Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
The Bureau of Industry and Security published a temporary final rule (91 FR 60505, RIN 0694-AK57) implementing the anti-stockpiling directive of Proclamation 11052 (6 August 2026), which sets Section 232 minimum import prices and tariffs on polysilicon and derivatives from 4 December 2026. The rule, effective 22 September through 3 December 2026, lets Commerce bar importers of record that import volumes substantially above their historic averages, caps weekly volumes of importers registered with CBP on or after 6 August 2026, and sets a waiver process.
On 8 May 2026 China's National Health Commission released a public consultation draft proposing material amendments to the 2023 Implementation Rules for the Administrative Regulations on Human Genetic Resources, with a comment deadline of 7 June 2026. The draft narrows the statutory "foreign party" definition to a bright-line 50% equity/voting threshold (excluding VIE-structured entities), restricts "HGR Information" strictly to nucleic-acid sequence data (excluding clinical, imaging, and metabolic data), removes the separate Article 37 security-review requirement for sensitive HGR datasets, and introduces a same-day or next-working-day fast-track confirmation for international clinical trials not involving HGR information export.
Prime Minister Phạm Minh Chính issued Directive 38/CĐ-TTg on 5 May 2026, mobilising a cross-ministerial enforcement campaign against intellectual property infringement running 7–30 May 2026 with a 31 May reporting deadline. The directive explicitly responds to the USTR 2026 Special 301 designation of Vietnam as a Priority Foreign Country — the first such designation in eleven years — which triggers a statutory 30-day window for USTR to decide whether to open a Section 301 investigation. Ministries of Public Security, Industry and Trade (Market Surveillance), Information and Communications, and Culture are mobilised for coordinated raids targeting counterfeit-goods exporters, pirated-content platforms, and software-copyright violators, with the Prime Minister signalling enforcement will be permanent rather than a one-off campaign.
The US Bureau of Industry and Security issued a final rule (RIN 0694-AK74, 91 FR 17851, FR doc 2026-06851, signed 7 April 2026, published 9 April 2026, effective 7 April 2026) extending two compliance dates in the January 2025 Foundry Due Diligence (FDD) interim final rule that introduced the "Authorized IC Designer" / "Approved IC Designer" framework for advanced-computing integrated circuits controlled under ECCN 3A090.a. The prior 13 April 2026 cutoff for Authorized IC Designer status — the self-certification pathway available to designers headquartered in Country Group A:1 / A:5 / Taiwan and not parented in Macau or D:5 — is moved to 31 December 2026, and the application window to become an Approved IC Designer is extended to the same date with a subsequent 180-day authorization runway. The rule is a procedural deadline-extension only; it does not change the substantive scope, eligibility criteria, ECCN classifications, or end-use / end-user restrictions of the FDD IFR.
Premier Li Qiang signed State Council Order No. 834 on 31 March 2026 promulgating the "Provisions on Industrial Chain and Supply Chain Security" (18 articles), adopted at the State Council executive meeting on 13 March 2026 and effective on the date of publication. The Provisions are the first dedicated PRC administrative regulation on industrial- and supply-chain security and consolidate authorities drawn from the National Security Law, Foreign Relations Law, Anti-Foreign Sanctions Law, and Foreign Trade Law into a horizontal defensive framework. They establish a cross-agency coordination mechanism spanning roughly 15 central departments (industrial, security, cyberspace, customs and financial regulators) plus provincial governments; create a security-investigation system; and vest broad countermeasure authority over both foreign states (Article 14 — import/export prohibitions and special levies) and foreign organisations and individuals (Article 15 — import/export bans, China-investment bars, transaction prohibitions, entry bars and revocation of work or residence permits, with extension to effectively-controlled subsidiaries). The Provisions also impose compliance, information-sharing, strategic-reserve and emergency-response obligations on PRC organisations and individuals, and authorise requisition, mandated production and directed transportation in the event of supply-chain disruption.
Minister of Trade Regulation No. 6 of 2026 (Permendag 6/2026), signed 26 March 2026 and effective 1 April 2026, amends the appendix of Permendag 22/2023 on Goods Prohibited for Export, making four substantive changes to Indonesia's prohibited-export list: (i) nitrogen-containing mineral and chemical fertilizers, including urea in all forms, are added to the prohibited-export list as a food-security instrument; (ii) rice is removed from the prohibited-export list, partially reversing a long-standing prohibition; (iii) rough wood, sawn wood, and wood carpentry and building products are added as value-added-export-requirement items, extending Indonesia's hilirisasi downstream-processing doctrine from minerals into the forestry-products sector; and (iv) rattan weaving materials remain prohibited for export. Together with the simultaneously enacted Permendag 5/2026 (fourth amendment to Permendag 23/2023 on export-licensing procedures), this forms Indonesia's most consequential 2026 export-regulation package.
On 3 February 2026 the European Commission opened an in-depth Phase II investigation under the Foreign Subsidies Regulation (FSR) — the second FSR ex officio case and the first targeting the renewable-energy wind-OEM sector — into whether Xinjiang Goldwind Science & Technology Co., Ltd. and its EU affiliates received Chinese foreign subsidies (grants, preferential tax treatment, and state-bank preferential financing) that distort competition for wind-turbine supply and services in the EU internal market. The case (FS.100143) follows the April 2024 preliminary-review opening and subjects Goldwind to an 18-month Phase II investigation with potential redressive-measures decision. The action structurally extends the FSR enforcement perimeter from security equipment (Nuctech, FS.100068) into the green-transition energy-equipment supply chain.
Malaysia's Minister of Finance gazetted P.U. (A) 25/2026, the Customs (Prohibition of Imports) (Amendment) (No. 2) Order 2026, on 14 January 2026, taking effect 15 January 2026. The order adds ammonium nitrate and potassium nitrate to the list of goods subject to import licensing under the Customs (Prohibition of Imports) Order, requiring importers to obtain an approved permit before bringing either chemical into Malaysia. Both compounds have legitimate fertilizer and industrial uses but are also recognised explosive precursors, and the measure is administered as a dual-use/security-sensitive chemical control rather than a straightforward agricultural-input tariff. Global Trade Alert lists Canada, China and Germany among the trade partners affected by the new licensing gate.
Taiwan's Legislative Yuan passed the Artificial Intelligence Basic Act (人工智慧基本法) on third reading on 23 December 2025, and President Lai Ching-te promulgated the 20-article statute on 14 January 2026, bringing it into force immediately. The Act designates the National Science and Technology Council (NSTC) as the central AI-policy competent authority and codifies seven governance principles — sustainability and well-being, human autonomy, privacy protection and data governance, cybersecurity and safety, transparency and explainability, fairness and non-discrimination, and accountability — that apply to all public-sector AI procurement and high-risk sectoral applications. The statute establishes a statutory foundation for the Taiwan AI Action Plan 2.0, mandates an Executive Yuan National AI Strategy Committee, and provides authority for sector-specific implementing regulations by FSC, NCC, MOHW, and MOTC across finance, telecoms, medical, and autonomous-vehicle AI within a two-year window. As the first national AI governance statute in the Greater China region and the third globally after the EU AI Act and South Korea's AI Basic Act, it frames regulatory expectations for the companies at the heart of the global AI hardware supply chain — TSMC, NVIDIA ODM partners, and advanced-packaging incumbents — that are headquartered or operate substantially in Taiwan.
On 22 December 2025 the FCC's Public Safety and Homeland Security Bureau released Public Notice DA-25-1086, adding to the Covered List (under section 1709 of the FY2025 NDAA) all unmanned aircraft systems (UAS) and UAS critical components produced in a foreign country, plus communications and video-surveillance equipment/services produced by DJI Technologies and Autel Robotics (and their subsidiaries, affiliates, and licensing/JV partners). The designation is comprehensive by scope — every foreign-made drone from consumer quadcopters to large uncrewed systems, with no size/performance carve-out — and blocks the FCC from granting any new equipment authorization to covered UAS/components going forward. Previously authorized models already in the US market are not revoked. A follow-on Public Notice (DA-26-22, 7 January 2026) narrowed the scope with a temporary exemption (see amendments).
On 10 December 2025 the European Commission opened an in-depth investigation under the Foreign Subsidies Regulation (FSR) — its first ex officio Phase II investigation — into whether Chinese state-controlled security-scanner producer Nuctech received foreign subsidies enabling it to offer prices and conditions that EU competitors could not match across airport, port, and border-crossing markets. Nuctech Technology, controlled by Tsinghua Tongfang (PRC state-linked), operates EU subsidiaries in Poland and the Netherlands (Nuctech Warsaw and Nuctech Netherlands), supplying threat-detection scanners to roughly 80% of EU airports and 70% of EU sea and land border crossings. The case (FS.100068) followed April 2024 unannounced FSR dawn raids at Nuctech's Polish and Dutch premises — one of the first uses of FSR inspection powers — and sets a precedent for ex officio scrutiny of state-subsidised foreign incumbents beyond the M&A and public-procurement tracks where FSR had previously operated.
On 10 December 2025 the National Assembly of Vietnam adopted Law No. 134/2025/QH15 on Artificial Intelligence (8 chapters, 35 articles), Vietnam's first dedicated AI statutory framework and one of the first comprehensive horizontal AI laws in Southeast Asia. The law establishes a three-tier risk-based regulatory architecture (high / medium / low) for the research, development, provision, deployment, and use of AI systems; defines the rights and obligations of providers, deployers, importers, distributors, and users; and mandates state oversight via the Ministry of Information & Communications and Ministry of Science & Technology. Prohibited acts include systematic deception, manipulation of human perception, generation of fake content endangering national security, exploitation of vulnerable populations, and obstruction of human-supervision mechanisms. The law applies to Vietnamese agencies, organizations, and individuals as well as foreign organizations and individuals involved in AI-related activities in Vietnam, taking effect 1 March 2026 with 12-18 month transition windows for existing systems depending on sector.
Vietnam's National Assembly passed Law on Cybersecurity No. 116/2025/QH15 on 10 December 2025 (434 of 443 deputies in favour), effective 1 July 2026. The law supersedes both the 2018 Cybersecurity Law (Law 24/2018/QH14) and the 2015 Law on Cyber Information Security, consolidating cybersecurity, cyber-information-security, and network-information-security into a unified Ministry of Public Security-led framework. It retains data-localization obligations for foreign digital-service providers handling personal data, user-generated content, and relationship graphs of Vietnamese users (minimum 24-month retention), introduces 6-hour urgent / 24-hour standard content take-down windows on MPS request, expressly prohibits AI/deepfake forgery of images, voices, and videos for illegal purposes, and mandates child-safety platform measures.
Germany's transposition of EU Directive 2022/2555 (NIS2), enacted as the "Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung." Bundestag passage 13 November 2025; Bundesrat approval 21 November 2025; published as BGBl. I 2025 Nr. 301 on 5 December 2025; entered into force 6 December 2025. The statute designates the Bundesamt für Sicherheit in der Informationstechnik (BSI) as the central national supervisory authority over an estimated 29,500 covered entities across 18 critical and important sectors, introduces a mandatory 24h initial / 72h detailed / 1-month final cyber-incident reporting cascade, establishes board-level personal liability for senior management, and applies to SME critical- infrastructure suppliers — with no transitional grace period from entry into force.
Presidential Decree No. 693 of 30 September 2025 ("On certain particularities of the sale of property held in federal ownership"), signed by Vladimir Putin and entered into force on the day of its official publication, creates an accelerated pathway for disposing of federally-owned property in cases determined by a separate decision of the President, where the goal is to ensure the Russian Federation's defence capability and security. Market valuation and the appraisal report must be completed within 10 business days of signing the appraisal contract; PSB Bank JSC (formerly Promsvyazbank, the state-controlled defence-procurement bank) is designated as the sale-organising agent and seller-on-behalf-of-the-state. The Decree also authorises the President to set special features of how Russian legislation on privatisation, joint-stock companies, limited-liability companies, the securities market, banks and competition protection applies to such sales. Expressly framed as a counter-measure to "unfriendly" actions by the United States and its allies; structurally the disposal-mechanism complement to the foreign-asset external- administration and seizure decrees (95/322/520/442) — the fast-track liquidation channel that converts seized or nationalised assets into state-budget cash for defence purposes.
Italy enacted Legge 23 settembre 2025, n. 132 — "Disposizioni e deleghe al Governo in materia di intelligenza artificiale" — published in Gazzetta Ufficiale Serie Generale n. 223 of 25 September 2025 (atto 25G00143) and entered into force on 10 October 2025. The statute makes Italy the first EU member state to enact a comprehensive national AI law complementing Regulation (EU) 2024/1689 (EU AI Act), designating AgID (Agency for Digital Italy) and ACN (National Cybersecurity Agency) as national oversight authorities under Presidency-of-the-Council-of-Ministers coordination. It sets sectoral rules for healthcare, labour, intellectual professions, public administration and the judiciary; authorises up to €1 billion in state-backed venture capital (via CDP Venture Capital) for AI, cybersecurity and telecoms; creates criminal penalties of up to five years' imprisonment for harmful deepfakes; mandates parental consent for under-14 users; and delegates secondary legislation to the Government across multiple domains.
On 17 September 2025 the US Department of Commerce, through BIS, published an interim final rule (90 FR 44767, FR Doc 2025-18015) formally adopting the procedures by which additional automobile parts articles may be added to the scope of the Section 232 25% tariff on automobiles and automobile parts originally imposed by Proclamation 10908 (26 March 2025). The rule, required by the Proclamation to be established within 90 days, codifies four recurring two-week submission windows each year (opening on the first day of January, April, July and October) for inclusion petitions, and obliges the International Trade Administration to issue a public determination memorandum within 60 days of the close of each window. Comments on the interim final rule were due by 3 November 2025; the first inclusions window under the rule opened on 1 April 2026.
The FCC adopted a Report and Order (FCC 25-49) on 7 August 2025 — the first comprehensive overhaul of submarine cable landing license rules since 2001 — effective 26 November 2025. The order prohibits Indefeasible Right of Use (IRU) agreements that would give entities from designated foreign adversary countries (China including Hong Kong and Macau, Cuba, Iran, DPRK, Russia, and Venezuela) control over Submarine Line Terminal Equipment (SLTE) on US cable landings, and mandates new annual reporting plus certification/disclosure requirements covering ownership, cybersecurity and physical security plans, and FCC Covered List compliance. The order operationalises the FCC's bifurcated policy package: accelerating legitimate commercial cable buildout while hardening national-security review for foreign-adversary-connected infrastructure.
On 25 June 2025 the European Commission adopted COM(2025) 335 final, a proposed Regulation establishing a single market for space activities — the first EU-level framework harmonising the authorisation, registration and supervision of space activities across Member States, replacing 13 fragmented national regimes. The Act rests on three pillars: safety (mandatory tracking of space objects, space- debris mitigation rules, an EU registry of space objects), resilience (cybersecurity requirements scaled to company size and risk profile) and sustainability (environmental impact assessment and active debris-removal R&D). It applies to both EU and non-EU operators providing space services in Europe, giving it extraterritorial reach over SpaceX/Starlink, Amazon Kuiper, OneWeb, Chinese SatNet/G60 and ISRO. The proposal is being negotiated under the ordinary legislative procedure; the Competitiveness Council of 9 December 2025 broadly endorsed its objectives, and the public consultation closed on 7 November 2025.
On 4 June 2025 the Verkhovna Rada adopted Law No. 4473-IX, amending the Customs Code of Ukraine to exempt from import (customs) duty goods brought into Ukraine's customs territory for security and defence needs. The law entered into force on 15 June 2025. Coverage includes optical fibre and fibre-optic cable imported by enterprises for the manufacture or repair of unmanned aerial systems (drones) and other defence equipment, as well as materials supplied to the Armed Forces of Ukraine and other authorised defence entities, removing a cost input for Ukraine's wartime domestic drone-manufacturing base. A companion law, No. 4474-IX, grants a parallel VAT exemption for the same import category.
On 4 June 2025 the Verkhovna Rada adopted Law No. 4474-IX, amending subsection 2 of section XX ("Transitional Provisions") of the Tax Code of Ukraine to exempt from value-added tax the import into Ukraine's customs territory of goods for security and defence needs, including optical fibre and fibre-optic cable used in the manufacture and repair of unmanned aerial systems (drones). The law entered into force on 15 June 2025. It is the VAT-side companion to Law No. 4473-IX (filed separately), which grants the equivalent customs-duty exemption for the same import category — the Rada split duty relief and VAT relief into two parallel statutory amendments passed the same day.
The Bureau of Industry and Security issued an interim final rule ("Adoption and Procedures of the Section 232 Steel and Aluminum Tariff Inclusions Process," 90 FR 18780, RIN 0694-AK13) adopting the procedural framework directed by Proclamations 10895 and 10896 of 10 February 2025 for adding derivative steel and aluminum articles to the scope of the 25% Section 232 duties. Eligible US producers and industry associations may submit inclusion requests during three two-week windows per year (opening in May, September and January); BIS evaluates each request on a sixty-day clock and publishes a determination memorandum granting or denying inclusion. The rule replaces the legacy product-exclusions architecture with a domestic-producer-driven inclusions architecture, structurally expanding the perimeter of covered tariff lines over time.
Stortinget adopted Norway's new Minerals Act (Lov om mineralvirksomhet og forvaltning av mineralressurser) on 12 June 2025, replacing the 2009 Minerals Act and entering into force 1 July 2026. The statute introduces a national-security review pillar enabling authorities to deny or condition projects that threaten national preparedness, reduces exploration-licence duration from seven to three years to accelerate project initiation, expands Sámi consultation protections from Finnmark to all traditional Sámi areas (Sápmi), and mandates explicit alignment with the EU Critical Raw Materials Act (CRMA, Regulation (EU) 2024/1252). The Act covers Norway's most strategically significant mineral assets including the Fen carbonatite REE field (Europe's largest known REE deposit) and major copper-zinc deposits.
Japan's National Diet enacted the Cyber Response Capability Enhancement Act (重要電子計算機に対する不正な行為による被害の防止に関する法律, Law No. 42 of 2025) on 16 May 2025, together with companion arrangement legislation. Commonly known as the Active Cyber Defense (ACD) Law, the statute authorises (i) government monitoring of foreign-origin internet traffic transiting designated Japanese communication infrastructure for national-security threat indicators, (ii) pre-emptive access and neutralisation operations against attacker infrastructure abroad by the National Police Agency and the Self-Defense Forces under unified command, and (iii) mandatory cyber-incident reporting and government cooperation duties on critical-infrastructure operators. Implementation is phased through November 2027, with the NISC reorganised into the National Cybersecurity Office (NCO) under the Cabinet Secretariat from July 2025.
Regulation (EU) 2025/38 of the European Parliament and of the Council of 19 December 2024 lays down measures to strengthen solidarity and capacities in the Union to detect, prepare for, and respond to cyber threats and incidents, and amends Regulation (EU) 2021/694 (Digital Europe Programme). Published in the Official Journal on 15 January 2025; entered into force on 4 February 2025 (20 days after OJ publication). The regulation establishes (i) a European Cybersecurity Alert System composed of national and cross-border Security Operations Centre (SOC) hubs interconnected EU-wide, (ii) a Cybersecurity Emergency Mechanism funded through the Digital Europe Programme, (iii) an EU Cybersecurity Reserve of trusted private-sector incident-response providers, and (iv) an ENISA-led post-incident review mechanism for significant or large-scale cybersecurity incidents. It complements the Cyber Resilience Act (Reg 2024/2847) and the NIS2 Directive as the third leg of the EU horizontal-cybersecurity stack.
The National Assembly of Vietnam passed the Law on Data (Luật Dữ liệu), No. 60/2024/QH15, on 30 November 2024; it enters into force on 1 July 2025. The Law is Vietnam's first comprehensive horizontal data-governance statute, extending regulation beyond personal data (already covered by Decree 13/2023/ND-CP) to all digital data — public, private, and sectoral. It introduces statutory categories of "important data" (dữ liệu quan trọng) and "core data" (dữ liệu cốt lõi) tied to national-defence and national-security review for cross-border transfer, and establishes the National Data Centre under the Ministry of Public Security plus a statutory data-broker / data-services licensing framework.
Regulation (EU) 2024/2847 of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, signed 23 October 2024 and entering into force 10 December 2024. The CRA is the first EU statutory cybersecurity regime covering all hardware and software products with a direct or indirect data connection placed on the EU market, imposing essential cybersecurity requirements, conformity assessment with CE marking, mandatory vulnerability handling, and 24-hour early-warning notification of actively-exploited vulnerabilities to ENISA. Main manufacturer obligations apply from 11 December 2027; conformity-assessment-body notification provisions apply from 11 June 2026 and reporting obligations from 11 September 2026. Penalties reach EUR 15M or 2.5% of global annual turnover.
The Bureau of Industry and Security (BIS) published a clerical correction to its 16 September 2024 final rule "Administrative and Enforcement Provisions" (RIN 0694-AJ84, 89 FR 75477). The original final rule's instruction No. 2 erroneously stated that 15 CFR 764.5 paragraph (b) was to be revised; BIS clarifies that only paragraphs (a) and (c) through (f) were revised and paragraph (g) added, while paragraph (b) was not intended to be amended. The correction is purely typographical and has no substantive effect on the underlying enforcement procedural changes.
Australia's first standalone cyber-security statute (Act No. 98 of 2024), passed by Parliament on 25 November 2024 and granted Royal Assent on 29 November 2024, with provisions commencing in tranches through 30 May 2025. The Act creates four binding regimes: (i) mandatory security-of-things standards for connected and IoT products supplied in Australia under regulations administered by the Department of Home Affairs; (ii) a mandatory ransomware / cyber-extortion payment disclosure regime requiring reporting business entities with annual turnover above AUD 3 million to notify the Australian Signals Directorate within 72 hours of any ransom payment made by or on behalf of the entity; (iii) a statutory Cyber Incident Review Board to conduct no-blame post-incident reviews of significant cyber incidents; and (iv) a "limited use" protection restricting how information voluntarily shared with the National Cyber Security Coordinator may be used by Commonwealth agencies. The Act implements core initiatives from the 2023-2030 Australian Cyber Security Strategy and affects every firm selling connected devices into Australia or operating above the turnover threshold in Australia.
The Bureau of Industry and Security (BIS) published a final rule (RIN 0694-AJ84; 89 FR 75477) amending 15 CFR Parts 764 and 766 of the Export Administration Regulations (EAR) to restructure administrative enforcement procedures. The rule revamps the voluntary self-disclosure (VSD) process under 15 CFR 764.5, abolishes prior penalty caps, amends the penalty guidelines in Supplement No. 1 to Part 766, and establishes that a deliberate decision not to disclose a "significant apparent violation" of the EAR will be treated as an aggravating factor when BIS calibrates administrative sanctions. The rule is effective on publication (16 September 2024).
The Bureau of Industry and Security (BIS) issued a technical-corrections rule fixing language in the July 18, 2024 interim final rule on "Standards-Related Activities and the Export Administration Regulations" (FR Doc. 2024-15810). The July 18 rule inadvertently revised text related to recent Entity List modifications; this 2024-07-25 corrections document restores the prior Entity List language. The corrections are administrative and do not change substantive export-control policy or add/remove any Entity List parties. Both rules touch 15 CFR Part 744.
The Bureau of Industry and Security (BIS) finalized amendments to its Defense Priorities and Allocations System (DPAS) regulation at 15 CFR Part 700, originally proposed February 7, 2024. The final rule clarifies long-standing standards and procedures by which BIS provides Special Priorities Assistance (SPA) under the Defense Production Act of 1950, revises Schedule I to delineate Department of Commerce DPAS jurisdiction from other agencies' priority-rating authorities, and applies non-substantive technical edits reflecting updates since the regulation was last amended in 2014. The rule takes effect August 21, 2024.
The Bureau of Industry and Security (BIS) issued an interim final rule (FR Doc. 2024-15810) amending the Export Administration Regulations (EAR) so that certain "releases" of technology and software during "standards-related activities" are no longer subject to the EAR. The rule revises 15 CFR §734.10 and consolidates the patchwork of prior carve-outs (May 2019 Huawei 5G TGL, June 2020 IFR, September 2022 Entity-List-wide IFR) into a single activity-based exclusion. The change enables US firms to participate in international standards bodies (IEEE, 3GPP, ITU, ISO, IEC) alongside Entity-Listed parties — most consequentially Huawei — without licence exposure. Comments were due September 16, 2024.
The Department of Commerce published a final rule redesignating the regulations implementing Executive Order 13873 (Securing the Information and Communications Technology and Services Supply Chain) from 15 CFR subtitle A, part 7 (Office of the Secretary of Commerce) to 15 CFR subtitle B, chapter VII, part 791, under the Bureau of Industry and Security (BIS). The redesignation reflects the formal transfer of ICTS-transaction review authority from the Secretary of Commerce to BIS's new Office of Information and Communications Technology and Services (OICTS). The rule is non-substantive — it relocates the existing regulatory text without altering the scope of covered ICTS transactions, the foreign-adversary list, the review procedures, or any substantive obligations on parties. Effective on publication (18 July 2024) without notice and comment because it is an internal agency reorganization.
Senegalese President Bassirou Diomaye Faye signed Décret n° 2024-1502 on 31 July 2024, suspending all artisanal and industrial mining operations and barring the issuance of new mining exploration and exploitation titles within a 500-metre corridor along the left bank of the Faleme River until 30 June 2027. The measure was adopted in Council of Ministers on 18 July 2024 following a ministerial mission to the zone in May 2024, and is motivated by severe environmental degradation, public-health risks from mercury and sediment contamination, and border-security concerns along the Senegal-Mali boundary in the OMVS basin.
The Bureau of Industry and Security finalized a rule (BIS-2024-0035; 89 FR 43740) amending the administrative exclusion-request process under the Section 232 steel and aluminum tariffs originally imposed in 2018. The rule removes 12 General Approved Exclusions (six for steel, six for aluminum) that had been in place since the December 2020 GAE rule and modifies procedures across five prior BIS interim final rules implementing the exclusion process. The changes were published on May 20, 2024 and take effect July 1, 2024, tightening the channel by which US importers can obtain product-level relief from the underlying 25% steel / 10% aluminum duties.
Japan's National Diet enacted the Act on the Protection and Use of Critical Economic Security Information (重要経済安保情報の保護及び活用に関する法律, Act No. 27 of 2024) on 10 May 2024; it was promulgated on 17 May 2024 and came into full operation on 16 May 2025. The law establishes Japan's first peace-time economic-security clearance regime extending to private-sector employees. It designates "Critical Economic Security Information" (CESI) covering threat-intelligence on critical-infrastructure cyber attacks, regulatory-review information on essential infrastructure, and vulnerability data on critical-product supply chains; mandates Cabinet Office "適性評価" (suitability assessment) for cleared personnel; and imposes criminal penalties of up to five years' imprisonment for unauthorised disclosure. The CESI Act complements the 2022 Economic Security Promotion Act (ESPA), closing the information-protection gap and aligning Japan's framework with Five Eyes and EU partners for joint R&D and dual-use cooperation.
Loi n° 2024-449 of 21 May 2024, known as the SREN law (Sécuriser et Réguler l'Espace Numérique), was definitively adopted by the French Parliament on 10 April 2024, validated in part by the Conseil Constitutionnel on 17 May 2024 (Decision n° 2024-866 DC), promulgated by the President on 21 May 2024, and published in the Journal Officiel on 22 May 2024. SREN is France's digital-sovereignty omnibus statute: it transposes parts of the EU Digital Services Act (Regulation 2022/2065), Digital Markets Act (Regulation 2022/1925), and Data Governance Act (Regulation 2022/868) into French law and layers national-level instruments on top — most consequentially a data-localisation hook for sensitive public-sector data tied to the ANSSI SecNumCloud sovereign-cloud certification scheme, an ARCOM-enforced age-verification regime for adult-content sites (with €250k or 2%-of-turnover fines and account-closure powers), an "anti-scam" cybersecurity filter requiring browsers and DNS resolvers to block ANSSI-designated fraudulent domains, a jeux-en-ligne (JONUM) regime for cryptoasset-adjacent gaming, and a coordination framework between CSA, CNIL, ARCOM, and the Autorité de la concurrence. SREN is one of the first EU member-state digital omnibus statutes anchoring national public-sector data-hosting rules to a sovereign-cloud certification scheme.
The Cyberspace Administration of China (CAC) issued the Provisions on Promoting and Regulating Cross-Border Data Flows (《促进和规范数据跨境流动规定》) on 22 March 2024, effective immediately. The rules substantially raise the thresholds at which CAC security assessment, Standard Contractual Clauses (SCC), or Personal Information Protection Certification are required for outbound data transfers, and create categorical exemptions for contract performance, HR management, intra-group transfers below a volume threshold, and transit data processed in China with no domestic personal information introduced. A Free Trade Zone pilot mechanism allows designated FTZs (Shanghai Lingang, Tianjin, Beijing) to publish their own negative lists defining which data categories still require prior approval, easing conditions for multinationals with operations in those zones.
FinCEN published the Beneficial Ownership Information Access and Safeguards Final Rule (FR Doc 2023-27973, 88 FR 88732, December 22, 2023; effective February 20, 2024), implementing the access and disclosure provisions of Section 6403(c) of the Corporate Transparency Act (CTA) enacted as part of the Anti-Money Laundering Act of 2020. The rule defines six categories of authorized recipients permitted to access the FinCEN BOI database — US federal agencies engaged in national security/intelligence/law enforcement, state/local/tribal law enforcement, foreign law enforcement and competent authorities (via intermediary federal agency), financial institutions using BOI for customer due diligence (CDD), federal functional regulators assessing financial-institution CDD compliance, and Treasury officers/employees. Access is to be phased in, beginning with a 2024 pilot for key federal agencies before extending to financial institutions and their supervisors. The rule establishes data-security standards, re-disclosure prohibitions, and oversight mechanisms governing each recipient category.
BIS amended §§ 734.15 and 734.19 of the Export Administration Regulations (EAR) to clarify that a "release of software" for purposes of the transfer-of-access-information provision includes both source code and object code. A cross-reference was also added from § 734.15 to § 734.19. The practical effect is that providing a decryption key, password, or other access credential to a foreign person to unlock controlled software requires an export licence to the same degree as exporting the software itself would.
The Bureau of Industry and Security (BIS) published a final rule (FR Doc 2023-18772; 88 FR 59927) amending 15 CFR 766.24 of the Export Administration Regulations (EAR) to create an additional option for the renewal of Temporary Denial Orders (TDOs). Under the new provision, BIS may request the Assistant Secretary for Export Enforcement renew a TDO for up to one year — rather than the standard maximum of 180 days — where the record demonstrates a pattern of repeated, ongoing, and/or continuous apparent violations. The rule was motivated by the sustained TDO enforcement campaign against Russian and Belarusian civil aviation entities that began in April 2022 following Russia's invasion of Ukraine.
The Bureau of Industry and Security (BIS) amended the Chemical Weapons Convention Regulations (CWCR, 15 CFR Part 710) to lower the concentration threshold above which mixtures containing a Schedule 2A chemical trigger declaration and export/import reporting obligations — from 30% to 10% by weight or volume. The three affected Schedule 2A chemicals are Amiton (a nerve-agent precursor), PFIB (a fluoromonomer byproduct), and BZ (an incapacitating agent). The change implements OPCW Conference of States Parties Decision C-14/DEC.4 (2009) and takes immediate effect on publication; 10% is the statutory floor set by the Chemical Weapons Convention Implementation Act (CWCIA).
Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities, published OJ L 333, 27 December 2022, entered into force 16 January 2023, with Member State transposition deadline 17 October 2024 (rules applicable from 18 October 2024). The CER Directive repeals Council Directive 2008/114/EC on European Critical Infrastructures, extending the scope from two sectors (energy, transport) to eleven essential-service sectors: energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, public administration, space, and food. Member States must adopt national resilience strategies, conduct risk assessments at least every four years, identify "critical entities" providing essential services whose disruption would have significant cross-border impacts, and ensure those entities implement technical, security, and organisational resilience measures, business-continuity plans, incident-reporting obligations, and personnel-security background checks. The CER Directive is the physical and hybrid resilience twin to the NIS2 Directive (2022/2555) — the two instruments form the binding EU critical-infrastructure-protection architecture replacing the 2008/114/EC regime.
Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive), published OJ L 333, 27 December 2022, entered into force 16 January 2023. NIS2 repeals and substantially expands the 2016 NIS1 Directive (2016/1148), extending the scope from ~7 sectors to 18 enumerated essential and important sectors, imposing binding cybersecurity risk- management and incident-reporting obligations on covered entities, introducing board-level management accountability, and mandating Member State transposition by 17 October 2024. NIS2 is the structural EU statutory anchor for national cybersecurity frameworks across the bloc, operating alongside DORA (Reg 2022/2554) for financial-sector digital resilience and CRA (Reg 2024/2847) for product cybersecurity.
The Bureau of Industry and Security (BIS) Office of Antiboycott Compliance amended Supplement No. 2 to Part 766 of the Export Administration Regulations to update penalty determination guidance for administrative enforcement cases involving antiboycott violations. The rule recategorizes violations — Category A now contains only the most serious violations with penalties beginning at the statutory maximum — and eliminates "no admit/no deny" settlements, requiring all settlement agreements to include admissions of fact. The changes apply to all US persons subject to antiboycott provisions, principally those receiving or complying with requests tied to the Arab League boycott of Israel.
The Bureau of Industry and Security (BIS) issued an interim final rule (IFR, 87 FR 55241, FR Doc. 2022-19415) amending the Export Administration Regulations (EAR) to authorize the release of specified items to all entities on the Entity List without a licence when such release occurs in the context of a "standards-related activity." The IFR expanded a narrower June 2020 predecessor that had applied only to Huawei and its affiliates; this 2022 rule extended equivalent authorization to the full Entity List. Authorized items include EAR99 technology and software, items controlled solely for anti-terrorism (AT) reasons, and certain cryptographic technology (ECCNs 5D002 and 5E002) used in standards development. The rule amended 15 CFR §§ 734.10, 744.11, 744.16, and Part 772 and was superseded by a broader 2024 IFR that recasted the carve-out as an activity-based exclusion from EAR jurisdiction entirely.
Government Decree 53/2022/ND-CP, signed 15 August 2022 and effective 1 October 2022, implements Article 26 of Vietnam's 2018 Law on Cybersecurity. It mandates in-country storage of three categories of data — personal data of users in Vietnam, user-generated data, and user-relationship data — for both domestic and foreign cyberspace- service providers, with a minimum 24-month retention period. Foreign enterprises providing telecoms, data storage, domain names, e-commerce, online payments, social networks, online video games, or messaging services to users in Vietnam must establish a Vietnamese branch or representative office within 12 months of a Minister of Public Security written request. The decree closes a four-year implementation gap on the 2018 Cybersecurity Law and is the principal Vietnamese digital-trade barrier alongside Decree 13/2023/ND-CP (Personal Data Protection).
BIS published an interim rule on January 12, 2022 delaying the effective date of its October 21, 2021 cybersecurity items interim final rule by 45 days, from January 19, 2022 to March 7, 2022. The underlying October 2021 rule establishes new Export Control Classification Numbers (ECCNs) for cybersecurity items — including intrusion software, command-and-control platforms, and surveillance tools — and introduces License Exception ACE (Authorized Cybersecurity Exports) for national security and anti-terrorism purposes. The delay was granted after twelve public comments highlighted significant compliance challenges, with BIS acknowledging the need for additional time for industry to update procedures and for BIS to issue supplemental guidance before the controls took effect.
Effective 5 October 2021, BIS published a final rule (86 FR 55268, FR Doc 2021-20649) making targeted editorial corrections and clarifications across eleven parts of the Export Administration Regulations (15 CFR Parts 732, 734, 736, 738, 740, 744, 748, 750, 770, 772, and 774). The errors corrected were inadvertent inconsistencies between different EAR parts where outdated or slightly divergent language had accumulated; the rule aligns those sections with the most-current language used elsewhere in the regulations. No substantive changes to licensing requirements, control lists, or end-use restrictions were made — this is a regulatory maintenance action.