Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
Decree 353/2025/NĐ-CP is the principal implementing instrument of Vietnam's Law on Digital Technology Industry (Law No. 71/2025/QH15), effective 1 January 2026 — the same date as the parent statute. The decree's five chapters and 36 articles operationalise three pillars: (i) a comprehensive State-support and preferential-incentive framework for products, services, and infrastructure across the semiconductor, AI, cloud, fintech, and e-commerce sectors; (ii) a high-quality-human-resources development framework covering training funds, scholarship schemes, and foreign-expert visa fast-tracks; and (iii) Vietnam's first statutory innovation sandbox, allowing organisations to deploy new digital products and business models under time- and scope-limited regulatory carve-outs where current law has not kept pace with practice.
The Huadu District Government Office in Guangzhou (Guangdong Province) issued "Measures for Promoting High-Quality Development of New Energy and Intelligent Connected Vehicle Industries" (花府办规〔2025〕11号), effective upon issuance on 31 December 2025 for a two-year term. The package covers R&D-platform grants (up to RMB 100m per enterprise), model-promotion subsidies (up to RMB 50m per model), an L4+ autonomous-vehicle fleet-scale bonus (up to RMB 20m per enterprise), core-component investment rebates (1% of qualifying investment ≥RMB 50m, capped at RMB 300m), battery-production scale bonuses (up to RMB 60m for 5GWh+ output), at least RMB 200m for a "vehicle-road-cloud" integrated pilot zone (200+ autonomous vehicles, ~2,000 OBU retrofits), per-enterprise autonomous-fleet-operation subsidies (up to RMB 200m for qualifying passenger/cargo fleets), preferential industrial-land pricing (minimum 70% of benchmark rate), and facility-cost subsidies (up to RMB 150m/year for 3-5 years). It is a sub-provincial, district-level instrument implementing national NEV industrial-policy and the 2025-2026 Automobile Industry Stabilization and Growth Work Plan at the local level.
Taiwan's Legislative Yuan passed the Artificial Intelligence Basic Act (人工智慧基本法) on third reading on 23 December 2025, and President Lai Ching-te promulgated the 20-article statute on 14 January 2026, bringing it into force immediately. The Act designates the National Science and Technology Council (NSTC) as the central AI-policy competent authority and codifies seven governance principles — sustainability and well-being, human autonomy, privacy protection and data governance, cybersecurity and safety, transparency and explainability, fairness and non-discrimination, and accountability — that apply to all public-sector AI procurement and high-risk sectoral applications. The statute establishes a statutory foundation for the Taiwan AI Action Plan 2.0, mandates an Executive Yuan National AI Strategy Committee, and provides authority for sector-specific implementing regulations by FSC, NCC, MOHW, and MOTC across finance, telecoms, medical, and autonomous-vehicle AI within a two-year window. As the first national AI governance statute in the Greater China region and the third globally after the EU AI Act and South Korea's AI Basic Act, it frames regulatory expectations for the companies at the heart of the global AI hardware supply chain — TSMC, NVIDIA ODM partners, and advanced-packaging incumbents — that are headquartered or operate substantially in Taiwan.
On 10 December 2025 the National Assembly of Vietnam adopted Law No. 134/2025/QH15 on Artificial Intelligence (8 chapters, 35 articles), Vietnam's first dedicated AI statutory framework and one of the first comprehensive horizontal AI laws in Southeast Asia. The law establishes a three-tier risk-based regulatory architecture (high / medium / low) for the research, development, provision, deployment, and use of AI systems; defines the rights and obligations of providers, deployers, importers, distributors, and users; and mandates state oversight via the Ministry of Information & Communications and Ministry of Science & Technology. Prohibited acts include systematic deception, manipulation of human perception, generation of fake content endangering national security, exploitation of vulnerable populations, and obstruction of human-supervision mechanisms. The law applies to Vietnamese agencies, organizations, and individuals as well as foreign organizations and individuals involved in AI-related activities in Vietnam, taking effect 1 March 2026 with 12-18 month transition windows for existing systems depending on sector.
Vietnam's National Assembly passed Law on Cybersecurity No. 116/2025/QH15 on 10 December 2025 (434 of 443 deputies in favour), effective 1 July 2026. The law supersedes both the 2018 Cybersecurity Law (Law 24/2018/QH14) and the 2015 Law on Cyber Information Security, consolidating cybersecurity, cyber-information-security, and network-information-security into a unified Ministry of Public Security-led framework. It retains data-localization obligations for foreign digital-service providers handling personal data, user-generated content, and relationship graphs of Vietnamese users (minimum 24-month retention), introduces 6-hour urgent / 24-hour standard content take-down windows on MPS request, expressly prohibits AI/deepfake forgery of images, voices, and videos for illegal purposes, and mandates child-safety platform measures.
On 20 November 2025 the White House and US Department of Commerce / Bureau of Industry and Security (BIS) authorised Abu Dhabi AI holding company G42 to import advanced computing chips — equivalent to approximately 35,000 Nvidia GB300 Blackwell processors — under the UAE-pioneered Regulated Technology Environment (RTE) compliance framework. The RTE is an Emirati-designed technology governance and audit architecture, developed by G42 and approved under BIS guidelines, with binding UAE-side controls to prevent onward diversion to foreign adversary nations. The authorisation accelerates the Stargate UAE project — a 1 GW AI compute cluster being built by G42 for OpenAI in partnership with Oracle, Cisco, NVIDIA, and SoftBank Group — and represents the first concluded major country-level advanced-compute authorisation following the May 2025 rescission of the Biden-era AI Diffusion Rule.
On 19 November 2025, the U.S. Treasury's Office of Foreign Assets Control (OFAC), in a coordinated action with Australia's Department of Foreign Affairs and Trade and the UK's Foreign, Commonwealth and Development Office, designated 5 individuals and 7 companies linked to two Russia-based "bulletproof hosting" (BPH) providers, Media Land and Aeza Group, under Executive Order 13694. Media Land and its subsidiaries (Media Land Technology, Data Center Kirishi, ML Cloud) supplied server infrastructure to ransomware groups including LockBit, BlackSuit and Play. The designations also targeted three companies Aeza Group used to evade its July 2025 OFAC designation and rebrand its infrastructure: Hypercore Ltd. (United Kingdom), Smart Digital Ideas DOO (Serbia), and Datavice MCHJ (Uzbekistan). All designated persons' U.S.-nexus assets are blocked and U.S. persons are prohibited from transacting with them.
On 18 November 2025, the European Supervisory Authorities (EBA, ESMA, and EIOPA) jointly designated 19 Critical ICT Third-Party Providers (CTPPs) under DORA Article 31, with immediate effect — the first-ever exercise of direct EU financial-regulator supervision over hyperscale cloud and infrastructure providers. The designated entities include Amazon Web Services, Microsoft Azure, Google Cloud, Deutsche Telekom, Oracle, SAP, IBM, Bloomberg LP, London Stock Exchange Group (LSEG), Tata Consultancy Services, and Orange, among others. Designation triggers direct oversight by a lead ESA (EBA for banking-critical, ESMA for capital-markets-critical, EIOPA for insurance-critical) via Joint Examination Teams (JETs), with powers to conduct investigations, carry out on-site inspections, and impose fines of up to 1% of average daily worldwide turnover per day for non-compliance.
The EuroHPC Joint Undertaking, via Horizon Europe grant agreement 101253078, is co-funding "AI:AT — the AI Factory Austria" with EUR 14,999,999.45 in EU/EuroHPC funding against a total project cost of EUR 29,999,998.79 (matched roughly 50/50 by Austrian national and consortium co-funding). The grant runs 1 July 2025 to 30 June 2028 and is coordinated by Advanced Computing Austria (ACA) GmbH together with the AIT Austrian Institute of Technology and a consortium of Austrian academic and industry partners. AI:AT builds supercomputing infrastructure and AI services as Austria's national node in the EU's AI Factories network, one implementing grant under the EU AI Continent Action Plan (COM(2025)165, filed 2025-04-09-eu-ai-continent-action-plan).
Thailand's Board of Investment issued Notification No. 9/2568 on 14 November 2025, amending the Activity List Eligible for Investment Promotion by splitting the prior single data-center category into two tiers based on power-usage efficiency: high-efficiency data centers (PUE ≤ 1.3) qualify for an 8-year corporate income tax (CIT) exemption, while other data centers receive a 5-year CIT exemption. A precursor restructure (Notification No. 5/2568, 5 June 2025) first introduced the two-tier category split; Notification 9/2568 added location-differentiated terms based on the Eastern Economic Corridor (EEC). New benefit conditions require applicants to submit a Thailand-benefit plan — training programmes, academic/R&D partnerships, local supply-chain support, or knowledge transfer to Thai nationals — that must be implemented before CIT exemption benefits can be exercised.
India's Ministry of Electronics and Information Technology (MeitY) notified the Digital Personal Data Protection Rules, 2025 via Gazette notification G.S.R. 846(E) on 13 November 2025, operationalising the 2023 DPDP Act. The Rules introduce a "negative list" cross-border personal-data transfer regime under Rule 14, verifiable parental consent, breach-notification windows, and tiered penalties up to INR 250 crore. Implementation is phased: Data Protection Board provisions in force on notification, Consent Manager rules from 13 Nov 2026, and core data-fiduciary / cross-border-transfer obligations from 13 May 2027.
The Australian Renewable Energy Agency (ARENA) announced up to AUD 45 million in funding for Fortescue's Solar Innovation Hub, a 500 MW test bed within Fortescue's 1.5 GW solar PV development pipeline at the Cloudbreak Solar Farm in the Pilbara region of Western Australia. The funding uses a portfolio structure covering up to 10 individual demonstration projects under one agreement, including Built Robotics' automated pile-driving technology and 5B's rapid-deployment Maverick solar system, aimed at cutting installed solar costs and supporting ARENA's Ultra Low-Cost Solar goal of 30% module efficiency at 30 cents/watt installed cost by 2030. Global Trade Alert logged the grant as a trade-distorting subsidy to Fortescue's solar manufacturing and deployment activity.
The European Investment Fund (EIF), part of the EIB Group, invested EUR 20 million (~USD 23.1 million) on 6 November 2025 in TIN Capital's European Cyber Tech Fund V, a growth-equity vehicle backing European cybersecurity scale-ups. EIF's participation is supported under the European Commission's InvestEU programme; alongside Invest-NL and private investors, the fund closed at over EUR 80 million. The EIF frames the investment as strengthening Europe's digital security and autonomy amid incoming EU cybersecurity regulation (NIS2, the Cybersecurity Act, DORA). Global Trade Alert separately logs the transaction as a "red"-flagged state-linked financial investment-support intervention.
The General Office of the Fujian Provincial People's Government issued Min Zheng Ban [2025] No. 30, "Several Measures to Promote the Development of the Artificial Intelligence Industry and Empowerment Applications in Fujian Province," on 2025-11-04. The notice implements the national "AI+" initiative at provincial level via three quantified subsidy tracks: a talent-recruitment supplement of RMB 200,000/year per person for AI engineers registered on a provincial core-engineer roster; a compute subsidy covering up to 50% of annual cloud/compute-service spend (capped at RMB 500,000 per firm) for companies purchasing at least RMB 100,000 of computing services per year; and a one-time capital subsidy of up to 50% of build cost (capped at RMB 5,000,000) for qualifying AI innovation platforms. The measure is in force through 2028-12-31 (per GTA state-act revocation date) and is one of a wave of province- and city-level AI industrial-policy notices issued across China in late 2025.
On 17 October 2025 Türkiye's Ministry of Industry and Technology opened the "HIT-AI" call, a USD 1.6 billion support tranche under the HIT-30 High Technology Investment Programme (see `2024-07-26-turkiye-hit-30-high-technology- investment-programme`), targeting large-scale IT investments delivering AI services, managed/self-service cloud offerings, and AI-hardware buildouts of at least USD 100 million. The call bundles multiple instruments — tax reduction up to 60%, capex grants up to 40% (with an additional up to 20% grant specifically for AI-hardware investment), concessional financing up to 70%, employment support, and market-development support up to 20% — and was announced alongside a parallel USD 1.5 billion "HIT-Data Centre" call, a USD 300 million "HIT-Quantum" call, and a USD 1 billion "HIT-Industrial Robot" call. Minister Mehmet Fatih Kacır framed the combined package as designed to mobilise USD 10 billion in data-centre and AI investment by 2030, lifting national data-centre capacity from 250 MW to 1 GW.
On 17 October 2025 Türkiye's Ministry of Industry and Technology opened the "HIT-Data Centre" call, a USD 1.5 billion support tranche under the HIT-30 High Technology Investment Programme (see `2024-07-26-turkiye-hit-30-high-technology-investment-programme`), targeting data-centre facilities of at least 30 MW IT capacity with at least 50% AI-compatible hardware and a Power Usage Effectiveness (PUE) of 1.4 or lower. The call was announced alongside three parallel HIT-30 sector calls — a USD 1.6 billion "HIT-AI" call (see `2025-10-17-turkiye-hit-ai-cloud-infrastructure-call`), a USD 300 million "HIT-Quantum" call, and a USD 1 billion "HIT-Industrial Robot" call — and offers the same tax, grant, financing, employment, and market-development instrument stack used across the HIT-30 programme. Global Trade Alert logs this single government call as two separate "interventions" (tax/social insurance relief and unspecified state aid) under state act 95013.
On 17 October 2025 Türkiye's Ministry of Industry and Technology opened the "HIT-Industrial Robot" call, a USD 1 billion support tranche under the HIT-30 High Technology Investment Programme (see `2024-07-26-turkiye-hit-30-high-technology-investment-programme`), targeting manufacturers that commit to a minimum annual production capacity of 5,000 industrial robots and localisation of critical components (servo motors, reducers/gearboxes, servo drives), plus supporting R&D-centre buildout. The call was announced alongside three parallel HIT-30 sector calls — a USD 1.6 billion "HIT-AI" call (see `2025-10-17-turkiye-hit-ai-cloud-infrastructure-call`), a USD 1.5 billion "HIT-Data Centre" call (see `2025-10-17-turkiye-hit-data-centre-call`), and a USD 300 million "HIT-Quantum" call — and offers the same tax, grant, financing, employment, and market-development instrument stack used across the HIT-30 programme. Global Trade Alert logs this single government call as two separate "interventions" (state loan and tax/social-insurance relief) under state act 95018.
On 17 October 2025 Türkiye's Ministry of Industry and Technology opened the "HIT-Quantum" call, a USD 300 million support tranche under the HIT-30 High Technology Investment Programme (see `2024-07-26-turkiye-hit-30-high-technology-investment-programme`), aimed at building high-capacity infrastructure for quantum computing services, a scalable quantum hardware/software ecosystem for research centres, universities and the private sector, and skilled-workforce development. The call was announced alongside three parallel HIT-30 sector calls — a USD 1.6 billion "HIT-AI" call (see `2025-10-17-turkiye-hit-ai-cloud-infrastructure-call`), a USD 1.5 billion "HIT-Data Centre" call (see `2025-10-17-turkiye-hit-data-centre-call`), and a USD 1 billion "HIT-Industrial Robot" call (see `2025-10-17-turkiye-hit-industrial-robot-call`). Global Trade Alert logs this single government call as three separate "interventions" (financial grant, state loan, and tax/social-insurance relief) under state act 95017.
On 18 September 2025 Brazil's federal government published Medida Provisória (Provisional Measure) 1318/2025, creating REDATA — the Special Taxation Regime for Datacenter Services — alongside a parallel IT-export regime (REPES). REDATA zeroes federal taxes on servers, storage, networking, cooling and other datacenter capital equipment for qualifying operators from 1 January 2026, conditioned on 100% renewable/zero-carbon energy sourcing, a 2% of investment R&D-in-Brazil commitment, and preferential use of Brazilian- manufactured components. The Finance Ministry projects R$5.2 billion in forgone-tax incentives in 2026 alone, with potential to unlock up to R$2 trillion in private datacenter investment over ten years. REDATA is framed as implementing the National Datacenter Policy (PNDC) under the Nova Indústria Brasil industrial-policy umbrella.
On 18 September 2025, as part of the third phase of France's national AI strategy under the France 2030 programme, the government opened the "Pionniers de l'intelligence artificielle" (Pioneers of AI) call for projects, operated by Bpifrance and the NALU ("Numérique, Algorithmes, Logiciels et Usages") agency program led by Inria. The scheme funds disruptive AI technologies and applications across industrial robotics, healthcare, energy production/distribution and manufacturing through a three-phase funnel: Phase 1 (technical feasibility, EUR 100k-200k over 6-12 months), Phase 2 (demonstrator, EUR 400k-800k over 6-18 months) and Phase 3 (market launch, EUR 3-8M over 1-3 years), with projects re-vetted for technological and economic relevance between phases. Submissions run 11 September 2025 to 9 June 2026 across multiple deadline windows; as of the government's 18 June 2026 update, 51 projects (23 in a first round, 28 in a second) had been selected, including firms such as IMIND (microelectronics), Skipper NDT, Sagacity Health, Lutece Dynamics, HyprView, DeepLife, Phagos and Wintics, alongside multiple Inria-led projects.
On 25 August 2025, Brazil's federal government launched a combined BRL 12 billion (~USD 2.2bn) subsidised credit line to fund the diffusion of Industry 4.0 machinery and equipment across the Brazilian industrial base. BNDES (national development bank) contributes BRL 10 billion nationwide through its "Crédito Indústria 4.0" line; Finep (research-financing agency) adds BRL 2 billion via its "Difusão Tecnológica" line, reserved for companies in the North, Northeast and Center-West regions to narrow regional investment gaps. Financing covers capital goods incorporating robotics, artificial intelligence, cloud computing, sensing, machine-to-machine communication and IoT, at concessional rates of roughly 7.5-8% plus spread; credit approvals began 15 September 2025. The line operates under the Nova Indústria Brasil (NIB) national industrial-policy framework.
Banque des Territoires, acting on behalf of the French State under the France 2030 programme, launched a EUR 500 million fund-of-funds called "Global Tech Coté" on 7 August 2025. The vehicle takes minority stakes (EUR 15 million minimum, capped at 10% of a target fund's subscribed capital) in privately-managed investment funds that in turn back publicly-listed French technology companies with strong growth potential, aiming to build up domestic asset-management capacity alongside the state's stated goal of channelling capital into equities. The selection window for management companies runs until 31 December 2026 or until the EUR 500 million envelope is exhausted, whichever comes first.
Italy's Ministry of Enterprises and Made in Italy (MIMIT) signed a decree ("Disciplina degli interventi di sostegno alla domanda di servizi di cloud computing e cyber security") on 18 July 2025 establishing a EUR 150 million fund, drawn from FSC 2014-2020 resources, to subsidize SME and self-employed purchases of cloud computing and cybersecurity services nationwide. Beneficiaries receive a non-repayable grant covering up to 50% of eligible expenses, capped at EUR 20,000 per beneficiary, conditional on holding a connectivity contract of at least 30 Mbps download speed. Supplier registration (a prerequisite for the voucher's use) was originally set to close 23 April 2026 and was later extended to 27 May 2026; beneficiary application procedures follow once the authorized-supplier list is formed.
The Joint Committee of the European Supervisory Authorities (EBA, EIOPA, ESMA) published the Guide on DORA Oversight Activities (JC 2025 29) on 15 July 2025, the definitive operational description of how the ESAs will supervise Critical ICT Third-Party Providers (CTPPs) designated under DORA Art. 31. The guide establishes the governance of Joint Examination Teams (JETs), the oversight examination lifecycle (planning, risk assessment, binding recommendations, follow-up), penalty processes of up to 1% of average daily worldwide turnover per day of breach (DORA Art. 35(6)), and lead-overseer assignments (EBA for banking, ESMA for capital markets, EIOPA for insurance). It is authoritative ESA interpretive guidance, not legally binding per se, but constitutes the supervisory playbook CTPPs and their dependent financial entities must plan against.
The Beijing Economic-Technological Development Zone (BDA / Yizhuang) Management Committee issued Jingjiguanfa [2025] No. 15, "Several Measures on Promoting Quantum Technology and Industry Development in the Beijing Economic-Technological Development Zone," on 2025-07-14, effective immediately and in force through 2027-12-31. The package spans ten support lines covering the full quantum stack (computing hardware/software, communications, sensing): up to RMB 2,000,000 one-off support for disruptive early-stage R&D projects, R&D-investment matching at 20% of an enterprise's prior-year R&D spend capped at RMB 5,000,000, 1:1 matching up to RMB 30,000,000 for enterprises undertaking state/municipal quantum research tasks, RMB 500,000 per product for new-technology/product certifications, up to RMB 100,000 per flagship application-demonstration project, up to RMB 30,000,000/year (three years max) for quantum-computing cloud platforms and compute centers, up to RMB 5,000,000/year (three years max) for operating industry-ecosystem platforms, rent subsidies up to RMB 1.5/sqm/day (max 2,000 sqm, three years), and talent, financing ("patient capital"/future-industry guidance fund), and international- cooperation support. The zone targets an internationally influential quantum industry cluster by 2027.
On 1 July 2025, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated Aeza Group, a St. Petersburg, Russia-based "bulletproof hosting" (BPH) provider, along with two affiliated companies and four Aeza Group leaders (Arsenii Penzev, Yuri Bozoyan, Vladimir Gast, Igor Knyazev), for supplying server infrastructure that shielded ransomware operators, infostealer groups, and darknet drug marketplaces from law-enforcement takedown. In coordination with the UK's National Crime Agency, OFAC also designated Aeza International Ltd., a UK front company Aeza used to lease IP addresses to cybercriminals. The action was taken under Executive Order 13694 (as amended by E.O. 14144 and E.O. 14306) and builds on OFAC's February 2025 designation of BPH provider ZServers.
Vietnam's government issued Decree No. 160/2025/ND-CP establishing the National Data Development Fund, a non-budget state financial fund capitalised at VND 1 trillion (approx. USD 38.3 million). The fund, administered by the Ministry of Public Security, provides subsidised loans, interest-payment support, and grants — delegated through state-owned commercial and policy banks — to develop and protect data infrastructure and to support AI, big data, cloud computing, blockchain, and IoT projects serving state management and digital-transformation goals, with priority for rural and disadvantaged regions. The decree took effect 1 July 2025.
The National Assembly of Vietnam passed the Personal Data Protection Law (Luật Bảo vệ dữ liệu cá nhân), Law No. 91/2025/QH15, on 26 June 2025; it enters into force on 1 January 2026. The PDPL is Vietnam's first statutory (rather than decree-level) personal-data-protection framework, elevating the prior Decree 13/2023/ND-CP (PDPD) regime into a 5-chapter, 39-article primary statute and adding revenue-based administrative penalties of up to 5% of prior-year annual revenue for cross-border data-transfer violations and up to 10x illegal gains for unlawful data trading. The law is implemented by Decree 356/2025/ND-CP (issued 31 December 2025, effective 1 January 2026) and applies extraterritorially to foreign organisations offering services to or processing the personal data of Vietnam residents.
On 14 June 2025 Vietnam's 15th National Assembly adopted Law No. 71/2025/QH15 on the Digital Technology Industry (DTI Law) at its 9th session. The Law enters into force on 1 January 2026 (with certain provisions phased) and is the world's first standalone primary statute dedicated to the digital technology industry, covering digital-tech production and services, semiconductor manufacturing, artificial-intelligence systems, digital assets (legally recognised as property under the Civil Code), and Concentrated Digital Technology Zones. It codifies sector-specific incentives — multi-year corporate income tax reductions, R&D-cost deductions, preferential public procurement, five-year personal income tax exemption for high-quality digital professionals, five-year visa and work-permit exemptions for foreign experts, and 50% subsidy for SME advanced-technology acquisition — and sets headline targets of 150,000 digital-tech enterprises and USD 74bn digital-economy contribution by 2030/2035 (with USD 43bn / USD 74bn variants in different government summaries).
On 13 May 2025, two days before the AI Diffusion Rule's primary 15 May 2025 compliance date, the Trump administration's BIS announced it would rescind the Biden-era Framework for AI Diffusion (90 FR 4544) and simultaneously issued three guidance documents that re-routed US AI export policy through existing EAR authorities. The package comprises (1) GP10 guidance asserting that all ECCN 3A090 ICs designed by PRC-headquartered firms are presumptively EAR-violative, with Huawei Ascend 910B/910C/910D processors named explicitly — making US- and non-US-person use, transfer, financing, or servicing of those chips anywhere in the world a presumptive General Prohibition 10 violation; (2) a policy statement warning industry that supplying US advanced computing ICs for training or inference of Chinese AI models risks EAR enforcement; and (3) industry guidance on diversion-prevention diligence. BIS stated a formal Federal Register rescission and replacement rule would follow.
On 12 May 2025, Saudi Arabia's Crown Prince and PIF Chairman Mohammed bin Salman launched HUMAIN, a new PIF-owned company mandated to "operate and invest across the artificial intelligence (AI) value chain as a unified operating company" — spanning next-generation data centers, AI/cloud infrastructure, and a multimodal Arabic large language model (ALLAM). PIF's wholly-owned Saudi Company for Artificial Intelligence (SCAI) was folded into HUMAIN at launch. The company is a Vision 2030 vehicle for economic diversification away from oil into a state-controlled AI industrial base, and has since signed multi-billion-dollar infrastructure and chip-supply deals with NVIDIA, AWS, AMD, Cisco, and xAI, and a USD 1.2bn financing package with Saudi's National Infrastructure Fund toward a stated 6.6GW domestic data-center capacity target over the next decade.
On 9 April 2025 the European Commission adopted Communication COM(2025)165, the AI Continent Action Plan, setting out a five-pillar strategy to make the EU a global AI leader. The pillars are (1) computing infrastructure, (2) data for AI, (3) strategic AI innovation and adoption, (4) AI skills and talent, and (5) regulatory simplification. Headline commitments include mobilising approximately €200bn of public+private investment via the InvestAI initiative announced at the AI Action Summit in Paris (11 February 2025), deploying 13 AI Factories (HPC-anchored shared compute facilities) plus regional antennas, building 5 AI Gigafactories powered by >100,000 advanced AI processors with €20bn earmarked from InvestAI, launching the Apply AI Strategy and Data Union Strategy, and proposing a Cloud and AI Development Act with a public consultation closing 4 June 2025. The one-year progress report (9 April 2026) confirmed 19 AI Factories deployed across EU supercomputers with 13 Antennas providing regional access, and €1bn in Apply AI funding calls earmarked.
Japan's Cabinet approved an amendment to the Cabinet Order on Inward Direct Investment under the Foreign Exchange and Foreign Trade Act (FEFTA) on 1 April 2025; the order was promulgated 4 April 2025 and entered into force 19 May 2025. The amendment introduces two new investor categories — Type-A (investors legally or contractually obligated to share information with foreign governments) and Type-B (investors effectively in a comparable position without formal legal obligation) — and eliminates or narrows exemptions from mandatory prior-notification screening for both categories. The primary driver is concern over minority-stake acquisitions by Chinese investors in Japanese listed companies operating in sensitive sectors including cloud computing, telecommunications infrastructure, semiconductor equipment, and advanced electronics. The reform is structurally distinct from the outbound FEFTA catch-all controls overhaul (2025-10-09) and from the Economic Security Promotion Act (2022-05-18); it is the inbound FDI-screening complement to that framework.
The Nigeria Data Protection Commission issued the General Application and Implementation Directive (GAID) 2025 on 20 March 2025, the principal implementing directive of the Nigeria Data Protection Act 2023 (NDPA). The GAID came fully into force on 19 September 2025, replacing the Nigeria Data Protection Regulation (NDPR) 2019 as the operative enforcement instrument. It applies extraterritorially to any data controller or processor established outside Nigeria that processes personal data of Nigerian data subjects, imposes a tripartite cross-border transfer framework (adequacy decisions, Transfer Instruments, and statutory exceptions), mandates Data Protection Impact Assessments for AI and high-risk technologies, and carries a civil-penalty ceiling of 2% of annual gross revenue or NGN 10 million for designated data controllers and processors of major importance (DCPMIs), whichever is greater.
Indonesia's Ministry of Communications and Digital Affairs (Kemkomdigi) promulgated Permenkomdigi No. 5/2025 on 25 March 2025 as the implementing regulation under Government Regulation PP 71/2019 governing Public-Scope Electronic System Operators (PSE Lingkup Publik), defined as operators running electronic systems for government institutions or critical public services. The regulation mandates registration, data classification by risk level (low/medium/ high/strategic) with corresponding domestic storage and processing requirements, content- moderation governance, and access-blocking mechanisms for prohibited electronic information. All public-scope PSEs must achieve compliance by 25 March 2026, with non-compliant operators subject to progressive administrative sanctions under Articles 100-series ranging from written warnings to access disconnection (pemutusan akses) and removal from official registries.
Joint Communication JOIN(2025) 9 final, adopted 21 February 2025, establishes the EU's first cable-infrastructure-specific resilience framework. It introduces a four-pillar Cable Security Toolbox (prevention, detection, response/recovery, deterrence), designates Cable Projects of European Interest (CPEIs) for priority public funding, and allocates €347 million under the Connecting Europe Facility Digital programme for cross-border subsea cable diversification, redundancy, and repair-ship capacity. The plan also formalises EU-NATO Task Force on Resilience of Critical Undersea Infrastructure follow-on workstreams and establishes an attribution and diplomatic-response framework for cable-sabotage incidents, referencing Baltic Sea cable-cutting events from 2023 to 2025.
Japan's National Diet enacted the Cyber Response Capability Enhancement Act (重要電子計算機に対する不正な行為による被害の防止に関する法律, Law No. 42 of 2025) on 16 May 2025, together with companion arrangement legislation. Commonly known as the Active Cyber Defense (ACD) Law, the statute authorises (i) government monitoring of foreign-origin internet traffic transiting designated Japanese communication infrastructure for national-security threat indicators, (ii) pre-emptive access and neutralisation operations against attacker infrastructure abroad by the National Police Agency and the Self-Defense Forces under unified command, and (iii) mandatory cyber-incident reporting and government cooperation duties on critical-infrastructure operators. Implementation is phased through November 2027, with the NISC reorganised into the National Cybersecurity Office (NCO) under the Cabinet Secretariat from July 2025.
South Korea's Ministry of Science and ICT (MSIT) committed in its 2025 Work Plan to establish a National AI Computing Center via public-private partnership (PPP), with an anchor envelope of KRW 2 trillion rising to KRW 4 trillion through 2030. In July 2025 MSIT executed the first major tranche: KRW 1.46 trillion (approx. USD 1.1 billion) to procure approximately 13,000 high-performance GPUs (NVIDIA B200 and H200) distributed across three domestic cloud operators — Naver Cloud, NHN Cloud, and Kakao. This is Korea's first PPP-structured sovereign-AI compute procurement instrument, structurally distinct from the AI Basic Act (horizontal regulatory framework) and the Semiconductor Special Act (fab investment incentives), as it directly addresses the compute- infrastructure supply constraint for AI model training and national AI research.
President Trump signed Executive Order 14179 on 23 January 2025 (published in the Federal Register on 31 January 2025 as 90 FR 8741, doc 2025-02172). The order revokes Biden-era Executive Order 14110 of 30 October 2023 ("Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence") and directs federal agencies to identify and rescind, revise, or suspend any policies, regulations, memoranda, or guidance documents adopted pursuant to the revoked Biden order. It mandates that the Assistant to the President for Science and Technology, the Assistant to the President for National Security Affairs, the Special Advisor for AI and Crypto, and the Assistant to the President for Economic Policy develop an AI Action Plan within 180 days to "sustain and enhance America's global AI dominance." The plan was released on 23 July 2025. EO 14179 reframes US AI industrial-policy posture from safety-first regulation to deregulation, infrastructure investment, and export-competitiveness.
The UK government published the AI Opportunities Action Plan (CP 1241) on 13 January 2025, authored by Matt Clifford CBE (Chair, ARIA), and simultaneously accepted all 50 recommendations via the government response (CP 1242). The plan establishes binding cross-government commitments including a 20× expansion of UK sovereign AI compute capacity by 2030, designation of AI Growth Zones (Culham, Oxfordshire named first), a National Data Library, and energy-grid prioritisation for AI datacentres. It positions AI compute as critical national infrastructure and represents the most comprehensive national AI industrial-policy roadmap published in the UK to date.
The Bureau of Industry and Security signed an Interim Final Rule on 13 January 2025 (90 FR 4544, published 15 January 2025) introducing the first horizontal export-control regime for advanced AI compute and closed-weight model weights. It revised ECCN 3A090 advanced-IC thresholds, created a new ECCN 4E091 covering closed-weight model weights trained on more than 10^26 operations, and bucketed every destination worldwide into a three-tier country group: Tier 1 (~18 close allies, license-free flows), Tier 2 (the rest of the world, per-country compute caps with National VEU and Universal VEU pathways), Tier 3 (US arms-embargoed destinations including China and Russia under comprehensive denial). It added license exceptions AIA, ACM, and LPP and set staggered compliance dates of 15 May 2025 (general) and 15 January 2026 (data-center / model-weight provisions). The Trump administration's BIS rescinded the rule on 13 May 2025 — two days before the primary compliance date — but it was on the books for four months and shaped allied compliance build-out and the architecture of subsequent US AI export controls.
Bolivia's Decreto Supremo 5309, signed by President Luis Arce on 8 January 2025, mandates that all public-sector entities migrate their information systems to Free Software and Open Standards by 12 January 2030. The decree includes a data-localization provision barring storage of non-public state data on servers outside Bolivian territory; government cloud workloads must run either on public-entity infrastructure or on state-operated cloud services within the country. AGETIC (Bolivia's ICT agency) is responsible for overseeing compliance and developing the implementation plan (approved via the companion Decreto Supremo 5322 on 23 January 2025).