Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
President Trump signed a Section 232 proclamation on 13 August 2026 (published in the Federal Register 19 August 2026, FR doc 2026-16979) imposing tariffs on unmanned aircraft systems (UAS/drones) and components, following a Commerce Department finding that US reliance on foreign-produced (chiefly Chinese, e.g. DJI/Autel) drones and critical components creates supply-chain and cybersecurity national- security risk. A 100% ad valorem tariff applies to Annex I items (drones with maximum takeoff weight over 25kg, thermal-imaging drones, docking stations, and listed critical components); a 25% ad valorem tariff applies to Annex II items (other listed UAS). Qualifying-origin content from the EU, Japan, Korea, Switzerland, Taiwan and Liechtenstein is capped at 15%; UK-origin content is capped at 10%. UAS duties take effect 3 September 2026; component duties take effect 9 February 2027. The proclamation also authorizes Commerce to set up an onshoring program giving temporary relief to firms committing to build or expand US production of covered drones and components.
On 1 April 2026, Prime Minister Takaichi Sanae and President Emmanuel Macron held a Tokyo summit and signed a bilateral roadmap on cooperation in critical minerals — the first formal Japan-France instrument on supply-chain resilience for rare earths and other critical materials. The centrepiece is joint government support for Caremag, a heavy rare-earths refining project in southern France due to begin operations in late 2026, with backing from Japan Organization for Metals and Energy Security (JOGMEC), Iwatani Corporation, and the French government; the project targets approximately 20% of Japan's future demand for dysprosium and terbium (heavy rare-earth oxides used in EV motors, offshore-wind turbines, and electronic components). The two leaders also launched parallel high-level dialogues on dual-use AI, quantum technologies, space (including debris mitigation), cybersecurity, and a joint declaration on startups and innovation, expressing "serious concerns" over export controls on critical minerals and other materials affecting global supply chains — an explicit reference to China's tightening rare-earths export regime.
The Department of Commerce's International Trade Administration published a Federal Register notice on 10 April 2026 (91 FR 18412, doc 2026-06952) opening the inaugural Call for Proposals for the American AI Exports Program established under Executive Order 14320. Proposals are accepted from 1 April 2026 through 5:00 pm EDT on 30 June 2026 from US industry-led "pre-set" consortia offering full-stack American AI export packages — AI-optimised hardware, data pipelines, AI models and systems, security and cybersecurity measures, and sector-specific applications — for presentation by the US government to foreign public- and private-sector buyers. Designated consortia receive priority US-government advocacy, priority consideration for export-control licence engagement, interagency coordination, and federal-financing referrals (EXIM, DFC), with a 14-business-day completeness review and 60-calendar-day designation decision once a proposal is deemed complete.
Premier Li Qiang signed State Council Order No. 834 on 31 March 2026 promulgating the "Provisions on Industrial Chain and Supply Chain Security" (18 articles), adopted at the State Council executive meeting on 13 March 2026 and effective on the date of publication. The Provisions are the first dedicated PRC administrative regulation on industrial- and supply-chain security and consolidate authorities drawn from the National Security Law, Foreign Relations Law, Anti-Foreign Sanctions Law, and Foreign Trade Law into a horizontal defensive framework. They establish a cross-agency coordination mechanism spanning roughly 15 central departments (industrial, security, cyberspace, customs and financial regulators) plus provincial governments; create a security-investigation system; and vest broad countermeasure authority over both foreign states (Article 14 — import/export prohibitions and special levies) and foreign organisations and individuals (Article 15 — import/export bans, China-investment bars, transaction prohibitions, entry bars and revocation of work or residence permits, with extension to effectively-controlled subsidiaries). The Provisions also impose compliance, information-sharing, strategic-reserve and emergency-response obligations on PRC organisations and individuals, and authorise requisition, mandated production and directed transportation in the event of supply-chain disruption.
South Korea's 13th National Strategic Technology Special Committee (chaired by MSIT) adopted the 2026 Annual Implementation Plan for the First Basic Plan for National Strategic Technology Development (2024–2028), committing KRW 8.6 trillion in 2026 R&D investment — a ~30% YoY increase from KRW 6.5 trillion in 2025 — across 19 NEXT strategic-technology fields encompassing AI, semiconductors, quantum, displays, and secondary batteries, coordinated across 23 ministries. The plan is supplemented by KRW 46.6 trillion in policy finance delivered through Korea Development Bank (KDB), Industrial Bank of Korea (IBK), Korea Credit Guarantee Fund (KCGF), and Korea Technology Finance Corporation (KOTEC), providing the horizontal funding-coordination architecture that operationalises all sector-specific Korean strategic-technology legislative instruments.
On 17 February 2026, Prime Minister Mark Carney launched Canada's first standalone Defence Industrial Strategy (DIS), introducing the "Build–Partner–Buy" framework as the central guiding principle of Canadian defence procurement. The strategy mobilises over half a trillion CAD across the next decade — including ~CAD 180 bn in defence procurement opportunities, ~CAD 290 bn in defence-related capital investment, and ~CAD 125 bn in anticipated downstream economic benefit by 2035 — and targets 125,000 new high-paying jobs. Operationally, the DIS introduces Canadian Content Value (CCV) requirements with a proposed Canadian Company Boost for firms meeting 70–100% domestic-content thresholds, sets a 10-year goal of awarding 70% of defence procurements to Canadian firms, and signals willingness to invoke the national security exception to set aside trade-agreement obligations and exclude foreign bidders for "sovereign capability" contracts. It is the first standalone industrial-strategy document covering the Canadian defence-industrial base, distinct from prior DPA-narrow filings.
On 29 January 2026, European Council President António Costa and Vietnamese Prime Minister Phạm Minh Chính signed a Joint Statement in Hanoi upgrading EU-Vietnam bilateral relations to a Comprehensive Strategic Partnership (CSP) — the highest tier in Vietnam's diplomatic hierarchy, placing the EU on the same level as Vietnam's CSPs with China, Russia, India, South Korea, Japan, Australia, France, and the United States. The CSP establishes a reinforced bilateral cooperation framework spanning critical raw materials, semiconductor supply chains, artificial intelligence, trusted 5G infrastructure, climate and energy transition, security and defence (including cyber and maritime), and full implementation of the 2019 EU-Vietnam Free Trade Agreement (EVFTA) tariff-elimination schedule plus ratification of the EU-Vietnam Investment Protection Agreement (EVIPA). It is the EU's eleventh CSP globally and its second in Southeast Asia (after Singapore, 2024), and constitutes the foundational bilateral parent framework for all future EU-Vietnam cooperation under the EU Critical Raw Materials Act (CRMA) Article 13 third-country strategic-project designation pipeline, given Vietnam's approximately 22 Mt rare-earth reserves — the world's second-largest deposit after China.
Taiwan's Legislative Yuan passed the Artificial Intelligence Basic Act (人工智慧基本法) on third reading on 23 December 2025, and President Lai Ching-te promulgated the 20-article statute on 14 January 2026, bringing it into force immediately. The Act designates the National Science and Technology Council (NSTC) as the central AI-policy competent authority and codifies seven governance principles — sustainability and well-being, human autonomy, privacy protection and data governance, cybersecurity and safety, transparency and explainability, fairness and non-discrimination, and accountability — that apply to all public-sector AI procurement and high-risk sectoral applications. The statute establishes a statutory foundation for the Taiwan AI Action Plan 2.0, mandates an Executive Yuan National AI Strategy Committee, and provides authority for sector-specific implementing regulations by FSC, NCC, MOHW, and MOTC across finance, telecoms, medical, and autonomous-vehicle AI within a two-year window. As the first national AI governance statute in the Greater China region and the third globally after the EU AI Act and South Korea's AI Basic Act, it frames regulatory expectations for the companies at the heart of the global AI hardware supply chain — TSMC, NVIDIA ODM partners, and advanced-packaging incumbents — that are headquartered or operate substantially in Taiwan.
Vietnam's National Assembly passed Law on Cybersecurity No. 116/2025/QH15 on 10 December 2025 (434 of 443 deputies in favour), effective 1 July 2026. The law supersedes both the 2018 Cybersecurity Law (Law 24/2018/QH14) and the 2015 Law on Cyber Information Security, consolidating cybersecurity, cyber-information-security, and network-information-security into a unified Ministry of Public Security-led framework. It retains data-localization obligations for foreign digital-service providers handling personal data, user-generated content, and relationship graphs of Vietnamese users (minimum 24-month retention), introduces 6-hour urgent / 24-hour standard content take-down windows on MPS request, expressly prohibits AI/deepfake forgery of images, voices, and videos for illegal purposes, and mandates child-safety platform measures.
The UK Foreign, Commonwealth & Development Office designated two China-based commercial cyber companies — Sichuan Anxun Information Technology Co Ltd (known as i-Soon) and Integrity Technology Group Incorporated — under the UK's Cyber sanctions regime, freezing their UK assets and imposing controls on commercial transactions and investment instruments involving them. i-Soon was designated for targeting over 80 government and private-sector IT systems worldwide, including UK public-sector and private-industry networks. Integrity Tech was designated for operating a covert botnet of more than 260,000 compromised devices globally and supplying access to it to enable unauthorised intrusion into UK public-sector systems.
Israel's Minister of Defense signed an order on 18 November 2025 revoking the Order Governing the Control of Commodities and Services (Engagement in Encryption Items) of 1974, with effect on 21 March 2026 (four-month implementation period). The 51-year-old standalone Encryption Order regime — which licensed both civilian and defense-grade encryption items through a parallel Ministry of Defense track — is replaced by a unified architecture in which defense-grade dual-use items move to the Defense Export Controls Agency (DECA) at the Ministry of Defense, and civilian dual-use items (Wassenaar list) move to the Export Control Agency (ECA) at the Ministry of Economy and Industry. Many B2C consumer products with embedded encryption are decontrolled outright; B2B / commercial products remain controlled but under DECA or ECA rather than the legacy Encryption Order regime.
Cyprus Law 194(I)/2025 "The Establishment of a Framework for the Screening of Foreign Direct Investments Law of 2025" was enacted by the House of Representatives and published in the Official Gazette on 14 November 2025, entering into force on 2 April 2026. It establishes Cyprus's first-ever mandatory pre-approval FDI screening regime, designating the Ministry of Finance as the competent Screening Authority and applying to non-EU/EEA/Swiss investors acquiring ≥25% equity or voting rights in Cyprus entities valued at ≥€2 million across covered strategic sectors. The regime implements EU Regulation 2019/452 and includes a Cyprus-specific sectoral extension covering tourism and real estate — addressing golden-passport-era concerns about non-EU capital flows into the island's financial and hospitality economy.
Germany's transposition of EU Directive 2022/2555 (NIS2), enacted as the "Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung." Bundestag passage 13 November 2025; Bundesrat approval 21 November 2025; published as BGBl. I 2025 Nr. 301 on 5 December 2025; entered into force 6 December 2025. The statute designates the Bundesamt für Sicherheit in der Informationstechnik (BSI) as the central national supervisory authority over an estimated 29,500 covered entities across 18 critical and important sectors, introduces a mandatory 24h initial / 72h detailed / 1-month final cyber-incident reporting cascade, establishes board-level personal liability for senior management, and applies to SME critical- infrastructure suppliers — with no transitional grace period from entry into force.
Canada made SOR/2025-228, Regulations Amending the Special Economic Measures (Russia) Regulations, registered 2025-11-06 and announced by Minister Anand on 2025-11-12. The regulations add 13 individuals to Part 1 of Schedule 1, 11 entities to Part 2 of Schedule 1, and 100 vessels (by IMO number) to Schedule 1.1, freezing their Canadian assets and prohibiting dealings. Targets include Russian LNG-trading entities, drone-programme developers, cyber-infrastructure suppliers for hybrid operations against Ukraine, and Kyrgyzstan-based financial enablers (including Capital Bank of Central Asia and the A7 payments platform) used to evade earlier Russia sanctions. The 100-vessel designation targets Russia's "shadow fleet" used to move crude oil, LNG and arms while evading the G7 price cap and flag-state controls.
FinCEN issued a final rule under Section 311 of the USA PATRIOT Act (31 U.S.C. § 5318A) prohibiting US covered financial institutions from opening or maintaining a correspondent account for, or on behalf of, Cambodia-based Huione Group, a foreign financial institution found to be of primary money-laundering concern. Treasury determined that Huione Group and its subsidiaries — including Haowang Guarantee, Huione Pay PLC, and Huione Crypto — laundered at least $4 billion of illicit proceeds between August 2021 and January 2025, including funds tied to North Korean cyber-heist actors and Southeast Asian "pig-butchering" investment-scam compounds. The rule also imposes a special-due-diligence requirement on US covered institutions to guard against indirect access via foreign correspondent accounts. Effective November 17, 2025.
Italy enacted Legge 23 settembre 2025, n. 132 — "Disposizioni e deleghe al Governo in materia di intelligenza artificiale" — published in Gazzetta Ufficiale Serie Generale n. 223 of 25 September 2025 (atto 25G00143) and entered into force on 10 October 2025. The statute makes Italy the first EU member state to enact a comprehensive national AI law complementing Regulation (EU) 2024/1689 (EU AI Act), designating AgID (Agency for Digital Italy) and ACN (National Cybersecurity Agency) as national oversight authorities under Presidency-of-the-Council-of-Ministers coordination. It sets sectoral rules for healthcare, labour, intellectual professions, public administration and the judiciary; authorises up to €1 billion in state-backed venture capital (via CDP Venture Capital) for AI, cybersecurity and telecoms; creates criminal penalties of up to five years' imprisonment for harmful deepfakes; mandates parental consent for under-14 users; and delegates secondary legislation to the Government across multiple domains.
On 19 September 2025, the European Investment Fund (EIF), part of the European Investment Bank Group, signed a EUR 260 million (USD ~305 million) anchor-investor commitment into Jolt Capital V, a growth-stage deep-technology venture capital fund targeting a EUR 1 billion final close. The commitment is funded largely through the European Tech Champions Initiative (ETCI), an EU-backed programme that has committed over EUR 2.5 billion across 11 scale-up technology funds and aims to mobilise EUR 10 billion in total resources for late-stage European tech companies. Jolt Capital V will invest in growth-stage B2B companies across semiconductors, cybersecurity, AI, industry 4.0, new materials and mobility, sectors the EIB Group frames explicitly around European strategic autonomy and competitiveness.
New Zealand's 32nd sanctions round under the Russia Sanctions Act 2022 (Russia Sanctions Amendment Regulations (No 4) 2025, SL 2025/195) lowered the price cap on Russian-origin crude oil (HS 2709) from US$60/bbl to US$47.60/bbl, a roughly 21% cut, aligning New Zealand with the EU, UK and Canada's most recent price-cap reductions. The same instrument designated 19 individuals and entities plus 19 vessels, including Russia's GRU cyber unit 29155 (implicated in malware attacks on Ukrainian government networks), actors involved in chemical-weapons use and disinformation, additional "shadow fleet" tankers, alternative payment providers, and third-country facilitators based in North Korea and Iran supporting Russia's war effort.
On 8 September 2025, the UK Ministry of Defence published the Defence Industrial Strategy 2025 — "Making Defence an Engine for Growth" (CP 1388) — the first comprehensive cabinet-level UK defence industrial strategy in over a decade and the sector plan for Defence under the UK Modern Industrial Strategy umbrella (IS-8). The strategy was published alongside the Strategic Defence Review 2025 and operationalises the largest sustained defence- spending increase since the Cold War (rising to 2.6% of GDP by 2027 with ambition to 3% in the next Parliament). It defines six priority outcomes (growth, backing UK businesses, defence innovation, resilient industrial base, procurement transformation, enduring partnerships); establishes UK Defence Innovation (UKDI) within the MOD with a ringfenced £400m budget to accelerate dual-use technology; identifies priority defence capabilities (combat air, complex weapons, directed-energy weapons, next- generation land and maritime systems) plus dual-use sub-sectors (quantum, drones/autonomy, space, AI, cyber, engineering biology, advanced connectivity); and flags resilience priorities in steel, construction, energetic materials, batteries, semiconductors and rare earths.
On 14 August 2025 OFAC re-designated the cryptocurrency exchange Garantex Europe OU under its cyber authority (E.O. 13694, as amended) for processing over USD 100 million in transactions tied to ransomware and darknet-market actors since 2019, and designated its successor exchange Grinex — created by former Garantex staff to move customer deposits and continue operations after a March 2025 US Secret Service-led takedown of Garantex's infrastructure. OFAC also designated three Garantex executives, the A7A5 ruble-backed stablecoin issuer Old Vector (Kyrgyzstan), and Russian settlement-platform firm A7 and its subsidiaries A71 and A7 Agent — entities linked to sanctioned Moldovan oligarch Ilan Shor and sanctioned Promsvyazbank — for supplying the A7A5 token used to compensate Garantex customers and route funds through Grinex.
The FCC adopted a Report and Order (FCC 25-49) on 7 August 2025 — the first comprehensive overhaul of submarine cable landing license rules since 2001 — effective 26 November 2025. The order prohibits Indefeasible Right of Use (IRU) agreements that would give entities from designated foreign adversary countries (China including Hong Kong and Macau, Cuba, Iran, DPRK, Russia, and Venezuela) control over Submarine Line Terminal Equipment (SLTE) on US cable landings, and mandates new annual reporting plus certification/disclosure requirements covering ownership, cybersecurity and physical security plans, and FCC Covered List compliance. The order operationalises the FCC's bifurcated policy package: accelerating legitimate commercial cable buildout while hardening national-security review for foreign-adversary-connected infrastructure.
Czech Act No. 265/2025 Sb., promulgated in the Sbírka zákonů on 4 August 2025 and entering into force on 1 November 2025, is the first material amendment of the Czech Republic's foundational FDI screening statute (Act No. 34/2021 Sb.) since its enactment. The amendment broadens the perimeter of mandatory pre-closing FDI screening by cross-referencing the simultaneously-enacted Cybersecurity Act (Act No. 264/2025 Sb., transposing NIS2 Directive 2022/2555): entities designated as providers of "regulated services" under the Cybersecurity Act's "regime of higher obligation" automatically fall within mandatory FDI-screening scope, extending screening reach beyond the prior military-material / dual-use / critical-infrastructure perimeter to cover a broad sweep of digital, technology, healthcare, energy, and financial-services operators. The amendment also adds a confidentiality-sharing channel between MPO and NÚKIB, enabling coordinated supply-chain-security assessments for high-risk-vendor reviews under the new Cybersecurity Act.
The French government, sole shareholder of state-owned IN Groupe, backed IN Groupe's acquisition of IDEMIA Smart Identity (ISI) with a capital increase, completed 2025-07-01. The deal — IN Groupe's largest since its creation, with press estimates as high as EUR 1 billion though terms were not officially disclosed — creates a combined entity with over 4,000 employees and consolidated turnover above EUR 1 billion, making IN Groupe the world's largest provider of physical/digital identity cards and second-largest passport provider. The Ministry framed the operation as building a "global champion" in identity documents to secure French/ European sovereignty over the identity and biometrics value chain.
On 1 July 2025, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated Aeza Group, a St. Petersburg, Russia-based "bulletproof hosting" (BPH) provider, along with two affiliated companies and four Aeza Group leaders (Arsenii Penzev, Yuri Bozoyan, Vladimir Gast, Igor Knyazev), for supplying server infrastructure that shielded ransomware operators, infostealer groups, and darknet drug marketplaces from law-enforcement takedown. In coordination with the UK's National Crime Agency, OFAC also designated Aeza International Ltd., a UK front company Aeza used to lease IP addresses to cybercriminals. The action was taken under Executive Order 13694 (as amended by E.O. 14144 and E.O. 14306) and builds on OFAC's February 2025 designation of BPH provider ZServers.
On 25 June 2025 the European Commission adopted COM(2025) 335 final, a proposed Regulation establishing a single market for space activities — the first EU-level framework harmonising the authorisation, registration and supervision of space activities across Member States, replacing 13 fragmented national regimes. The Act rests on three pillars: safety (mandatory tracking of space objects, space- debris mitigation rules, an EU registry of space objects), resilience (cybersecurity requirements scaled to company size and risk profile) and sustainability (environmental impact assessment and active debris-removal R&D). It applies to both EU and non-EU operators providing space services in Europe, giving it extraterritorial reach over SpaceX/Starlink, Amazon Kuiper, OneWeb, Chinese SatNet/G60 and ISRO. The proposal is being negotiated under the ordinary legislative procedure; the Competitiveness Council of 9 December 2025 broadly endorsed its objectives, and the public consultation closed on 7 November 2025.
Greece enacted Law 5202/2025 on 22 May 2025, published in Government Gazette ΦΕΚ A' 84 on 23 May 2025 and effective the same day, establishing the country's first national mandatory and suspensory foreign direct investment screening mechanism, aligned with Regulation (EU) 2019/452. The Interministerial Committee for the Control of Foreign Direct Investment (ICC-FDI), with initial procedure run by the Ministry of Foreign Affairs, reviews non-EU acquisitions in "sensitive" sectors (energy, transportation, healthcare, ICT, digital infrastructure) and "particularly sensitive" sectors (national security, defence, cybersecurity, AI, ports and critical subsea infrastructure, borderland tourism). A two-phase review applies — 30 days Phase I, up to 150 days Phase II with EU Cooperation Mechanism notification — and the regime became fully operational on 11 November 2025.
The Legislative Yuan of Taiwan (ROC) passed amendments to Article 10-1 of the Statute for Industrial Innovation (產業創新條例) on third reading on 18 April 2025, promulgated by Presidential Decree on 7 May 2025 and effective for qualifying expenditures incurred from 1 January 2025. The amendment expands the scope of the existing Article 10-1 investment tax credit — previously covering hardware, software, technology, or technical services for smart machinery, 5G network deployment, and cybersecurity — to additionally cover (i) AI products or services and (ii) energy-conservation and carbon-reduction initiatives. The maximum eligible expenditure cap per company per taxable year is doubled from NT$1bn to NT$2bn, and the implementation period is extended through 31 December 2029. Secondary legislation operationalising the amended categories was jointly issued by MOEA and MOF on 27 November 2025 as the "Regulations Governing Tax Credits Claimed for Investments in Smart Machinery, 5G Networks, Cybersecurity, Artificial Intelligence (AI) Products or Services, and Energy Conservation and Carbon Reduction." This is Taiwan's first AI-and-green-tech investment tax credit mechanism in the general-industrial framework, distinct from Article 10-2 (the chip-specific R&D + advanced-equipment credit, "Taiwan Chips Act").
China's MOFCOM Unreliable Entity List Working Mechanism designated six US firms on 9 April 2025, effective 12:01 Beijing time 10 April 2025, under MOFCOM Order No. 4 of 2020. Cited trigger: participation in arms sales to Taiwan or military-technology cooperation with Taiwan in disregard of China's stated opposition, "seriously harming China's national sovereignty, security and development interests." Measures prohibit the six entities from import/export activities related to China, new investments in China, and impose entry/work-permit restrictions on senior management.
On 27 February 2025, the Parliament of the Republic of Moldova adopted Law No. 33/2025 amending Law No. 174/2021 on the mechanism for examining investments of importance for state security. The law entered into force on 20 April 2025 after publication in Monitorul Oficial Nr. 144-147 of 20 March 2025 (promulgated by Presidential Decree No. 118-X of 17 March 2025). Key operative changes expand the protected-sector perimeter to explicitly enumerate 17 categories covering data processing and storage, AI, robotics, cybersecurity, semiconductors, quantum, nanotechnology and biotechnology alongside the pre-existing energy, transport, communications, defence and aerospace pillars; add new grounds for refusal (money-laundering suspicion, corruption convictions, foreign-government control, cybersecurity risk, access to personal data of citizens); introduce enhanced Council powers including retroactive review of previously approved investments and fines of up to 5% of annual turnover (capped at MDL 5 million); and carve out intra-group transactions, asset sales below EUR 1 million, and state-owned-enterprise dealings. The Screening Council became operational in July 2025.
Japan's National Diet enacted the Cyber Response Capability Enhancement Act (重要電子計算機に対する不正な行為による被害の防止に関する法律, Law No. 42 of 2025) on 16 May 2025, together with companion arrangement legislation. Commonly known as the Active Cyber Defense (ACD) Law, the statute authorises (i) government monitoring of foreign-origin internet traffic transiting designated Japanese communication infrastructure for national-security threat indicators, (ii) pre-emptive access and neutralisation operations against attacker infrastructure abroad by the National Police Agency and the Self-Defense Forces under unified command, and (iii) mandatory cyber-incident reporting and government cooperation duties on critical-infrastructure operators. Implementation is phased through November 2027, with the NISC reorganised into the National Cybersecurity Office (NCO) under the Cabinet Secretariat from July 2025.
Regulation (EU) 2025/38 of the European Parliament and of the Council of 19 December 2024 lays down measures to strengthen solidarity and capacities in the Union to detect, prepare for, and respond to cyber threats and incidents, and amends Regulation (EU) 2021/694 (Digital Europe Programme). Published in the Official Journal on 15 January 2025; entered into force on 4 February 2025 (20 days after OJ publication). The regulation establishes (i) a European Cybersecurity Alert System composed of national and cross-border Security Operations Centre (SOC) hubs interconnected EU-wide, (ii) a Cybersecurity Emergency Mechanism funded through the Digital Europe Programme, (iii) an EU Cybersecurity Reserve of trusted private-sector incident-response providers, and (iv) an ENISA-led post-incident review mechanism for significant or large-scale cybersecurity incidents. It complements the Cyber Resilience Act (Reg 2024/2847) and the NIS2 Directive as the third leg of the EU horizontal-cybersecurity stack.
Regulation (EU) 2024/2847 of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, signed 23 October 2024 and entering into force 10 December 2024. The CRA is the first EU statutory cybersecurity regime covering all hardware and software products with a direct or indirect data connection placed on the EU market, imposing essential cybersecurity requirements, conformity assessment with CE marking, mandatory vulnerability handling, and 24-hour early-warning notification of actively-exploited vulnerabilities to ENISA. Main manufacturer obligations apply from 11 December 2027; conformity-assessment-body notification provisions apply from 11 June 2026 and reporting obligations from 11 September 2026. Penalties reach EUR 15M or 2.5% of global annual turnover.
Australia's first standalone cyber-security statute (Act No. 98 of 2024), passed by Parliament on 25 November 2024 and granted Royal Assent on 29 November 2024, with provisions commencing in tranches through 30 May 2025. The Act creates four binding regimes: (i) mandatory security-of-things standards for connected and IoT products supplied in Australia under regulations administered by the Department of Home Affairs; (ii) a mandatory ransomware / cyber-extortion payment disclosure regime requiring reporting business entities with annual turnover above AUD 3 million to notify the Australian Signals Directorate within 72 hours of any ransom payment made by or on behalf of the entity; (iii) a statutory Cyber Incident Review Board to conduct no-blame post-incident reviews of significant cyber incidents; and (iv) a "limited use" protection restricting how information voluntarily shared with the National Cyber Security Coordinator may be used by Commonwealth agencies. The Act implements core initiatives from the 2023-2030 Australian Cyber Security Strategy and affects every firm selling connected devices into Australia or operating above the turnover threshold in Australia.
The Seimas of the Republic of Lithuania adopted Law No. XIV-2985 on 26 September 2024, amending the Law on the Protection of Objects of Importance to Ensuring National Security (NSU Act), registered in the Teisės aktų registras (TAR) on 3 October 2024 and entering into force on 18 October 2024. The amendments expand the list of strategically important economic activities subject to FDI screening by the Commission for the Coordination of Protection of Objects of Importance to National Security to include the issuance of electronic money, electronic money tokens, asset-referenced tokens, and the provision of crypto-asset services (CASPs) as defined under EU MiCA Regulation 2023/1114, aligning Lithuania's screening perimeter with the EU crypto-assets regulatory framework. The law also refines core definitional concepts — "persons acting in concert," "controlling person," and "manager of critical information infrastructure" — to tighten beneficial-ownership and control analysis under the regime.
The Bureau of Industry and Security (BIS) amended the Export Administration Regulations (EAR) by adding three Kaspersky entities to the Entity List under End-User Review Committee (ERC) determinations — AO Kaspersky Lab (Moscow), OOO Kaspersky Group (Moscow), and Kaspersky Labs Limited (London). All three are designated for cooperation with Russian military and intelligence authorities in support of Russian government cyber-intelligence objectives. Exports, reexports, and in-country transfers of all items subject to the EAR to the three entities now require a BIS licence reviewed under a policy of presumption of denial, with no licence exceptions available. The action is paired with a same-week Commerce ICTS final determination prohibiting Kaspersky cybersecurity and anti-virus software transactions in the United States.
Japan's National Diet enacted the Act on the Protection and Use of Critical Economic Security Information (重要経済安保情報の保護及び活用に関する法律, Act No. 27 of 2024) on 10 May 2024; it was promulgated on 17 May 2024 and came into full operation on 16 May 2025. The law establishes Japan's first peace-time economic-security clearance regime extending to private-sector employees. It designates "Critical Economic Security Information" (CESI) covering threat-intelligence on critical-infrastructure cyber attacks, regulatory-review information on essential infrastructure, and vulnerability data on critical-product supply chains; mandates Cabinet Office "適性評価" (suitability assessment) for cleared personnel; and imposes criminal penalties of up to five years' imprisonment for unauthorised disclosure. The CESI Act complements the 2022 Economic Security Promotion Act (ESPA), closing the information-protection gap and aligning Japan's framework with Five Eyes and EU partners for joint R&D and dual-use cooperation.
Loi n° 2024-449 of 21 May 2024, known as the SREN law (Sécuriser et Réguler l'Espace Numérique), was definitively adopted by the French Parliament on 10 April 2024, validated in part by the Conseil Constitutionnel on 17 May 2024 (Decision n° 2024-866 DC), promulgated by the President on 21 May 2024, and published in the Journal Officiel on 22 May 2024. SREN is France's digital-sovereignty omnibus statute: it transposes parts of the EU Digital Services Act (Regulation 2022/2065), Digital Markets Act (Regulation 2022/1925), and Data Governance Act (Regulation 2022/868) into French law and layers national-level instruments on top — most consequentially a data-localisation hook for sensitive public-sector data tied to the ANSSI SecNumCloud sovereign-cloud certification scheme, an ARCOM-enforced age-verification regime for adult-content sites (with €250k or 2%-of-turnover fines and account-closure powers), an "anti-scam" cybersecurity filter requiring browsers and DNS resolvers to block ANSSI-designated fraudulent domains, a jeux-en-ligne (JONUM) regime for cryptoasset-adjacent gaming, and a coordination framework between CSA, CNIL, ARCOM, and the Autorité de la concurrence. SREN is one of the first EU member-state digital omnibus statutes anchoring national public-sector data-hosting rules to a sovereign-cloud certification scheme.
Latvia's Saeima adopted on 27 March 2024 amendments to the National Security Law (Nacionālās drošības likums), entering into force on 24 April 2024, that widen the perimeter of foreign-investment and ownership transactions subject to Cabinet of Ministers pre-clearance over "companies of significance to national security." The amendments expand the universe of regulated subjects beyond registered companies to include foundations and associations, tighten the rules on beneficial-ownership disclosure, and bring additional sensitive activities — energy security including LNG-terminal acquisitions, electronic communications, cybersecurity, and critical-raw-materials processing — under the regime, while clarifying Cabinet authority to impose conditions or unwind transactions retroactively. The law functions as Latvia's horizontal FDI-screening instrument under the EU-wide cooperation framework of Regulation 2019/452.
The Cyberspace Administration of China (CAC) issued the Provisions on Promoting and Regulating Cross-Border Data Flows (《促进和规范数据跨境流动规定》) on 22 March 2024, effective immediately. The rules substantially raise the thresholds at which CAC security assessment, Standard Contractual Clauses (SCC), or Personal Information Protection Certification are required for outbound data transfers, and create categorical exemptions for contract performance, HR management, intra-group transfers below a volume threshold, and transit data processed in China with no domestic personal information introduced. A Free Trade Zone pilot mechanism allows designated FTZs (Shanghai Lingang, Tianjin, Beijing) to publish their own negative lists defining which data categories still require prior approval, easing conditions for multinationals with operations in those zones.
Bulgaria's National Assembly adopted on 22 February 2024 amendments to the Investment Promotion Act establishing the country's first horizontal foreign direct investment screening mechanism, published in State Gazette No. 20 on 8 March 2024 and entering into force on 12 March 2024. The regime implements EU Regulation 2019/452 by creating an Interdepartmental Screening Council with a 45-day decision window over non-EU investments meeting a 10 % equity stake or €2 million threshold in critical-infrastructure, dual-use, advanced-technology, media, and financial-infrastructure sectors, with no threshold for investments by Russian or Belarusian persons or in oil and petroleum activities. Non-compliance and false declarations carry fines of 5 % of investment value, with a minimum BGN 50,000.
Ireland's Screening of Third Country Transactions Act 2023 (Act No. 28 of 2023), signed into law on 31 October 2023 and commenced on 6 January 2025 via S.I. No. 651 of 2024, establishes Ireland's first-ever mandatory inbound FDI screening regime. The Act empowers the Minister for Enterprise, Tourism and Employment to assess, condition, or prohibit transactions by third-country investors (non-EU/EEA/Switzerland) exceeding a EUR 2 million cumulative threshold in targets operating across critical infrastructure, critical technologies, dual-use items, supply of critical inputs, sensitive personal data, and media freedom. A 90-day standstill period applies during Ministerial determination, with criminal sanctions and transaction-voiding powers available for non-compliance.
Decree-Law No. 104 of 10 August 2023 ("Decreto Asset" / Omnibus Decree, GU n.186 of 10 Aug 2023, in force 11 Aug 2023) was converted with amendments into Law No. 136 of 9 October 2023 (GU n.236 of 9 Oct 2023). The conversion law materially expanded Italy's "Golden Power" foreign-direct-investment screening regime (DL 21/2012). Two key extensions: (i) intra-group transactions involving entities outside the EU are no longer exempt from the exercise of special powers — only the prior notification carve-out was preserved; (ii) acts, resolutions and operations concerning intellectual-property rights in artificial intelligence, semiconductor production, cybersecurity, aerospace, energy storage, quantum and nuclear technologies, and food production technologies fall within scope when one or more counter-parties sit outside the EU. The Prime Minister also obtained an explicit veto power over transactions creating "exceptional situations" not already covered by sectoral or EU prudential / merger rules, including those touching qualifying holdings in the financial sector.
Bureau of Industry and Security final rule (88 FR 46071, Doc 2023-15343) adding four entities to the Entity List effective July 18, 2023. Intellexa S.A. (Greece) and Intellexa Limited (Ireland) — the corporate architecture behind the "Predator" commercial spyware platform — and Cytrox Holdings Zrt. (Hungary) and Cytrox AD (North Macedonia) — the developer of the underlying spyware technology — were listed for "trafficking in cyber exploits used to gain access to information systems, thereby threatening the privacy and security of individuals and organizations worldwide." All items subject to the EAR require a license with a presumption-of-denial review policy for all four entities, effectively cutting off access to US-origin hardware, software, and technology.
Luxembourg's Chambre des Députés adopted the first-ever national FDI-screening statute on 14 July 2023 (promulgated by the Grand Duke and published in Mémorial A n° 411 on 18 July 2023), entering into force 1 September 2023. The law requires non-EU investors to notify the Ministre de l'Économie before completing direct or indirect acquisitions of ≥25% voting rights / equity in Luxembourg entities engaged in "critical activities" across twelve sectors. The Minister can approve, conditionally approve, or prohibit transactions within a two-month initial screening window, with a further 60-day deep-review phase available; an inter-ministerial Comité de filtrage (Economy + Foreign Affairs + Finance + SREL intelligence service) advises on security and public-order grounds consistent with EU Regulation 2019/452.
Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA) is the EU's first horizontal cyber- and ICT-resilience instrument for the financial sector. Adopted 14 December 2022 and published in the Official Journal on 27 December 2022, it entered into force on 16 January 2023 and applies from 17 January 2025. DORA covers approximately 22,000 EU regulated financial entities across ~20 entity types (credit institutions, insurers, investment firms, CCPs, trading venues, crypto-asset service providers, etc.) under five pillars: ICT risk management, ICT-incident reporting, digital operational resilience testing (including threat-led penetration testing for significant entities), ICT third-party risk management, and information sharing. Structurally novel, DORA establishes the Critical ICT Third-Party Provider (CTPP) oversight regime under which the European Supervisory Authorities (EBA, ESMA, EIOPA) acquire direct supervisory powers over hyperscale cloud providers (AWS, Azure, GCP, Oracle) servicing EU financial entities — the first EU mechanism for ESA direct oversight of non-financial cloud providers.
Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive), published OJ L 333, 27 December 2022, entered into force 16 January 2023. NIS2 repeals and substantially expands the 2016 NIS1 Directive (2016/1148), extending the scope from ~7 sectors to 18 enumerated essential and important sectors, imposing binding cybersecurity risk- management and incident-reporting obligations on covered entities, introducing board-level management accountability, and mandating Member State transposition by 17 October 2024. NIS2 is the structural EU statutory anchor for national cybersecurity frameworks across the bloc, operating alongside DORA (Reg 2022/2554) for financial-sector digital resilience and CRA (Reg 2024/2847) for product cybersecurity.
Belgium's first horizontal foreign-direct-investment screening regime, established by a Cooperation Agreement signed on 30 November 2022 between the Federal State and the Flemish, Walloon, Brussels-Capital and German-Community governments, and in force from 1 July 2023. The agreement creates a centralised Interfederal Screening Commission (ISC), chaired by the FPS Economy, to receive and process mandatory ex-ante notifications of foreign acquisitions of 10%, 25% or higher voting-rights / control thresholds (sector-dependent) in Belgian undertakings active in eleven strategic sectors. ISC decisions are binding; sanctions for failure to notify or for non-compliance with conditions imposed include unwinding of the transaction and administrative fines.
Government Decree 53/2022/ND-CP, signed 15 August 2022 and effective 1 October 2022, implements Article 26 of Vietnam's 2018 Law on Cybersecurity. It mandates in-country storage of three categories of data — personal data of users in Vietnam, user-generated data, and user-relationship data — for both domestic and foreign cyberspace- service providers, with a minimum 24-month retention period. Foreign enterprises providing telecoms, data storage, domain names, e-commerce, online payments, social networks, online video games, or messaging services to users in Vietnam must establish a Vietnamese branch or representative office within 12 months of a Minister of Public Security written request. The decree closes a four-year implementation gap on the 2018 Cybersecurity Law and is the principal Vietnamese digital-trade barrier alongside Decree 13/2023/ND-CP (Personal Data Protection).
BIS finalized changes to the Export Administration Regulations (EAR) governing controls on cybersecurity items — primarily intrusion software, command-and-control platforms, and surveillance tools capable of disrupting or monitoring information systems without authorization. The final rule, effective May 26 2022, revises License Exception ACE (Authorized Cybersecurity Exports) originally established by an October 2021 interim rule and narrows end-user carve-outs for government end users in Country Group D:5 and A:6 destinations. Exports of affected ECCNs (4A005, 4D001, 4D004, 4E001, 5A001.j, 5B001, 5D001, 5E001) to Country Groups E:1 and E:2 remain prohibited; D:1 through D:5 government-end-user transactions require a license.
On November 4, 2021, BIS added four entities to the Entity List under a policy of denial: NSO Group and Candiru (Israel), Positive Technologies (Russia), and Computer Security Initiative Consultancy PTE (Singapore). NSO Group and Candiru were designated for supplying commercial spyware to foreign governments used to maliciously surveil government officials, journalists, activists, and academics; Positive Technologies and CSIC for trafficking cyber tools enabling unauthorized access to information systems. All four entities now require BIS licenses for any export, re-export, or in-country transfer of EAR-controlled items, with a presumption of denial.