new controls on the export of advanced computing chips, chipmaking equipment, and US-person services supporting Chinese semiconductor fabrication. The October 7 2022 rule blocked supply of GPUs above set performance thresholds (initially 600 GB/s interconnect / 4800 TOPS) to China and added end-use restrictions on manufacturing tools used in advanced (≤14/16 nm logic, ≤18 nm DRAM, ≤128-layer NAND) facilities, with a foreign direct product rule extending coverage globally.
The Bureau of Industry and Security (BIS) added 31 Chinese entities — including Yangtze Memory Technologies Co., Ltd. (YMTC), China's largest NAND flash manufacturer — to the Unverified List (UVL), suspending license exceptions and requiring end-user statements for all EAR-controlled items destined to these parties. BIS simultaneously removed nine Chinese entities previously on the UVL after successfully completing end-use checks. The rule also established a new 60-day UVL-to-Entity-List escalation clock and clarified that sustained host-government obstruction of end-use checks constitutes independent grounds for Entity List designation — a structural enforcement change aimed at closing China's pattern of blocking BIS post-shipment verification visits.
The Bureau of Industry and Security expanded EAR sanctions against Russia and Belarus effective 15 September 2022, adding new export-control categories covering quantum computing equipment and related technology (new licensing requirements under a near-total policy of denial), discrete chemicals and biologics including fentanyl precursors and CBW-related production equipment (new Supplement No. 6 to Part 746), and 57 EAR99 industrial items added to the industry-sector sanctions list (Supplement No. 4). Six entities were concurrently designated as Russian Military End Users (MEU), and MEU/MIEU licensing restrictions were extended worldwide (previously limited to six countries). The rule also extended the Foreign Direct Product Rule to additional categories of foreign-made items.
Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector (Digital Markets Act, DMA) was published in OJ L 265 on 12 October 2022, entered into force on 1 November 2022, and applied for the most part from 2 May 2023. The DMA establishes an ex-ante competition framework imposing binding obligations and prohibitions on designated "gatekeepers" operating Core Platform Services (CPS) in the EU — covering search engines, social-networking services, video-sharing platforms, number-independent interpersonal communications, operating systems, web browsers, virtual assistants, cloud computing, online intermediation services, and online advertising. The European Commission designated six gatekeepers on 6 September 2023 (Alphabet, Amazon, Apple, ByteDance, Meta, Microsoft); full compliance with all obligations was required by 7 March 2024. Subsequent designations added Booking.com (May 2024) and Apple iPadOS (April 2024). The DMA functions as the EU's structural anchor for ex-ante digital competition regulation, closing the enforcement gap left by ex-post competition law (Articles 101–102 TFEU) where market-tipping dynamics make remedies ineffective after the fact.
The UK laid the Republic of Belarus (Sanctions) (EU Exit) (Amendment) Regulations 2022 (UKSI 2022/748), in force 5 July 2022, extending the Belarus sanctions regime to mirror measures already imposed on Russia over the invasion of Ukraine. The regulations ban export to Belarus of dual-use goods and technology for all purposes, and of critical-industry goods and technology including quantum-computing components, microelectronics, marine and navigation equipment, and aircraft/aircraft parts. They widen existing import bans to cover a greater range of petroleum/mineral products and prohibit import of arms, iron and steel products originating in or consigned from Belarus, and extend financial sanctions barring Belarusian companies from issuing debt or securities in London or obtaining loans from UK banks, and barring UK persons from providing financial services to the National Bank of the Republic of Belarus or the Belarusian Ministry of Finance.
Effective 24 February 2022 — the date of Russia's full-scale invasion of Ukraine — the US Bureau of Industry and Security (BIS) published an interim final rule (87 FR 12226, FR Doc 2022-04300) adding sweeping new export license requirements under a new § 746.8 of the Export Administration Regulations (EAR). The rule requires a licence for any item in CCL Categories 3–9 (electronics, computers, telecommunications, sensors, lasers, navigation/avionics, marine, aerospace, propulsion) exported, reexported, or transferred to Russia, with a review policy of denial. Two new Russia-specific Foreign Direct Product (FDP) rules extend US jurisdiction to foreign-manufactured goods: the Russia FDP Rule (§ 734.9(f)) covers all foreign-made items using US technology/equipment destined for Russia, and the Russia-MEU FDP Rule (§ 734.9(g)) covers items destined to 47 designated military-end-user (MEU) entities with no licence exceptions available. All three restrictions carry a presumption of denial, making this the most sweeping peacetime expansion of the EAR since its modern codification.
The US Bureau of Industry and Security (BIS) amended the Export Administration Regulations (EAR) effective November 26, 2021, by adding 28 entries to the Entity List across China (12), Japan (1), Pakistan (13 including 2 individuals), Singapore (1), and Taiwan (1). Designations span three distinct threat clusters: (1) eight Chinese entities supporting military applications of quantum computing, including QuantumCTek Co. and the Hefei National Laboratory for Physical Sciences at Microscale; (2) approximately twelve Pakistani procurement entities and three Chinese suppliers facilitating Pakistan's unsafeguarded nuclear activities and ballistic missile program; and (3) the Corad Technology network across China, Japan, Singapore, and Taiwan that sold Western technology to Iran's military/space programs and North Korean front companies. Additionally, the Moscow Institute of Physics and Technology was added to the Military End-User (MEU) List for producing military products. All Entity List entries carry presumption-of-denial licensing policy with no exceptions available.
The Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法 — PIPL) was adopted at the 30th meeting of the 13th NPC Standing Committee on 20 August 2021 and entered into force on 1 November 2021, constituting the third and final pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Data Security Law (2021). The PIPL is China's comprehensive personal-information statute establishing consent-based and necessity-based legal bases for PI processing, a tiered cross-border personal-data transfer regime (CAC security assessment / PI protection certification / Standard Contractual Clauses), extraterritorial application (Art. 3) to non-Chinese controllers offering services to or analysing the behaviour of PRC residents, and a heightened protection regime for sensitive personal information and data of minors under 14. It mandates data-protection impact assessments, personal-information-protection-officer obligations at designated handlers, breach notification, and a full suite of data-subject rights including access, rectification, deletion, portability, objection, and automated- decision-making opt-out. Article 53 requires overseas controllers to establish a domestic representative or designated entity in China, providing a domestic enforcement counterparty.
The Data Security Law of the People's Republic of China (中华人民共和国数据安全法) was adopted at the 29th meeting of the 13th NPC Standing Committee on 10 June 2021 and entered into force on 1 September 2021, constituting the second pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Personal Information Protection Law (2021). The DSL establishes a tiered data-classification regime — "important data" and "national core data" — with escalating security obligations including risk assessment, risk monitoring, breach reporting, and classified-protection requirements for data handlers. It introduces a data-export security review for "important data" generated or collected within China, the statutory parent authority operationalised by the 2024 CAC Cross-Border Data Flow Provisions, and enacts a §36 blocking statute prohibiting Chinese organisations and individuals from transferring data stored in China to foreign judicial or law-enforcement authorities without prior PRC government approval.
The National Security and Investment Act 2021 (c.25), receiving Royal Assent on 29 April 2021 and entering full force on 4 January 2022, created the UK's first standalone investment-screening regime, separating national-security review from the Competition and Markets Authority merger-control process. The Act empowers the Secretary of State to call in any acquisition of "control or influence" over a qualifying entity or asset on national-security grounds, and designates 17 sensitive sectors in which acquisitions crossing 25%/50%/75% share-or-voting-rights thresholds (or material influence) require mandatory pre-completion notification to the Investment Security Unit (Cabinet Office); completion before clearance is void and criminal sanctions of up to 5 years imprisonment apply to non-notifying parties. The Act is the structural peer of US CFIUS/FIRRMA (2018), EU Regulation 2019/452, Germany AWG §§55–62, France Décret 2014-479, Netherlands Wet Vifo, and the broader allied FDI-screening parent-statute lattice, and the enabling statute under which all UK mandatory-notification schedule amendments operate.
The U.S. Bureau of Industry and Security (BIS) added seven Chinese supercomputing entities to the Entity List, imposing a license requirement covering all items subject to the Export Administration Regulations (EAR) with a presumption of denial. The entities were designated for procuring and building supercomputers used by China's military actors, supporting China's military modernization, and aiding the development of weapons of mass destruction (WMD) and hypersonic weapons programs. This was the Biden administration's first Entity List action targeting China's supercomputing sector.
The Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法) was adopted at the 24th meeting of the 12th NPC Standing Committee on 7 November 2016 and entered into force on 1 June 2017, establishing the foundational legal framework for network security governance across all sectors. The law creates the Critical Information Infrastructure Operator (CIIO) designation and protection regime administered by the Cyberspace Administration of China (CAC), mandates data localisation for personal information and important data collected or generated by CIIOs in China, and establishes cross-border data-transfer security assessment requirements under Article 37 — the provision later operationalised by DSL 2021, PIPL 2021, and the 2024 CAC Cross-Border Data Flow Provisions. The CSL introduced multi-level protection scheme (等级保护制度 / MLPS) obligations for all network operators and network-product/service security-review procedures, under which CAC triggered the cybersecurity review of Didi Global in 2021 and the exclusion of Micron's products from Chinese critical-infrastructure projects in 2023.
Decreto-Legge 15 marzo 2012 n. 21 (GU n. 63 of 15 March 2012), converted with amendments into Legge 11 maggio 2012 n. 56 (GU n. 111 of 14 May 2012), establishes Italy's "Golden Power" special-powers regime — the foundational statute authorising the Italian Government to impose conditions on, veto, or prescribe remedies for corporate transactions in strategic sectors. The decree marked Italy's transition from a golden-share model (applicable only to privatised companies) to a sector-wide golden-power model applicable to any company carrying out activities of strategic relevance. Administered by the Presidenza del Consiglio dei Ministri (DICA), the regime has been progressively extended from its original defence + national-security + energy/transport/ communications scope to cover 5G, cloud, critical-raw-materials, financial-credit-insurance, agri-food, healthcare, media, space, and AI through a series of amending decrees from 2019 to 2026.
Japan's Foreign Exchange and Foreign Trade Act (FEFTA, Act No. 228 of 1 December 1949; 外国為替及び外国貿易法) is the foundational umbrella statute governing the entire modern Japanese economic-statecraft toolkit. Originally a restrictive positive-list regime for foreign-exchange transactions, FEFTA was fundamentally liberalised by the 1980 revision (positive-list to negative-list shift) and again overhauled in 1998 to establish the modern regulatory architecture. Three principal enforcement arms operate under FEFTA: (i) security export controls administered by METI via the Export Trade Control Order and the Foreign Exchange Order (covering the Wassenaar Arrangement, Australia Group, MTCR, NSG, and CWC controlled-items lists plus Japan-specific catch-all controls); (ii) inward FDI screening administered jointly by the Ministry of Finance and sector ministries (prior notification and pre-notification regime, substantially expanded 2019–2020 with Core Business Sectors covering semiconductors, critical minerals, advanced materials, cloud computing, and aerospace added 2021); and (iii) autonomous economic sanctions (asset- freeze and payment-restriction designations against Russia, Iran, DPRK, Myanmar, Belarus, and others via Cabinet Orders made under FEFTA authority). Structurally peer-foundational to the US Trade Expansion Act 1962, US Trade Act 1974, UK SAMLA 2018, CN Export Control Law 2020, and CN Anti-Foreign Sanctions Law 2021 as the G7+CN foundational economic- statecraft statute cluster.