Restrictions on what technology may move, to whom, and across which border. This is the domain where a research collaboration, a code repository or a support call can become a controlled export.
What we track
EU dual-use regulation
EU. Control lists, licensing, and the catch-all provisions that reach items on no list at all.
US export administration regulations
US. Entity list changes and the foreign direct product rule, including its tightening for advanced chips.
AI model weights
US. Licence conditions extended to cover model weights and not only hardware.
Wassenaar Arrangement
International. Plenary decisions, including controls on quantum and advanced semiconductor equipment.
Manufacturing equipment
EU and US. Controls extended to advanced CNC and additive manufacturing.
Sanctions interaction
All jurisdictions. Where export control and sanctions regimes overlap on the same counterparty.
Who is in scope
Anyone who develops, holds or transfers controlled technology, which now includes software, source code and technical data. Universities, research groups and engineering teams are in scope on the same terms as exporters of physical goods.
US rules reach further than US territory. The foreign direct product rule can capture items made outside the United States using US technology, which brings non-US manufacturers into a US licensing regime through their tooling.
Where the deadlines fall
Entity list additions and licence condition changes take effect on publication, sometimes with a short wind-down for shipments already in transit. There is no implementation period to plan against, which makes this the fastest-moving domain in the coverage set.
Wassenaar plenary decisions arrive annually and then flow into national control lists over the following months, which gives a short window to prepare.
Where organisations get caught
An export can be a file transfer. Once model weights, source code and technical data are controlled, moving them to a colleague abroad can require a licence. So can granting repository access to a contractor, and nobody in engineering knew that licence existed.
Deemed export. Giving a national of a controlled country access to controlled technology can count as an export to that country, even when nothing crosses a border. That makes this a human resources and identity question, and it reaches recruitment, onboarding and access provisioning.
Catch-all provisions. An item on no control list can still require a licence if you know or suspect an end use of concern. That converts export compliance from a list-checking exercise into a diligence obligation, and the standard is what you should have known.
Questions worth asking now
- Do we hold or develop anything on a control list, including software and technical data?
- Who has repository access, and do we know their nationality where the rules require it?
- Has any team shared model weights, designs or source code across a border this year?
- Which of our suppliers or customers appear on an entity list, and who checks?
- Does our engineering tooling bring us inside the foreign direct product rule?
- If a new control landed tomorrow, who in the business would find out first?
Related domains
AI security covers the model weights now caught by licence conditions. Quantum security and PQC covers the quantum equipment controls. Third-party and supply chain risk covers counterparty screening.