Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
On 19 May 2026, Treasurer Jim Chalmers announced a further overhaul of Australia's foreign investment framework under the Foreign Acquisitions and Takeovers Act 1975. The package introduces a performance target of processing all low-risk applications within 30 days from 1 January 2027, expands the exemption-certificate regime for repeat low-risk investors, and eliminates approval requirements for certain low-risk transaction types. Countervailing measures tighten the framework: enhanced compliance and enforcement powers are added for avoidance and non-compliance, and screening requirements are explicitly increased for sensitive sectors including critical minerals, critical infrastructure, critical technology, sensitive data, and defence-site-proximate assets.
President Trump issued five Presidential Determinations on 20 April 2026 under Section 303 of the Defense Production Act of 1950 (50 U.S.C. § 4533), invoking the authority granted by Executive Order 14156 (Declaring a National Energy Emergency, signed 20 January 2025). The five determinations cover: (1) domestic petroleum production, refining, and logistics; (2) large-scale energy and energy-related infrastructure development, manufacturing, and deployment; (3) natural gas transmission, processing, storage, and LNG capacity; (4) coal supply chains and baseload power generation; (5) grid infrastructure, equipment, and supply chain. Each determination authorises the relevant Cabinet Secretary (primarily Energy) to use DPA §303 powers — direct loans, loan guarantees, purchase commitments, and equity investments — to expand domestic capacity in the named category.
Germany's first cross-sector federal statute establishing minimum requirements for the physical protection and resilience of critical infrastructure operators (KRITIS) — sectors covered include energy, transport, water, food, ICT, financial services, health, and federal government infrastructure. Transposes EU Directive 2022/2557 (CER Directive on the resilience of critical entities). Identifies operators of critical facilities with Europe-wide significance, mandates national risk analyses for critical services, requires operator risk-management measures and creates a federal incident-reporting regime. Passed by the Bundestag on 29 January 2026, confirmed by the Bundesrat on 6 March 2026, published in BGBl. 2026 I Nr. 66 on 16 March 2026, in force from 17 March 2026.
The Overseas Investment (National Interest Test and Other Matters) Amendment Act 2025 (No 81 of 2025) is the largest rewrite of New Zealand's Overseas Investment Act 2005 since the 2018 residential-land amendment. The Bill (Government Bill 171) was introduced by the Minister of Finance in June 2025, passed all three readings in the House of Representatives, received Royal Assent on 19 December 2025, and was brought into force on 6 March 2026 by the Overseas Investment (National Interest Test and Other Matters) Amendment Act 2025 Commencement Order 2026 (SL 2026/2). The Act replaces the OIA's residual "investor test" discretion with a single statutory national-interest test applied to all "sensitive asset" transactions, introduces a new s 29B repeat-investor mechanism (Treasury does not re-litigate investor risk factors on subsequent applications outside strategically important businesses), creates new military / dual-use technology call-in transactions and critical-direct-supplier call-in transactions (amended s 85), and adds a no-change-of-control transaction category. Administered by The Treasury (policy lead) and Toitū Te Whenua LINZ (operations / case handling), with consent decisions issued by the responsible Ministers.
On 19 December 2025 the Swiss Federal Assembly adopted in final vote the Federal Act on the Screening of Foreign Investments (Bundesgesetz über die Prüfung ausländischer Investitionen, Investitionsprüfgesetz / IPG; popularly the "Lex China", parliamentary business 22.035). The Act introduces Switzerland's first general ex-ante FDI-screening regime: acquisitions of control over Swiss companies active in security-critical sectors by foreign state-controlled investors require prior approval by SECO, with escalation to the Federal Council. The optional- referendum window runs until 17 April 2026; entry into force is not expected before 2027 once implementing ordinances are adopted. Critical sectors named in the Act include military and dual-use goods, electricity grids and generation, water supply, pharma and health, telecommunications, transport infrastructure and financial-market infrastructure.
The UK Ministry of Defence announced the Atlantic Bastion programme on 8 December 2025, establishing a hybrid naval force to defend UK and NATO subsea cable and pipeline infrastructure against Russian submarine threats. The programme integrates ships, submarines, aircraft, and autonomous uncrewed vessels through AI-powered acoustic detection and a digital targeting web, with £14 million in combined MOD/industry seedcorn investment already committed, 26 UK and European firms submitting anti-submarine sensor proposals, and capabilities due to be deployed in 2026. Atlantic Bastion implements the Strategic Defence Review 2025 undersea-warfare commitments and is coordinated through the Undersea Infrastructure Security (UIS) Oversight Board chaired by the Cabinet Office.
On 26 November 2025, Scotland's Deputy First Minister and Cabinet Secretary for Economy and Gaelic, Kate Forbes MSP, wrote to the Scottish Parliament's Economy and Fair Work Committee confirming that the preferred bidder for Glasgow Prestwick Airport had withdrawn from the sale process after a "robust commercial deal" had been negotiated. The letter discloses that the proposed acquisition was subject to mandatory notification to the UK Government under the National Security and Investment Act 2021, a reserved matter on which Scottish Ministers cannot comment. Media reporting (Global Trade Alert; Daily Business) identifies the withdrawn bidder as Turkish conglomerate Limak Holding and attributes the collapse directly to the UK national-security review process ("Westminster officials opening an investigation"). The airport, which employs over 500 people directly and anchors an Ayrshire aerospace cluster, remains in Scottish Government public ownership.
Cyprus Law 194(I)/2025 "The Establishment of a Framework for the Screening of Foreign Direct Investments Law of 2025" was enacted by the House of Representatives and published in the Official Gazette on 14 November 2025, entering into force on 2 April 2026. It establishes Cyprus's first-ever mandatory pre-approval FDI screening regime, designating the Ministry of Finance as the competent Screening Authority and applying to non-EU/EEA/Swiss investors acquiring ≥25% equity or voting rights in Cyprus entities valued at ≥€2 million across covered strategic sectors. The regime implements EU Regulation 2019/452 and includes a Cyprus-specific sectoral extension covering tourism and real estate — addressing golden-passport-era concerns about non-EU capital flows into the island's financial and hospitality economy.
Germany's transposition of EU Directive 2022/2555 (NIS2), enacted as the "Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung." Bundestag passage 13 November 2025; Bundesrat approval 21 November 2025; published as BGBl. I 2025 Nr. 301 on 5 December 2025; entered into force 6 December 2025. The statute designates the Bundesamt für Sicherheit in der Informationstechnik (BSI) as the central national supervisory authority over an estimated 29,500 covered entities across 18 critical and important sectors, introduces a mandatory 24h initial / 72h detailed / 1-month final cyber-incident reporting cascade, establishes board-level personal liability for senior management, and applies to SME critical- infrastructure suppliers — with no transitional grace period from entry into force.
The Hrvatski sabor (Croatian Parliament) unanimously adopted the Act on Screening of Foreign Direct Investments on 24 October 2025; the law was published in Narodne Novine 136/2025 and entered into force on 13 November 2025. It establishes Croatia's first-ever statutory horizontal FDI-screening regime, implementing EU Regulation 2019/452 in Croatian law. The Act captures direct or indirect acquisitions by non-EU investors of at least 10 % of share capital, voting rights or property rights in Croatian entities operating in sensitive sectors (defence, dual-use, critical infrastructure, critical minerals, emerging tech, sensitive personal data, energy, transport, health, digital infrastructure, media, financial services). The reviewing authority must decide within 120 days, exceptionally 150 days, of a complete application. Croatia was one of the last EU Member States without a horizontal screening law.
The FCC adopted a Report and Order (FCC 25-49) on 7 August 2025 — the first comprehensive overhaul of submarine cable landing license rules since 2001 — effective 26 November 2025. The order prohibits Indefeasible Right of Use (IRU) agreements that would give entities from designated foreign adversary countries (China including Hong Kong and Macau, Cuba, Iran, DPRK, Russia, and Venezuela) control over Submarine Line Terminal Equipment (SLTE) on US cable landings, and mandates new annual reporting plus certification/disclosure requirements covering ownership, cybersecurity and physical security plans, and FCC Covered List compliance. The order operationalises the FCC's bifurcated policy package: accelerating legitimate commercial cable buildout while hardening national-security review for foreign-adversary-connected infrastructure.
Czech Act No. 265/2025 Sb., promulgated in the Sbírka zákonů on 4 August 2025 and entering into force on 1 November 2025, is the first material amendment of the Czech Republic's foundational FDI screening statute (Act No. 34/2021 Sb.) since its enactment. The amendment broadens the perimeter of mandatory pre-closing FDI screening by cross-referencing the simultaneously-enacted Cybersecurity Act (Act No. 264/2025 Sb., transposing NIS2 Directive 2022/2555): entities designated as providers of "regulated services" under the Cybersecurity Act's "regime of higher obligation" automatically fall within mandatory FDI-screening scope, extending screening reach beyond the prior military-material / dual-use / critical-infrastructure perimeter to cover a broad sweep of digital, technology, healthcare, energy, and financial-services operators. The amendment also adds a confidentiality-sharing channel between MPO and NÚKIB, enabling coordinated supply-chain-security assessments for high-risk-vendor reviews under the new Cybersecurity Act.
Czech Republic's first standalone federal statute on the resilience of critical-infrastructure entities — Act No. 266/2025 Sb., "Zákon o odolnosti subjektů kritické infrastruktury a o změně souvisejících zákonů" (Critical Infrastructure Act). Transposes EU Directive 2022/2557 (CER Directive on the resilience of critical entities) into Czech law and removes critical-infrastructure regulation from the earlier crisis-management law (Zákon č. 240/2000 Sb.) into a dedicated statute. Covers the 11 CER-Directive sectors (energy, transport, banking, financial-market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space, food production-processing-distribution) and obligates designated operators of essential services to conduct risk analyses, implement technical/organisational resilience measures, report incidents to sector-competent authorities, and submit to inspection. Published in the Sbírka zákonů on 4 August 2025; in force 19 August 2025; operator information-obligation deadline 1 March 2026.
The Assembly of Albania (Kuvendi i Republikës së Shqipërisë) adopted Law No. 56/2025 on 11 July 2025, published in Fletorja Zyrtare (Official Gazette) No. 124 of the same date, amending Article 10 of Law No. 7764/1993 "On Foreign Investments" to introduce Albania's first-ever mandatory FDI screening mechanism. The law requires investors to submit applications for screening of any foreign investment "related to or affecting critical public infrastructure, critical technologies, dual-use goods, supply of critical inputs, access to sensitive information, or media freedom" — categories aligned with EU Regulation 2019/452 — while delegating thresholds, timelines, and procedural safeguards to a forthcoming Decision of the Council of Ministers (DCM). Albania becomes the first country in the Western Balkans to establish an investment-screening regime aligned with EU Regulation 2019/452, opening a new issuer-country code (AL) on the IPTM register and anchoring a regional cluster that currently stands at RS=1, MK=0, BA=0, ME=0, XK=0.
Greece enacted Law 5202/2025 on 22 May 2025, published in Government Gazette ΦΕΚ A' 84 on 23 May 2025 and effective the same day, establishing the country's first national mandatory and suspensory foreign direct investment screening mechanism, aligned with Regulation (EU) 2019/452. The Interministerial Committee for the Control of Foreign Direct Investment (ICC-FDI), with initial procedure run by the Ministry of Foreign Affairs, reviews non-EU acquisitions in "sensitive" sectors (energy, transportation, healthcare, ICT, digital infrastructure) and "particularly sensitive" sectors (national security, defence, cybersecurity, AI, ports and critical subsea infrastructure, borderland tourism). A two-phase review applies — 30 days Phase I, up to 150 days Phase II with EU Cooperation Mechanism notification — and the regime became fully operational on 11 November 2025.
On 27 February 2025, the Parliament of the Republic of Moldova adopted Law No. 33/2025 amending Law No. 174/2021 on the mechanism for examining investments of importance for state security. The law entered into force on 20 April 2025 after publication in Monitorul Oficial Nr. 144-147 of 20 March 2025 (promulgated by Presidential Decree No. 118-X of 17 March 2025). Key operative changes expand the protected-sector perimeter to explicitly enumerate 17 categories covering data processing and storage, AI, robotics, cybersecurity, semiconductors, quantum, nanotechnology and biotechnology alongside the pre-existing energy, transport, communications, defence and aerospace pillars; add new grounds for refusal (money-laundering suspicion, corruption convictions, foreign-government control, cybersecurity risk, access to personal data of citizens); introduce enhanced Council powers including retroactive review of previously approved investments and fines of up to 5% of annual turnover (capped at MDL 5 million); and carve out intra-group transactions, asset sales below EUR 1 million, and state-owned-enterprise dealings. The Screening Council became operational in July 2025.
Joint Communication JOIN(2025) 9 final, adopted 21 February 2025, establishes the EU's first cable-infrastructure-specific resilience framework. It introduces a four-pillar Cable Security Toolbox (prevention, detection, response/recovery, deterrence), designates Cable Projects of European Interest (CPEIs) for priority public funding, and allocates €347 million under the Connecting Europe Facility Digital programme for cross-border subsea cable diversification, redundancy, and repair-ship capacity. The plan also formalises EU-NATO Task Force on Resilience of Critical Undersea Infrastructure follow-on workstreams and establishes an attribution and diplomatic-response framework for cable-sabotage incidents, referencing Baltic Sea cable-cutting events from 2023 to 2025.
Japan's National Diet enacted the Cyber Response Capability Enhancement Act (重要電子計算機に対する不正な行為による被害の防止に関する法律, Law No. 42 of 2025) on 16 May 2025, together with companion arrangement legislation. Commonly known as the Active Cyber Defense (ACD) Law, the statute authorises (i) government monitoring of foreign-origin internet traffic transiting designated Japanese communication infrastructure for national-security threat indicators, (ii) pre-emptive access and neutralisation operations against attacker infrastructure abroad by the National Police Agency and the Self-Defense Forces under unified command, and (iii) mandatory cyber-incident reporting and government cooperation duties on critical-infrastructure operators. Implementation is phased through November 2027, with the NISC reorganised into the National Cybersecurity Office (NCO) under the Cabinet Secretariat from July 2025.
Regulation (EU) 2025/38 of the European Parliament and of the Council of 19 December 2024 lays down measures to strengthen solidarity and capacities in the Union to detect, prepare for, and respond to cyber threats and incidents, and amends Regulation (EU) 2021/694 (Digital Europe Programme). Published in the Official Journal on 15 January 2025; entered into force on 4 February 2025 (20 days after OJ publication). The regulation establishes (i) a European Cybersecurity Alert System composed of national and cross-border Security Operations Centre (SOC) hubs interconnected EU-wide, (ii) a Cybersecurity Emergency Mechanism funded through the Digital Europe Programme, (iii) an EU Cybersecurity Reserve of trusted private-sector incident-response providers, and (iv) an ENISA-led post-incident review mechanism for significant or large-scale cybersecurity incidents. It complements the Cyber Resilience Act (Reg 2024/2847) and the NIS2 Directive as the third leg of the EU horizontal-cybersecurity stack.
Australia's first standalone cyber-security statute (Act No. 98 of 2024), passed by Parliament on 25 November 2024 and granted Royal Assent on 29 November 2024, with provisions commencing in tranches through 30 May 2025. The Act creates four binding regimes: (i) mandatory security-of-things standards for connected and IoT products supplied in Australia under regulations administered by the Department of Home Affairs; (ii) a mandatory ransomware / cyber-extortion payment disclosure regime requiring reporting business entities with annual turnover above AUD 3 million to notify the Australian Signals Directorate within 72 hours of any ransom payment made by or on behalf of the entity; (iii) a statutory Cyber Incident Review Board to conduct no-blame post-incident reviews of significant cyber incidents; and (iv) a "limited use" protection restricting how information voluntarily shared with the National Cyber Security Coordinator may be used by Commonwealth agencies. The Act implements core initiatives from the 2023-2030 Australian Cyber Security Strategy and affects every firm selling connected devices into Australia or operating above the turnover threshold in Australia.
The Seimas of the Republic of Lithuania adopted Law No. XIV-2985 on 26 September 2024, amending the Law on the Protection of Objects of Importance to Ensuring National Security (NSU Act), registered in the Teisės aktų registras (TAR) on 3 October 2024 and entering into force on 18 October 2024. The amendments expand the list of strategically important economic activities subject to FDI screening by the Commission for the Coordination of Protection of Objects of Importance to National Security to include the issuance of electronic money, electronic money tokens, asset-referenced tokens, and the provision of crypto-asset services (CASPs) as defined under EU MiCA Regulation 2023/1114, aligning Lithuania's screening perimeter with the EU crypto-assets regulatory framework. The law also refines core definitional concepts — "persons acting in concert," "controlling person," and "manager of critical information infrastructure" — to tighten beneficial-ownership and control analysis under the regime.
The Bureau of Industry and Security (BIS) finalized amendments to its Defense Priorities and Allocations System (DPAS) regulation at 15 CFR Part 700, originally proposed February 7, 2024. The final rule clarifies long-standing standards and procedures by which BIS provides Special Priorities Assistance (SPA) under the Defense Production Act of 1950, revises Schedule I to delineate Department of Commerce DPAS jurisdiction from other agencies' priority-rating authorities, and applies non-substantive technical edits reflecting updates since the regulation was last amended in 2014. The rule takes effect August 21, 2024.
Japan's National Diet enacted the Act on the Protection and Use of Critical Economic Security Information (重要経済安保情報の保護及び活用に関する法律, Act No. 27 of 2024) on 10 May 2024; it was promulgated on 17 May 2024 and came into full operation on 16 May 2025. The law establishes Japan's first peace-time economic-security clearance regime extending to private-sector employees. It designates "Critical Economic Security Information" (CESI) covering threat-intelligence on critical-infrastructure cyber attacks, regulatory-review information on essential infrastructure, and vulnerability data on critical-product supply chains; mandates Cabinet Office "適性評価" (suitability assessment) for cleared personnel; and imposes criminal penalties of up to five years' imprisonment for unauthorised disclosure. The CESI Act complements the 2022 Economic Security Promotion Act (ESPA), closing the information-protection gap and aligning Japan's framework with Five Eyes and EU partners for joint R&D and dual-use cooperation.
Latvia's Saeima adopted on 27 March 2024 amendments to the National Security Law (Nacionālās drošības likums), entering into force on 24 April 2024, that widen the perimeter of foreign-investment and ownership transactions subject to Cabinet of Ministers pre-clearance over "companies of significance to national security." The amendments expand the universe of regulated subjects beyond registered companies to include foundations and associations, tighten the rules on beneficial-ownership disclosure, and bring additional sensitive activities — energy security including LNG-terminal acquisitions, electronic communications, cybersecurity, and critical-raw-materials processing — under the regime, while clarifying Cabinet authority to impose conditions or unwind transactions retroactively. The law functions as Latvia's horizontal FDI-screening instrument under the EU-wide cooperation framework of Regulation 2019/452.
Bill C-34, the National Security Review of Investments Modernization Act, received Royal Assent on 22 March 2024 — the first major overhaul of the Investment Canada Act (ICA) national-security review regime since 2009. Non-regulatory provisions came into force on 3 September 2024 by Order Fixing P.C. 2024-826 (SI/TR-32, Canada Gazette Part II). The Act creates a pre-implementation filing obligation for investments in prescribed "sensitive sectors" (final list set by regulation), gives the Minister of Innovation new authority to extend reviews and impose interim conditions or accept undertakings without a Governor-in-Council order, raises monetary penalties, and establishes information-sharing authorities with allied screening regimes. ISED's updated NSR Guidelines (5 March 2025) elevate "economic security" to a standalone factor and align the prescribed-sector list with the Sensitive Technology List (STL).
Commission Recommendation (EU) 2024/779 of 26 February 2024, published in the Official Journal on 8 March 2024, establishes the EU's first dedicated policy framework for the security and resilience of submarine cable infrastructure. It creates an informal Submarine Cable Infrastructure Expert Group of Member State authorities chaired by the Commission with ENISA participation, introduces the Cable Projects of European Interest (CPEI) designation mechanism for priority Union funding, and mandates a consolidated Union-wide risk and vulnerability assessment culminating in a Cable Security Toolbox of mitigating measures. Scope covers cables, landing stations, terrestrial tail connections, repair centres, and cable-laying vessel capacity. The recommendation is non-binding under TFEU Article 292 but constitutes the foundational soft-law framework that the later 2025 Cable Security Action Plan (JOIN(2025) 9) operationalises with binding CPEI lists and €347M CEF Digital funding.
Bulgaria's National Assembly adopted on 22 February 2024 amendments to the Investment Promotion Act establishing the country's first horizontal foreign direct investment screening mechanism, published in State Gazette No. 20 on 8 March 2024 and entering into force on 12 March 2024. The regime implements EU Regulation 2019/452 by creating an Interdepartmental Screening Council with a 45-day decision window over non-EU investments meeting a 10 % equity stake or €2 million threshold in critical-infrastructure, dual-use, advanced-technology, media, and financial-infrastructure sectors, with no threshold for investments by Russian or Belarusian persons or in oil and petroleum activities. Non-compliance and false declarations carry fines of 5 % of investment value, with a minimum BGN 50,000.
The Significant Investments Review Act 2024 (Act No. 1 of 2024) is Singapore's first horizontal, cross-sector statutory FDI screening regime. The Bill was passed by Parliament on 9 January 2024, assented to by the President on 6 February 2024 and gazetted on 14 February 2024; the Act commenced on 28 March 2024 under the SIRA 2024 (Commencement) Notification (S 228/2024), together with the Significant Investments Review Regulations 2024 (S 229/2024). The Act creates an "ownership-and-control" layer over a limited number of "designated entities" the Minister for Trade and Industry has identified as critical to Singapore's national-security interests, plus an "any entity" call-in power exercisable against firms that have acted against Singapore's national-security interests, regardless of whether they are designated. Acquisitions of ≥5% require post-closing notification within 7 days; acquisitions of ≥12% / ≥25% / ≥50% and cessations of ≥50% / ≥75% controller status require prior ministerial approval. Administered by the Office of Significant Investments Review (OSIR) within MTI. SIRA is the Singaporean structural peer of US CFIUS, EU Regulation 2019/452, the German AWG §§55-62, the French Décret 2014-479, the UK NSI Act 2021, the Netherlands Wet Vifo, and the Canada ICA national-security review.
Ireland's Screening of Third Country Transactions Act 2023 (Act No. 28 of 2023), signed into law on 31 October 2023 and commenced on 6 January 2025 via S.I. No. 651 of 2024, establishes Ireland's first-ever mandatory inbound FDI screening regime. The Act empowers the Minister for Enterprise, Tourism and Employment to assess, condition, or prohibit transactions by third-country investors (non-EU/EEA/Switzerland) exceeding a EUR 2 million cumulative threshold in targets operating across critical infrastructure, critical technologies, dual-use items, supply of critical inputs, sensitive personal data, and media freedom. A 90-day standstill period applies during Ministerial determination, with criminal sanctions and transaction-voiding powers available for non-compliance.
Sweden's first horizontal foreign-direct-investment screening regime. Lag (2023:560) om granskning av utländska direktinvesteringar — promulgated (utfärdad) by the Ministry of Justice on 21 September 2023 on the basis of Government Bill 2022/23:116, and entered into force on 1 December 2023 — establishes mandatory ex-ante notification to Inspektionen för strategiska produkter (ISP) for direct or indirect acquisitions of voting rights of ≥10%, 20%, 30%, 50%, 65%, or 90% in Swedish entities conducting "skyddsvärd verksamhet" (protected business activities). The protected-activity perimeter is defined by Förordning (2023:624) and the ISP listing across seven sub-categories: essential services, security-sensitive activities, critical raw materials/metals/ minerals, sensitive location and personal data, military equipment, dual-use goods, and emerging or strategically protected technologies. Both EU and non-EU investors are within scope. Unnotified transactions are void by operation of law and may carry administrative fines of SEK 25,000 to SEK 100 million. From 1 Dec 2023 to 29 Nov 2024 ISP processed 1,206 notifications, opened 24 deeper screenings, approved 11, approved 5 with conditions, and prohibited 1 transaction.
President Ferdinand Marcos Jr. signed Republic Act 11954, the Maharlika Investment Fund Act of 2023, on 18 July 2023, establishing the Philippines' first sovereign wealth fund. The Act creates the Maharlika Investment Corporation (MIC) with PHP 500 billion target authorised capital and PHP 125 billion paid-in capital sourced from Bangko Sentral ng Pilipinas dividends, Land Bank of the Philippines, Development Bank of the Philippines, and national-government appropriations. The Bureau of the Treasury initially issued IRR on 28 August 2023; following a presidential suspension on 12 October 2023, the revised IRR was finalised and published in the Official Gazette on 10 November 2023. The MIC's first major strategic-stake deployment took place in January 2025 with a USD 350 million acquisition of a 20% stake in the National Grid Corporation of the Philippines (NGCP), previously partly owned via State Grid Corporation of China.
Luxembourg's Chambre des Députés adopted the first-ever national FDI-screening statute on 14 July 2023 (promulgated by the Grand Duke and published in Mémorial A n° 411 on 18 July 2023), entering into force 1 September 2023. The law requires non-EU investors to notify the Ministre de l'Économie before completing direct or indirect acquisitions of ≥25% voting rights / equity in Luxembourg entities engaged in "critical activities" across twelve sectors. The Minister can approve, conditionally approve, or prohibit transactions within a two-month initial screening window, with a further 60-day deep-review phase available; an inter-ministerial Comité de filtrage (Economy + Foreign Affairs + Finance + SREL intelligence service) advises on security and public-order grounds consistent with EU Regulation 2019/452.
Spain's comprehensive 2023 implementing regulation of Law 19/2003, of 4 July, on the legal regime of capital movements and economic transactions with the exterior. Adopted as Real Decreto 571/2023 of 4 July 2023, published in the Boletín Oficial del Estado on 5 July 2023 (BOE-A-2023-15549), and in force from 1 September 2023. The Decree repeals the predecessor Royal Decree 664/1999 of 23 April on foreign investments, updates the declaration regime to reflect twenty years of practice and capital-market innovation, and operationalises the Article 7-bis horizontal FDI-screening mechanism that the 2020 COVID-emergency reforms (RDL 8/2020 and RDL 11/2020) inserted into Law 19/2003. It introduces a binding consultation regime (consulta vinculante), reduces the screening review period to three months, refines the catalogue of sensitive sectors (defence, dual-use, critical technologies, critical infrastructure, critical inputs, media, electoral process, access to sensitive information, and activities affecting public security, health and order), and codifies notification thresholds for non-EU/EFTA investors (>10% control or material influence; minimum transaction values of EUR 5 million / EUR 1 million for certain sectors).
Lov 2023-06-20 nr. 77 (Lov om endringer i sikkerhetsloven — eierskapskontroll og lovens virkeområde), adopted by the Storting on 9 June 2023, signed 20 June 2023, in force 1 July 2023, is Norway's first substantive overhaul of Chapter 10 (Eierskapskontroll / ownership control) of the 2018 Security Act (Sikkerhetsloven). The amendment widens the scope of undertakings that can be brought under ownership control beyond entities directly linked to a "grunnleggende nasjonal funksjon" (fundamental national function) to include businesses of vital importance to national-security interests and businesses of significant importance to fundamental national functions, lowers and adds notification thresholds, and equips the King in Council with enhanced powers to block, condition, or unwind qualifying acquisitions. The reform converts a narrow security-classified regime into a broad horizontal FDI-screening architecture for Norway, the host of the world's largest sovereign wealth fund and a NATO frontline state.
On 9 June 2023 the National Assembly of the Republic of Slovenia adopted Zakon o spremembah in dopolnitvah Zakona o spodbujanju investicij — ZSInv-C (Act on Amendments to the Investment Promotion Act), published in Uradni list RS No. 65/23 on 17 June 2023 and entering into force on 1 July 2023. The amendment converts Slovenia's temporary COVID-era inward FDI screening regime (originally introduced under ZIUOPDVE in 2020 and set to expire June 2023) into a permanent, horizontal screening framework administered by the Ministry of Economy, Tourism and Sport (MGTŠ). Non-EU (third-country) investors acquiring ≥10% voting rights or control in Slovenian entities operating in sectors listed under EU Regulation 2019/452 — including critical infrastructure, critical technology and dual-use goods, critical inputs, sensitive data, media, and health/AI/robotics — must submit a mandatory pre-closing notification; the ministry has suspensory power and may block, condition, or unwind transactions on grounds of security or public order. A subsequent 2024 amendment (Uradni list RS No. 31/24) broadened scope by redefining "corporate entity" to capture indirect investments channelled via branches of foreign entities established in other EU member states.
Law no. 164/2023, adopted by the Parliament of Romania on 31 May 2023 and published in Monitorul Oficial Partea I nr. 495 of 7 June 2023, approves and amends Emergency Government Ordinance 46/2022 implementing EU Regulation 2019/452 on screening of foreign direct investments. The law extends Romania's mandatory ex-ante FDI screening to investors established within the European Union (previously only non-EU investments were captured), sets a EUR 2 million de minimis transaction threshold for sensitive-sector deals, formally establishes the Commission for the Examination of Foreign Direct Investments (CEISD) chaired by the Prime Minister with multi-ministry composition, and empowers the Government to unwind transactions that breach the regime. Gun-jumping penalties reach up to 10 % of the investor's worldwide turnover. In force 10 June 2023.
The Foreign Investment Reliability Assessment Act (välismaise investori usaldusväärsuse hindamise seadus, VUHS), adopted by the Riigikogu on 25 January 2023 and in force from 1 September 2023, establishes Estonia's first horizontal ex-ante foreign direct-investment screening regime. The Act transposes EU Regulation 2019/452 into Estonian law and designates the Consumer Protection and Technical Regulatory Authority (Tarbijakaitse ja Tehnilise Järelevalve Amet — TTJA) as the screening authority. It covers acquisitions of qualifying holdings or material influence in target undertakings operating in defence, dual-use, vital services, energy and communications infrastructure, transport, financial services, media, critical raw materials extraction and other strategic sectors. TTJA can prohibit, condition or unwind non-compliant transactions and impose administrative non-compliance levies.
Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities, published OJ L 333, 27 December 2022, entered into force 16 January 2023, with Member State transposition deadline 17 October 2024 (rules applicable from 18 October 2024). The CER Directive repeals Council Directive 2008/114/EC on European Critical Infrastructures, extending the scope from two sectors (energy, transport) to eleven essential-service sectors: energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, public administration, space, and food. Member States must adopt national resilience strategies, conduct risk assessments at least every four years, identify "critical entities" providing essential services whose disruption would have significant cross-border impacts, and ensure those entities implement technical, security, and organisational resilience measures, business-continuity plans, incident-reporting obligations, and personnel-security background checks. The CER Directive is the physical and hybrid resilience twin to the NIS2 Directive (2022/2555) — the two instruments form the binding EU critical-infrastructure-protection architecture replacing the 2008/114/EC regime.
Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive), published OJ L 333, 27 December 2022, entered into force 16 January 2023. NIS2 repeals and substantially expands the 2016 NIS1 Directive (2016/1148), extending the scope from ~7 sectors to 18 enumerated essential and important sectors, imposing binding cybersecurity risk- management and incident-reporting obligations on covered entities, introducing board-level management accountability, and mandating Member State transposition by 17 October 2024. NIS2 is the structural EU statutory anchor for national cybersecurity frameworks across the bloc, operating alongside DORA (Reg 2022/2554) for financial-sector digital resilience and CRA (Reg 2024/2847) for product cybersecurity.
Belgium's first horizontal foreign-direct-investment screening regime, established by a Cooperation Agreement signed on 30 November 2022 between the Federal State and the Flemish, Walloon, Brussels-Capital and German-Community governments, and in force from 1 July 2023. The agreement creates a centralised Interfederal Screening Commission (ISC), chaired by the FPS Economy, to receive and process mandatory ex-ante notifications of foreign acquisitions of 10%, 25% or higher voting-rights / control thresholds (sector-dependent) in Belgian undertakings active in eleven strategic sectors. ISC decisions are binding; sanctions for failure to notify or for non-compliance with conditions imposed include unwinding of the transaction and administrative fines.
Act No. 497/2022 Coll. on the Screening of Foreign Investments and on amendments to certain acts, adopted by the National Council of the Slovak Republic on 29 November 2022 and promulgated in the Zbierka zákonov on 23 December 2022, established Slovakia's first horizontal ex-ante foreign-direct-investment screening regime. The Act took effect on 1 March 2023, transposing EU Regulation 2019/452 into Slovak law and replacing the prior sector-specific approach under Act No. 45 on critical infrastructure. Screening is administered by the Ministry of the Economy of the Slovak Republic across three procedures (mandatory, voluntary, and ex officio) and covers transactions in defence, dual-use, critical infrastructure, critical raw materials, biotechnology, AI, semiconductors and other emerging technologies. The Ministry can prohibit, condition or unwind non-compliant transactions and impose administrative penalties.
Denmark's foundational cross-sector horizontal FDI screening statute. Lov nr 842 of 10 May 2021 — investeringsscreeningsloven — was adopted by the Folketing on 4 May 2021, signed on 10 May 2021, and entered into force on 1 July 2021 (with application to transactions implemented from 1 September 2021). The Act is administered by Erhvervsstyrelsen (Danish Business Authority) and combines (i) a mandatory pre-closing authorisation regime for foreign investments in "particularly sensitive sectors" — defence, dual-use products, IT-security functions/services, critical technology, critical infrastructure — triggered at 10% ownership / voting rights or equivalent control, with (ii) a voluntary notification scheme (typically engaged at 25%+) for foreign investments and special economic agreements in other sectors. Enforcement runs through blocking orders, unwinding orders, and criminal sanctions including fines and imprisonment. Structural peer of the US CFIUS regime, EU Regulation 2019/452, the German AWG §§55-62, the French Décret 2014-479 / R. 151-1 et seq., the UK NSI Act 2021, the Netherlands Wet Vifo, the Italian Golden Power Decree, and the Swedish FDI screening regime.
The German Federal Government adopted the 17th amendment to the Außenwirtschaftsverordnung (AWV, Foreign Trade and Payments Ordinance), published 30 April 2021 and entering into force 1 May 2021, aligning Germany's FDI screening regime with EU Regulation 2019/452. The amendment adds 16 further sectors to the sector-specific mandatory-notification regime, on top of the 11 already covered, bringing the total to 27 -- including AI, robotics, autonomous vehicles/drones, semiconductors, quantum technology, satellite systems, cybersecurity, and critical raw materials. Filing thresholds are voting-rights acquisitions of 10% or more by a non-EU/EFTA investor in the newly added sectors, with subsequent review triggers at 20%, 25%, 40%, 50% and 75%.
Czech Republic's foundational horizontal FDI screening statute. Zákon č. 34/2021 Sb., o prověřování zahraničních investic — adopted by Parliament in January 2021, published in Sbírka zákonů on 29 January 2021, and entered into force on 1 May 2021 — transposes the cooperation obligations of EU Regulation 2019/452 and creates the first cross-sector pre-clearance regime for non-EU investments into Czech firms. The Act is administered by the Ministerstvo průmyslu a obchodu (MPO) and combines (i) a mandatory ex-ante consent regime for non-EU investments acquiring ≥10% in companies producing military material, selected dual-use goods, or operating critical / critical-information infrastructure, with (ii) a discretionary ex-officio review available up to 5 years post-closing for any other "public-order or internal-security" sensitive investment. The Government decides on MPO's recommendation; remedies include conditions, prohibition, and forced divestment, with fines up to 1% of the global net turnover of the foreign investor.
The Investitionskontrollgesetz (InvKG, "Investment Control Act") is Austria's horizontal, statutory FDI screening regime. Published as Article 1 of the Federal Law BGBl. I Nr. 87/2020 on 24 July 2020 and entering into force on 25 July 2020, the Act replaced the previous narrow §§25a–25e Außenwirtschaftsgesetz 2011 (Foreign Trade Act) regime — under which fewer than 10 permits were issued from 2013 to mid-2020 — and transposes EU Regulation 2019/452 establishing a framework for the screening of foreign direct investments into the Union. The InvKG introduces mandatory ex-ante notification and approval of non-EU / non-EEA / non-Swiss acquisitions where the acquirer crosses any of the 10% / 25% / 50% voting-rights thresholds in an Austrian target operating in the critical sectors listed in Annex Part 1 (especially sensitive: defence, energy / water / telecoms critical infrastructure, dual-use technology, cybersecurity, AI, quantum technology, robotics, semiconductors, biotech, health, vaccines) and 25% / 50% in the sectors listed in Annex Part 2 (broader, including media, food-security, electronic communications infrastructure, financial infrastructure). Administered by the Bundesministerium für Arbeit und Wirtschaft (BMAW), with case decisions taken in coordination with the Komitee für Investitionskontrolle (inter-ministerial Investment Control Committee) and, where the case is escalated to the EU cooperation mechanism, the Commission and EU peer Member States. The InvKG is Austria's functional peer of US CFIUS / FIRRMA, UK NSI Act 2021, Germany AWG §§55–62, France Décret 2014-479 / R. 151-1 et seq., Italy Golden Power Decree, Netherlands Wet Vifo, Denmark investeringsscreeningsloven, and Belgium ISC. Sunset clause: originally limited to 30 June 2022 under §17(2) InvKG; permanently extended by BGBl. I Nr. 80/2022 of 14 July 2022.
Finland's parent foreign-direct-investment screening statute. Laki ulkomaalaisten yritysostojen seurannasta (172/2012) — originally enacted in 2012 to replace the 1992 act — was comprehensively amended by Act 682/2020, which entered into force 11 October 2020 to align Finnish national procedure with EU Regulation 2019/452 establishing the EU FDI cooperation mechanism. The Act establishes (i) mandatory ex-ante notification to the Ministry of Economic Affairs and Employment (TEM) for non-EU/EEA acquisitions of Finnish entities producing or supplying defence equipment, dual-use goods, or products/services critical to functions vital to society, and (ii) voluntary notification for any acquisition of a Finnish company with "critical interests for securing societal vital functions." Foreign-owner triggers apply at 10%, one-third, and 50% of voting rights or equivalent influence. TEM is designated the Finnish FDI contact point under Reg 2019/452. Confirmation is granted by TEM unless a key national interest is endangered, in which case the matter is referred to a Government plenary session (Valtioneuvoston yleisistunto); a denied transaction obliges the foreign owner to dispose of the shares within a stated period.
The Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法) was adopted at the 24th meeting of the 12th NPC Standing Committee on 7 November 2016 and entered into force on 1 June 2017, establishing the foundational legal framework for network security governance across all sectors. The law creates the Critical Information Infrastructure Operator (CIIO) designation and protection regime administered by the Cyberspace Administration of China (CAC), mandates data localisation for personal information and important data collected or generated by CIIOs in China, and establishes cross-border data-transfer security assessment requirements under Article 37 — the provision later operationalised by DSL 2021, PIPL 2021, and the 2024 CAC Cross-Border Data Flow Provisions. The CSL introduced multi-level protection scheme (等级保护制度 / MLPS) obligations for all network operators and network-product/service security-review procedures, under which CAC triggered the cybersecurity review of Didi Global in 2021 and the exclusion of Micron's products from Chinese critical-infrastructure projects in 2023.
Germany's Außenwirtschaftsgesetz (AWG, Foreign Trade and Payments Act; BGBl. I 2013 S. 1482 of 6 June 2013, replacing the original 1961 Act) is the foundational parent statute of the modern German economic-statecraft toolkit, providing the legislative authority for (i) export licensing of dual-use goods and technology administered by BAFA under the Außenwirtschaftsverordnung (AWV) implementing regulation — the national complement to EU Dual-Use Recast Regulation 2021/821; (ii) inward FDI screening by BMWK under §§ 55–62 AWG covering non-EU/non-EFTA acquisitions of ≥ 25% of voting rights cross-sectorally and ≥ 10%/20% in 27 sensitive-sector activities including defence, semiconductors, AI, quantum, biotech, space, and critical infrastructure; and (iii) German implementation of EU-level and autonomous trade and sanctions restrictions. As the EU's largest economy and a top-tier dual-use exporter, Germany's AWG-based regime is structurally peer-foundational to JP FEFTA 1949, UK NSI Act 2021, US ECRA 2018, CN Export Control Law 2020, and NL Wet Vifo 2022 in the G7+CN economic- statecraft parent-statute cluster.