Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
Premier Li Qiang signed State Council Order No. 839 on 20 May 2026, promulgating the "Regulations for the Implementation of the Mineral Resources Law of the People's Republic of China" (8 chapters, 79 articles), effective 15 June 2026. The Regulations are the primary implementing instrument for the revised Mineral Resources Law and establish a unified governance architecture across the entire mineral value chain — exploration, production, processing, stockpiling, and emergency supply mobilisation — with inter-agency coordination spanning MNR, NDRC, MIIT, the State Grain and Material Reserves Administration, NEA, and the State Administration of Mine Safety. The Regulations introduce a three-layer strategic reserve system (physical stockpiles, production-capacity reserves, and in-ground strategic areas), grant the state authority to directly organise mining and distribution during supply emergencies (Article 59), and explicitly authorise countermeasures against nations that restrict China's access to mineral supply chains (Article 76).
Sultan Haitham bin Tariq issued Royal Decree 39/2026 on 1 March 2026, published in the Sultanate of Oman Official Gazette Issue 1638 on 8 March 2026 (effective the following day), enacting a new Statute of the Public Authority for Special Economic Zones and Free Zones (OPAZ) and consolidating the Public Establishment for Industrial Estates under the unified OPAZ regulatory umbrella. The Statute restructures OPAZ's institutional architecture for administering Oman's 23 special economic zones, free zones, and industrial cities, expands OPAZ's supervisory and oversight powers — including project registration, licensing, permits, approvals, certificates, regulation of municipal services within zones — and mandates a single-window platform consolidating the full suite of zone-related services for investors. The decree is the institutional-governance complement to the substantive SEZ/FZ framework established by Royal Decree 38/2025 and operationalises the Vision 2040 economic-diversification strategy at the binding regulatory-authority layer, covering RO 22.4 bn (~USD 58 bn) in cumulative committed investment across the OPAZ-administered zone network.
Kenya's Senate introduced the Artificial Intelligence Bill, 2026 (Senate Bills No. 4 of 2025) on 19 February 2026, sponsored by Nominated Senator Karen Nyamu; the bill received its first reading on 2 April 2026 and was committed to the Senate Standing Committee on Information, Communication and Technology for public-input review. The bill establishes a risk-based AI regulatory framework explicitly modelled on the EU AI Act (Regulation 2024/1689), creating a four-tier classification (prohibited / high-risk / limited-risk / minimal-risk) with conformity- assessment, technical-documentation, and human-oversight obligations for high-risk AI systems. It creates the Office of the Artificial Intelligence Commissioner as a new statutory regulator with licensing, enforcement, and administrative-penalty powers, and bans social-scoring systems, real-time remote biometric identification in public spaces, emotion recognition in workplaces and education, and predictive policing based on profiling. The bill is the first comprehensive national AI regulatory instrument in Africa, closing a structural geographic gap in the global AI-governance architecture and positioning Kenya as the Brussels-effect template-recipient for the African continent.
Taiwan's Legislative Yuan passed the Artificial Intelligence Basic Act (人工智慧基本法) on third reading on 23 December 2025, and President Lai Ching-te promulgated the 20-article statute on 14 January 2026, bringing it into force immediately. The Act designates the National Science and Technology Council (NSTC) as the central AI-policy competent authority and codifies seven governance principles — sustainability and well-being, human autonomy, privacy protection and data governance, cybersecurity and safety, transparency and explainability, fairness and non-discrimination, and accountability — that apply to all public-sector AI procurement and high-risk sectoral applications. The statute establishes a statutory foundation for the Taiwan AI Action Plan 2.0, mandates an Executive Yuan National AI Strategy Committee, and provides authority for sector-specific implementing regulations by FSC, NCC, MOHW, and MOTC across finance, telecoms, medical, and autonomous-vehicle AI within a two-year window. As the first national AI governance statute in the Greater China region and the third globally after the EU AI Act and South Korea's AI Basic Act, it frames regulatory expectations for the companies at the heart of the global AI hardware supply chain — TSMC, NVIDIA ODM partners, and advanced-packaging incumbents — that are headquartered or operate substantially in Taiwan.
In the early hours of 11 December 2025 the Council of the EU and the European Parliament reached provisional political agreement in trilogue on the "EU Pharma Package" — the revised pharmaceutical Regulation (COM 2023/0131) and Directive (COM 2023/0132) — the most significant overhaul of EU pharmaceutical legislation in over two decades. The package replaces Directive 2001/83/EC (Community Code on medicinal products for human use) and Regulation (EC) 726/2004 (the EMA Regulation), and consolidates the orphan-medicine (Regulation 141/2000) and pediatric-medicine regulations into a single framework. Headline provisions: (i) a new "8+1(+1)(+1)" IP-incentive architecture — 8 years of regulatory data protection plus 1 year of market protection, with up to two additional 12-month extensions for products addressing unmet medical need or new active substances meeting comparative-trial conditions, capped at 11 years total; (ii) an EU-wide list of critical medicines under enhanced governance via the Medicines Shortages Steering Group (MSSG) and an EMA "list of critical shortages in the EU"; (iii) mandatory shortage-prevention plans on marketing-authorisation holders for prescription medicines and Commission-designated products; (iv) modernisation of clinical-trial requirements, environmental-risk assessment, antimicrobial stewardship, and a transferable-exclusivity-voucher (TEV) regime to incentivise novel antibiotic R&D. The COREPER I committee endorsed the compromise text on 6 March 2026 and final adoption by Parliament and Council is expected during summer 2026, with the regulatory framework becoming applicable in 2028.
President Claudia Sheinbaum signed a comprehensive reform to Mexico's Customs Law (Ley Aduanera) published in the Diario Oficial de la Federación on 19 November 2025, entering into force 1 January 2026. The decree formally recognises the Agencia Nacional de Aduanas de México (ANAM) as the autonomous customs authority with expanded inspection and fiscalisation powers, creates a new inter-secretarial Consejo Aduanero with binding decisional authority over customs-agent licensing, and mandates real-time electronic traceability and video-surveillance at all recintos fiscales. The reform is Mexico's most comprehensive statutory overhaul of its customs-administration architecture in over a decade, directly conditioning USMCA-origin compliance infrastructure for approximately US$800 billion in annual MX-US trade and over 3,200 IMMEX-registered nearshoring operators.
The Kachin Independence Organisation (KIO) formally introduced a Rare Earth Mining Management Regulation in October 2025, establishing permit procedures, investor obligations, environmental protection rules, chemical-use standards, labour provisions, and enforcement mechanisms for the heavy-rare-earth (HREE) mining industry it controls in Chipwi and Pangwa townships of Kachin State. The KIO assumed de facto territorial governance of Kachin Special Region No. 1 in October 2024 following KIA military operations, inheriting authority over hundreds of Chinese-operated extraction sites that collectively supply an estimated 60–70 % of China's heavy rare earth oxide imports (~41,700 t in 2023) — the proximate basis for China's ~95 % global market share in terbium, dysprosium, and holmium. The regulation formalises a permit-and-tax regime that includes an export levy of approximately 35,000 CNY/tonne (~USD 4,800), with export permission first reactivated by KIO on 27 March 2025 after a post-takeover suspension of all mining and export activity.
The Joint Committee of the European Supervisory Authorities (EBA, EIOPA, ESMA) published the Guide on DORA Oversight Activities (JC 2025 29) on 15 July 2025, the definitive operational description of how the ESAs will supervise Critical ICT Third-Party Providers (CTPPs) designated under DORA Art. 31. The guide establishes the governance of Joint Examination Teams (JETs), the oversight examination lifecycle (planning, risk assessment, binding recommendations, follow-up), penalty processes of up to 1% of average daily worldwide turnover per day of breach (DORA Art. 35(6)), and lead-overseer assignments (EBA for banking, ESMA for capital markets, EIOPA for insurance). It is authoritative ESA interpretive guidance, not legally binding per se, but constitutes the supervisory playbook CTPPs and their dependent financial entities must plan against.
Indonesia's Ministry of Communications and Digital Affairs (Kemkomdigi) promulgated Permenkomdigi No. 5/2025 on 25 March 2025 as the implementing regulation under Government Regulation PP 71/2019 governing Public-Scope Electronic System Operators (PSE Lingkup Publik), defined as operators running electronic systems for government institutions or critical public services. The regulation mandates registration, data classification by risk level (low/medium/ high/strategic) with corresponding domestic storage and processing requirements, content- moderation governance, and access-blocking mechanisms for prohibited electronic information. All public-scope PSEs must achieve compliance by 25 March 2026, with non-compliant operators subject to progressive administrative sanctions under Articles 100-series ranging from written warnings to access disconnection (pemutusan akses) and removal from official registries.
Zambia's Parliament enacted the Property Transfer Tax (Amendment) Act No. 27 of 2024, assented to by President Hichilema on 24 December 2024 and in force from 1 January 2025. The Act introduces a first-ever dedicated Property Transfer Tax (PTT) schedule for mining rights: 10% of realised value on transfers of mining licences and mineral processing licences, and 8% on transfers of exploration licences. The measure directly raises the transaction cost of copper and cobalt mine acquisitions, stake transfers, and licence assignments across the Zambia Copperbelt. It is the fifth distinct fiscal or governance instrument enacted since 2024 in Zambia's rolling reform of its mining regulatory architecture.
Malaysia's Personal Data Protection (Amendment) Act 2024 (Act A1727), gazetted 17 October 2024, enters its third and final commencement phase on 1 June 2025 per commencement order P.U.(B) 522/2024. Phase 3 activates sections 6 and 9 of the amending Act, which impose mandatory Data Protection Officer (DPO) appointment thresholds, a 72-hour breach-notification duty to the Commissioner, and a statutory data-portability right, bringing Malaysia's PDPA broadly into alignment with GDPR and the ASEAN Model AI Governance Framework.
The National Assembly of Vietnam passed the Law on Data (Luật Dữ liệu), No. 60/2024/QH15, on 30 November 2024; it enters into force on 1 July 2025. The Law is Vietnam's first comprehensive horizontal data-governance statute, extending regulation beyond personal data (already covered by Decree 13/2023/ND-CP) to all digital data — public, private, and sectoral. It introduces statutory categories of "important data" (dữ liệu quan trọng) and "core data" (dữ liệu cốt lõi) tied to national-defence and national-security review for cross-border transfer, and establishes the National Data Centre under the Ministry of Public Security plus a statutory data-broker / data-services licensing framework.
The European Union's Artificial Intelligence Act, Regulation (EU) 2024/1689, was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. It establishes the world's first horizontal, risk-tiered legal framework for the development, market placement, and use of AI systems — covering prohibited practices, high-risk systems, general-purpose AI models, and minimal-risk applications — with extraterritorial reach over any provider placing an AI system on the EU market or whose output is used in the EU. Penalties reach up to EUR 35 million or 7% of global annual turnover. Application is staged: prohibitions from 2 February 2025, GPAI and governance from 2 August 2025, the bulk of high-risk obligations from 2 August 2026, and product-safety-embedded high-risk systems from 2 August 2027.
Loi n° 2024-449 of 21 May 2024, known as the SREN law (Sécuriser et Réguler l'Espace Numérique), was definitively adopted by the French Parliament on 10 April 2024, validated in part by the Conseil Constitutionnel on 17 May 2024 (Decision n° 2024-866 DC), promulgated by the President on 21 May 2024, and published in the Journal Officiel on 22 May 2024. SREN is France's digital-sovereignty omnibus statute: it transposes parts of the EU Digital Services Act (Regulation 2022/2065), Digital Markets Act (Regulation 2022/1925), and Data Governance Act (Regulation 2022/868) into French law and layers national-level instruments on top — most consequentially a data-localisation hook for sensitive public-sector data tied to the ANSSI SecNumCloud sovereign-cloud certification scheme, an ARCOM-enforced age-verification regime for adult-content sites (with €250k or 2%-of-turnover fines and account-closure powers), an "anti-scam" cybersecurity filter requiring browsers and DNS resolvers to block ANSSI-designated fraudulent domains, a jeux-en-ligne (JONUM) regime for cryptoasset-adjacent gaming, and a coordination framework between CSA, CNIL, ARCOM, and the Autorité de la concurrence. SREN is one of the first EU member-state digital omnibus statutes anchoring national public-sector data-hosting rules to a sovereign-cloud certification scheme.
Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data — the "Data Act" — was published in the Official Journal on 22 December 2023, entered into force on 11 January 2024, and applies generally from 12 September 2025 (with longer transitional periods for IoT product-design obligations under Article 3(1), which apply to products placed on the market after 12 September 2026, and for the data-portability standardisation framework, applicable from 12 September 2027). The Data Act is the third pillar of the EU data-economy framework alongside the GDPR (personal data) and the Data Governance Act 2022/868 (data-intermediation services), and is the world's first horizontal statutory regime governing access to and portability of industrial / IoT / non-personal data — covering by-design data-availability obligations on connected-product manufacturers, a mandatory cloud- switching framework with progressive elimination of switching charges, B2G emergency data-sharing in exceptional needs, unfair-contract-terms protection for SMEs, and safeguards against unlawful international government access to non-personal data held in EU cloud.
Regulation (EU) 2022/868 of the European Parliament and of the Council of 30 May 2022 on European data governance — the Data Governance Act (DGA) — was published in the Official Journal on 3 June 2022, entered into force on 23 June 2022, and became fully applicable on 24 September 2023. The DGA is the second pillar of the EU data-economy framework (alongside GDPR for personal data and the Data Act 2023/2854 for industrial/IoT data) and establishes four structural mechanisms: (i) a harmonised public-sector data re-use regime for protected data held by public-sector bodies; (ii) a mandatory notification and structural-separation regime for data-intermediation service providers; (iii) a voluntary recognition framework for data-altruism organisations (RDAOs); and (iv) the European Data Innovation Board (EDIB) to co-ordinate national competent authorities and advise on common European data spaces and interoperability standards. The regulation is the foundational parent statute of the existing French SREN law filing (2024-05-21) and functions as enabling legislation for the EU's sectoral common-data-space programme (Health, Agriculture, Finance, Mobility, Green Deal, Energy, etc.).
The Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法 — PIPL) was adopted at the 30th meeting of the 13th NPC Standing Committee on 20 August 2021 and entered into force on 1 November 2021, constituting the third and final pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Data Security Law (2021). The PIPL is China's comprehensive personal-information statute establishing consent-based and necessity-based legal bases for PI processing, a tiered cross-border personal-data transfer regime (CAC security assessment / PI protection certification / Standard Contractual Clauses), extraterritorial application (Art. 3) to non-Chinese controllers offering services to or analysing the behaviour of PRC residents, and a heightened protection regime for sensitive personal information and data of minors under 14. It mandates data-protection impact assessments, personal-information-protection-officer obligations at designated handlers, breach notification, and a full suite of data-subject rights including access, rectification, deletion, portability, objection, and automated- decision-making opt-out. Article 53 requires overseas controllers to establish a domestic representative or designated entity in China, providing a domestic enforcement counterparty.
The Data Security Law of the People's Republic of China (中华人民共和国数据安全法) was adopted at the 29th meeting of the 13th NPC Standing Committee on 10 June 2021 and entered into force on 1 September 2021, constituting the second pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Personal Information Protection Law (2021). The DSL establishes a tiered data-classification regime — "important data" and "national core data" — with escalating security obligations including risk assessment, risk monitoring, breach reporting, and classified-protection requirements for data handlers. It introduces a data-export security review for "important data" generated or collected within China, the statutory parent authority operationalised by the 2024 CAC Cross-Border Data Flow Provisions, and enacts a §36 blocking statute prohibiting Chinese organisations and individuals from transferring data stored in China to foreign judicial or law-enforcement authorities without prior PRC government approval.
The Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法) was adopted at the 24th meeting of the 12th NPC Standing Committee on 7 November 2016 and entered into force on 1 June 2017, establishing the foundational legal framework for network security governance across all sectors. The law creates the Critical Information Infrastructure Operator (CIIO) designation and protection regime administered by the Cyberspace Administration of China (CAC), mandates data localisation for personal information and important data collected or generated by CIIOs in China, and establishes cross-border data-transfer security assessment requirements under Article 37 — the provision later operationalised by DSL 2021, PIPL 2021, and the 2024 CAC Cross-Border Data Flow Provisions. The CSL introduced multi-level protection scheme (等级保护制度 / MLPS) obligations for all network operators and network-product/service security-review procedures, under which CAC triggered the cybersecurity review of Didi Global in 2021 and the exclusion of Micron's products from Chinese critical-infrastructure projects in 2023.