Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
The Federal Acquisition Regulatory Council (DOD, GSA, and NASA) published a Notice of Proposed Rulemaking on 17 February 2026 (FR Doc 2026-03065, 91 FR 7223) implementing Section 5949(a) of the NDAA FY2023 (Pub. L. 117-263), which bars executive agencies from acquiring electronic products or services containing semiconductor components designed, produced, or provided by SMIC, CXMT, YMTC, or their affiliates. A Part B prohibition extends the restriction to "critical systems" whose subsystems incorporate covered semiconductors regardless of COTS sourcing. The comment period closed 20 April 2026; proposed prohibitions take effect 23 December 2027.
Pakistan's Directorate General of Customs Valuation (Karachi), acting under the Federal Board of Revenue, issued Valuation Ruling No. 2035/2026 on 16 January 2026 under Section 25A of the Customs Act, 1969, fixing revised minimum customs (C&F) values for 62 models of old and used branded mobile phones (Apple, Samsung, Google Pixel, OnePlus) imported in commercial quantity without original packaging or accessories, conditional on the device having been activated at least six months before export. The revision was a downward rationalization — press reporting cites benchmark values ranging from US$25 (iPhone SE, 1st/2nd generation) up to US$460 (iPhone 15 Pro Max) — bringing declared-value floors back in line with a documented decline in global secondary-market prices for older-generation devices. Global Trade Alert logs China as the principal origin affected.
Türkiye's Ministry of Trade published Tebliğ No. 2026/13 ("İthalatta Gözetim Uygulanmasına İlişkin Tebliğ") in the Official Gazette on 31 December 2025 (Sayı 33124, 4th mükerrer), entering into force 30 days later on 30 January 2026. It imposes a forward-looking import surveillance regime on television dish (satellite) antennas: imports priced at or below a Ministry-set reference unit customs value require a surveillance certificate ("gözetim belgesi") issued electronically before customs clearance. Global Trade Alert logs the measure as a discrete "certainly harmful" import-licensing intervention (MAST Chapter E: non-automatic licensing), naming China, Czechia and France among the affected exporting countries; the exact GTİP line and USD/unit threshold are not publicly disclosed.
Taiwan's Legislative Yuan passed the Artificial Intelligence Basic Act (人工智慧基本法) on third reading on 23 December 2025, and President Lai Ching-te promulgated the 20-article statute on 14 January 2026, bringing it into force immediately. The Act designates the National Science and Technology Council (NSTC) as the central AI-policy competent authority and codifies seven governance principles — sustainability and well-being, human autonomy, privacy protection and data governance, cybersecurity and safety, transparency and explainability, fairness and non-discrimination, and accountability — that apply to all public-sector AI procurement and high-risk sectoral applications. The statute establishes a statutory foundation for the Taiwan AI Action Plan 2.0, mandates an Executive Yuan National AI Strategy Committee, and provides authority for sector-specific implementing regulations by FSC, NCC, MOHW, and MOTC across finance, telecoms, medical, and autonomous-vehicle AI within a two-year window. As the first national AI governance statute in the Greater China region and the third globally after the EU AI Act and South Korea's AI Basic Act, it frames regulatory expectations for the companies at the heart of the global AI hardware supply chain — TSMC, NVIDIA ODM partners, and advanced-packaging incumbents — that are headquartered or operate substantially in Taiwan.
On 22 December 2025 the FCC's Public Safety and Homeland Security Bureau released Public Notice DA-25-1086, adding to the Covered List (under section 1709 of the FY2025 NDAA) all unmanned aircraft systems (UAS) and UAS critical components produced in a foreign country, plus communications and video-surveillance equipment/services produced by DJI Technologies and Autel Robotics (and their subsidiaries, affiliates, and licensing/JV partners). The designation is comprehensive by scope — every foreign-made drone from consumer quadcopters to large uncrewed systems, with no size/performance carve-out — and blocks the FCC from granting any new equipment authorization to covered UAS/components going forward. Previously authorized models already in the US market are not revoked. A follow-on Public Notice (DA-26-22, 7 January 2026) narrowed the scope with a temporary exemption (see amendments).
Vietnam's National Assembly passed Law on Cybersecurity No. 116/2025/QH15 on 10 December 2025 (434 of 443 deputies in favour), effective 1 July 2026. The law supersedes both the 2018 Cybersecurity Law (Law 24/2018/QH14) and the 2015 Law on Cyber Information Security, consolidating cybersecurity, cyber-information-security, and network-information-security into a unified Ministry of Public Security-led framework. It retains data-localization obligations for foreign digital-service providers handling personal data, user-generated content, and relationship graphs of Vietnamese users (minimum 24-month retention), introduces 6-hour urgent / 24-hour standard content take-down windows on MPS request, expressly prohibits AI/deepfake forgery of images, voices, and videos for illegal purposes, and mandates child-safety platform measures.
Italy enacted Legge 23 settembre 2025, n. 132 — "Disposizioni e deleghe al Governo in materia di intelligenza artificiale" — published in Gazzetta Ufficiale Serie Generale n. 223 of 25 September 2025 (atto 25G00143) and entered into force on 10 October 2025. The statute makes Italy the first EU member state to enact a comprehensive national AI law complementing Regulation (EU) 2024/1689 (EU AI Act), designating AgID (Agency for Digital Italy) and ACN (National Cybersecurity Agency) as national oversight authorities under Presidency-of-the-Council-of-Ministers coordination. It sets sectoral rules for healthcare, labour, intellectual professions, public administration and the judiciary; authorises up to €1 billion in state-backed venture capital (via CDP Venture Capital) for AI, cybersecurity and telecoms; creates criminal penalties of up to five years' imprisonment for harmful deepfakes; mandates parental consent for under-14 users; and delegates secondary legislation to the Government across multiple domains.
The FCC adopted a Report and Order (FCC 25-49) on 7 August 2025 — the first comprehensive overhaul of submarine cable landing license rules since 2001 — effective 26 November 2025. The order prohibits Indefeasible Right of Use (IRU) agreements that would give entities from designated foreign adversary countries (China including Hong Kong and Macau, Cuba, Iran, DPRK, Russia, and Venezuela) control over Submarine Line Terminal Equipment (SLTE) on US cable landings, and mandates new annual reporting plus certification/disclosure requirements covering ownership, cybersecurity and physical security plans, and FCC Covered List compliance. The order operationalises the FCC's bifurcated policy package: accelerating legitimate commercial cable buildout while hardening national-security review for foreign-adversary-connected infrastructure.
The Nigeria Data Protection Commission issued the General Application and Implementation Directive (GAID) 2025 on 20 March 2025, the principal implementing directive of the Nigeria Data Protection Act 2023 (NDPA). The GAID came fully into force on 19 September 2025, replacing the Nigeria Data Protection Regulation (NDPR) 2019 as the operative enforcement instrument. It applies extraterritorially to any data controller or processor established outside Nigeria that processes personal data of Nigerian data subjects, imposes a tripartite cross-border transfer framework (adequacy decisions, Transfer Instruments, and statutory exceptions), mandates Data Protection Impact Assessments for AI and high-risk technologies, and carries a civil-penalty ceiling of 2% of annual gross revenue or NGN 10 million for designated data controllers and processors of major importance (DCPMIs), whichever is greater.
Japan's National Diet enacted the Cyber Response Capability Enhancement Act (重要電子計算機に対する不正な行為による被害の防止に関する法律, Law No. 42 of 2025) on 16 May 2025, together with companion arrangement legislation. Commonly known as the Active Cyber Defense (ACD) Law, the statute authorises (i) government monitoring of foreign-origin internet traffic transiting designated Japanese communication infrastructure for national-security threat indicators, (ii) pre-emptive access and neutralisation operations against attacker infrastructure abroad by the National Police Agency and the Self-Defense Forces under unified command, and (iii) mandatory cyber-incident reporting and government cooperation duties on critical-infrastructure operators. Implementation is phased through November 2027, with the NISC reorganised into the National Cybersecurity Office (NCO) under the Cabinet Secretariat from July 2025.
Malaysia's Personal Data Protection (Amendment) Act 2024 (Act A1727), gazetted 17 October 2024, enters its third and final commencement phase on 1 June 2025 per commencement order P.U.(B) 522/2024. Phase 3 activates sections 6 and 9 of the amending Act, which impose mandatory Data Protection Officer (DPO) appointment thresholds, a 72-hour breach-notification duty to the Commissioner, and a statutory data-portability right, bringing Malaysia's PDPA broadly into alignment with GDPR and the ASEAN Model AI Governance Framework.
FinCEN published a final rule (FR Doc 2024-23920, 89 FR 83782, effective on publication October 18, 2024) clarifying the public-utility exemption to the Corporate Transparency Act's beneficial ownership information (BOI) reporting rule. The amendment to 31 CFR 1010.380(c)(2)(xv) corrects a drafting cross-reference so the exemption explicitly covers any regulated public utility under 26 U.S.C. 7701(a)(33)(A) *or* (D) that provides telecommunications services, electrical power, natural gas, or water and sewer services within the United States. The change codifies FinCEN's June 10, 2024 telecommunications-provider guidance and is effective immediately upon publication; it neither expands nor restricts the underlying universe of reporting companies beyond aligning the rule text with the CTA statute.
On 6 September 2024 China's National Development and Reform Commission (NDRC) and Ministry of Commerce (MOFCOM) jointly issued Order No. 23, the Special Administrative Measures (Negative List) for Foreign Investment Access (2024 Edition), effective 1 November 2024. The 2024 list reduces nationwide restrictions from 31 to 29 entries, removing the last two manufacturing- sector restrictions (publication printing must be Chinese-controlled; investment in TCM-decoction steaming/roasting/calcination processes and confidential-formula proprietary Chinese-medicine production prohibited). Restrictions remain in services (telecommunications value-added, healthcare, education) and in 21 prohibited categories (news publishing, postal monopoly, fishing, gene therapy, tobacco). The 2021 edition is repealed on the same date.
The Bureau of Industry and Security (BIS) issued an interim final rule (FR Doc. 2024-15810) amending the Export Administration Regulations (EAR) so that certain "releases" of technology and software during "standards-related activities" are no longer subject to the EAR. The rule revises 15 CFR §734.10 and consolidates the patchwork of prior carve-outs (May 2019 Huawei 5G TGL, June 2020 IFR, September 2022 Entity-List-wide IFR) into a single activity-based exclusion. The change enables US firms to participate in international standards bodies (IEEE, 3GPP, ITU, ISO, IEC) alongside Entity-Listed parties — most consequentially Huawei — without licence exposure. Comments were due September 16, 2024.
Signed by President Javier Milei and the entire cabinet on 20 December 2023 and published in the Boletín Oficial extraordinario on 21 December 2023, Decreto de Necesidad y Urgencia 70/2023 declares a public emergency across economic, financial, fiscal, administrative, pension, tariff, sanitary, and social matters until 31 December 2025 (Article 1) and enacts 366 articles across 16 titles that fundamentally restructure Argentina's regulatory framework. The DNU repeals or amends dozens of statutes to deregulate foreign trade (repealing the Compre Nacional buy-preference law Ley 18.875 and the price-control framework Ley 27.345), opens privatisation of state enterprises (Aerolíneas Argentinas, ENARSA, Banco Nación, Correo Argentino, Trenes Argentinos), dismantles the Ley de Abastecimiento price-control regime, liberalises civil aviation cabotage to foreign carriers, deregulates hydrocarbons export and mining permitting, and replaces the severance-pay regime with a capitalisation-fund system. It is the foundational enabling framework for all subsequent Milei-administration deregulatory instruments filed on the IPTM register, including RIGI (Law 27.742), Decreto 38/2025, Decreto 449/2025, and Decreto 563/2025.
The Bureau of Industry and Security (BIS) issued an interim final rule (IFR, 87 FR 55241, FR Doc. 2022-19415) amending the Export Administration Regulations (EAR) to authorize the release of specified items to all entities on the Entity List without a licence when such release occurs in the context of a "standards-related activity." The IFR expanded a narrower June 2020 predecessor that had applied only to Huawei and its affiliates; this 2022 rule extended equivalent authorization to the full Entity List. Authorized items include EAR99 technology and software, items controlled solely for anti-terrorism (AT) reasons, and certain cryptographic technology (ECCNs 5D002 and 5E002) used in standards development. The rule amended 15 CFR §§ 734.10, 744.11, 744.16, and Part 772 and was superseded by a broader 2024 IFR that recasted the carve-out as an activity-based exclusion from EAR jurisdiction entirely.
Government Decree 53/2022/ND-CP, signed 15 August 2022 and effective 1 October 2022, implements Article 26 of Vietnam's 2018 Law on Cybersecurity. It mandates in-country storage of three categories of data — personal data of users in Vietnam, user-generated data, and user-relationship data — for both domestic and foreign cyberspace- service providers, with a minimum 24-month retention period. Foreign enterprises providing telecoms, data storage, domain names, e-commerce, online payments, social networks, online video games, or messaging services to users in Vietnam must establish a Vietnamese branch or representative office within 12 months of a Minister of Public Security written request. The decree closes a four-year implementation gap on the 2018 Cybersecurity Law and is the principal Vietnamese digital-trade barrier alongside Decree 13/2023/ND-CP (Personal Data Protection).
The Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法 — PIPL) was adopted at the 30th meeting of the 13th NPC Standing Committee on 20 August 2021 and entered into force on 1 November 2021, constituting the third and final pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Data Security Law (2021). The PIPL is China's comprehensive personal-information statute establishing consent-based and necessity-based legal bases for PI processing, a tiered cross-border personal-data transfer regime (CAC security assessment / PI protection certification / Standard Contractual Clauses), extraterritorial application (Art. 3) to non-Chinese controllers offering services to or analysing the behaviour of PRC residents, and a heightened protection regime for sensitive personal information and data of minors under 14. It mandates data-protection impact assessments, personal-information-protection-officer obligations at designated handlers, breach notification, and a full suite of data-subject rights including access, rectification, deletion, portability, objection, and automated- decision-making opt-out. Article 53 requires overseas controllers to establish a domestic representative or designated entity in China, providing a domestic enforcement counterparty.
The Data Security Law of the People's Republic of China (中华人民共和国数据安全法) was adopted at the 29th meeting of the 13th NPC Standing Committee on 10 June 2021 and entered into force on 1 September 2021, constituting the second pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Personal Information Protection Law (2021). The DSL establishes a tiered data-classification regime — "important data" and "national core data" — with escalating security obligations including risk assessment, risk monitoring, breach reporting, and classified-protection requirements for data handlers. It introduces a data-export security review for "important data" generated or collected within China, the statutory parent authority operationalised by the 2024 CAC Cross-Border Data Flow Provisions, and enacts a §36 blocking statute prohibiting Chinese organisations and individuals from transferring data stored in China to foreign judicial or law-enforcement authorities without prior PRC government approval.
MOFCOM Order No. 4 of 2020, issued and effective 19 September 2020, establishes the Unreliable Entity List (UEL / 不可靠实体清单) regime — China's primary countermeasure framework for designating foreign companies, organisations, and individuals that are deemed to endanger Chinese national sovereignty, security, or development interests, or that apply discriminatory measures against Chinese entities in violation of normal market principles. The UEL inter-ministerial Working Mechanism, administered through MOFCOM, may impose restrictions or prohibitions on the designated entity's China-related import/export activities, investment in China, and entry or stay of senior personnel in China, as well as fines. Promulgated under the Foreign Trade Law of the PRC and the National Security Law of the PRC, the Provisions serve as the statutory parent for every UEL designation announcement since 2023, and operate as the structural peer of the US BIS Entity List / OFAC SDN architecture and the simultaneously promulgated Anti-Foreign Sanctions Law framework.
The Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法) was adopted at the 24th meeting of the 12th NPC Standing Committee on 7 November 2016 and entered into force on 1 June 2017, establishing the foundational legal framework for network security governance across all sectors. The law creates the Critical Information Infrastructure Operator (CIIO) designation and protection regime administered by the Cyberspace Administration of China (CAC), mandates data localisation for personal information and important data collected or generated by CIIOs in China, and establishes cross-border data-transfer security assessment requirements under Article 37 — the provision later operationalised by DSL 2021, PIPL 2021, and the 2024 CAC Cross-Border Data Flow Provisions. The CSL introduced multi-level protection scheme (等级保护制度 / MLPS) obligations for all network operators and network-product/service security-review procedures, under which CAC triggered the cybersecurity review of Didi Global in 2021 and the exclusion of Micron's products from Chinese critical-infrastructure projects in 2023.