Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
On June 8, 2026, the US Department of Defense published its annual update to the Section 1260H Chinese Military Companies (CMIC) list, adding 65 entities (17 new parent companies and 48 subsidiaries), bringing the total to approximately 188–200 designated entities. Major additions span EV and battery manufacturing (BYD, NIO, CATL), consumer internet (Alibaba, Baidu, Tencent), semiconductors (SMIC, YMTC, CXMT), solar (JA Solar, Trina Solar), biotech (BGI Genomics, WuXi AppTec), drones/robotics (DJI, Unitree, RoboSense), and telecoms (TP-Link). Effective June 30, 2026, DoD is prohibited from procuring goods, services, or technology directly from listed entities; effective June 30, 2027, the ban extends to indirect supply-chain procurement through prime contractors and all sub-tiers.
Japan's Diet passed the Foreign Exchange and Foreign Trade Act (FEFTA) 2026 Amendment on 29 May 2026; the law was promulgated on 5 June 2026. The amendment represents the most significant overhaul of Japan's inbound FDI screening regime since FEFTA was first applied to national-security transactions in 2019. Three structural additions: (1) indirect-acquisition screening — extends mandatory prior-notification to acquisitions of Japanese sensitive-sector companies effected through intermediate holding structures or offshore parent vehicles, closing the principal gap exploited by Chinese and GCC SWF investors via SPV chains; (2) call-in powers — grants the Minister of Finance authority to open a review up to ten years retroactively where an acquisition was not pre-notified or where circumstances have materially changed since clearance, directly analogous to CFIUS § 721(b)(1)(D) retroactive jurisdiction; (3) cross-ministerial "Japan CFIUS" consultation framework — formally institutionalises a standing inter-agency committee (Finance, METI, MoD, NPA, MIAC) modelled on the US CFIUS committee, replacing the prior ad-hoc inter-ministerial process. Cross-ministerial and indirect-acquisition provisions entered into force immediately on promulgation (5 June 2026); remaining Cabinet-Order-level implementing provisions to follow within one year.
On 29 January 2026, European Council President António Costa and Vietnamese Prime Minister Phạm Minh Chính signed a Joint Statement in Hanoi upgrading EU-Vietnam bilateral relations to a Comprehensive Strategic Partnership (CSP) — the highest tier in Vietnam's diplomatic hierarchy, placing the EU on the same level as Vietnam's CSPs with China, Russia, India, South Korea, Japan, Australia, France, and the United States. The CSP establishes a reinforced bilateral cooperation framework spanning critical raw materials, semiconductor supply chains, artificial intelligence, trusted 5G infrastructure, climate and energy transition, security and defence (including cyber and maritime), and full implementation of the 2019 EU-Vietnam Free Trade Agreement (EVFTA) tariff-elimination schedule plus ratification of the EU-Vietnam Investment Protection Agreement (EVIPA). It is the EU's eleventh CSP globally and its second in Southeast Asia (after Singapore, 2024), and constitutes the foundational bilateral parent framework for all future EU-Vietnam cooperation under the EU Critical Raw Materials Act (CRMA) Article 13 third-country strategic-project designation pipeline, given Vietnam's approximately 22 Mt rare-earth reserves — the world's second-largest deposit after China.
Taiwan's Legislative Yuan passed the Artificial Intelligence Basic Act (人工智慧基本法) on third reading on 23 December 2025, and President Lai Ching-te promulgated the 20-article statute on 14 January 2026, bringing it into force immediately. The Act designates the National Science and Technology Council (NSTC) as the central AI-policy competent authority and codifies seven governance principles — sustainability and well-being, human autonomy, privacy protection and data governance, cybersecurity and safety, transparency and explainability, fairness and non-discrimination, and accountability — that apply to all public-sector AI procurement and high-risk sectoral applications. The statute establishes a statutory foundation for the Taiwan AI Action Plan 2.0, mandates an Executive Yuan National AI Strategy Committee, and provides authority for sector-specific implementing regulations by FSC, NCC, MOHW, and MOTC across finance, telecoms, medical, and autonomous-vehicle AI within a two-year window. As the first national AI governance statute in the Greater China region and the third globally after the EU AI Act and South Korea's AI Basic Act, it frames regulatory expectations for the companies at the heart of the global AI hardware supply chain — TSMC, NVIDIA ODM partners, and advanced-packaging incumbents — that are headquartered or operate substantially in Taiwan.
On 22 December 2025 the FCC's Public Safety and Homeland Security Bureau released Public Notice DA-25-1086, adding to the Covered List (under section 1709 of the FY2025 NDAA) all unmanned aircraft systems (UAS) and UAS critical components produced in a foreign country, plus communications and video-surveillance equipment/services produced by DJI Technologies and Autel Robotics (and their subsidiaries, affiliates, and licensing/JV partners). The designation is comprehensive by scope — every foreign-made drone from consumer quadcopters to large uncrewed systems, with no size/performance carve-out — and blocks the FCC from granting any new equipment authorization to covered UAS/components going forward. Previously authorized models already in the US market are not revoked. A follow-on Public Notice (DA-26-22, 7 January 2026) narrowed the scope with a temporary exemption (see amendments).
The Overseas Investment (National Interest Test and Other Matters) Amendment Act 2025 (No 81 of 2025) is the largest rewrite of New Zealand's Overseas Investment Act 2005 since the 2018 residential-land amendment. The Bill (Government Bill 171) was introduced by the Minister of Finance in June 2025, passed all three readings in the House of Representatives, received Royal Assent on 19 December 2025, and was brought into force on 6 March 2026 by the Overseas Investment (National Interest Test and Other Matters) Amendment Act 2025 Commencement Order 2026 (SL 2026/2). The Act replaces the OIA's residual "investor test" discretion with a single statutory national-interest test applied to all "sensitive asset" transactions, introduces a new s 29B repeat-investor mechanism (Treasury does not re-litigate investor risk factors on subsequent applications outside strategically important businesses), creates new military / dual-use technology call-in transactions and critical-direct-supplier call-in transactions (amended s 85), and adds a no-change-of-control transaction category. Administered by The Treasury (policy lead) and Toitū Te Whenua LINZ (operations / case handling), with consent decisions issued by the responsible Ministers.
Vietnam's National Assembly passed Law on Cybersecurity No. 116/2025/QH15 on 10 December 2025 (434 of 443 deputies in favour), effective 1 July 2026. The law supersedes both the 2018 Cybersecurity Law (Law 24/2018/QH14) and the 2015 Law on Cyber Information Security, consolidating cybersecurity, cyber-information-security, and network-information-security into a unified Ministry of Public Security-led framework. It retains data-localization obligations for foreign digital-service providers handling personal data, user-generated content, and relationship graphs of Vietnamese users (minimum 24-month retention), introduces 6-hour urgent / 24-hour standard content take-down windows on MPS request, expressly prohibits AI/deepfake forgery of images, voices, and videos for illegal purposes, and mandates child-safety platform measures.
President Trump signed Executive Order "Saving TikTok While Protecting National Security" on September 25, 2025, certifying a restructuring plan as a "qualified divestiture" under the 2024 PAFACA law and directing the Attorney General not to enforce the Act for 120 days while the transaction closes. The plan creates TikTok USDS Joint Venture LLC, valued at roughly $14 billion, with a new US-investor consortium (Oracle, Silver Lake and MGX at 15% each, plus other investors, totaling 50%), affiliates of existing ByteDance investors holding 30.1%, and ByteDance itself retaining 19.9%. Oracle will run US data storage and algorithm retraining/oversight; the deal closed January 22, 2026.
Italy enacted Legge 23 settembre 2025, n. 132 — "Disposizioni e deleghe al Governo in materia di intelligenza artificiale" — published in Gazzetta Ufficiale Serie Generale n. 223 of 25 September 2025 (atto 25G00143) and entered into force on 10 October 2025. The statute makes Italy the first EU member state to enact a comprehensive national AI law complementing Regulation (EU) 2024/1689 (EU AI Act), designating AgID (Agency for Digital Italy) and ACN (National Cybersecurity Agency) as national oversight authorities under Presidency-of-the-Council-of-Ministers coordination. It sets sectoral rules for healthcare, labour, intellectual professions, public administration and the judiciary; authorises up to €1 billion in state-backed venture capital (via CDP Venture Capital) for AI, cybersecurity and telecoms; creates criminal penalties of up to five years' imprisonment for harmful deepfakes; mandates parental consent for under-14 users; and delegates secondary legislation to the Government across multiple domains.
Act L of 2025 (2025. évi L. törvény) is the Hungarian National Assembly statute that elevates a set of war-emergency government decrees — including the foreign-investment screening regime previously embedded in Government Decree 561/2022 — to permanent statutory level. Promulgated in Magyar Közlöny and entered into force on 19 August 2025, the Act preserves Hungary's "Second Regime" of FDI screening operating in parallel with the General Regime (which implements EU Reg 2019/452 since 2019). The Second Regime applies to a broad set of strategic sectors — energy, transport, communications, telecoms, pharmaceuticals, food processing, defence, financial services and healthcare — and requires approval from the Minister of National Economy for qualifying acquisitions (direct or indirect majority, ≥5% interest, ≥3% in listed companies, or ownership/operation of strategic infrastructure) where transaction value reaches HUF 350 million (~EUR 890,000). Notification is due within 10 days of signing; the MoE originally had 30 business days (extendable +15 calendar days). The Act also entrenches the Hungarian state right of first refusal on photovoltaic generation companies (NACE 35.11'08, excluding sub-50 kVA household installations), exercised through MNV Zrt. The Special Regime is structurally distinct from the General Regime and represents Hungary's peer to the German AWG §§55-62, French Décret 2014-479, Dutch Wet Vifo, and Italian Golden Power. Amended by Act XCIII of 2025 (in force 17 December 2025), which extended the MoE screening deadline to 45 business days and excluded bank-financing security arrangements from notification.
On 2025-07-08 President Trump issued a Section 721 (Defense Production Act) order retroactively prohibiting Hong Kong-based Suirui International Co., Ltd.'s 2020 acquisition of Jupiter Systems, LLC, a US video-wall and audio-visual technology maker, from Foxconn. CFIUS found the transaction posed a national security risk because a Chinese military company holds an indirect interest in Suirui Group and can appoint one of its directors, creating a risk that Jupiter's products — used in military and critical- infrastructure environments — could be compromised. The order requires Suirui to fully divest all interests and rights in Jupiter within 120 days of the order (extendable at CFIUS's discretion) and bars Jupiter from holding interests in Suirui-linked Asian subsidiaries formed after the 2020 deal.
On 21 April 2025, President Shavkat Mirziyoyev signed Presidential Resolution No. PP-145 "On the Privatization of Large Enterprises with State Participation on International Markets," establishing the 2025–2028 roadmap for selling minority equity stakes (10–25%) in 12 major state-owned enterprises via IPO/SPO on international and domestic exchanges, and full/near-full stakes in 29 further enterprises through competitive public tenders. The resolution introduced a three-tier asset-segmentation framework — large SOEs (IPO/SPO with international advisor mandates), medium SOEs (domestic stock-exchange sale), and small assets/real estate (e-platform sale) — and mandated engagement of international investment banks and a State Privatization Commission to oversee implementation. It was issued the same day as the sister Presidential Decree UP-70 "On the Privatization Program for 2025," which approved a 2025 annual program targeting 30 trillion UZS (~USD 2.4 bn) in state-asset disposals across 115 companies, 659 real-estate properties, and 6,100 hectares of land.
Japan's Cabinet approved an amendment to the Cabinet Order on Inward Direct Investment under the Foreign Exchange and Foreign Trade Act (FEFTA) on 1 April 2025; the order was promulgated 4 April 2025 and entered into force 19 May 2025. The amendment introduces two new investor categories — Type-A (investors legally or contractually obligated to share information with foreign governments) and Type-B (investors effectively in a comparable position without formal legal obligation) — and eliminates or narrows exemptions from mandatory prior-notification screening for both categories. The primary driver is concern over minority-stake acquisitions by Chinese investors in Japanese listed companies operating in sensitive sectors including cloud computing, telecommunications infrastructure, semiconductor equipment, and advanced electronics. The reform is structurally distinct from the outbound FEFTA catch-all controls overhaul (2025-10-09) and from the Economic Security Promotion Act (2022-05-18); it is the inbound FDI-screening complement to that framework.
On 24 February 2025 President Prabowo Subianto launched Badan Pengelola Investasi Daya Anagata Nusantara (Danantara), Indonesia's new state investment-management agency, consolidating around USD 900bn–1tn of Indonesian state-owned-enterprise assets — including Pertamina, PLN, Bank Mandiri, BRI, BNI, Telkom, MIND ID, Antam and Inalum — into a single super-holding modelled on Singapore's Temasek. Danantara was created by the Third Amendment to the BUMN Law (Law No. 1 of 2025, enacted 24 February 2025) and Government Regulation No. 10 of 2025 on its organisation and governance, with board appointments formalised by Presidential Regulation No. 30 of 2025. The agency reports directly to the President, bypassing the Ministry of State-Owned Enterprises, and is mandated to deploy SOE balance-sheet capacity into Prabowo's 8% growth target via co-investment in mineral downstreaming, refinery and EV-battery build-out, food security, and semiconductor / data-centre infrastructure.
Japan's National Diet enacted the Cyber Response Capability Enhancement Act (重要電子計算機に対する不正な行為による被害の防止に関する法律, Law No. 42 of 2025) on 16 May 2025, together with companion arrangement legislation. Commonly known as the Active Cyber Defense (ACD) Law, the statute authorises (i) government monitoring of foreign-origin internet traffic transiting designated Japanese communication infrastructure for national-security threat indicators, (ii) pre-emptive access and neutralisation operations against attacker infrastructure abroad by the National Police Agency and the Self-Defense Forces under unified command, and (iii) mandatory cyber-incident reporting and government cooperation duties on critical-infrastructure operators. Implementation is phased through November 2027, with the NISC reorganised into the National Cybersecurity Office (NCO) under the Cabinet Secretariat from July 2025.
The Bureau of Industry and Security (BIS) amended the Export Administration Regulations (EAR) by adding 13 entities under 13 entries to the Entity List, listed under the destinations of Burma (1), China (11), and Pakistan (1). The PRC additions concentrate on the optics/photonics, RF/microwave, and military-civil-fusion research-institute layer of China's military-modernization stack — including CAS Changchun Institute of Optics, Fine Mechanics and Physics (CIOMP), Shanghai Institute of Optics and Fine Mechanics (SIOM), Peng Cheng Laboratory, Ji Hua Laboratory, and the Yaguang/Chengdu RML defense-electronics cluster — with explicit references to support for hypersonic-weapons development. The Burma entity is Telecom International Myanmar (Mytel), added for providing surveillance services and financial support to the post-coup military regime; the Pakistan entity (Emerging Future Solutions Pvt Ltd) was added for contributions to Pakistan's ballistic-missile programme. All 13 entries carry a license requirement for all items subject to the EAR with a presumption-of-denial review policy and no license exceptions. The rule was effective on publication, January 6, 2025, with a savings clause through February 5, 2025 for goods already en route.
On 22 December 2024 the Politburo of the Communist Party of Vietnam, under General Secretary Tô Lâm, issued Resolution 57-NQ/TW designating science, technology, innovation, and national digital transformation as Vietnam's "top strategic breakthrough" through 2030 with vision to 2045. The resolution targets ≥50% digital-economy share of GDP, top-30 global ranking in innovation and digital transformation, and at least 10 globally-competitive Vietnamese digital-technology enterprises by 2030. It identifies data, AI, blockchain, and IoT as priority bottlenecks and operates as the parent/umbrella authority under which all subsequent Government, National Assembly, Prime-Ministerial and Ministerial tech-industrial instruments are formulated. Operational implementation runs through Government Resolution 03/NQ-CP of 9 January 2025 (action programme).
Cabinet Resolution No. 97 of 2024 is the implementing regulation of UAE Federal Decree-Law No. 43 of 2021 on Commodities Subject to Non-Proliferation. It operationalises the UAE's horizontal dual-use export-control regime, empowering the Executive Office for Control & Non-Proliferation (EOCN) to designate prohibited and restricted goods on the National Control List and to issue export/transit/re-export permits within 20 working days. The Control List covers nuclear materials, chemicals and precursors, electronics, telecommunications, sensors and lasers, navigation systems, avionics, marine and aerospace equipment, propulsion systems, and "national controlled commodities" (armoured vehicles, autonomous equipment). This is the regulatory architecture under which post-G42 advanced AI-chip outbound flows from the UAE are licensed.
The Protecting Americans from Foreign Adversary Controlled Applications Act (PAFACA), enacted as Division H of P.L. 118-50 (21st Century Peace through Strength Act), prohibits app stores and internet hosting services from distributing, maintaining, or updating "foreign adversary controlled applications" — defined explicitly to include ByteDance Ltd and its subsidiaries (TikTok). ByteDance was given 270 days from enactment (until January 19, 2025) to execute a "qualified divestiture" — selling TikTok to an owner with no operational relationship with a foreign adversary — or face a nationwide distribution ban. The Supreme Court unanimously upheld the law's constitutionality in TikTok, Inc. v. Garland (January 17, 2025), rejecting First Amendment challenges and affirming the national-security rationale grounded in data-collection concerns.
The Significant Investments Review Act 2024 (Act No. 1 of 2024) is Singapore's first horizontal, cross-sector statutory FDI screening regime. The Bill was passed by Parliament on 9 January 2024, assented to by the President on 6 February 2024 and gazetted on 14 February 2024; the Act commenced on 28 March 2024 under the SIRA 2024 (Commencement) Notification (S 228/2024), together with the Significant Investments Review Regulations 2024 (S 229/2024). The Act creates an "ownership-and-control" layer over a limited number of "designated entities" the Minister for Trade and Industry has identified as critical to Singapore's national-security interests, plus an "any entity" call-in power exercisable against firms that have acted against Singapore's national-security interests, regardless of whether they are designated. Acquisitions of ≥5% require post-closing notification within 7 days; acquisitions of ≥12% / ≥25% / ≥50% and cessations of ≥50% / ≥75% controller status require prior ministerial approval. Administered by the Office of Significant Investments Review (OSIR) within MTI. SIRA is the Singaporean structural peer of US CFIUS, EU Regulation 2019/452, the German AWG §§55-62, the French Décret 2014-479, the UK NSI Act 2021, the Netherlands Wet Vifo, and the Canada ICA national-security review.
Signed by President Javier Milei and the entire cabinet on 20 December 2023 and published in the Boletín Oficial extraordinario on 21 December 2023, Decreto de Necesidad y Urgencia 70/2023 declares a public emergency across economic, financial, fiscal, administrative, pension, tariff, sanitary, and social matters until 31 December 2025 (Article 1) and enacts 366 articles across 16 titles that fundamentally restructure Argentina's regulatory framework. The DNU repeals or amends dozens of statutes to deregulate foreign trade (repealing the Compre Nacional buy-preference law Ley 18.875 and the price-control framework Ley 27.345), opens privatisation of state enterprises (Aerolíneas Argentinas, ENARSA, Banco Nación, Correo Argentino, Trenes Argentinos), dismantles the Ley de Abastecimiento price-control regime, liberalises civil aviation cabotage to foreign carriers, deregulates hydrocarbons export and mining permitting, and replaces the severance-pay regime with a capitalisation-fund system. It is the foundational enabling framework for all subsequent Milei-administration deregulatory instruments filed on the IPTM register, including RIGI (Law 27.742), Decreto 38/2025, Decreto 449/2025, and Decreto 563/2025.
Lov 2023-06-20 nr. 77 (Lov om endringer i sikkerhetsloven — eierskapskontroll og lovens virkeområde), adopted by the Storting on 9 June 2023, signed 20 June 2023, in force 1 July 2023, is Norway's first substantive overhaul of Chapter 10 (Eierskapskontroll / ownership control) of the 2018 Security Act (Sikkerhetsloven). The amendment widens the scope of undertakings that can be brought under ownership control beyond entities directly linked to a "grunnleggende nasjonal funksjon" (fundamental national function) to include businesses of vital importance to national-security interests and businesses of significant importance to fundamental national functions, lowers and adds notification thresholds, and equips the King in Council with enhanced powers to block, condition, or unwind qualifying acquisitions. The reform converts a narrow security-classified regime into a broad horizontal FDI-screening architecture for Norway, the host of the world's largest sovereign wealth fund and a NATO frontline state.
The Bureau of Industry and Security (BIS) added 76 Russian entities to the Entity List effective February 24, 2023, spanning three rationale categories: (1) biometric surveillance technology enabling Russian filtration operations in occupied Ukraine; (2) illicit acquisition of U.S.-origin controlled items; and (3) the Russian military-industrial complex encompassing missiles, aviation, shipbuilding, semiconductors, telecom, and defense electronics. All 76 entities are subject to a license requirement for all EAR-subject items with a presumption of denial; 66 entities receive footnote-3 designation as Russian military end-users, subjecting them to the Russia/Belarus Military End-User Foreign Direct Product Rule under §734.9(g). Four existing Entity List entries were simultaneously revised with additional aliases and tightened to a policy of denial. Notable designations include KAMAZ, the Skolkovo Foundation, Skoltech, Ilyushin Aviation Complex, and the State Missile Center Named After Akademika V.P. Makeyev.
Government Decree 53/2022/ND-CP, signed 15 August 2022 and effective 1 October 2022, implements Article 26 of Vietnam's 2018 Law on Cybersecurity. It mandates in-country storage of three categories of data — personal data of users in Vietnam, user-generated data, and user-relationship data — for both domestic and foreign cyberspace- service providers, with a minimum 24-month retention period. Foreign enterprises providing telecoms, data storage, domain names, e-commerce, online payments, social networks, online video games, or messaging services to users in Vietnam must establish a Vietnamese branch or representative office within 12 months of a Minister of Public Security written request. The decree closes a four-year implementation gap on the 2018 Cybersecurity Law and is the principal Vietnamese digital-trade barrier alongside Decree 13/2023/ND-CP (Personal Data Protection).
The Wet veiligheidstoets investeringen, fusies en overnames ("Vifo Act") is the Netherlands' cross-sector statutory FDI screening regime. Adopted by the States-General on 18 May 2022 (Stb. 2022, 215) and entered into force on 1 June 2023 together with two implementing decrees (Stb. 2023, 173 — main implementing decree; Stb. 2023, 172 — decree defining the scope of "sensitive technology"), the Act establishes mandatory pre-closing notification and a security review by the Bureau Toetsing Investeringen (BTI, part of the Ministry of Economic Affairs and Climate) for transactions affecting (i) "vital providers" in critical infrastructure sectors — energy, transport, telecoms, port operators, banking infrastructure — and (ii) Dutch undertakings active in "sensitive technology", defined to include EU Reg 2021/821 Annex I dual-use items, military goods, and additional national-security technologies. The regime applies retrospectively to transactions completed after 8 September 2020. It is the foundational instrument under which the Dutch national export-control measures on ASML DUV immersion lithography (filed: 2023-06-30 and 2024-09-07) operate, and the Dutch peer of US CFIUS, EU Regulation 2019/452, the German AWG §§55-62, the French Décret 2014-479 / R. 151-1 et seq., and the UK NSI Act 2021.
Canada amended the Special Economic Measures (Russia) Regulations via SOR/2022-067, registered and in force 24 March 2022, establishing a new "Restricted Goods and Technologies List" and prohibiting any person in Canada, and any Canadian outside Canada, from exporting, selling, supplying or shipping any listed good or technology to Russia or to any person in Russia. The list is maintained and published separately by Global Affairs Canada and covers items with dual civilian/military applications across electronics, computers, telecommunications, sensors and lasers, navigation and avionics, marine, aerospace and transportation equipment.
On 24 February 2022, hours after Russia's invasion of Ukraine began, the UK Foreign Secretary announced a full asset freeze on VTB, Russia's second-largest bank (£154bn in assets, 95,000 employees), alongside a freeze on all Russian bank assets in the UK and a ban on Russian companies raising finance on UK markets. The package designated more than 100 companies and individuals -- including five major defence firms (Rostec, Uralvagonzavod, Tactical Missile Corporation, United Aircraft Corporation, United Shipbuilding Corporation) and Putin-inner-circle figures such as Kirill Shamalov -- for asset freezes and travel bans. Aeroflot was banned from UK airspace and new export controls were imposed on electronics, telecommunications and aerospace goods to Russia.
Effective 24 February 2022 — the date of Russia's full-scale invasion of Ukraine — the US Bureau of Industry and Security (BIS) published an interim final rule (87 FR 12226, FR Doc 2022-04300) adding sweeping new export license requirements under a new § 746.8 of the Export Administration Regulations (EAR). The rule requires a licence for any item in CCL Categories 3–9 (electronics, computers, telecommunications, sensors, lasers, navigation/avionics, marine, aerospace, propulsion) exported, reexported, or transferred to Russia, with a review policy of denial. Two new Russia-specific Foreign Direct Product (FDP) rules extend US jurisdiction to foreign-manufactured goods: the Russia FDP Rule (§ 734.9(f)) covers all foreign-made items using US technology/equipment destined for Russia, and the Russia-MEU FDP Rule (§ 734.9(g)) covers items destined to 47 designated military-end-user (MEU) entities with no licence exceptions available. All three restrictions carry a presumption of denial, making this the most sweeping peacetime expansion of the EAR since its modern codification.
The Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法 — PIPL) was adopted at the 30th meeting of the 13th NPC Standing Committee on 20 August 2021 and entered into force on 1 November 2021, constituting the third and final pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Data Security Law (2021). The PIPL is China's comprehensive personal-information statute establishing consent-based and necessity-based legal bases for PI processing, a tiered cross-border personal-data transfer regime (CAC security assessment / PI protection certification / Standard Contractual Clauses), extraterritorial application (Art. 3) to non-Chinese controllers offering services to or analysing the behaviour of PRC residents, and a heightened protection regime for sensitive personal information and data of minors under 14. It mandates data-protection impact assessments, personal-information-protection-officer obligations at designated handlers, breach notification, and a full suite of data-subject rights including access, rectification, deletion, portability, objection, and automated- decision-making opt-out. Article 53 requires overseas controllers to establish a domestic representative or designated entity in China, providing a domestic enforcement counterparty.
The Data Security Law of the People's Republic of China (中华人民共和国数据安全法) was adopted at the 29th meeting of the 13th NPC Standing Committee on 10 June 2021 and entered into force on 1 September 2021, constituting the second pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Personal Information Protection Law (2021). The DSL establishes a tiered data-classification regime — "important data" and "national core data" — with escalating security obligations including risk assessment, risk monitoring, breach reporting, and classified-protection requirements for data handlers. It introduces a data-export security review for "important data" generated or collected within China, the statutory parent authority operationalised by the 2024 CAC Cross-Border Data Flow Provisions, and enacts a §36 blocking statute prohibiting Chinese organisations and individuals from transferring data stored in China to foreign judicial or law-enforcement authorities without prior PRC government approval.
Regulation (EU) 2021/821, adopted 20 May 2021 and applied from 9 September 2021, establishes the Union regime for controlling exports, brokering, technical assistance, transit, and transfer of dual-use items, repealing Regulation (EC) No 428/2009. Annex I lists controlled items implementing internationally agreed dual-use controls under the Wassenaar Arrangement, MTCR, Australia Group, NSG, and Chemical Weapons Convention. The regulation introduces a new catch-all control on cyber-surveillance technologies that could facilitate human-rights violations (Art. 5 and Annex IV), and strengthens cooperation between Member States and the European Commission, placing specific obligations on exporters. It serves as the statutory anchor for all EU export licences, every multilateral-regime transposition into EU law, and coordination mechanisms with US BIS, UK ECJU, JP METI, and KR MOTIE export-control regimes.
The Bureau of Industry and Security (BIS) issued an interim final rule on January 15, 2021 substantially expanding the Export Administration Regulations (EAR) Part 744 end-use and end-user control framework to cover military-intelligence entities in China, Cuba, Iran, North Korea, Russia, Syria, and Venezuela. The rule created a new license requirement for exports of ANY EAR-subject item to named military-intelligence end-users — including EAR99-classified items — and separately imposed restrictions on U.S. persons worldwide providing "support" to military-intelligence end-uses or end-users without a BIS licence. It also broadened chemical and biological weapons controls from "will directly assist" to "will support," expanding the reach of §744.4 and §744.3 on WMD-delivery systems. A technical correction published March 17, 2021 (FR Doc 2021-05623) fixed a drafting error in Instruction 9 that would have inadvertently deleted §744.3(a)(3)(i)-(ii), the rocket systems and UAV provisions.
MOFCOM Order No. 4 of 2020, issued and effective 19 September 2020, establishes the Unreliable Entity List (UEL / 不可靠实体清单) regime — China's primary countermeasure framework for designating foreign companies, organisations, and individuals that are deemed to endanger Chinese national sovereignty, security, or development interests, or that apply discriminatory measures against Chinese entities in violation of normal market principles. The UEL inter-ministerial Working Mechanism, administered through MOFCOM, may impose restrictions or prohibitions on the designated entity's China-related import/export activities, investment in China, and entry or stay of senior personnel in China, as well as fines. Promulgated under the Foreign Trade Law of the PRC and the National Security Law of the PRC, the Provisions serve as the statutory parent for every UEL designation announcement since 2023, and operate as the structural peer of the US BIS Entity List / OFAC SDN architecture and the simultaneously promulgated Anti-Foreign Sanctions Law framework.
Effective 17 August 2020 (published in the Federal Register 20 August 2020, Vol. 85 No. 162, FR Doc 2020-18213), BIS implemented three simultaneous measures targeting Huawei's global supply chain. First, 38 non-U.S. affiliates of Huawei Technologies Co., Ltd. were added to the Entity List with the most restrictive license review policy (presumption of denial) and designated under footnote 1, extending the Huawei-specific Foreign-Produced Direct Product Rule (FDPR) to their operations. Second, the Temporary General License (TGL), which since May 2019 had authorized limited ongoing transactions with Huawei (network maintenance, software updates, standards participation), was allowed to expire on 13 August 2020 and replaced with a narrower authorization. Third, BIS expanded the scope of the Huawei FDPR (General Prohibition Three) to cover foreign-produced items when a footnote 1 entity is a party to any transaction or when the item will be used in the production or development of products for any footnote 1 entity, closing the design-house loophole that had allowed TSMC to supply HiSilicon/Kirin chips as long as Huawei was not the direct importer.
The Investitionskontrollgesetz (InvKG, "Investment Control Act") is Austria's horizontal, statutory FDI screening regime. Published as Article 1 of the Federal Law BGBl. I Nr. 87/2020 on 24 July 2020 and entering into force on 25 July 2020, the Act replaced the previous narrow §§25a–25e Außenwirtschaftsgesetz 2011 (Foreign Trade Act) regime — under which fewer than 10 permits were issued from 2013 to mid-2020 — and transposes EU Regulation 2019/452 establishing a framework for the screening of foreign direct investments into the Union. The InvKG introduces mandatory ex-ante notification and approval of non-EU / non-EEA / non-Swiss acquisitions where the acquirer crosses any of the 10% / 25% / 50% voting-rights thresholds in an Austrian target operating in the critical sectors listed in Annex Part 1 (especially sensitive: defence, energy / water / telecoms critical infrastructure, dual-use technology, cybersecurity, AI, quantum technology, robotics, semiconductors, biotech, health, vaccines) and 25% / 50% in the sectors listed in Annex Part 2 (broader, including media, food-security, electronic communications infrastructure, financial infrastructure). Administered by the Bundesministerium für Arbeit und Wirtschaft (BMAW), with case decisions taken in coordination with the Komitee für Investitionskontrolle (inter-ministerial Investment Control Committee) and, where the case is escalated to the EU cooperation mechanism, the Commission and EU peer Member States. The InvKG is Austria's functional peer of US CFIUS / FIRRMA, UK NSI Act 2021, Germany AWG §§55–62, France Décret 2014-479 / R. 151-1 et seq., Italy Golden Power Decree, Netherlands Wet Vifo, Denmark investeringsscreeningsloven, and Belgium ISC. Sunset clause: originally limited to 30 June 2022 under §17(2) InvKG; permanently extended by BGBl. I Nr. 80/2022 of 14 July 2022.
The Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法) was adopted at the 24th meeting of the 12th NPC Standing Committee on 7 November 2016 and entered into force on 1 June 2017, establishing the foundational legal framework for network security governance across all sectors. The law creates the Critical Information Infrastructure Operator (CIIO) designation and protection regime administered by the Cyberspace Administration of China (CAC), mandates data localisation for personal information and important data collected or generated by CIIOs in China, and establishes cross-border data-transfer security assessment requirements under Article 37 — the provision later operationalised by DSL 2021, PIPL 2021, and the 2024 CAC Cross-Border Data Flow Provisions. The CSL introduced multi-level protection scheme (等级保护制度 / MLPS) obligations for all network operators and network-product/service security-review procedures, under which CAC triggered the cybersecurity review of Didi Global in 2021 and the exclusion of Micron's products from Chinese critical-infrastructure projects in 2023.