Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
The Republic of Korea's National Assembly passed the Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trustworthiness ("AI Basic Act") in plenary session on 26 December 2024, consolidating 19 separate AI bills tabled in the 22nd National Assembly. The statute was promulgated on 21 January 2025 and takes effect on 22 January 2026 after a one-year preparation period. Korea becomes the second jurisdiction worldwide — after the EU AI Act — to enact a comprehensive horizontal AI law, and the first in the Asia-Pacific. The Act establishes a risk-tiered regime targeting "high-impact" AI in healthcare, energy, public services, employment decisions, and generative-AI labelling, with extraterritorial reach over foreign providers whose systems affect the Korean market or users (mandatory local representative). It creates an AI Safety Institute, a national AI policy "control tower," and R&D / standardisation programmes under MSIT. Penalties are modest by international comparison — fines up to KRW 30 million plus a one-year grace period before full enforcement.
Regulation (EU) 2025/38 of the European Parliament and of the Council of 19 December 2024 lays down measures to strengthen solidarity and capacities in the Union to detect, prepare for, and respond to cyber threats and incidents, and amends Regulation (EU) 2021/694 (Digital Europe Programme). Published in the Official Journal on 15 January 2025; entered into force on 4 February 2025 (20 days after OJ publication). The regulation establishes (i) a European Cybersecurity Alert System composed of national and cross-border Security Operations Centre (SOC) hubs interconnected EU-wide, (ii) a Cybersecurity Emergency Mechanism funded through the Digital Europe Programme, (iii) an EU Cybersecurity Reserve of trusted private-sector incident-response providers, and (iv) an ENISA-led post-incident review mechanism for significant or large-scale cybersecurity incidents. It complements the Cyber Resilience Act (Reg 2024/2847) and the NIS2 Directive as the third leg of the EU horizontal-cybersecurity stack.
The National Assembly of Vietnam passed the Law on Data (Luật Dữ liệu), No. 60/2024/QH15, on 30 November 2024; it enters into force on 1 July 2025. The Law is Vietnam's first comprehensive horizontal data-governance statute, extending regulation beyond personal data (already covered by Decree 13/2023/ND-CP) to all digital data — public, private, and sectoral. It introduces statutory categories of "important data" (dữ liệu quan trọng) and "core data" (dữ liệu cốt lõi) tied to national-defence and national-security review for cross-border transfer, and establishes the National Data Centre under the Ministry of Public Security plus a statutory data-broker / data-services licensing framework.
Australia's first standalone cyber-security statute (Act No. 98 of 2024), passed by Parliament on 25 November 2024 and granted Royal Assent on 29 November 2024, with provisions commencing in tranches through 30 May 2025. The Act creates four binding regimes: (i) mandatory security-of-things standards for connected and IoT products supplied in Australia under regulations administered by the Department of Home Affairs; (ii) a mandatory ransomware / cyber-extortion payment disclosure regime requiring reporting business entities with annual turnover above AUD 3 million to notify the Australian Signals Directorate within 72 hours of any ransom payment made by or on behalf of the entity; (iii) a statutory Cyber Incident Review Board to conduct no-blame post-incident reviews of significant cyber incidents; and (iv) a "limited use" protection restricting how information voluntarily shared with the National Cyber Security Coordinator may be used by Commonwealth agencies. The Act implements core initiatives from the 2023-2030 Australian Cyber Security Strategy and affects every firm selling connected devices into Australia or operating above the turnover threshold in Australia.
The European Union's Artificial Intelligence Act, Regulation (EU) 2024/1689, was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. It establishes the world's first horizontal, risk-tiered legal framework for the development, market placement, and use of AI systems — covering prohibited practices, high-risk systems, general-purpose AI models, and minimal-risk applications — with extraterritorial reach over any provider placing an AI system on the EU market or whose output is used in the EU. Penalties reach up to EUR 35 million or 7% of global annual turnover. Application is staged: prohibitions from 2 February 2025, GPAI and governance from 2 August 2025, the bulk of high-risk obligations from 2 August 2026, and product-safety-embedded high-risk systems from 2 August 2027.
The U.S. Treasury's Office of Foreign Assets Control (OFAC) issued a final rule amending 31 CFR § 560.540 of the Iranian Transactions and Sanctions Regulations (ITSR) to incorporate, with amendments, General License (GL) D-2 — originally issued on OFAC's website on September 23, 2022 — which authorizes the export, reexport, and provision of certain services, software, and hardware incident to communications over the internet to persons in Iran. The codification preserves the GL D-2 expansion (cloud-based services; third-country importation of hardware/software previously exported to Iran; ex-Iran installation, repair and replacement services; case-by-case licensing for internet-freedom activities) and updates the § 560.540 List of Services, Software, and Hardware Incident to Communications. Effective June 17, 2024, the List is amended to exclude laptops, tablets, and personal computing devices with an Adjusted Peak Performance (APP) exceeding 1 Weighted TeraFLOP (WT) — narrowing the consumer-electronics authorization to lower-performance devices and aligning the carve-out with broader BIS-style compute thresholds. The rule does not relax primary ITSR prohibitions; it codifies a humanitarian / internet-freedom exception while inserting a narrow high-performance-compute carve-out.
The Indiana Economic Development Corporation approved up to USD 18.3 million in EDGE (Economic Development for a Growing Economy) payroll-based tax credits for Amazon Data Services Inc., tied to Amazon Web Services' USD 11 billion data center campus at the Indiana Enterprise Center in New Carlisle, St. Joseph County. The credit was one component of a larger state incentive package announced by Governor Eric Holcomb on 2024-04-25, which also included up to USD 55 million in Hoosier Business Investment tax credits, up to USD 20 million in redevelopment tax credits, up to USD 5 million in training grants, a USD 7 million road-infrastructure contribution, and a 50-year state sales-tax exemption on data center equipment. IEDC records cite an incentive-agreement effective date of 2023-09-01. The project committed to creating at least 1,000 new jobs.
The Indiana Economic Development Corporation approved up to USD 55 million in Hoosier Business Investment (HBI) tax credits for Amazon Data Services Inc., tied to Amazon Web Services' USD 11 billion data center campus at the Indiana Enterprise Center in New Carlisle, St. Joseph County. This is the largest single instrument in the five-part state incentive package Governor Eric Holcomb announced on 2024-04-25, which also included up to USD 18.3 million in EDGE payroll tax credits, up to USD 20 million in redevelopment tax credits, up to USD 5 million in training grants, a USD 7 million road-infrastructure contribution, and a 50-year state sales-tax exemption on data center equipment. IEDC describes all incentives as performance-based, claimable only once the underlying investment and job-creation commitments are verified. IEDC records cite an incentive-agreement effective date of 2023-09-01.
The Indiana Economic Development Corporation approved up to USD 20 million in redevelopment tax credits for Amazon Data Services Inc., tied to Amazon Web Services' USD 11 billion data center campus at the Indiana Enterprise Center in New Carlisle, St. Joseph County. This is the third of five distinct incentive instruments in the state package Governor Eric Holcomb announced on 2024-04-25, alongside up to USD 18.3 million in EDGE payroll tax credits, up to USD 55 million in Hoosier Business Investment tax credits, up to USD 5 million in training grants, a USD 7 million road-infrastructure contribution, and a 50-year state sales-tax exemption on data center equipment. IEDC records cite an incentive-agreement effective date of 2023-09-01.
Loi n° 2024-449 of 21 May 2024, known as the SREN law (Sécuriser et Réguler l'Espace Numérique), was definitively adopted by the French Parliament on 10 April 2024, validated in part by the Conseil Constitutionnel on 17 May 2024 (Decision n° 2024-866 DC), promulgated by the President on 21 May 2024, and published in the Journal Officiel on 22 May 2024. SREN is France's digital-sovereignty omnibus statute: it transposes parts of the EU Digital Services Act (Regulation 2022/2065), Digital Markets Act (Regulation 2022/1925), and Data Governance Act (Regulation 2022/868) into French law and layers national-level instruments on top — most consequentially a data-localisation hook for sensitive public-sector data tied to the ANSSI SecNumCloud sovereign-cloud certification scheme, an ARCOM-enforced age-verification regime for adult-content sites (with €250k or 2%-of-turnover fines and account-closure powers), an "anti-scam" cybersecurity filter requiring browsers and DNS resolvers to block ANSSI-designated fraudulent domains, a jeux-en-ligne (JONUM) regime for cryptoasset-adjacent gaming, and a coordination framework between CSA, CNIL, ARCOM, and the Autorité de la concurrence. SREN is one of the first EU member-state digital omnibus statutes anchoring national public-sector data-hosting rules to a sovereign-cloud certification scheme.
On April 4, 2024, the Bureau of Industry and Security published an interim final rule (89 FR 23876) providing corrections, clarifications, and targeted revisions to the October 2023 advanced-computing and semiconductor manufacturing equipment rules. The most substantive change splits the former License Exception NAC (Notified Advanced Computing) into two separate exceptions: NAC (retaining the 25-day prior notification requirement) and a new ACA (Advanced Computing Authorized) exception that permits certain shipments without advance notification. The rule also adds ECCN 4A090.b covering computers and assemblies containing advanced ICs, restores national-security controls to several ECCNs, and addresses various technical drafting errors from the October 2023 rules.
The Cyberspace Administration of China (CAC) issued the Provisions on Promoting and Regulating Cross-Border Data Flows (《促进和规范数据跨境流动规定》) on 22 March 2024, effective immediately. The rules substantially raise the thresholds at which CAC security assessment, Standard Contractual Clauses (SCC), or Personal Information Protection Certification are required for outbound data transfers, and create categorical exemptions for contract performance, HR management, intra-group transfers below a volume threshold, and transit data processed in China with no domestic personal information introduced. A Free Trade Zone pilot mechanism allows designated FTZs (Shanghai Lingang, Tianjin, Beijing) to publish their own negative lists defining which data categories still require prior approval, easing conditions for multinationals with operations in those zones.
Three Commission Delegated Regulations (CDR 2024/1772, 1773, 1774) adopted 13 March 2024 and published in the EU Official Journal on 25 June 2024 constitute the first batch of binding Level 2 implementing rules under DORA (Regulation (EU) 2022/2554). CDR 2024/1772 sets ICT incident classification criteria and materiality thresholds for mandatory reporting; CDR 2024/1773 specifies the required content of contractual policies for ICT third-party services supporting critical or important functions; CDR 2024/1774 defines the ICT risk management tools, methods, processes, and policies — including a simplified framework for smaller in-scope entities. All three apply from 17 January 2025 alongside the parent DORA regulation, covering approximately 22,000 EU regulated financial entities.