Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
On 8 May 2026 China's National Health Commission released a public consultation draft proposing material amendments to the 2023 Implementation Rules for the Administrative Regulations on Human Genetic Resources, with a comment deadline of 7 June 2026. The draft narrows the statutory "foreign party" definition to a bright-line 50% equity/voting threshold (excluding VIE-structured entities), restricts "HGR Information" strictly to nucleic-acid sequence data (excluding clinical, imaging, and metabolic data), removes the separate Article 37 security-review requirement for sensitive HGR datasets, and introduces a same-day or next-working-day fast-track confirmation for international clinical trials not involving HGR information export.
Section 851 of the FY 2026 National Defense Authorization Act (P.L. 119-60), signed December 18, 2025, prohibits US federal agencies from procuring biotechnology equipment or services from designated "biotechnology companies of concern" (BCCs), and bars federal contractors from using such equipment/services in work performed under federal contracts, grants, or loans. The final enacted text ties initial BCC designations to DoD's existing §1260H Chinese-military-company list (which currently includes BGI and MGI, but not WuXi AppTec or WuXi Biologics) and directs OMB to designate additional BCCs within one year of enactment; operational prohibitions activate 60-90 days after FAR revision, with a five-year grandfather period for pre-existing contracts — enforcement is expected to begin in 2027-28. The legislation is the successor to H.R.8333 (118th Congress, House-passed September 2024 but stalled in the Senate before adjournment) and represents the first enacted US federal-procurement biotech-supply-chain-resilience statute.
In the early hours of 11 December 2025 the Council of the EU and the European Parliament reached provisional political agreement in trilogue on the "EU Pharma Package" — the revised pharmaceutical Regulation (COM 2023/0131) and Directive (COM 2023/0132) — the most significant overhaul of EU pharmaceutical legislation in over two decades. The package replaces Directive 2001/83/EC (Community Code on medicinal products for human use) and Regulation (EC) 726/2004 (the EMA Regulation), and consolidates the orphan-medicine (Regulation 141/2000) and pediatric-medicine regulations into a single framework. Headline provisions: (i) a new "8+1(+1)(+1)" IP-incentive architecture — 8 years of regulatory data protection plus 1 year of market protection, with up to two additional 12-month extensions for products addressing unmet medical need or new active substances meeting comparative-trial conditions, capped at 11 years total; (ii) an EU-wide list of critical medicines under enhanced governance via the Medicines Shortages Steering Group (MSSG) and an EMA "list of critical shortages in the EU"; (iii) mandatory shortage-prevention plans on marketing-authorisation holders for prescription medicines and Commission-designated products; (iv) modernisation of clinical-trial requirements, environmental-risk assessment, antimicrobial stewardship, and a transferable-exclusivity-voucher (TEV) regime to incentivise novel antibiotic R&D. The COREPER I committee endorsed the compromise text on 6 March 2026 and final adoption by Parliament and Council is expected during summer 2026, with the regulatory framework becoming applicable in 2028.
FinCEN issued a final rule under Section 311 of the USA PATRIOT Act (31 U.S.C. § 5318A) prohibiting US covered financial institutions from opening or maintaining a correspondent account for, or on behalf of, Cambodia-based Huione Group, a foreign financial institution found to be of primary money-laundering concern. Treasury determined that Huione Group and its subsidiaries — including Haowang Guarantee, Huione Pay PLC, and Huione Crypto — laundered at least $4 billion of illicit proceeds between August 2021 and January 2025, including funds tied to North Korean cyber-heist actors and Southeast Asian "pig-butchering" investment-scam compounds. The rule also imposes a special-due-diligence requirement on US covered institutions to guard against indirect access via foreign correspondent accounts. Effective November 17, 2025.
Regulation (EU) 2024/2847 of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, signed 23 October 2024 and entering into force 10 December 2024. The CRA is the first EU statutory cybersecurity regime covering all hardware and software products with a direct or indirect data connection placed on the EU market, imposing essential cybersecurity requirements, conformity assessment with CE marking, mandatory vulnerability handling, and 24-hour early-warning notification of actively-exploited vulnerabilities to ENISA. Main manufacturer obligations apply from 11 December 2027; conformity-assessment-body notification provisions apply from 11 June 2026 and reporting obligations from 11 September 2026. Penalties reach EUR 15M or 2.5% of global annual turnover.
Australia's first standalone cyber-security statute (Act No. 98 of 2024), passed by Parliament on 25 November 2024 and granted Royal Assent on 29 November 2024, with provisions commencing in tranches through 30 May 2025. The Act creates four binding regimes: (i) mandatory security-of-things standards for connected and IoT products supplied in Australia under regulations administered by the Department of Home Affairs; (ii) a mandatory ransomware / cyber-extortion payment disclosure regime requiring reporting business entities with annual turnover above AUD 3 million to notify the Australian Signals Directorate within 72 hours of any ransom payment made by or on behalf of the entity; (iii) a statutory Cyber Incident Review Board to conduct no-blame post-incident reviews of significant cyber incidents; and (iv) a "limited use" protection restricting how information voluntarily shared with the National Cyber Security Coordinator may be used by Commonwealth agencies. The Act implements core initiatives from the 2023-2030 Australian Cyber Security Strategy and affects every firm selling connected devices into Australia or operating above the turnover threshold in Australia.
FinCEN issued a final rule under Section 311 of the USA PATRIOT Act (31 U.S.C. § 5318A) prohibiting US covered financial institutions from opening or maintaining a correspondent account for, or on behalf of, Iraq-based Al-Huda Bank, a foreign financial institution found to be of primary money-laundering concern. Treasury determined that Al-Huda Bank exploited its access to US dollars to support designated Foreign Terrorist Organizations including Iran's Islamic Revolutionary Guard Corps (IRGC) and IRGC-Quds Force, as well as Iran-aligned Iraqi militias Kata'ib Hizballah and Asa'ib Ahl al-Haq. The rule also imposes a special-due-diligence requirement on US covered institutions to guard against indirect access via foreign correspondent accounts. Published in the Federal Register on July 3, 2024; effective August 2, 2024.
Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data — the "Data Act" — was published in the Official Journal on 22 December 2023, entered into force on 11 January 2024, and applies generally from 12 September 2025 (with longer transitional periods for IoT product-design obligations under Article 3(1), which apply to products placed on the market after 12 September 2026, and for the data-portability standardisation framework, applicable from 12 September 2027). The Data Act is the third pillar of the EU data-economy framework alongside the GDPR (personal data) and the Data Governance Act 2022/868 (data-intermediation services), and is the world's first horizontal statutory regime governing access to and portability of industrial / IoT / non-personal data — covering by-design data-availability obligations on connected-product manufacturers, a mandatory cloud- switching framework with progressive elimination of switching charges, B2G emergency data-sharing in exceptional needs, unfair-contract-terms protection for SMEs, and safeguards against unlawful international government access to non-personal data held in EU cloud.
Regulation (EU) 2022/868 of the European Parliament and of the Council of 30 May 2022 on European data governance — the Data Governance Act (DGA) — was published in the Official Journal on 3 June 2022, entered into force on 23 June 2022, and became fully applicable on 24 September 2023. The DGA is the second pillar of the EU data-economy framework (alongside GDPR for personal data and the Data Act 2023/2854 for industrial/IoT data) and establishes four structural mechanisms: (i) a harmonised public-sector data re-use regime for protected data held by public-sector bodies; (ii) a mandatory notification and structural-separation regime for data-intermediation service providers; (iii) a voluntary recognition framework for data-altruism organisations (RDAOs); and (iv) the European Data Innovation Board (EDIB) to co-ordinate national competent authorities and advise on common European data spaces and interoperability standards. The regulation is the foundational parent statute of the existing French SREN law filing (2024-05-21) and functions as enabling legislation for the EU's sectoral common-data-space programme (Health, Agriculture, Finance, Mobility, Green Deal, Energy, etc.).
Germany's Außenwirtschaftsgesetz (AWG, Foreign Trade and Payments Act; BGBl. I 2013 S. 1482 of 6 June 2013, replacing the original 1961 Act) is the foundational parent statute of the modern German economic-statecraft toolkit, providing the legislative authority for (i) export licensing of dual-use goods and technology administered by BAFA under the Außenwirtschaftsverordnung (AWV) implementing regulation — the national complement to EU Dual-Use Recast Regulation 2021/821; (ii) inward FDI screening by BMWK under §§ 55–62 AWG covering non-EU/non-EFTA acquisitions of ≥ 25% of voting rights cross-sectorally and ≥ 10%/20% in 27 sensitive-sector activities including defence, semiconductors, AI, quantum, biotech, space, and critical infrastructure; and (iii) German implementation of EU-level and autonomous trade and sanctions restrictions. As the EU's largest economy and a top-tier dual-use exporter, Germany's AWG-based regime is structurally peer-foundational to JP FEFTA 1949, UK NSI Act 2021, US ECRA 2018, CN Export Control Law 2020, and NL Wet Vifo 2022 in the G7+CN economic- statecraft parent-statute cluster.