AI agents have become the default first stop for technical questions. Engineers ask them to draft code. Program managers ask them to summarize specifications. Sales teams ask them to explain a product’s capabilities to a customer. It’s fast, it’s convenient, and it feels harmless.

But in the trade compliance world, there’s a question that almost nobody is asking before they hit “enter”: where did that answer come from, and does the answer itself now carry an export control classification?

This isn’t a hypothetical concern. It’s a structural gap between how generative AI works and how U.S. export control law works, and it’s one that compliance teams need to start closing now.

The Core Problem: AI Doesn’t Know What It’s Touching

When you ask an AI agent a question, it doesn’t just reason from a blank slate. It draws on training data, retrieval systems, connected repositories, or live web content to construct an answer. The AI has no innate concept of the Export Administration Regulations (EAR), the International Traffic in Arms Regulations (ITAR), or the Commerce Control List. It doesn’t know — and typically doesn’t disclose — whether the underlying data it pulled from includes controlled technology, controlled technical data, or ITAR-controlled defense information.

That matters because export control classification isn’t only about the individual pieces of information. It’s about what you build with them.

Lesson One From Trade Compliance Training: The Whole Can Be Controlled Even When the Parts Aren’t

Anyone trained in trade classification has heard some version of this example: walk into a convenience store and buy a glass jar, a rag, gasoline, and a lighter. Individually, every one of those items is completely unregulated. You can buy all four without raising an eyebrow. But combine them with the intent and technical understanding to create an incendiary device, and you’ve created something that falls under a very different regulatory — and legal — category entirely.

Export control classification works the same way. The EAR and ITAR don’t just look at whether input A is controlled and input B is controlled. They look at what the combination becomes. A “specially designed” component test, an end-use determination, or a technical data aggregation analysis can pull an otherwise benign combination of unregulated parts into a controlled classification. Trade compliance professionals are trained to think about the assembled output, not just the individual inputs.

AI systems are not trained to think this way at all. They optimize for a helpful, complete answer — not for whether the synthesis of multiple data sources creates a new item subject to control.

Lesson Two: Code Generation Can Quietly Cross a Line

Consider a developer who asks an AI coding assistant to help build an application that includes encryption functionality. The AI may pull in open-source cryptographic libraries, sample implementations, or patterns learned from public code repositories. On its own, publicly available open-source encryption code is generally excluded from EAR jurisdiction under the publicly available technology carve-out.

But once that code is modified, integrated into a broader software architecture, and combined with other proprietary functionality — particularly functionality tied to specific end uses, end users, or performance parameters — the resulting product may no longer qualify for that exclusion. The finished software can become a controlled item, specifically requiring an Export Control Classification Number (ECCN) review, even though every individual snippet the AI pulled in was technically public. Nobody flagged it, because nobody asked the AI to check.

Lesson Three: The Deemed Export Problem

Here’s a third example worth adding to the list: deemed exports. If an engineer at a U.S. company asks an AI assistant a technical question in a conversation that includes, or is later shared with, a foreign national colleague — and the AI’s answer synthesizes controlled technical data from an internal repository — that transfer of technical data to a foreign person, even inside the United States, can itself constitute a “deemed export” under the EAR or ITAR. The AI isn’t aware of who is in the room, who has access to the chat log, or what jurisdiction the recipient is from. It just answers the question.

What Compliance Teams Should Be Doing Now

  1. Map your AI data sources. Know what repositories, document stores, and training data your AI tools can access, and flag any that contain ECCN-classified or ITAR-controlled material.
  2. Treat AI-generated outputs as new items for classification purposes, not simply as restatements of existing, already-cleared information.
  3. Build access controls around AI tools the same way you would around a controlled technical data room — including nationality-based restrictions where relevant.
  4. Train employees that “the AI told me it was fine” is not a compliance determination, and that the convenience-store lesson applies just as much to code and data as it does to household chemicals.

AI isn’t going away from technical workflows, and it shouldn’t. But trade compliance teams need to extend the same combination thinking they’ve always applied to physical products into the world of AI-generated outputs — before the export control violation shows up in a compliance audit instead of a training slide.


Leave a Reply

Your email address will not be published. Required fields are marked *