Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
Regulation (EU) 2025/38 of the European Parliament and of the Council of 19 December 2024 lays down measures to strengthen solidarity and capacities in the Union to detect, prepare for, and respond to cyber threats and incidents, and amends Regulation (EU) 2021/694 (Digital Europe Programme). Published in the Official Journal on 15 January 2025; entered into force on 4 February 2025 (20 days after OJ publication). The regulation establishes (i) a European Cybersecurity Alert System composed of national and cross-border Security Operations Centre (SOC) hubs interconnected EU-wide, (ii) a Cybersecurity Emergency Mechanism funded through the Digital Europe Programme, (iii) an EU Cybersecurity Reserve of trusted private-sector incident-response providers, and (iv) an ENISA-led post-incident review mechanism for significant or large-scale cybersecurity incidents. It complements the Cyber Resilience Act (Reg 2024/2847) and the NIS2 Directive as the third leg of the EU horizontal-cybersecurity stack.
Australia's first standalone cyber-security statute (Act No. 98 of 2024), passed by Parliament on 25 November 2024 and granted Royal Assent on 29 November 2024, with provisions commencing in tranches through 30 May 2025. The Act creates four binding regimes: (i) mandatory security-of-things standards for connected and IoT products supplied in Australia under regulations administered by the Department of Home Affairs; (ii) a mandatory ransomware / cyber-extortion payment disclosure regime requiring reporting business entities with annual turnover above AUD 3 million to notify the Australian Signals Directorate within 72 hours of any ransom payment made by or on behalf of the entity; (iii) a statutory Cyber Incident Review Board to conduct no-blame post-incident reviews of significant cyber incidents; and (iv) a "limited use" protection restricting how information voluntarily shared with the National Cyber Security Coordinator may be used by Commonwealth agencies. The Act implements core initiatives from the 2023-2030 Australian Cyber Security Strategy and affects every firm selling connected devices into Australia or operating above the turnover threshold in Australia.
The Seimas of the Republic of Lithuania adopted Law No. XIV-2985 on 26 September 2024, amending the Law on the Protection of Objects of Importance to Ensuring National Security (NSU Act), registered in the Teisės aktų registras (TAR) on 3 October 2024 and entering into force on 18 October 2024. The amendments expand the list of strategically important economic activities subject to FDI screening by the Commission for the Coordination of Protection of Objects of Importance to National Security to include the issuance of electronic money, electronic money tokens, asset-referenced tokens, and the provision of crypto-asset services (CASPs) as defined under EU MiCA Regulation 2023/1114, aligning Lithuania's screening perimeter with the EU crypto-assets regulatory framework. The law also refines core definitional concepts — "persons acting in concert," "controlling person," and "manager of critical information infrastructure" — to tighten beneficial-ownership and control analysis under the regime.
The Bureau of Industry and Security (BIS) finalized amendments to its Defense Priorities and Allocations System (DPAS) regulation at 15 CFR Part 700, originally proposed February 7, 2024. The final rule clarifies long-standing standards and procedures by which BIS provides Special Priorities Assistance (SPA) under the Defense Production Act of 1950, revises Schedule I to delineate Department of Commerce DPAS jurisdiction from other agencies' priority-rating authorities, and applies non-substantive technical edits reflecting updates since the regulation was last amended in 2014. The rule takes effect August 21, 2024.
Japan's National Diet enacted the Act on the Protection and Use of Critical Economic Security Information (重要経済安保情報の保護及び活用に関する法律, Act No. 27 of 2024) on 10 May 2024; it was promulgated on 17 May 2024 and came into full operation on 16 May 2025. The law establishes Japan's first peace-time economic-security clearance regime extending to private-sector employees. It designates "Critical Economic Security Information" (CESI) covering threat-intelligence on critical-infrastructure cyber attacks, regulatory-review information on essential infrastructure, and vulnerability data on critical-product supply chains; mandates Cabinet Office "適性評価" (suitability assessment) for cleared personnel; and imposes criminal penalties of up to five years' imprisonment for unauthorised disclosure. The CESI Act complements the 2022 Economic Security Promotion Act (ESPA), closing the information-protection gap and aligning Japan's framework with Five Eyes and EU partners for joint R&D and dual-use cooperation.
Latvia's Saeima adopted on 27 March 2024 amendments to the National Security Law (Nacionālās drošības likums), entering into force on 24 April 2024, that widen the perimeter of foreign-investment and ownership transactions subject to Cabinet of Ministers pre-clearance over "companies of significance to national security." The amendments expand the universe of regulated subjects beyond registered companies to include foundations and associations, tighten the rules on beneficial-ownership disclosure, and bring additional sensitive activities — energy security including LNG-terminal acquisitions, electronic communications, cybersecurity, and critical-raw-materials processing — under the regime, while clarifying Cabinet authority to impose conditions or unwind transactions retroactively. The law functions as Latvia's horizontal FDI-screening instrument under the EU-wide cooperation framework of Regulation 2019/452.
Bill C-34, the National Security Review of Investments Modernization Act, received Royal Assent on 22 March 2024 — the first major overhaul of the Investment Canada Act (ICA) national-security review regime since 2009. Non-regulatory provisions came into force on 3 September 2024 by Order Fixing P.C. 2024-826 (SI/TR-32, Canada Gazette Part II). The Act creates a pre-implementation filing obligation for investments in prescribed "sensitive sectors" (final list set by regulation), gives the Minister of Innovation new authority to extend reviews and impose interim conditions or accept undertakings without a Governor-in-Council order, raises monetary penalties, and establishes information-sharing authorities with allied screening regimes. ISED's updated NSR Guidelines (5 March 2025) elevate "economic security" to a standalone factor and align the prescribed-sector list with the Sensitive Technology List (STL).
Commission Recommendation (EU) 2024/779 of 26 February 2024, published in the Official Journal on 8 March 2024, establishes the EU's first dedicated policy framework for the security and resilience of submarine cable infrastructure. It creates an informal Submarine Cable Infrastructure Expert Group of Member State authorities chaired by the Commission with ENISA participation, introduces the Cable Projects of European Interest (CPEI) designation mechanism for priority Union funding, and mandates a consolidated Union-wide risk and vulnerability assessment culminating in a Cable Security Toolbox of mitigating measures. Scope covers cables, landing stations, terrestrial tail connections, repair centres, and cable-laying vessel capacity. The recommendation is non-binding under TFEU Article 292 but constitutes the foundational soft-law framework that the later 2025 Cable Security Action Plan (JOIN(2025) 9) operationalises with binding CPEI lists and €347M CEF Digital funding.
Bulgaria's National Assembly adopted on 22 February 2024 amendments to the Investment Promotion Act establishing the country's first horizontal foreign direct investment screening mechanism, published in State Gazette No. 20 on 8 March 2024 and entering into force on 12 March 2024. The regime implements EU Regulation 2019/452 by creating an Interdepartmental Screening Council with a 45-day decision window over non-EU investments meeting a 10 % equity stake or €2 million threshold in critical-infrastructure, dual-use, advanced-technology, media, and financial-infrastructure sectors, with no threshold for investments by Russian or Belarusian persons or in oil and petroleum activities. Non-compliance and false declarations carry fines of 5 % of investment value, with a minimum BGN 50,000.
The Significant Investments Review Act 2024 (Act No. 1 of 2024) is Singapore's first horizontal, cross-sector statutory FDI screening regime. The Bill was passed by Parliament on 9 January 2024, assented to by the President on 6 February 2024 and gazetted on 14 February 2024; the Act commenced on 28 March 2024 under the SIRA 2024 (Commencement) Notification (S 228/2024), together with the Significant Investments Review Regulations 2024 (S 229/2024). The Act creates an "ownership-and-control" layer over a limited number of "designated entities" the Minister for Trade and Industry has identified as critical to Singapore's national-security interests, plus an "any entity" call-in power exercisable against firms that have acted against Singapore's national-security interests, regardless of whether they are designated. Acquisitions of ≥5% require post-closing notification within 7 days; acquisitions of ≥12% / ≥25% / ≥50% and cessations of ≥50% / ≥75% controller status require prior ministerial approval. Administered by the Office of Significant Investments Review (OSIR) within MTI. SIRA is the Singaporean structural peer of US CFIUS, EU Regulation 2019/452, the German AWG §§55-62, the French Décret 2014-479, the UK NSI Act 2021, the Netherlands Wet Vifo, and the Canada ICA national-security review.