Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
On 18 September 2026 the President signed a proclamation extending Proclamation 10973 (originally issued 19 September 2025), which conditions issuance/entry on new H-1B specialty-occupation petitions on a $100,000 payment by the sponsoring employer, for a further 12 months through 21 September 2027 (exceptions remain at DHS Secretary discretion for national-interest cases). Alongside it the President signed a companion executive order, "Enhancing Program Integrity and Interagency Coordination in the Administration of the H-1B Nonimmigrant Visa Program," directing DHS, State and Labor to coordinate review of H-1B petitions and consult Commerce, Education and SBA on employment data, with heightened scrutiny for employers with recent or planned US-worker layoffs. The accompanying fact sheet cites a 92% drop in H-1B registrations by the largest IT-outsourcing firms (24,946 to 2,055) and a ~97% decrease in consular H-1B processing requests since the original 2025 proclamation. ## Severity basis Quant anchor from the primary source: $100,000 flat fee per covered H-1B petition, extended for a further 12-month term (through 2027-09-21); a measured 92% reduction in H-1B registrations by the largest IT-outsourcing filers (24,946 → 2,055) and a ~97% drop in consular H-1B processing requests attributed to the fee regime since its 2025 introduction. Severity 4/5: a binding, renewed cost barrier with a demonstrated order-of-magnitude effect on offshore-staffing-dependent filers, not a one-off or symbolic measure.
FinCEN reissued the Southwest Border Geographic Targeting Order (GTO), requiring money services businesses (MSBs) in designated ZIP codes to file Currency Transaction Reports on cash transactions between $1,000 and $10,000 — below the standard $10,000 CTR threshold. The reissued order runs September 3, 2026 through March 1, 2027 (180 days) and covers Bernalillo, Doña Ana, and San Juan Counties in New Mexico and Cameron, El Paso, Hidalgo, Maverick, and Webb Counties in Texas. Newly-covered MSBs (relative to the March 2026 order) have a compliance date of October 3, 2026. Treasury Secretary Bessent framed the order as targeting Mexico-based drug-cartel money laundering through the border MSB channel.
China's Ministry of Commerce issued Announcement No. 26 of 2026 on June 24, 2026, establishing a formal reporting and handling system for violations of export controls on strategic minerals and dual-use items, effective July 1, 2026. The mechanism opens two reporting channels — a dedicated hotline (010-12369) and an online portal (aqygzj.mofcom.gov.cn) — through which any organisation or individual may report suspected violations including unauthorised exports, circumvention via third-country re-routing, illegal technology transfers, and provision of services to sanctioned exporters. Anonymous reports are accepted; real-name reporters may qualify for monetary rewards; voluntary self-disclosure is treated as a mitigating factor in penalty determination. Service providers including freight forwarders and financial institutions face mandatory reporting obligations when they discover suspected violations in the course of business.
Prime Minister Phạm Minh Chính issued Directive 38/CĐ-TTg on 5 May 2026, mobilising a cross-ministerial enforcement campaign against intellectual property infringement running 7–30 May 2026 with a 31 May reporting deadline. The directive explicitly responds to the USTR 2026 Special 301 designation of Vietnam as a Priority Foreign Country — the first such designation in eleven years — which triggers a statutory 30-day window for USTR to decide whether to open a Section 301 investigation. Ministries of Public Security, Industry and Trade (Market Surveillance), Information and Communications, and Culture are mobilised for coordinated raids targeting counterfeit-goods exporters, pirated-content platforms, and software-copyright violators, with the Prime Minister signalling enforcement will be permanent rather than a one-off campaign.
The Office of the United States Trade Representative released the 2026 Special 301 Report on 30 April 2026, designating Vietnam as a Priority Foreign Country (PFC) — the most severe category under Section 182 of the Trade Act of 1974 (19 U.S.C. § 2242). This is the first PFC designation since Ukraine held the status from 2013 through 2015, a gap of approximately 11 years. The PFC designation triggers a statutory 30-day window (expiring ~30 May 2026) within which USTR must decide whether to initiate a Section 301 investigation under 19 U.S.C. § 2412(b)(2)(A), which could lead to tariffs, withdrawal of trade benefits, or other Section 301 enforcement remedies against Vietnam. Separately, the EU was added to the Watch List for the first time, citing AI training-data, geographical-indications, and customs-enforcement concerns.
Minister of Trade Regulation No. 12 of 2026, signed by Trade Minister Budi Santoso and effective on its date of promulgation (29 April 2026), is the fifth amendment to Permendag 23/2023 on Export Policy and Regulation. It introduces a new discretionary authority — distinct from administrative sanctions — for the Director General of Foreign Trade to suspend issuance of, freeze, and revoke Business Licensing in the Export Sector (Perizinan Berusaha di Bidang Ekspor), and to suspend verification / technical-tracing services. Crucially, it institutionalises cross-ministerial initiating authority: other ministries and agencies may formally propose suspension / freezing / revocation, with proposals reviewed in coordination meetings convened under the Coordinating Ministry for Economic Affairs or the Coordinating Ministry for Food Affairs. Decisions are issued via INATRADE / SINSW with automated notification to exporters. The stated rationale is protecting national interests, public welfare, government-programme implementation, and presidential directives — operationalised as safeguarding domestic supply of "certain goods" (palm oil, rice, sugar, mineral, and fertiliser categories cited in policy framing).
FinCEN issued an amendment to its June 30, 2025 special-measure order (90 FR 27770) that had prohibited US covered financial institutions from transmitting funds to or from CIBanco S.A., a Mexican multiple-banking institution previously designated as of primary money-laundering concern in connection with illicit-opioid trafficking. Effective April 16, 2026, the amendment authorizes transmittals of funds ordinarily incident and necessary for the Government of Mexico to liquidate CIBanco. The carve-out is narrow: the broader §2313a prohibition on US-side correspondent activity with CIBanco remains in force outside the liquidation channel.
Premier Li Qiang signed State Council Order No. 835 on 13 April 2026 promulgating the "Regulations of the People's Republic of China on Countering Foreign States' Unlawful Extraterritorial Jurisdiction" (20 articles), effective on the date of publication. The Regulations are the first State Council–level administrative regulation to operationalise the PRC's framework for identifying and countering foreign extraterritorial measures on a horizontal basis, complementing the 2021 Anti-Foreign Sanctions Law and the March 2025 AFSL implementation regulations. Article 5 establishes a State Council–led inter-agency coordination mechanism; Article 6 vests the State Council legal affairs department (the Ministry of Justice in practice) with authority to identify "improper" foreign extraterritorial measures and to grant exemptions; Article 8 authorises a new Malicious Entity List targeting foreign organisations and individuals that "promote or participate in implementing" such measures, with nine countermeasure categories spanning visa denial, asset freezing, trade restrictions and fines; Article 11 codifies an exemption-application channel under which Chinese persons facing conflicting legal demands may request approval to comply with foreign measures within a defined scope; Article 14 authorises a private right of action for harmed Chinese citizens and organisations to sue parties enforcing such measures; and Article 18 elevates enforcement beyond administrative penalties by referencing potential criminal liability.
FinCEN issued an expanded Geographic Targeting Order (GTO) requiring money services businesses (MSBs) located in designated counties and ZIP codes across Arizona, California, New Mexico, and Texas to file Currency Transaction Reports (CTRs) on cash transactions between $1,000 and $10,000 — well below the standard $10,000 CTR threshold. The order took effect March 7, 2026 and runs through September 2, 2026; the FR notice (FR Doc. 2026-04641) was published March 10, 2026. The expansion adds Bernalillo, Doña Ana, and San Juan Counties in New Mexico and Maricopa and Pima Counties in Arizona to the geography covered by the prior September 10, 2025 GTO. Compliance date for newly-covered MSBs is April 6, 2026; reports must be filed within 30 days (extended from the standard 15-day CTR deadline). The instrument is part of the post-2024 US enforcement architecture targeting fentanyl-related illicit-finance flows through the US-Mexico border MSB channel.
Sultan Haitham bin Tariq issued Royal Decree 39/2026 on 1 March 2026, published in the Sultanate of Oman Official Gazette Issue 1638 on 8 March 2026 (effective the following day), enacting a new Statute of the Public Authority for Special Economic Zones and Free Zones (OPAZ) and consolidating the Public Establishment for Industrial Estates under the unified OPAZ regulatory umbrella. The Statute restructures OPAZ's institutional architecture for administering Oman's 23 special economic zones, free zones, and industrial cities, expands OPAZ's supervisory and oversight powers — including project registration, licensing, permits, approvals, certificates, regulation of municipal services within zones — and mandates a single-window platform consolidating the full suite of zone-related services for investors. The decree is the institutional-governance complement to the substantive SEZ/FZ framework established by Royal Decree 38/2025 and operationalises the Vision 2040 economic-diversification strategy at the binding regulatory-authority layer, covering RO 22.4 bn (~USD 58 bn) in cumulative committed investment across the OPAZ-administered zone network.
Directive (EU) 2026/470 of 24 February 2026, published in the EU Official Journal on 26 February 2026 and entered into force on 18 March 2026, amends the Corporate Sustainability Reporting Directive (CSRD, Directive (EU) 2022/2464) and the Corporate Sustainability Due Diligence Directive (CSDDD, Directive (EU) 2024/1760). It raises CSRD scope thresholds to undertakings with more than 1,000 employees and more than EUR 450 million net turnover, raises CSDDD scope thresholds to entities with more than 5,000 employees and EUR 1.5 billion turnover (and non-EU entities with EUR 1.5 billion EU turnover), drops the requirement to adopt or put into effect a climate transition plan under CSDDD, and replaces reasonable-assurance with limited-assurance for CSRD reports. CSRD-related provisions must be transposed by 19 March 2027; CSDDD-related provisions by 26 July 2028.
At the Maiden Mining Local Content Summit held in Takoradi on 18 February 2026, Minerals Commission CEO Isaac Tandoh announced the revocation of more than 300 small-scale mining licences held fraudulently or left dormant, alongside a comprehensive regulatory reset covering all segments of Ghana's mining sector. The reform package includes the repeal of L.I. 2462 (which had permitted mining in forest reserves), introduction of a new medium-scale licensing tier, a sliding-scale gold royalty regime designed to increase state capture during high-price periods, and mandatory local-content thresholds across procurement, employment, and equity participation. Surface-mining operations will be required to use fully Ghanaian-owned contractors; underground-mining contracts must carry at least 50% Ghanaian ownership. The reforms structurally affect large-scale operators including Newmont, AngloGold Ashanti, Zijin Mining, and Atlantic Lithium.
The Federal Acquisition Regulatory Council (DOD, GSA, and NASA) published a Notice of Proposed Rulemaking on 17 February 2026 (FR Doc 2026-03065, 91 FR 7223) implementing Section 5949(a) of the NDAA FY2023 (Pub. L. 117-263), which bars executive agencies from acquiring electronic products or services containing semiconductor components designed, produced, or provided by SMIC, CXMT, YMTC, or their affiliates. A Part B prohibition extends the restriction to "critical systems" whose subsystems incorporate covered semiconductors regardless of COTS sourcing. The comment period closed 20 April 2026; proposed prohibitions take effect 23 December 2027.
On 3 February 2026 the European Commission opened an in-depth Phase II investigation under the Foreign Subsidies Regulation (FSR) — the second FSR ex officio case and the first targeting the renewable-energy wind-OEM sector — into whether Xinjiang Goldwind Science & Technology Co., Ltd. and its EU affiliates received Chinese foreign subsidies (grants, preferential tax treatment, and state-bank preferential financing) that distort competition for wind-turbine supply and services in the EU internal market. The case (FS.100143) follows the April 2024 preliminary-review opening and subjects Goldwind to an 18-month Phase II investigation with potential redressive-measures decision. The action structurally extends the FSR enforcement perimeter from security equipment (Nuctech, FS.100068) into the green-transition energy-equipment supply chain.
On 9 February 2026 the UK Office of Financial Sanctions Implementation (OFSI) published a comprehensively revised enforcement and monetary-penalties guidance following its July–October 2025 public consultation. The update introduces a Settlement Scheme (20% penalty discount for subjects who agree not to contest OFSI's findings within 30 business days), an Early Account Scheme (up to 20% discount for legal persons providing a timely senior-attested factual account), a revised voluntary-disclosure framework (maximum discount cut from 50% to 30% and renamed to cover both prompt self-reporting and full cooperation), a four-level case-assessment seriousness matrix (severity × conduct), and fixed monetary penalties of £5,000 and £10,000 for information, reporting, and licensing offences. A planned legislative amendment (requiring primary legislation) will subsequently double the statutory civil monetary-penalty cap from £1m / 50%-of-breach to £2m / 100%-of-breach; in the interim the Policing and Crime Act 2017 caps remain in force. The revised guidance is the foundational enforcement architecture for all UK financial-sanctions programs (Russia, Iran, DPRK, Syria, Belarus, Myanmar, and 10+ additional regimes).
Germany's first cross-sector federal statute establishing minimum requirements for the physical protection and resilience of critical infrastructure operators (KRITIS) — sectors covered include energy, transport, water, food, ICT, financial services, health, and federal government infrastructure. Transposes EU Directive 2022/2557 (CER Directive on the resilience of critical entities). Identifies operators of critical facilities with Europe-wide significance, mandates national risk analyses for critical services, requires operator risk-management measures and creates a federal incident-reporting regime. Passed by the Bundestag on 29 January 2026, confirmed by the Bundesrat on 6 March 2026, published in BGBl. 2026 I Nr. 66 on 16 March 2026, in force from 17 March 2026.
Turkey's Public Procurement Authority published Communiqué No. 2026/1 in the Official Gazette (22 January 2026, Gazette No. 33145), raising the monetary thresholds and limits under Public Procurement Law No. 4734 by 27.67% — the December 2025 year-on-year change in the domestic producer price index (Yİ-ÜFE), applied per the Law's Article 67 mandatory annual indexation mechanism. The revised thresholds apply from 1 February 2026 through 31 January 2027, including an international-tender threshold of TL 18,734,124 for general-budget goods/services procurement and TL 686,924,429 for construction/works tenders. Global Trade Alert logged the update as a public-procurement-access intervention because raising the monetary bands widens the range of below-threshold tenders eligible for domestic-restricted procedures.
On 19 January 2026 the Government of Vietnam issued Decree No. 29/2026/ND-CP, establishing the regulatory architecture for Vietnam's first domestic carbon trading exchange. The decree (6 chapters, 35 articles) governs registration, domestic coding, ownership transfer, custody, trading and settlement of greenhouse gas (GHG) emission quotas and eligible carbon credits. The Hanoi Stock Exchange (HNX) operates the trading platform and the Vietnam Securities Depository and Clearing Corporation (VSDC) handles registration, custody and settlement, with a pilot phase running through 31 December 2028 (no exchange-services fee) ahead of full commercialisation from 1 January 2029.
FinCEN issued a Geographic Targeting Order (GTO) under 31 U.S.C. § 5326 requiring banks and money transmitters located in Hennepin and Ramsey Counties, Minnesota (i.e., Minneapolis–St. Paul metro) to file reports with FinCEN on transactions of $3,000 or more where the beneficiary is located outside the United States. The order is effective February 12, 2026 through August 10, 2026 and is paired with a parallel Treasury/IRS audit and enforcement push targeting alleged government-benefits fraud (notably the federal child-nutrition program rings under prosecution in Minnesota since 2022). It is the second high-profile FinCEN GTO of the Trump 2.0 administration after the Southwest-border MSB GTO.
FinCEN issued a final rule delaying by two years the effective date of the August 28, 2024 Investment Adviser AML Rule (89 FR 72156) — which would have required SEC-registered investment advisers (RIAs) and Exempt Reporting Advisers (ERAs) to implement AML/CFT programs and file SARs under the Bank Secrecy Act. The compliance deadline moves from January 1, 2026 to January 1, 2028. Treasury cited the need for additional time to review and re-tailor the rule to the diverse business models and risk profiles of the investment adviser sector, and to coordinate with related rulemakings. The final rule follows the September 22, 2025 NPRM and the August 5, 2025 exemptive relief order that had already paused enforcement.
Presidential Decision No. 10767, published in the Official Gazette (Resmî Gazete, Issue No. 33118) on 25 December 2025, re-sets the Digital Services Tax (Dijital Hizmet Vergisi, DHV) rate under Article 5(3) of Law No. 7194. The rate, set at 7.5% since the tax's 2020 introduction, is reduced to 5% for revenue generated from 1 January 2026 and to 2.5% for revenue generated from 1 January 2027. The tax applies to gross Turkish-sourced revenue of digital-service providers (online advertising, content sales, social-media/intermediary platforms) exceeding statutory turnover thresholds, and falls predominantly on large non-resident platform operators (Google, Meta, Amazon and comparable multinationals).
Taiwan's Legislative Yuan passed the Artificial Intelligence Basic Act (人工智慧基本法) on third reading on 23 December 2025, and President Lai Ching-te promulgated the 20-article statute on 14 January 2026, bringing it into force immediately. The Act designates the National Science and Technology Council (NSTC) as the central AI-policy competent authority and codifies seven governance principles — sustainability and well-being, human autonomy, privacy protection and data governance, cybersecurity and safety, transparency and explainability, fairness and non-discrimination, and accountability — that apply to all public-sector AI procurement and high-risk sectoral applications. The statute establishes a statutory foundation for the Taiwan AI Action Plan 2.0, mandates an Executive Yuan National AI Strategy Committee, and provides authority for sector-specific implementing regulations by FSC, NCC, MOHW, and MOTC across finance, telecoms, medical, and autonomous-vehicle AI within a two-year window. As the first national AI governance statute in the Greater China region and the third globally after the EU AI Act and South Korea's AI Basic Act, it frames regulatory expectations for the companies at the heart of the global AI hardware supply chain — TSMC, NVIDIA ODM partners, and advanced-packaging incumbents — that are headquartered or operate substantially in Taiwan.
On 22 December 2025 the FCC's Public Safety and Homeland Security Bureau released Public Notice DA-25-1086, adding to the Covered List (under section 1709 of the FY2025 NDAA) all unmanned aircraft systems (UAS) and UAS critical components produced in a foreign country, plus communications and video-surveillance equipment/services produced by DJI Technologies and Autel Robotics (and their subsidiaries, affiliates, and licensing/JV partners). The designation is comprehensive by scope — every foreign-made drone from consumer quadcopters to large uncrewed systems, with no size/performance carve-out — and blocks the FCC from granting any new equipment authorization to covered UAS/components going forward. Previously authorized models already in the US market are not revoked. A follow-on Public Notice (DA-26-22, 7 January 2026) narrowed the scope with a temporary exemption (see amendments).
Section 851 of the FY 2026 National Defense Authorization Act (P.L. 119-60), signed December 18, 2025, prohibits US federal agencies from procuring biotechnology equipment or services from designated "biotechnology companies of concern" (BCCs), and bars federal contractors from using such equipment/services in work performed under federal contracts, grants, or loans. The final enacted text ties initial BCC designations to DoD's existing §1260H Chinese-military-company list (which currently includes BGI and MGI, but not WuXi AppTec or WuXi Biologics) and directs OMB to designate additional BCCs within one year of enactment; operational prohibitions activate 60-90 days after FAR revision, with a five-year grandfather period for pre-existing contracts — enforcement is expected to begin in 2027-28. The legislation is the successor to H.R.8333 (118th Congress, House-passed September 2024 but stalled in the Senate before adjournment) and represents the first enacted US federal-procurement biotech-supply-chain-resilience statute.
Morocco's Loi de Finances n° 50-25 for fiscal year 2026, promulgated by Dahir n° 1-25-67 of 10 December 2025 and published in Bulletin Officiel n° 7465 bis of 16 December 2025, sets the FY2026 customs-tariff schedule (continuing the EU Common External Tariff alignment process at 2.5%/17.5%/40% tiers with sector-specific input reductions), amends the fiscal regimes for Zones d'Accélération Industrielle and Casablanca Finance City, and delivers the 2026 tranche of the multi-year IS (corporate-tax) rate-convergence schedule under Framework Law n° 69-19. The law also extends green-investment fiscal accelerators aligned with the EU's Carbon Border Adjustment Mechanism and the EU-Morocco Strategic Partnership on Sustainable Raw Materials Value Chains, and contains phosphate-sector fiscal provisions affecting OCP Group's DAP/MAP/TSP export treatment. Entry into force: 1 January 2026.
On 10 December 2025 the National Assembly of Vietnam adopted Law No. 134/2025/QH15 on Artificial Intelligence (8 chapters, 35 articles), Vietnam's first dedicated AI statutory framework and one of the first comprehensive horizontal AI laws in Southeast Asia. The law establishes a three-tier risk-based regulatory architecture (high / medium / low) for the research, development, provision, deployment, and use of AI systems; defines the rights and obligations of providers, deployers, importers, distributors, and users; and mandates state oversight via the Ministry of Information & Communications and Ministry of Science & Technology. Prohibited acts include systematic deception, manipulation of human perception, generation of fake content endangering national security, exploitation of vulnerable populations, and obstruction of human-supervision mechanisms. The law applies to Vietnamese agencies, organizations, and individuals as well as foreign organizations and individuals involved in AI-related activities in Vietnam, taking effect 1 March 2026 with 12-18 month transition windows for existing systems depending on sector.
Vietnam's National Assembly passed Law on Cybersecurity No. 116/2025/QH15 on 10 December 2025 (434 of 443 deputies in favour), effective 1 July 2026. The law supersedes both the 2018 Cybersecurity Law (Law 24/2018/QH14) and the 2015 Law on Cyber Information Security, consolidating cybersecurity, cyber-information-security, and network-information-security into a unified Ministry of Public Security-led framework. It retains data-localization obligations for foreign digital-service providers handling personal data, user-generated content, and relationship graphs of Vietnamese users (minimum 24-month retention), introduces 6-hour urgent / 24-hour standard content take-down windows on MPS request, expressly prohibits AI/deepfake forgery of images, voices, and videos for illegal purposes, and mandates child-safety platform measures.
On 18 November 2025, the European Supervisory Authorities (EBA, ESMA, and EIOPA) jointly designated 19 Critical ICT Third-Party Providers (CTPPs) under DORA Article 31, with immediate effect — the first-ever exercise of direct EU financial-regulator supervision over hyperscale cloud and infrastructure providers. The designated entities include Amazon Web Services, Microsoft Azure, Google Cloud, Deutsche Telekom, Oracle, SAP, IBM, Bloomberg LP, London Stock Exchange Group (LSEG), Tata Consultancy Services, and Orange, among others. Designation triggers direct oversight by a lead ESA (EBA for banking-critical, ESMA for capital-markets-critical, EIOPA for insurance-critical) via Joint Examination Teams (JETs), with powers to conduct investigations, carry out on-site inspections, and impose fines of up to 1% of average daily worldwide turnover per day for non-compliance.
India's Ministry of Electronics and Information Technology (MeitY) notified the Digital Personal Data Protection Rules, 2025 via Gazette notification G.S.R. 846(E) on 13 November 2025, operationalising the 2023 DPDP Act. The Rules introduce a "negative list" cross-border personal-data transfer regime under Rule 14, verifiable parental consent, breach-notification windows, and tiered penalties up to INR 250 crore. Implementation is phased: Data Protection Board provisions in force on notification, Consent Manager rules from 13 Nov 2026, and core data-fiduciary / cross-border-transfer obligations from 13 May 2027.
Germany's transposition of EU Directive 2022/2555 (NIS2), enacted as the "Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung." Bundestag passage 13 November 2025; Bundesrat approval 21 November 2025; published as BGBl. I 2025 Nr. 301 on 5 December 2025; entered into force 6 December 2025. The statute designates the Bundesamt für Sicherheit in der Informationstechnik (BSI) as the central national supervisory authority over an estimated 29,500 covered entities across 18 critical and important sectors, introduces a mandatory 24h initial / 72h detailed / 1-month final cyber-incident reporting cascade, establishes board-level personal liability for senior management, and applies to SME critical- infrastructure suppliers — with no transitional grace period from entry into force.
FinCEN issued a final rule under Section 311 of the USA PATRIOT Act (31 U.S.C. § 5318A) prohibiting US covered financial institutions from opening or maintaining a correspondent account for, or on behalf of, Cambodia-based Huione Group, a foreign financial institution found to be of primary money-laundering concern. Treasury determined that Huione Group and its subsidiaries — including Haowang Guarantee, Huione Pay PLC, and Huione Crypto — laundered at least $4 billion of illicit proceeds between August 2021 and January 2025, including funds tied to North Korean cyber-heist actors and Southeast Asian "pig-butchering" investment-scam compounds. The rule also imposes a special-due-diligence requirement on US covered institutions to guard against indirect access via foreign correspondent accounts. Effective November 17, 2025.
Italy enacted Legge 23 settembre 2025, n. 132 — "Disposizioni e deleghe al Governo in materia di intelligenza artificiale" — published in Gazzetta Ufficiale Serie Generale n. 223 of 25 September 2025 (atto 25G00143) and entered into force on 10 October 2025. The statute makes Italy the first EU member state to enact a comprehensive national AI law complementing Regulation (EU) 2024/1689 (EU AI Act), designating AgID (Agency for Digital Italy) and ACN (National Cybersecurity Agency) as national oversight authorities under Presidency-of-the-Council-of-Ministers coordination. It sets sectoral rules for healthcare, labour, intellectual professions, public administration and the judiciary; authorises up to €1 billion in state-backed venture capital (via CDP Venture Capital) for AI, cybersecurity and telecoms; creates criminal penalties of up to five years' imprisonment for harmful deepfakes; mandates parental consent for under-14 users; and delegates secondary legislation to the Government across multiple domains.
On September 10, 2025 FinCEN issued a Geographic Targeting Order (GTO) under 31 USC 5326 requiring money services businesses (MSBs) in designated southwest-border counties and ZIP codes across California, Texas, and (newly added) Arizona to file Currency Transaction Reports (CTRs) on cash transactions between $1,000 and $10,000 — well below the BSA's standard $10,000 CTR threshold. The order ran through March 6, 2026 (180 days, the GTO statutory maximum) and was subsequently extended via the March 10, 2026 expanded GTO (FR Doc. 2026-04641) which retained the $1,000 floor and added inland transit hubs (Bernalillo, Doña Ana, San Juan in NM; Maricopa, Pima in AZ). The September 2025 order modified an earlier March 14, 2025 GTO that had used a $200 threshold and covered a narrower TX/CA strip; the September 2025 modification raised the threshold to $1,000 in response to MSB-industry feedback on operational burden, while extending the geography to include Arizona. Filing deadline is extended from the standard 15 days to 30 days.
FinCEN published an order amending the three June 25, 2025 special-measure orders (as previously amended by the July 11, 2025 order, FR doc 2025-12973) prohibiting US covered financial institutions from transmitting funds to or from CIBanco S.A., Intercam Banco S.A., and Vector Casa de Bolsa, S.A. de C.V. — three Mexican institutions designated of primary money-laundering concern in connection with illicit-opioid trafficking under Section 2313a of the Fiscal Year 2024 NDAA. The amendment extends the effective date of all three prohibitions from September 4, 2025 to October 20, 2025, granting US covered institutions an additional ~46 days to wind down correspondent exposures. The underlying primary-money-laundering-concern findings remain intact — only the implementation deadline shifts.
The Mauritius Finance Act 2025 (Act No. 18 of 2025), assented to by Acting President Dharambeer Gokhool G.C.S.K. and gazetted in August 2025, is an omnibus financial-sector statute amending the Companies Act, Financial Services Act 2007, Income Tax Act, Bank of Mauritius Act, and FIAMLA. Its headline provisions are: (i) introduction of a Qualified Domestic Minimum Top-Up Tax (QDMTT) aligned with the OECD GloBE Pillar Two rules, imposing a 15% effective minimum tax on Mauritius profits of MNE groups with consolidated revenue ≥ EUR 750 million; (ii) new fiscal incentives for investments in AI infrastructure and Virtual Asset Service Provider (VASP) licensees; (iii) enhanced beneficial-ownership (UBO) identification and record-keeping requirements under the Companies Act, aligned with FATF Recommendation 24; (iv) tightened substance and economic-presence requirements for Global Business Companies (GBCs); and (v) an expanded AML/CFT administrative- penalty framework under FIAMLA.
Czech Republic's first standalone federal statute on the resilience of critical-infrastructure entities — Act No. 266/2025 Sb., "Zákon o odolnosti subjektů kritické infrastruktury a o změně souvisejících zákonů" (Critical Infrastructure Act). Transposes EU Directive 2022/2557 (CER Directive on the resilience of critical entities) into Czech law and removes critical-infrastructure regulation from the earlier crisis-management law (Zákon č. 240/2000 Sb.) into a dedicated statute. Covers the 11 CER-Directive sectors (energy, transport, banking, financial-market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space, food production-processing-distribution) and obligates designated operators of essential services to conduct risk analyses, implement technical/organisational resilience measures, report incidents to sector-competent authorities, and submit to inspection. Published in the Sbírka zákonů on 4 August 2025; in force 19 August 2025; operator information-obligation deadline 1 March 2026.
The Joint Committee of the European Supervisory Authorities (EBA, EIOPA, ESMA) published the Guide on DORA Oversight Activities (JC 2025 29) on 15 July 2025, the definitive operational description of how the ESAs will supervise Critical ICT Third-Party Providers (CTPPs) designated under DORA Art. 31. The guide establishes the governance of Joint Examination Teams (JETs), the oversight examination lifecycle (planning, risk assessment, binding recommendations, follow-up), penalty processes of up to 1% of average daily worldwide turnover per day of breach (DORA Art. 35(6)), and lead-overseer assignments (EBA for banking, ESMA for capital markets, EIOPA for insurance). It is authoritative ESA interpretive guidance, not legally binding per se, but constitutes the supervisory playbook CTPPs and their dependent financial entities must plan against.
FinCEN published an order amending the three June 25, 2025 special-measure orders (FR docs 2025-11991, 2025-11993, 2025-11990; 90 FR 27770 et seq.) prohibiting US covered financial institutions from transmitting funds to or from CIBanco S.A., Intercam Banco S.A., and Vector Casa de Bolsa, S.A. de C.V. — three Mexican institutions designated of primary money-laundering concern in connection with illicit-opioid trafficking under Section 2313a of the Fiscal Year 2024 NDAA. This first extension shifts the effective date of all three prohibitions from July 21, 2025 to September 4, 2025 (a 45-day delay), giving US covered institutions additional time to wind down correspondent exposures. The underlying primary-money-laundering- concern findings remain unchanged — only the implementation deadline shifts.
Canada announced on 29 June 2025 that it would rescind the Digital Services Tax Act (originally enacted 20 June 2024) to revive US-Canada trade negotiations after President Trump suspended talks on 27 June, citing the 3% DST on large digital-services revenues as a discriminatory measure against US technology firms. The Canada Revenue Agency halted collection effective 30 June 2025, and legislation to retroactively repeal the Act back to its June 2024 enactment date is to follow, with refunds — plus interest at the standard corporate tax refund rate — to be paid to affected taxpayers including US technology majors.
On 26 June 2025, the Governing Board of Mexico's National Banking and Securities Commission (CNBV), invoking Article 129 of the Ley de Instituciones de Crédito, decreed the temporary managerial intervention of CI Banco, S.A. and Intercam Banco, S.A., replacing their administrative bodies and legal representatives. The measure came one day after the US Treasury's FinCEN designated both institutions (along with Vector Casa de Bolsa) as foreign financial institutions of primary money-laundering concern tied to opioid-trafficking networks, and prohibited certain US fund transmittals to them. CNBV/SHCP framed the intervention as a depositor- and creditor-protection measure to safeguard the two banks' operations against the fallout of the US action; Vector Casa de Bolsa was not included in the CNBV intervention.
On 26 June 2025 President Bola Ahmed Tinubu signed four acts constituting Nigeria's most comprehensive fiscal overhaul in decades: the Nigeria Tax Act 2025 (NTA), Nigeria Tax Administration Act 2025 (NTAA), Nigeria Revenue Service (Establishment) Act 2025, and Joint Revenue Board (Establishment) Act 2025. The NTA consolidates and repeals six core statutes — CITA, PITA, PPTA, VAT Act, CGT Act, and Stamp Duties Act — into a single unified code effective 1 January 2026, while the NTAA standardises assessment, filing, and enforcement procedures across all federal taxes. The two establishment acts restructure the Federal Inland Revenue Service (FIRS) into the Nigeria Revenue Service (NRS) with a broadened mandate and create an empowered Joint Revenue Board to coordinate federal-state fiscal relations.
The National Assembly of Vietnam passed the Personal Data Protection Law (Luật Bảo vệ dữ liệu cá nhân), Law No. 91/2025/QH15, on 26 June 2025; it enters into force on 1 January 2026. The PDPL is Vietnam's first statutory (rather than decree-level) personal-data-protection framework, elevating the prior Decree 13/2023/ND-CP (PDPD) regime into a 5-chapter, 39-article primary statute and adding revenue-based administrative penalties of up to 5% of prior-year annual revenue for cross-border data-transfer violations and up to 10x illegal gains for unlawful data trading. The law is implemented by Decree 356/2025/ND-CP (issued 31 December 2025, effective 1 January 2026) and applies extraterritorially to foreign organisations offering services to or processing the personal data of Vietnam residents.
On 25 June 2025 the European Commission adopted COM(2025) 335 final, a proposed Regulation establishing a single market for space activities — the first EU-level framework harmonising the authorisation, registration and supervision of space activities across Member States, replacing 13 fragmented national regimes. The Act rests on three pillars: safety (mandatory tracking of space objects, space- debris mitigation rules, an EU registry of space objects), resilience (cybersecurity requirements scaled to company size and risk profile) and sustainability (environmental impact assessment and active debris-removal R&D). It applies to both EU and non-EU operators providing space services in Europe, giving it extraterritorial reach over SpaceX/Starlink, Amazon Kuiper, OneWeb, Chinese SatNet/G60 and ISRO. The proposal is being negotiated under the ordinary legislative procedure; the Competitiveness Council of 9 December 2025 broadly endorsed its objectives, and the public consultation closed on 7 November 2025.
The Hong Kong Legislative Council passed the Stablecoins Ordinance (Cap. 656) on 21 May 2025 (third reading), brought into operation by the Secretary for Financial Services and the Treasury on 1 August 2025. The Ordinance introduces a mandatory licensing regime administered by the Hong Kong Monetary Authority (HKMA) for any person who issues a fiat-referenced stablecoin (FRS) in Hong Kong, issues an HKD-pegged stablecoin anywhere in the world, or actively markets such issuance to the Hong Kong public. Key requirements include minimum HK$25 million paid-up capital, segregated pools of high-quality liquid reserve assets fully backing circulating supply, mandatory redemption-at-par rights for holders, AML/CFT controls, and broad HKMA enforcement powers including licence suspension, revocation, and financial penalties. A six-month transitional period for existing operators expires 31 January 2026.
Switzerland's State Secretariat for Economic Affairs (SECO) and the US Treasury Office of Foreign Assets Control (OFAC) signed a Memorandum of Understanding on 9 May 2025 (jointly published 16 May 2025) establishing a framework for information-sharing, coordinated investigations, designated points of contact, regular bilateral meetings, joint training, and exchange of technical expertise on sanctions enforcement. The MoU is not legally binding and neither side is obliged to share information, but it formalises an enforcement-cooperation channel that previously operated only ad-hoc. It is the first sanctions-enforcement MoU Switzerland has concluded with a third country (the US has a comparable arrangement with the UK's OFSI), and SECO has indicated more such MoUs will follow.
Commission Delegated Regulation (EU) 2025/532, adopted 24 March 2025 and published in the Official Journal on 2 July 2025, supplements DORA (Regulation (EU) 2022/2554) with binding Regulatory Technical Standards governing ICT subcontracting of critical or important functions. It requires all EU-regulated financial entities to establish a subcontracting policy, conduct due-diligence and concentration-risk assessments at each tier of the ICT supply chain (including nth-party providers), impose equivalent resilience standards on sub-ICT-providers, and maintain enforceable termination and information-access rights. The RTS entered into force on 22 July 2025, completing the second-batch DORA implementing acts on outsourcing chains.
The Office of Foreign Assets Control (OFAC) issued a final rule on 21 March 2025 adopting without change its 13 September 2024 interim final rule that doubled the recordkeeping retention requirement for transactions subject to OFAC regulations from five years to ten years. The extension aligns 31 CFR 501.601, paragraph IV.B of appendix A to part 501, and 31 CFR 515.572 with the 10-year statute of limitations for IEEPA and TWEA violations enacted by the 21st Century Peace through Strength Act of 24 April 2024. The interim final rule's 10-year retention obligation became effective 12 March 2025; the final rule confirmed the IFR text without modification.
FinCEN issued an interim final rule (FR Doc 2025-05199, 90 FR 13688, published March 26, 2025) revising the definition of "reporting company" under the Corporate Transparency Act to mean only entities formed under the law of a foreign country that have registered to do business in a U.S. State or tribal jurisdiction. All entities created in the United States — previously known as "domestic reporting companies" — and U.S. persons are exempted from BOI reporting. Foreign reporting companies registered before March 26, 2025 must file by April 25, 2025; those registered on or after that date have 30 days from registration. Foreign reporting companies are not required to report any U.S. persons as beneficial owners. The IFR is effective immediately; FinCEN is accepting comments and intends to finalize the rule.
The Nigeria Data Protection Commission issued the General Application and Implementation Directive (GAID) 2025 on 20 March 2025, the principal implementing directive of the Nigeria Data Protection Act 2023 (NDPA). The GAID came fully into force on 19 September 2025, replacing the Nigeria Data Protection Regulation (NDPR) 2019 as the operative enforcement instrument. It applies extraterritorially to any data controller or processor established outside Nigeria that processes personal data of Nigerian data subjects, imposes a tripartite cross-border transfer framework (adequacy decisions, Transfer Instruments, and statutory exceptions), mandates Data Protection Impact Assessments for AI and high-risk technologies, and carries a civil-penalty ceiling of 2% of annual gross revenue or NGN 10 million for designated data controllers and processors of major importance (DCPMIs), whichever is greater.
Indonesia's Ministry of Communications and Digital Affairs (Kemkomdigi) promulgated Permenkomdigi No. 5/2025 on 25 March 2025 as the implementing regulation under Government Regulation PP 71/2019 governing Public-Scope Electronic System Operators (PSE Lingkup Publik), defined as operators running electronic systems for government institutions or critical public services. The regulation mandates registration, data classification by risk level (low/medium/ high/strategic) with corresponding domestic storage and processing requirements, content- moderation governance, and access-blocking mechanisms for prohibited electronic information. All public-scope PSEs must achieve compliance by 25 March 2026, with non-compliant operators subject to progressive administrative sanctions under Articles 100-series ranging from written warnings to access disconnection (pemutusan akses) and removal from official registries.