Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
On 7 September 2026 the UK made the Iran (Sanctions) (Amendment) Regulations 2026 (SI 2026/983), laid before Parliament 8 September 2026 and due to come into force 29 September 2026. The instrument substantially rewrites the Iran (Sanctions) Regulations 2023 and the Iran (Sanctions) Regulations 2019, adding new financial restrictions (bans on loans, credit and joint ventures with Iranian manufacturing, oil/gas, petrochemical and uranium interests; a ban on UK banks opening accounts or representative offices for Iranian banks; an insurance/reinsurance ban; a ban on trading Iranian government bonds issued after the regulation date), new trade-control chapters covering gold/precious metals/diamonds, energy-related goods and services, and sectoral software, new import bans on Iranian gold, oil, petrochemicals and natural gas, and new aircraft/shipping parts restricting Iranian cargo flights, chartering of specified vessels, and UK port entry and ship registration for sanctions-evading vessels.
President Trump signed Executive Order 14420 on 26 August 2026, declaring a national emergency under IEEPA and the National Emergencies Act over foreign threats to the US bulk-power system. The order generally prohibits the acquisition, import, transfer, or installation of foreign-produced bulk-power system electric equipment — transformers, inverters, battery storage, generators, circuit breakers, turbines, and industrial control systems, including associated software and remote-access capabilities — where a transaction involves a "Covered Foreign Entity" and poses a risk of sabotage, unauthorized access, or catastrophic disruption to critical infrastructure. Local electric distribution facilities are excluded. No countries or companies are named in the order itself; DOE must publish implementing rules within 120 days (by 24 December 2026) identifying covered equipment and entities, and submit recommended Federal Acquisition Regulation revisions within 180 days.
Taiwan's Legislative Yuan passed the Artificial Intelligence Basic Act (人工智慧基本法) on third reading on 23 December 2025, and President Lai Ching-te promulgated the 20-article statute on 14 January 2026, bringing it into force immediately. The Act designates the National Science and Technology Council (NSTC) as the central AI-policy competent authority and codifies seven governance principles — sustainability and well-being, human autonomy, privacy protection and data governance, cybersecurity and safety, transparency and explainability, fairness and non-discrimination, and accountability — that apply to all public-sector AI procurement and high-risk sectoral applications. The statute establishes a statutory foundation for the Taiwan AI Action Plan 2.0, mandates an Executive Yuan National AI Strategy Committee, and provides authority for sector-specific implementing regulations by FSC, NCC, MOHW, and MOTC across finance, telecoms, medical, and autonomous-vehicle AI within a two-year window. As the first national AI governance statute in the Greater China region and the third globally after the EU AI Act and South Korea's AI Basic Act, it frames regulatory expectations for the companies at the heart of the global AI hardware supply chain — TSMC, NVIDIA ODM partners, and advanced-packaging incumbents — that are headquartered or operate substantially in Taiwan.
On 11 December 2025 the US Department of State announced the inaugural Pax Silica Summit, held in Washington D.C. on 12 December 2025, at which the United States, Australia, Japan, the Republic of Korea, the United Kingdom, Singapore and Israel signed the non-binding Pax Silica Declaration. The declaration commits signatories to coordinate "trusted" supply chains across the full technology stack — software, frontier foundation models, network infrastructure, compute and semiconductors, advanced manufacturing, transportation logistics, minerals refining and processing, and energy — explicitly to reduce "coercive dependencies." The coalition has since expanded to add the United Arab Emirates, Greece, Qatar, Sweden and India (signed 20 February 2026 at the India AI Impact Summit), and on 26 March 2026 State announced a USD 250 million Pax Silica Fund intended to catalyse trusted-capital co-investment in critical-minerals processing and semiconductor supply chains.
On 10 December 2025 the National Assembly of Vietnam adopted Law No. 134/2025/QH15 on Artificial Intelligence (8 chapters, 35 articles), Vietnam's first dedicated AI statutory framework and one of the first comprehensive horizontal AI laws in Southeast Asia. The law establishes a three-tier risk-based regulatory architecture (high / medium / low) for the research, development, provision, deployment, and use of AI systems; defines the rights and obligations of providers, deployers, importers, distributors, and users; and mandates state oversight via the Ministry of Information & Communications and Ministry of Science & Technology. Prohibited acts include systematic deception, manipulation of human perception, generation of fake content endangering national security, exploitation of vulnerable populations, and obstruction of human-supervision mechanisms. The law applies to Vietnamese agencies, organizations, and individuals as well as foreign organizations and individuals involved in AI-related activities in Vietnam, taking effect 1 March 2026 with 12-18 month transition windows for existing systems depending on sector.
India's Ministry of Electronics and Information Technology (MeitY) notified the Digital Personal Data Protection Rules, 2025 via Gazette notification G.S.R. 846(E) on 13 November 2025, operationalising the 2023 DPDP Act. The Rules introduce a "negative list" cross-border personal-data transfer regime under Rule 14, verifiable parental consent, breach-notification windows, and tiered penalties up to INR 250 crore. Implementation is phased: Data Protection Board provisions in force on notification, Consent Manager rules from 13 Nov 2026, and core data-fiduciary / cross-border-transfer obligations from 13 May 2027.
India's Directorate General of Foreign Trade (DGFT) issued Notification No. 31/2025-26 on 23 September 2025, revising Appendix-3 of Schedule-II of the ITC(HS) Export Policy to add a new Category 7 — "Certain Emerging Technologies and related items" — to the SCOMET (Special Chemicals, Organisms, Materials, Equipment and Technologies) list. Category 7 brings under export-licence control: quantum-computing systems (≥34 qubits with controlled error rates), cryogenic CMOS integrated circuits, advanced lithography tools (≤45 nm minimum resolvable feature), additive-manufacturing equipment under vacuum, and related software/technology. The notification took effect 30 days from issuance, on 23 October 2025, and is the first new SCOMET category created since the list's last major restructure, aligning India's strategic-trade-control regime with parallel US BIS, Wassenaar Arrangement, and EU dual-use list updates.
The US Bureau of Industry and Security (BIS) amended the Export Administration Regulations to remove three foreign-owned semiconductor fabs operating in China — Intel Semiconductor (Dalian) Ltd, Samsung China Semiconductor Co. Ltd, and SK hynix Semiconductor (China) Ltd — from the Validated End-User (VEU) Authorizations list (15 CFR Part 748). BIS framed the VEU program as a "loophole" that previously allowed these fabs to receive most US-origin chipmaking equipment, software and technology license-free, a privilege no US-owned fab in China ever had. After the effective date, every restricted shipment to these fabs will require an individual export license, reviewed case-by-case under the existing 2022/2023 advanced- computing controls. The rule is published as Federal Register document 2025-16735 (90 FR 42321), Docket BIS-2025-0555, RIN 0694-AK32.
On 18 July 2025, the Council of the European Union adopted the 18th package of restrictive measures against Russia, anchored by Council Regulation (EU) 2025/1494 amending Regulation 833/2014 (sectoral measures), Council Implementing Regulation (EU) 2025/1476 implementing Regulation 269/2014 (asset-freeze listings), Council Decision (CFSP) 2025/1495 (vessel listings), and Council Regulation (EU) 2025/1472 (parallel Belarus measures). The package is the largest energy-sector escalation since 2022 and pivots from new-perimeter creation toward enforcement and circumvention closure. Headline measures: (i) the Russian-crude price cap is lowered from USD 60 to USD 47.6 per barrel with a new automatic dynamic mechanism re-indexing the cap to global oil prices every six months at a 15 % discount to the 22-week trailing average (effective 3 Sep 2025, with a transitional exemption to 18 Oct 2025 for pre-20 Jul 2025 contracts compliant with the prior cap); (ii) full transaction ban extended to 22 additional Russian banks, bringing the total cut off from the EU financial system to 45; transaction ban extended to third-country financial institutions and crypto-asset service providers facilitating circumvention; (iii) full transaction ban on Nord Stream 1 and Nord Stream 2 pipelines; (iv) import ban on refined oil products derived from Russian crude processed in third countries; (v) 105 additional vessels added to the shadow-fleet port-access ban (cumulative total 444); (vi) 26 new entities added to Annex IV military end-user list (15 Russian + 11 from China/Hong Kong/Turkey); (vii) Council Implementing Regulation 2025/1476 lists 14 individuals + 41 entities under asset-freeze, including a major Indian refinery (Nayara Energy, part-owned by Rosneft), three Chinese suppliers of battlefield goods, shadow-fleet operators, and entities involved in the deportation of Ukrainian children; (viii) parallel Belarus complementary measures via Regulation 2025/1472. Wind-down periods vary: 90 days for oil-price-cap contracts; banking-software wind-down to 30 Sep 2025; trade-goods wind-downs Oct 2025–Jan 2026 by category. Entry into force on 19 July 2025 (day following publication in the Official Journal), except for measures with explicit deferred application dates.
The National Assembly of Vietnam passed the Personal Data Protection Law (Luật Bảo vệ dữ liệu cá nhân), Law No. 91/2025/QH15, on 26 June 2025; it enters into force on 1 January 2026. The PDPL is Vietnam's first statutory (rather than decree-level) personal-data-protection framework, elevating the prior Decree 13/2023/ND-CP (PDPD) regime into a 5-chapter, 39-article primary statute and adding revenue-based administrative penalties of up to 5% of prior-year annual revenue for cross-border data-transfer violations and up to 10x illegal gains for unlawful data trading. The law is implemented by Decree 356/2025/ND-CP (issued 31 December 2025, effective 1 January 2026) and applies extraterritorially to foreign organisations offering services to or processing the personal data of Vietnam residents.
On 20 June 2025, the US Treasury's Office of Foreign Assets Control designated one individual, eight entities, and one vessel pursuant to Executive Order 13382 (WMD proliferators) for procuring and transshipping sensitive machinery to Iran's Rayan Roshd Afzar Company (RRA), a producer of UAV components and aerospace software for the IRGC. The vessel SHUN KAI XING, owned by Hong Kong-based Unico Shipping Co Ltd and chartered by Singapore-based V-Shipping Pte Ltd, was carrying the machinery for RRA and an affiliated firm when its cargo was inspected; the designated network — including China-based Shenzhen Xinxin Shipping, Dongguan Zanyin Machinery and Equipment, Athena Shipping, shipmaster Zhang Yanbing, and Turkiye-based Edisa Dis Ticaret Limited Sirketi — then falsified bills of lading to obscure the Iran-bound, RRA-consigned cargo after the inspection.
The US Bureau of Industry and Security amended the Export Administration Regulations to add 12 entities to the Entity List under the destinations of China (11) and Taiwan (1) via Final Rule 2025-05427 (90 FR 14046), companion to the larger 70-entity rule (2025-05426) published the same day. Targets fall in three clusters: (i) Beijing Academy of Artificial Intelligence and Beijing Innovation Wisdom Technology — added for acquiring US-origin items in support of China's military modernization, specifically developing large AI models and advanced computing chips for defense; (ii) the Inspur group — Inspur (Beijing) Electronic Information Industry, Inspur Electronic Information Industry, Inspur Electronic Information (Hong Kong), Inspur (HK) Electronics, Inspur Software, and Inspur Taiwan — added as subsidiaries contributing to supercomputers for military end use; and (iii) Henan Dingxin, Nettrix Information Industry, Suma Technology, and Suma-USI Electronics — added for involvement in the development of Chinese exascale supercomputers. License requirements are for all items subject to the EAR; review policy is presumption of denial for the AI cluster and policy of denial for the supercomputer clusters.
BIS (acting through its Office of Information and Communications Technology and Services, OICTS) published a final rule under Executive Order 13873's ICTS authority prohibiting certain connected-vehicle (CV) transactions involving hardware and software designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction of the People's Republic of China or the Russian Federation. The rule reaches the Vehicle Connectivity System (VCS — hardware/software enabling external RF connectivity above 450 MHz) and the Automated Driving System (ADS) software stack. Effective 17 March 2025, with phased prohibitions: import/sale of CVs incorporating covered software prohibited from model year 2027; import of covered VCS hardware prohibited from model year 2030 (or 1 January 2029 for hardware not associated with a model year). Importers and connected-vehicle manufacturers must file annual Declarations of Conformity.
The National Assembly of Vietnam passed the Law on Data (Luật Dữ liệu), No. 60/2024/QH15, on 30 November 2024; it enters into force on 1 July 2025. The Law is Vietnam's first comprehensive horizontal data-governance statute, extending regulation beyond personal data (already covered by Decree 13/2023/ND-CP) to all digital data — public, private, and sectoral. It introduces statutory categories of "important data" (dữ liệu quan trọng) and "core data" (dữ liệu cốt lõi) tied to national-defence and national-security review for cross-border transfer, and establishes the National Data Centre under the Ministry of Public Security plus a statutory data-broker / data-services licensing framework.
Regulation (EU) 2024/2847 of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, signed 23 October 2024 and entering into force 10 December 2024. The CRA is the first EU statutory cybersecurity regime covering all hardware and software products with a direct or indirect data connection placed on the EU market, imposing essential cybersecurity requirements, conformity assessment with CE marking, mandatory vulnerability handling, and 24-hour early-warning notification of actively-exploited vulnerabilities to ENISA. Main manufacturer obligations apply from 11 December 2027; conformity-assessment-body notification provisions apply from 11 June 2026 and reporting obligations from 11 September 2026. Penalties reach EUR 15M or 2.5% of global annual turnover.
The US Bureau of Industry and Security issued a final rule on 5 September 2024 (effective 6 September 2024, published in the Federal Register on the same day as 89 FR 73285) establishing multilateral export controls on four categories of emerging technologies: (1) quantum computing items including quantum computers, related cryogenic / control / measurement systems, and certain quantum software; (2) gate-all-around field-effect transistor (GAAFET) production technology — the next-node semiconductor architecture beyond FinFET; (3) advanced additive-manufacturing equipment for metals + alloys; (4) certain biotech-related items added in a parallel rule on 12 September 2024. The rule operates without country exceptions for some categories, with multilateral coordination via Wassenaar + Australia Group + Nuclear Suppliers Group frameworks.
The U.S. Bureau of Industry and Security (BIS) published a final rule expanding the scope of the Iran Foreign Direct Product (FDP) rule in the Export Administration Regulations (EAR) to implement the "No Technology for Terror Act" (Public Law 118-50, Division N), signed by President Biden on April 24, 2024. The expanded rule extends EAR jurisdiction to additional foreign-produced items destined for Iran — including a broader set of items derived from U.S.-origin technology or software, or produced by plants/components that are themselves direct products of U.S.-origin technology — and requires a BIS license for their export, reexport, or in-country transfer to Iran. The rule also provides specified exclusions from the otherwise-applicable license requirements. The rule became effective on July 23, 2024 (publication July 26, 2024).
The European Union's Artificial Intelligence Act, Regulation (EU) 2024/1689, was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. It establishes the world's first horizontal, risk-tiered legal framework for the development, market placement, and use of AI systems — covering prohibited practices, high-risk systems, general-purpose AI models, and minimal-risk applications — with extraterritorial reach over any provider placing an AI system on the EU market or whose output is used in the EU. Penalties reach up to EUR 35 million or 7% of global annual turnover. Application is staged: prohibitions from 2 February 2025, GPAI and governance from 2 August 2025, the bulk of high-risk obligations from 2 August 2026, and product-safety-embedded high-risk systems from 2 August 2027.
BIS final rule (FR Doc 2024-13148, 89 FR 51644, RIN 0694-AJ87) expanding the Export Administration Regulations' Russia and Belarus sanctions architecture. Effective 12 June 2024 (most provisions) and 16 September 2024 (the EAR99 enterprise-software paragraph at §746.8(a)(8)), the rule introduces a new licence requirement for thirteen named categories of EAR99 enterprise software (ERP, CRM, BI, SCM, EDW, CMMS, project management, PLM, BIM, CAD, CAM, ETO) destined for Russia or Belarus; permits address-only Entity List designations to capture high-diversion addresses; adds eight Hong Kong addresses to the Entity List; and refines the Russia/Belarus Industry Sector Sanctions and Foreign Direct Product (FDP) rule. Released the day before the G7 Italy summit alongside coordinated OFAC, State, and Treasury actions that together designated 300+ persons and entities.
Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data — the "Data Act" — was published in the Official Journal on 22 December 2023, entered into force on 11 January 2024, and applies generally from 12 September 2025 (with longer transitional periods for IoT product-design obligations under Article 3(1), which apply to products placed on the market after 12 September 2026, and for the data-portability standardisation framework, applicable from 12 September 2027). The Data Act is the third pillar of the EU data-economy framework alongside the GDPR (personal data) and the Data Governance Act 2022/868 (data-intermediation services), and is the world's first horizontal statutory regime governing access to and portability of industrial / IoT / non-personal data — covering by-design data-availability obligations on connected-product manufacturers, a mandatory cloud- switching framework with progressive elimination of switching charges, B2G emergency data-sharing in exceptional needs, unfair-contract-terms protection for SMEs, and safeguards against unlawful international government access to non-personal data held in EU cloud.
Bureau of Industry and Security final rule (88 FR 46071, Doc 2023-15343) adding four entities to the Entity List effective July 18, 2023. Intellexa S.A. (Greece) and Intellexa Limited (Ireland) — the corporate architecture behind the "Predator" commercial spyware platform — and Cytrox Holdings Zrt. (Hungary) and Cytrox AD (North Macedonia) — the developer of the underlying spyware technology — were listed for "trafficking in cyber exploits used to gain access to information systems, thereby threatening the privacy and security of individuals and organizations worldwide." All items subject to the EAR require a license with a presumption-of-denial review policy for all four entities, effectively cutting off access to US-origin hardware, software, and technology.
Effective 17 August 2020 (published in the Federal Register 20 August 2020, Vol. 85 No. 162, FR Doc 2020-18213), BIS implemented three simultaneous measures targeting Huawei's global supply chain. First, 38 non-U.S. affiliates of Huawei Technologies Co., Ltd. were added to the Entity List with the most restrictive license review policy (presumption of denial) and designated under footnote 1, extending the Huawei-specific Foreign-Produced Direct Product Rule (FDPR) to their operations. Second, the Temporary General License (TGL), which since May 2019 had authorized limited ongoing transactions with Huawei (network maintenance, software updates, standards participation), was allowed to expire on 13 August 2020 and replaced with a narrower authorization. Third, BIS expanded the scope of the Huawei FDPR (General Prohibition Three) to cover foreign-produced items when a footnote 1 entity is a party to any transaction or when the item will be used in the production or development of products for any footnote 1 entity, closing the design-house loophole that had allowed TSMC to supply HiSilicon/Kirin chips as long as Huawei was not the direct importer.