Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
President Trump signed a Section 232 proclamation on 13 August 2026 (published in the Federal Register 19 August 2026, FR doc 2026-16979) imposing tariffs on unmanned aircraft systems (UAS/drones) and components, following a Commerce Department finding that US reliance on foreign-produced (chiefly Chinese, e.g. DJI/Autel) drones and critical components creates supply-chain and cybersecurity national- security risk. A 100% ad valorem tariff applies to Annex I items (drones with maximum takeoff weight over 25kg, thermal-imaging drones, docking stations, and listed critical components); a 25% ad valorem tariff applies to Annex II items (other listed UAS). Qualifying-origin content from the EU, Japan, Korea, Switzerland, Taiwan and Liechtenstein is capped at 15%; UK-origin content is capped at 10%. UAS duties take effect 3 September 2026; component duties take effect 9 February 2027. The proclamation also authorizes Commerce to set up an onshoring program giving temporary relief to firms committing to build or expand US production of covered drones and components.
On 1 April 2026, Prime Minister Takaichi Sanae and President Emmanuel Macron held a Tokyo summit and signed a bilateral roadmap on cooperation in critical minerals — the first formal Japan-France instrument on supply-chain resilience for rare earths and other critical materials. The centrepiece is joint government support for Caremag, a heavy rare-earths refining project in southern France due to begin operations in late 2026, with backing from Japan Organization for Metals and Energy Security (JOGMEC), Iwatani Corporation, and the French government; the project targets approximately 20% of Japan's future demand for dysprosium and terbium (heavy rare-earth oxides used in EV motors, offshore-wind turbines, and electronic components). The two leaders also launched parallel high-level dialogues on dual-use AI, quantum technologies, space (including debris mitigation), cybersecurity, and a joint declaration on startups and innovation, expressing "serious concerns" over export controls on critical minerals and other materials affecting global supply chains — an explicit reference to China's tightening rare-earths export regime.
The Department of Commerce's International Trade Administration published a Federal Register notice on 10 April 2026 (91 FR 18412, doc 2026-06952) opening the inaugural Call for Proposals for the American AI Exports Program established under Executive Order 14320. Proposals are accepted from 1 April 2026 through 5:00 pm EDT on 30 June 2026 from US industry-led "pre-set" consortia offering full-stack American AI export packages — AI-optimised hardware, data pipelines, AI models and systems, security and cybersecurity measures, and sector-specific applications — for presentation by the US government to foreign public- and private-sector buyers. Designated consortia receive priority US-government advocacy, priority consideration for export-control licence engagement, interagency coordination, and federal-financing referrals (EXIM, DFC), with a 14-business-day completeness review and 60-calendar-day designation decision once a proposal is deemed complete.
Premier Li Qiang signed State Council Order No. 834 on 31 March 2026 promulgating the "Provisions on Industrial Chain and Supply Chain Security" (18 articles), adopted at the State Council executive meeting on 13 March 2026 and effective on the date of publication. The Provisions are the first dedicated PRC administrative regulation on industrial- and supply-chain security and consolidate authorities drawn from the National Security Law, Foreign Relations Law, Anti-Foreign Sanctions Law, and Foreign Trade Law into a horizontal defensive framework. They establish a cross-agency coordination mechanism spanning roughly 15 central departments (industrial, security, cyberspace, customs and financial regulators) plus provincial governments; create a security-investigation system; and vest broad countermeasure authority over both foreign states (Article 14 — import/export prohibitions and special levies) and foreign organisations and individuals (Article 15 — import/export bans, China-investment bars, transaction prohibitions, entry bars and revocation of work or residence permits, with extension to effectively-controlled subsidiaries). The Provisions also impose compliance, information-sharing, strategic-reserve and emergency-response obligations on PRC organisations and individuals, and authorise requisition, mandated production and directed transportation in the event of supply-chain disruption.
South Korea's 13th National Strategic Technology Special Committee (chaired by MSIT) adopted the 2026 Annual Implementation Plan for the First Basic Plan for National Strategic Technology Development (2024–2028), committing KRW 8.6 trillion in 2026 R&D investment — a ~30% YoY increase from KRW 6.5 trillion in 2025 — across 19 NEXT strategic-technology fields encompassing AI, semiconductors, quantum, displays, and secondary batteries, coordinated across 23 ministries. The plan is supplemented by KRW 46.6 trillion in policy finance delivered through Korea Development Bank (KDB), Industrial Bank of Korea (IBK), Korea Credit Guarantee Fund (KCGF), and Korea Technology Finance Corporation (KOTEC), providing the horizontal funding-coordination architecture that operationalises all sector-specific Korean strategic-technology legislative instruments.
On 17 February 2026, Prime Minister Mark Carney launched Canada's first standalone Defence Industrial Strategy (DIS), introducing the "Build–Partner–Buy" framework as the central guiding principle of Canadian defence procurement. The strategy mobilises over half a trillion CAD across the next decade — including ~CAD 180 bn in defence procurement opportunities, ~CAD 290 bn in defence-related capital investment, and ~CAD 125 bn in anticipated downstream economic benefit by 2035 — and targets 125,000 new high-paying jobs. Operationally, the DIS introduces Canadian Content Value (CCV) requirements with a proposed Canadian Company Boost for firms meeting 70–100% domestic-content thresholds, sets a 10-year goal of awarding 70% of defence procurements to Canadian firms, and signals willingness to invoke the national security exception to set aside trade-agreement obligations and exclude foreign bidders for "sovereign capability" contracts. It is the first standalone industrial-strategy document covering the Canadian defence-industrial base, distinct from prior DPA-narrow filings.
The European Investment Fund (EIF), part of the EIB Group, announced on 9 February 2026 an anchor investment of EUR 300 million (~USD 354.8 million) in Seaya Growth Tech Fund I, a Spain-based pan-European growth venture capital vehicle targeting a EUR 1 billion final close. The commitment is made under the European Tech Champions Initiative (ETCI), and the fund will make growth-stage (Series C+) equity investments in European companies across applied AI, deep-tech, fintech, climate solutions, smart manufacturing, supply-chain resilience, capital-market autonomy, cybersecurity and environmental technology. Global Trade Alert separately logs the transaction as a "red"-flagged state-linked financial-investment-support intervention.
On 29 January 2026, the Council of the European Union adopted Council Implementing Regulation (EU) 2026/267 and the accompanying Council Decision, implementing the EU's Iran human-rights restrictive-measures regime (Regulation (EU) No 359/2011, in place since 2011 and renewed annually). The package designates 15 individuals and 6 entities over the violent repression of peaceful protests, arbitrary detention, and internet/media censorship in Iran, bringing the regime's cumulative total to 24 individuals and 26 entities. The six newly listed entities are the Iranian Audio-Visual Media Regulatory Authority (SATRA), the IRGC-linked Seraj Cyberspace Organization, the Working Group for Determining Instances of Criminal Content (WGDICC), Yaftar Pazhohan Pishtaz Rayanesh Limited Company, Douran Software Technologies, and Masaf Institute. Designated parties are subject to an EU-wide asset freeze and a prohibition on making funds or economic resources available to them; listed individuals additionally face a travel ban.
The European Investment Bank signed guarantee agreements with Banco Santander totalling EUR 450 million on 29 January 2026, announced by EIB Group President Nadia Calviño during the Group's results presentation in Brussels. The guarantees are expected to unlock around EUR 900 million in new supply-chain financing for European companies: EUR 400 million for security-and-defence manufacturers (cybersecurity, surveillance, resilience and defence-technology suppliers) under the EIB's EUR 3 billion pan-European intermediated financing instrument for the defence industrial base, and EUR 500 million for companies in clean technologies, telecommunications and digital infrastructure via reverse-factoring supply-chain-finance instruments. Santander is reported as the fourth major European bank to sign under the defence-supply-chain programme, and the clean-tech/digital tranche contributes to the EIB Group's TechEU initiative.
On 29 January 2026, European Council President António Costa and Vietnamese Prime Minister Phạm Minh Chính signed a Joint Statement in Hanoi upgrading EU-Vietnam bilateral relations to a Comprehensive Strategic Partnership (CSP) — the highest tier in Vietnam's diplomatic hierarchy, placing the EU on the same level as Vietnam's CSPs with China, Russia, India, South Korea, Japan, Australia, France, and the United States. The CSP establishes a reinforced bilateral cooperation framework spanning critical raw materials, semiconductor supply chains, artificial intelligence, trusted 5G infrastructure, climate and energy transition, security and defence (including cyber and maritime), and full implementation of the 2019 EU-Vietnam Free Trade Agreement (EVFTA) tariff-elimination schedule plus ratification of the EU-Vietnam Investment Protection Agreement (EVIPA). It is the EU's eleventh CSP globally and its second in Southeast Asia (after Singapore, 2024), and constitutes the foundational bilateral parent framework for all future EU-Vietnam cooperation under the EU Critical Raw Materials Act (CRMA) Article 13 third-country strategic-project designation pipeline, given Vietnam's approximately 22 Mt rare-earth reserves — the world's second-largest deposit after China.
Taiwan's Legislative Yuan passed the Artificial Intelligence Basic Act (人工智慧基本法) on third reading on 23 December 2025, and President Lai Ching-te promulgated the 20-article statute on 14 January 2026, bringing it into force immediately. The Act designates the National Science and Technology Council (NSTC) as the central AI-policy competent authority and codifies seven governance principles — sustainability and well-being, human autonomy, privacy protection and data governance, cybersecurity and safety, transparency and explainability, fairness and non-discrimination, and accountability — that apply to all public-sector AI procurement and high-risk sectoral applications. The statute establishes a statutory foundation for the Taiwan AI Action Plan 2.0, mandates an Executive Yuan National AI Strategy Committee, and provides authority for sector-specific implementing regulations by FSC, NCC, MOHW, and MOTC across finance, telecoms, medical, and autonomous-vehicle AI within a two-year window. As the first national AI governance statute in the Greater China region and the third globally after the EU AI Act and South Korea's AI Basic Act, it frames regulatory expectations for the companies at the heart of the global AI hardware supply chain — TSMC, NVIDIA ODM partners, and advanced-packaging incumbents — that are headquartered or operate substantially in Taiwan.
The European Investment Bank agreed to lend up to EUR 870 million to Nokia to accelerate research and development of next-generation mobile network technologies (5G-Advanced and 6G radio access network hardware and software). The facility is structured in two tranches of EUR 435 million each: the first was signed in December 2025, with the second expected to be signed in mid-2026. The financing is delivered under the EIB's TechEU initiative and backed by an InvestEU guarantee, explicitly framed around EU strategic autonomy in mobile-network technology and support for EU security and defence objectives given the cybersecurity features of the radio networks involved.
Vietnam's National Assembly passed Law on Cybersecurity No. 116/2025/QH15 on 10 December 2025 (434 of 443 deputies in favour), effective 1 July 2026. The law supersedes both the 2018 Cybersecurity Law (Law 24/2018/QH14) and the 2015 Law on Cyber Information Security, consolidating cybersecurity, cyber-information-security, and network-information-security into a unified Ministry of Public Security-led framework. It retains data-localization obligations for foreign digital-service providers handling personal data, user-generated content, and relationship graphs of Vietnamese users (minimum 24-month retention), introduces 6-hour urgent / 24-hour standard content take-down windows on MPS request, expressly prohibits AI/deepfake forgery of images, voices, and videos for illegal purposes, and mandates child-safety platform measures.
The UK Foreign, Commonwealth & Development Office designated two China-based commercial cyber companies — Sichuan Anxun Information Technology Co Ltd (known as i-Soon) and Integrity Technology Group Incorporated — under the UK's Cyber sanctions regime, freezing their UK assets and imposing controls on commercial transactions and investment instruments involving them. i-Soon was designated for targeting over 80 government and private-sector IT systems worldwide, including UK public-sector and private-industry networks. Integrity Tech was designated for operating a covert botnet of more than 260,000 compromised devices globally and supplying access to it to enable unauthorised intrusion into UK public-sector systems.
On 19 November 2025, the U.S. Treasury's Office of Foreign Assets Control (OFAC), in a coordinated action with Australia's Department of Foreign Affairs and Trade and the UK's Foreign, Commonwealth and Development Office, designated 5 individuals and 7 companies linked to two Russia-based "bulletproof hosting" (BPH) providers, Media Land and Aeza Group, under Executive Order 13694. Media Land and its subsidiaries (Media Land Technology, Data Center Kirishi, ML Cloud) supplied server infrastructure to ransomware groups including LockBit, BlackSuit and Play. The designations also targeted three companies Aeza Group used to evade its July 2025 OFAC designation and rebrand its infrastructure: Hypercore Ltd. (United Kingdom), Smart Digital Ideas DOO (Serbia), and Datavice MCHJ (Uzbekistan). All designated persons' U.S.-nexus assets are blocked and U.S. persons are prohibited from transacting with them.
Israel's Minister of Defense signed an order on 18 November 2025 revoking the Order Governing the Control of Commodities and Services (Engagement in Encryption Items) of 1974, with effect on 21 March 2026 (four-month implementation period). The 51-year-old standalone Encryption Order regime — which licensed both civilian and defense-grade encryption items through a parallel Ministry of Defense track — is replaced by a unified architecture in which defense-grade dual-use items move to the Defense Export Controls Agency (DECA) at the Ministry of Defense, and civilian dual-use items (Wassenaar list) move to the Export Control Agency (ECA) at the Ministry of Economy and Industry. Many B2C consumer products with embedded encryption are decontrolled outright; B2B / commercial products remain controlled but under DECA or ECA rather than the legacy Encryption Order regime.
Cyprus Law 194(I)/2025 "The Establishment of a Framework for the Screening of Foreign Direct Investments Law of 2025" was enacted by the House of Representatives and published in the Official Gazette on 14 November 2025, entering into force on 2 April 2026. It establishes Cyprus's first-ever mandatory pre-approval FDI screening regime, designating the Ministry of Finance as the competent Screening Authority and applying to non-EU/EEA/Swiss investors acquiring ≥25% equity or voting rights in Cyprus entities valued at ≥€2 million across covered strategic sectors. The regime implements EU Regulation 2019/452 and includes a Cyprus-specific sectoral extension covering tourism and real estate — addressing golden-passport-era concerns about non-EU capital flows into the island's financial and hospitality economy.
Germany's transposition of EU Directive 2022/2555 (NIS2), enacted as the "Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung." Bundestag passage 13 November 2025; Bundesrat approval 21 November 2025; published as BGBl. I 2025 Nr. 301 on 5 December 2025; entered into force 6 December 2025. The statute designates the Bundesamt für Sicherheit in der Informationstechnik (BSI) as the central national supervisory authority over an estimated 29,500 covered entities across 18 critical and important sectors, introduces a mandatory 24h initial / 72h detailed / 1-month final cyber-incident reporting cascade, establishes board-level personal liability for senior management, and applies to SME critical- infrastructure suppliers — with no transitional grace period from entry into force.
Canada made SOR/2025-228, Regulations Amending the Special Economic Measures (Russia) Regulations, registered 2025-11-06 and announced by Minister Anand on 2025-11-12. The regulations add 13 individuals to Part 1 of Schedule 1, 11 entities to Part 2 of Schedule 1, and 100 vessels (by IMO number) to Schedule 1.1, freezing their Canadian assets and prohibiting dealings. Targets include Russian LNG-trading entities, drone-programme developers, cyber-infrastructure suppliers for hybrid operations against Ukraine, and Kyrgyzstan-based financial enablers (including Capital Bank of Central Asia and the A7 payments platform) used to evade earlier Russia sanctions. The 100-vessel designation targets Russia's "shadow fleet" used to move crude oil, LNG and arms while evading the G7 price cap and flag-state controls.
The European Investment Fund (EIF), part of the EIB Group, invested EUR 20 million (~USD 23.1 million) on 6 November 2025 in TIN Capital's European Cyber Tech Fund V, a growth-equity vehicle backing European cybersecurity scale-ups. EIF's participation is supported under the European Commission's InvestEU programme; alongside Invest-NL and private investors, the fund closed at over EUR 80 million. The EIF frames the investment as strengthening Europe's digital security and autonomy amid incoming EU cybersecurity regulation (NIS2, the Cybersecurity Act, DORA). Global Trade Alert separately logs the transaction as a "red"-flagged state-linked financial investment-support intervention.
On 29 October 2025, during the Future Investment Initiative (FII9) in Riyadh, Saudi Arabia's Local Content & Government Procurement Authority (LCGPA) and the PIF-owned Saudi Information Technology Company (SITE) signed an agreement launching "Phase One" of national adoption of localised cybersecurity technologies. The agreement commits more than 15 Saudi government entities to source cybersecurity products — Rakeen NGFW (next-generation firewalls), Rakeen IPS (intrusion-prevention systems) and Rakeen XDR (extended detection and response) — from Rakeen Cybersecurity, a SITE subsidiary established to localise these technologies domestically. The signing was attended by the Minister of Industry and Mineral Resources and LCGPA board chairman Bandar Al-Khorayf, PIF Governor Yasir Alrumayyan, and National Cybersecurity Authority (NCA) Governor Majed Almazyed.
FinCEN issued a final rule under Section 311 of the USA PATRIOT Act (31 U.S.C. § 5318A) prohibiting US covered financial institutions from opening or maintaining a correspondent account for, or on behalf of, Cambodia-based Huione Group, a foreign financial institution found to be of primary money-laundering concern. Treasury determined that Huione Group and its subsidiaries — including Haowang Guarantee, Huione Pay PLC, and Huione Crypto — laundered at least $4 billion of illicit proceeds between August 2021 and January 2025, including funds tied to North Korean cyber-heist actors and Southeast Asian "pig-butchering" investment-scam compounds. The rule also imposes a special-due-diligence requirement on US covered institutions to guard against indirect access via foreign correspondent accounts. Effective November 17, 2025.
Italy enacted Legge 23 settembre 2025, n. 132 — "Disposizioni e deleghe al Governo in materia di intelligenza artificiale" — published in Gazzetta Ufficiale Serie Generale n. 223 of 25 September 2025 (atto 25G00143) and entered into force on 10 October 2025. The statute makes Italy the first EU member state to enact a comprehensive national AI law complementing Regulation (EU) 2024/1689 (EU AI Act), designating AgID (Agency for Digital Italy) and ACN (National Cybersecurity Agency) as national oversight authorities under Presidency-of-the-Council-of-Ministers coordination. It sets sectoral rules for healthcare, labour, intellectual professions, public administration and the judiciary; authorises up to €1 billion in state-backed venture capital (via CDP Venture Capital) for AI, cybersecurity and telecoms; creates criminal penalties of up to five years' imprisonment for harmful deepfakes; mandates parental consent for under-14 users; and delegates secondary legislation to the Government across multiple domains.
On 19 September 2025, the European Investment Fund (EIF), part of the European Investment Bank Group, signed a EUR 260 million (USD ~305 million) anchor-investor commitment into Jolt Capital V, a growth-stage deep-technology venture capital fund targeting a EUR 1 billion final close. The commitment is funded largely through the European Tech Champions Initiative (ETCI), an EU-backed programme that has committed over EUR 2.5 billion across 11 scale-up technology funds and aims to mobilise EUR 10 billion in total resources for late-stage European tech companies. Jolt Capital V will invest in growth-stage B2B companies across semiconductors, cybersecurity, AI, industry 4.0, new materials and mobility, sectors the EIB Group frames explicitly around European strategic autonomy and competitiveness.
New Zealand's 32nd sanctions round under the Russia Sanctions Act 2022 (Russia Sanctions Amendment Regulations (No 4) 2025, SL 2025/195) lowered the price cap on Russian-origin crude oil (HS 2709) from US$60/bbl to US$47.60/bbl, a roughly 21% cut, aligning New Zealand with the EU, UK and Canada's most recent price-cap reductions. The same instrument designated 19 individuals and entities plus 19 vessels, including Russia's GRU cyber unit 29155 (implicated in malware attacks on Ukrainian government networks), actors involved in chemical-weapons use and disinformation, additional "shadow fleet" tankers, alternative payment providers, and third-country facilitators based in North Korea and Iran supporting Russia's war effort.
On 8 September 2025, the UK Ministry of Defence published the Defence Industrial Strategy 2025 — "Making Defence an Engine for Growth" (CP 1388) — the first comprehensive cabinet-level UK defence industrial strategy in over a decade and the sector plan for Defence under the UK Modern Industrial Strategy umbrella (IS-8). The strategy was published alongside the Strategic Defence Review 2025 and operationalises the largest sustained defence- spending increase since the Cold War (rising to 2.6% of GDP by 2027 with ambition to 3% in the next Parliament). It defines six priority outcomes (growth, backing UK businesses, defence innovation, resilient industrial base, procurement transformation, enduring partnerships); establishes UK Defence Innovation (UKDI) within the MOD with a ringfenced £400m budget to accelerate dual-use technology; identifies priority defence capabilities (combat air, complex weapons, directed-energy weapons, next- generation land and maritime systems) plus dual-use sub-sectors (quantum, drones/autonomy, space, AI, cyber, engineering biology, advanced connectivity); and flags resilience priorities in steel, construction, energetic materials, batteries, semiconductors and rare earths.
On 8 September 2025, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated 19 targets — companies and individuals based in Burma (Myanmar) and Cambodia — for operating or supporting networks of scam compounds that defraud Americans through virtual-currency investment fraud ("pig butchering") schemes. Nine targets operate out of Shwe Kokko, Burma, a scam-compound hub under the protection of the OFAC-designated Karen National Army (KNA), and ten targets are based in Cambodia, including Heng He Bavet's casino-linked complex in Bavet. Designations were made pursuant to Executive Order 13581 (transnational criminal organizations) and, for the Burma-based Shwe Myint Thaung Yinn Industry & Manufacturing Company, also under Executive Order 14014 (Burma sanctions program) as an entity acting on behalf of designated individual Tin Win. Treasury cited a U.S. government estimate that Americans lost over $10 billion in 2024 to Southeast Asia-based scam operations, a 66% increase over the prior year. All U.S.-nexus property of designated persons is blocked and U.S. persons are prohibited from transacting with them.
On 14 August 2025 OFAC re-designated the cryptocurrency exchange Garantex Europe OU under its cyber authority (E.O. 13694, as amended) for processing over USD 100 million in transactions tied to ransomware and darknet-market actors since 2019, and designated its successor exchange Grinex — created by former Garantex staff to move customer deposits and continue operations after a March 2025 US Secret Service-led takedown of Garantex's infrastructure. OFAC also designated three Garantex executives, the A7A5 ruble-backed stablecoin issuer Old Vector (Kyrgyzstan), and Russian settlement-platform firm A7 and its subsidiaries A71 and A7 Agent — entities linked to sanctioned Moldovan oligarch Ilan Shor and sanctioned Promsvyazbank — for supplying the A7A5 token used to compensate Garantex customers and route funds through Grinex.
The FCC adopted a Report and Order (FCC 25-49) on 7 August 2025 — the first comprehensive overhaul of submarine cable landing license rules since 2001 — effective 26 November 2025. The order prohibits Indefeasible Right of Use (IRU) agreements that would give entities from designated foreign adversary countries (China including Hong Kong and Macau, Cuba, Iran, DPRK, Russia, and Venezuela) control over Submarine Line Terminal Equipment (SLTE) on US cable landings, and mandates new annual reporting plus certification/disclosure requirements covering ownership, cybersecurity and physical security plans, and FCC Covered List compliance. The order operationalises the FCC's bifurcated policy package: accelerating legitimate commercial cable buildout while hardening national-security review for foreign-adversary-connected infrastructure.
Czech Act No. 265/2025 Sb., promulgated in the Sbírka zákonů on 4 August 2025 and entering into force on 1 November 2025, is the first material amendment of the Czech Republic's foundational FDI screening statute (Act No. 34/2021 Sb.) since its enactment. The amendment broadens the perimeter of mandatory pre-closing FDI screening by cross-referencing the simultaneously-enacted Cybersecurity Act (Act No. 264/2025 Sb., transposing NIS2 Directive 2022/2555): entities designated as providers of "regulated services" under the Cybersecurity Act's "regime of higher obligation" automatically fall within mandatory FDI-screening scope, extending screening reach beyond the prior military-material / dual-use / critical-infrastructure perimeter to cover a broad sweep of digital, technology, healthcare, energy, and financial-services operators. The amendment also adds a confidentiality-sharing channel between MPO and NÚKIB, enabling coordinated supply-chain-security assessments for high-risk-vendor reviews under the new Cybersecurity Act.
Italy's Ministry of Enterprises and Made in Italy (MIMIT) signed a decree ("Disciplina degli interventi di sostegno alla domanda di servizi di cloud computing e cyber security") on 18 July 2025 establishing a EUR 150 million fund, drawn from FSC 2014-2020 resources, to subsidize SME and self-employed purchases of cloud computing and cybersecurity services nationwide. Beneficiaries receive a non-repayable grant covering up to 50% of eligible expenses, capped at EUR 20,000 per beneficiary, conditional on holding a connectivity contract of at least 30 Mbps download speed. Supplier registration (a prerequisite for the voucher's use) was originally set to close 23 April 2026 and was later extended to 27 May 2026; beneficiary application procedures follow once the authorized-supplier list is formed.
The French government, sole shareholder of state-owned IN Groupe, backed IN Groupe's acquisition of IDEMIA Smart Identity (ISI) with a capital increase, completed 2025-07-01. The deal — IN Groupe's largest since its creation, with press estimates as high as EUR 1 billion though terms were not officially disclosed — creates a combined entity with over 4,000 employees and consolidated turnover above EUR 1 billion, making IN Groupe the world's largest provider of physical/digital identity cards and second-largest passport provider. The Ministry framed the operation as building a "global champion" in identity documents to secure French/ European sovereignty over the identity and biometrics value chain.
On 1 July 2025, the U.S. Treasury's Office of Foreign Assets Control (OFAC) designated Aeza Group, a St. Petersburg, Russia-based "bulletproof hosting" (BPH) provider, along with two affiliated companies and four Aeza Group leaders (Arsenii Penzev, Yuri Bozoyan, Vladimir Gast, Igor Knyazev), for supplying server infrastructure that shielded ransomware operators, infostealer groups, and darknet drug marketplaces from law-enforcement takedown. In coordination with the UK's National Crime Agency, OFAC also designated Aeza International Ltd., a UK front company Aeza used to lease IP addresses to cybercriminals. The action was taken under Executive Order 13694 (as amended by E.O. 14144 and E.O. 14306) and builds on OFAC's February 2025 designation of BPH provider ZServers.
On 25 June 2025 the European Commission adopted COM(2025) 335 final, a proposed Regulation establishing a single market for space activities — the first EU-level framework harmonising the authorisation, registration and supervision of space activities across Member States, replacing 13 fragmented national regimes. The Act rests on three pillars: safety (mandatory tracking of space objects, space- debris mitigation rules, an EU registry of space objects), resilience (cybersecurity requirements scaled to company size and risk profile) and sustainability (environmental impact assessment and active debris-removal R&D). It applies to both EU and non-EU operators providing space services in Europe, giving it extraterritorial reach over SpaceX/Starlink, Amazon Kuiper, OneWeb, Chinese SatNet/G60 and ISRO. The proposal is being negotiated under the ordinary legislative procedure; the Competitiveness Council of 9 December 2025 broadly endorsed its objectives, and the public consultation closed on 7 November 2025.
On 18 June 2025 the European Investment Bank (EIB) and the BPCE banking group signed a EUR 300 million loan agreement to expand financing available to French small and medium-sized enterprises (SMEs) active in the security and defence supply chain, delivered through BPCE's Banque Populaire and Caisse d'Epargne networks. It is the first such operation the EIB has signed in France, and the second in Europe, under the EIB's Pan-EU Security & Defence Lending Envelope, which was expanded from EUR 1 billion to EUR 3 billion earlier in 2025 (a first tranche was signed with Deutsche Bank in Germany the preceding week). Funds are earmarked for SMEs investing in cybersecurity, surveillance, resilience, and defence technologies.
The European Investment Fund (EIF), part of the EIB Group, and the European Commission announced a EUR 40 million (~USD 45.2 million) investment in Keen Venture Partners' European Defence and Security Tech Fund on 22 May 2025. The commitment is made under the InvestEU Defence Equity Facility (DEF), a EUR 175 million joint instrument (EUR 100 million from the European Defence Fund plus EUR 75 million from the EIF) created to close the equity-financing gap for early-stage European defence and dual-use technology companies through 2027. The Keen fund targets a final size of EUR 125 million and plans to back 20-25 early-stage startups across European NATO countries working on information superiority, cyber defence, robotics, AI, autonomous systems and space technologies. Global Trade Alert separately logs the transaction as a "red"-flagged state-linked financial-investment-support intervention.
Greece enacted Law 5202/2025 on 22 May 2025, published in Government Gazette ΦΕΚ A' 84 on 23 May 2025 and effective the same day, establishing the country's first national mandatory and suspensory foreign direct investment screening mechanism, aligned with Regulation (EU) 2019/452. The Interministerial Committee for the Control of Foreign Direct Investment (ICC-FDI), with initial procedure run by the Ministry of Foreign Affairs, reviews non-EU acquisitions in "sensitive" sectors (energy, transportation, healthcare, ICT, digital infrastructure) and "particularly sensitive" sectors (national security, defence, cybersecurity, AI, ports and critical subsea infrastructure, borderland tourism). A two-phase review applies — 30 days Phase I, up to 150 days Phase II with EU Cooperation Mechanism notification — and the regime became fully operational on 11 November 2025.
On 20 May 2025, the Council of the European Union adopted Council Implementing Regulation (EU) 2025/965 and Council Decision (CFSP) 2025/966, implementing the EU's dedicated hybrid-threats restrictive- measures regime (Regulation (EU) 2024/2642) rather than the sectoral Russia sanctions track. The package designates 21 individuals and 6 entities for enabling Russian state-sponsored destabilising activity, including information manipulation and interference and cyberattacks against the EU and its partners. Named entities include Stark Industries Solutions Ltd (UK-registered "bulletproof" web-hosting provider used as infrastructure for Russian cyberattacks) and its owner/CEO Ivan and Iurie Neculiti, Czech-based pro-Kremlin media outlet Voice of Europe, and Turkish media company AFA Medya and its founder Hüseyin Doğru. Designated parties are subject to an EU-wide asset freeze and prohibition on making funds available; designated individuals additionally face a travel ban. This is a distinct legal instrument from the same-day 17th Russia sectoral sanctions package (Regulation (EU) 2025/932/933), adopted under the separate hybrid- threats horizontal regime.
The Legislative Yuan of Taiwan (ROC) passed amendments to Article 10-1 of the Statute for Industrial Innovation (產業創新條例) on third reading on 18 April 2025, promulgated by Presidential Decree on 7 May 2025 and effective for qualifying expenditures incurred from 1 January 2025. The amendment expands the scope of the existing Article 10-1 investment tax credit — previously covering hardware, software, technology, or technical services for smart machinery, 5G network deployment, and cybersecurity — to additionally cover (i) AI products or services and (ii) energy-conservation and carbon-reduction initiatives. The maximum eligible expenditure cap per company per taxable year is doubled from NT$1bn to NT$2bn, and the implementation period is extended through 31 December 2029. Secondary legislation operationalising the amended categories was jointly issued by MOEA and MOF on 27 November 2025 as the "Regulations Governing Tax Credits Claimed for Investments in Smart Machinery, 5G Networks, Cybersecurity, Artificial Intelligence (AI) Products or Services, and Energy Conservation and Carbon Reduction." This is Taiwan's first AI-and-green-tech investment tax credit mechanism in the general-industrial framework, distinct from Article 10-2 (the chip-specific R&D + advanced-equipment credit, "Taiwan Chips Act").
China's MOFCOM Unreliable Entity List Working Mechanism designated six US firms on 9 April 2025, effective 12:01 Beijing time 10 April 2025, under MOFCOM Order No. 4 of 2020. Cited trigger: participation in arms sales to Taiwan or military-technology cooperation with Taiwan in disregard of China's stated opposition, "seriously harming China's national sovereignty, security and development interests." Measures prohibit the six entities from import/export activities related to China, new investments in China, and impose entry/work-permit restrictions on senior management.
On 27 February 2025, the Parliament of the Republic of Moldova adopted Law No. 33/2025 amending Law No. 174/2021 on the mechanism for examining investments of importance for state security. The law entered into force on 20 April 2025 after publication in Monitorul Oficial Nr. 144-147 of 20 March 2025 (promulgated by Presidential Decree No. 118-X of 17 March 2025). Key operative changes expand the protected-sector perimeter to explicitly enumerate 17 categories covering data processing and storage, AI, robotics, cybersecurity, semiconductors, quantum, nanotechnology and biotechnology alongside the pre-existing energy, transport, communications, defence and aerospace pillars; add new grounds for refusal (money-laundering suspicion, corruption convictions, foreign-government control, cybersecurity risk, access to personal data of citizens); introduce enhanced Council powers including retroactive review of previously approved investments and fines of up to 5% of annual turnover (capped at MDL 5 million); and carve out intra-group transactions, asset sales below EUR 1 million, and state-owned-enterprise dealings. The Screening Council became operational in July 2025.
Japan's National Diet enacted the Cyber Response Capability Enhancement Act (重要電子計算機に対する不正な行為による被害の防止に関する法律, Law No. 42 of 2025) on 16 May 2025, together with companion arrangement legislation. Commonly known as the Active Cyber Defense (ACD) Law, the statute authorises (i) government monitoring of foreign-origin internet traffic transiting designated Japanese communication infrastructure for national-security threat indicators, (ii) pre-emptive access and neutralisation operations against attacker infrastructure abroad by the National Police Agency and the Self-Defense Forces under unified command, and (iii) mandatory cyber-incident reporting and government cooperation duties on critical-infrastructure operators. Implementation is phased through November 2027, with the NISC reorganised into the National Cybersecurity Office (NCO) under the Cabinet Secretariat from July 2025.
Regulation (EU) 2025/38 of the European Parliament and of the Council of 19 December 2024 lays down measures to strengthen solidarity and capacities in the Union to detect, prepare for, and respond to cyber threats and incidents, and amends Regulation (EU) 2021/694 (Digital Europe Programme). Published in the Official Journal on 15 January 2025; entered into force on 4 February 2025 (20 days after OJ publication). The regulation establishes (i) a European Cybersecurity Alert System composed of national and cross-border Security Operations Centre (SOC) hubs interconnected EU-wide, (ii) a Cybersecurity Emergency Mechanism funded through the Digital Europe Programme, (iii) an EU Cybersecurity Reserve of trusted private-sector incident-response providers, and (iv) an ENISA-led post-incident review mechanism for significant or large-scale cybersecurity incidents. It complements the Cyber Resilience Act (Reg 2024/2847) and the NIS2 Directive as the third leg of the EU horizontal-cybersecurity stack.
By Government Decision No. 1533 of 27 November 2024 (published in the Official Monitor No. 1232 of 9 December 2024), the Government of Romania adopted the National Strategy for the Defence Industry 2024-2030. The strategy commits Romania to a 2.5%-of-GDP defence budget through 2030 with 35% earmarked for equipment procurement, sets ten sectoral objectives spanning powders/explosives, munitions, armoured vehicles, naval and aeronautical production, military C4I/cybersecurity, SME advancement, R&D, and a regulatory framework for autonomous combat vehicles and loitering munitions, and invokes Article 346 TFEU to anchor industrial-participation cooperation between foreign primes and national industry. A flagship target is domestic production of two million artillery projectiles per year by 2030.
Regulation (EU) 2024/2847 of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, signed 23 October 2024 and entering into force 10 December 2024. The CRA is the first EU statutory cybersecurity regime covering all hardware and software products with a direct or indirect data connection placed on the EU market, imposing essential cybersecurity requirements, conformity assessment with CE marking, mandatory vulnerability handling, and 24-hour early-warning notification of actively-exploited vulnerabilities to ENISA. Main manufacturer obligations apply from 11 December 2027; conformity-assessment-body notification provisions apply from 11 June 2026 and reporting obligations from 11 September 2026. Penalties reach EUR 15M or 2.5% of global annual turnover.
Australia's first standalone cyber-security statute (Act No. 98 of 2024), passed by Parliament on 25 November 2024 and granted Royal Assent on 29 November 2024, with provisions commencing in tranches through 30 May 2025. The Act creates four binding regimes: (i) mandatory security-of-things standards for connected and IoT products supplied in Australia under regulations administered by the Department of Home Affairs; (ii) a mandatory ransomware / cyber-extortion payment disclosure regime requiring reporting business entities with annual turnover above AUD 3 million to notify the Australian Signals Directorate within 72 hours of any ransom payment made by or on behalf of the entity; (iii) a statutory Cyber Incident Review Board to conduct no-blame post-incident reviews of significant cyber incidents; and (iv) a "limited use" protection restricting how information voluntarily shared with the National Cyber Security Coordinator may be used by Commonwealth agencies. The Act implements core initiatives from the 2023-2030 Australian Cyber Security Strategy and affects every firm selling connected devices into Australia or operating above the turnover threshold in Australia.
The Seimas of the Republic of Lithuania adopted Law No. XIV-2985 on 26 September 2024, amending the Law on the Protection of Objects of Importance to Ensuring National Security (NSU Act), registered in the Teisės aktų registras (TAR) on 3 October 2024 and entering into force on 18 October 2024. The amendments expand the list of strategically important economic activities subject to FDI screening by the Commission for the Coordination of Protection of Objects of Importance to National Security to include the issuance of electronic money, electronic money tokens, asset-referenced tokens, and the provision of crypto-asset services (CASPs) as defined under EU MiCA Regulation 2023/1114, aligning Lithuania's screening perimeter with the EU crypto-assets regulatory framework. The law also refines core definitional concepts — "persons acting in concert," "controlling person," and "manager of critical information infrastructure" — to tighten beneficial-ownership and control analysis under the regime.
The Bureau of Industry and Security (BIS) amended the Export Administration Regulations (EAR) by adding three Kaspersky entities to the Entity List under End-User Review Committee (ERC) determinations — AO Kaspersky Lab (Moscow), OOO Kaspersky Group (Moscow), and Kaspersky Labs Limited (London). All three are designated for cooperation with Russian military and intelligence authorities in support of Russian government cyber-intelligence objectives. Exports, reexports, and in-country transfers of all items subject to the EAR to the three entities now require a BIS licence reviewed under a policy of presumption of denial, with no licence exceptions available. The action is paired with a same-week Commerce ICTS final determination prohibiting Kaspersky cybersecurity and anti-virus software transactions in the United States.
Japan's National Diet enacted the Act on the Protection and Use of Critical Economic Security Information (重要経済安保情報の保護及び活用に関する法律, Act No. 27 of 2024) on 10 May 2024; it was promulgated on 17 May 2024 and came into full operation on 16 May 2025. The law establishes Japan's first peace-time economic-security clearance regime extending to private-sector employees. It designates "Critical Economic Security Information" (CESI) covering threat-intelligence on critical-infrastructure cyber attacks, regulatory-review information on essential infrastructure, and vulnerability data on critical-product supply chains; mandates Cabinet Office "適性評価" (suitability assessment) for cleared personnel; and imposes criminal penalties of up to five years' imprisonment for unauthorised disclosure. The CESI Act complements the 2022 Economic Security Promotion Act (ESPA), closing the information-protection gap and aligning Japan's framework with Five Eyes and EU partners for joint R&D and dual-use cooperation.
Loi n° 2024-449 of 21 May 2024, known as the SREN law (Sécuriser et Réguler l'Espace Numérique), was definitively adopted by the French Parliament on 10 April 2024, validated in part by the Conseil Constitutionnel on 17 May 2024 (Decision n° 2024-866 DC), promulgated by the President on 21 May 2024, and published in the Journal Officiel on 22 May 2024. SREN is France's digital-sovereignty omnibus statute: it transposes parts of the EU Digital Services Act (Regulation 2022/2065), Digital Markets Act (Regulation 2022/1925), and Data Governance Act (Regulation 2022/868) into French law and layers national-level instruments on top — most consequentially a data-localisation hook for sensitive public-sector data tied to the ANSSI SecNumCloud sovereign-cloud certification scheme, an ARCOM-enforced age-verification regime for adult-content sites (with €250k or 2%-of-turnover fines and account-closure powers), an "anti-scam" cybersecurity filter requiring browsers and DNS resolvers to block ANSSI-designated fraudulent domains, a jeux-en-ligne (JONUM) regime for cryptoasset-adjacent gaming, and a coordination framework between CSA, CNIL, ARCOM, and the Autorité de la concurrence. SREN is one of the first EU member-state digital omnibus statutes anchoring national public-sector data-hosting rules to a sovereign-cloud certification scheme.