Regulation explainerAerospace & Defense

ITAR and EAR export controls for AI software: what each pipeline artifact means

US export controls were written for drawings, specifications and hardware, but a machine-learning pipeline creates new artifacts that carry the same know-how: labeled sensor data, trained weights, evaluation reports and prompts. This page maps each artifact to the ITAR and EAR concepts that decide its status, then turns them into engineering controls your empowered official and export counsel can review.

Reviewed 8 min read

On this page
  1. Why ML pipelines create new export-control questions
  2. Who makes the call on export status
  3. The instruments that govern a defense ML pipeline
  4. Five terms that decide the answer
  5. Artifact-by-artifact mapping for an ML pipeline
  6. Foreign-national engineers and technology control plans
  7. Cloud regions, encryption and hosted model APIs
  8. Advanced-computing and model-weight controls are a separate topic
  9. Engineering controls for an export-controlled ML pipeline
  10. A sensor-fusion model moves from R&D to a partner trial
  11. Questions and answers
  12. Sources

Why ML pipelines create new export-control questions

A traditional defense program controls technical data that people write on purpose: drawings, interface specifications, test procedures. An ML pipeline also produces controlled know-how as a side effect. A labeled dataset of radar returns can reveal a sensor's performance envelope, and a detector's weights can encode signatures gathered over years of trials.

These artifacts move faster than hardware. A dataset reaches a cloud bucket in seconds, a contractor abroad opens a notebook, a prompt with a design detail goes to a hosted model in an unknown region. Each move can be an export. So classify each kind of artifact, record its status where engineers see it, and enforce access and egress in the tooling.

Who makes the call on export status

The instruments that govern a defense ML pipeline

Most US defense AI work touches the first two; UK and allied teams add the third.

International Traffic in Arms Regulations (ITAR), 22 CFR Parts 120–130[^1]

United States: Department of State (DDTC)

Applies whenThe work involves a US Munitions List (USML) defense article, its technical data, or a defense service1.

  • Register with DDTC if you manufacture or export defense articles or furnish defense services1.
  • Obtain a license or agreement before exporting technical data or furnishing a defense service, including to foreign persons in the United States1.

Export Administration Regulations (EAR), 15 CFR Parts 730–774[^2]

United States: Department of Commerce, Bureau of Industry and Security (BIS)

Applies whenThe software or technology is on the Commerce Control List, including the 600 series military entries and the 9x515 spacecraft entries2.

  • Classify items by Export Control Classification Number (ECCN) and check license needs by destination, end user and end use2.
  • Treat release of controlled technology or source code to a foreign person in the United States as a deemed export5.

Export Control Order 2008 (SI 2008/3231)[^7] and the UK Strategic Export Control Lists[^8]

United Kingdom: Export Control Joint Unit

Applies whenA UK team transfers military or dual-use software or technology, including electronically7.

  • Check items against the UK Military and Dual-Use Lists and hold the right license for controlled transfers, including by email or cloud78.
  • US-origin ITAR or EAR content keeps its US controls on top of UK licensing.

Five terms that decide the answer

Technical data (ITAR)
Information required to design, develop, produce, operate, repair or modify a defense article, including software directly related to it9. The ML question is whether a dataset, model or report contains or reproduces such information.
Defense service (ITAR)
Assistance, including training, given to foreign persons in the design, integration, testing, operation or modification of defense articles10. Helping a partner tune a model can qualify with no file changing hands.
Technology (EAR)
Information necessary for the development, production or use of an item on the Commerce Control List2; for a controlled sensor, training know-how is often the controlled part.
Deemed export
Releasing controlled technical data or technology to a foreign person inside the United States65. Under the ITAR it counts as an export to every country where that person holds or has held citizenship, or currently holds permanent residency6.
Public domain and fundamental research
Published, generally accessible information is outside the ITAR, including fundamental research at accredited US universities whose results are ordinarily published11. Company R&D with proprietary or access restrictions rarely qualifies.

Artifact-by-artifact mapping for an ML pipeline

Brief counsel with the middle column; apply the right column as the default until they decide.

Pipeline artifactQuestion to put to counselDefault engineering control
Raw sensor dataDoes it reveal performance, signatures or characteristics of a USML or CCL item?Store in a controlled enclave with US-person access and jurisdiction tags on every file.
Labeled training setsDo the labels add controlled knowledge, such as target classes or threat parameters?Track lineage to source data; inherit the most restrictive tag of any input.
Trained weightsCan the model reproduce controlled data or reveal design detail when queried or inspected?Mark weights with the dataset's status; register them in a controlled model registry.
Evaluation and red-team reportsDo they state detection ranges, failure modes or countermeasure effects?Treat as technical data by default; release only after review.
Source codeIs the code specially designed for a defense article, or generic ML tooling?Separate generic libraries from program-specific code in different repositories.
Prompts and model outputsDo prompts carry design detail to a hosted model, and where does it run?Block egress to unapproved endpoints; log prompts in the enclave.
Support and integration workIs any foreign person being helped to integrate, test or operate the system?Route through an agreement review before any technical meeting.

These are conservative defaults, not determinations; relax them only on a written decision from your empowered official.

Foreign-national engineers and technology control plans

Mixed teams are normal in ML engineering, so deemed exports are the most frequent exposure. If a foreign-national engineer can open a controlled bucket, read a model card listing detection ranges or join a design review, the export happens when they look.

The usual tool is a technology control plan: which data is controlled, who may access it, how access is enforced and how staff are briefed. For ML work it should name controlled repositories, registries and compute clusters, and make US-person status an identity attribute so access is denied by default.

Where a foreign national needs access, the routes are an ITAR export license or technical assistance agreement, or an EAR deemed-export license. Each takes time, so staffing and export planning must start together.

Cloud regions, encryption and hosted model APIs

The ITAR and the EAR both say that sending or storing unclassified technical data or technology is not an export when it is secured with end-to-end encryption meeting stated conditions34. For AI workloads, the details decide everything.

  • If

    You store controlled datasets or weights in a commercial cloud region outside the United States.

    Then

    Rely on the carve-out only with end-to-end encryption using FIPS 140-2 validated modules or equivalent strength, keys held by authorized parties, and no storage in proscribed countries3.

    If the provider or anyone else can decrypt, the carve-out no longer applies.

  • If

    You want to train or run inference on controlled data in a cloud.

    Then

    Use a US-region or government cloud environment with US-person-only administrative access, confirmed in the contract.

    Compute needs plaintext, so encryption cannot cover processing; access controls have to.

  • If

    Engineers want to send prompts containing program detail to a commercial LLM API.

    Then

    Block it by default; allow only endpoints whose hosting region, operator access and retention your empowered official has reviewed.

    The provider decrypts the prompt to answer it, which makes the request a potential release.

Advanced-computing and model-weight controls are a separate topic

Engineering controls for an export-controlled ML pipeline

0 of 7 checked

A sensor-fusion model moves from R&D to a partner trial

Questions and answers

Are open-weight models covered by the ITAR?

A generic, published open-weight model is normally public-domain information. Once you fine-tune it on controlled data or specialize it for a defense article, the derived weights may embody technical data. Keep the base model and the derivative apart, with separate status, and ask counsel to rule on the derivative.

Can we publish research based on a defense AI project?

Only after export review. The ITAR's fundamental research route covers research at accredited US universities whose results are ordinarily published without proprietary or government restrictions11, which company contract work rarely meets. A pre-publication review that removes controlled data, performance figures and design detail is the safer default.

Can we use a commercial LLM API on an ITAR program?

Not by default. A prompt containing technical data can be a release, because the provider decrypts it to answer. Some providers offer US-region or government environments with US-person operations; your empowered official should review hosting, operator access and retention terms before controlled content goes near one.

Who signs off on the export status of a model?

Your empowered official, advised by export counsel, owns jurisdiction and classification decisions, and a commodity jurisdiction request to DDTC settles unclear cases. Engineering supplies accurate inputs, such as dataset lineage, what the model can reveal, where it runs and who can reach it, then enforces the decision in tooling.

Sources

  1. International Traffic in Arms Regulations, 22 CFR Parts 120–130 — Electronic Code of Federal Regulations · checked 10 October 2026
  2. Export Administration Regulations, 15 CFR Parts 730–774 — Electronic Code of Federal Regulations · checked 10 October 2026
  3. 22 CFR § 120.54 — Activities that are not exports, reexports, retransfers, or temporary imports — Legal Information Institute, Cornell Law School · checked 10 October 2026
  4. 15 CFR § 734.18 — Activities that are not exports, reexports, or transfers — Legal Information Institute, Cornell Law School · checked 10 October 2026
  5. 15 CFR § 734.13 — Export — Legal Information Institute, Cornell Law School · checked 10 October 2026
  6. 22 CFR § 120.50 — Export — Legal Information Institute, Cornell Law School · checked 10 October 2026
  7. The Export Control Order 2008 (SI 2008/3231) — legislation.gov.uk · checked 10 October 2026
  8. Consolidated list of strategic military and dual-use items that require export authorisation — Export Control Joint Unit, UK Government · checked 10 October 2026
  9. 22 CFR § 120.33 — Technical data — Legal Information Institute, Cornell Law School · checked 10 October 2026
  10. 22 CFR § 120.32 — Defense service — Legal Information Institute, Cornell Law School · checked 10 October 2026
  11. 22 CFR § 120.34 — Public domain — Legal Information Institute, Cornell Law School · checked 10 October 2026

More in Aerospace & Defense

Back to Aerospace & Defense

Next step

Send us your pipeline diagram before the jurisdiction review

Share a sketch of where your data, weights and compute sit and who can reach them. We will mark the points that need an export decision and the controls that would enforce it, ready for your empowered official and counsel.

Review my ML pipeline