Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
On 3 June 2026 the European Commission adopted a legislative proposal for the Cloud and AI Development Act (CADA) — COM(2026) 502 — as part of the European Technological Sovereignty Package. The CADA proposes to triple EU data-centre capacity over five to seven years, introduces a single EU-wide sovereignty assessment framework for cloud and AI services, and establishes common EU-level procurement mechanisms for public administrations prioritising EU-based cloud and AI infrastructure. As a Commission proposal the CADA now enters co-decision (European Parliament + Council) and is not yet law; it is structurally distinct from the co-adopted Chips Act 2.0, addressing cloud infrastructure and AI compute capacity rather than semiconductor supply chains.
The UK Department for Science, Innovation and Technology (DSIT) launched the Sovereign AI Fund on 16 April 2026, a £500 million state-anchored equity vehicle chaired by James Wise (Balderton Capital) and designed to operate at venture-capital speed. The Fund makes direct equity investments in UK-headquartered AI startups and bundles allocations of UK AI Research Resource (AIRR) supercomputer capacity alongside investment tickets; an initial cohort of six startups received up to one million GPU hours each and Callosum received the first equity ticket. The Fund is the principal operational implementation of the AI Opportunities Action Plan (CP 1241, January 2025) compute-and-capability pillar and has a dedicated government portal at sovereignai.gov.uk.
Thailand's Board of Investment issued Notification No. 9/2568 on 14 November 2025, amending the Activity List Eligible for Investment Promotion by splitting the prior single data-center category into two tiers based on power-usage efficiency: high-efficiency data centers (PUE ≤ 1.3) qualify for an 8-year corporate income tax (CIT) exemption, while other data centers receive a 5-year CIT exemption. A precursor restructure (Notification No. 5/2568, 5 June 2025) first introduced the two-tier category split; Notification 9/2568 added location-differentiated terms based on the Eastern Economic Corridor (EEC). New benefit conditions require applicants to submit a Thailand-benefit plan — training programmes, academic/R&D partnerships, local supply-chain support, or knowledge transfer to Thai nationals — that must be implemented before CIT exemption benefits can be exercised.
On 17 October 2025 Türkiye's Ministry of Industry and Technology opened the "HIT-AI" call, a USD 1.6 billion support tranche under the HIT-30 High Technology Investment Programme (see `2024-07-26-turkiye-hit-30-high-technology- investment-programme`), targeting large-scale IT investments delivering AI services, managed/self-service cloud offerings, and AI-hardware buildouts of at least USD 100 million. The call bundles multiple instruments — tax reduction up to 60%, capex grants up to 40% (with an additional up to 20% grant specifically for AI-hardware investment), concessional financing up to 70%, employment support, and market-development support up to 20% — and was announced alongside a parallel USD 1.5 billion "HIT-Data Centre" call, a USD 300 million "HIT-Quantum" call, and a USD 1 billion "HIT-Industrial Robot" call. Minister Mehmet Fatih Kacır framed the combined package as designed to mobilise USD 10 billion in data-centre and AI investment by 2030, lifting national data-centre capacity from 250 MW to 1 GW.
On 18 September 2025 Brazil's federal government published Medida Provisória (Provisional Measure) 1318/2025, creating REDATA — the Special Taxation Regime for Datacenter Services — alongside a parallel IT-export regime (REPES). REDATA zeroes federal taxes on servers, storage, networking, cooling and other datacenter capital equipment for qualifying operators from 1 January 2026, conditioned on 100% renewable/zero-carbon energy sourcing, a 2% of investment R&D-in-Brazil commitment, and preferential use of Brazilian- manufactured components. The Finance Ministry projects R$5.2 billion in forgone-tax incentives in 2026 alone, with potential to unlock up to R$2 trillion in private datacenter investment over ten years. REDATA is framed as implementing the National Datacenter Policy (PNDC) under the Nova Indústria Brasil industrial-policy umbrella.
Italy's Ministry of Enterprises and Made in Italy (MIMIT) signed a decree ("Disciplina degli interventi di sostegno alla domanda di servizi di cloud computing e cyber security") on 18 July 2025 establishing a EUR 150 million fund, drawn from FSC 2014-2020 resources, to subsidize SME and self-employed purchases of cloud computing and cybersecurity services nationwide. Beneficiaries receive a non-repayable grant covering up to 50% of eligible expenses, capped at EUR 20,000 per beneficiary, conditional on holding a connectivity contract of at least 30 Mbps download speed. Supplier registration (a prerequisite for the voucher's use) was originally set to close 23 April 2026 and was later extended to 27 May 2026; beneficiary application procedures follow once the authorized-supplier list is formed.
Indonesia's Ministry of Communications and Digital Affairs (Kemkomdigi) promulgated Permenkomdigi No. 5/2025 on 25 March 2025 as the implementing regulation under Government Regulation PP 71/2019 governing Public-Scope Electronic System Operators (PSE Lingkup Publik), defined as operators running electronic systems for government institutions or critical public services. The regulation mandates registration, data classification by risk level (low/medium/ high/strategic) with corresponding domestic storage and processing requirements, content- moderation governance, and access-blocking mechanisms for prohibited electronic information. All public-scope PSEs must achieve compliance by 25 March 2026, with non-compliant operators subject to progressive administrative sanctions under Articles 100-series ranging from written warnings to access disconnection (pemutusan akses) and removal from official registries.
The UK government published the AI Opportunities Action Plan (CP 1241) on 13 January 2025, authored by Matt Clifford CBE (Chair, ARIA), and simultaneously accepted all 50 recommendations via the government response (CP 1242). The plan establishes binding cross-government commitments including a 20× expansion of UK sovereign AI compute capacity by 2030, designation of AI Growth Zones (Culham, Oxfordshire named first), a National Data Library, and energy-grid prioritisation for AI datacentres. It positions AI compute as critical national infrastructure and represents the most comprehensive national AI industrial-policy roadmap published in the UK to date.
The Indiana Economic Development Corporation approved up to USD 18.3 million in EDGE (Economic Development for a Growing Economy) payroll-based tax credits for Amazon Data Services Inc., tied to Amazon Web Services' USD 11 billion data center campus at the Indiana Enterprise Center in New Carlisle, St. Joseph County. The credit was one component of a larger state incentive package announced by Governor Eric Holcomb on 2024-04-25, which also included up to USD 55 million in Hoosier Business Investment tax credits, up to USD 20 million in redevelopment tax credits, up to USD 5 million in training grants, a USD 7 million road-infrastructure contribution, and a 50-year state sales-tax exemption on data center equipment. IEDC records cite an incentive-agreement effective date of 2023-09-01. The project committed to creating at least 1,000 new jobs.
The Indiana Economic Development Corporation approved up to USD 55 million in Hoosier Business Investment (HBI) tax credits for Amazon Data Services Inc., tied to Amazon Web Services' USD 11 billion data center campus at the Indiana Enterprise Center in New Carlisle, St. Joseph County. This is the largest single instrument in the five-part state incentive package Governor Eric Holcomb announced on 2024-04-25, which also included up to USD 18.3 million in EDGE payroll tax credits, up to USD 20 million in redevelopment tax credits, up to USD 5 million in training grants, a USD 7 million road-infrastructure contribution, and a 50-year state sales-tax exemption on data center equipment. IEDC describes all incentives as performance-based, claimable only once the underlying investment and job-creation commitments are verified. IEDC records cite an incentive-agreement effective date of 2023-09-01.
The Indiana Economic Development Corporation approved up to USD 20 million in redevelopment tax credits for Amazon Data Services Inc., tied to Amazon Web Services' USD 11 billion data center campus at the Indiana Enterprise Center in New Carlisle, St. Joseph County. This is the third of five distinct incentive instruments in the state package Governor Eric Holcomb announced on 2024-04-25, alongside up to USD 18.3 million in EDGE payroll tax credits, up to USD 55 million in Hoosier Business Investment tax credits, up to USD 5 million in training grants, a USD 7 million road-infrastructure contribution, and a 50-year state sales-tax exemption on data center equipment. IEDC records cite an incentive-agreement effective date of 2023-09-01.
The Cyberspace Administration of China (CAC) issued the Provisions on Promoting and Regulating Cross-Border Data Flows (《促进和规范数据跨境流动规定》) on 22 March 2024, effective immediately. The rules substantially raise the thresholds at which CAC security assessment, Standard Contractual Clauses (SCC), or Personal Information Protection Certification are required for outbound data transfers, and create categorical exemptions for contract performance, HR management, intra-group transfers below a volume threshold, and transit data processed in China with no domestic personal information introduced. A Free Trade Zone pilot mechanism allows designated FTZs (Shanghai Lingang, Tianjin, Beijing) to publish their own negative lists defining which data categories still require prior approval, easing conditions for multinationals with operations in those zones.
BIS amended §§ 734.15 and 734.19 of the Export Administration Regulations (EAR) to clarify that a "release of software" for purposes of the transfer-of-access-information provision includes both source code and object code. A cross-reference was also added from § 734.15 to § 734.19. The practical effect is that providing a decryption key, password, or other access credential to a foreign person to unlock controlled software requires an export licence to the same degree as exporting the software itself would.
The Bureau of Industry and Security (BIS) added 37 entities under 38 entries to the Entity List, effective March 2, 2023, spanning six destinations: China (28), Pakistan (4), Burma (3), Russia (1), Belarus (1), and Taiwan (1). The China tranche — the largest — targets entities supporting the People's Liberation Army's military modernization, including BGI Research and Forensic Genomics International (genomic surveillance/data risk), Inspur Group Co. Ltd. (cloud servers supplied to Chinese military), and Loongson Technology (domestic CPU developer). Three Burmese entities, including the Ministry of Transport and Communications, are designated for providing surveillance equipment enabling the military junta's tracking and targeting of civilians. Pakistani entities Abdul Razaq Asim, Add-On Technology, and Dynamic Engineers are added for contributing to Pakistan's ballistic missile programs; Russian DMT Electronics and Belarusian DMT Trading LLC for export-control evasion. All listed entities are subject to a license requirement for all items subject to the EAR, with the review policy being presumption of denial for the majority of Chinese entries.
BIS published a technical correction to the Entity List (15 CFR Part 744, Supplement No. 4) fixing three errors in the February 14, 2022 final rule (87 FR 8180; FR Doc. 2022-03029) that added and revised Huawei entities. Two entries — Huawei Cloud Brazil (São Paulo) and Huawei Technologies Co., Ltd. (China, with 22+ affiliated addresses) — incorrectly cited §736.2(b)(3)(vi) as the Foreign Direct Product rule trigger instead of the correct §734.9(e) (the Huawei-specific FDP rule); a third error was a typographical fix to the footnote reference ("except for" → "EXCEPT\2\ for"). No new restrictions were created; the substantive export control status of all listed Huawei entities is unchanged, but exporters relying on the CFR text now have the correct regulatory citation for license requirement determinations.
The Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法 — PIPL) was adopted at the 30th meeting of the 13th NPC Standing Committee on 20 August 2021 and entered into force on 1 November 2021, constituting the third and final pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Data Security Law (2021). The PIPL is China's comprehensive personal-information statute establishing consent-based and necessity-based legal bases for PI processing, a tiered cross-border personal-data transfer regime (CAC security assessment / PI protection certification / Standard Contractual Clauses), extraterritorial application (Art. 3) to non-Chinese controllers offering services to or analysing the behaviour of PRC residents, and a heightened protection regime for sensitive personal information and data of minors under 14. It mandates data-protection impact assessments, personal-information-protection-officer obligations at designated handlers, breach notification, and a full suite of data-subject rights including access, rectification, deletion, portability, objection, and automated- decision-making opt-out. Article 53 requires overseas controllers to establish a domestic representative or designated entity in China, providing a domestic enforcement counterparty.
The Data Security Law of the People's Republic of China (中华人民共和国数据安全法) was adopted at the 29th meeting of the 13th NPC Standing Committee on 10 June 2021 and entered into force on 1 September 2021, constituting the second pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Personal Information Protection Law (2021). The DSL establishes a tiered data-classification regime — "important data" and "national core data" — with escalating security obligations including risk assessment, risk monitoring, breach reporting, and classified-protection requirements for data handlers. It introduces a data-export security review for "important data" generated or collected within China, the statutory parent authority operationalised by the 2024 CAC Cross-Border Data Flow Provisions, and enacts a §36 blocking statute prohibiting Chinese organisations and individuals from transferring data stored in China to foreign judicial or law-enforcement authorities without prior PRC government approval.
The Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法) was adopted at the 24th meeting of the 12th NPC Standing Committee on 7 November 2016 and entered into force on 1 June 2017, establishing the foundational legal framework for network security governance across all sectors. The law creates the Critical Information Infrastructure Operator (CIIO) designation and protection regime administered by the Cyberspace Administration of China (CAC), mandates data localisation for personal information and important data collected or generated by CIIOs in China, and establishes cross-border data-transfer security assessment requirements under Article 37 — the provision later operationalised by DSL 2021, PIPL 2021, and the 2024 CAC Cross-Border Data Flow Provisions. The CSL introduced multi-level protection scheme (等级保护制度 / MLPS) obligations for all network operators and network-product/service security-review procedures, under which CAC triggered the cybersecurity review of Didi Global in 2021 and the exclusion of Micron's products from Chinese critical-infrastructure projects in 2023.
Decreto-Legge 15 marzo 2012 n. 21 (GU n. 63 of 15 March 2012), converted with amendments into Legge 11 maggio 2012 n. 56 (GU n. 111 of 14 May 2012), establishes Italy's "Golden Power" special-powers regime — the foundational statute authorising the Italian Government to impose conditions on, veto, or prescribe remedies for corporate transactions in strategic sectors. The decree marked Italy's transition from a golden-share model (applicable only to privatised companies) to a sector-wide golden-power model applicable to any company carrying out activities of strategic relevance. Administered by the Presidenza del Consiglio dei Ministri (DICA), the regime has been progressively extended from its original defence + national-security + energy/transport/ communications scope to cover 5G, cloud, critical-raw-materials, financial-credit-insurance, agri-food, healthcare, media, space, and AI through a series of amending decrees from 2019 to 2026.