So… other than publicity, and maybe some secondary sanctions exposure, what was the value, if any, of that update? VTB was already subject to an asset freeze, no? explain in language for the common public
Claude’s initial response, which I took issue with:
You’re right about the core of it. VTB’s money was already frozen. Nothing about how an American bank handles a VTB hit changed on Sunday. Blocked is blocked, and there is no such thing as more blocked. If the only audience were US institutions, this update would be paperwork.
The audience is not US institutions.
The new tag changes which rulebook foreign banks apply. Russia sanctions and Iran sanctions are not two flavors of the same thing to a bank in Dubai, Istanbul, Mumbai or Shanghai. The Russia rules that expose foreign banks to US penalties are discretionary. Treasury may act against a foreign bank that handles significant business for a sanctioned Russian entity, and in practice it has acted sparingly, often with a warning first. The Iran rules are older, partly written by Congress rather than the President, and carry mandatory triggers. Foreign bank boards have long memories about what happened to institutions that got caught on the wrong side of Iran sanctions in the 2010s, and the fines involved.
There is a second layer that has nothing to do with US law. Many non-US banks write their own internal policies so that any Iran connection is a hard stop, while Russia exposure gets a case-by-case review. Adding an Iran tag to VTB can therefore trip a stricter internal rule automatically at institutions that had been carefully doing limited Russia business. That is my read from how these policies are typically drafted, not something Treasury said.
The designation also outlives a Russia deal. This is the part I would put first if I were writing it for a general reader. There is real talk of the Ukraine war ending and of Russia sanctions being unwound as part of a settlement. If that happens, VTB’s Russia designations come off. The Iran designation would not, because it rests on different conduct under a different authority. Think of a condemned building. A second violation notice does not make it more condemned, but if the first notice is withdrawn, the second one still keeps the doors locked. Treasury has bought itself a lock that a Russia peace deal does not open.
And it puts the accusation on the public record. Until this week, a foreign bank could plausibly say it had no idea VTB was running correspondent accounts for sanctioned Iranian banks or moving frozen Iranian assets. Now that claim is on a US government page with VTB’s name on it. Nobody gets to be surprised anymore, and “we didn’t know” stops being available as a defense.
One smaller thing that matters to people who run screening systems. OFAC took 21 of VTB’s old names, things like plain “VNESHTORGBANK,” and moved them from “used to be called this” to “also called this.” Some screening setups treat former names as lower priority or filter them out. Those 21 names just came back to full strength, and no press release explains why.
So the honest summary is that this update does very little to VTB’s money and quite a lot to VTB’s remaining business relationships and to the government’s negotiating position. Which is roughly what you would expect from a campaign whose stated goal is isolation rather than seizure.
My follow-up:
well, if you were already defying the US Russia sanctions, how likely is it that this would change your behavior? Is it just because the President is more focused on Iran now than Russia? And would it really change the behavior of Chinese firms?
And the response:
Your first question mostly answers itself, and it exposes something soft in what I told you earlier.
Anyone still clearing business for VTB in September 2026 has already made peace with being outside the US financial system. That population is self-selected for indifference. Adding a tag to a party you were already willing to be caught dealing with is not a new deterrent, it is the same deterrent restated. The banks that could be moved by this are the ones with US correspondent accounts they still want to keep, and those banks mostly exited VTB in 2022. So the group sitting between “already gone” and “already defiant” is thin.
I also overstated one thing. I said the Iran rules carry mandatory triggers where the Russia ones are discretionary. That is true of the statutory Iran provisions, CISADA and IFCA and the NDAA correspondent-account section, but it is not true of what OFAC actually invoked here. Treasury’s own release says OFAC “can prohibit or impose strict conditions on” a foreign bank’s correspondent account. That is permissive language. The legal difference between the Russia exposure and the new Iran exposure is narrower than I made it sound. What is genuinely different is reputational, not statutory.
On whether this is about presidential attention, largely yes, and I would put it more bluntly than I did. Treasury is running an Iran campaign that needs visible targets while it is simultaneously negotiating over Russia. Hitting VTB under a Russia authority would cut across the negotiation. Hitting the same bank under an Iran authority produces the headline without disturbing that track. The choice of authority is doing diplomatic work as much as legal work. The durability point I raised stands, since an Iran designation survives a Russia settlement, but I should be clear that is a benefit to Treasury’s future position rather than a cost imposed on VTB today.
Chinese firms are the weakest part of the case. The large state banks pulled back from VTB years ago and have run conservative Iran policies since the last decade. Nothing here reaches them because they already left. The institutions that do handle sanctioned trade are small regional banks with no dollar business to lose, and the precedent for how that plays out is Bank of Kunlun, which the US designated in 2012 over Iran and which China then simply used as the designated channel. Cutting a bank off from a system it does not use is not much of a penalty. Add that a growing share of this trade settles in renminbi through CIPS, and the lever you are pulling is attached to nothing.
Where I think there is real value, and it is plumbing rather than deterrence, is that a designation under an Iran authority creates a predicate for designating the people who help VTB with its Iran business. Those orders generally include a materially-assisted prong, though I have not pulled the text of 13902 to confirm the specific wording. If that is right, the update is less a punishment of VTB than a hook for whoever gets named next.
so, maybe not Much Ado About Nothing, but more like Much Ado About Something Possibly in the Future…. meh.
Attached is today’s State Department Fact Sheet on “Operations Economic Outcast” and Treasury’s related press release. Also attached are Treasury Secretary Bessent’s related remarks. Look at these, and any 3rd party news and commentary pieces on today’s OFAC action. Summarize what happened, and analyze the short-term and longer-term implications of these actions. What is substantive, and what is rhetorical? Are there measures that will be implemented in the really near future, such that US consumers and voters are likely to see tangible benefits from these actions by Election Day in November 2026? Add any other commentary you find that adds to the overall picture. Check all that you write against the sources you use – and correct anything that is not well-supported by the sources. List the sources at the end. No hallucinations, please. Write this for an audience that has interest in US politics and the economy, but is not necessarily well-versed in sanctions except in the most basic way – so write accordingly.
And here is Claude’s analysis of yesterday’s Iran sanctions actions and rhetoric – with some significant pushback from me on some elements that Claude initially thought too much of:
Treasury and State spent August 24 rolling out “Operation Economic Outcast” with the kind of language usually reserved for military campaigns: an “economic D-Day,” a “zero leakage” approach, nearly 60 new entries on the SDN list, and five new sectoral determinations under Executive Order 13902 covering digital assets, technology, gold, aviation, and shipping. Secretary Bessent framed it as the start of a sustained campaign to collapse every remaining option for Tehran.
That’s a lot of rollout. The burning question is how much of it is actually new, once you get past the press conference and into the designation text itself.
The determinations nobody used
Start with the five sectoral determinations, since that’s where the branding worked hardest. E.O. 13902 isn’t a new authority. Trump signed it in January 2020 to cover construction, mining, manufacturing, and textiles. Treasury added the financial sector that October. Petroleum and petrochemicals followed in October 2024. Digital assets, technology, gold, aviation, and shipping are the fourth round of sector additions to an order that’s now six and a half years old.
That history matters for a second reason beyond age. Iran and the Government of Iran are already subject to a comprehensive US embargo under the ITSR. A sectoral determination adds nothing to what a US person is already barred from doing with Iran directly. Its entire function is secondary sanctions exposure for non-US persons. That works by giving OFAC an easier evidentiary path, operating in the sector rather than proving a specific significant transaction, to reach someone who isn’t otherwise within US jurisdiction. Whether a determination matters in practice depends entirely on whether OFAC designates anyone under it.
So who did OFAC designate today under the five new sectors? Nobody. Every one of the roughly 60 new entries in the State Department fact sheet and the Treasury press release cites an authority that predates this week.
Authority
What it covers
Used for today’s designations?
E.O. 13382 (2005)
WMD and missile proliferation
Yes, the Hong Kong/China procurement network supporting Malek Ashtar University, the BRE Line logistics network
E.O. 13694, as amended (2015 onward)
Malicious cyber activity
Yes, the six individuals tied to Iran’s Ministry of Intelligence and Security
E.O. 13224, as amended (2001)
Counterterrorism
Yes, Mohammad Ahmed Suhil Fattouh, Ivan Obukhov, and their shipping vehicles
Yes, the shadow fleet vessels and owners, the Wellbred trading network
E.O. 13949 (2020)
Conventional arms
Yes, the seven Iranian military officials named by State
E.O. 13846 (2018)
JCPOA reimposition, petroleum trade
Yes, the petrochemical traders named by State
E.O. 13902, the five sectors added Aug. 24, 2026
Digital assets, technology, gold, aviation, shipping
No
Five new sectors, zero new designees. That’s worth sitting with, because it’s a useful diagnostic for reading any Treasury rollout of this size. The announced legal architecture and the actual designation list are two different documents, and they don’t have to move together. A determination is Treasury giving itself a faster path to designate people operating in a sector. It isn’t a designation. Until OFAC puts a name under one of the five new sectors, the practical effect on Iran’s economy from that piece of Monday’s announcement is exactly zero, no different from the day before the press conference.
There’s a comparison worth keeping in mind for judging how much these five sectors could eventually matter. When Treasury added the financial sector to E.O. 13902 in October 2020, analysts flagged it at the time as functionally close to a full embargo, since almost any transaction with an Iranian counterparty eventually touches Iran’s banking system somewhere. A narrower sector, like textiles or mining, only closes off that one line of business, and a counterparty can just trade in something else. Of this week’s five, shipping and gold probably have that kind of financial-sector-style reach, since they sit close to how Iran actually moves and stores value. Digital assets and technology are narrower by comparison, and aviation narrower still. None of that is testable yet. It’s a question about which sector Treasury reaches for first, once it reaches for any of them. Bessent told reporters he expects Treasury to designate a major financial institution later this week. Whether that designation cites one of Monday’s five new sectors, rather than the financial sector determination that’s already existed since 2020, is the detail worth checking when it happens.
What the general license suspensions actually touch
The other piece of Monday’s announcement billed as tightening the screws is the suspension of several general licenses. The Treasury release describes them as licenses that had authorized certain remittance payments to Iran and Iranian access to the US cultural and academic system. OFAC’s own recent actions listing for August 24 confirms Iran General License G, the academic exchange license in place since 2014, covering university exchange agreements, scholarships, and the administration of entrance exams for Iranian applicants, along with a license covering professional and amateur sports exchanges. Trade press reporting also has the personal, noncommercial remittance license under 31 CFR 560.550 suspended, with a wind down running through roughly September 8 under a newly issued General License BB.
That’s a real change for the people who use those licenses. It isn’t a real change for the IRGC or for regime leadership, and the reason is built into how the licenses were written. General licenses covering personal remittances and academic exchange exist because they were carved out of the comprehensive embargo for individuals and civil society. As a matter of standard OFAC drafting, that class of license already excludes the Government of Iran and any blocked person from using it. The IRGC was never moving money through a remittance channel covered by GL 560.550, and regime officials weren’t the ones administering entrance exams under GL G. The population that loses access when these licenses come off the board is Iranian civilians receiving money from family abroad, and Iranian students, researchers, and athletes trying to participate in exchange programs. Regime and IRGC finance runs through exchange houses, shadow banking networks, gold, and crypto, the same channels the new designations and the sectoral determinations are aimed at, not through a university scholarship program.
That’s a real tension in how Monday’s action describes itself. The stated target throughout is the regime and its enablers. The general license suspensions land somewhere else, on ordinary Iranians and on the people-to-people channels Iran sanctions programs have historically tried to preserve even during periods of maximum pressure, not on the regime the campaign says it’s targeting.
What this adds up to
None of this makes Monday’s action empty. Roughly 60 new SDN entries is a real expansion of target lists in networks already under scrutiny: the Hong Kong and China procurement chains, the shadow fleet, the MOIS cyber cluster, the oil brokerage networks running through the UAE and Singapore. Those designations use existing, well-tested authorities. They carry the consequences designations ordinarily carry:
Blocked property in the United States or in the hands of US persons
Correspondent banking exposure for foreign financial institutions that keep dealing with the newly listed parties
A paper trail other governments and banks will have to account for in their own due diligence
The two pieces of Monday’s announcement built to sound the most unprecedented are the five new sectors and the general license suspensions. They’re also the two doing the least actual work right now. The determinations haven’t been used yet. The license suspensions hit civilians rather than the regime they’re framed as targeting. That’s a pattern worth checking for in any sanctions rollout that leans hard on scale and language. Look at what got designated under the headline new authority before assuming the headline new authority did anything. If Treasury designates a bank or a shipping registry under the aviation or shipping determination in the coming weeks, that’s the moment the unprecedented framing starts to earn itself. Until then, it’s capacity, not action.
Source verification
Sources checked directly: the State Department fact sheet and the Treasury press release announcing Operation Economic Outcast, both dated August 24, 2026; Secretary Bessent’s prepared remarks from the same day; and OFAC’s own recent actions listing for August 24, 2026, which confirms the suspension of Iran General License G and the sports and cultural exchange license. Every legal basis cited above for the roughly 60 new designations was checked against the authority codes in the two primary announcements rather than assumed. The E.O. 13902 sector determination history (2020 construction, mining, manufacturing, and textiles; October 2020 financial sector; October 2024 petroleum and petrochemicals) is confirmed against OFAC FAQ 831 and contemporaneous client alerts from that period. The personal remittance general license under 31 CFR 560.550 and the General License BB wind down window were reported by trade press covering the rollout and have not yet been independently pulled from OFAC’s own general license text. Treat that specific detail as reported rather than primary source confirmed until the underlying license is checked directly.
Let’s assume I am the sanctions officer at a company with a fair number of high-risk segments of my business – not a small number, but nowhere near a majority. And we built an Ai model to evaluate transactions, documents and third party records for sanctions matches, such that the model recommends and presents all its research for a human to evaluate. Based on changes to Russian and Iranian sanctions from July 1, 2024 to June 30, 2026, including changes in designations, guidance, licensing and any other relevant content published by UK, EU and/or U S regulators, how many times would we have likely needed to retrain our model over that 24 month period? Explain when and why, in non-legal language (not a lawyer). check your response against your sources and flag and correct anything that is not well-supported by them. List your sources. Assume that my firm has a pretty full range of exposure, including crypto, securities and maritime shipping.
And the response:
Quick framing before the timeline: your model does two different jobs, and they don’t need retraining at the same rate.
One job is matching against reference data – SDN entries, the EU consolidated list, the UK sanctions list, vessel IMO numbers. That data changes constantly (weekly, sometimes daily) and shouldn’t require retraining at all if the system is built the way most of these tools are – list content lives in a lookup layer, and the model just queries it. That’s a data refresh, not a retrain.
The other job is pattern recognition – reading a bill of lading and recognizing deceptive shipping language, following an ownership chain through three shell layers, flagging a stablecoin flow that looks like sanctions evasion. That’s the part that goes stale when the underlying typology changes – a genuinely new evasion pattern, a new category of prohibited conduct, a new legal test for what counts as “control.” That’s what actually calls for retraining.
I’m assuming your model is architected with that separation (list-matching decoupled from typology-modeling), since that’s how compliance vendors generally build these systems. If yours instead has entity names baked into model weights, the honest answer is “constantly” – so it’s worth confirming that assumption internally.
With that framing, here’s my read of the 24 months.
Bottom line
My estimate: somewhere around 6-7 retrain-worthy events, clustering unevenly rather than spread on a fixed cadence. About three of those are large enough (new prohibition categories, a rebuilt legal architecture, a switch from name-by-name matching to categorical rules) that I’d call them full retrains rather than targeted updates.
The waves, in plain terms
1. October 31, 2024 – OFAC maritime shipping guidance. Treasury published scenario-based guidance describing deceptive shipping patterns – falsified bills of lading, AIS location-spoofing to hide ship-to-ship transfers, SDN proxies buried in trade documents issued to help maritime sector stakeholders identify new or common fact patterns indicative of sanctions evasion and address common counterparty due diligence issues. If your document-review component wasn’t already trained to recognize these fact patterns, this is the kind of thing that needs to go into the model, not just a rulebook update.
2. December 2024 – January 2025 – the shadow fleet buildout. EU package 15 introduced targeted measures against vessels used to circumvent sanctions, the “shadow fleet,” and for the first time imposed full sanctions on third-country actors including Chinese entities. Then, on January 10, 2025, OFAC issued sweeping new sanctions targeting Russia’s energy sector, including a new petroleum services ban, expanded secondary sanctions authority, and designations of Russian oil producers, insurance providers, and more than 180 shadow fleet vessels, done in parallel with the UK, which designated Gazprom Neft and Surgutneftegas the same day, followed by OFAC and OFSI publishing a memorandum of understanding to strengthen cooperation. A brand-new prohibition category (petroleum services) plus expanded secondary-sanctions exposure for foreign banks is a genuine typology addition, not a list update.
3. February 2025 – Iran’s posture flips. National Security Presidential Memorandum 2, issued when Trump took office, formally reinstated the “maximum pressure” strategy against Iran and significantly expanded its scope. In parallel, EU package 16 hit energy, trade, transport, infrastructure and financial services and added listings touching Russian crypto-asset exchanges and the maritime sector for the first time. This is where “Iran risk” stops meaning “drones and human rights” and starts meaning a full petroleum-sector campaign – a different thing for a model to detect.
4. March – May 2025 – the campaign gets teeth, and it’s China-shaped. OFAC’s Iran push became a near-monthly cadence targeting Chinese “teapot” refineries and Iranian shadow-banking exchange-house networks – since February 2025, OFAC sanctioned over 1,000 Iran-related persons, vessels, and aircraft as part of this campaign. Treasury also updated its 2019 maritime evasion guidance on April 16, 2025, as part of implementing NSPM-2. Separately, US and European law enforcement seized Garantex’s web domain and froze over $26 million in cryptocurrency on March 6, 2025. The teapot-refinery and exchange-house patterns are genuinely novel fact patterns for a model that was probably trained mostly on Russia-shaped typologies.
5. July 2025 – the oil price cap stops being a fixed number. EU package 18 introduced an automatic and dynamic mechanism to modify the oil price cap so it stays roughly 15% below the average market price for Russian crude, reviewed every six months, alongside the first-ever full transaction bans on Chinese crypto-asset service providers and on two Chinese financial institutions found to be frustrating EU sanctions. If your model treats “is this deal above the price cap” as a static threshold check, that logic now needs to track a moving, scheduled value – a structural change, not a data point. The UK matched the cap cut and published its first Cryptoassets Threat Assessment on July 21, 2025.
6. August – October 2025 – the densest stretch of the whole window. Four things landed close together: OFAC sanctioned a network tied to the shuttered exchange Garantex and its successor Grinex, along with the ruble-backed stablecoin A7A5, which had been moving roughly a billion dollars a day – a genuinely new evasion typology (sanctioned-bank-backed stablecoin as a settlement rail). Then the E3 invoked the UN “snapback” mechanism on August 28, 2025, resulting in full reimposition of UN sanctions on Iran effective September 27, 2025, and the EU and UK reintroduced autonomous sanctions measures against Iran that had been eased in 2015 – not new listings, but a wholesale rebuild of the Iran sanctions architecture back toward its pre-2015 scope. Days later, EU package 19 introduced specific binding legal definitions of “ownership” and “control” for designated entities – directly relevant to any third-party-ownership-chain logic your model runs. And on October 22, 2025, OFAC designated Rosneft and Lukoil, Russia’s two largest oil companies, under Executive Order 14024 – the first designation by the Trump administration of Russian actors under the war-related sanctions authorities, a sharp reversal after a year in which Russia designations had dropped to 74 total, down from over 3,000 in 2024. Any one of these would justify a retrain; together, this is the strongest single cluster in the 24 months.
7. April 2026 – crypto logic changes shape, not just scope. EU package 20 added a ban on EU operator engagement with the Russian national payment card system Mir or the faster payments system SBP – a payment-rail typology your model may not have needed before – and, more structurally, shifted crypto enforcement away from naming specific platforms or tokens toward a blanket prohibition on transactions with crypto-asset service providers in designated categories. That’s a different kind of rule to encode: a categorical, jurisdiction-based test rather than a name-match.
One thing just outside your window worth flagging for context: EU package 21 landed July 23, 2026 amending Regulation 833 and Regulation 269, entering into force the following day – three weeks after your June 30 cutoff, so I’ve left it out of the count, but it’s the next wave you’d hit almost immediately.
On your specific exposure
Maritime: the heaviest thread by far – the October 2024 guidance, the shadow fleet buildout across essentially every EU package, and the UK’s escalation to active tanker interdiction in 2026 all sit here.
Crypto: three distinct shape-changes, not just more designations – individual exchange listings (early 2025), first-ever crypto-service-provider transaction bans (mid-2025), then a categorical/jurisdictional ban (2026). Plus the stablecoin typology from Garantex/A7A5, which doesn’t resemble earlier crypto sanctions patterns at all.
Securities: thinner, but real – EU’s central-securities-depository protections (package 15), the Russian Direct Investment Fund transaction ban (package 18), and a non-binding CJEU Advocate General opinion from September 25, 2025 advising that “freezing of funds” should be read broadly enough to cover voting rights and participation rights of depository-receipt holders – worth watching since it isn’t yet a final ruling.
Checking this against my sources
What’s solid: every date, designation, and mechanism description above comes directly from primary sources (Consilium, OFAC/Treasury releases, OFSI notices) or law-firm client alerts summarizing them, and I’ve kept the sourcing tight to those.
What’s my judgment layered on top, not something any source states: which of these events “would” trigger a retrain, and the total count of 6-7. No regulator or vendor publishes a “here’s when compliance AI needs retraining” schedule – that’s an inference I’m drawing from the nature of each change (new prohibition category vs. more names on an existing list), and a different model architecture or risk appetite would land on a different number. Treat the count as a reasoned estimate, not a fact.
Two things I want to flag rather than let sit unqualified: the CJEU item is an Advocate General opinion, not a binding judgment – I’ve labeled it that way above. And the “over 1,000 Iran designations” figure is cumulative as reported in an April 2026 source, so it’s close to but not exactly aligned with your June 30, 2026 cutoff – the true count at your exact end date is very likely a bit lower.
One gap: I did not attempt to catalogue every individual OFAC Iran designation round (there were dozens) or every weekly OFSI list update – that would run to hundreds of entries and wouldn’t change the retrain analysis, since after the first round establishes a typology (teapot refinery, shadow banking exchange house), subsequent similar rounds are list updates, not new patterns.
Half of the fun (and at least half of the challenge) is finding interesting things to investigate and develop. Today’s EU sanctions post came out of a desire for a single thread to follow, with some useful graphics – especially considering the challenges of herding 27 EU cats. Similar desires to put things into a manageable size box brought the Practitioners Guides and Plain Language Guides – and yesterday’s analysis of the risk implications of DHS’ UFLPA Entity List.
But, as my wife enjoys reminding me – other people have good ideas, too. And, I assume, good questions as well.
So, do you have a Burning Question for me (and Claude) to look into for you? It can be a summarization type task, a trend analysis task or… hey, I’m not going to limit what you ask about sanctions or export control.
So, feel free to put your question to me in the comments, or use the Contact page.
Thanks – looking forward to your ideas for new topics.
Count the EU’s Russia packages by designations added and you learn almost
nothing. Package 21 alone carried 218 listings, the largest single batch in four
years, and not one of them changed how a screening program works. What changes
your program is a new kind of restriction: a category of counterparty you now
have to test for, a contract term you now have to insert, a service you can no
longer provide.
By that measure the twenty-one packages contain roughly two dozen genuinely
distinct restriction types, and they did not arrive evenly.
One note on where this starts. The EU has had Russia sanctions since 2014,
and the post-Crimea framework already limited Russian bank and corporate access
to European capital markets. Package 1 extended that framework rather than
inventing it, and the same is arguably true of parts of the early export
controls. The 2022 measures are different enough in scale and in kind to be
worth treating on their own terms, which is what this article does, but the
baseline was not zero.
Note: this is a long article. A PDF version is available for download at the end, and it adds an appendix listing the amending regulation behind each of the twenty-one packages.
Package 1 restricted Russian access to EU capital and financial markets
(Regulation 2022/262). Package 2 opened the export control front, covering goods
and technology for defence, aviation and space, and oil refining (Regulation
2022/328).
Package 3 is the consequential one. It banned transactions with the Central
Bank of Russia, cut seven banks off the SWIFT financial messaging network, and
closed EU airspace to Russian aircraft (Regulation 2022/334, extended by
2022/345, 2022/350 and 2022/394).
Package 4 added three measures (Regulation 2022/428). The first banned new
investment in Russia’s energy sector. The second barred imports of Russian iron
and steel. The last prohibited exports of luxury goods.
Timing matters here in a way it rarely does later. The Central Bank measure
landed on 28 February, four days into the invasion, alongside parallel US and UK
action. That simultaneity was the point. A reserve freeze telegraphed in advance
is a reserve freeze that gets moved.
Why it mattered
The immediate effect was severe and short-lived. The ruble fell from roughly
80 to 120 per dollar within two weeks. Russia’s central bank raised its key rate
from 9.5 percent to 20 percent on 28 February.
Within about two months the currency had recovered to pre-invasion levels.
Capital controls, a requirement that exporters convert 80 percent of their
foreign currency earnings, and a demand that energy buyers pay in rubles did
most of that work. Analysts have generally read this as the financial shock
being absorbed rather than proving decisive. Roughly €300 billion in Russian
central bank reserves sat frozen across the EU, other G7 states and Australia,
about two-thirds of it in the EU, but Russia’s current account surplus kept
climbing on continued energy sales.
The EU’s approach already differed from Washington’s in one visible way. It
deliberately left Sberbank and Gazprombank off the SWIFT cutoff, because those
were the payment channels for European gas. The United States had no equivalent
reason to carve anyone out.
Switzerland aligned almost immediately, a real departure from its historical
posture. It did so by mirroring EU measures through its own Ukraine Ordinance
rather than adopting them directly, and that mechanism would later produce
timing gaps that still cause trouble. Belarus was pulled in from package 3
onward, establishing the mirroring pattern that has held since.
Packages 5-9: building the sectoral toolkit
April to December 2022
This is where the sectoral measures were built.
Package 5 carried four distinct measures (Regulation 2022/576). It closed EU
ports to Russian vessels and barred Russian road hauliers from EU territory. Coal
imports were banned outright. And this package introduced the first restriction
on crypto assets, capping what Russian persons could hold.
Package 6 delivered the crude oil and refined products import ban, the
measure that took longest to negotiate (Regulation 2022/879). The ban reached oil
arriving by sea but excluded oil delivered to the EU through pipelines, an
exemption Hungary, Slovakia and Czechia still operate under. The same package
brought the first professional services ban, covering accounting, audit,
bookkeeping and consulting.
Package 7 banned gold imports and extended the port access ban to locks
(Regulation 2022/1269).
Package 8, in October 2022, did two things that would define the following
four years (Regulation 2022/1904). It created a listing criterion aimed
specifically at people facilitating circumvention, which meant the EU could now
designate someone for helping others evade sanctions rather than for any
underlying conduct. The same package established the oil price cap. Less
prominently, it also widened the services bans to architectural, engineering, IT
consultancy and legal advisory work (Article 5n).
Package 9 closed the year with a ban on new investment in Russian mining and
a prohibition on advertising and market research services (Regulation
2022/2474).
Why it mattered
The revenue effect was real and measurable. The Council reported Russian
revenues down 26.9 percent in January 2023 against January 2022, and down 41.7
percent in February. The Council’s explanation of these figures is somewhat
vague, but they most likely refer to oil and gas revenues. The February number
is the one most plausibly connected to package 6, since the refined products ban
and the price cap only took effect on 5 February 2023.
The price cap is the more interesting story, because it is the clearest case
of a sanctions measure generating its own countermeasure. The cap was designed
to keep Russian oil flowing to global markets while limiting what Russia earned
from it, and it worked through leverage over Western shipping and insurance.
Russia’s answer was to assemble a fleet of older tankers under opaque ownership
and arrange insurance outside the coalition, so the shipping and insurance
leverage the cap depended on no longer reached the trade. The shadow fleet went
from essentially nothing to carrying most Russian crude within about two
years. Elisabeth Braw has argued publicly that Western governments would not
have imposed the cap had they anticipated that outcome, which is a strong claim
but not an unreasonable one.
The cap is also the most genuinely coalition-built instrument of the entire
effort, agreed across the G7, the EU and Australia. That agreement did not
extend to enforcement. The United States leaned on the threat of secondary
sanctions against foreign financial institutions that handled capped oil. The EU
leaned instead on its jurisdiction over the shipping and insurance companies
themselves. Same cap, different levers, and third-country intermediaries learned
quickly which one bit harder.
Packages 10-13: the circumvention turn
February 2023 to February 2024
Four packages over a full year, and almost everything in them is aimed at closing the routes goods were taking around the restrictions already in place, rather than at adding new targets. These packages also refined measures already on the books in three places.
Package 10 banned transit of dual-use goods and arms through Russian territory (Regulation 2023/427). Package 11 extended that transit ban and formalised cooperation with third countries (Regulation 2023/1214).
Package 12 introduced three measures worth singling out (Regulation 2023/2878). The first is the “no-Russia clause”, which requires EU exporters to write a contractual prohibition on re-export to Russia into their sales agreements (Article 12g). The second is a ban on providing enterprise management and industrial design software. The third is a reporting requirement for outbound transfers above €100,000 by EU companies owned or controlled by Russian persons. Package 12 also banned imports of Russian diamonds, along with LPG and several metals, which is a story in itself and taken up below.
Package 13, at the two-year mark, was mostly additional sanctions designations (Regulation 2024/745). It added 194 individuals and entities and took the total past 2,000. But two things in it pointed forward.
The first was a widening of export controls. Aluminium electrolytic capacitors went onto the list of goods that could strengthen Russia’s military and technological base (Annex VII Part B). Electrical transformers, static converters and inductors went onto the separate list of goods that could build up Russian industry generally (Annex XXIII, Article 3k). That second list had previously covered three specific tariff codes. Package 13 replaced them with the entire tariff heading that sits above those codes, so every transformer, converter and inductor became controlled rather than three named types. For an exporter, that is the difference between checking a code list and re-screening a product line. Existing contracts had until 25 May 2024 to complete.
The second was the addition of 27 entities to the list carrying stricter dual-use and advanced technology export restrictions (Annex IV). Those designations reached into mainland China, India, Sri Lanka, Serbia, Kazakhstan, Thailand and Turkey.
The no-Russia clause, and why it has no US twin
The no-Russia clause deserves attention because it is an EU original. Washington’s route to the same problem runs through the BIS Entity List and the foreign direct product rules. The Entity List is the Bureau of Industry and Security’s roster of foreign parties that US exporters need a licence to ship to, with those licences generally presumed denied. The foreign direct product rules extend US licensing authority to goods manufactured outside the United States when they were made using US technology or equipment, which is how Washington reaches transactions with no American party in them at all.
Brussels went the other way. It pushed the obligation into private contracts, making the exporter responsible for a term in a sales agreement. Neither approach has obviously won. The EU version is cheaper to administer and harder to enforce. The US version is the reverse.
Diamonds, and the limits of provenance
The diamond ban deserves its own treatment, because it shows what happens when a restriction depends on where something came from rather than who paid for it.
Russia is the world’s largest diamond producer by volume, at roughly a third of global supply. Alrosa accounts for over 90 percent of Russian production, and the Russian state holds a majority stake in it, split between the federal government and the Republic of Sakha (Yakutia), the region of eastern Siberia where the mines sit, together with that republic’s districts. Diamond revenue therefore reaches the Russian state rather than private shareholders. In absolute terms the target is small. Alrosa’s 2023 results put the business at around $3.5 billion, a rounding error against hydrocarbons.
The cost to Antwerp was more visible. Belgium imported roughly €1.8 billion of Russian rough diamonds in 2021, about a quarter of its total rough imports. That fell to around €1.4 billion in 2022 and to €288 million in the first half of 2023, most of the decline arriving before the ban did. The Antwerp World Diamond Centre argued throughout that an EU-only ban would be dramatic for Antwerp and produce no impact on Russia, because trade would simply reroute through Dubai and Mumbai.
Belgium’s position is the interesting part. Rather than resisting, it ended up leading the coordination, on the reasoning that serving as the world’s Russian-diamond laundromat was doing more damage to Antwerp’s standing than a ban would do to its trade.
India is where enforcement actually lives. Over 90 percent of the world’s diamonds are cut and polished there, and Alrosa supplied around 40 percent of India’s rough imports. A ban on Russian-origin stones only means something if Indian polishers segregate Russian goods from everything else, which is why G7 delegations went to India in September 2023 to make the case. The EU’s answer was to require that rough diamonds of half a carat or more be certified through Antwerp from September 2024, with the record kept on a blockchain ledger. Smaller stones fell outside the requirement.
Then the coalition came apart. The United States disengaged from the G7 traceability working groups after pushback from African producers, Indian polishers and New York jewellers. A Biden administration official’s position was that the September 2024 commitment bound the EU rather than the United States. The polished-diamond traceability deadline slipped from 1 March 2025 by ten months, and Botswana was added as a second verification hub alongside Antwerp.
That is a sharper illustration of the pattern than anything in the financial measures. Everyone agreed on the target. Only the EU built the verification regime.
Russian countermeasures become a compliance problem
This is also when Russian countermeasures stopped being defensive and became something screening and legal teams had to account for.
Presidential Decree 302 of April 2023 created a mechanism for placing assets of companies from “unfriendly states” under external management. It was used. Carlsberg and Danone are the well-known examples.
In parallel, Russian claimants began using Article 248 of the Arbitrazh Procedure Code to pull disputes into Russian courts in breach of arbitration agreements. The results included the seizure of roughly $155.8 million of JPMorgan funds on VTB’s application, and a freeze of around $1.15 billion of assets held by a UK subsidiary of Linde.
For EU companies still holding Russian assets, this is when exit became materially more expensive than staying.
Switzerland was still keeping close pace, completing its package 10 alignment on 29 March 2023, about a month behind.
Packages 14-17: shadow fleet and the third-country pivot
June 2024 to May 2025
Package 14 is the densest single package in the entire set of measures (Regulation 2024/1745). It banned LNG re-exports and new investment in Russian LNG projects. Use of the Central Bank’s SPFS financial messaging system, Russia’s domestic alternative to SWIFT, was outlawed. The same package created a port access and services ban aimed at vessels supporting the war, which is the first version of what became the shadow fleet regime. Least noticed at the time, it also built a litigation and expropriation shield, letting EU companies claim damages in member state courts from Russian parties that benefited from expropriation (Articles 11a and 11b).
Package 15 completed that last thought by making Russian court judgments obtained under Article 248 unrecognisable and unenforceable in the EU (Regulation 2024/3192).
Packages 16 and 17 were mostly additional sanctions designations, but with a telling shift. Of the 53 entities added to export restrictions in package 16, roughly two-thirds were located in third countries (Regulation 2025/395). Package 17 added chemical precursors and 189 more vessels, taking the listed total to 342 (Regulation 2025/932).
Why it mattered
This is where the EU stopped writing rules about Russia and started writing rules about everyone else who deals with Russia. The third-country listing shift matters operationally more than the vessel counts. A screening hit on a Kyrgyz, Emirati or Hong Kong trading company is now a routine outcome rather than an anomaly.
The shadow fleet data is the most useful evidence available on whether any of this works, and it points somewhere specific. Alignment beats aggression. Robin Brooks’ analysis of tanker departures found activity in vessels sanctioned jointly by the United States, EU and UK down about 90 percent year over year, against 86 percent for US-only designations. The gap is small, but the direction matches what practitioners see. A vessel designated in one jurisdiction shops for ports. A vessel designated in three runs out of them.
The litigation shield is worth flagging as a genuine novelty. Sanctions regimes normally regulate what their own persons may do. Articles 11a and 11b instead create a private right of recovery against Russian beneficiaries of expropriation, which is closer to a tort remedy than a restrictive measure. No other major regime has copied it.
Switzerland’s lag started lengthening here. Package 16 was adopted on 24 February 2025 and implemented on 14 May 2025.
Packages 18-21: the energy endgame and the crypto build-out
July 2025 to July 2026
Energy tightened on every remaining front.
Package 18 lowered the oil price cap and, more significantly, set it to adjust periodically under the terms of the relevant Council Decision rather than sitting at a fixed number (Regulation 2025/1494). It also banned imports of refined products made from Russian crude, regardless of where the refining took place.
Package 19 banned LNG imports outright (Regulation 2025/2033). It also prohibited transactions involving Mir and the Faster Payments System, known as SBP. Mir is Russia’s domestic card scheme, built after 2014 precisely so that being cut off from Visa and Mastercard would not stop domestic payments. SBP is the central bank’s instant payments system. Prohibiting them closes the retail payment channels that survived the SWIFT measures.
Package 20 banned the provision of services to Russian LNG terminals and imposed due diligence obligations on tanker sales (Regulation 2026/506). Package 21 extended the terminal services ban to third-country operators controlled by Russian companies (Regulation 2026/1848).
The second development is crypto becoming a separate target category in its own right, rather than an incidental restriction attached to other measures.
Package 5 capped the value of crypto assets Russian persons could hold. Package 8 banned providing crypto wallets to them outright. Package 20 went considerably further, prohibiting transactions with crypto-asset service providers and platforms established in Russia, and naming RUBx, a ruble-pegged stablecoin, as a specific target (Article 5bb). Package 21 added a prohibition on Russian citizens and residents owning, controlling or holding positions in EU crypto-asset service providers, effective 25 August 2026.
The price cap is the clearest case in the whole set of a restriction that kept being re-tuned after it was imposed. Package 18 set it to adjust on a periodic basis. Package 21 then suspended that adjustment for a full year, to July 2027, loosening a measure the EU had built specifically so that it would keep tightening without further decisions.
That is the kind of regulatory detail that disappears when a package is summarised by its number of sanctioned designations.
October 2025: same targets, three different rules
Three jurisdictions moved on Russia’s two largest oil companies inside nine days, using three different legal instruments.
Date
Jurisdiction
Action
Mechanism
15 Oct 2025
UK
Rosneft and Lukoil designated, with 88 other targets
Asset freeze. OFSI licensed certain German Rosneft subsidiaries through at least October 2027, in coordination with German authorities, so those refineries could keep operating.
22 Oct 2025
US
Rosneft, Lukoil and more than 30 subsidiaries designated
SDN listing under EO 14024, pulling in the 50 percent rule and exposing foreign financial institutions to secondary sanctions risk.
23 Oct 2025
EU
Package 19 adopted
Full transaction ban on Rosneft and Gazprom Neft under Article 5aa, applying the EU’s own ownership and control test.
Same companies, same week, three different legal hooks. A screening team covering all three regimes got three different answers about the same corporate family in the same month.
Does any of it work
The evidence is genuinely contested, and the research organizations disagree with each other.
The evidence that oil is still moving despite the designations is substantial. As of mid-June 2026, the United States, UK, EU, Australia, Canada and New Zealand had collectively designated 653 unique tankers. Analysis from earlier in the year found 111 of the 623 then-designated vessels still loading Russian cargo, and G7-plus sanctioned tankers carrying roughly 68 percent of Russian crude exports. KSE put Russian oil export revenues at $20.8 billion in April 2026, down slightly month over month but $8.2 billion above the prior year.
The evidence pointing the other way is thinner but real. Russian reliance on Western maritime services climbed back to around 42 percent by May 2026, and new shadow fleet entrants slowed to a trickle across 2026. Both suggest vessel designations have made the shadow route expensive enough to push cargo back under the price cap’s reach.
Both can be true. Designating vessels one at a time degrades the alternative faster than it stops the trade. CREA has argued the entity-based approach is too easily defeated by intermediaries and special purpose vehicles, and has pushed for a full maritime services ban instead. Package 20’s groundwork for exactly that suggests the argument landed.
Two other developments
In December 2025 the EU moved to freeze Russian central bank assets in Europe indefinitely rather than on a renewable basis. That is a change in the character of the measure, not just its duration, and it has drawn commentary about longer-term effects on how other states think about holding reserves in European institutions.
Switzerland’s lag became a live compliance problem. Package 19 was adopted on 23 October 2025. Swiss implementation was partly done on 12 December 2025 and only completed on 25 February 2026. Baker McKenzie noted plainly that the delay created legal uncertainty for firms operating across both jurisdictions, and that the pattern is likely to repeat.
All twenty-one, grouped
Twenty-one packages, and the pattern is hard to miss once it is laid out. Everything the EU uses today was invented in the first ten months. The four years since have been spent extending those measures to new counterparties, new routes and new intermediaries.
There is a useful corollary for anyone tracking alignment with other regimes. Gaps between the EU, United States and UK appear when someone invents a mechanism, not when someone extends one. The moment a new tool is created is the moment the other jurisdictions either copy it or decline to, and the diamond traceability regime is the clearest example. Packages that extend existing measures rarely change the alignment picture, because whatever alignment there was got settled when the measure was first built.
The practical implication is that a new package is not by itself news. The question is what kind of change it contains. If all that changed is more names on the list, your existing screening already absorbs it. If there is a new kind of restriction, meaning a contract term you have to insert, a class of counterparty you now have to test for, or a service you can no longer provide, that is the one where somebody has to read the annex.
Sourcing and self-check
Documented, traceable to primary or official sources. Every package’s contents, adoption date and amending regulation number come from the Council of the EU’s package timeline, the Official Journal, and the Council’s own press releases. The Council’s timeline page was last reviewed on 23 April 2026 and therefore stops at package 20. Package 21 content comes from the Council’s 23 July 2026 press release and from law firm and P&I club analyses published since. Central bank reserve figures and the January and February 2023 revenue decline percentages are the Council’s own published numbers. The 28 February 2022 rate move from 9.5 to 20 percent and the ruble’s move from roughly 80 to 120 per dollar are contemporaneous reporting. Swiss implementation dates are from SECO decrees as reported by Lenz & Staehelin and Baker McKenzie. The October 2025 Rosneft and Lukoil actions and their differing legal bases are from Covington, Sullivan & Cromwell, Arnold & Porter and McDermott alerts. Diamond trade figures are from IPIS and Reuters reporting.
Secondary analysis, flagged as such. The shadow fleet effectiveness figures of 90 percent against 86 percent are Robin Brooks’ calculation from his own vessel database. Vessel counts, revenue figures and the share of exports carried by sanctioned tankers come from KSE Institute, CREA and GSSC, which use different methodologies over different reporting periods and do not fully agree with each other. The claim that the price cap caused the shadow fleet is widely held but not formally established, and the Braw remark is an argument rather than a finding. CREA’s call for a full maritime services ban is advocacy, though package 20’s language suggests the EU is moving that way.
Editorial judgment, not anyone’s official framing. The six-category taxonomy and the decision about what counts as a distinct restriction type rather than an extension of an existing one are mine. Reasonable practitioners would draw some of these lines differently.
Known gaps. Belarus is treated here as a mirroring jurisdiction rather than as an actor in its own right, and the Belarus packages are not traced individually. The parallel EU regimes covering hybrid threats, human rights and riot control agents are outside scope except where they intersect, and the boundary between “the Russia package” and “the other measures adopted the same day” has been getting blurrier since package 17.
and now, a PDF which might be easier for you to digest:
The UFLPA Reaches Further Than the Importer of Record
Most compliance conversations about the Uyghur Forced Labor Prevention Act stop at the importer. Goods get detained, someone scrambles for supply chain documentation, the shipment clears or it doesn’t. That framing understates how much risk the statute actually spreads around. An importer facing a UFLPA detention is exposed to more than a held container, and the customs brokers, freight forwarders, and financial institutions touching the same shipment carry a version of that exposure too, even though none of them filed the entry.
This article works through the whole chain: what the UFLPA actually requires, what happens when an importer can’t clear the rebuttable presumption, and what changes, or doesn’t, for everyone else standing between the factory floor and the port.
What the UFLPA Actually Requires
Start with a distinction worth keeping precise: the UFLPA is not a sanctions program in the OFAC sense. There’s no blocking of assets and no general prohibition on transacting with a listed entity. It’s a forced labor import prohibition that Customs and Border Protection enforces at the border under existing customs law.
The underlying prohibition predates the UFLPA by nearly a century. Section 307 of the Tariff Act of 1930, codified at 19 U.S.C. § 1307, has long barred the importation of goods made wholly or in part by forced labor. The UFLPA, enacted December 23, 2021, with its enforcement mechanism taking effect June 21, 2022, doesn’t rewrite that prohibition. It adds a rebuttable presumption: CBP must presume that goods sourced from Xinjiang, or produced by an entity on the UFLPA Entity List, were made with forced labor and are therefore barred from entry under Section 307. The presumption is what makes the statute operationally different from ordinary forced labor enforcement. Before the UFLPA, CBP generally had to build a case for exclusion. Now, for goods tied to a listed entity or to Xinjiang itself, the burden shifts to the importer from the moment the shipment is flagged.
Who Decides What’s on the List, and How Big It’s Gotten
The Entity List is maintained by the Forced Labor Enforcement Task Force, chaired by the Department of Homeland Security, with the Office of the U.S. Trade Representative and the Departments of Labor, State, Treasury, Justice, and Commerce also represented. It’s actually a consolidated register of four separate statutory lists, corresponding to categories set out in Section 2(d)(2)(B) of the Act: entities in Xinjiang that mine, produce, or manufacture goods wholly or partly with forced labor; entities working with the Xinjiang government to recruit, transport, transfer, harbor, or receive members of persecuted groups out of the region; and the manufacturers and exporters downstream of those entities that incorporate their inputs.
The list has grown quickly, and unevenly. As of August 3, 2026, it stands at 187 entities, following the addition of 43 companies on July 31, the largest single expansion since the law’s enactment and roughly a 30 percent increase in one notice. It was also the first expansion under the current administration and the first since January 2025. The new listings span aluminum, apparel, copper, cotton, and tomato producers, sectors CBP has flagged as high priority for forced labor exposure independent of this particular update.
How CBP Actually Enforces the Presumption
Enforcement happens at the port of entry, and CBP does it alone. FLETF’s role is upstream, deciding who goes on the list; it doesn’t adjudicate individual shipments. When a flagged shipment arrives, CBP detains it and issues a Notice of Detention. To get the goods released, the importer has to fully comply with CBP’s guidance and any FLETF inquiries, respond completely to every information request, and demonstrate by clear and convincing evidence that the supply chain is free of forced labor. In practice, that means tier-by-tier production records, transportation logs, employment records, and independent third-party audits, traced back to raw material origin. There’s no de minimis exemption. Any amount of input traceable to a listed entity, however small a share of the finished good, can hold up an entire shipment.
What Happens When an Importer Can’t Clear It
If the presumption isn’t rebutted within the response window, the consequences run on two separate tracks: what happens to the goods, and what happens to the importer.
On the goods themselves, failure to rebut moves the shipment from detention to exclusion, meaning the goods are formally denied entry and the importer has to re-export or destroy them. If CBP remains unsatisfied that forced labor wasn’t involved, the goods can go further still, to seizure and forfeiture under CBP’s authority for customs violations, at which point they become the government’s property rather than simply being turned away.
The importer’s own legal exposure is a separate matter, and it doesn’t require a UFLPA-specific penalty provision to bite. Bringing in prohibited merchandise, or making inaccurate statements about origin or sourcing along the way, can trigger the ordinary Title 19 penalty framework under 19 U.S.C. § 1592 for a material false statement or omission to CBP. That’s not new law created by the UFLPA; it’s the same statute that has always covered customs fraud and negligence, and a UFLPA presumption failure often surfaces alongside exactly that kind of documentation problem. The penalty scales with culpability:
Culpability
Penalty
Fraud
Up to the domestic value of the merchandise
Gross negligence
Up to 4x the government’s loss, or 40% of dutiable value
Negligence
Up to 2x the government’s loss, or 20% of dutiable value
Separately from any 1592 penalty, CBP can assess liquidated damages against the importer’s customs bond for breaching its conditions, an independent mechanism running in parallel. Beyond the individual case, CBP can revoke import privileges and put an importer’s future entries under heavier audit and investigation, so a single UFLPA episode tends to outlast the shipment that triggered it.
And the newest edge is criminal. DHS has said explicitly that importers who knowingly circumvent UFLPA restrictions can face criminal prosecution, backed by an active enforcement body: the DOJ and DHS Trade Fraud Task Force has surpassed a billion dollars in recoveries and charged losses in under a year. That’s a meaningful shift from “your shipment gets held” to “willful evasion gets referred for prosecution.”
What Changes for Everyone Else in the Chain
Carriers. Nothing in CBP’s or FLETF’s public UFLPA materials creates liability for an ocean or air carrier based on the nature of someone else’s cargo. The statutory mechanism, detention, exclusion, seizure, forfeiture, runs against the goods and the party making entry, not the transporter. A carrier’s exposure comes from the ordinary rules governing its own conduct: manifesting accuracy, documentary fraud, and complicity in evasion schemes such as falsified bills of lading or transshipment, not from UFLPA itself.
Customs brokers and freight forwarders. This is where the ground has actually shifted. On June 3, 2026, the White House issued Executive Order 14411, “Strengthening Customs Enforcement,” directing DHS and CBP to revise the rules governing importers of record, customs brokers, freight forwarders, and bonded merchandise custodians alike, not just the entity filing the entry. The order sets enforcement priorities that put forced labor alongside misclassification, undervaluation, and illegal transshipment, including investigations under the Enforce and Protect Act. It also tightens the penalty environment generally: a penalty floor of at least 50 percent of the assessed amount, elimination of mitigation for repeat offenders, and a new minimum liquidated-damages floor. None of that creates a UFLPA-specific broker penalty. What it does is layer a considerably less forgiving enforcement posture on top of the broker penalty framework that already existed under 19 U.S.C. § 1641 for a broker’s own false certifications or failure of due diligence. A broker or forwarder that can document what its importer told it, and when, is in a meaningfully better position than one that can’t.
Banks and trade finance. Here the distinction is sharper. The UFLPA isn’t administered by Treasury and doesn’t carry OFAC’s blocking-sanctions mechanism, so there’s no statutory hook making a bank’s issuance or confirmation of a letter of credit itself a UFLPA violation when the underlying shipment later gets detained. A joint advisory from State, Treasury, Commerce, DHS, USTR, and Labor addressing Xinjiang-linked business exposure exists, but it says plainly that it’s explanatory only and doesn’t carry the force of law. A bank’s real exposure runs through ordinary channels instead: standard AML monitoring for trade-based money laundering red flags, and, more consequentially, the frequent overlap between UFLPA-listed entities and separate designations on OFAC’s SDN list or Commerce’s Entity List. When that overlap exists, it’s the other designation, not the UFLPA listing, that triggers an actual blocking or licensing obligation. Worth checking the cross-reference specifically rather than assuming a UFLPA hit alone carries OFAC-style duties.
Why the Timing Matters
The direction of travel through mid-2026 has been consistently toward more enforcement, applied more broadly, not less. Beyond the Entity List expansion and Executive Order 14411, USTR’s Section 301 forced labor tariffs took effect July 24, 2026, covering 60 economies found to have failed to prohibit or effectively prevent trade in forced-labor goods. CBP issued a new, consolidated Forced Labor Enforcement Operational Guidance for Importers in June 2026, replacing the 2022 version. And CBP’s own detention dashboard had actually shown declining activity since January 2025 right up until this recent burst, which several firms tracking the space are reading as the calm before a renewed push rather than a genuine pullback.
One caution worth passing along for anyone researching this independently: some trade press and vendor content in circulation this year has conflated an unrelated Supreme Court decision on freight broker liability for highway safety, a negligent-hiring case with no connection to forced labor or import compliance, with UFLPA-related obligations, apparently to lend urgency to compliance-software pitches. It’s worth tracing any startling claim about new UFLPA broker or carrier liability back to a primary source, whether the executive order text, a FLETF or CBP notice, or an actual court opinion, before treating it as authoritative.
None of this changes what any one party in the chain should actually do differently: build the documentation while the people who’d know still remember where the inputs came from, not after CBP asks for it. But it’s worth understanding that a UFLPA problem rarely stays contained to the importer’s desk for long.
Actually, I do have a question: If I provided an update, could you pull all the info you could, plus identify for each listing, where else I should look, based on the nature of the listing?
and the response (ignore the fact that Claude and I already have a relationship):
Yes – and it would layer naturally on top of your existing reformatting workflow rather than replace it.
For each listing you pass along, I’d do two separate things. First, pull whatever’s publicly findable on it – press releases, prior designation history, news coverage, anything that adds context beyond the bare SDN entry. Second, and this is the part you’re actually asking about, tell you specifically where to go dig further, chosen by what kind of listing it is rather than handing you the same generic list every time.
That second part is where the nature of the listing matters. A few examples pulled straight from the pattern in your own recent updates:
A vessel or shipping entity tied to an Iran designation (HormuzSafe, the shadow fleet tankers) – I’d point you to Equasis for registered owner, manager, and flag history, plus Windward or Lloyd’s List Intelligence and UANI or C4ADS for the network picture.
A crypto exchange entity like the Shelbit network – blockchain analytics platforms (Chainalysis, TRM Labs, Elliptic) and on-chain explorers matter more here than corporate registries, since the trail runs through wallets as much as paperwork.
A Cuba military-industrial entity tied to GAESA or MINFAR (Tecnoimport, UIM) – ASCE and Cuba Study Group research tend to go deeper than general corporate databases, since a lot of that structure never shows up in any commercial registry.
A Russia entity – OpenSanctions or OCCRP Aleph first, since they’ve already scraped a good deal of EGRUL, then the Ukrainian NSDC list and the KSE tracker for anything more recent than what’s been indexed.
A plain corporate or individual addition with no obvious sector hook – OpenCorporates and the registry of wherever it’s domiciled, plus a check of whether OFAC’s own AKA or Linked To fields already answer the question.
One caveat, consistent with what I said earlier: the first half I can actually run myself. The second half means I’m handing you the right door, not opening it – I still can’t get past the paywalls on Orbis, Sayari, or Kontur/SPARK, so for anything that needs those, that’s where you’d take it from there.
let’s assume I see a new set of designations from a regulator who has some sort of ownership and control sanctions requirement. How would I research to find the additional entities implicated by this? What sources would I be looking at – both global coverage and ones with more targeted geographic coverage (e.g. Iran or Crimea)? And how much of this can you do, and what are you not able to , and why?
and the response:
Good question, and the timing is useful because there’s a live example running right now: BIS just built a brand-new automatic O&C mechanism into the export control system. The Affiliates Rule automatically extends the Entity List and Military End-User List to entities owned 50 percent or more by listed entities, modeled explicitly on OFAC’s rule. It was adopted as an interim final rule with immediate effect in September 2025, then stayed by BIS until November 9, 2026 – so it reactivates in three months. That’s a genuinely useful anchor for this answer since it’s exactly the “new O&C requirement, now go find the implicated universe” scenario you’re describing.
First, the framing question that determines your whole approach: is this regime self-executing or discretionary?
Self-executing/arithmetic regimes (OFAC’s 50% Rule, OFSI’s 2022 update, and BIS’s Affiliates Rule once it’s live) don’t require the regulator to take further action – an entity is captured the moment aggregate ownership crosses the threshold, regardless of whether it’s ever named. Your research task here is essentially corporate math: build the ownership tree and sum the stakes held by listed/blocked parties.
Discretionary/control-test regimes (the EU’s “owned or controlled by” doctrine, and UK guidance beyond the pure ownership percentage) require an affirmative designation or a documented control assessment – board composition, contractual control, negative control rights, etc. Here you’re not doing arithmetic, you’re building an evidentiary case, and “implicated” doesn’t mean “automatically caught,” it means “worth flagging as a candidate.”
Worth noting on the BIS rule specifically, since it’s new: if Company A, an Entity List party, owns 50 percent of Company B, which owns 50 percent of Company C, Company C is subject to the same restrictions as Company A – so it chains through multiple tiers, and the rule applies regardless of the foreign country in which the affiliate is located. It also creates an affirmative duty to determine ownership rather than letting silence default to clear.
Research workflow, roughly in order:
Start with the regulator’s own materials – the designation notice, Federal Register/OJEU entry, and any accompanying press release or FAQ. Regulators frequently name known subsidiaries in the announcement itself (Treasury in particular tends to do this for network-style designations, e.g. IRISL-related actions), which shortcuts a lot of downstream work.
Pull the existing entry’s own metadata – AKAs, “linked to,” prior addresses, registration numbers. This is the cheapest signal and gets skipped constantly.
Confirm the exact threshold mechanic for that regime (aggregate vs. per-owner, direct vs. indirect, does it chain through unlisted intermediate tiers).
Build the tree in both directions – not just subsidiaries down, but parents and sibling entities, since aggregation across multiple blocked co-owners can trip the threshold even when no single owner does.
Cross-check each node against the list itself – a subsidiary you find might already be separately listed under a different name.
Validate anything load-bearing against a primary-source document (registry filing, share register, annual report), not a secondary aggregator’s summary.
Flag and document anything where ownership can’t be resolved – under a rule like BIS’s this is now itself a compliance-relevant fact, not a dead end.
Sources – global coverage:
OpenCorporates – aggregates official company registries, decent free tier
Moody’s Orbis/Bureau van Dijk, Sayari Graph, LSEG World-Check, LexisNexis Risk Solutions (Dow Jones’s old risk data now sits inside RELX alongside your former employer Accuity) – all paid, all built for exactly this
OpenSanctions.org – free for non-commercial use, and genuinely useful here: it structures identifying information consistently so that relationships between entities, like company ownership or control, can be easily identified, integrating data from 444 global sources
OCCRP Aleph and ICIJ’s Offshore Leaks Database – investigative-journalism-sourced, unusually good at surfacing offshore shell layers that official registries don’t show
Open Ownership (the BODS standard) – complements OpenSanctions for beneficial-ownership-specific queries
Primary registries where they’re genuinely free: UK Companies House + PSC register, SEC EDGAR, EU member-state beneficial ownership registers (coverage is uneven post-rollback in some states)
Targeted – Iran:
Iran-linked evasion structures are disproportionately asset-based (vessels, shipping management companies) rather than pure holding-company trees, so vessel data matters as much as corporate data:
Lloyd’s List Intelligence / Windward – AIS tracking and beneficial-ownership-behind-flag analysis, paid
UANI and TankerTrackers.com – track Iran-linked shadow fleet vessels and front companies specifically
C4ADS – has published detailed network maps of IRISL/NITC successor structures
Treasury’s own past IRISL-related press releases and designation packages, since OFAC did a lot of this mapping itself over 15+ years
Targeted – Russia/Crimea:
EGRUL/EGRIP-based aggregators (Kontur.Focus, SPARK-Interfax, Rusprofile) – the authoritative underlying data, but increasingly hard to access from outside Russia and typically require Russian payment/phone verification
OpenSanctions and OCCRP Aleph both scrape a meaningful amount of EGRUL data already, so they’re often the more practically accessible route to the same underlying facts
KSE Institute’s Leave Russia tracker – useful for corporate exit/restructuring signals
YouControl – Ukrainian-sourced data with good Russia-adjacent coverage
Ukraine’s own NSDC/”War and Sanctions” designations – frequently anticipate or run parallel to Western lists and come with their own ownership rationale worth cross-referencing
RUSI and Transparency International UK – both have done sustained investigative work specifically mapping Russian elite ownership networks
What I can and can’t do here, honestly:
I can search the open web, read regulator press materials and FAQs, pull from freely accessible registries, and synthesize investigative/NGO reporting – and I can help you build and document the research workflow itself, with citations kept separate from inference.
What I can’t do, and the reasons matter for how you’d rely on this:
No login or API access to any paid platform – Sayari, Orbis, World-Check, LexisNexis Risk, Kontur/SPARK. I have no account, no credentials, and no way to acquire them mid-session even if you have a license, so anything behind those walls I simply cannot see.
No independent verification of an ownership percentage. If I surface a number from a news article or aggregator, that’s secondhand until checked against a primary document – I’ll flag it as such rather than presenting it as established.
No guaranteed completeness. Web search samples the indexed internet; it doesn’t exhaustively traverse a six-tier ownership graph the way a purpose-built product claims to, and coverage of non-English-language and offshore-secrecy-jurisdiction filings is systematically thin. Absence of a hit from me is not evidence the entity isn’t captured.
Can’t get past geo-blocking or verification walls (EGRUL-adjacent systems requiring Russian phone/payment being the clearest case).
Can’t make the actual compliance determination – whether to block, whether the evidence meets your institution’s risk threshold – that’s a licensed judgment call, not a factual output, and especially with a discretionary-control regime like the EU’s, it’s inherently a judgment exercise, not a lookup.
On genuinely obscure multi-hop chains, an LLM’s biggest risk is producing a plausible-sounding structure that isn’t actually sourced. I’ll cite as I go specifically so that risk stays visible to you rather than hidden in confident prose.
So, I’m a beta tester for ACSS‘ CSS-EU certification exam, and I’ve been studying. In the midst of it, I came across the following “non-paper” issued by the Dutch government in February 2023 about sanctions enforcement:
and I was curious – how much of this actually got promulgated by the EU? So, I asked Claude – here’s the response:
Quick note on dating: the paper’s reference to the 9 February 2023 European Council conclusions places it right around the EU’s 10th sanctions package. Everything below covers what’s happened across the roughly eleven packages adopted since (11th through 21st, the last landing July 23, 2026).
Context
The paper came from the Dutch government in the run-up to what it called “the year of success in countering circumvention.” It made five clusters of asks. Here’s each one, and where it actually stands 3.5 years on.
1. Strengthen the feedback loop between national enforcement and EU-level policy
Proposed: Better cooperation between customs, tax authorities, prosecutors, intelligence services, and statistics agencies at the national level, with that intelligence routed up to Brussels so loopholes in the sanctions text itself could get closed.
What happened: The concrete deliverable here is Directive (EU) 2024/1226, adopted April 24, 2024, which harmonizes the definition of criminal offenses and penalties for sanctions violations across Member States and builds a formal cooperation channel among national authorities, the Commission, Europol, Eurojust, and the European Public Prosecutor’s Office though it stops short of a single EU-level entry point for reporting breaches that span multiple Member States. Transposition was due by May 20, 2025. The Commission opened infringement proceedings against 18 Member States in July 2025 for failing to fully transpose it. As of early 2026, practitioner commentary is still describing EU sanctions enforcement as structurally fragmented, with divergent penalty regimes and investigative approaches across Member States encouraging forum shopping by operators seeking softer enforcement jurisdictions, and a mid-2026 industry survey went so far as to call fragmentation, not designation volume, the defining sanctions challenge of the year, with regulators now moving in different directions rather than the relative coordination seen earlier in the war.
Verdict: Real legislative architecture exists now that didn’t in February 2023. But this is the one proposal area where the paper’s own diagnosis (uneven application among Member States) is, by the EU’s own admission via infringement actions, still an open problem.
2. Strengthen the EU point of contact for circumvention
Proposed: A safe channel for Member States to share circumvention intelligence in Brussels, a platform for common analysis, and explicit use of the incoming Anti-Money Laundering Authority (AMLA, cited at 500 FTE) for this purpose.
What happened: The Sanctions Coordinators Forum, chaired by the EU Sanctions Envoy, has become the closest thing to the coordination venue described. By its seventh meeting in 2026 it was gathering high-level representatives from all Member States plus the US, UK, Canada, Japan, South Korea, Liechtenstein, New Zealand, Norway, and Switzerland, with Ukraine joining for dedicated sessions. That’s broader (and more diplomatic in character) than the narrower Brussels analysis cell the paper described.
AMLA itself did get built, though its link to circumvention specifically is thinner than the paper implied. It was formed June 26, 2024, headquartered in Frankfurt, and took up operations July 1, 2025. It absorbed the European Banking Authority’s AML/CFT mandates on January 1, 2026, and direct supervision of roughly 40 selected high-risk entities is scheduled to begin in 2028. Its core mandate is money laundering and terrorist financing; sanctions-compliance monitoring by obliged entities sits within that broader remit rather than as a dedicated anti-circumvention function, and its staffing trajectory (roughly 430 by end-2027) is smaller than the 500 FTE figure the paper cited.
Verdict: A coordination venue exists and meets regularly, and AMLA exists roughly on schedule. But I couldn’t find evidence of a discrete, named “circumvention information-sharing platform” as such. What exists instead is a layered patchwork: the Forum, the Europol/Eurojust/EPPO channel created by the 2024 Directive, and AMLA on the financial-intelligence side, which is a looser outcome than a single point of contact.
3. Diplomatic outreach
Proposed: A Special Envoy, EU démarches, letters from EU institutions, coordination with G7-plus partners.
What happened: This is the proposal that landed most cleanly, largely because it was already in motion. David O’Sullivan took up the role of International Special Envoy for the Implementation of EU Sanctions in January 2023, essentially contemporaneous with the paper itself. He’s since made the outreach role highly visible: in February 2026 he traveled to Kyrgyzstan and told reporters that trade data showed goods being imported there for the specific purpose of re-export to Russia, singling out radio equipment and machine tools; he’s made joint trips to Kazakhstan and Kyrgyzstan with his UK counterpart; and in June 2026 he told Euronews that China remained a “very big problem” for circumvention, with no sign of it abating.
Verdict: The most fully and durably realized of the five clusters.
4. Expand the EU toolbox
This proposal had several distinct sub-parts, worth taking one at a time.
Guidance for companies: The Commission published practical guidance for EU operators on September 7, 2023, setting out enhanced due-diligence expectations for strategic risk assessment and best practices for screening business partners, transactions, and goods, plus a list of circumvention red flags. It’s been refreshed since in coordination with G7 partners as part of joint industry guidance on preventing sanctions evasion. Realized, and fast.
Contractual end-use obligations: The “no-Russia clause” under Article 12g of Regulation 833/2014 was introduced in the 12th package in December 2023, requiring exporters to contractually prohibit re-export to Russia, and was later extended to Belarus. Realized.
Trade toolbox against a non-cooperative state: The anti-circumvention tool, Article 12f of Regulation 833/2014, was introduced as an “exceptional and last resort measure” in the 11th package in June 2023. It then sat unused for nearly three years. It was first activated in the 20th package, imposing targeted export restrictions on Kyrgyzstan in response to systemic evasion, specifically covering CNC machine tools and telecommunications equipment being diverted to Russia for drone and missile manufacturing. Realized, though the multi-year gap between creation and first use suggests Member States found it politically harder to invoke than the paper anticipated.
Watch list / published suspicions: The closest analog is the Common High Priority List, a jointly maintained EU-US-UK-Japan list of dual-use and advanced-technology items found on the battlefield or critical to Russian weapons production, first published in 2023 and expanded since. That’s a goods list, though, not the entity-level “watch list” or publication of unproven “suspicions” the paper floated as a way to enable due diligence short of formal listing. I didn’t find evidence the EU adopted that softer mechanism; where it had sufficient evidence, it moved straight to formal designation rather than a public warning step.
Verdict: Substantially realized across three of four sub-elements, with the “publish suspicions” idea appearing to be the one that wasn’t taken up.
5. Expand listing capacities
Proposed: Broaden the ability to list third-country persons and entities beyond the narrow original criteria, which required proving a link to circumvention by an EU actor, and cover a wider category of components tied to weapons production.
What happened: The 11th package amended Regulation 269/2014’s listing criteria to add persons and entities that “significantly frustrate” EU sanctions. Since then, successive packages have repeatedly added third-country entities under Annex IV of Regulation 833/2014, language in the Council’s own 2026 texts describes entities “in third countries other than Russia that indirectly contribute to Russia’s military and technological enhancement thereby enabling the circumvention of Union restrictive measures or frustrating their purpose”, which tracks the non-paper’s ask almost verbatim. The 19th package, in late 2025, specifically designated non-Russian operators in the UAE and China producing or supplying military and dual-use goods to Russia, and the EU’s asset-freeze list by that point already included entities established in the UK, China, Hong Kong, the UAE, and Kyrgyzstan.
Verdict: The second most fully realized cluster, with a clear and repeated pattern of use across nearly a dozen packages rather than a one-off change.
Bottom line
Ranked by how faithfully the EU followed through: diplomatic outreach and expanded listing capacity were both substantially delivered and are still actively used today. Toolbox expansion was mostly delivered, guidance, the no-Russia clause, and the anti-circumvention tool are all real and in force, with the softer “publish suspicions” idea being the exception. The feedback-loop proposal produced genuine legislation in Directive 2024/1226, but its central goal (unified application) remains, by the Commission’s own infringement actions, unfinished. And the “point of contact” proposal exists in a more diffuse form (Forum plus Europol/Eurojust/EPPO plus AMLA) than the single Brussels platform the paper described.
Worth flagging something the non-paper didn’t address at all: unanimity. Every package still needs all 27 Council votes, and that friction has visibly shaped recent outcomes, the 20th package had to clear a Hungarian veto threat before adoption, and the 21st package in July 2026 emerged narrower than the Commission’s original June proposal after Member States pushed back on scope. None of the five proposals touch that structural constraint, and it’s arguably the single biggest brake on how fast anti-circumvention policy can move regardless of how well the other five workstreams perform.
Self-check
High confidence, multiple independent sources: O’Sullivan’s appointment and role, the anti-circumvention tool’s creation and first (Kyrgyzstan) use, the no-Russia clause, Directive 2024/1226 and its transposition shortfall, the AMLA timeline, the September 2023 Commission guidance, and the pattern of third-country Annex IV listings.
Lower confidence: I could not confirm or rule out whether the EU seriously considered and rejected a formal “publish suspicions short of listing” mechanism, versus simply never taking it up, my read is an absence of evidence in press and legal-alert coverage, which isn’t the same as proof it doesn’t exist. Similarly, “no discrete circumvention information-sharing platform” is an inference from silence rather than a confirmed negative, worth a targeted follow-up search if it matters for the piece.
Sources
European Council conclusions, 9 Feb 2023 (context for the non-paper)
Council Regulation (EU) 2023/1214 and 2023/1215 (11th package), June 2023, Skadden summary
well, OFAC is also a strict liability regime – all who touch the transaction have violated the regulations, but the consequences, if any, vary according to the Enforcement Guidelines. So, OFAC just balances the scales differently, wouldn’t you say?
Claude responded:
Yes — and that’s a genuinely better way to put it than how it was left last message, so it’s worth correcting rather than defending the weaker version.
The mechanics check out
OFAC’s civil liability is strict: a violation exists the moment a blockable transaction occurs, full stop — OFAC need not prove fault or intent to bring an enforcement action and issue a civil penalty, and a civil penalty can be assessed even if the violator had no idea they were dealing with a sanctioned party. What actually happens next is calibrated entirely by the Enforcement Guidelines at 31 CFR Part 501, Appendix A — egregious versus non-egregious, voluntary self-disclosure, willfulness or recklessness, quality of the compliance program, awareness of the conduct, harm to program objectives. So the fault inquiry hasn’t been discarded, it’s just been relocated to the remedy stage instead of the liability stage. “Balances the scales differently” describes that far more precisely than the earlier “bets on speed vs. bets on accuracy” line, which overstated the contrast.
And here’s the part that actually strengthens the parallel rather than just conceding it: the UK made exactly this same move. For breaches committed on or after 15 June 2022, OFSI can impose civil monetary penalties on a strict liability basis, regardless of the absence of knowledge or a reasonable cause to suspect — before that date, OFSI had to show knowledge or reasonable cause to suspect on the balance of probabilities. So the “we wait for fault before we act” framing offered earlier doesn’t even hold up as a clean description of the UK’s own penalty regime anymore. Knowledge and intent still matter there, but now as a severity factor within OFSI’s case assessment, not as a threshold for liability — the same architecture as OFAC’s General Factors.
So where does the real difference actually live now?
Not in whether fault matters — both regimes have converged on “fault affects the size of the punishment, not whether a violation occurred.” It survives in what strict liability is allowed to reach. OFAC’s fault-blindness attaches to an immediate, automatic property action: the money gets locked up the moment the objective trigger exists, and that seizure doesn’t reverse just because a later fault inquiry clears the customer — unblocking still requires its own separate license. The UK’s 2022 reform, notably, didn’t build an equivalent mechanism. It made it easier to fine someone for the underlying conduct without proving they knew — but it stopped there. It didn’t create a parallel power to seize Customer A’s payment while that question gets sorted out, because there’s still nothing belonging to the designated person to seize in Scenario A, for the reasons worked through earlier.
That’s actually a more interesting finding than where things were left before: it isn’t that UK-style regimes are squeamish about strict liability in general — 2022 proves they aren’t. It’s that they’ve kept strict liability confined to punishing conduct after the fact, and never extended it into a mechanism for provisionally seizing an uninvolved party’s property before fault is even alleged. OFAC does both.