Regulation explainerAerospace & Defense
ITAR and EAR export controls for AI software: what each pipeline artifact means
US export controls were written for drawings, specifications and hardware, but a machine-learning pipeline creates new artifacts that carry the same know-how: labeled sensor data, trained weights, evaluation reports and prompts. This page maps each artifact to the ITAR and EAR concepts that decide its status, then turns them into engineering controls your empowered official and export counsel can review.
On this page
- Why ML pipelines create new export-control questions
- Who makes the call on export status
- The instruments that govern a defense ML pipeline
- Five terms that decide the answer
- Artifact-by-artifact mapping for an ML pipeline
- Foreign-national engineers and technology control plans
- Cloud regions, encryption and hosted model APIs
- Advanced-computing and model-weight controls are a separate topic
- Engineering controls for an export-controlled ML pipeline
- A sensor-fusion model moves from R&D to a partner trial
- Questions and answers
- Sources
Why ML pipelines create new export-control questions
A traditional defense program controls technical data that people write on purpose: drawings, interface specifications, test procedures. An ML pipeline also produces controlled know-how as a side effect. A labeled dataset of radar returns can reveal a sensor's performance envelope, and a detector's weights can encode signatures gathered over years of trials.
These artifacts move faster than hardware. A dataset reaches a cloud bucket in seconds, a contractor abroad opens a notebook, a prompt with a design detail goes to a hosted model in an unknown region. Each move can be an export. So classify each kind of artifact, record its status where engineers see it, and enforce access and egress in the tooling.
Who makes the call on export status
The instruments that govern a defense ML pipeline
Most US defense AI work touches the first two; UK and allied teams add the third.
International Traffic in Arms Regulations (ITAR), 22 CFR Parts 120–130[^1]
United States: Department of State (DDTC)Applies whenThe work involves a US Munitions List (USML) defense article, its technical data, or a defense service1.
Export Administration Regulations (EAR), 15 CFR Parts 730–774[^2]
United States: Department of Commerce, Bureau of Industry and Security (BIS)Applies whenThe software or technology is on the Commerce Control List, including the 600 series military entries and the 9x515 spacecraft entries2.
Export Control Order 2008 (SI 2008/3231)[^7] and the UK Strategic Export Control Lists[^8]
United Kingdom: Export Control Joint UnitApplies whenA UK team transfers military or dual-use software or technology, including electronically7.
Five terms that decide the answer
- Technical data (ITAR)
- Information required to design, develop, produce, operate, repair or modify a defense article, including software directly related to it9. The ML question is whether a dataset, model or report contains or reproduces such information.
- Defense service (ITAR)
- Assistance, including training, given to foreign persons in the design, integration, testing, operation or modification of defense articles10. Helping a partner tune a model can qualify with no file changing hands.
- Technology (EAR)
- Information necessary for the development, production or use of an item on the Commerce Control List2; for a controlled sensor, training know-how is often the controlled part.
- Deemed export
- Releasing controlled technical data or technology to a foreign person inside the United States65. Under the ITAR it counts as an export to every country where that person holds or has held citizenship, or currently holds permanent residency6.
- Public domain and fundamental research
- Published, generally accessible information is outside the ITAR, including fundamental research at accredited US universities whose results are ordinarily published11. Company R&D with proprietary or access restrictions rarely qualifies.
Artifact-by-artifact mapping for an ML pipeline
Brief counsel with the middle column; apply the right column as the default until they decide.
| Pipeline artifact | Question to put to counsel | Default engineering control |
|---|---|---|
| Raw sensor data | Does it reveal performance, signatures or characteristics of a USML or CCL item? | Store in a controlled enclave with US-person access and jurisdiction tags on every file. |
| Labeled training sets | Do the labels add controlled knowledge, such as target classes or threat parameters? | Track lineage to source data; inherit the most restrictive tag of any input. |
| Trained weights | Can the model reproduce controlled data or reveal design detail when queried or inspected? | Mark weights with the dataset's status; register them in a controlled model registry. |
| Evaluation and red-team reports | Do they state detection ranges, failure modes or countermeasure effects? | Treat as technical data by default; release only after review. |
| Source code | Is the code specially designed for a defense article, or generic ML tooling? | Separate generic libraries from program-specific code in different repositories. |
| Prompts and model outputs | Do prompts carry design detail to a hosted model, and where does it run? | Block egress to unapproved endpoints; log prompts in the enclave. |
| Support and integration work | Is any foreign person being helped to integrate, test or operate the system? | Route through an agreement review before any technical meeting. |
These are conservative defaults, not determinations; relax them only on a written decision from your empowered official.
Foreign-national engineers and technology control plans
Mixed teams are normal in ML engineering, so deemed exports are the most frequent exposure. If a foreign-national engineer can open a controlled bucket, read a model card listing detection ranges or join a design review, the export happens when they look.
The usual tool is a technology control plan: which data is controlled, who may access it, how access is enforced and how staff are briefed. For ML work it should name controlled repositories, registries and compute clusters, and make US-person status an identity attribute so access is denied by default.
Where a foreign national needs access, the routes are an ITAR export license or technical assistance agreement, or an EAR deemed-export license. Each takes time, so staffing and export planning must start together.
Cloud regions, encryption and hosted model APIs
The ITAR and the EAR both say that sending or storing unclassified technical data or technology is not an export when it is secured with end-to-end encryption meeting stated conditions34. For AI workloads, the details decide everything.
- If
You store controlled datasets or weights in a commercial cloud region outside the United States.
ThenRely on the carve-out only with end-to-end encryption using FIPS 140-2 validated modules or equivalent strength, keys held by authorized parties, and no storage in proscribed countries3.
If the provider or anyone else can decrypt, the carve-out no longer applies.
- If
You want to train or run inference on controlled data in a cloud.
ThenUse a US-region or government cloud environment with US-person-only administrative access, confirmed in the contract.
Compute needs plaintext, so encryption cannot cover processing; access controls have to.
- If
Engineers want to send prompts containing program detail to a commercial LLM API.
ThenBlock it by default; allow only endpoints whose hosting region, operator access and retention your empowered official has reviewed.
The provider decrypts the prompt to answer it, which makes the request a potential release.
Advanced-computing and model-weight controls are a separate topic
Engineering controls for an export-controlled ML pipeline
A sensor-fusion model moves from R&D to a partner trial
Questions and answers
Are open-weight models covered by the ITAR?
A generic, published open-weight model is normally public-domain information. Once you fine-tune it on controlled data or specialize it for a defense article, the derived weights may embody technical data. Keep the base model and the derivative apart, with separate status, and ask counsel to rule on the derivative.
Can we publish research based on a defense AI project?
Only after export review. The ITAR's fundamental research route covers research at accredited US universities whose results are ordinarily published without proprietary or government restrictions11, which company contract work rarely meets. A pre-publication review that removes controlled data, performance figures and design detail is the safer default.
Can we use a commercial LLM API on an ITAR program?
Not by default. A prompt containing technical data can be a release, because the provider decrypts it to answer. Some providers offer US-region or government environments with US-person operations; your empowered official should review hosting, operator access and retention terms before controlled content goes near one.
Who signs off on the export status of a model?
Your empowered official, advised by export counsel, owns jurisdiction and classification decisions, and a commodity jurisdiction request to DDTC settles unclear cases. Engineering supplies accurate inputs, such as dataset lineage, what the model can reveal, where it runs and who can reach it, then enforces the decision in tooling.
Sources
- International Traffic in Arms Regulations, 22 CFR Parts 120–130 — Electronic Code of Federal Regulations · checked 10 October 2026
- Export Administration Regulations, 15 CFR Parts 730–774 — Electronic Code of Federal Regulations · checked 10 October 2026
- 22 CFR § 120.54 — Activities that are not exports, reexports, retransfers, or temporary imports — Legal Information Institute, Cornell Law School · checked 10 October 2026
- 15 CFR § 734.18 — Activities that are not exports, reexports, or transfers — Legal Information Institute, Cornell Law School · checked 10 October 2026
- 15 CFR § 734.13 — Export — Legal Information Institute, Cornell Law School · checked 10 October 2026
- 22 CFR § 120.50 — Export — Legal Information Institute, Cornell Law School · checked 10 October 2026
- The Export Control Order 2008 (SI 2008/3231) — legislation.gov.uk · checked 10 October 2026
- Consolidated list of strategic military and dual-use items that require export authorisation — Export Control Joint Unit, UK Government · checked 10 October 2026
- 22 CFR § 120.33 — Technical data — Legal Information Institute, Cornell Law School · checked 10 October 2026
- 22 CFR § 120.32 — Defense service — Legal Information Institute, Cornell Law School · checked 10 October 2026
- 22 CFR § 120.34 — Public domain — Legal Information Institute, Cornell Law School · checked 10 October 2026