Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
Taiwan's Legislative Yuan passed the Artificial Intelligence Basic Act (人工智慧基本法) on third reading on 23 December 2025, and President Lai Ching-te promulgated the 20-article statute on 14 January 2026, bringing it into force immediately. The Act designates the National Science and Technology Council (NSTC) as the central AI-policy competent authority and codifies seven governance principles — sustainability and well-being, human autonomy, privacy protection and data governance, cybersecurity and safety, transparency and explainability, fairness and non-discrimination, and accountability — that apply to all public-sector AI procurement and high-risk sectoral applications. The statute establishes a statutory foundation for the Taiwan AI Action Plan 2.0, mandates an Executive Yuan National AI Strategy Committee, and provides authority for sector-specific implementing regulations by FSC, NCC, MOHW, and MOTC across finance, telecoms, medical, and autonomous-vehicle AI within a two-year window. As the first national AI governance statute in the Greater China region and the third globally after the EU AI Act and South Korea's AI Basic Act, it frames regulatory expectations for the companies at the heart of the global AI hardware supply chain — TSMC, NVIDIA ODM partners, and advanced-packaging incumbents — that are headquartered or operate substantially in Taiwan.
On 10 December 2025 the National Assembly of Vietnam adopted Law No. 134/2025/QH15 on Artificial Intelligence (8 chapters, 35 articles), Vietnam's first dedicated AI statutory framework and one of the first comprehensive horizontal AI laws in Southeast Asia. The law establishes a three-tier risk-based regulatory architecture (high / medium / low) for the research, development, provision, deployment, and use of AI systems; defines the rights and obligations of providers, deployers, importers, distributors, and users; and mandates state oversight via the Ministry of Information & Communications and Ministry of Science & Technology. Prohibited acts include systematic deception, manipulation of human perception, generation of fake content endangering national security, exploitation of vulnerable populations, and obstruction of human-supervision mechanisms. The law applies to Vietnamese agencies, organizations, and individuals as well as foreign organizations and individuals involved in AI-related activities in Vietnam, taking effect 1 March 2026 with 12-18 month transition windows for existing systems depending on sector.
Vietnam's National Assembly passed Law on Cybersecurity No. 116/2025/QH15 on 10 December 2025 (434 of 443 deputies in favour), effective 1 July 2026. The law supersedes both the 2018 Cybersecurity Law (Law 24/2018/QH14) and the 2015 Law on Cyber Information Security, consolidating cybersecurity, cyber-information-security, and network-information-security into a unified Ministry of Public Security-led framework. It retains data-localization obligations for foreign digital-service providers handling personal data, user-generated content, and relationship graphs of Vietnamese users (minimum 24-month retention), introduces 6-hour urgent / 24-hour standard content take-down windows on MPS request, expressly prohibits AI/deepfake forgery of images, voices, and videos for illegal purposes, and mandates child-safety platform measures.
On 20 November 2025 the White House and US Department of Commerce / Bureau of Industry and Security (BIS) authorised Abu Dhabi AI holding company G42 to import advanced computing chips — equivalent to approximately 35,000 Nvidia GB300 Blackwell processors — under the UAE-pioneered Regulated Technology Environment (RTE) compliance framework. The RTE is an Emirati-designed technology governance and audit architecture, developed by G42 and approved under BIS guidelines, with binding UAE-side controls to prevent onward diversion to foreign adversary nations. The authorisation accelerates the Stargate UAE project — a 1 GW AI compute cluster being built by G42 for OpenAI in partnership with Oracle, Cisco, NVIDIA, and SoftBank Group — and represents the first concluded major country-level advanced-compute authorisation following the May 2025 rescission of the Biden-era AI Diffusion Rule.
On 18 November 2025, the European Supervisory Authorities (EBA, ESMA, and EIOPA) jointly designated 19 Critical ICT Third-Party Providers (CTPPs) under DORA Article 31, with immediate effect — the first-ever exercise of direct EU financial-regulator supervision over hyperscale cloud and infrastructure providers. The designated entities include Amazon Web Services, Microsoft Azure, Google Cloud, Deutsche Telekom, Oracle, SAP, IBM, Bloomberg LP, London Stock Exchange Group (LSEG), Tata Consultancy Services, and Orange, among others. Designation triggers direct oversight by a lead ESA (EBA for banking-critical, ESMA for capital-markets-critical, EIOPA for insurance-critical) via Joint Examination Teams (JETs), with powers to conduct investigations, carry out on-site inspections, and impose fines of up to 1% of average daily worldwide turnover per day for non-compliance.
India's Ministry of Electronics and Information Technology (MeitY) notified the Digital Personal Data Protection Rules, 2025 via Gazette notification G.S.R. 846(E) on 13 November 2025, operationalising the 2023 DPDP Act. The Rules introduce a "negative list" cross-border personal-data transfer regime under Rule 14, verifiable parental consent, breach-notification windows, and tiered penalties up to INR 250 crore. Implementation is phased: Data Protection Board provisions in force on notification, Consent Manager rules from 13 Nov 2026, and core data-fiduciary / cross-border-transfer obligations from 13 May 2027.
On 18 September 2025 Brazil's federal government published Medida Provisória (Provisional Measure) 1318/2025, creating REDATA — the Special Taxation Regime for Datacenter Services — alongside a parallel IT-export regime (REPES). REDATA zeroes federal taxes on servers, storage, networking, cooling and other datacenter capital equipment for qualifying operators from 1 January 2026, conditioned on 100% renewable/zero-carbon energy sourcing, a 2% of investment R&D-in-Brazil commitment, and preferential use of Brazilian- manufactured components. The Finance Ministry projects R$5.2 billion in forgone-tax incentives in 2026 alone, with potential to unlock up to R$2 trillion in private datacenter investment over ten years. REDATA is framed as implementing the National Datacenter Policy (PNDC) under the Nova Indústria Brasil industrial-policy umbrella.
The National Assembly of Vietnam passed the Personal Data Protection Law (Luật Bảo vệ dữ liệu cá nhân), Law No. 91/2025/QH15, on 26 June 2025; it enters into force on 1 January 2026. The PDPL is Vietnam's first statutory (rather than decree-level) personal-data-protection framework, elevating the prior Decree 13/2023/ND-CP (PDPD) regime into a 5-chapter, 39-article primary statute and adding revenue-based administrative penalties of up to 5% of prior-year annual revenue for cross-border data-transfer violations and up to 10x illegal gains for unlawful data trading. The law is implemented by Decree 356/2025/ND-CP (issued 31 December 2025, effective 1 January 2026) and applies extraterritorially to foreign organisations offering services to or processing the personal data of Vietnam residents.
On 14 June 2025 Vietnam's 15th National Assembly adopted Law No. 71/2025/QH15 on the Digital Technology Industry (DTI Law) at its 9th session. The Law enters into force on 1 January 2026 (with certain provisions phased) and is the world's first standalone primary statute dedicated to the digital technology industry, covering digital-tech production and services, semiconductor manufacturing, artificial-intelligence systems, digital assets (legally recognised as property under the Civil Code), and Concentrated Digital Technology Zones. It codifies sector-specific incentives — multi-year corporate income tax reductions, R&D-cost deductions, preferential public procurement, five-year personal income tax exemption for high-quality digital professionals, five-year visa and work-permit exemptions for foreign experts, and 50% subsidy for SME advanced-technology acquisition — and sets headline targets of 150,000 digital-tech enterprises and USD 74bn digital-economy contribution by 2030/2035 (with USD 43bn / USD 74bn variants in different government summaries).
On 13 May 2025, two days before the AI Diffusion Rule's primary 15 May 2025 compliance date, the Trump administration's BIS announced it would rescind the Biden-era Framework for AI Diffusion (90 FR 4544) and simultaneously issued three guidance documents that re-routed US AI export policy through existing EAR authorities. The package comprises (1) GP10 guidance asserting that all ECCN 3A090 ICs designed by PRC-headquartered firms are presumptively EAR-violative, with Huawei Ascend 910B/910C/910D processors named explicitly — making US- and non-US-person use, transfer, financing, or servicing of those chips anywhere in the world a presumptive General Prohibition 10 violation; (2) a policy statement warning industry that supplying US advanced computing ICs for training or inference of Chinese AI models risks EAR enforcement; and (3) industry guidance on diversion-prevention diligence. BIS stated a formal Federal Register rescission and replacement rule would follow.
On 9 April 2025 the European Commission adopted Communication COM(2025)165, the AI Continent Action Plan, setting out a five-pillar strategy to make the EU a global AI leader. The pillars are (1) computing infrastructure, (2) data for AI, (3) strategic AI innovation and adoption, (4) AI skills and talent, and (5) regulatory simplification. Headline commitments include mobilising approximately €200bn of public+private investment via the InvestAI initiative announced at the AI Action Summit in Paris (11 February 2025), deploying 13 AI Factories (HPC-anchored shared compute facilities) plus regional antennas, building 5 AI Gigafactories powered by >100,000 advanced AI processors with €20bn earmarked from InvestAI, launching the Apply AI Strategy and Data Union Strategy, and proposing a Cloud and AI Development Act with a public consultation closing 4 June 2025. The one-year progress report (9 April 2026) confirmed 19 AI Factories deployed across EU supercomputers with 13 Antennas providing regional access, and €1bn in Apply AI funding calls earmarked.
Japan's Cabinet approved an amendment to the Cabinet Order on Inward Direct Investment under the Foreign Exchange and Foreign Trade Act (FEFTA) on 1 April 2025; the order was promulgated 4 April 2025 and entered into force 19 May 2025. The amendment introduces two new investor categories — Type-A (investors legally or contractually obligated to share information with foreign governments) and Type-B (investors effectively in a comparable position without formal legal obligation) — and eliminates or narrows exemptions from mandatory prior-notification screening for both categories. The primary driver is concern over minority-stake acquisitions by Chinese investors in Japanese listed companies operating in sensitive sectors including cloud computing, telecommunications infrastructure, semiconductor equipment, and advanced electronics. The reform is structurally distinct from the outbound FEFTA catch-all controls overhaul (2025-10-09) and from the Economic Security Promotion Act (2022-05-18); it is the inbound FDI-screening complement to that framework.
Japan's National Diet enacted the Cyber Response Capability Enhancement Act (重要電子計算機に対する不正な行為による被害の防止に関する法律, Law No. 42 of 2025) on 16 May 2025, together with companion arrangement legislation. Commonly known as the Active Cyber Defense (ACD) Law, the statute authorises (i) government monitoring of foreign-origin internet traffic transiting designated Japanese communication infrastructure for national-security threat indicators, (ii) pre-emptive access and neutralisation operations against attacker infrastructure abroad by the National Police Agency and the Self-Defense Forces under unified command, and (iii) mandatory cyber-incident reporting and government cooperation duties on critical-infrastructure operators. Implementation is phased through November 2027, with the NISC reorganised into the National Cybersecurity Office (NCO) under the Cabinet Secretariat from July 2025.
President Trump signed Executive Order 14179 on 23 January 2025 (published in the Federal Register on 31 January 2025 as 90 FR 8741, doc 2025-02172). The order revokes Biden-era Executive Order 14110 of 30 October 2023 ("Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence") and directs federal agencies to identify and rescind, revise, or suspend any policies, regulations, memoranda, or guidance documents adopted pursuant to the revoked Biden order. It mandates that the Assistant to the President for Science and Technology, the Assistant to the President for National Security Affairs, the Special Advisor for AI and Crypto, and the Assistant to the President for Economic Policy develop an AI Action Plan within 180 days to "sustain and enhance America's global AI dominance." The plan was released on 23 July 2025. EO 14179 reframes US AI industrial-policy posture from safety-first regulation to deregulation, infrastructure investment, and export-competitiveness.
The National Assembly of Vietnam passed the Law on Data (Luật Dữ liệu), No. 60/2024/QH15, on 30 November 2024; it enters into force on 1 July 2025. The Law is Vietnam's first comprehensive horizontal data-governance statute, extending regulation beyond personal data (already covered by Decree 13/2023/ND-CP) to all digital data — public, private, and sectoral. It introduces statutory categories of "important data" (dữ liệu quan trọng) and "core data" (dữ liệu cốt lõi) tied to national-defence and national-security review for cross-border transfer, and establishes the National Data Centre under the Ministry of Public Security plus a statutory data-broker / data-services licensing framework.
The European Union's Artificial Intelligence Act, Regulation (EU) 2024/1689, was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. It establishes the world's first horizontal, risk-tiered legal framework for the development, market placement, and use of AI systems — covering prohibited practices, high-risk systems, general-purpose AI models, and minimal-risk applications — with extraterritorial reach over any provider placing an AI system on the EU market or whose output is used in the EU. Penalties reach up to EUR 35 million or 7% of global annual turnover. Application is staged: prohibitions from 2 February 2025, GPAI and governance from 2 August 2025, the bulk of high-risk obligations from 2 August 2026, and product-safety-embedded high-risk systems from 2 August 2027.
Three Commission Delegated Regulations (CDR 2024/1772, 1773, 1774) adopted 13 March 2024 and published in the EU Official Journal on 25 June 2024 constitute the first batch of binding Level 2 implementing rules under DORA (Regulation (EU) 2022/2554). CDR 2024/1772 sets ICT incident classification criteria and materiality thresholds for mandatory reporting; CDR 2024/1773 specifies the required content of contractual policies for ICT third-party services supporting critical or important functions; CDR 2024/1774 defines the ICT risk management tools, methods, processes, and policies — including a simplified framework for smaller in-scope entities. All three apply from 17 January 2025 alongside the parent DORA regulation, covering approximately 22,000 EU regulated financial entities.
Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data — the "Data Act" — was published in the Official Journal on 22 December 2023, entered into force on 11 January 2024, and applies generally from 12 September 2025 (with longer transitional periods for IoT product-design obligations under Article 3(1), which apply to products placed on the market after 12 September 2026, and for the data-portability standardisation framework, applicable from 12 September 2027). The Data Act is the third pillar of the EU data-economy framework alongside the GDPR (personal data) and the Data Governance Act 2022/868 (data-intermediation services), and is the world's first horizontal statutory regime governing access to and portability of industrial / IoT / non-personal data — covering by-design data-availability obligations on connected-product manufacturers, a mandatory cloud- switching framework with progressive elimination of switching charges, B2G emergency data-sharing in exceptional needs, unfair-contract-terms protection for SMEs, and safeguards against unlawful international government access to non-personal data held in EU cloud.
On 25 October 2023 the Bureau of Industry and Security published an interim final rule (88 FR 73424; FR Doc 2023-23055) making substantive revisions to the October 7 2022 advanced-computing IFR, incorporating 43 public comments covering 78 topics. The rule replaced the prior TOPS-based performance metric with a new "Total Processing Performance" (TPP) / performance-density dual-threshold structure for ECCN 3A090, splitting the control into tiers 3A090.a (full licence requirement for highest-capability datacenter AI chips) and 3A090.b (new License Exception NAC with 25-day prior notification for the intermediate tier). Geographic scope was expanded from China-and-Macau to Country Groups D:1/D:4/D:5 to block diversion via third-country intermediaries and offshore datacenters.
The US Bureau of Industry and Security issued an interim final rule on 17 October 2023 that substantially expanded the advanced-computing and semiconductor manufacturing controls first imposed in October 2022. The rule closed the performance-threshold workaround that NVIDIA had used to ship China-specific A800/H800 GPUs, replacing it with a "performance density" metric and adding a new "Notified Advanced Computing" licence category. It expanded controls on chipmaking equipment (additional ECCNs covering deposition, etch, metrology), pulled 21 additional countries (mostly Middle East / Central Asia) into a regional licensing scheme to prevent transshipment, and added 13 Chinese entities to the Entity List including AI-chip designers.
The Bureau of Industry and Security (BIS) added 37 entities under 38 entries to the Entity List, effective March 2, 2023, spanning six destinations: China (28), Pakistan (4), Burma (3), Russia (1), Belarus (1), and Taiwan (1). The China tranche — the largest — targets entities supporting the People's Liberation Army's military modernization, including BGI Research and Forensic Genomics International (genomic surveillance/data risk), Inspur Group Co. Ltd. (cloud servers supplied to Chinese military), and Loongson Technology (domestic CPU developer). Three Burmese entities, including the Ministry of Transport and Communications, are designated for providing surveillance equipment enabling the military junta's tracking and targeting of civilians. Pakistani entities Abdul Razaq Asim, Add-On Technology, and Dynamic Engineers are added for contributing to Pakistan's ballistic missile programs; Russian DMT Electronics and Belarusian DMT Trading LLC for export-control evasion. All listed entities are subject to a license requirement for all items subject to the EAR, with the review policy being presumption of denial for the majority of Chinese entries.
Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA) is the EU's first horizontal cyber- and ICT-resilience instrument for the financial sector. Adopted 14 December 2022 and published in the Official Journal on 27 December 2022, it entered into force on 16 January 2023 and applies from 17 January 2025. DORA covers approximately 22,000 EU regulated financial entities across ~20 entity types (credit institutions, insurers, investment firms, CCPs, trading venues, crypto-asset service providers, etc.) under five pillars: ICT risk management, ICT-incident reporting, digital operational resilience testing (including threat-led penetration testing for significant entities), ICT third-party risk management, and information sharing. Structurally novel, DORA establishes the Critical ICT Third-Party Provider (CTPP) oversight regime under which the European Supervisory Authorities (EBA, ESMA, EIOPA) acquire direct supervisory powers over hyperscale cloud providers (AWS, Azure, GCP, Oracle) servicing EU financial entities — the first EU mechanism for ESA direct oversight of non-financial cloud providers.
Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector (Digital Markets Act, DMA) was published in OJ L 265 on 12 October 2022, entered into force on 1 November 2022, and applied for the most part from 2 May 2023. The DMA establishes an ex-ante competition framework imposing binding obligations and prohibitions on designated "gatekeepers" operating Core Platform Services (CPS) in the EU — covering search engines, social-networking services, video-sharing platforms, number-independent interpersonal communications, operating systems, web browsers, virtual assistants, cloud computing, online intermediation services, and online advertising. The European Commission designated six gatekeepers on 6 September 2023 (Alphabet, Amazon, Apple, ByteDance, Meta, Microsoft); full compliance with all obligations was required by 7 March 2024. Subsequent designations added Booking.com (May 2024) and Apple iPadOS (April 2024). The DMA functions as the EU's structural anchor for ex-ante digital competition regulation, closing the enforcement gap left by ex-post competition law (Articles 101–102 TFEU) where market-tipping dynamics make remedies ineffective after the fact.
Government Decree 53/2022/ND-CP, signed 15 August 2022 and effective 1 October 2022, implements Article 26 of Vietnam's 2018 Law on Cybersecurity. It mandates in-country storage of three categories of data — personal data of users in Vietnam, user-generated data, and user-relationship data — for both domestic and foreign cyberspace- service providers, with a minimum 24-month retention period. Foreign enterprises providing telecoms, data storage, domain names, e-commerce, online payments, social networks, online video games, or messaging services to users in Vietnam must establish a Vietnamese branch or representative office within 12 months of a Minister of Public Security written request. The decree closes a four-year implementation gap on the 2018 Cybersecurity Law and is the principal Vietnamese digital-trade barrier alongside Decree 13/2023/ND-CP (Personal Data Protection).
The Act on the Promotion of Ensuring National Security through Integrated Implementation of Economic Measures (Law No. 43 of 2022), enacted 18 May 2022, establishes a four-pillar framework: (1) supply-chain resilience for "specified critical products," (2) security of critical infrastructure, (3) state-backed development of "specified critical technologies," and (4) non-disclosure of nationally sensitive patents. A December 2022 Cabinet Order designated 11 product categories as specified critical products, including semiconductors, storage batteries, permanent magnets, cloud programs, LNG, critical minerals, machine tools, and aircraft parts. Competent ministries must publish stable-supply plans, can fund private-sector surveys, and may provide subsidies to qualifying firms.
France 2030 is a €54 billion public investment plan unveiled by President Emmanuel Macron on 12 October 2021 to fund breakthrough innovation and reindustrialisation across ten strategic priorities — small modular nuclear reactors, green hydrogen, low-carbon transport (incl. two million EVs/year), food/agritech, twenty drug therapies for cancer and chronic disease, cultural industries, space, deep-sea exploration, semiconductors and electronic components, and robotics/digital (AI/cloud). Two cross-cutting rules require 50% of investment to flow to decarbonisation and 50% to emerging innovative players. Operationalised from the 2022 budget law, the plan is coordinated by the Secrétariat général pour l'investissement (SGPI) under the Prime Minister and delivered by ANR, ADEME, Bpifrance and Caisse des Dépôts / Banque des Territoires.
The Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法 — PIPL) was adopted at the 30th meeting of the 13th NPC Standing Committee on 20 August 2021 and entered into force on 1 November 2021, constituting the third and final pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Data Security Law (2021). The PIPL is China's comprehensive personal-information statute establishing consent-based and necessity-based legal bases for PI processing, a tiered cross-border personal-data transfer regime (CAC security assessment / PI protection certification / Standard Contractual Clauses), extraterritorial application (Art. 3) to non-Chinese controllers offering services to or analysing the behaviour of PRC residents, and a heightened protection regime for sensitive personal information and data of minors under 14. It mandates data-protection impact assessments, personal-information-protection-officer obligations at designated handlers, breach notification, and a full suite of data-subject rights including access, rectification, deletion, portability, objection, and automated- decision-making opt-out. Article 53 requires overseas controllers to establish a domestic representative or designated entity in China, providing a domestic enforcement counterparty.
The Data Security Law of the People's Republic of China (中华人民共和国数据安全法) was adopted at the 29th meeting of the 13th NPC Standing Committee on 10 June 2021 and entered into force on 1 September 2021, constituting the second pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Personal Information Protection Law (2021). The DSL establishes a tiered data-classification regime — "important data" and "national core data" — with escalating security obligations including risk assessment, risk monitoring, breach reporting, and classified-protection requirements for data handlers. It introduces a data-export security review for "important data" generated or collected within China, the statutory parent authority operationalised by the 2024 CAC Cross-Border Data Flow Provisions, and enacts a §36 blocking statute prohibiting Chinese organisations and individuals from transferring data stored in China to foreign judicial or law-enforcement authorities without prior PRC government approval.
The Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法) was adopted at the 24th meeting of the 12th NPC Standing Committee on 7 November 2016 and entered into force on 1 June 2017, establishing the foundational legal framework for network security governance across all sectors. The law creates the Critical Information Infrastructure Operator (CIIO) designation and protection regime administered by the Cyberspace Administration of China (CAC), mandates data localisation for personal information and important data collected or generated by CIIOs in China, and establishes cross-border data-transfer security assessment requirements under Article 37 — the provision later operationalised by DSL 2021, PIPL 2021, and the 2024 CAC Cross-Border Data Flow Provisions. The CSL introduced multi-level protection scheme (等级保护制度 / MLPS) obligations for all network operators and network-product/service security-review procedures, under which CAC triggered the cybersecurity review of Didi Global in 2021 and the exclusion of Micron's products from Chinese critical-infrastructure projects in 2023.
Decreto-Legge 15 marzo 2012 n. 21 (GU n. 63 of 15 March 2012), converted with amendments into Legge 11 maggio 2012 n. 56 (GU n. 111 of 14 May 2012), establishes Italy's "Golden Power" special-powers regime — the foundational statute authorising the Italian Government to impose conditions on, veto, or prescribe remedies for corporate transactions in strategic sectors. The decree marked Italy's transition from a golden-share model (applicable only to privatised companies) to a sector-wide golden-power model applicable to any company carrying out activities of strategic relevance. Administered by the Presidenza del Consiglio dei Ministri (DICA), the regime has been progressively extended from its original defence + national-security + energy/transport/ communications scope to cover 5G, cloud, critical-raw-materials, financial-credit-insurance, agri-food, healthcare, media, space, and AI through a series of amending decrees from 2019 to 2026.
Japan's Foreign Exchange and Foreign Trade Act (FEFTA, Act No. 228 of 1 December 1949; 外国為替及び外国貿易法) is the foundational umbrella statute governing the entire modern Japanese economic-statecraft toolkit. Originally a restrictive positive-list regime for foreign-exchange transactions, FEFTA was fundamentally liberalised by the 1980 revision (positive-list to negative-list shift) and again overhauled in 1998 to establish the modern regulatory architecture. Three principal enforcement arms operate under FEFTA: (i) security export controls administered by METI via the Export Trade Control Order and the Foreign Exchange Order (covering the Wassenaar Arrangement, Australia Group, MTCR, NSG, and CWC controlled-items lists plus Japan-specific catch-all controls); (ii) inward FDI screening administered jointly by the Ministry of Finance and sector ministries (prior notification and pre-notification regime, substantially expanded 2019–2020 with Core Business Sectors covering semiconductors, critical minerals, advanced materials, cloud computing, and aerospace added 2021); and (iii) autonomous economic sanctions (asset- freeze and payment-restriction designations against Russia, Iran, DPRK, Myanmar, Belarus, and others via Cabinet Orders made under FEFTA authority). Structurally peer-foundational to the US Trade Expansion Act 1962, US Trade Act 1974, UK SAMLA 2018, CN Export Control Law 2020, and CN Anti-Foreign Sanctions Law 2021 as the G7+CN foundational economic- statecraft statute cluster.