Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
The Republic of Korea's National Assembly passed the Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trustworthiness ("AI Basic Act") in plenary session on 26 December 2024, consolidating 19 separate AI bills tabled in the 22nd National Assembly. The statute was promulgated on 21 January 2025 and takes effect on 22 January 2026 after a one-year preparation period. Korea becomes the second jurisdiction worldwide — after the EU AI Act — to enact a comprehensive horizontal AI law, and the first in the Asia-Pacific. The Act establishes a risk-tiered regime targeting "high-impact" AI in healthcare, energy, public services, employment decisions, and generative-AI labelling, with extraterritorial reach over foreign providers whose systems affect the Korean market or users (mandatory local representative). It creates an AI Safety Institute, a national AI policy "control tower," and R&D / standardisation programmes under MSIT. Penalties are modest by international comparison — fines up to KRW 30 million plus a one-year grace period before full enforcement.
The National Assembly of Vietnam passed the Law on Data (Luật Dữ liệu), No. 60/2024/QH15, on 30 November 2024; it enters into force on 1 July 2025. The Law is Vietnam's first comprehensive horizontal data-governance statute, extending regulation beyond personal data (already covered by Decree 13/2023/ND-CP) to all digital data — public, private, and sectoral. It introduces statutory categories of "important data" (dữ liệu quan trọng) and "core data" (dữ liệu cốt lõi) tied to national-defence and national-security review for cross-border transfer, and establishes the National Data Centre under the Ministry of Public Security plus a statutory data-broker / data-services licensing framework.
In two consecutive sectoral notifications, Pakistan's Special Technology Zones Authority (STZA) — a federal body under the Cabinet Division — formally declared two additional Special Technology Zones. The Khanpur Industrial Project (Mumrial, Khanpur, District Haripur, Khyber Pakhtunkhwa; ~197 acres / 199,174 sq ft of existing and proposed infrastructure) was notified on 12 September 2024. The LEOS Technology Zone (Lehtrar Road, Nilore, Islamabad; 19.23 acres / 225,562 sq ft) was notified on 8 November 2024. Both zones operate under the Special Technology Zones Authority Act, 2021 incentive regime, which provides Zone Enterprises and Zone Developers a 10-year exemption from income tax, customs duty on capital-goods imports, and sales tax (under the Customs Act 1969, Income Tax Ordinance 2001 and Sales Tax Act 1990), together with eligibility for Special Forex Accounts under State Bank of Pakistan regulations (no requirement to convert USD inflows to PKR). The umbrella incentive window for the STZA regime runs until 30 June 2035, with each zone enterprise's 10-year clock starting from the date the zone developer certifies commercial operation.
Regulation (EU) 2024/2847 of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, signed 23 October 2024 and entering into force 10 December 2024. The CRA is the first EU statutory cybersecurity regime covering all hardware and software products with a direct or indirect data connection placed on the EU market, imposing essential cybersecurity requirements, conformity assessment with CE marking, mandatory vulnerability handling, and 24-hour early-warning notification of actively-exploited vulnerabilities to ENISA. Main manufacturer obligations apply from 11 December 2027; conformity-assessment-body notification provisions apply from 11 June 2026 and reporting obligations from 11 September 2026. Penalties reach EUR 15M or 2.5% of global annual turnover.
The U.S. Treasury's Office of Foreign Assets Control (OFAC) published in the Federal Register (89 FR 84472–84474, FR Doc 2024-24524) three general licenses issued under the Western Balkans Stabilization Regulations (31 CFR Part 588): GL 3A, GL 4, and GL 5. All three were originally issued on 18 June 2024 concurrent with OFAC's expansion of Republika Srpska / Dodik-network designations; the 23 October 2024 Federal Register notice formalises them per the Administrative Procedure Act notice requirements. GL 3A (which superseded GL 3 of 16 November 2023) authorises transactions involving certain WBSR-blocked entities that are ordinarily incident and necessary to the exportation or re-exportation of agricultural commodities, medicine, medical devices, replacement parts and components, software updates, or activities involving medical prevention, diagnosis, treatment, or clinical trials. GL 4 authorises wind-down transactions with entities blocked on 18 June 2024 through a defined cutoff. GL 5 authorises transactions ordinarily incident and necessary to the manufacture, distribution, operation, installation, or maintenance/repair of drinking-water pumps manufactured or distributed by the WBSR-blocked Bosnian Serb entity Kaldera Company EL PGP d.o.o. (and 50%-or-more-owned subsidiaries), preserving municipal water supply continuity.
Norway's Ministry of Foreign Affairs amended the Eksportkontrollforskrift (Regulations on the export of defence- related products, dual-use items, technology and services) to add a new national control list — Annex III ("List III") — for emerging and disruptive technologies not yet covered by the EU dual-use list. Exports of items on Annex III require a licence from the Ministry of Foreign Affairs regardless of destination, including a catch-all licensing obligation. Controls cover semiconductor manufacturing equipment (including dry-etch apparatus), enriched silicon/germanium substrates, high- performance integrated circuits, quantum computers above specified controlled-qubit thresholds, quantum software and technology, software/technology for reverse-engineering integrated-circuit layouts, and additive-manufacturing equipment for metal/alloy components. The amendment, announced 3 October 2024 and effective 1 November 2024 (with a one-month transitional period), aligns Norway with parallel national measures adopted by the United States (BIS 6 Sep 2024 emerging- technology IFR), the Netherlands, the United Kingdom, Japan, Spain, Denmark and Finland.
Law 14.968/2024 establishes the Brasil Semicon program, extending and expanding semiconductor industry incentives through 2073 (aligned with Manaus Free Trade Zone benefits). Provides R$7 billion annually in tax incentives for semiconductor and ICT sectors, with R$21 billion committed through 2026. Expands PADIS eligibility to include chip design services and software, and calculates R&D credits on total revenue rather than domestic sales alone, encouraging exports.
The US Bureau of Industry and Security issued a final rule on 5 September 2024 (effective 6 September 2024, published in the Federal Register on the same day as 89 FR 73285) establishing multilateral export controls on four categories of emerging technologies: (1) quantum computing items including quantum computers, related cryogenic / control / measurement systems, and certain quantum software; (2) gate-all-around field-effect transistor (GAAFET) production technology — the next-node semiconductor architecture beyond FinFET; (3) advanced additive-manufacturing equipment for metals + alloys; (4) certain biotech-related items added in a parallel rule on 12 September 2024. The rule operates without country exceptions for some categories, with multilateral coordination via Wassenaar + Australia Group + Nuclear Suppliers Group frameworks.
BIS final rule (FR Doc 2024-19132, 89 FR 68539, published 27 August 2024) expanding the Russia/Belarus-Military End User (MEU) Foreign-Direct Product (FDP) rule under the Export Administration Regulations so that it also applies to transactions involving Entity List entries posing a significant diversion risk to Russia's and Belarus's defense industry or intelligence services — the rule is renamed accordingly. The rule also imposes new export, reexport, and in-country transfer controls on software for the operation of computer numerical control (CNC) machine tools destined for Russia or Belarus, and makes corrections eliminating obsolete cross- references introduced by the BIS 25 January 2024 and 18 June 2024 Russia/Belarus final rules. Effective 27 August 2024, except amendatory instruction 11 effective 16 September 2024.
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) issued a final rule amending three sanctions programs. The rule adds a new general license at 31 CFR § 525.512 to the Burma Sanctions Regulations authorizing the provision of agricultural commodities, medicine, medical devices, replacement parts and components for medical devices, and software updates for medical devices to individuals whose property and interests in property are blocked. It also updates the authorities section of the Burma Sanctions Regulations to reflect recent legislation, replaces "the Office of Foreign Assets Control" / "the Director of the Office of Foreign Assets Control" with the acronym "OFAC" in three sections of the Sudan Stabilization Sanctions Regulations, and corrects a cross-reference in the Ukraine-/Russia- Related Sanctions Regulations. The rule is effective on publication.
The U.S. Bureau of Industry and Security (BIS) published a final rule expanding the scope of the Iran Foreign Direct Product (FDP) rule in the Export Administration Regulations (EAR) to implement the "No Technology for Terror Act" (Public Law 118-50, Division N), signed by President Biden on April 24, 2024. The expanded rule extends EAR jurisdiction to additional foreign-produced items destined for Iran — including a broader set of items derived from U.S.-origin technology or software, or produced by plants/components that are themselves direct products of U.S.-origin technology — and requires a BIS license for their export, reexport, or in-country transfer to Iran. The rule also provides specified exclusions from the otherwise-applicable license requirements. The rule became effective on July 23, 2024 (publication July 26, 2024).
The Bureau of Industry and Security (BIS) issued an interim final rule (FR Doc. 2024-15810) amending the Export Administration Regulations (EAR) so that certain "releases" of technology and software during "standards-related activities" are no longer subject to the EAR. The rule revises 15 CFR §734.10 and consolidates the patchwork of prior carve-outs (May 2019 Huawei 5G TGL, June 2020 IFR, September 2022 Entity-List-wide IFR) into a single activity-based exclusion. The change enables US firms to participate in international standards bodies (IEEE, 3GPP, ITU, ISO, IEC) alongside Entity-Listed parties — most consequentially Huawei — without licence exposure. Comments were due September 16, 2024.
The European Union's Artificial Intelligence Act, Regulation (EU) 2024/1689, was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. It establishes the world's first horizontal, risk-tiered legal framework for the development, market placement, and use of AI systems — covering prohibited practices, high-risk systems, general-purpose AI models, and minimal-risk applications — with extraterritorial reach over any provider placing an AI system on the EU market or whose output is used in the EU. Penalties reach up to EUR 35 million or 7% of global annual turnover. Application is staged: prohibitions from 2 February 2025, GPAI and governance from 2 August 2025, the bulk of high-risk obligations from 2 August 2026, and product-safety-embedded high-risk systems from 2 August 2027.
The Bureau of Industry and Security (BIS) amended the Export Administration Regulations (EAR) by adding three Kaspersky entities to the Entity List under End-User Review Committee (ERC) determinations — AO Kaspersky Lab (Moscow), OOO Kaspersky Group (Moscow), and Kaspersky Labs Limited (London). All three are designated for cooperation with Russian military and intelligence authorities in support of Russian government cyber-intelligence objectives. Exports, reexports, and in-country transfers of all items subject to the EAR to the three entities now require a BIS licence reviewed under a policy of presumption of denial, with no licence exceptions available. The action is paired with a same-week Commerce ICTS final determination prohibiting Kaspersky cybersecurity and anti-virus software transactions in the United States.
BIS final rule (FR Doc 2024-13148, 89 FR 51644, RIN 0694-AJ87) expanding the Export Administration Regulations' Russia and Belarus sanctions architecture. Effective 12 June 2024 (most provisions) and 16 September 2024 (the EAR99 enterprise-software paragraph at §746.8(a)(8)), the rule introduces a new licence requirement for thirteen named categories of EAR99 enterprise software (ERP, CRM, BI, SCM, EDW, CMMS, project management, PLM, BIM, CAD, CAM, ETO) destined for Russia or Belarus; permits address-only Entity List designations to capture high-diversion addresses; adds eight Hong Kong addresses to the Entity List; and refines the Russia/Belarus Industry Sector Sanctions and Foreign Direct Product (FDP) rule. Released the day before the G7 Italy summit alongside coordinated OFAC, State, and Treasury actions that together designated 300+ persons and entities.
The U.S. Treasury's Office of Foreign Assets Control (OFAC) issued a final rule amending 31 CFR § 560.540 of the Iranian Transactions and Sanctions Regulations (ITSR) to incorporate, with amendments, General License (GL) D-2 — originally issued on OFAC's website on September 23, 2022 — which authorizes the export, reexport, and provision of certain services, software, and hardware incident to communications over the internet to persons in Iran. The codification preserves the GL D-2 expansion (cloud-based services; third-country importation of hardware/software previously exported to Iran; ex-Iran installation, repair and replacement services; case-by-case licensing for internet-freedom activities) and updates the § 560.540 List of Services, Software, and Hardware Incident to Communications. Effective June 17, 2024, the List is amended to exclude laptops, tablets, and personal computing devices with an Adjusted Peak Performance (APP) exceeding 1 Weighted TeraFLOP (WT) — narrowing the consumer-electronics authorization to lower-performance devices and aligning the carve-out with broader BIS-style compute thresholds. The rule does not relax primary ITSR prohibitions; it codifies a humanitarian / internet-freedom exception while inserting a narrow high-performance-compute carve-out.
The Bureau of Industry and Security (BIS), within the U.S. Department of Commerce, published an interim final rule (FR Doc 2024-08813) on April 30, 2024 amending the Export Administration Regulations (EAR) to restructure export controls on firearms, ammunition, parts, accessories, and related technology and software (EAR Categories 0 and 1). The rule created new Export Control Classification Numbers (ECCNs) for semi-automatic firearms, added Crime Control / Detection (CC) license requirements, narrowed license-exception eligibility, introduced a presumption of denial for many non-government end-users, and imposed a default 1-year license validity for semi-automatic firearms. Effective May 30, 2024; later rescinded (except for the new ECCNs) by FR Doc 2025-18992 on September 30, 2025.
Loi n° 2024-449 of 21 May 2024, known as the SREN law (Sécuriser et Réguler l'Espace Numérique), was definitively adopted by the French Parliament on 10 April 2024, validated in part by the Conseil Constitutionnel on 17 May 2024 (Decision n° 2024-866 DC), promulgated by the President on 21 May 2024, and published in the Journal Officiel on 22 May 2024. SREN is France's digital-sovereignty omnibus statute: it transposes parts of the EU Digital Services Act (Regulation 2022/2065), Digital Markets Act (Regulation 2022/1925), and Data Governance Act (Regulation 2022/868) into French law and layers national-level instruments on top — most consequentially a data-localisation hook for sensitive public-sector data tied to the ANSSI SecNumCloud sovereign-cloud certification scheme, an ARCOM-enforced age-verification regime for adult-content sites (with €250k or 2%-of-turnover fines and account-closure powers), an "anti-scam" cybersecurity filter requiring browsers and DNS resolvers to block ANSSI-designated fraudulent domains, a jeux-en-ligne (JONUM) regime for cryptoasset-adjacent gaming, and a coordination framework between CSA, CNIL, ARCOM, and the Autorité de la concurrence. SREN is one of the first EU member-state digital omnibus statutes anchoring national public-sector data-hosting rules to a sovereign-cloud certification scheme.
Three-year export-promotion policy issued by the Bangladesh Ministry of Commerce on 25 February 2024 covering FY2024-25 through FY2026-27. Sets a $110bn merchandise+services export target by FY2026-27 (vs. ~$56bn FY2023-24 base), restructures the cash-incentive regime, and designates "highest priority" and "special development" sectors including ready-made garments, leather, jute, ICT, pharmaceuticals, agro-processing, light engineering, and plastics. Explicitly designed as the transition framework for navigating Bangladesh's LDC graduation (effective 24 November 2026), at which point the country will lose EU Everything-But-Arms duty-free access and face an estimated 10% average MFN tariff on EU exports.
Ministerial order signed by the French Minister of Economy on 2 February 2024 and published in JORF n°0034 of 10 February 2024 establishing France's first national export-control list under Article 9 of EU Regulation 2021/821 on dual-use goods. The arrêté requires prior authorisation for exports to non-EU third countries of (i) quantum computers and their enabling technologies (qubit devices, control systems, measurement equipment) and (ii) equipment for the design, development, production, test and inspection of advanced electronic components, plus associated software and technology. The annex was substantively replaced by the Arrêté du 27 mars 2025 (explicit technical thresholds including ≥34-qubit systems with C-NOT error ≤10⁻⁴, HBM 6000+ processing performance, cryogenic cooling, dry-etch and EUV-mask tooling, and Si-28/Si-30/Ge isotopically-controlled materials) and is repealed by the Arrêté du 10 mars 2026 with entry into force 11 May 2026.