Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
President Trump signed a Section 232 proclamation on 13 August 2026 (published in the Federal Register 19 August 2026, FR doc 2026-16979) imposing tariffs on unmanned aircraft systems (UAS/drones) and components, following a Commerce Department finding that US reliance on foreign-produced (chiefly Chinese, e.g. DJI/Autel) drones and critical components creates supply-chain and cybersecurity national- security risk. A 100% ad valorem tariff applies to Annex I items (drones with maximum takeoff weight over 25kg, thermal-imaging drones, docking stations, and listed critical components); a 25% ad valorem tariff applies to Annex II items (other listed UAS). Qualifying-origin content from the EU, Japan, Korea, Switzerland, Taiwan and Liechtenstein is capped at 15%; UK-origin content is capped at 10%. UAS duties take effect 3 September 2026; component duties take effect 9 February 2027. The proclamation also authorizes Commerce to set up an onshoring program giving temporary relief to firms committing to build or expand US production of covered drones and components.
Premier Li Qiang signed State Council Order No. 834 on 31 March 2026 promulgating the "Provisions on Industrial Chain and Supply Chain Security" (18 articles), adopted at the State Council executive meeting on 13 March 2026 and effective on the date of publication. The Provisions are the first dedicated PRC administrative regulation on industrial- and supply-chain security and consolidate authorities drawn from the National Security Law, Foreign Relations Law, Anti-Foreign Sanctions Law, and Foreign Trade Law into a horizontal defensive framework. They establish a cross-agency coordination mechanism spanning roughly 15 central departments (industrial, security, cyberspace, customs and financial regulators) plus provincial governments; create a security-investigation system; and vest broad countermeasure authority over both foreign states (Article 14 — import/export prohibitions and special levies) and foreign organisations and individuals (Article 15 — import/export bans, China-investment bars, transaction prohibitions, entry bars and revocation of work or residence permits, with extension to effectively-controlled subsidiaries). The Provisions also impose compliance, information-sharing, strategic-reserve and emergency-response obligations on PRC organisations and individuals, and authorise requisition, mandated production and directed transportation in the event of supply-chain disruption.
On 17 February 2026, Prime Minister Mark Carney launched Canada's first standalone Defence Industrial Strategy (DIS), introducing the "Build–Partner–Buy" framework as the central guiding principle of Canadian defence procurement. The strategy mobilises over half a trillion CAD across the next decade — including ~CAD 180 bn in defence procurement opportunities, ~CAD 290 bn in defence-related capital investment, and ~CAD 125 bn in anticipated downstream economic benefit by 2035 — and targets 125,000 new high-paying jobs. Operationally, the DIS introduces Canadian Content Value (CCV) requirements with a proposed Canadian Company Boost for firms meeting 70–100% domestic-content thresholds, sets a 10-year goal of awarding 70% of defence procurements to Canadian firms, and signals willingness to invoke the national security exception to set aside trade-agreement obligations and exclude foreign bidders for "sovereign capability" contracts. It is the first standalone industrial-strategy document covering the Canadian defence-industrial base, distinct from prior DPA-narrow filings.
On 29 January 2026, European Council President António Costa and Vietnamese Prime Minister Phạm Minh Chính signed a Joint Statement in Hanoi upgrading EU-Vietnam bilateral relations to a Comprehensive Strategic Partnership (CSP) — the highest tier in Vietnam's diplomatic hierarchy, placing the EU on the same level as Vietnam's CSPs with China, Russia, India, South Korea, Japan, Australia, France, and the United States. The CSP establishes a reinforced bilateral cooperation framework spanning critical raw materials, semiconductor supply chains, artificial intelligence, trusted 5G infrastructure, climate and energy transition, security and defence (including cyber and maritime), and full implementation of the 2019 EU-Vietnam Free Trade Agreement (EVFTA) tariff-elimination schedule plus ratification of the EU-Vietnam Investment Protection Agreement (EVIPA). It is the EU's eleventh CSP globally and its second in Southeast Asia (after Singapore, 2024), and constitutes the foundational bilateral parent framework for all future EU-Vietnam cooperation under the EU Critical Raw Materials Act (CRMA) Article 13 third-country strategic-project designation pipeline, given Vietnam's approximately 22 Mt rare-earth reserves — the world's second-largest deposit after China.
Taiwan's Legislative Yuan passed the Artificial Intelligence Basic Act (人工智慧基本法) on third reading on 23 December 2025, and President Lai Ching-te promulgated the 20-article statute on 14 January 2026, bringing it into force immediately. The Act designates the National Science and Technology Council (NSTC) as the central AI-policy competent authority and codifies seven governance principles — sustainability and well-being, human autonomy, privacy protection and data governance, cybersecurity and safety, transparency and explainability, fairness and non-discrimination, and accountability — that apply to all public-sector AI procurement and high-risk sectoral applications. The statute establishes a statutory foundation for the Taiwan AI Action Plan 2.0, mandates an Executive Yuan National AI Strategy Committee, and provides authority for sector-specific implementing regulations by FSC, NCC, MOHW, and MOTC across finance, telecoms, medical, and autonomous-vehicle AI within a two-year window. As the first national AI governance statute in the Greater China region and the third globally after the EU AI Act and South Korea's AI Basic Act, it frames regulatory expectations for the companies at the heart of the global AI hardware supply chain — TSMC, NVIDIA ODM partners, and advanced-packaging incumbents — that are headquartered or operate substantially in Taiwan.
Vietnam's National Assembly passed Law on Cybersecurity No. 116/2025/QH15 on 10 December 2025 (434 of 443 deputies in favour), effective 1 July 2026. The law supersedes both the 2018 Cybersecurity Law (Law 24/2018/QH14) and the 2015 Law on Cyber Information Security, consolidating cybersecurity, cyber-information-security, and network-information-security into a unified Ministry of Public Security-led framework. It retains data-localization obligations for foreign digital-service providers handling personal data, user-generated content, and relationship graphs of Vietnamese users (minimum 24-month retention), introduces 6-hour urgent / 24-hour standard content take-down windows on MPS request, expressly prohibits AI/deepfake forgery of images, voices, and videos for illegal purposes, and mandates child-safety platform measures.
Germany's transposition of EU Directive 2022/2555 (NIS2), enacted as the "Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung." Bundestag passage 13 November 2025; Bundesrat approval 21 November 2025; published as BGBl. I 2025 Nr. 301 on 5 December 2025; entered into force 6 December 2025. The statute designates the Bundesamt für Sicherheit in der Informationstechnik (BSI) as the central national supervisory authority over an estimated 29,500 covered entities across 18 critical and important sectors, introduces a mandatory 24h initial / 72h detailed / 1-month final cyber-incident reporting cascade, establishes board-level personal liability for senior management, and applies to SME critical- infrastructure suppliers — with no transitional grace period from entry into force.
FinCEN issued a final rule under Section 311 of the USA PATRIOT Act (31 U.S.C. § 5318A) prohibiting US covered financial institutions from opening or maintaining a correspondent account for, or on behalf of, Cambodia-based Huione Group, a foreign financial institution found to be of primary money-laundering concern. Treasury determined that Huione Group and its subsidiaries — including Haowang Guarantee, Huione Pay PLC, and Huione Crypto — laundered at least $4 billion of illicit proceeds between August 2021 and January 2025, including funds tied to North Korean cyber-heist actors and Southeast Asian "pig-butchering" investment-scam compounds. The rule also imposes a special-due-diligence requirement on US covered institutions to guard against indirect access via foreign correspondent accounts. Effective November 17, 2025.
Italy enacted Legge 23 settembre 2025, n. 132 — "Disposizioni e deleghe al Governo in materia di intelligenza artificiale" — published in Gazzetta Ufficiale Serie Generale n. 223 of 25 September 2025 (atto 25G00143) and entered into force on 10 October 2025. The statute makes Italy the first EU member state to enact a comprehensive national AI law complementing Regulation (EU) 2024/1689 (EU AI Act), designating AgID (Agency for Digital Italy) and ACN (National Cybersecurity Agency) as national oversight authorities under Presidency-of-the-Council-of-Ministers coordination. It sets sectoral rules for healthcare, labour, intellectual professions, public administration and the judiciary; authorises up to €1 billion in state-backed venture capital (via CDP Venture Capital) for AI, cybersecurity and telecoms; creates criminal penalties of up to five years' imprisonment for harmful deepfakes; mandates parental consent for under-14 users; and delegates secondary legislation to the Government across multiple domains.
On 8 September 2025, the UK Ministry of Defence published the Defence Industrial Strategy 2025 — "Making Defence an Engine for Growth" (CP 1388) — the first comprehensive cabinet-level UK defence industrial strategy in over a decade and the sector plan for Defence under the UK Modern Industrial Strategy umbrella (IS-8). The strategy was published alongside the Strategic Defence Review 2025 and operationalises the largest sustained defence- spending increase since the Cold War (rising to 2.6% of GDP by 2027 with ambition to 3% in the next Parliament). It defines six priority outcomes (growth, backing UK businesses, defence innovation, resilient industrial base, procurement transformation, enduring partnerships); establishes UK Defence Innovation (UKDI) within the MOD with a ringfenced £400m budget to accelerate dual-use technology; identifies priority defence capabilities (combat air, complex weapons, directed-energy weapons, next- generation land and maritime systems) plus dual-use sub-sectors (quantum, drones/autonomy, space, AI, cyber, engineering biology, advanced connectivity); and flags resilience priorities in steel, construction, energetic materials, batteries, semiconductors and rare earths.
Greece enacted Law 5202/2025 on 22 May 2025, published in Government Gazette ΦΕΚ A' 84 on 23 May 2025 and effective the same day, establishing the country's first national mandatory and suspensory foreign direct investment screening mechanism, aligned with Regulation (EU) 2019/452. The Interministerial Committee for the Control of Foreign Direct Investment (ICC-FDI), with initial procedure run by the Ministry of Foreign Affairs, reviews non-EU acquisitions in "sensitive" sectors (energy, transportation, healthcare, ICT, digital infrastructure) and "particularly sensitive" sectors (national security, defence, cybersecurity, AI, ports and critical subsea infrastructure, borderland tourism). A two-phase review applies — 30 days Phase I, up to 150 days Phase II with EU Cooperation Mechanism notification — and the regime became fully operational on 11 November 2025.
Japan's National Diet enacted the Cyber Response Capability Enhancement Act (重要電子計算機に対する不正な行為による被害の防止に関する法律, Law No. 42 of 2025) on 16 May 2025, together with companion arrangement legislation. Commonly known as the Active Cyber Defense (ACD) Law, the statute authorises (i) government monitoring of foreign-origin internet traffic transiting designated Japanese communication infrastructure for national-security threat indicators, (ii) pre-emptive access and neutralisation operations against attacker infrastructure abroad by the National Police Agency and the Self-Defense Forces under unified command, and (iii) mandatory cyber-incident reporting and government cooperation duties on critical-infrastructure operators. Implementation is phased through November 2027, with the NISC reorganised into the National Cybersecurity Office (NCO) under the Cabinet Secretariat from July 2025.
Regulation (EU) 2024/2847 of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, signed 23 October 2024 and entering into force 10 December 2024. The CRA is the first EU statutory cybersecurity regime covering all hardware and software products with a direct or indirect data connection placed on the EU market, imposing essential cybersecurity requirements, conformity assessment with CE marking, mandatory vulnerability handling, and 24-hour early-warning notification of actively-exploited vulnerabilities to ENISA. Main manufacturer obligations apply from 11 December 2027; conformity-assessment-body notification provisions apply from 11 June 2026 and reporting obligations from 11 September 2026. Penalties reach EUR 15M or 2.5% of global annual turnover.
Japan's National Diet enacted the Act on the Protection and Use of Critical Economic Security Information (重要経済安保情報の保護及び活用に関する法律, Act No. 27 of 2024) on 10 May 2024; it was promulgated on 17 May 2024 and came into full operation on 16 May 2025. The law establishes Japan's first peace-time economic-security clearance regime extending to private-sector employees. It designates "Critical Economic Security Information" (CESI) covering threat-intelligence on critical-infrastructure cyber attacks, regulatory-review information on essential infrastructure, and vulnerability data on critical-product supply chains; mandates Cabinet Office "適性評価" (suitability assessment) for cleared personnel; and imposes criminal penalties of up to five years' imprisonment for unauthorised disclosure. The CESI Act complements the 2022 Economic Security Promotion Act (ESPA), closing the information-protection gap and aligning Japan's framework with Five Eyes and EU partners for joint R&D and dual-use cooperation.
Latvia's Saeima adopted on 27 March 2024 amendments to the National Security Law (Nacionālās drošības likums), entering into force on 24 April 2024, that widen the perimeter of foreign-investment and ownership transactions subject to Cabinet of Ministers pre-clearance over "companies of significance to national security." The amendments expand the universe of regulated subjects beyond registered companies to include foundations and associations, tighten the rules on beneficial-ownership disclosure, and bring additional sensitive activities — energy security including LNG-terminal acquisitions, electronic communications, cybersecurity, and critical-raw-materials processing — under the regime, while clarifying Cabinet authority to impose conditions or unwind transactions retroactively. The law functions as Latvia's horizontal FDI-screening instrument under the EU-wide cooperation framework of Regulation 2019/452.
Bulgaria's National Assembly adopted on 22 February 2024 amendments to the Investment Promotion Act establishing the country's first horizontal foreign direct investment screening mechanism, published in State Gazette No. 20 on 8 March 2024 and entering into force on 12 March 2024. The regime implements EU Regulation 2019/452 by creating an Interdepartmental Screening Council with a 45-day decision window over non-EU investments meeting a 10 % equity stake or €2 million threshold in critical-infrastructure, dual-use, advanced-technology, media, and financial-infrastructure sectors, with no threshold for investments by Russian or Belarusian persons or in oil and petroleum activities. Non-compliance and false declarations carry fines of 5 % of investment value, with a minimum BGN 50,000.
Ireland's Screening of Third Country Transactions Act 2023 (Act No. 28 of 2023), signed into law on 31 October 2023 and commenced on 6 January 2025 via S.I. No. 651 of 2024, establishes Ireland's first-ever mandatory inbound FDI screening regime. The Act empowers the Minister for Enterprise, Tourism and Employment to assess, condition, or prohibit transactions by third-country investors (non-EU/EEA/Switzerland) exceeding a EUR 2 million cumulative threshold in targets operating across critical infrastructure, critical technologies, dual-use items, supply of critical inputs, sensitive personal data, and media freedom. A 90-day standstill period applies during Ministerial determination, with criminal sanctions and transaction-voiding powers available for non-compliance.
Bureau of Industry and Security final rule (88 FR 46071, Doc 2023-15343) adding four entities to the Entity List effective July 18, 2023. Intellexa S.A. (Greece) and Intellexa Limited (Ireland) — the corporate architecture behind the "Predator" commercial spyware platform — and Cytrox Holdings Zrt. (Hungary) and Cytrox AD (North Macedonia) — the developer of the underlying spyware technology — were listed for "trafficking in cyber exploits used to gain access to information systems, thereby threatening the privacy and security of individuals and organizations worldwide." All items subject to the EAR require a license with a presumption-of-denial review policy for all four entities, effectively cutting off access to US-origin hardware, software, and technology.
Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA) is the EU's first horizontal cyber- and ICT-resilience instrument for the financial sector. Adopted 14 December 2022 and published in the Official Journal on 27 December 2022, it entered into force on 16 January 2023 and applies from 17 January 2025. DORA covers approximately 22,000 EU regulated financial entities across ~20 entity types (credit institutions, insurers, investment firms, CCPs, trading venues, crypto-asset service providers, etc.) under five pillars: ICT risk management, ICT-incident reporting, digital operational resilience testing (including threat-led penetration testing for significant entities), ICT third-party risk management, and information sharing. Structurally novel, DORA establishes the Critical ICT Third-Party Provider (CTPP) oversight regime under which the European Supervisory Authorities (EBA, ESMA, EIOPA) acquire direct supervisory powers over hyperscale cloud providers (AWS, Azure, GCP, Oracle) servicing EU financial entities — the first EU mechanism for ESA direct oversight of non-financial cloud providers.
Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive), published OJ L 333, 27 December 2022, entered into force 16 January 2023. NIS2 repeals and substantially expands the 2016 NIS1 Directive (2016/1148), extending the scope from ~7 sectors to 18 enumerated essential and important sectors, imposing binding cybersecurity risk- management and incident-reporting obligations on covered entities, introducing board-level management accountability, and mandating Member State transposition by 17 October 2024. NIS2 is the structural EU statutory anchor for national cybersecurity frameworks across the bloc, operating alongside DORA (Reg 2022/2554) for financial-sector digital resilience and CRA (Reg 2024/2847) for product cybersecurity.
Belgium's first horizontal foreign-direct-investment screening regime, established by a Cooperation Agreement signed on 30 November 2022 between the Federal State and the Flemish, Walloon, Brussels-Capital and German-Community governments, and in force from 1 July 2023. The agreement creates a centralised Interfederal Screening Commission (ISC), chaired by the FPS Economy, to receive and process mandatory ex-ante notifications of foreign acquisitions of 10%, 25% or higher voting-rights / control thresholds (sector-dependent) in Belgian undertakings active in eleven strategic sectors. ISC decisions are binding; sanctions for failure to notify or for non-compliance with conditions imposed include unwinding of the transaction and administrative fines.
Government Decree 53/2022/ND-CP, signed 15 August 2022 and effective 1 October 2022, implements Article 26 of Vietnam's 2018 Law on Cybersecurity. It mandates in-country storage of three categories of data — personal data of users in Vietnam, user-generated data, and user-relationship data — for both domestic and foreign cyberspace- service providers, with a minimum 24-month retention period. Foreign enterprises providing telecoms, data storage, domain names, e-commerce, online payments, social networks, online video games, or messaging services to users in Vietnam must establish a Vietnamese branch or representative office within 12 months of a Minister of Public Security written request. The decree closes a four-year implementation gap on the 2018 Cybersecurity Law and is the principal Vietnamese digital-trade barrier alongside Decree 13/2023/ND-CP (Personal Data Protection).
The Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法 — PIPL) was adopted at the 30th meeting of the 13th NPC Standing Committee on 20 August 2021 and entered into force on 1 November 2021, constituting the third and final pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Data Security Law (2021). The PIPL is China's comprehensive personal-information statute establishing consent-based and necessity-based legal bases for PI processing, a tiered cross-border personal-data transfer regime (CAC security assessment / PI protection certification / Standard Contractual Clauses), extraterritorial application (Art. 3) to non-Chinese controllers offering services to or analysing the behaviour of PRC residents, and a heightened protection regime for sensitive personal information and data of minors under 14. It mandates data-protection impact assessments, personal-information-protection-officer obligations at designated handlers, breach notification, and a full suite of data-subject rights including access, rectification, deletion, portability, objection, and automated- decision-making opt-out. Article 53 requires overseas controllers to establish a domestic representative or designated entity in China, providing a domestic enforcement counterparty.
The Data Security Law of the People's Republic of China (中华人民共和国数据安全法) was adopted at the 29th meeting of the 13th NPC Standing Committee on 10 June 2021 and entered into force on 1 September 2021, constituting the second pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Personal Information Protection Law (2021). The DSL establishes a tiered data-classification regime — "important data" and "national core data" — with escalating security obligations including risk assessment, risk monitoring, breach reporting, and classified-protection requirements for data handlers. It introduces a data-export security review for "important data" generated or collected within China, the statutory parent authority operationalised by the 2024 CAC Cross-Border Data Flow Provisions, and enacts a §36 blocking statute prohibiting Chinese organisations and individuals from transferring data stored in China to foreign judicial or law-enforcement authorities without prior PRC government approval.
Regulation (EU) 2021/821, adopted 20 May 2021 and applied from 9 September 2021, establishes the Union regime for controlling exports, brokering, technical assistance, transit, and transfer of dual-use items, repealing Regulation (EC) No 428/2009. Annex I lists controlled items implementing internationally agreed dual-use controls under the Wassenaar Arrangement, MTCR, Australia Group, NSG, and Chemical Weapons Convention. The regulation introduces a new catch-all control on cyber-surveillance technologies that could facilitate human-rights violations (Art. 5 and Annex IV), and strengthens cooperation between Member States and the European Commission, placing specific obligations on exporters. It serves as the statutory anchor for all EU export licences, every multilateral-regime transposition into EU law, and coordination mechanisms with US BIS, UK ECJU, JP METI, and KR MOTIE export-control regimes.
The Investitionskontrollgesetz (InvKG, "Investment Control Act") is Austria's horizontal, statutory FDI screening regime. Published as Article 1 of the Federal Law BGBl. I Nr. 87/2020 on 24 July 2020 and entering into force on 25 July 2020, the Act replaced the previous narrow §§25a–25e Außenwirtschaftsgesetz 2011 (Foreign Trade Act) regime — under which fewer than 10 permits were issued from 2013 to mid-2020 — and transposes EU Regulation 2019/452 establishing a framework for the screening of foreign direct investments into the Union. The InvKG introduces mandatory ex-ante notification and approval of non-EU / non-EEA / non-Swiss acquisitions where the acquirer crosses any of the 10% / 25% / 50% voting-rights thresholds in an Austrian target operating in the critical sectors listed in Annex Part 1 (especially sensitive: defence, energy / water / telecoms critical infrastructure, dual-use technology, cybersecurity, AI, quantum technology, robotics, semiconductors, biotech, health, vaccines) and 25% / 50% in the sectors listed in Annex Part 2 (broader, including media, food-security, electronic communications infrastructure, financial infrastructure). Administered by the Bundesministerium für Arbeit und Wirtschaft (BMAW), with case decisions taken in coordination with the Komitee für Investitionskontrolle (inter-ministerial Investment Control Committee) and, where the case is escalated to the EU cooperation mechanism, the Commission and EU peer Member States. The InvKG is Austria's functional peer of US CFIUS / FIRRMA, UK NSI Act 2021, Germany AWG §§55–62, France Décret 2014-479 / R. 151-1 et seq., Italy Golden Power Decree, Netherlands Wet Vifo, Denmark investeringsscreeningsloven, and Belgium ISC. Sunset clause: originally limited to 30 June 2022 under §17(2) InvKG; permanently extended by BGBl. I Nr. 80/2022 of 14 July 2022.
The modern French FDI-screening regime is codified in Code monétaire et financier (CMF) Art. L151-1 to L151-7, substantially restructured by Loi PACTE n° 2019-486 du 22 mai 2019 (Art. 152-158) and operationalised by Décret n° 2019-1590 du 31 décembre 2019 (in force 1 April 2020) with implementing Arrêté du 31 décembre 2019. The regime requires prior authorisation from DG Trésor for non-EU/EEA acquisitions reaching ≥25% of a French target's voting rights across 17 sensitive sectors enumerated in CMF Art. R151-3, and for ≥10% acquisitions in listed-company targets (threshold made permanent by Décret 2023-1293 from 1 January 2024, having been originally introduced during COVID-19 by Décret 2020-892). Approximately 310 notifications are received annually; the regime closes the last major G7 EU-member-state FDI-screening parent-statute gap after DE AWG §§55-62, IT Golden Power DL 21/2012, NL Wet Vifo, UK NSI Act 2021, US CFIUS, JP FEFTA, AU FATA, and CH IPG.
The Sanctions and Anti-Money Laundering Act 2018 (SAMLA, Chapter 13) received Royal Assent on 23 May 2018 and established the UK's autonomous post-Brexit sanctions legal framework. Part 1 empowers Ministers (FCDO, HM Treasury) to impose financial, trade, immigration, aircraft, and shipping sanctions by statutory instrument for purposes including UN compliance, national security, foreign-policy objectives, and promotion of human rights and democracy. Part 2 grants Ministers authority to make AML and counter-terrorist-financing regulations aligned with FATF standards, previously derived from EU Anti-Money-Laundering Directives. SAMLA is the parent enabling statute for every UK sanctions regime in force post-Brexit, including 30+ thematic and geographic regulations covering Russia (SI 2019/855), Iran, DPRK, Belarus, Myanmar, Syria, Venezuela, cyber, chemical weapons, global anti-corruption, and global human rights; under SAMLA, OFSI (HM Treasury) holds civil monetary-penalty and criminal-referral enforcement powers. Structurally peer to US IEEPA, EU Council Regulation framework, CN AFSL 2021, and JP FEFTA as the G7+CN foundational sanctions-statute cluster.
The Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法) was adopted at the 24th meeting of the 12th NPC Standing Committee on 7 November 2016 and entered into force on 1 June 2017, establishing the foundational legal framework for network security governance across all sectors. The law creates the Critical Information Infrastructure Operator (CIIO) designation and protection regime administered by the Cyberspace Administration of China (CAC), mandates data localisation for personal information and important data collected or generated by CIIOs in China, and establishes cross-border data-transfer security assessment requirements under Article 37 — the provision later operationalised by DSL 2021, PIPL 2021, and the 2024 CAC Cross-Border Data Flow Provisions. The CSL introduced multi-level protection scheme (等级保护制度 / MLPS) obligations for all network operators and network-product/service security-review procedures, under which CAC triggered the cybersecurity review of Didi Global in 2021 and the exclusion of Micron's products from Chinese critical-infrastructure projects in 2023.
The International Emergency Economic Powers Act of 1977 (IEEPA, Title II of Pub. L. 95-223, 91 Stat. 1626, codified at 50 U.S.C. §§ 1701–1708) was signed by President Carter on 28 December 1977 and grants the President sweeping authority to declare a national emergency with respect to "any unusual and extraordinary threat, which has its source in whole or substantial part outside the United States, to the national security, foreign policy, or economy of the United States" — and then to investigate, regulate, direct, compel, nullify, void, prevent, or prohibit any transaction in, or involving, foreign exchange, banking transfers, importing, exporting, or dealings in property by persons subject to US jurisdiction. IEEPA is the parent enabling statute for every OFAC-administered autonomous sanctions program (Russia, Iran, DPRK, Venezuela, Cuba, Syria, Belarus, Myanmar, cyber, Global Magnitsky, Hong Kong, ICC, and others) as well as the legal basis for the entire Trump-era IEEPA-tariff regime (EO 14193–14195 fentanyl tariffs, Canada/Mexico/China; EO 14257 reciprocal-tariff framework; EO 14323 Brazil; EO 14380 Cuba; EO 14382 Iran; and the US-India interim tariff agreement). Between 1977 and 2025 Presidents invoked IEEPA in 77 national-emergency declarations; of these, 7+ directly parent IPTM-filed implementing actions, with ~dozens of OFAC SDN designation actions tracing their legal root to this statute.