Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · BIS / EAR

Deemed exports and technology transfer: BIS / EAR and EU compared

A US-based technology company recruits a software engineer who holds citizenship from a country subject to strict export-control treatment. The engineer will work on a project involving controlled encryption technology. Does that access require a licence? The answer depends entirely on the deemed-export rules under the Export Administration Regulations ("EAR"), administered by the Bureau of Industry and Security ("BIS"). The same company has a subsidiary in Germany. The German entity employs researchers from outside the EU. Does EU dual-use law impose a parallel obligation? The two regimes give very different answers – and getting either wrong carries serious consequences.

As of April 2026, deemed exports and technology transfer under the BIS / EAR treat the release of controlled technology or source code to a foreign national on US soil as an export to that person's country of nationality, requiring a licence where one would be required for a physical export. The EU dual-use regime under Council Regulation (EU) 2021/821 does not contain a direct equivalent deemed-export rule, though it imposes its own intangible technology-transfer controls triggered by the nature of the technology and its destination, not by the nationality of the recipient within the EU. The divergence between these regimes creates real compliance gaps for multinationals and cross-border research institutions.

This analysis sets out the BIS / EAR deemed-export test in detail, maps the EU position against it, identifies the principal points of divergence, examines the practical risk flags that arise in multinational workforces and joint ventures, and explains when cross-border counsel is needed.

What is a deemed export under the BIS / EAR, and why does it matter for multinational employers?

A deemed export is, under the EAR, the release of technology or source code subject to an Export Control Classification Number ("ECCN") to a foreign national inside the United States, which BIS treats as an export to that person's most recent country of citizenship or permanent residence. The legal basis is IEEPA, implemented through the EAR. Where a licence would be required to ship the same technology physically to the destination country, a licence is equally required before the foreign national accesses it on US soil.

The practical consequence is profound. Multinational employers, universities, and research institutions must screen the nationality of employees and students before granting access to controlled items on the Commerce Control List ("CCL"). This is not a theoretical risk. In our experience, many organisations that have mature physical-export compliance programmes have paid far less attention to the internal technology-access dimension. The question they rarely ask: "What is the nationality of the person sitting at this workstation?" is often the most important question in the deemed-export analysis.

The scope of "technology" under the EAR is broad. It captures know-how, design data, specifications, and source code that fall within a controlled ECCN. It does not capture information that is in the public domain, arises from fundamental research that will be published, or constitutes educational information in catalogue-listed courses. These exclusions matter greatly in a university or R&D setting – but their boundaries are less clear than compliance teams sometimes assume.

BIS has historically focused enforcement in sectors with the highest risk of diversion: advanced semiconductors, encryption, aerospace, and materials with military applications. A deemed-export violation in these sectors can attract significant civil penalties and, where wilful, criminal referral to the Department of Justice.

How does EU dual-use law handle intangible technology transfer?

The EU dual-use regime, operating under Council Regulation (EU) 2021/821, regulates intangible technology transfer, but it does so through a fundamentally different conceptual lens. There is no direct EU equivalent of the BIS deemed-export rule. The EU instrument does not treat the nationality of a person within EU territory as the trigger for a licence requirement. Instead, the EU regime focuses on the destination of the technology, the nature of the item, and whether the technology is being transferred or made accessible to a person or entity outside the EU.

What the EU does regulate, and what compliance teams sometimes miss, is the export of technology by electronic means – email, file-sharing, cloud access – to a person or entity in a third country. If a French engineer emails controlled technical specifications to a colleague at a joint-venture facility in a country subject to EU controls, that transmission is an export within the meaning of Council Regulation (EU) 2021/821 and may require a licence from the relevant national competent authority in France.

Each EU Member State maintains its own licensing authority. In Germany that is BAFA; in France, the SBDU sits within the Ministry of Economy; in the Netherlands, the relevant directorate-general of the Ministry of Foreign Affairs handles licensing. This fragmentation means that a single multinational operating across three EU jurisdictions may face three separate licensing processes for the same technology transfer, each with its own procedural timeline and evidentiary requirements.

The EU regime does provide a range of general authorisations – standing permissions covering defined categories of exports – but these do not map neatly onto the BIS licence exception structure. A transfer covered by an EU general export authorisation may still require a specific BIS licence, and vice versa. In our cross-border practice, the assumption that EU clearance implies US clearance (or the reverse) is one of the most persistent and costly misconceptions we encounter.

Where do the regimes diverge on deemed exports and technology transfer?

The divergence between the BIS / EAR and EU regimes on deemed exports and technology transfer runs across at least five distinct dimensions, each of which has practical compliance consequences.

First, the trigger. Under the EAR, the trigger is the nationality of the person receiving access to controlled technology inside the United States. Under the EU regime, the trigger is the destination to which technology is transmitted or made available – not the nationality of the person in EU territory. A German subsidiary employing a national from a sensitive destination can, in principle, share controlled technology with that employee without a licence requirement under EU rules (absent specific end-use or end-user concerns), whereas doing the same thing in the US entity would require a BIS licence or a qualifying exception.

Second, the scope of "release." The EAR definition of "release" is deliberately wide: visual inspection of a controlled item, oral exchange of controlled information, and access to technology in any medium all constitute a release. The EU regime focuses primarily on transmission by electronic or other means to a third country. Internal access within EU territory is generally not the operative EU question, though Member States may impose additional national controls.

Third, the exceptions architecture. BIS operates a structured licence-exception regime, including a specific exception for foreign nationals employed in the US when their country of nationality appears on the approved list and the technology falls within defined parameters. The EU general authorisation system is functionally different: it is destination-based, sector-based, and in some cases item-specific. There is no EU analogue to the BIS licence exception for individual foreign nationals employed at US facilities.

Fourth, the regulatory update cycle. The CCL is updated on a rolling basis, often in response to interagency review or multilateral arrangement changes. EU Annex I to Council Regulation (EU) 2021/821 is also updated periodically to reflect Wassenaar Arrangement, Australia Group, Nuclear Suppliers Group, and Missile Technology Control Regime revisions. In practice, the US and EU lists track closely at the multilateral level, but US unilateral controls – particularly for advanced semiconductors, quantum computing items, and certain AI-related technology – can diverge significantly from EU controls. This creates categories of technology that require a BIS licence but not an EU export authorisation, and businesses operating across both regimes need classification analysis under both.

Fifth, enforcement and the consequence of non-compliance. BIS enforcement of deemed-export violations can result in civil penalties on a per-violation basis, denial of export privileges, and, in egregious cases, criminal prosecution. EU Member States enforce their own national regimes, and the penalties vary by jurisdiction. The extraterritorial dimension of BIS enforcement – including its ability to pursue non-US parties who have re-exported US-origin technology in violation of the EAR – is broader and better-established than any equivalent EU extraterritorial reach. For a multinational group, a deemed-export violation in the US entity can therefore have reverberations for the entire group's export-privilege status.

Which regime is stricter on deemed exports and technology transfer?

The BIS / EAR regime is, on balance, stricter in its treatment of deemed exports because it imposes a nationality-based licence trigger that has no direct equivalent in EU law. A business that employs nationals from countries subject to US controls faces a more expansive set of internal technology-access restrictions under the EAR than it does under Council Regulation (EU) 2021/821 for the same employees working in EU facilities.

That said, the question of strictness is not one-dimensional. The EU regime is, in some respects, more demanding on intangible-transfer documentation. Member State competent authorities in Germany and the Netherlands, in our experience, apply rigorous end-user and end-use requirements that go beyond what a US deemed-export analysis requires. A BIS deemed-export licence may issue on the basis of nationality clearance and classification; an EU licence for transmission to the same destination may require detailed end-use undertakings, site-visit conditions, and post-shipment reporting.

The principle that applies across both regimes is this: where two or more regimes govern the same transfer, the stricter prohibition governs. A multinational that is BIS-clean but EU-unlicensed for the same technology transfer is not in compliance. The regimes do not substitute for one another. We regularly advise clients on the need to run parallel classification and licensing analyses rather than assuming that clearance under one regime satisfies the other.

There is also a third layer that businesses with US-origin content must keep in mind. BIS's de minimis and foreign-direct-product rules extend US jurisdiction extraterritorially to non-US items incorporating or produced from controlled US technology or software. A European manufacturer that uses US-origin controlled software in its production process may, in certain circumstances, find that its exports are subject to BIS jurisdiction even though it is not a US person and the item is not US-origin. This extraterritorial dimension of the EAR is, in our experience, significantly under-appreciated by compliance teams outside the United States.

Risk flags in multinational workforces, joint ventures, and cloud environments

The highest-risk scenarios we encounter in cross-border practice fall into a consistent set of categories. Understanding them is the starting point for a practical risk-reduction programme.

Foreign-national employees and secondees. A multinational that seconds employees between its US and EU entities must assess whether the technology each employee accesses in either location requires a deemed-export licence under the EAR. Secondment agreements that are silent on technology access are a red flag. The analysis must be done before the secondee starts work, not retroactively.

Joint ventures with non-US, non-EU partners. A joint venture between a US parent and a third-country partner creates a permanent technology-access question. The partner's employees, if they access controlled technology at US or EU facilities, may trigger licence requirements under one or both regimes. Joint-venture agreements and IP-sharing schedules that do not address this are operationally incomplete.

Cloud environments and virtual access. BIS has confirmed that cloud access to controlled technology constitutes a release where the foreign national accessing the cloud is located outside the United States or accesses from an uncontrolled location. EU guidance from national competent authorities varies, but the general direction of travel is toward treating cloud-based access to controlled technology as a transfer subject to authorisation requirements where the end user or destination triggers controls. Businesses that moved controlled technology to cloud infrastructure without an export-control assessment have, in our experience, created undisclosed compliance gaps.

University and research institution collaboration. The fundamental-research exclusion under the EAR provides important relief, but it applies only to research that is not restricted for proprietary reasons and whose results will be published without pre-publication review for export-control purposes. Sponsored research arrangements with government contracts, or those subject to publication restrictions, may fall outside the exclusion. Researchers and technology-transfer offices that apply the exclusion without analysing the specific terms of each research agreement are taking a risk.

M&A and post-acquisition integration. An acquisition target may have employed foreign nationals who accessed controlled technology without the required deemed-export licences. That historical violation does not disappear on closing. Post-acquisition integration must include a deemed-export audit, and the acquiring entity should assess whether a voluntary self-disclosure ("VSD") to BIS is warranted. A VSD, properly prepared, typically results in a more favourable outcome than a violation discovered through enforcement.

The procedure: classification, licensing, and the decision sequence

For both the BIS / EAR and EU regimes, the compliance decision sequence follows the same logical structure, even though the specific tests differ. Working through it in order – and documenting each step – is both the correct methodology and the best evidence that a compliance programme is functioning properly.

The first question is classification. Under the EAR, the technology must be assessed against the CCL to determine whether it falls within a specific ECCN. Technology that is not on the CCL is classified as EAR99 and generally does not require a licence (though some EAR99 items may still be subject to controls for certain destinations, end-users, or end-uses). Under Council Regulation (EU) 2021/821, the equivalent question is whether the technology appears in Annex I, which mirrors the multilateral control lists.

The second question, under the EAR for deemed exports, is the nationality of the person who will access the technology. If that person's most recent country of citizenship or permanent residence is a country for which a licence would be required to export the technology physically, a deemed-export licence is required unless an exception applies.

The third question is whether a licence exception covers the release. BIS maintains a structured set of exceptions; the one most frequently relevant to deemed exports permits releases to nationals of countries on an approved list and to permanent residents in specified circumstances. Confirming that an exception applies requires both a classification check and a nationality check. Neither alone is sufficient.

The fourth question, if no exception applies, is the licensing process. A BIS deemed-export licence application requires a description of the technology, the identity of the foreign national, the scope of access, and in many cases an end-use statement. BIS processing times vary; for sensitive technology categories, review can extend over several months. Planning the employment start date around the licensing timeline is a practical necessity, not an optional precaution.

For EU intangible-transfer situations, the parallel sequence runs through the national competent authority. Timeline and documentation requirements vary by Member State, but the export-control assessment – classification, destination analysis, end-user screening, licence-exception review – follows the same logic.

Documentation should be retained for all steps. Both BIS and EU Member State authorities expect records of the classification decision, the licence or exception relied upon, and the ongoing monitoring of any licence conditions. In our experience, businesses that document their methodology – even where the conclusion is that no licence is needed – are in a materially better position if the compliance assessment is later questioned by an authority.

The position above covers the standard case. Your facts – the technology in question, the nationalities involved, the countries of concern, and the access controls in place – change the analysis significantly. For a tailored assessment, contact Calder & Vance at info@caldervance.com.

Cross-border extraterritorial reach: when BIS jurisdiction follows the technology beyond US borders

One of the most consequential – and least well-understood – dimensions of the BIS / EAR regime is its extraterritorial reach over non-US persons and non-US items. The EAR extends US jurisdiction to foreign-made items that incorporate US-origin controlled technology above the applicable de minimis threshold, and to foreign-made items that are the direct product of US-origin controlled technology or production equipment.

In practical terms, a European or Asian manufacturer whose production process relies on US-controlled software or whose design uses US-origin controlled technology may find that its finished product is subject to BIS jurisdiction. Re-exporting that product without checking BIS requirements is a potential EAR violation, regardless of whether the manufacturer is a US person or located in the United States. This is the foreign-direct-product rule, and it has been applied and expanded significantly in recent years to cover certain categories of advanced semiconductor manufacturing equipment and technology.

The EU has no equivalent extraterritorial mechanism. EU controls apply to items in the EU and to EU persons, but they do not, in the same way, follow technology incorporated into non-EU-origin items manufactured outside the EU by non-EU persons. This asymmetry creates a compliance dynamic where non-US companies in the supply chain of advanced technology sectors must assess BIS exposure even where they have no direct relationship with the United States.

If a transaction has already been flagged – whether through a compliance review, a BIS inquiry, or a voluntary screening hit – an early review of the exposure can preserve options that narrow with time. Contact us at info@caldervance.com to discuss the position.

A practical divergence scenario: the same transfer, two different answers

Consider a representative fact pattern that illustrates how differently the two regimes can respond to identical facts.

A multinational engineering group has a US entity and a German subsidiary. Both entities are working on a controlled electromagnetic component subject to an ECCN with licence requirements for a specific destination country. The German subsidiary recruits a senior engineer who is a national of that destination country and who will need access to the full technical specifications of the component.

Under the EAR, the access by the engineer to those specifications at the German subsidiary is not a BIS deemed export in itself – the deemed-export rule applies to releases inside the United States, not to releases at non-US locations. However, if the same engineer is seconded to the US entity for three months, access there triggers the deemed-export analysis, and a BIS licence will likely be required before access is granted.

Under Council Regulation (EU) 2021/821, the German subsidiary's question is different. If the engineer accesses the controlled specifications within Germany and does not transmit them to a third country, no EU export authorisation is triggered by that internal access. However, if the engineer uses remote access tools to pull documents from a server in a third country, or transmits materials to a contact at a facility in the destination country, that transmission is a potential EU-controlled technology transfer requiring authorisation from BAFA.

The same multinational group now faces two separate licence requirements from two separate authorities, arising from the same technology and the same engineer, but triggered at different points. Managing both requires a compliance programme that is aware of both regimes simultaneously – which is rarely the default position for organisations that built their export-compliance function around physical-goods controls.

In a recent matter, we advised a manufacturing group facing precisely this configuration following the recruitment of a senior technical employee with dual nationalities, one of which created BIS sensitivity. We assessed the classification of the technology involved, confirmed the applicable deemed-export requirement, identified the relevant BIS licence exception, and mapped the parallel EU technology-transfer exposure for the German entity. The matter proceeded on the basis of a documented exception analysis and a revised access-control protocol, without disrupting the employment start.

Common misconceptions and practical objections

In advising cross-border businesses on deemed exports and technology transfer, we encounter a consistent set of misconceptions that create compliance risk.

The myth that published technology is always free from controls. The fundamental-research and public-domain exclusions under the EAR are real and important, but they have defined boundaries. Technology that has been published but originated under a controlled research programme, or that is accessible only through a subscription database with access controls, may not qualify for the public-domain exclusion. Assuming that anything findable online is uncontrolled is a risk the BIS enforcement record does not support.

The myth that EU export clearance means BIS clearance. As noted above, these are independent regimes with independent classification and licensing requirements. EU general export authorisations do not satisfy BIS requirements, and BIS licence exceptions do not satisfy EU authorisation requirements. Businesses that run only one analysis for a cross-border technology transfer are conducting a partial compliance assessment.

The myth that deemed-export obligations apply only to defence contractors. The EAR's deemed-export rules apply to any technology on the CCL, which includes a wide range of commercial, dual-use items well beyond defence hardware. Encryption software, advanced materials, telecommunications equipment, and sensors all appear on the CCL. A commercial software company, a research hospital, or an energy-sector manufacturer may have deemed-export obligations without ever having had a contract with a defence procurement authority.

The myth that hiring permanent residents eliminates deemed-export risk. BIS's approach to permanent residents is nuanced. A permanent resident who was born in, or who holds citizenship of, a country subject to US export controls may still require a deemed-export licence analysis, even if they hold US permanent-resident status. The analysis turns on the specific facts of the individual's immigration history and citizenship, not solely on their current resident status. Treating all permanent residents as automatically cleared is a compliance shortcut that BIS does not endorse.

Related practices

Frequently asked questions on deemed exports and technology transfer

Where do the regimes diverge on deemed exports and technology transfer?

The primary divergence is on the trigger. The BIS / EAR regime triggers a licence requirement based on the nationality of the person receiving access to controlled technology inside the United States. The EU regime under Council Regulation (EU) 2021/821 does not apply a nationality-based internal trigger; it focuses instead on the destination to which technology is transmitted or made accessible from EU territory. A multinational employer faces a more expansive set of internal access restrictions under BIS than under EU law, but may face more demanding end-use documentation requirements under certain EU Member State regimes. The two regimes also differ in their licence-exception architecture and in BIS's extraterritorial reach over non-US items incorporating US-origin controlled technology.

Which regime is stricter on deemed exports and technology transfer?

On the deemed-export question specifically, the BIS / EAR is stricter: its nationality-based internal-access trigger has no EU equivalent. However, the EU regime can be more demanding on intangible-transfer documentation and end-use conditions for certain destination-country transfers. The operative principle is that both regimes must be satisfied independently: a business that is compliant under one but not the other is not in compliance. Where both apply, the stricter prohibition governs, and that requires a parallel analysis under each regime rather than an assumption that clearance under one satisfies the other.

What should a cross-border business do about deemed exports and technology transfer?

A cross-border business should start with a technology-access audit: map the controlled items or technology in use, classify them against both the CCL and the EU Annex I list, and identify the nationalities of all persons who access controlled technology at US or EU facilities. From that map, assess whether current access controls satisfy deemed-export requirements under the EAR and intangible-transfer requirements under Council Regulation (EU) 2021/821. Where gaps are identified, address licensing requirements before access is granted – not retrospectively. Maintain documentation of each classification decision and the licence or exception relied upon. If historical non-compliance is identified, consider whether a voluntary self-disclosure to BIS is appropriate. Legal counsel with cross-regime experience should be engaged for any situation involving advanced technology, sensitive nationalities, or a combined BIS and EU exposure.

About the author

Viktor Lindqvist advises exporters and trading houses on dual-use export controls, maritime and trade sanctions, and end-use compliance. His practice encompasses technology-transfer analysis under both the BIS / EAR and EU dual-use regimes, ECCN classification, licence exception assessments, and enforcement-defence support for exporters identified with potential EAR violations. Calder & Vance – International Sanctions & Export Control Counsel.

About Calder & Vance

Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.

To stress-test your deemed-export screening programme or discuss a cross-border technology-transfer exposure, reach our team at info@caldervance.com.

Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.